WO2024027271A1 - 应用流量感知方法及系统 - Google Patents
应用流量感知方法及系统 Download PDFInfo
- Publication number
- WO2024027271A1 WO2024027271A1 PCT/CN2023/093987 CN2023093987W WO2024027271A1 WO 2024027271 A1 WO2024027271 A1 WO 2024027271A1 CN 2023093987 W CN2023093987 W CN 2023093987W WO 2024027271 A1 WO2024027271 A1 WO 2024027271A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- application
- application traffic
- traffic
- information
- identification
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0813—Configuration setting characterised by the conditions triggering a change of settings
- H04L41/082—Configuration setting characterised by the conditions triggering a change of settings the condition being updates or upgrades of network functionality
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/11—Identifying congestion
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/25—Mapping addresses of the same type
- H04L61/2503—Translation of Internet protocol [IP] addresses
- H04L61/2592—Translation of Internet protocol [IP] addresses using tunnelling or encapsulation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/30—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
- H04L63/302—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information gathering intelligence information for situation awareness or reconnaissance
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
Definitions
- Embodiments of the present invention relate to the field of data communication and transmission, and specifically to an application traffic sensing method and system.
- Embodiments of the present invention provide an application traffic sensing method and system to at least solve the problem in related technologies that the sensing depth message cannot be parsed and only supports simple Layer 2 message header identification and processing.
- an application traffic sensing method including: performing traffic identification on application traffic received from the first user edge device CE, and identifying the application traffic according to the identification result; The identification of the application traffic adds Ethernet Layer 2 header information to the packet of the application traffic to encapsulate the packet of the application traffic; and sends the encapsulated packet to the first provider edge.
- Equipment PE so that the first PE imports the packet into a transmission pipe that meets the service level agreement SLA of the application traffic for transmission.
- an application traffic awareness system including: an escaping device configured to sequentially identify, identify and encapsulate the application traffic received from the first user edge device CE, and encapsulate the The packet of the application traffic is sent to the first provider edge device PE, so that the first PE imports the packet into a transmission pipe that meets the service level agreement SLA of the application traffic for transmission.
- a computer-readable storage medium is also provided.
- a computer program is stored in the computer-readable storage medium, wherein the computer program is configured to execute any of the above methods when running. Steps in Examples.
- an electronic device including a memory and a processor.
- a computer program is stored in the memory, and the processor is configured to run the computer program to perform any of the above. Steps in method embodiments.
- Figure 1 is a hardware structure block diagram of a mobile terminal applying a traffic sensing method according to an embodiment of the present invention
- Figure 2 is a flow chart of an application traffic sensing method according to an embodiment of the present invention.
- Figure 3 is a flow chart of an application traffic sensing method according to an embodiment of the present invention.
- Figure 4 is a flow chart of application traffic encapsulation according to an embodiment of the present invention.
- Figure 5 is a flow chart of an application traffic sensing method according to an embodiment of the present invention.
- Figure 6 is a flow chart of an application traffic sensing method according to an embodiment of the present invention.
- Figure 7 is a flow chart of an application traffic sensing method according to an embodiment of the present invention.
- Figure 8 is a structural block diagram of an application traffic sensing system according to an embodiment of the present invention.
- Figure 9 is a structural block diagram of an escape device according to an embodiment of the present invention.
- Figure 10 is a structural block diagram of a parsing module according to an embodiment of the present invention.
- Figure 11 is a structural block diagram of an application traffic sensing system according to an embodiment of the present invention.
- Figure 12 is a schematic structural diagram of an application traffic-aware network framework according to a scenario embodiment of the present invention.
- Figure 13 is a structural block diagram of an escape device according to a scene embodiment of the present invention.
- Figure 14 is a flow chart of an application traffic sensing method according to a scenario embodiment of the present invention.
- Figure 15 is a flow chart of an application traffic sensing method according to a scenario embodiment of the present invention.
- FIG. 1 is a hardware structure block diagram of a mobile terminal applying a traffic sensing method according to an embodiment of the present invention.
- the mobile terminal may include one or more (only one is shown in Figure 1) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned mobile terminal may also include a transmission device 106 and an input and output device 108 for communication functions.
- processors 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA
- a memory 104 for storing data
- the above-mentioned mobile terminal may also include a transmission device 106 and an input and output device 108 for communication functions.
- the structure shown in Figure 1 is only illustrative, and it does not limit the structure of the above-mentioned mobile terminal.
- the mobile terminal may also include more or fewer components than shown in FIG. 1 , or have a different configuration than shown in FIG. 1 .
- the memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the application traffic sensing method in the embodiment of the present invention.
- the processor 102 executes the computer program by running the computer program stored in the memory 104.
- Memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory.
- the memory 104 may further include memory located remotely relative to the processor 102, and these remote memories may be connected to the mobile terminal through a network. Examples of the above-mentioned networks include but are not limited to the Internet, intranets, local area networks, mobile communication networks and combinations thereof.
- the transmission device 106 is used to receive or send data via a network.
- Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the mobile terminal.
- the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station to communicate with the Internet.
- the transmission device 106 may be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet wirelessly.
- RF Radio Frequency
- application awareness refers to traffic identification and labeling of access applications
- traffic import refers to directing the identified application traffic to transmission paths and pipes that meet its SLA requirements.
- existing application-aware network modeling includes the following components:
- Application-aware edge node Identifies the application flow accessed by the Client.
- the source of the identification information can be the Layer 2 to Layer 4 header information encapsulated in the data packet, or the application identifier directly encapsulated at the application layer by the application APP; based on the identification results Encapsulate the application traffic and provide it to the business sensing head node for further processing.
- Application-aware head node Receives application traffic from the application-aware edge node and obtains application identification information from it. It performs path search and matching through the application identifier and application parameter information it maintains, and directs traffic to a path that meets SLA requirements.
- Application-aware intermediate node The intermediate node locally applies a series of traffic or resource policies based on the application identification information carried in the packet to ensure the transmission requirements of the application.
- Application-aware tail node The transmission path terminates at the tail node. If application-related identifiers are carried in the form of tunnel encapsulation in the transmission and forwarding path, the application identification information is stripped off at the tail node.
- application-aware edge nodes and head nodes can be physically combined and deployed in the same entity.
- application sensing is performed at the edge nodes of the network. Since traffic sensing often requires in-depth analysis of packets, it has high requirements on the packet processing capabilities of the device hardware.
- existing transmission network equipment usually does not have this deep packet parsing capability and only supports simple Layer 2 packet header identification and processing.
- the present invention proposes an application traffic-aware method and system, which can translate complex application traffic information into simple messages.
- Layer 2 information through methods, can enable rapid upgrade and adaptation between traditional transmission networks and application-aware networks.
- FIG. 1 is a flow chart of the application traffic sensing method according to an embodiment of the present invention. As shown in Figure 2, the process includes follow these steps:
- Step S202 Perform traffic identification on the application traffic received from the first user edge device (Customer Edge, CE), and identify the application traffic according to the identification result;
- Step S204 Add Ethernet Layer 2 header information to the application traffic packet according to the identification of the application traffic to encapsulate the application traffic packet;
- Step S206 Send the encapsulated message to the first provider edge device (Provider Edge, PE), so that the first PE can import the message into a transmission pipeline that meets the service level agreement (Service Level Agreement, SLA) of the application traffic. Make the transfer.
- PE Provide Edge
- SLA Service Level Agreement
- traffic identification is performed on the application traffic received from the first CE, and the application traffic is identified according to the identification result; Ethernet Layer 2 header information is added to the packet of the application traffic according to the identification of the application traffic, so as to Encapsulate the application traffic packet; send the encapsulated packet to the first PE, so that the first PE can import the packet into the transmission pipeline that meets the SLA of the application traffic for transmission, which solves the problem that the related technology cannot parse the sensing depth packet.
- This document only supports simple Layer 2 packet header identification and processing issues, achieving the effect of rapid upgrade and adaptation between traditional transmission networks and application-aware networks.
- the execution subject of the above steps may be a base station, a terminal, etc., but is not limited thereto.
- the method before performing traffic identification on the application traffic received from the first CE, the method further includes: establishing a parsing control table corresponding to the application traffic matching the application flow number, and establishing a parsing control table corresponding to the application traffic matching the escape encapsulation information.
- Package control table is a flow chart of an application traffic sensing method according to an embodiment of the present invention. As shown in Figure 3, the process includes the following steps:
- Step S302 establish a parsing control table corresponding to application traffic and application flow number matching and an encapsulation control table corresponding to application traffic and escape encapsulation information;
- Step S304 Perform traffic identification on the application traffic received from the first CE, and identify the application traffic according to the identification result;
- Step S306 Add Ethernet Layer 2 header information to the application traffic packet according to the identification of the application traffic to encapsulate the application traffic packet;
- Step S308 Send the encapsulated packet to the first PE, so that the first PE can import the packet into a transmission pipe that meets the SLA of the application traffic for transmission.
- performing traffic identification on the application traffic received from the first user edge device CE, and identifying the application traffic according to the identification result includes: identifying and obtaining the five-tuple information and ingress port information of the application traffic, And based on the five-tuple information and ingress port information, the matching application flow number is found in the parsing control table to complete the identification of the application flow.
- adding Ethernet Layer 2 header information to the packet of the application traffic according to the identification of the application traffic includes: searching for matching escape encapsulation information in the encapsulation control table according to the application flow number; encapsulating according to the escape The information is to add Ethernet Layer 2 header information to application traffic packets.
- Figure 4 is a flow chart of application traffic encapsulation according to an embodiment of the present invention. As shown in Figure 4, the process includes the following steps:
- Step S402 search for matching escape encapsulation information in the encapsulation control table according to the application flow number
- Step S404 Add Ethernet Layer 2 header information to the application traffic packet according to the escape encapsulation information.
- the method further includes: the first PE searches for a matching transmission pipe based on the Ethernet Layer 2 header information; the first PE transmits the encapsulated packet through the transmission channel.
- the message is sent to the second PE.
- Figure 5 is a flow chart of an application traffic sensing method according to an embodiment of the present invention. As shown in Figure 5, the process includes the following steps:
- Step S502 Establish a parsing control table corresponding to application traffic and application flow number matching and an encapsulation control table corresponding to application traffic and escape encapsulation information;
- Step S504 Perform traffic identification on the application traffic received from the first CE, and identify the application traffic according to the identification result;
- Step S506 Add Ethernet Layer 2 header information to the application traffic packet according to the identification of the application traffic to encapsulate the application traffic packet;
- Step S508 Send the encapsulated message to the first PE, so that the first PE can import the message into a transmission pipe that meets the SLA of the application traffic for transmission;
- Step S510 The first PE searches for a matching transmission pipe based on the Ethernet Layer 2 header information
- Step S512 The first PE sends the encapsulated message to the second PE through the transmission channel.
- the first PE imports the packet into a transmission pipe that meets the SLA of the application traffic for transmission, it also includes: reversely searching for a matching application flow number based on the Ethernet Layer 2 header information; Strip the Ethernet Layer 2 header information of the encapsulated packet; reversely search based on the application flow number to match the port number of the second CE that receives the application traffic; send the application traffic to the second CE through the port corresponding to the port number.
- Figure 6 is a flow chart of an application traffic sensing method according to an embodiment of the present invention. As shown in Figure 6, the process includes the following steps:
- Step S602 Reversely search and match the application flow number based on the Ethernet Layer 2 header information
- Step S604 Strip the Ethernet Layer 2 header information of the encapsulated message according to the application flow number
- Step S606 reversely search according to the application flow number to match the port number of the second CE that receives the application traffic;
- Step S608 Send the application traffic to the second CE through the port corresponding to the port number.
- FIG. 7 is a flow chart of an application traffic sensing method according to an embodiment of the present invention. As shown in Figure 7, the process includes the following steps:
- Step S702 reversely search and match the application flow number based on the Ethernet Layer 2 header information
- Step S704 Strip the Ethernet Layer 2 header information of the encapsulated message according to the application flow number
- Step S706 reversely search according to the application flow number to match the port number of the second CE that receives the application traffic;
- Step S708 Send the application traffic to the second CE through the port corresponding to the port number
- Step S710 The second CE delivers the received application traffic to the user equipment.
- the Layer 2 header message includes at least one of the following: virtual local area network information VLAN or multi-protocol label switching information MPLS.
- the method according to the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is Better implementation.
- the technical solution of the present invention can be embodied in the form of a software product in essence or the part that contributes to the existing technology.
- the computer software product is stored in a storage medium (such as ROM/RAM, disk, CD), including several instructions to cause a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present invention.
- This embodiment also provides an application traffic sensing system, which is used to implement the above embodiments and preferred implementations. What has already been described will not be described again.
- the terms “device”, “module” and “unit” may be a combination of software and/or hardware that implements a predetermined function.
- the systems described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.
- Figure 8 is a structural block diagram of an application traffic awareness system according to an embodiment of the present invention.
- the application traffic awareness system 80 includes: an escaping device 810, configured to sequentially identify application traffic received from the first CE. , identify and encapsulate, and send the encapsulated application traffic packet to the first PE, so that the first PE can import the packet into a transmission pipeline that meets the SLA of the application traffic for transmission.
- an escaping device 810 configured to sequentially identify application traffic received from the first CE. , identify and encapsulate, and send the encapsulated application traffic packet to the first PE, so that the first PE can import the packet into a transmission pipeline that meets the SLA of the application traffic for transmission.
- Figure 9 is a structural block diagram of an escaping device according to an embodiment of the present invention.
- the escaping device 810 includes: a parsing module 910 configured to perform traffic identification on application traffic, and The application traffic is identified according to the identification result; the encapsulation module 920 is configured to add Ethernet Layer 2 header information to the application traffic packet according to the identification of the application traffic to encapsulate the application traffic packet; the sending module 930 is configured to To send the encapsulated packet to the first PE.
- Figure 10 is a structural block diagram of a parsing module according to an embodiment of the present invention.
- the parsing module 910 includes: an identification unit 1010, configured to identify the five-tuple information obtained from the application traffic and Ingress port information; the identification unit 1020 is configured to search and match the application flow number in the parsing control table according to the five-tuple information and the ingress port information to complete identification of the application flow.
- FIG. 11 is a structural block diagram of an application traffic sensing system according to an embodiment of the present invention.
- the application traffic sensing system 110 in addition to the device shown in FIG. 8 , the application traffic sensing system 110 also includes:
- the management and control center 1110 is configured to establish a parsing control table corresponding to application traffic and application flow number matching and an encapsulation control table corresponding to application traffic and escape encapsulation information, and deliver the parsing control table and encapsulation control table to the escape device.
- the escaping device 810 is further configured to reversely identify and identify the encapsulated message. And strip the Ethernet Layer 2 header information of the packet, and send the packet with the Ethernet Layer 2 header information stripped to the second CE.
- the escape device can identify, label, and encapsulate application traffic, as well as reversely identify, identify, and strip the encapsulated messages, which corresponds to the bidirectional transmission of application traffic. matched. That is, in this transmission, the current escaping device may be set to identify, label, and encapsulate application traffic. In the next transmission, the current escaping device may be set to reversely identify and label the encapsulated messages. and stripping.
- each of the above-mentioned devices, modules, and units can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but is not limited to this: the above-mentioned devices, modules, and units are all located in the same processor; Alternatively, each of the above devices, modules, and units may be located in different processors in any combination.
- Embodiments of the present invention also provide a computer-readable storage medium that stores a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.
- the above-mentioned computer-readable storage media may include but is not limited to: U disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), mobile hard disk, Various media such as magnetic disks or optical disks that can store computer programs.
- An embodiment of the present invention also provides an electronic device, including a memory and a processor.
- a computer program is stored in the memory, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
- the above-mentioned electronic device may further include a transmission device and an input-output device, wherein the transmission device is connected to the above-mentioned processor.
- the input and output device is connected to the above-mentioned processor.
- the above-mentioned devices, modules, units or steps of the embodiments of the present invention can be implemented using general-purpose computing devices, and they can be concentrated on a single computing device, or distributed among multiple computing devices.
- they can be implemented with program codes executable by the computing devices, so that they can be stored in a storage device and executed by the computing devices, and in some cases, can be implemented in a manner different from that described here.
- the steps shown or described are performed in sequence, or they are separately made into individual integrated circuit modules, or multiple modules or steps among them are made into a single integrated circuit module. As such, the invention is not limited to any specific combination of hardware and software.
- FIG 12 is a schematic structural diagram of an application traffic-aware network framework according to a scenario embodiment of the present invention.
- the network framework includes:
- CE equipment customer service access equipment. User application traffic is aggregated through the CE equipment and then accessed to the transmission network. Specifically including CE1 and CE2.
- Escape device Set to interface with CE devices to import user application traffic. And identify the application traffic based on the five-tuple information of the access packet (source IP, destination IP, protocol type, source TCP/UDP port number, destination TCP/UDP port number) and input interface. Assume the role of application-aware edge node. Also set up to identify traffic based on the results of applying traffic-aware segmentation. It is also set to add additional layer 2 header information to the corresponding application traffic based on the traffic identification results and the traffic identification escape results issued by the management and control, including but not limited to VLAN, MPLS label and other labels (the following part uses VLAN as an example to describe) . Complete the parsing, sensing and escaping of application traffic. It is also set to connect to the PE device of the transmission network and send the escaped packets to the PE device from the corresponding egress port. Specifically, it includes escape device 1 and escape device 2.
- PE equipment Set to interface with the escape device, and identify and identify traffic by parsing the VLAN and other fields of matching packets. It is also set to receive the business path calculation results issued by the management and control platform, and guide the identified application traffic to a path that meets SLA requirements. Specifically including PE1 and PE2.
- Management and control center Set up to collect and maintain transmission network topology and link data information, and support the dynamic establishment and teardown of transmission links when necessary. It is also set to collect and maintain application traffic characteristic information, as well as SLA requirements corresponding to application traffic (which can be obtained through static configuration or interaction through control protocol extension). It is also set to perform policy matching on the network TE database according to the application traffic SLA requirements, obtain the service path that meets the application SLA requirements, and deliver the matching results to the transmission network device.
- Figure 13 is a structural block diagram of the escaping device according to the scenario embodiment of the present invention. As shown in Figure 13, the escaping device includes:
- Component 1 Parser.
- the parser accesses user application traffic from interfaces P1-Pn and analyzes it. Based on the analysis results, it obtains the traffic five-tuple information (source IP, destination IP, protocol type, TCP/UDP source port number, TCP/UDP destination port number). , combine the ingress port number of the traffic input to form a Key value query parsing control table, and mark the corresponding packets based on the application flow number information returned from the parsing control table.
- Component 2 Parse the control table.
- This table is used to store the mapping relationship between message quintuples and application flow numbers.
- the content is configured and issued by the management and control center and is queried by the parser.
- parsing control table The specific structure of the parsing control table is shown in Table 1, which includes input port number, source IP (Source IP, SIP), destination IP (Destination IP, destination IP), protocol type, TCP/UDP source port number, TCP/ UDP destination port number and application flow number.
- Component 3 Encapsulation control table.
- This entry stores the mapping information between application traffic and outbound encapsulation.
- the traffic identification information is the entry key value.
- the escaped traffic identification information is stored in the form of the outbound interface plus the target encapsulation VLAN, MPLS label, etc.
- the escape encapsulation results of traffic identification include but are not limited to VLAN, MPLS label and other information.
- VLAN virtual local area network
- MPLS label physical layer network
- This entry is configured and issued by the control center.
- Table 2 The specific structure of the encapsulation control table is shown in Table 2, which includes the application flow number, outer VLAN identifier, inner VLAN ID and egress port number.
- Component 4 Wrapper.
- the encapsulator is used to escape and encapsulate the identified application traffic.
- the encapsulator receives the message input by the parser and the application traffic identifier carried along the way. And use the application traffic identifier as the key value to perform a matching query on the encapsulation control table.
- the encapsulation control table returns matching encapsulation information to the encapsulator, performs corresponding encapsulation processing on the corresponding application message, and sends the encapsulated escape message from the specified outbound interface.
- FIG. 14 is a flow chart of the application traffic sensing method according to the scenario embodiment of the present invention, as shown in Figure 14 , the process includes the following steps:
- Step 1402 collect network/application information
- the management and control center collects: application traffic characteristic information, transmission network topology information, transmission network pipeline bandwidth, delay, jitter and other related information.
- Step 1404, CE1 sends the aggregated application traffic to escape device 1;
- Component 1 parser parses customer services and obtains traffic quintuple information (source IP, destination IP, protocol type, source TCP/UDP port number, destination TCP/UDP port number). Combined with the incoming port information, the control table is queried and parsed according to the matching rules issued by the management and control.
- Component 2 parser control table Query the parsing control table based on the five-tuple information and return the application flow number to component 1.
- Component 3 encapsulation control table Query the encapsulation control table according to the application flow number, and return the queried escape encapsulation information to component 4
- Component 4 encapsulator performs corresponding escape and encapsulation processing on the application message based on the return result of component 3, adds one or two layers of VLAN information, and sends it out from the device through the designated interface.
- Step 1406 Escape device 1 sends the encapsulated application traffic packet to PE1;
- Step 1408 PE1 receives and parses the message input by escape device 1, and sends it to PE2;
- PE1 Based on the escaped VLAN information carried in the packet, combined with the path calculation results issued by the management and control center, PE1 performs a transmission channel mapping search based on the VLAN information, and imports the corresponding application traffic into the corresponding transmission pipe based on the matching results and sends it to the remote PE2 equipment.
- Step 1410 PE2 receives the message through the transmission pipe and sends it to escape device 2;
- PE2 sends the message from the relevant interface to the escape device 2 according to the mapping relationship between the pipe issued by the management and control and the user-side interface.
- Step 1412 Escape device 2 receives application traffic from PE2 and sends it to CE2;
- the escape device 2 performs a reverse table lookup process based on the access port number and VLAN encapsulation information. After obtaining the application flow number, it performs a VLAN stripping operation on the packet, and reversely queries the CE interconnection port number based on the application flow number. From the relevant port Send to CE2.
- Step 1414 CE2 receives the traffic and forwards it to the connected user equipment
- CE2 receives traffic and forwards it to the connected user equipment to complete end-to-end traffic sensing and transmission.
- FIG. 15 is a flow chart of the application traffic awareness method according to the scenario embodiment of the present invention. As shown in Figure 15, the process includes Following steps:
- Step 1502 collect application/network information and issue control table items
- the management and control center collects application traffic characteristic information, calculates the resources of the escape VLAN, allocates VLAN mapping resources for the corresponding traffic, and then delivers the escape device and PE equipment. 2) The management and control center collects SLA information associated with application traffic. 3) The management and control center collects the topology and transmission pipeline information of the OTN network (such as ODUk, OSU pipeline information). 4) Calculate the application traffic transmission path based on the three; deliver the mapping relationship between VLAN and transmission pipe to the PE device.
- Step 1504 apply traffic awareness and escape encapsulation
- the escape device installs the control table items issued by the control center.
- the parser selects from the traffic quintuple information (source IP, destination IP, protocol type, source TCP/UDP port number, destination TCP/UDP port number), combined with the input port information of the traffic input, based on the matching rules issued by the management and control.
- the corresponding field generates an application traffic number value, and the application traffic number value is carried with the packet and output to the escape encapsulation processor.
- an enterprise user has both video application traffic and data transmission application traffic and accesses the escape device through access port 1.
- the source IP and destination IP of the two application traffic are the same, but the protocol type is the same as the layer 4 port.
- the number information is different.
- the escape device parser queries the parsing control table shown in Table 3 and hits rule 1 and rule 2, and obtains application flow numbers 123 and 234 respectively.
- Table 4 Scenario embodiment encapsulation control table
- Step 1506 Introduce the application traffic into the transmission channel for transmission
- the PE device receives video application and data application traffic from the port at the same time, and identifies them according to the corresponding VLAN identification (100, 100) (100, 200). According to the identification results, the mapping information issued by the management and control is matched, and the two different types of application traffic are imported into different ODU/OSU pipelines that meet their SLA requirements for transmission.
- Step 1508 reverse VLAN stripping of application traffic
- the remote PE device terminates the corresponding application traffic from the ODU/OSU pipe and sends it to the remote escape device.
- the remote escaping device performs a reverse application flow number query based on the VLAN encapsulation information of the packet and performs VLAN removal. It restores the original traffic encapsulation and sends it to the remote CE from the corresponding port.
- the CE device performs necessary demultiplexing and sends it to the underlying application terminal. Complete the end-to-end application sensing and transmission process.
- embodiments of the present invention provide an application traffic sensing method and system, which can perform in-depth analysis of application traffic and convert the analysis results into simple layer two encapsulation information, while also providing applications based on the system.
- End-to-end implementation of perceptual network By deploying this system at the edge of traditional transmission networks (including but not limited to OTN networks), existing network equipment can achieve application awareness by simply identifying simple Ethernet packet Layer 2 header information (including but not limited to VLAN). Effect. It solves the problem that traditional transmission network equipment hardware does not have the ability to deeply analyze packets and cannot perform fine traffic management.
- the existing traditional transmission network can be easily upgraded to the application awareness network, greatly reducing the operator's equipment capital investment and network costs. renovation expenses.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Evolutionary Computation (AREA)
- Technology Law (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本发明实施例提供了一种应用流量感知方法及系统,通过本发明实施例,通过对从第一CE接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识;根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;将封装后的报文发送至第一PE,以便第一PE将报文导入到满足应用流量的SLA的传输管道进行传输。
Description
相关申请的交叉引用
本申请基于2022年8月1日提交的发明名称为“应用流量感知方法及系统”的中国专利申请CN202210920075.6,并且要求该专利申请的优先权,通过引用将其所公开的内容全部并入本申请。
本发明实施例涉及数据通信和传输领域,具体而言,涉及一种应用流量感知方法及系统。
随着网络的演进,各种新兴行业与应用不断涌现。这些不同类型的新兴应用往往对带宽、时延、抖动等性能具有不同的要求。这也对承载网络的传输服务和设备提出了更为严苛和差异化的要求。基于该背景,业界提出了应用感知网络的概念,旨在提供一整套基于应用的流量感知与差异化传送端到端方案。
现有方案中,应用感知在网络的边缘结点进行,由于流量感知往往需要对报文进行深度解析,对设备硬件的分组处理能力具有很高的要求。而现有的传输网络设备通常并不具备这种深度报文解析的能力,仅支持简单的二层报文头识别和处理。
发明内容
本发明实施例提供了一种应用流量感知方法及系统,以至少解决相关技术中不能解析感知深度报文,仅支持简单的二层报文头识别和处理的问题。
根据本发明的一个实施例,提供了一种应用流量感知方法,包括:对从第一用户边缘设备CE接收的应用流量进行流量识别,并根据所述识别结果对所述应用流量进行标识;根据所述应用流量的标识在所述应用流量的报文中增加以太网二层头信息,以对所述应用流量的报文进行封装;将封装后的所述报文发送至第一提供商边缘设备PE,以便所述第一PE将所述报文导入到满足所述应用流量的服务等级协议SLA的传输管道进行传输。
根据本发明的另一个实施例,提供了一种应用流量感知系统,包括:转义装置,设置为对从第一用户边缘设备CE接收的应用流量依次进行识别、标识和封装,并将封装后的所述应用流量的报文发送至第一提供商边缘设备PE,以便所述第一PE将所述报文导入到满足所述应用流量的服务等级协议SLA的传输管道进行传输。
根据本发明的又一个实施例,还提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序,其中,所述计算机程序被设置为运行时执行上述任一项方法实施例中的步骤。
根据本发明的又一个实施例,还提供了一种电子装置,包括存储器和处理器,所述存储器中存储有计算机程序,所述处理器被设置为运行所述计算机程序以执行上述任一项方法实施例中的步骤。
图1是本发明实施例的一种应用流量感知方法的移动终端的硬件结构框图;
图2是根据本发明实施例的应用流量感知方法的流程图;
图3是根据本发明实施例的应用流量感知方法的流程图;
图4是根据本发明实施例的应用流量封装的流程图;
图5是根据本发明实施例的应用流量感知方法的流程图;
图6是根据本发明实施例的应用流量感知方法的流程图;
图7是根据本发明实施例的应用流量感知方法的流程图;
图8是根据本发明实施例的应用流量感知系统的结构框图;
图9是根据本发明实施例的转义装置的结构框图;
图10是根据本发明实施例的解析模块的结构框图;
图11是根据本发明实施例的应用流量感知系统的结构框图;
图12是根据本发明场景实施例的应用流量感知网络框架的结构示意图;
图13是根据本发明场景实施例的转义装置的结构框图;
图14是根据本发明场景实施例的应用流量感知方法的流程图;
图15是根据本发明场景实施例的应用流量感知方法的流程图。
下文中将参考附图并结合实施例来详细说明本发明的实施例。
需要说明的是,本发明的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。
本申请实施例中所提供的方法实施例可以在移动终端、计算机终端或者类似的运算装置中执行。以运行在移动终端上为例,图1是本发明实施例的一种应用流量感知方法的移动终端的硬件结构框图。如图1所示,移动终端可以包括一个或多个(图1中仅示出一个)处理器102(处理器102可以包括但不限于微处理器MCU或可编程逻辑器件FPGA等的处理装置)和用于存储数据的存储器104,其中,上述移动终端还可以包括用于通信功能的传输设备106以及输入输出设备108。本领域普通技术人员可以理解,图1所示的结构仅为示意,其并不对上述移动终端的结构造成限定。例如,移动终端还可包括比图1中所示更多或者更少的组件,或者具有与图1所示不同的配置。
存储器104可用于存储计算机程序,例如,应用软件的软件程序以及模块,如本发明实施例中的应用流量感知方法对应的计算机程序,处理器102通过运行存储在存储器104内的计算机程序,从而执行各种功能应用以及数据处理,即实现上述的方法。存储器104可包括高速随机存储器,还可包括非易失性存储器,如一个或者多个磁性存储装置、闪存、或者其他非易失性固态存储器。在一些实例中,存储器104可进一步包括相对于处理器102远程设置的存储器,这些远程存储器可以通过网络连接至移动终端。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
传输装置106用于经由一个网络接收或者发送数据。上述的网络具体实例可包括移动终端的通信供应商提供的无线网络。在一个实例中,传输装置106包括一个网络适配器(Network Interface Controller,NIC),其可通过基站与其他网络设备相连从而可与互联网进行通讯。在一个实例中,传输装置106可以为射频(Radio Frequency,RF)模块,其用于通过无线方式与互联网进行通讯。
现有的应用感知网络的关键在于应用感知与流量导入。其中:应用感知指的是对接入应用进行流量识别和标识;流量导入是指将识别后的应用流量导入至满足其SLA需求的传输路径与管道。为了实现上述目标,现有的应用感知网络建模包括以下组件构成:
应用感知边缘节点:对Client接入的应用流进行识别,识别信息来源可以是数据报文封装的二层至四层头信息,或者是由应用APP直接在应用层封装的应用标识;根据识别结果将应用流量进行封装,提供给业务感知头节点进行下一步处理。
应用感知头节点:从应用感知边缘节点接收应用流量,并从中获取应用标识信息。通过其维护的应用标识与应用参数信息进行路径查找匹配,将流量导入到满足SLA需求的路径中。
应用感知中间节点:中间节点根据报文携带的应用标识信息,在本地应用一系列的流量或资源策略来保证应用的传输要求。
应用感知尾节点:传输路径在尾节点终结,如应用相关的标识在传输转发路径中以tunnel封装的形式携带,则在尾节点剥离该应用标识信息。
其中,应用感知边缘节点和头节点,在物理上可以合并部署于同一个实体内。但在以上建模的框架内,应用感知在网络的边缘结点进行,由于流量感知往往需要对报文进行深度解析,对设备硬件的分组处理能力具有很高的要求。而现有的传输网络设备通常并不具备这种深度报文解析的能力,仅支持简单的二层报文头识别和处理。
为了使得现有传输网络在不进行硬件升级的条件下具备向应用感知网络切换的能力,本发,发明提出了一种应用流量感知方法及系统,可以将复杂应用流量信息转义为简单报文二层信息,通过方法,可以使得传统传输网络与应用感知网络之间进行快速升级适配。
在本实施例中提供了一种运行于图1所示的移动终端的应用流量感知方法,图2是根据本发明实施例的应用流量感知方法的流程图,如图2所示,该流程包括如下步骤:
步骤S202,对从第一用户边缘设备(Customer Edge,CE)接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识;
步骤S204,根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;
步骤S206,将封装后的报文发送至第一提供商边缘设备(Provider Edge,PE),以便第一PE将报文导入到满足应用流量的服务等级协议(Service Level Agreement,SLA)的传输管道进行传输。
通过上述步骤,通过对从第一CE接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识;根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;将封装后的报文发送至第一PE,以便第一PE将报文导入到满足应用流量的SLA的传输管道进行传输,解决了相关技术中不能解析感知深度报文,仅支持简单的二层报文头识别和处理的问题,达到了传统传输网络与应用感知网络之间可以进行快速升级适配的效果。
其中,上述步骤的执行主体可以为基站、终端等,但不限于此。
在一个示例性实施例中,在对从第一CE接收的应用流量进行流量识别之前,还包括:建立应用流量与应用流编号匹配对应的解析控制表以及应用流量与转义封装信息匹配对应的封装控制表。图3是根据本发明实施例的应用流量感知方法的流程图,如图3所示,该流程包括如下步骤:
步骤S302,建立应用流量与应用流编号匹配对应的解析控制表以及应用流量与转义封装信息匹配对应的封装控制表;
步骤S304,对从第一CE接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识;
步骤S306,根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;
步骤S308,将封装后的报文发送至第一PE,以便第一PE将报文导入到满足应用流量的SLA的传输管道进行传输。
在一个示例性实施例中,对从第一用户边缘设备CE接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识,包括:识别获取应用流量的五元组信息和入端口信息,并根据五元组信息和入端口信息在解析控制表中查找匹配应用流编号,以完成对应用流量进行标识。
在一个示例性实施例中,根据应用流量的标识在应用流量的报文中增加以太网二层头信息,包括:根据应用流编号在封装控制表中查找匹配转义封装信息;根据转义封装信息为应用流量的报文中增加以太网二层头信息。图4是根据本发明实施例的应用流量封装的流程图,如图4所示,该流程包括如下步骤:
步骤S402,根据应用流编号在封装控制表中查找匹配转义封装信息;
步骤S404,根据转义封装信息为应用流量的报文中增加以太网二层头信息。
在一个示例性实施例中,将封装后的报文发送至第一PE之后,还包括:第一PE根据以太网二层头信息查找匹配传输管道;第一PE通过传输通道,将封装后的报文发送至第二PE。图5是根据本发明实施例的应用流量感知方法的流程图,如图5所示,该流程包括如下步骤:
步骤S502,建立应用流量与应用流编号匹配对应的解析控制表以及应用流量与转义封装信息匹配对应的封装控制表;
步骤S504,对从第一CE接收的应用流量进行流量识别,并根据识别结果对应用流量进行标识;
步骤S506,根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;
步骤S508,将封装后的报文发送至第一PE,以便第一PE将报文导入到满足应用流量的SLA的传输管道进行传输;
步骤S510,第一PE根据以太网二层头信息查找匹配传输管道;
步骤S512,第一PE通过传输通道,将封装后的报文发送至第二PE。
在一个示例性实施例中,第一PE将报文导入到满足应用流量的SLA的传输管道进行传输之后,还包括:根据以太网二层头信息反向查找匹配应用流编号;根据应用流编号剥离封装后的报文的以太网二层头信息;根据应用流编号反向查找匹配接收应用流量的第二CE的端口号;将应用流量通过端口号对应的端口发送至第二CE。图6是根据本发明实施例的应用流量感知方法的流程图,如图6所示,该流程包括如下步骤:
步骤S602,根据以太网二层头信息反向查找匹配应用流编号;
步骤S604,根据应用流编号剥离封装后的报文的以太网二层头信息;
步骤S606,根据应用流编号反向查找匹配接收应用流量的第二CE的端口号;
步骤S608,将应用流量通过端口号对应的端口发送至第二CE。
在一个示例性实施例中,将应用流量通过端口号对应的端口发送至第二CE之后,还包括:第二CE将接收的应用流量下发至用户设备。图7是根据本发明实施例的应用流量感知方法的流程图,如图7所示,该流程包括如下步骤:
步骤S702,根据以太网二层头信息反向查找匹配应用流编号;
步骤S704,根据应用流编号剥离封装后的报文的以太网二层头信息;
步骤S706,根据应用流编号反向查找匹配接收应用流量的第二CE的端口号;
步骤S708,将应用流量通过端口号对应的端口发送至第二CE;
步骤S710,第二CE将接收的应用流量下发至用户设备。
在一个示例性实施例中,二层头部报文包括以下至少之一:虚拟局域网信息VLAN或者多协议标签交换信息MPLS。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到根据上述实施例的方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端设备(可以是手机,计算机,服务器,或者网络设备等)执行本发明各个实施例所述的方法。
在本实施例中还提供了一种应用流量感知系统,该系统用于实现上述实施例及优选实施方式,已经进行过说明的不再赘述。如以下所使用的,术语“装置”、“模块”、“单元”可以实现预定功能的软件和/或硬件的组合。尽管以下实施例所描述的系统较佳地以软件来实现,但是硬件,或者软件和硬件的组合的实现也是可能并被构想的。
图8是根据本发明实施例的应用流量感知系统的结构框图,如图8所示,该应用流量感知系统80包括:转义装置810,设置为对从第一CE接收的应用流量依次进行识别、标识和封装,并将封装后的应用流量的报文发送至第一PE,以便第一PE将报文导入到满足应用流量的SLA的传输管道进行传输。
在一个示例性实施例中,图9是根据本发明实施例的转义装置的结构框图,如图9所示,转义装置810包括:解析模块910,设置为对应用流量进行流量识别,并根据识别结果对应用流量进行标识;封装模块920,设置为根据应用流量的标识在应用流量的报文中增加以太网二层头信息,以对应用流量的报文进行封装;发送模块930,设置为将封装后的报文发送至第一PE。
在一个示例性实施例中,图10是根据本发明实施例的解析模块的结构框图,如图10所示,解析模块910包括:识别单元1010,设置为识别获取应用流量的五元组信息和入端口信息;标识单元1020,设置为根据五元组信息和入端口信息在解析控制表中查找匹配所述应用流编号,以完成对应用流量进行标识。
在一个示例性实施例中,图11是根据本发明实施例的应用流量感知系统的结构框图,如图11所示,该应用流量感知系统110除了包括图8所示的装置外,还包括:管控中心1110,设置为建立应用流量与应用流编号匹配对应的解析控制表以及应用流量与转义封装信息匹配对应的封装控制表,并将解析控制表和封装控制表下发至转义装置。
在一个示例性实施例中,转义装置810还设置为,对封装后的报文进行反向识别、标识
以及剥离报文的以太网二层头信息,并将剥离以太网二层头信息的报文发送至第二CE。
其中,本领域的技术人员应该知道,转义装置的可以对应用流量进行识别、标识、封装,以及对封装后的报文进行反向识别、标识以及剥离,是根据应用流量可双向传输相对应匹配的。即在本次传输中当前的转义装置可能设置为对应用流量进行识别、标识、封装,在下一次传输中,当前的转义装置就可能设置为对封装后的报文进行反向识别、标识以及剥离。
需要说明的是,上述各个装置、模块、单元是可以通过软件或硬件来实现的,对于后者,可以通过以下方式实现,但不限于此:上述装置、模块、单元均位于同一处理器中;或者,上述各个装置、模块、单元以任意组合的形式分别位于不同的处理器中。
本发明的实施例还提供了一种计算机可读存储介质,该计算机可读存储介质中存储有计算机程序,其中,该计算机程序被设置为运行时执行上述任一项方法实施例中的步骤。
在一个示例性实施例中,上述计算机可读存储介质可以包括但不限于:U盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、移动硬盘、磁碟或者光盘等各种可以存储计算机程序的介质。
本发明的实施例还提供了一种电子装置,包括存储器和处理器,该存储器中存储有计算机程序,该处理器被设置为运行计算机程序以执行上述任一项方法实施例中的步骤。
在一个示例性实施例中,上述电子装置还可以包括传输设备以及输入输出设备,其中,该传输设备和上述处理器连接。该输入输出设备和上述处理器连接。
本实施例中的具体示例可以参考上述实施例及示例性实施方式中所描述的示例,本实施例在此不再赘述。
显然,本领域的技术人员应该明白,上述的本发明实施例的各装置、模块、单元或各步骤可以用通用的计算装置来实现,它们可以集中在单个的计算装置上,或者分布在多个计算装置所组成的网络上,它们可以用计算装置可执行的程序代码来实现,从而,可以将它们存储在存储装置中由计算装置来执行,并且在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤,或者将它们分别制作成各个集成电路模块,或者将它们中的多个模块或步骤制作成单个集成电路模块来实现。这样,本发明不限制于任何特定的硬件和软件结合。
为了使得本领域的技术人员更好地理解本发明的技术方案,下面结合具体的场景实施例进行阐述。
场景实施例一
图12是根据本发明场景实施例的应用流量感知网络框架的结构示意图,如图12所示,该网络框架包括:
CE设备:客户业务接入设备,用户应用流量通过CE设备汇聚后接入传输网络。具体包括CE1和CE2。
转义装置:设置为与CE设备对接导入用户应用流量。并根据接入报文的五元组信息(源IP,目的IP,协议类型,源TCP/UDP端口号,目的TCP/UDP端口号)和输入接口识别应用流量。承担应用感知边缘结点的角色。还设置为根据应用流量感知细分的结果对流量进行标识。还设置为根据流量标识结果,结合管控下发的流量标识转义结果,为相应应用流量增加额外的二层头信息,包括但不限于VLAN,MPLS label等标签(以下部分以VLAN为例描述)。完成应用流量的解析感知和转义。还设置为与传输网络PE设备对接,将转义后的报文从对应的出端口发送给PE设备。具体地,包括转义装置1和转义装置2。
PE设备:设置为与转义装置对接,通过解析匹配报文的VLAN等字段对流量进行识别和标识。还设置为接收管控平台下发的业务路径计算结果,将识别后的应用流量导入至满足SLA要求的路径。具体包括PE1和PE2。
管控中心:设置为收集维护传输网络拓扑与链路数据信息,必要时支持传输链路的动态建立与拆除。还设置为收集维护应用流量特征信息,以及应用流量相应的SLA需求(可以通过静态配置,或者通过控制协议扩展交互获取)。还设置为根据应用流量SLA要求对网络TE数据库进行策略匹配,获取满足应用SLA要求的业务路径,并将匹配结果下发传输网络设备。
为了实现上述转义装置的功能,本场景实施例提供了一种转义装置,图13是根据本发明场景实施例的转义装置的结构框图,如图13所示,该转义装置包括:
组件1:解析器。
解析器从接口P1-Pn接入用户应用流量并进行解析,根据解析将结果获取流量五元组信息(源IP,目的IP,协议类型,TCP/UDP源端口号,TCP/UDP目的端口号),结合流量输入的入端口号组成Key值查询解析控制表,根据解析控制表的返回应用流编号信息对相应的报文进行标记。
组件2:解析控制表。
该表用于存储报文五元组与应用流编号的映射关系,其中的内容由管控中心配置下发并供解析器查询。
解析控制表的具体结构如表1所示,其中,包括输入端口号、源IP(Source IP,SIP)、目的IP(Destination IP,目的IP)、协议类型、TCP/UDP源端口号、TCP/UDP目的端口号以及应用流编号。
表1:解析控制表
组件3:封装控制表。
1)该表项存储应用流量与出向封装的映射信息,其中流量识别信息为表项key值,转义后的流量识别信息以出接口加目标封装VLAN、MPLS label等方式存储。
2)流量识别的转义封装结果包括但不限于VLAN,MPLS label等信息。同时考虑到流量细分的粒度以及同一个接口上存在的应用流量数目,可以通过多层VLAN或者MPLS label堆叠的方式进行扩展,达到动态扩展流量转义容量规格的目的。
3)该表项由管控中心配置下发。
该封装控制表的具体结构如表2所示,其中,包括应用流编号、外层VLAN标识、内层
VLAN标识以及出端口号。
表2:封装控制表
组件4:封装器。
1)封装器用于对识别出的应用流量进行转义封装处理
2)封装器接收解析器输入的报文及其随路携带的应用流量标识。并使用应用流量标识作为key值对封装控制表进行匹配查询。
3)封装控制表向封装器返回匹配的封装信息,对相应的应用报文进行相应的封装处理,并从指定的出接口发出封装后的转义报文。
场景实施例二
根据场景实施例一提供的网络框架,在本场景实施例二提供了具体的应用流量感知方法的流程,图14是根据本发明场景实施例的应用流量感知方法的流程图,如图14所示,该流程包括以下步骤:
步骤1402,网络/应用信息收集;
1)管控中心收集:应用流量特征信息、传输网络拓扑信息、传输网络管道带宽、时延、抖动等相关信息。
2)对应用流量的转义规则和网络通道的路径关联进行统一计算,并下发解析控制表和封装控制表到转义装置;下发转义后的VLAN与传输软/硬管道映射关系至PE设备。
步骤1404,CE1将汇聚后的应用流量发送至转义装置1;
转义装置1中各组件工作流程如下所示:
1)组件1解析器:解析客户业务,获取流量五元组信息(源IP,目的IP,协议类型,源TCP/UDP端口号,目的TCP/UDP端口号)。结合入端口信息,根据管控下发的匹配规则查询解析控制表。
2)组件2解析器控制表:根据五元组信息查询解析控制表,向组件1返回应用流编号。
3)组件3封装控制表:根据应用流编号查询封装控制表,将查询到的转义封装信息返回给组件4
4)组件4封装器:根据组件3的返回结果对应用报文进行相应的转义封装处理,加上一层或两层VLAN信息,并通过指定的接口从本装置发出。
步骤1406,转义装置1将经过封装处理后的应用流量的报文发送给PE1;
步骤1408,PE1接收并解析转义装置1输入的报文,并发送至PE2;
PE1根据报文携带的转义VLAN信息,结合管控中心下发的路径计算结果,基于VLAN信息进行传输通道映射查找,并根据匹配结果将相应的应用流量导入到对应传输管道发送给远端的PE2设备。
步骤1410,PE2通过传输管道接收报文,并发送至转义装置2;
PE2根据管控下发的管道与用户侧接口的映射关系从相关接口发出给转义装置2
步骤1412,转义装置2从PE2接收应用流量,并发送至CE2;
转义装置2根据接入端口号与VLAN封装信息执行反向查表流程,获取到应用流编号后对报文进行VLAN剥离操作,并根据应用流编号反向查询CE对接端口号,从相关端口发送给CE2。
步骤1414,CE2接收流量转发给下挂的用户设备;
CE2接收流量转发给下挂的用户设备,完成端到端的流量感知与传输。
场景实施例三
本场景实施例三提供了基于VLAN转义方式为OTN传输网络提供应用感知的实施方案,图15是根据本发明场景实施例的应用流量感知方法的流程图,如图15所示,该流程包括以下步骤:
步骤1502,应用/网络信息收集与控制表项下发;
1)管控中心收集应用流量特性信息,同时计算转义VLAN的资源情况,进行对应流量的VLAN映射资源分配后下发转义装置与PE设备。2)管控中心收集应用流量的关联SLA信息。3)管控中心收集OTN网络的拓扑与传输管道信息(如ODUk,OSU管道信息)。4)根据三者进行应用流量传输路径计算;将VLAN与传输管道的映射关系下发PE设备。
步骤1504,应用流量感知与转义封装;
1)转义装置安装管控中心下发的控制表项。解析器从流量五元组信息(源IP,目的IP,协议类型,源TCP/UDP端口号,目的TCP/UDP端口号)中,结合流量输入的入端口信息,根据管控下发的匹配规则选取对应的字段生成应用流量编号值,应用流量编号值随报文携带输出给转义封装处理器。
2)如某企业用户,同时存在视频应用流量和数据传输应用流量并通过接入端口1接入转义装置,这两种应用流量的源IP一致,目的IP一致,但是协议类型与四层端口号信息不同。转义装置解析器查询表3所示的解析控制表命中规则1和规则2,分别得到应用流编号为123和234。
表3:场景实施例解析控制表
3)使用应用流编号通过查找表4所示的封装控制表,根据封装表返回结果分别将视频业务和数据传输业务带上外层VLAN标识(100,100)(100,200),并从出端口号1发出。
表4:场景实施例封装控制表
步骤1506,将应用流量导入传输通道进行传输;
PE设备从端口同时接收视频应用和数据应用流量,根据相应的VLAN标识(100,100)(100,200)进行识别。根据识别结果匹配管控下发的映射信息,将两种不同类型的应用流量分别导入到满足其SLA需求的不同ODU/OSU管道中进行传输。
步骤1508,应用流量反向剥离VLAN;
远端PE设备从ODU/OSU管道中终结对应的应用流量并发送给远端转义装置。远端转义装置根据报文的VLAN封装信息进行反向应用流编号查询并执行VLAN移除,恢复原有流量封装后从对应的端口发出给远端CE。之后,CE设备进行必要的解复用后发送给下挂的应用终端。完成端到端的应用感知与传输流程。
综上,本发明实施例提供了一种应用流量感知方法及系统,可以对应用流量进行深度解析、并将解析结果转义为简单二层封装信息的转换装置,同时提供了基于该系统的应用感知网络端到端实现方案。通过在传统传输网络(包括但不限于OTN网络)边缘部署该系统,网络已有设备仅通过识别简单的以太网报文二层头信息(包括但不限于VLAN),即可以达到具备应用感知能力的效果。解决了传统传输网络设备硬件不具备报文深度解析能力、无法进行精细流量管理的问题。通过该系统中的应用感知与信息转义装置即转义装置的按需部署和对接,可以便捷地将现有传统传输网络向应用感知网络进行升级,极大减少运营商的设备资金投入和网络改造开销。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
Claims (15)
- 一种应用流量感知方法,包括:对从第一用户边缘设备CE接收的应用流量进行流量识别,并根据所述识别结果对所述应用流量进行标识;根据所述应用流量的标识在所述应用流量的报文中增加以太网二层头信息,以对所述应用流量的报文进行封装;将封装后的所述报文发送至第一提供商边缘设备PE,以便所述第一PE将所述报文导入到满足所述应用流量的服务等级协议SLA的传输管道进行传输。
- 根据权利要求1所述的方法,其中,在所述对从第一用户边缘设备CE接收的应用流量进行流量识别之前,还包括:建立所述应用流量与应用流编号匹配对应的解析控制表以及所述应用流量与转义封装信息匹配对应的封装控制表。
- 根据权利要求2所述的方法,其中,所述对从第一用户边缘设备CE接收的应用流量进行流量识别,并根据所述识别结果对所述应用流量进行标识,包括:识别获取所述应用流量的五元组信息和入端口信息,并根据所述五元组信息和入端口信息在所述解析控制表中查找匹配所述应用流编号,以完成对所述应用流量进行标识。
- 根据权利要求2所述的方法,其中,所述根据应用流量的标识在所述应用流量的报文中增加以太网二层头信息,包括:根据所述应用流编号在所述封装控制表中查找匹配所述转义封装信息;根据所述转义封装信息为所述应用流量的报文中增加以太网二层头信息。
- 根据权利要求1所述的方法,其中,所述将封装后的所述报文发送至第一提供商边缘设备PE之后,还包括:所述第一PE根据所述以太网二层头信息查找匹配传输管道;所述第一PE通过所述传输通道,将封装后的所述报文发送至第二PE。
- 根据权利要求1所述的方法,其中,所述第一PE将所述报文导入到满足所述应用流量的服务等级协议SLA的传输管道进行传输之后,还包括:根据所述以太网二层头信息反向查找匹配所述应用流编号;根据所述应用流编号剥离封装后的所述报文的所述以太网二层头信息;根据所述应用流编号反向查找匹配接收所述应用流量的第二CE的端口号;将所述应用流量通过所述端口号对应的端口发送至所述第二CE。
- 根据权利要求6所述的方法,其中,所述将应用流量通过所述端口号对应的端口发送至所述第二CE之后,还包括:所述第二CE将接收的所述应用流量下发至用户设备。
- 根据权利要求1-7任一所述的方法,所述二层头部报文包括以下至少之一:虚拟局域网信息VLAN或者多协议标签交换信息MPLS。
- 一种应用流量感知系统,包括:转义装置,设置为对从第一用户边缘设备CE接收的应用流量依次进行识别、标识和封装,并将封装后的所述应用流量的报文发送至第一提供商边缘设备PE,以便所述第一PE将所述报文导入到满足所述应用流量的服务等级协议SLA的传输管道进行传输。
- 根据权利要求9应用流量感知系统,其中,所述转义装置包括:解析模块,设置为对所述应用流量进行流量识别,并根据所述识别结果对所述应用流量进行标识;封装模块,设置为根据所述应用流量的标识在所述应用流量的报文中增加以太网二层头信息,以对所述应用流量的报文进行封装;发送模块,设置为将封装后的所述报文发送至所述第一PE。
- 根据权利要求10应用流量感知系统,其中,所述解析模块包括:识别单元,设置为识别获取所述应用流量的五元组信息和入端口信息;标识单元,设置为根据所述五元组信息和入端口信息在所述解析控制表中查找匹配所述应用流编号,以完成对所述应用流量进行标识。
- 根据权利要求9所述的装置,还包括:管控中心,设置为建立所述应用流量与应用流编号匹配对应的解析控制表以及所述应用流量与转义封装信息匹配对应的封装控制表,并将所述解析控制表和所述封装控制表下发至所述转义装置。
- 根据权利要求9所述的装置,其中,所述转义装置还设置为,对封装后的所述报文进行反向识别、标识以及剥离所述报文的以太网二层头信息,并将剥离所述以太网二层头信息的所述报文发送至第二CE。
- 一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序,其中,所述计算机程序被处理器执行时实现所述权利要求1至8任一项中所述的方法。
- 一种电子装置,包括存储器、处理器以及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述处理器执行所述计算机程序时实现所述权利要求1至8任一项中所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202210920075.6A CN117544566A (zh) | 2022-08-01 | 2022-08-01 | 应用流量感知方法及系统 |
| CN202210920075.6 | 2022-08-01 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024027271A1 true WO2024027271A1 (zh) | 2024-02-08 |
Family
ID=89794460
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/093987 Ceased WO2024027271A1 (zh) | 2022-08-01 | 2023-05-12 | 应用流量感知方法及系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN117544566A (zh) |
| WO (1) | WO2024027271A1 (zh) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110166361A (zh) * | 2019-05-30 | 2019-08-23 | 新华三技术有限公司 | 一种报文转发方法及装置 |
| WO2020125651A1 (zh) * | 2018-12-17 | 2020-06-25 | 中兴通讯股份有限公司 | 标签属性识别方法、装置、设备及存储介质 |
| CN114765567A (zh) * | 2021-01-11 | 2022-07-19 | 中国电信股份有限公司 | 通信方法和通信系统 |
| CN114827057A (zh) * | 2021-01-11 | 2022-07-29 | 中国电信股份有限公司 | 通信方法以及通信系统 |
-
2022
- 2022-08-01 CN CN202210920075.6A patent/CN117544566A/zh active Pending
-
2023
- 2023-05-12 WO PCT/CN2023/093987 patent/WO2024027271A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020125651A1 (zh) * | 2018-12-17 | 2020-06-25 | 中兴通讯股份有限公司 | 标签属性识别方法、装置、设备及存储介质 |
| CN110166361A (zh) * | 2019-05-30 | 2019-08-23 | 新华三技术有限公司 | 一种报文转发方法及装置 |
| CN114765567A (zh) * | 2021-01-11 | 2022-07-19 | 中国电信股份有限公司 | 通信方法和通信系统 |
| CN114827057A (zh) * | 2021-01-11 | 2022-07-29 | 中国电信股份有限公司 | 通信方法以及通信系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN117544566A (zh) | 2024-02-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10880214B2 (en) | Service routing packet processing method and apparatus, and network system | |
| CN102301663B (zh) | 一种报文处理方法及相关设备 | |
| US10404605B2 (en) | Packet processing method, device and computer storage medium | |
| US11627070B2 (en) | Data packet processing method and apparatus, storage medium, and electronic device | |
| CN106911778A (zh) | 一种流量引导方法和系统 | |
| CN115334589B (zh) | 报文传输方法、装置、相关设备及存储介质 | |
| CN107426077A (zh) | 用于实现物理网络和虚拟网络互通的方法和设备 | |
| EP4191966B1 (en) | Method and system for processing data message and storage medium | |
| WO2021017930A1 (zh) | 报文转发 | |
| WO2018121257A1 (zh) | 报文发送方法、装置、系统以及存储介质 | |
| CN104253878B (zh) | Dhcp relay终结子接口的vlan信息管理系统及方法 | |
| US10531168B2 (en) | Low-latency data switching device and method | |
| CN117376233A (zh) | 数据处理方法、装置及系统 | |
| CN115242713A (zh) | 基于ipv6的分段路由报文的转发方法、配置方法及设备 | |
| CN103748842B (zh) | 一种转发数据包的方法、装置和路由设备 | |
| CN103379187B (zh) | 一种数据处理方法及网关网元 | |
| CN111865805B (zh) | 一种组播gre报文处理方法及系统 | |
| CN104219160A (zh) | 生成输入参数的方法及设备 | |
| WO2020114083A1 (zh) | 一种ioam信息的处理方法和装置 | |
| CN113852917B (zh) | 一种基于组播的下行数据包寻址方法及系统 | |
| CN109218176B (zh) | 一种报文处理的方法及装置 | |
| WO2024027271A1 (zh) | 应用流量感知方法及系统 | |
| CN103460675B (zh) | 集群以及转发方法 | |
| US20200044953A1 (en) | Data Packet Fast Routing Method | |
| WO2024002101A1 (zh) | 报文传输方法、装置、相关设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23848981 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 23848981 Country of ref document: EP Kind code of ref document: A1 |