WO2025001981A1 - 接入控制方法、装置、计算机可读介质及电子设备 - Google Patents
接入控制方法、装置、计算机可读介质及电子设备 Download PDFInfo
- Publication number
- WO2025001981A1 WO2025001981A1 PCT/CN2024/100535 CN2024100535W WO2025001981A1 WO 2025001981 A1 WO2025001981 A1 WO 2025001981A1 CN 2024100535 W CN2024100535 W CN 2024100535W WO 2025001981 A1 WO2025001981 A1 WO 2025001981A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- access
- tunnel
- access device
- configuration information
- gateway
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/08—Access restriction or access information delivery, e.g. discovery data delivery
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4633—Interconnection of networks using encapsulation techniques, e.g. tunneling
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W48/00—Access restriction; Network selection; Access point selection
- H04W48/18—Selecting a network or a communication service
Definitions
- the present application relates to the field of computer and communication technology, and in particular to an access control method, device, computer-readable medium and electronic device.
- VPC Virtual Private Cloud
- cloud uses subnets to logically isolate resources to provide users with an isolated network environment, flexible and definable subnet segments, and supports adding new defined segments to existing VPCs at any time to ensure an inexhaustible supply of IP addresses and resolve the limitation on the number of nodes brought by traditional subnets.
- cloud users can use VPN and other methods to connect to local data centers and smoothly migrate their businesses to the cloud.
- the embodiments of the present application provide an access control method, device, computer-readable medium and electronic device, which can reduce the dependence on traditional dedicated line networks when accessing private networks and effectively improve the network access speed.
- An embodiment of the present application provides an access control method, comprising: obtaining device information of an access device, and obtaining information of a private network to be accessed by the access device; sending a tunnel creation instruction to an access gateway corresponding to the private network according to the information of the private network, so as to instruct the access gateway to establish a transmission tunnel with the access device; generating configuration information for the access device, the configuration information being used to instruct the access device to establish a transmission tunnel with the access gateway; in response to detecting that the access device is online, sending the configuration information to the access device, so that the access device establishes a transmission tunnel with the access gateway according to the configuration information, and accesses the private network based on the established transmission tunnel.
- the embodiment of the present application also provides an access control device, comprising: an acquisition unit, configured to acquire device information of an access device and acquire information of a private network to be accessed by the access device; a sending unit, configured to The invention relates to a method for transmitting the transmission tunnel between the access device and the access gateway of the private network through the information of the private network, so as to instruct the access gateway to establish a transmission tunnel with the access device; a generating unit is configured to generate configuration information for the access device, wherein the configuration information is used to instruct the access device to establish a transmission tunnel with the access gateway; and a processing unit is configured to send the configuration information to the access device in response to detecting that the access device is online, so that the access device establishes a transmission tunnel with the access gateway according to the configuration information, and accesses the private network based on the established transmission tunnel.
- An embodiment of the present application further provides a computer-readable medium on which a computer program is stored.
- the computer program is executed by a processor, the access control method as described in the above embodiment is implemented.
- An embodiment of the present application also provides an electronic device, comprising: one or more processors; a storage device for storing one or more computer programs, wherein when the one or more computer programs are executed by the one or more processors, the electronic device implements the access control method as described in the above embodiment.
- the present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium.
- a processor of an electronic device reads and executes the computer program from the computer-readable storage medium, so that the electronic device executes the access control method provided in the above various optional embodiments.
- FIG1 is a schematic diagram showing an exemplary system architecture to which the technical solution of an embodiment of the present application can be applied;
- FIG2 shows a flow chart of an access control method according to an embodiment of the present application
- FIG3 is a schematic diagram showing an exemplary system architecture to which the access control solution of the embodiment of the present application can be applied;
- FIG4 is a schematic diagram showing an exemplary system architecture to which the access control solution of the embodiment of the present application can be applied;
- FIG5 is a schematic diagram showing a connection relationship between a CPE and an access gateway according to an embodiment of the present application
- FIG6 is a schematic diagram showing an exemplary system architecture to which the access control solution of the embodiment of the present application can be applied;
- FIG7 is a schematic diagram showing a connection relationship between a UPF and an access gateway according to an embodiment of the present application
- FIG8 is a schematic diagram showing a connection relationship between an access gateway and a dedicated line gateway according to an embodiment of the present application
- FIG9 shows an interactive flow chart of an access control method according to an embodiment of the present application.
- FIG10 is a schematic diagram showing a cloud network controller processing a heartbeat message according to an embodiment of the present application
- FIG11 shows an interactive flow chart of an access control method according to an embodiment of the present application
- FIG12 shows a block diagram of an access control device according to an embodiment of the present application.
- FIG. 13 shows a schematic diagram of the structure of a computer system of an electronic device suitable for implementing an embodiment of the present application.
- cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and network within a wide area network or a local area network to achieve data calculation, storage, processing, and sharing.
- Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model. It can form a resource pool and be used on demand, which is flexible and convenient.
- the backend services of the cloud technology network system require a large amount of computing and storage resources, such as video websites, image websites and more portal websites.
- each item may have its own identification mark, which needs to be transmitted to the backend system for logical processing. Data of different levels will be processed separately, and all kinds of industry data will need to be processed separately. Strong system backing support can only be achieved through cloud computing.
- cloud users want to connect local IDC (Internet Data Center) or network equipment with VPC (Virtual Private Cloud, also known as proprietary network) in the cloud and enjoy low latency, high bandwidth, and secure network quality, they can only access the nearest POP (Point-of-Presence) point of the local operator through the operator's dedicated line, and then connect to the cloud VPC through the operator's dedicated line.
- POP Point-of-Presence
- the embodiment of the present application proposes a new network access control solution, which can enable the network access party to access the private network by issuing tunnel creation instructions and configuration information through a control device (hereinafter referred to as "controller"), thereby reducing the dependence on the traditional dedicated network when accessing the private network.
- controller a control device
- the access device after the access device is online, it can automatically access the private network according to the configuration information, effectively improving the network access speed.
- the system architecture includes a controller 101, a network access party 102, a mobile network core network element 103, a private network 106, and an access gateway (GateWay, GW for short) 104 and a forwarding device 105 corresponding to the private network 106.
- At least one access device 1021 is deployed in the network access party 102.
- the controller 101 may be a server, which may be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
- the access device 1021 may be a local CPE (Customer premises equipment) or a terminal device that can access the network, such as a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a vehicle terminal, an aircraft, etc., but is not limited thereto.
- the controller 101 may obtain the device information of the access device 1021 provided by the network access party 102, and obtain the information of the private network that the network access party 102 requests to access (i.e., the private network to be accessed by the access device 1021).
- the device information of the access device 1021 may be, for example, a unique identifier of the device, a network address of the device, port information of the device, etc.; the information of the private network may be, for example, identification information, network address information, port information, etc. of the private network.
- the controller 101 after acquiring the information of the private network that the network access party 102 requests to access, the controller 101 sends a tunnel creation instruction to the access gateway 104 corresponding to the private network according to the information of the private network. To instruct the access gateway 104 to establish a transmission tunnel with the access device 1021. At the same time, the controller 101 can generate configuration information for the access device 1021, and the configuration information is used to instruct the access device 1021 to establish a transmission tunnel with the access gateway 104.
- the controller 101 can send the configuration information to the access device 1021, so that the access device 1021 establishes a transmission tunnel with the access gateway 104 according to the configuration information, and accesses the private network based on the established transmission tunnel.
- the controller 101 can send a Generic Routing Encapsulation (GRE) tunnel establishment instruction to the access gateway 104 and the core network element 103 to instruct the core network element 103 to establish a GRE tunnel with the access gateway 104; and the transmission tunnel established between the access device 1021 and the access gateway 104 can be carried on the GRE tunnel.
- GRE Generic Routing Encapsulation
- the controller 101 can also send a tunnel creation instruction to the access gateway 104 and the forwarding device 105 connected between the access gateway 104 and the private network to instruct the access gateway 104 to establish a transmission tunnel with the forwarding device 105.
- the transmission tunnel between the access gateway 104 and the forwarding device 105 is used to transmit the traffic of the access device 1021 to the forwarding device 105, so that the forwarding device 105 routes the traffic of the access device 1021 to the private network.
- the transmission tunnel established between the access device 1021 and the access gateway 104 may be an IPSec (Internet Protocol Security) tunnel.
- IPSec Internet Protocol Security
- the access gateway 104 and the forwarding device 105 may be deployed inside the network provider, there is no need for encrypted transmission, so the IPSec tunnel may be decapsulated on the access gateway 104, and then the user traffic may be transferred to a more lightweight VXLAN (Virtual Extensible Local Area Network) tunnel, that is, the transmission tunnel between the access gateway 104 and the forwarding device 105 may be a VXLAN tunnel.
- VXLAN Virtual Extensible Local Area Network
- the core network element 103 may be a UPF (User Plane Function), which is an important part of the 3GPP 5G core network system architecture and is mainly responsible for the routing and forwarding related functions of user plane data packets in the 5G core network.
- the forwarding device 105 may be a NGW (Next Generation Gateway), which is mainly used in scenarios such as hybrid cloud dedicated line access, inter-domain interconnection, and public cloud interconnection to achieve high-performance forwarding, support multi-tenant access, support TGRE (Tunnel-GRE), VXLAN tunnel protocol, etc., and also support features such as fragmentation, reassembly, and speed limit.
- NGW Next Generation Gateway
- the access device can access the private network by sending tunnel creation instructions and configuration information through the controller 101, reducing the dependence on the traditional dedicated network when accessing the private network.
- the access device can automatically access the private network according to the configuration information, effectively improving the network access speed.
- FIG2 shows a flow chart of an access control method according to some embodiments of the present application, and the access control method may be executed by a controller, and the controller may be the controller 101 shown in FIG1.
- the access control method at least includes S210 to S230, which are described in detail as follows:
- S210 device information of an access device provided by a network access party is obtained, and information of a private network to which the network access party requests to access is obtained.
- the network access party may send the device information of the access device and the information of the private network requested to be accessed to the controller through a configuration interface or a console.
- the network access party may be a lessee of the private network, and the access device may be a CPE or a terminal device capable of accessing the network.
- the device information of the access device 1021 may be, for example, a unique identifier of the device, a network address of the device, and port information of the device; the information of the private network may be, for example, identification information, network address information, and port information of the private network.
- a tunnel creation instruction is sent to an access gateway corresponding to the private network according to information of the private network that the network access party requests to access, so as to instruct the access gateway to establish a transmission tunnel with the access device.
- the transmission tunnel between the access gateway and the access device may be an IPSec tunnel, so that the data of the access device can be guaranteed to be secure during transmission to the access gateway.
- the controller may obtain a tunnel encryption key provided by the network access party to the access device, and then add the tunnel encryption key to the tunnel creation instruction, so that an encrypted transmission tunnel is established between the access device and the access network gateway based on the tunnel encryption key.
- the process of the controller sending a tunnel creation instruction to the access gateway corresponding to the private network can specifically be executing the following processes in sequence: sending VRF (Virtual Routing Forwarding) creation information to the access gateway, sending IPSec tunnel creation information to the access gateway, sending interface IP creation information to the access gateway, configuring IKE (a hybrid encryption protocol) encryption information to the access gateway, configuring BGP (Border Gateway Protocol) information to the access gateway, etc.
- VRF Virtual Routing Forwarding
- IPSec tunnel creation information to the access gateway
- interface IP creation information to the access gateway
- IKE a hybrid encryption protocol
- BGP Border Gateway Protocol
- configuration information for the access device is generated, where the configuration information is used to instruct the access device to establish a transmission tunnel with the access gateway.
- the configuration information for the access device may include: creation of IPSec tunnel information, creation of interface IP information, and configuration of IKE encryption information.
- the configuration information may be stored in a database.
- S220 and S230 shown in FIG. 2 is not specifically limited.
- S220 may be executed first and then S230 according to the order shown in FIG. 2; or S230 may be executed first and then S230.
- S220 is executed; S220 and S230 may also be executed simultaneously.
- configuration information is sent to the access device, so that the access device establishes a transmission tunnel with the access gateway according to the configuration information and accesses the private network based on the established transmission tunnel.
- the access device after the access device goes online, it can periodically send a heartbeat message to the controller, and the controller can determine that the access device is online when receiving the heartbeat message sent by the access device. In this way, after the access device goes online, the controller can directly send the configuration information to the access device, and then the access device can automatically establish a transmission tunnel with the access gateway. In addition, after receiving the configuration information, the access device can also store the configuration information locally.
- the heartbeat message periodically sent by the access device after it goes online may also include the last startup time of the access device. Then the controller can obtain the last startup time of the access device from the heartbeat message sent by the access device, or obtain the last startup time recorded for the access device from the database; if the last startup time contained in the heartbeat message is inconsistent with the last startup time recorded in the database, it means that the access device has been restarted, and the current configuration information stored in the access device can be obtained. In response to the current configuration information of the access device not matching the configuration information for the access device stored in the database, the configuration information stored in the database can be sent to the access device.
- the technical solution of this embodiment enables the controller to promptly send the configuration information for the access device stored in the database to the access device after the access device is restarted or when the locally stored configuration information is lost, so as to ensure that the access device can obtain the latest configuration information and establish a transmission tunnel with the access gateway based on the latest configuration information.
- the process in which the controller sends the configuration information for the access device stored in the database to the access device may specifically be: searching for configuration information that is different from the current configuration information in the configuration information for the access device stored in the database, and then sending the found configuration information that is different to the access device.
- the technical solution of this embodiment enables only the difference configuration information to be sent to the access device, which can reduce the bandwidth and transmission time occupied by sending the configuration information compared to sending the complete configuration information to the access device, thereby ensuring that the access device can obtain the latest configuration information as soon as possible.
- the controller can update the last startup time recorded for the access device in the database according to the last startup time contained in the heartbeat message, so as to subsequently determine whether the access device has been restarted based on the updated last startup time in the database.
- the private network may correspond to at least two access gateways
- the controller may send configuration information to the access device to instruct the access device to establish transmission tunnels with at least two access gateways respectively, and instruct the access device to configure the transmission tunnel established between the access device and at least two access gateways as equal-cost multipath routing.
- ECMP Equal Cost Multi-path
- the transmission tunnel between the access device and the access network element may be established by the access device through the core network element and the access gateway.
- the controller may send a GRE tunnel establishment instruction to the access gateway and the core network element to instruct the core network element to establish a GRE tunnel with the access gateway.
- the transmission tunnel between the access device and the access gateway may be carried on the GRE tunnel. For example, if the transmission tunnel between the access device and the access gateway is an IPSec tunnel, then in the transmission tunnel established between the access device and the access gateway, the transmission tunnel between the core network element and the access gateway is an IPSec over GRE tunnel.
- the private network may correspond to at least two access gateways.
- the controller may send a GRE tunnel establishment instruction to at least two access gateways and at least two core network elements to instruct each core network element to establish a GRE tunnel with at least two access gateways respectively, and instruct each core network element to configure the GRE tunnel established between the core network element and at least two access gateways as an equal-cost multipath routing mode.
- the technical solution of this embodiment makes it possible to efficiently utilize the forwarding capabilities between the access gateway and the core network element, and can also ensure the reliability and stability of network transmission through ECMP when some core network elements or some access gateways are abnormal.
- a forwarding device may be connected between the access gateway and the private network.
- the forwarding device may be a gateway device, for example, the forwarding device may be an NGW device. After receiving the user traffic forwarded by the access gateway, the forwarding device may forward the user traffic to the private network.
- the controller can send tunnel creation instructions to the access gateway and the forwarding device connected between the access gateway and the private network to instruct the establishment of a transmission tunnel between the access gateway and the forwarding device.
- the transmission tunnel between the access gateway and the forwarding device is used to transmit the traffic of the access device to the forwarding device, so that the forwarding device routes the traffic of the access device to the private network.
- the private network may correspond to at least two access gateways and at least two forwarding devices
- the controller may send a tunnel creation instruction to the at least two access gateways and at least two forwarding devices to instruct each access gateway to establish a transmission tunnel with the at least two forwarding devices, and instruct each access gateway to configure the transmission tunnel established between the access gateway and the at least two forwarding devices as an equal-cost multipath routing.
- the transmission tunnel between the access gateway and the forwarding device can be a lightweight VXLAN tunnel. If the transmission tunnel between the access device and the access gateway is an IPSec tunnel, the access gateway can decapsulate the IPSec tunnel and then transfer the user traffic to the VXLAN tunnel, which is then routed to the forwarding device and transmitted to the private network by the forwarding device.
- a tunnel creation instruction is sent to the access gateway corresponding to the private network according to the information of the private network to be accessed by the access device, so as to instruct the access gateway to establish a transmission tunnel between the access device and the access device; at the same time, configuration information for the access device is generated, and after detecting that the access device is online, the configuration information is sent to the access device, so that the access device establishes a transmission tunnel with the access gateway according to the configuration information, and accesses the private network based on the established transmission tunnel, so that the access device can access the private network by sending the tunnel creation instruction and configuration information (controller), thereby reducing the dependence on the traditional dedicated line network when accessing the private network, and at the same time, after the access device is online, it can automatically access the private network according to the configuration information, effectively improving the network access speed.
- the cloud network controller is used to implement the functions of the controller described in the aforementioned embodiment.
- the user side can be a user who rents a private network VPC, that is, the network access party in the aforementioned embodiment
- the UPF is the core network element in the aforementioned embodiment
- the dedicated line gateway is the forwarding device in the aforementioned embodiment.
- the technical solution of the embodiment shown in FIG3 mainly adopts the design idea of separation of forwarding and control in NFV (Network Functions Virtualization), which is divided into a cloud network controller deployed on the cloud and the lower-layer network equipment.
- the cloud network controller is responsible for the management and control of the equipment, configuration distribution, status detection, etc.
- the network equipment includes the mobile CPE for accessing the network on the user side; base stations, UPF, etc. on the operator side; access gateways, dedicated line gateways, etc. on the cloud provider side.
- the user side when the CPE device on the user side accesses the network, the user side can connect its own CPE device (or the private IDC room mounted under the CPE) to the network closest to the user side, such as a mobile network, specifically a 4G or 5G network, etc.
- the UPF on the operator side and the access gateway on the cloud provider side can be connected via a dedicated line.
- an IPSec tunnel can be used between the user CPE device and the access gateway.
- the encrypted tunnel directly passes through the operator network to reach the access gateway, making the operator's public network and intranet links unaware of the tunnel, thereby ensuring the security of user data to the greatest extent.
- two (or more) dual-active access gateways may be deployed for network reliability.
- the two access gateways work simultaneously, each carrying a portion of the network traffic. When any one fails, the other can take over all service traffic without switching.
- the user CPE can IPSec tunnels are established with both gateways, and ECMP is configured on the CPE to make the two IPSec tunnels equally routed.
- the tunnel establishment and fault link switching process are all completed automatically by the network equipment, and users are completely unaware of it, which can provide users with a good experience.
- the operator in the connection between the cloud provider and the operator network, the operator usually provides a universal GRE tunnel for network encapsulation to distinguish its different users.
- One end of the GRE tunnel is the operator's UPF, and the other end is the cloud vendor's access gateway.
- the GRE tunnel is used to carry the IPSec tunnel established by the user's CPE.
- the GRE tunnel of the underlying network underlay
- the IPSec tunnel established by the user's CPE will be automatically loaded onto the GRE tunnel when passing through the UFP, that is, the gateway on the cloud is accessed in the form of IPSec over GRE.
- operators usually provide more than two UPFs (hereinafter, two are used as an example) as access.
- a full mesh GRE tunnel can be established between the two UPFs and the two access gateways through the cloud network controller, and the two tunnels on each device are ECMP.
- This can efficiently utilize the forwarding capabilities of network devices and ensure high reliability and stability of the network under abnormal circumstances. For example, if a UPF device is unavailable, due to the characteristics of ECMP scheduling, the traffic will be forwarded through another UPF. When the abnormal device is back online, the distribution of traffic will also be automatically restored. The same is true for the access gateway. As long as there is at least one UPF and access gateway left in the network, the user's traffic will not be affected, which improves the availability of link quality.
- VXLAN tunnel can be used between the access gateway and the dedicated gateway.
- the VNI VXLAN Network Identifier
- the VXLAN tunnel is very suitable for dividing tenants when cloud providers access. Since the network traffic has already entered the cloud provider, it does not need to be encrypted for transmission, so the IPSec tunnel can be decapsulated on the access gateway to transfer the user traffic to the lighter VXLAN tunnel.
- a cloud provider can provide more than two access gateways and dedicated line gateways (hereinafter, two gateways are used as an example) as access.
- two gateways are used as an example
- a VXLAN tunnel can be established between the two access gateways and the two dedicated line gateways through the cloud network controller, and the two tunnels on each device are ECMP. This can efficiently utilize the forwarding capabilities of network devices and ensure high reliability and stability of the network under abnormal circumstances.
- the cloud network controller when a user purchases a CPE device, can configure a tunnel to connect the CPE device to the cloud provider, and then the cloud network controller orchestrates the network tunnel instructions to the devices at both ends, and the CPE device can complete the access. Specifically, as shown in Figure 9, the following steps are included:
- S901 After purchasing a CPE device, the user activates the CPE cloud access function through the cloud network controller and configures the encryption key. key.
- the cloud network controller starts to orchestrate the IPSec tunnel for the CPE to access, and then prepares to send instructions for creating the tunnel to the CPE and the access gateway.
- the cloud network controller executes S903a to S903e, that is, sends VRF creation information, IPSec tunnel creation information, interface IP creation information, IKE encryption configuration information, BGP configuration information, etc. to the access gateway in sequence.
- the cloud network controller executes S904a to S904c, that is, sends IPSec tunnel creation information, interface IP creation information, IKE encryption configuration information, etc. to the CPE in sequence.
- the CPE can automatically connect to the access gateway to connect the local IDC and the VPC network on the cloud.
- the instructions arranged by the cloud network controller may not be sent to the CPE at any time (for example, the CPE may not be turned on). After the user configures the cloud network controller, he expects the CPE to automatically access the private network once it goes online, which requires the cloud network controller to provide CPE status detection and configuration re-issuance functions.
- each CPE can have a record in the database table of the cloud network controller, as shown in Table 1, which can record the identification information and configuration information of the CPE, and also store the last startup time of the CPE. After the CPE goes online, it can periodically report heartbeat information to the cloud network controller, and the message body carries the last startup time of the CPE.
- the cloud network controller When the cloud network controller receives the heartbeat message reported by the CPE, it checks whether the last startup time in the heartbeat message is consistent with the last startup time stored in the database. If there is an update, it means that the CPE has been restarted. There may be new configuration information during the CPE restart, or the CPE may fail and cause the locally stored configuration information to be lost. Therefore, the cloud network controller will perform a configuration check on the CPE when it determines that the CPE has been restarted. For example, the cloud network controller can obtain the current configuration information of the CPE through the management interface of the CPE, and then compare it with the configuration information in the database, and send the difference configuration information to the CPE.
- the cloud network controller will complete the configuration information for it when the CPE is powered on and automatically connected, and then the CPE will automatically establish an encrypted tunnel with the cloud provider's private network. The user is unaware of this process.
- the cloud network controller will automatically verify the configuration information of the CPE.
- the cloud network controller also needs to update the last startup time stored in the database in a timely manner. As shown in Figure 10, the CPE periodically reports heartbeat messages to the cloud network controller, and then the cloud network controller updates the information stored in the database accordingly, such as the last startup time.
- the embodiment of the present application adopts the idea of separation of control and transmission, that is, various configuration information is arranged and issued by the cloud network controller, and the underlying network devices do not need to care about the business, but only need to provide a standard control interface and configure the network according to the arrangement instructions of the cloud network controller.
- a schematic processing flow is shown in Figure 11, which includes the following steps:
- the cloud network controller sends configuration information to the UPF and the access gateway.
- the operator's UPF is connected to the cloud provider's access gateway through the cloud network controller, that is, a GRE tunnel is established between the UPF and the access gateway.
- the controller sends configuration information to the access gateway and the dedicated line gateway to configure a VXLAN tunnel between the access gateway and the dedicated line gateway to open up the connection between the access gateway and the dedicated line gateway.
- S1104 The controller allocates exclusive IPSec tunnel resources to the user, and allocates and configures them to the CPE and the access gateway to open up the connection between the CPE and the access gateway.
- users can access the VPC on the cloud through CPE using the mobile network.
- the user CPE can quickly and efficiently access the cloud VPC, making full use of the low latency and high bandwidth characteristics of the 4G/5G network, replacing the reliance on traditional dedicated lines when accessing dedicated gateways in some implementation methods.
- the cloud network controller can also automatically restore it. By building a full mesh network tunnel through multiple cloud network devices that serve as the primary and backup for each other, a more reliable connection service is provided, bringing users a network quality that is no less than that of a dedicated line connection.
- FIG12 shows a block diagram of an access control device according to some embodiments of the present application, and the access control device may be provided in a controller.
- an access control device 1200 includes: an acquiring unit 1202 , a sending unit 1204 , a generating unit 1206 and a processing unit 1208 .
- the acquisition unit 1202 is configured to acquire device information of the access device and acquire the device information to be connected to the access device.
- the sending unit 1204 is configured to send a tunnel creation instruction to the access gateway corresponding to the private network according to the information of the private network, so as to instruct the access gateway to establish a transmission tunnel with the access device;
- the generating unit 1206 is configured to generate configuration information for the access device, and the configuration information is used to instruct the access device to establish a transmission tunnel with the access gateway;
- the processing unit 1208 is configured to send the configuration information to the access device in response to detecting that the access device is online, so that the access device establishes a transmission tunnel with the access gateway according to the configuration information, and accesses the private network based on the established transmission tunnel.
- the access control device 1200 also includes: a receiving unit, configured to receive a heartbeat message periodically sent by the access device after it goes online, the heartbeat message containing the last startup time of the access device; the acquisition unit 1202 is also configured to: obtain the last startup time recorded for the access device from a database; if the last startup time contained in the heartbeat message is inconsistent with the last startup time recorded in the database, obtain the current configuration information in the access device; the sending unit 1204 is also configured to: in response to the current configuration information not matching the configuration information for the access device stored in the database, send the configuration information for the access device stored in the database to the access device.
- a receiving unit configured to receive a heartbeat message periodically sent by the access device after it goes online, the heartbeat message containing the last startup time of the access device
- the acquisition unit 1202 is also configured to: obtain the last startup time recorded for the access device from a database; if the last startup time contained in the heartbeat message is inconsistent with the last startup time recorded in the database, obtain the current configuration information in the access device
- the computer system 1300 may include a central processing unit (CPU) 1301, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1302 or a program loaded from a storage part 1308 to a random access memory (RAM) 1303, such as performing the method described in the above embodiment.
- CPU central processing unit
- RAM random access memory
- Various programs and data required for system operation are also stored in RAM 1303.
- CPU 1301, ROM 1302, and RAM 1303 are connected to each other via a bus 1304.
- An input/output (I/O) interface 1305 is also connected to the bus 1304.
- the following components can be connected to the I/O interface 1305: an input section 1306 including a keyboard, a mouse, etc.; an output section 1307 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker; a storage section 1308 including a hard disk, etc.; and a communication section 1309 including a network interface card such as a LAN (Local Area Network) card, a modem, etc.
- the communication section 1309 performs communication processing via a network such as the Internet.
- a driver 1310 is also connected to the I/O interface 1305 as needed. interface 1305.
- a removable medium 1311 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, or the like, is mounted on the drive 1310 as needed, so that a computer program read therefrom is installed into the storage section 1308 as needed.
- an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program is used to perform the method shown in the flowchart.
- the computer program can be downloaded and installed from a network through a communication section 1309, and/or installed from a removable medium 1311.
- CPU central processing unit
- the computer-readable medium shown in the embodiment of the present application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two.
- the computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above.
- Computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
- a computer-readable storage medium may be any tangible medium containing or storing a computer program, which may be used by or in combination with an instruction execution system, device or device.
- a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above.
- Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which may send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, apparatus, or device.
- the computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
- Each box in the flowchart or block diagram may represent a module, a program segment, or a portion of a code, and the above module, program segment, or a portion of a code contains one or more executable instructions for implementing the specified logical functions.
- the functions marked in the boxes may also occur in an order different from that marked in the accompanying drawings. For example, two consecutive representations of The blocks in the flowchart can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved.
- each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer programs.
- the units involved in the embodiments described in this application may be implemented by software or hardware, and the units described may also be set in a processor.
- the names of these units do not, in some cases, constitute limitations on the units themselves.
- the present application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiment; or may exist independently without being assembled into the electronic device.
- the above computer-readable medium carries one or more computer programs, and when the above one or more computer programs are executed by an electronic device, the electronic device implements the method described in the above embodiment.
- the technical solution according to the implementation methods of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable an electronic device to execute the method according to the implementation methods of the present application.
- a non-volatile storage medium which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.
- the electronic device may be a controller, and the controller may execute the access control method shown in FIG. 2 .
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
一种接入控制方法、装置、计算机可读介质及电子设备。该接入控制方法包括:获取接入设备的设备信息,并获取网络接入方请求接入的专有网络的信息;向专有网络对应的接入网关发送隧道创建指令,以指示接入网关建立与接入设备之间的传输隧道;生成针对接入设备的配置信息,所述配置信息用于指示接入设备建立与所述接入网关之间的传输隧道;若检测到所述接入设备上线,则将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
Description
本申请要求于2023年06月29日提交中国专利局、申请号为202310793815.9,发明名称为“接入控制方法、装置、计算机可读介质及电子设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及计算机及通信技术领域,具体而言,涉及一种接入控制方法、装置、计算机可读介质及电子设备。
虚拟私有云(Virtual Private Cloud)是云用户在云上申请的隔离的、私密的虚拟网络环境。VPC通过子网将资源进行逻辑隔离为用户提供隔离的网络环境、灵活的可定义子网网段,并支持随时在现有VPC中追加新的定义网段,保证IP地址取之不尽,解决传统子网带来的节点数量的限制,同时云用户可以使用VPN等方式连接本地数据中心后将业务平滑迁移到云端。
技术内容
本申请的实施例提供了一种接入控制方法、装置、计算机可读介质及电子设备,可以降低接入专有网络时对传统专线网络的依赖,有效提高了网络接入速度。
本申请的其他特性和优点将通过下面的详细描述变得显然,或部分地通过本申请的实践而习得。
本申请实施例提供了一种接入控制方法,包括:获取接入设备的设备信息,并获取所述接入设备待接入的专有网络的信息;根据所述专有网络的信息向所述专有网络对应的接入网关发送隧道创建指令,以指示所述接入网关建立与所述接入设备之间的传输隧道;生成针对所述接入设备的配置信息,所述配置信息用于指示所述接入设备建立与所述接入网关之间的传输隧道;响应于检测到所述接入设备上线,则将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
本申请实施例还提供了一种接入控制装置,包括:获取单元,配置为获取接入设备的设备信息,并获取所述接入设备待接入的专有网络的信息;发送单元,配置为根据所
述专有网络的信息向所述专有网络对应的接入网关发送隧道创建指令,以指示所述接入网关建立与所述接入设备之间的传输隧道;生成单元,配置为生成针对所述接入设备的配置信息,所述配置信息用于指示所述接入设备建立与所述接入网关之间的传输隧道;处理单元,配置为响应于检测到所述接入设备上线,则将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
本申请实施例还提供了一种计算机可读介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现如上述实施例中所述的接入控制方法。
本申请实施例还提供了一种电子设备,包括:一个或多个处理器;存储装置,用于存储一个或多个计算机程序,当所述一个或多个计算机程序被所述一个或多个处理器执行时,使得所述电子设备实现如上述实施例中所述的接入控制方法。
本申请实施例还提供了一种计算机程序产品,该计算机程序产品包括计算机程序,该计算机程序存储在计算机可读存储介质中。电子设备的处理器从计算机可读存储介质读取并执行该计算机程序,使得该电子设备执行上述各种可选实施例中提供的接入控制方法。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本申请。
附图简要说明
图1示出了可以应用本申请实施例的技术方案的示例性系统架构的示意图;
图2示出了根据本申请实施例的接入控制方法的流程图;
图3示出了可以应用本申请实施例的接入控制方案的示例性系统架构的示意图;
图4示出了可以应用本申请实施例的接入控制方案的示例性系统架构的示意图;
图5示出了根据本申请实施例的CPE与接入网关之间的连接关系示意图;
图6示出了可以应用本申请实施例的接入控制方案的示例性系统架构的示意图;
图7示出了根据本申请实施例的UPF与接入网关之间的连接关系示意图;
图8示出了根据本申请实施例的接入网关与专线网关之间的连接关系示意图;
图9示出了根据本申请实施例的接入控制方法的交互流程图;
图10示出了根据本申请实施例的云网络控制器根据心跳消息进行处理的示意图;
图11示出了根据本申请实施例的接入控制方法的交互流程图;
图12示出了根据本申请实施例的接入控制装置的框图;
图13示出了适于用来实现本申请实施例的电子设备的计算机系统的结构示意图。
现在参考附图以更全面的方式描述示例实施方式。然而,示例的实施方式能够以各种形式实施,且不应被理解为仅限于这些范例;相反,提供这些实施方式的目的是使得本申请更加全面和完整,并将示例实施方式的构思全面地传达给本领域的技术人员。
此外,本申请所描述的特征、结构或特性可以以任何合适的方式结合在一个或更多实施例中。在下面的描述中,有许多具体细节从而可以充分理解本申请的实施例。然而,本领域技术人员应意识到,在实施本申请的技术方案时可以不需用到实施例中的所有细节特征,可以省略一个或更多特定细节,或者可以采用其它的方法、元件、装置、步骤等。
附图中所示的方框图仅仅是功能实体,不一定必须与物理上独立的实体相对应。即,可以采用软件形式来实现这些功能实体,或在一个或多个硬件模块或集成电路中实现这些功能实体,或在不同网络和/或处理器装置和/或微控制器装置中实现这些功能实体。
附图中所示的流程图仅是示例性说明,不是必须包括所有的内容和操作/步骤,也不是必须按所描述的顺序执行。例如,有的操作/步骤还可以分解,而有的操作/步骤可以合并或部分合并,因此实际执行的顺序有可能根据实际情况改变。
需要说明的是:在本文中提及的“多个”是指两个或两个以上。“和/或”描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。字符“/”一般表示前后关联对象是一种“或”的关系。
本申请实施例的技术方案涉及到云技术(Cloud technology)领域,其中,云技术是指在广域网或局域网内将硬件、软件、网络等系列资源统一起来,实现数据的计算、储存、处理和共享的一种托管技术。
云技术是基于云计算商业模式应用的网络技术、信息技术、整合技术、管理平台技术、应用技术等的总称,可以组成资源池,按需所用,灵活便利。云技术网络系统的后台服务需要大量的计算、存储资源,如视频网站、图片类网站和更多的门户网站。伴随着互联网行业的高度发展和应用,将来每个物品都有可能存在自己的识别标志,都需要传输到后台系统进行逻辑处理,不同程度级别的数据将会分开处理,各类行业数据皆需
要强大的系统后盾支撑,只能通过云计算来实现。
在一些实施方法中,云用户如果想将本地IDC(Internet Data Center,互联网数据中心)或网络设备与云端的VPC(Virtual Private Cloud,虚拟私有云,也称为专有网络)打通,且享有低时延、高带宽、安全的网络质量,只能通过运营商开通专线的方式接入本地运营商最近的POP(Point-of-Presence,入网点)点,然后通过运营商专线连接至云VPC。这种方式不仅成本高,而且专线开通时间受运营商施工影响,同时对于经常移动或需要多地点部署的用户来讲非常不方便。
本申请实施例提出了一种新的网络接入控制方案,可以通过控制设备(下文用“控制器”表示)下发隧道创建指令及配置信息的方式实现网络接入方对专有网络的接入,降低了接入专有网络时对传统专线网络的依赖,同时使得在接入设备上线之后,可以自动根据配置信息接入专有网络,有效提高了网络接入速度。
具体地,在本申请的一个具体应用场景中,如图1所示,系统架构包括控制器101、网络接入方102、移动网络核心网网元103、专有网络106,以及对应于专有网络106的接入网关(GateWay,简称GW)104和转发设备105,网络接入方102内部署有至少一个接入设备1021。
在一些实施例中,控制器101可以是服务器,该服务器可以是独立的物理服务器,也可以是多个物理服务器构成的服务器集群或者分布式系统,还可以是提供云服务、云数据库、云计算、云函数、云存储、网络服务、云通信、中间件服务、域名服务、安全服务、CDN(Content Delivery Network,内容分发网络)、以及大数据和人工智能平台等基础云计算服务的云服务器。接入设备1021可以是本地CPE(Customer premises equipment,用户驻地设备)或者能够接入网络的终端设备等,终端设备比如可以是智能手机、平板电脑、笔记本电脑、台式计算机、智能音箱、智能手表、车载终端、飞行器等,但并不局限于此。
在本申请的一些实施例中,控制器101可以获取网络接入方102提供的接入设备1021的设备信息,并获取网络接入方102请求接入的专有网络(即接入设备1021待接入的专有网络)的信息。接入设备1021的设备信息比如可以是设备唯一标识、设备的网络地址、设备的端口信息等;专有网络的信息比如可以是专有网络的标识信息、网络地址信息、端口信息等。
在本申请的一些实施例中,控制器101在获取网络接入方102请求接入的专有网络的信息之后,根据专有网络的信息向专有网络对应的接入网关104发送隧道创建指令,
以指示接入网关104建立与接入设备1021之间的传输隧道。同时,控制器101可以生成针对接入设备1021的配置信息,该配置信息用于指示接入设备1021建立与接入网关104之间的传输隧道,进而控制器101在检测到接入设备1021上线之后,可以将该配置信息发送给接入设备1021,以使接入设备1021根据该配置信息与接入网关104建立传输隧道,并基于建立的传输隧道接入专有网络。
在一些实施例中,由于接入设备1021与接入网关104之间的传输隧道是通过移动网络核心网网元103建立的,因此控制器101可以向接入网关104和核心网网元103发送通用路由封装(Generic Routing Encapsulation,简称GRE)隧道建立指令,以指示核心网网元103与接入网关104建立GRE隧道;而接入设备1021与接入网关104之间建立的传输隧道可以承载在GRE隧道之上。
在一些实施例中,控制器101还可以向接入网关104,以及连接在接入网关104和专有网络之间的转发设备105发送隧道创建指令,以指示接入网关104与转发设备105之间建立传输隧道,接入网关104与转发设备105之间的传输隧道用于将接入设备1021的流量传输至转发设备105,以使转发设备105将接入设备1021的流量路由至专有网络。
在一些实施例中,为了保证数据的安全性,接入设备1021与接入网关104之间建立的传输隧道可以是IPSec(Internet Protocol Security,互联网安全协议)隧道。在一些实施例中,由于接入网关104与转发设备105可以是部署在网络提供方内部的,因此不需要进行加密传输,所以在接入网关104上可以解封装IPSec隧道,然后将用户流量转入更为轻量的VXLAN(Virtual Extensible Local Area Network,虚拟扩展局域网)隧道中,即接入网关104与转发设备105之间的传输隧道可以是VXLAN隧道。
在一些实施例中,核心网网元103可以是UPF(User Plane Function,用户面功能),UPF是3GPP 5G核心网系统架构的重要组成部分,主要负责5G核心网中用户平面数据包的路由和转发相关功能。转发设备105可以是NGW(Next Generation GateWay,下一代网关),主要用于混合云专线接入、域间互通、公有云互通等场景,实现高性能转发,支持多租户接入,支持TGRE(Tunnel-GRE)、VXLAN隧道协议等,同时支持分片、重组、限速等特性。
在图1所示的系统架构中,通过控制器101下发隧道创建指令及配置信息的方式就可以实现接入设备对专有网络的接入,降低了接入专有网络时对传统专线网络的依赖,同时使得在接入设备上线之后,可以自动根据配置信息接入专有网络,有效提高了网络接入速度。
以下对本申请实施例的技术方案的实现细节进行详细阐述:
图2示出了根据本申请的一些实施例的接入控制方法的流程图,该接入控制方法可以由控制器来执行,该控制器可以是图1中所示的控制器101。参照图2所示,该接入控制方法至少包括S210至S230,详细介绍如下:
在S210中,获取网络接入方提供的接入设备的设备信息,并获取网络接入方请求接入的专有网络的信息。
在一些实施例中,网络接入方可以通过配置接口或者控制台等向控制器发送接入设备的设备信息,以及请求接入的专有网络的信息。网络接入方可以是专有网络的租用方,接入设备可以是CPE或者能够接入网络的终端设备等。接入设备1021的设备信息比如可以是设备唯一标识、设备的网络地址、设备的端口信息等;专有网络的信息比如可以是专有网络的标识信息、网络地址信息、端口信息等。
在S220中,根据网络接入方请求接入的专有网络的信息向专有网络对应的接入网关发送隧道创建指令,以指示该接入网关建立与接入设备之间的传输隧道。
在一些实施例中,接入网关与接入设备之间的传输隧道可以是IPSec隧道,这样使得接入设备的数据在传输至接入网关的过程中,能够保证数据的安全性。在这种情况下,控制器可以获取网络接入方针对接入设备提供的隧道加密密钥,然后在隧道创建指令中添加该隧道加密密钥,以使接入设备与接入网网关之间基于隧道加密密钥建立加密传输隧道。
在一些实施例中,控制器向专有网络对应的接入网关发送隧道创建指令的过程具体可以是依次执行以下过程:向接入网关发送创建VRF(Virtual Routing Forwarding,虚拟路由转发)信息、向接入网关发送创建IPSec隧道信息、向接入网关发送创建接口IP信息、向接入网关配置IKE(一种混合型加密协议)加密信息、向接入网关配置BGP(Border Gateway Protocol,边界网关协议)信息等。
在S230中,生成针对接入设备的配置信息,该配置信息用于指示接入设备建立与接入网关之间的传输隧道。
在一些实施例中,针对接入设备的配置信息可以包括:创建IPSec隧道信息、创建接口IP信息、配置的IKE加密信息。控制器生成针对节加入设备的配置信息之后,可以将该配置信息存储到数据库中。
需要说明的是,图2中所示的S220与S230之间的执行顺序并不做具体限定,比如可以按照图2中所示的顺序先执行S220,再执行S230;或者也可以先执行S230,再执
行S220;也可以同时执行S220与S230。
在S240中,响应于检测到接入设备上线,则将配置信息发送给接入设备,以使接入设备根据配置信息与接入网关建立传输隧道,并基于建立的传输隧道接入专有网络。
在一些实施例中,接入设备在上线后可以向控制器周期性地发送心跳消息,那么控制器可以在接收到接入设备发送的心跳消息时,确定检测到接入设备上线。这样使得接入设备在上线之后,控制器就可以直接将配置信息发送给接入设备,进而接入设备可以自动与接入网关建立传输隧道。另外,接入设备接收到配置信息后,还可以在本地存储该配置信息。
在一些实施例中,接入设备上线后周期性发送的心跳消息中还可以包含有接入设备的上一次启动时间,那么控制器可以从接入设备发送的心跳消息中获取到接入设备的上一次启动时间,也可以从数据库中获取针对接入设备记录的上一次启动时间;如果心跳消息中包含的上一次启动时间与数据库中记录的上一次启动时间不一致,则说明接入设备发生了重启,那么可以获取接入设备中存储的当前配置信息。响应于接入设备的当前配置信息与数据库中存储的针对接入设备的配置信息不匹配,则可以将数据库中存储的配置信息发送给接入设备。该实施例的技术方案使得接入设备在重启后或者在本地存储的配置信息丢失的情况下,控制器可以及时将数据库中存储的针对接入设备的配置信息下发给接入设备,以保证接入设备能够获取到最新的配置信息,并基于最新的配置信息与接入网关建立传输隧道。
在一些实施例中,控制器将数据库中存储的针对接入设备的配置信息发送给接入设备的过程具体可以是:在数据库中存储的针对接入设备的配置信息中查找与当前配置信息存在差异的配置信息,然后将查找到的存在差异的配置信息发送给接入设备。该实施例的技术方案使得可以仅向接入设备发送差异配置信息,相较于向接入设备发送完整配置信息,可以减少发送配置信息所占用的带宽和传输时间,进而确保接入设备能够尽快获取到最新的配置信息。
在一些实施例中,控制器在将差异配置信息发送给接入设备之后,可以根据心跳消息中包含的上一次启动时间,对数据库中针对接入设备记录的上一次启动时间进行更新,以便于后续根据数据库中更新后的上一次启动时间来确定接入设备是否发生了重启。
在一些实施例中,专有网络可以对应有至少两个接入网关,那么控制器可以将配置信息发送给接入设备,以指示接入设备分别与至少两个接入网关建立传输隧道,并指示接入设备将接入设备与至少两个接入网关之间建立的传输隧道配置为等价多径路由
(Equal Cost Multi-path,简称ECMP)的方式,进而可以在任一接入网关出现故障时,能够通过其它接入网关无缝实现业务流量的接替,保证了业务流量传输的持续性与稳定性。
在一些实施例中,接入设备与接入网元之间的传输隧道可以是接入设备通过核心网网元与接入网关建立的,在这种情况下,控制器可以向接入网关和核心网网元发送GRE隧道建立指令,以指示核心网网元与接入网关建立GRE隧道;在这种情况下,接入设备与接入网关之间的传输隧道可以承载在GRE隧道之上。比如,接入设备与接入网关之间的传输隧道为IPSec隧道,那么在接入设备与接入网关之间建立的传输隧道中,核心网网元与接入网关之间的传输隧道为IPSec over GRE隧道。
在一些实施例中,专有网络可以对应有至少两个接入网关,在这种情况下,控制器可以向至少两个接入网关和至少两个核心网网元发送GRE隧道建立指令,以指示每个核心网网元分别与至少两个接入网关建立GRE隧道,并指示每个核心网网元将该核心网网元与至少两个接入网关之间建立的GRE隧道配置为等价多径路由的方式。该实施例的技术方案使得可以高效利用接入网关和核心网网元之间的转发能力,并且也可以在部分核心网网元或者部分接入网关出现异常中,通过ECMP来保证网络传输的可靠性和稳定性。
在一些实施例中,接入网关与专有网络之间可以连接有转发设备,转发设备可以是网关设备,比如转发设备可以是NGW设备,转发设备可以在接收到接入网关转发过来的用户流量之后,将用户流量转发到专有网络中。
在一些实施例中,控制器可以向接入网关,以及连接在接入网关和专有网络之间的转发设备发送隧道创建指令,以指示接入网关与转发设备之间建立传输隧道,接入网关与转发设备之间的传输隧道用于将接入设备的流量传输至转发设备,以使转发设备将接入设备的流量路由至专有网络。
在一些实施例中,专有网络可以对应于至少两个接入网关和至少两个转发设备,那么控制器可以向至少两个接入网关和至少两个转发设备发送隧道创建指令,以指示每个接入网关分别与至少两个转发设备之间建立传输隧道,并指示每个接入网关将该接入网关与至少两个转发设备之间建立的传输隧道配置为等价多径路由的方式。该实施例的技术方案使得可以高效利用接入网关和转发设备之间的转发能力,并且也可以在部分转发设备或者部分接入网关出现异常中,通过ECMP来保证网络传输的可靠性和稳定性。
在一些实施例中,由于接入网关与转发设备是在网络提供方内部,因此不需要进行加密传输,故接入网关与转发设备之间的传输隧道可以是轻量级的VXLAN隧道。如果接
入设备与接入网关之间的传输隧道是IPSec隧道,那么接入网关可以解封装IPSec隧道,然后将用户流量转入VXLAN隧道中,进而路由至转发设备,由转发设备传输给专有网络。
本申请上述实施例的技术方案中通过根据接入设备待接入的专有网络的信息向专有网络对应的接入网关发送隧道创建指令,以指示该接入网关建立与接入设备之间的传输隧道;同时生成针对接入设备的配置信息,以在检测到接入设备上线之后,将该配置信息发送给接入设备,以使接入设备根据该配置信息与接入网关建立传输隧道,并基于建立的传输隧道接入专有网络,使得可以通过(控制器)下发隧道创建指令及配置信息的方式就可以实现接入设备对专有网络的接入,降低了接入专有网络时对传统专线网络的依赖,同时使得在接入设备上线之后,可以自动根据配置信息接入专有网络,有效提高了网络接入速度。
以下结合图3至图11,以具体的应用场景对本申请实施例的网络接入方案再次进行详细说明:
在图3所示的应用场景中,云网络控制器用于实现前述实施例中所述的控制器的功能。其中,用户侧可以是租用专有网络VPC的用户,也即前述实施例中的网络接入方、UPF即为前述实施例中的核心网网元、专线网关即为前述实施例中的转发设备。图3所示实施例的技术方案主要采用NFV(Network Functions Virtualization,网络功能虚拟化)中转控分离的设计思路,分为云上部署的云网络控制器和下层的网络设备。云网络控制器负责对设备的管控、配置下发、状态检测等,网络设备包括用户侧的用于接入网络的移动CPE;运营商侧的基站、UPF等;云提供商侧的接入网关、专线网关等。
基于图3所示的应用场景,当用户侧的CPE设备接入网络时,用户侧可以将自己的CPE设备(或CPE下面挂载的私有IDC机房)接入离用户侧最近的网络,比如可以是移动网络,具体可以是4G或5G网络等。运营商侧的UPF与云提供商侧的接入网关之间可以通过专线连接。
由于空口网络是承载在公网之上,所以用户数据需要考虑加密性,因此如图4所示,可以在用户CPE设备与接入网关之间可以采用IPSec隧道方式,加密隧道直接穿过运营商网络抵达接入网关,使运营商公网和内网链路感知不到隧道,能够最大程度保证用户数据的安全性。
在一些实施例中,在云提供商网络中,为了网络的可靠性,可能会部署两台(或多台)双主模式的接入网关。两台接入网关同时工作,各自负载一部分的网络流量,任何一台出现故障时,另一台无需切换即可承接所有业务流量。如图5所示,用户CPE可以
与两台接网关都建立IPSec隧道,且在CPE上配置ECMP使两条IPSec隧道等价路由。隧道建立和故障链路切换的过程都是网络设备自动完成的,用户完全不感知,能够给用户提供良好的体验。
在一些实施例中,如图6所示,在云提供商与运营商网络的连接中,运营商通常会提供通用的GRE隧道来进行网络封装,用于区分其不同的用户。GRE隧道的一端是运营商的UPF,另一端是云厂商的接入网关,GRE隧道用来承载用户CPE建立的IPSec隧道。此时,底层网络(underlay)的GRE隧道对于用户是不可见的,用户CPE所建立的IPSec隧道在通过UFP时会自动负载到GRE隧道上,即IPSec over GRE的形式接入云上的网关。
在一些实施例中,如图7所示,运营商通常会提供2台以上的UPF(以下以2台为例进行说明)作为接入,此时可以通过云网络控制器对两台UPF和两台接入网关之间都建立全互联模式(full mesh)的GRE隧道,且在各自的设备上两条隧道为ECMP。这样可以高效的利用网络设备的转发能力,也能在异常情况下保证网络的高可靠性和稳定性。比如一台UPF设备不可用,由于ECMP调度的特性,流量会经由另一台UPF转发,当异常设备恢复上线后,流量的分发也会自动恢复。接入网关也是同理,只要网络中至少还剩一台UPF和接入网关,用户的流量就不会受损,提高了链路质量的可用性。
在一些实施例中,当用户流量到达接入网关后,需要经由专线网关到达VPC。在接入网关和专线网关之间可以采用VXLAN隧道,VXLAN的VNI(VXLAN Network Identifier,VXLAN网络标识符)有24个bit,最多可支持1600w+的用户接入,远多于VLAN(Virtual Local Area Network,虚拟局域网)的12bit,因此VXLAN隧道十分适合云提供商接入时划分租户。又由于网络流量已经进入到云提供商内部,因此无需加密传输,故在接入网关上即可解封装IPSec隧道,将用户流量转入更为轻量的VXLAN隧道中。
在一些实施例中,如图8所示,云提供商可以提供2台以上的接入网关和专线网关(以下以2台为例进行说明)作为接入,此时可以通过云网络控制器对两台接入网关和两台专线网关之间都建立VXLAN隧道,且在各自的设备上的两条隧道为ECMP。这样可以高效的利用网络设备的转发能力,也能在异常情况下保证网络的高可靠性和稳定性。
在本申请的一些实施例中,当用户购入一台CPE设备时,通过云网络控制器能够配置隧道将CPE设备接入云提供商,然后由云网络控制器编排网络隧道指令配置到两端设备上,CPE设备即可完成接入。具体如图9所示,包括以下步骤:
S901,用户购入CPE设备后,通过云网络控制器开通CPE入云功能,并配置加密密
钥。
S902,云网络控制器开始编排该CPE接入的IPSec隧道,然后准备向CPE和接入网关发送创建隧道的指令。
之后,云网络控制器执行S903a至S903e,即向接入网关依次发送创建VRF信息、创建IPSec隧道信息、创建接口IP信息,以及配置IKE加密信息、配置BGP信息等。然后,云网络控制器执行S904a至S904c,即向CPE依次发送创建IPSec隧道信息、创建接口IP信息,以及配置IKE加密信息等。
当CPE和接入网关都配置完毕后,CPE即可自动接入到接入网关,打通本地IDC与云上VPC网络。
在本申请的一些实施例中,由于用户CPE处于自己的网络环境中,不像接入网关作为服务器部署,因此云网络控制器编排的指令并不一定随时都能发送到CPE上(比如CPE可能未开机)。而用户通过云网络控制器配置之后期望CPE一旦上线即可自动接入专有网络,这就需要云网络控制器能够提供CPE状态检测和配置重下发功能。
可选地,每一台CPE在云网络控制器的数据库表中都可以存有一条记录,如表1所示,可以记录CPE的标识信息、配置信息,此外还额外存储了CPE的上一次启动时间。当CPE上线之后,可以周期性向云网络控制器上报心跳信息,消息体中携带CPE的上一次启动时间。
表1
云网络控制器收到CPE上报的心跳消息时,会检查心跳消息中的上一次启动时间是否与数据库中存储的上一次启动时间一致,如果有更新说明CPE发生过重启。在CPE重启期间有可能有新的配置信息,也有可能CPE发生故障导致本地存储的配置信息丢失,因此云网络控制器会在确定CPE发生过重启时对CPE进行配置核查。比如,云网络控制器可以通过CPE的管理接口获取CPE的当前配置信息,然后与数据库中的配置信息进行比较,并将差异配置信息下发到CPE上。这样对于新购买的设备,用户通过云网络控制器进行初次配置后,云网络控制器会在CPE上电自动接入时为它补齐配置信息,然后CPE就会自动与云提供商的专有网络建立加密隧道,这个过程用户无感知。而在CPE使用期间,任何时候的断电重启或意外宕机,云网络控制器都会自动对CPE的配置信息进行核
查修复。同时,云网络控制器也需要及时更新数据库中存储的上一次启动时间,如图10所示,CPE周期性上报心跳消息给云网络控制器,然后云网络控制器据此更新数据库中存储的信息,比如上一次启动时间等。
基于前述的系统架构和相关的配置,本申请实施例中采用了转控分离的思想,即各种配置信息都是通过云网络控制器进行编排下发的,底层的网络设备无需关心业务,只需提供标准的控制接口,按照云网络控制器的编排指令配置网络即可。一个示意的处理流程如图11所示,包括如下步骤:
S1101,初始化时,云网络控制器向UPF和接入网关发送配置信息,具体是通过云网络控制器将运营商的UPF与云提供商的接入网关打通,即在UPF与接入网关之间建立GRE隧道。
S1102,当用户需要使用专有网络时,通过云控制台向云网络控制器配置自身的CPE希望接入的VPC网络。
S1103,控制器通过下发配置信息至接入网关和专线网关,以在接入网关与专线网关之间配置VXLAN隧道,来打通接入网关与专线网关之间的连接。
S1104,控制器为该用户分配专属的IPSec隧道资源,分配配置到CPE和接入网关上,以打通CPE与接入网关之间的连接。
在完成上述配置之后,用户即可通过CPE使用移动网络的方式接入到云上VPC中。
可见,在本申请的实施例中,用户CPE可以快速高效接入云VPC,充分利用了4G/5G网络的低时延、高带宽特性,取代了一些实施方法中接入专有网关时对于传统专线的依赖。同时,通过云网络控制器,用户只需简单的配置即可让CPE设备自动接入专有网络,对于设备离线、异常宕机等场景,云网络控制器也能自动为其恢复。通过多台互为主备的云上网络设备,构建full mesh的网络隧道,提供可靠性更高的连接服务,给用户带来不亚于专线连接的网络质量。
以下介绍本申请的装置实施例,可以用于执行本申请上述实施例中的接入控制方法。对于本申请装置实施例中未披露的细节,请参照本申请上述的接入控制方法的实施例。
图12示出了根据本申请的一些实施例的接入控制装置的框图,该接入控制装置可以设置在控制器内。
参照图12所示,根据本申请的一些实施例的接入控制装置1200,包括:获取单元1202、发送单元1204、生成单元1206和处理单元1208。
其中,获取单元1202配置为获取接入设备的设备信息,并获取所述接入设备待接
入的专有网络的信息;发送单元1204配置为根据所述专有网络的信息向所述专有网络对应的接入网关发送隧道创建指令,以指示所述接入网关建立与所述接入设备之间的传输隧道;生成单元1206配置为生成针对所述接入设备的配置信息,所述配置信息用于指示所述接入设备建立与所述接入网关之间的传输隧道;处理单元1208配置为响应于检测到所述接入设备上线,则将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
在本申请的一些实施例中,基于前述方案,所述接入控制装置1200还包括:接收单元,配置为接收所述接入设备上线后周期性发送的心跳消息,所述心跳消息中包含有所述接入设备的上一次启动时间;所述获取单元1202还配置为:从数据库中获取针对所述接入设备记录的上一次启动时间;若所述心跳消息中包含的上一次启动时间与所述数据库中记录的上一次启动时间不一致,则获取所述接入设备中的当前配置信息;所述发送单元1204还配置为:响应于所述当前配置信息与所述数据库中存储的针对所述接入设备的配置信息不匹配,则将所述数据库中存储的针对所述接入设备的配置信息发送给所述接入设备。
图13示出了适于用来实现本申请实施例的电子设备的计算机系统的结构示意图,该电子设备可以是前述实施例中的控制器。
需要说明的是,图13示出的电子设备的计算机系统1300仅是一个示例,不应对本申请实施例的功能和使用范围带来任何限制。
如图13所示,计算机系统1300可以包括中央处理单元(Central Processing Unit,CPU)1301,其可以根据存储在只读存储器(Read-Only Memory,ROM)1302中的程序或者从存储部分1308加载到随机访问存储器(Random Access Memory,RAM)1303中的程序而执行各种适当的动作和处理,例如执行上述实施例中所述的方法。在RAM 1303中,还存储有系统操作所需的各种程序和数据。CPU 1301、ROM 1302以及RAM 1303通过总线1304彼此相连。输入/输出(Input/Output,I/O)接口1305也连接至总线1304。
以下部件可以连接至I/O接口1305:包括键盘、鼠标等的输入部分1306;包括诸如阴极射线管(Cathode Ray Tube,CRT)、液晶显示器(Liquid Crystal Display,LCD)等以及扬声器等的输出部分1307;包括硬盘等的存储部分1308;以及包括诸如LAN(Local Area Network,局域网)卡、调制解调器等的网络接口卡的通信部分1309。通信部分1309经由诸如因特网的网络执行通信处理。驱动器1310也根据需要连接至I/O
接口1305。可拆卸介质1311,诸如磁盘、光盘、磁光盘、半导体存储器等等,根据需要安装在驱动器1310上,以便于从其上读出的计算机程序根据需要被安装入存储部分1308。
特别地,根据本申请的实施例,上文参考流程图描述的过程可以被实现为计算机软件程序。例如,本申请的实施例包括一种计算机程序产品,其包括承载在计算机可读介质上的计算机程序,该计算机程序用于执行流程图所示的方法。在这样的实施例中,该计算机程序可以通过通信部分1309从网络上被下载和安装,和/或从可拆卸介质1311被安装。在该计算机程序被中央处理单元(CPU)1301执行时,执行本申请的系统中限定的各种功能。
需要说明的是,本申请实施例所示的计算机可读介质可以是计算机可读信号介质或者计算机可读存储介质或者是上述两者的任意组合。计算机可读存储介质例如可以是——但不限于——电、磁、光、电磁、红外线、或半导体的系统、装置或器件,或者任意以上的组合。计算机可读存储介质的更具体的例子可以包括但不限于:具有一个或多个导线的电连接、便携式计算机磁盘、硬盘、随机访问存储器(RAM)、只读存储器(ROM)、可擦式可编程只读存储器(Erasable Programmable Read Only Memory,EPROM)、闪存、光纤、便携式紧凑磁盘只读存储器(Compact Disc Read-Only Memory,CD-ROM)、光存储器件、磁存储器件、或者上述的任意合适的组合。在本申请中,计算机可读存储介质可以是任何包含或存储计算机程序的有形介质,该计算机程序可以被指令执行系统、装置或者器件使用或者与其结合使用。而在本申请中,计算机可读的信号介质可以包括在基带中或者作为载波一部分传播的数据信号,其中承载了计算机可读的计算机程序。这种传播的数据信号可以采用多种形式,包括但不限于电磁信号、光信号或上述的任意合适的组合。计算机可读的信号介质还可以是计算机可读存储介质以外的任何计算机可读介质,该计算机可读介质可以发送、传播或者传输用于由指令执行系统、装置或者器件使用或者与其结合使用的程序。计算机可读介质上包含的计算机程序可以用任何适当的介质传输,包括但不限于:无线、有线等等,或者上述的任意合适的组合。
附图中的流程图和框图,图示了按照本申请各种实施例的系统、方法和计算机程序产品的可能实现的体系架构、功能和操作。其中,流程图或框图中的每个方框可以代表一个模块、程序段、或代码的一部分,上述模块、程序段、或代码的一部分包含一个或多个用于实现规定的逻辑功能的可执行指令。也应当注意,在有些作为替换的实现中,方框中所标注的功能也可以以不同于附图中所标注的顺序发生。例如,两个接连地表示
的方框实际上可以基本并行地执行,它们有时也可以按相反的顺序执行,这依所涉及的功能而定。也要注意的是,框图或流程图中的每个方框、以及框图或流程图中的方框的组合,可以用执行规定的功能或操作的专用的基于硬件的系统来实现,或者可以用专用硬件与计算机程序的组合来实现。
描述于本申请实施例中所涉及到的单元可以通过软件的方式实现,也可以通过硬件的方式来实现,所描述的单元也可以设置在处理器中。其中,这些单元的名称在某种情况下并不构成对该单元本身的限定。
本申请还提供了一种计算机可读介质,该计算机可读介质可以是上述实施例中描述的电子设备中所包含的;也可以是单独存在,而未装配入该电子设备中。上述计算机可读介质承载有一个或者多个计算机程序,当上述一个或者多个计算机程序被一个该电子设备执行时,使得该电子设备实现上述实施例中所述的方法。
应当注意,尽管在上文详细描述中提及了用于动作执行的设备的若干模块或者单元,但是这种划分并非强制性的。实际上,根据本申请的实施方式,上文描述的两个或更多模块或者单元的特征和功能可以在一个模块或者单元中具体化。反之,上文描述的一个模块或者单元的特征和功能可以进一步划分为由多个模块或者单元来具体化。
通过以上的实施方式的描述,本领域的技术人员易于理解,这里描述的示例实施方式可以通过软件实现,也可以通过软件结合必要的硬件的方式来实现。因此,根据本申请实施方式的技术方案可以以软件产品的形式体现出来,该软件产品可以存储在一个非易失性存储介质(可以是CD-ROM,U盘,移动硬盘等)中或网络上,包括若干指令以使得一台电子设备执行根据本申请实施方式的方法。
比如,电子设备可以是控制器,那么控制器可以执行图2所示的接入控制方法。
本领域技术人员在考虑说明书及实践这里公开的实施方式后,将容易想到本申请的其它实施方案。本申请旨在涵盖本申请的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本申请的一般性原理并包括本申请未公开的本技术领域中的公知常识或惯用技术手段。
应当理解的是,本申请并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本申请的范围仅由所附的权利要求来限制。
Claims (16)
- 一种接入控制方法,由控制设备执行,所述方法包括:获取接入设备的设备信息,并获取所述接入设备待接入的专有网络的信息;根据所述专有网络的信息向所述专有网络对应的接入网关发送隧道创建指令,以指示所述接入网关建立与所述接入设备之间的传输隧道;生成针对所述接入设备的配置信息,所述配置信息用于指示所述接入设备建立与所述接入网关之间的传输隧道;响应于检测到所述接入设备上线,将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
- 根据权利要求1所述的接入控制方法,其中,所述接入控制方法还包括:响应于接收到所述接入设备发送的心跳消息,确定检测到所述接入设备上线;其中,所述心跳消息是所述接入设备上线后周期性发送的。
- 根据权利要求1所述的接入控制方法,其中,生成针对所述接入设备的配置信息后,进一步包括:将所述配置信息存储到数据库中;所述接入控制方法还包括:接收所述接入设备上线后周期性发送的心跳消息,所述心跳消息中包含有所述接入设备的上一次启动时间;从数据库中获取针对所述接入设备记录的上一次启动时间;响应于所述心跳消息中包含的上一次启动时间与所述数据库中记录的上一次启动时间不一致,获取所述接入设备中的当前配置信息;响应于所述当前配置信息与所述数据库中存储的针对所述接入设备的配置信息不匹配,将所述数据库中存储的配置信息发送给所述接入设备。
- 根据权利要求3所述的接入控制方法,其中,将所述数据库中存储的配置信息发送给所述接入设备,包括:在所述数据库中存储的针对所述接入设备的配置信息中查找与所述当前配置信息存在差异的配置信息;将查找到的存在差异的配置信息发送给所述接入设备。
- 根据权利要求3或4所述的接入控制方法,其中,在将所述数据库中存储的配置信息发送给所述接入设备之后,所述接入控制方法还包括:根据所述心跳消息中包含的上一次启动时间,对所述数据库中针对所述接入设备记录的上一次启动时间进行更新。
- 根据权利要求1至5任一项所述的接入控制方法,其中,所述接入控制方法还包括:获取所述网络接入方针对所述接入设备提供的隧道加密密钥;在所述隧道创建指令和所述配置信息中添加所述隧道加密密钥,以使所述接入设备与所述接入网关之间基于所述隧道加密密钥建立加密传输隧道。
- 根据权利要求1至6任一项所述的接入控制方法,其中,所述传输隧道是所述接入设备通过核心网网元与所述接入网关建立的;所述接入控制方法还包括:向所述接入网关和所述核心网网元发送通用路由封装GRE隧道建立指令,以指示所述核心网网元与所述接入网关建立GRE隧道;其中,所述接入设备与所述接入网关之间建立的传输隧道承载在所述GRE隧道之上。
- 根据权利要求7所述的接入控制方法,其特征在于,所述专有网络对应有至少两个接入网关;所述向所述接入网关和所述核心网网元发送通用路由封装GRE隧道建立指令,以指示所述核心网网元与所述接入网关建立GRE隧道,包括:向所述至少两个接入网关和至少两个所述核心网网元发送所述GRE隧道建立指令,以指示每个所述核心网网元分别与所述至少两个接入网关建立所述GRE隧道,并指示每个所述核心网网元将相应核心网网元与所述至少两个接入网关之间建立的GRE隧道配置为等价多径路由的方式。
- 根据权利要求1至8任一项所述的接入控制方法,其中,所述专有网络对应有至少两个接入网关;将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,包括:将所述配置信息发送给所述接入设备,以指示所述接入设备分别与所述至少两个接入网关建立传输隧道,并指示所述接入设备将所述接入设备与所述至少两个接入网关之间建立的传输隧道配置为等价多径路由的方式。
- 根据权利要求1至9中任一项所述的接入控制方法,其中,所述接入控制方法还包括:向所述接入网关,以及连接在所述接入网关和所述专有网络之间的转发设备发送隧道创建指令,以指示所述接入网关与所述转发设备之间建立传输隧道,所述接入网关与所述转发设备之间的传输隧道用于将所述接入设备的流量传输至所述转发设备,以使所 述转发设备将所述接入设备的流量路由至所述专有网络。
- 根据权利要求10所述的接入控制方法,其中,所述专有网络对应于至少两个接入网关和至少两个转发设备;向所述接入网关,以及连接在所述接入网关和所述专有网络之间的转发设备发送隧道创建指令,以指示所述接入网关与所述转发设备之间建立传输隧道,包括:向所述至少两个接入网关和至少两个转发设备发送隧道创建指令,以指示每个所述接入网关分别与所述至少两个转发设备之间建立传输隧道,并指示每个所述接入网关将相应接入网关与所述至少两个转发设备之间建立的传输隧道配置为等价多径路由的方式。
- 根据权利要求10或11所述的接入控制方法,其中,所述接入设备与所述接入网关之间建立的传输隧道包括互联网安全协议隧道;所述接入网关与所述转发设备之间建立的传输隧道包括虚拟扩展局域网隧道,所述虚拟扩展局域网隧道用于将所述接入网关对所述互联网安全协议隧道解封装之后的流量传输至所述转发设备。
- 一种接入控制装置,包括:获取单元,配置为获取接入设备的设备信息,并获取所述接入设备待接入的专有网络的信息;发送单元,配置为根据所述专有网络的信息向所述专有网络对应的接入网关发送隧道创建指令,以指示所述接入网关建立与所述接入设备之间的传输隧道;生成单元,配置为生成针对所述接入设备的配置信息,所述配置信息用于指示所述接入设备建立与所述接入网关之间的传输隧道;处理单元,配置为响应于检测到所述接入设备上线,则将所述配置信息发送给所述接入设备,以使所述接入设备根据所述配置信息与所述接入网关建立传输隧道,并基于建立的传输隧道接入所述专有网络。
- 一种非易失性计算机可读介质,其上存储有计算机程序,其中,所述计算机程序被处理器执行时实现如权利要求1至12中任一项所述的接入控制方法。
- 一种电子设备,包括:一个或多个处理器;存储器,用于存储一个或多个计算机程序,当所述一个或多个计算机程序被所述一个或多个处理器执行时,使得所述电子设备实现如权利要求1至12中任一项所述的接入控制方法。
- 一种计算机程序产品,所述计算机程序产品包括计算机指令,所述计算机指令存储在计算机可读存储介质中,当所述计算机指令被执行时,实现如权利要求1-12中任一项所述的接入控制方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US19/303,946 US20250385812A1 (en) | 2023-06-29 | 2025-08-19 | Access control |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310793815.9A CN119233364A (zh) | 2023-06-29 | 2023-06-29 | 接入控制方法、装置、计算机可读介质及电子设备 |
| CN202310793815.9 | 2023-06-29 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/303,946 Continuation US20250385812A1 (en) | 2023-06-29 | 2025-08-19 | Access control |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025001981A1 true WO2025001981A1 (zh) | 2025-01-02 |
Family
ID=93937370
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/100535 Ceased WO2025001981A1 (zh) | 2023-06-29 | 2024-06-21 | 接入控制方法、装置、计算机可读介质及电子设备 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20250385812A1 (zh) |
| CN (1) | CN119233364A (zh) |
| WO (1) | WO2025001981A1 (zh) |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9300487B1 (en) * | 2007-02-06 | 2016-03-29 | Apple Inc. | Re-establishing a direct tunnel between an access node and a gateway router |
| CN106789527A (zh) * | 2016-12-09 | 2017-05-31 | 中国联合网络通信集团有限公司 | 一种专线网络接入的方法及系统 |
| CN109151916A (zh) * | 2018-08-28 | 2019-01-04 | 北京佰才邦技术有限公司 | 移动网络业务的网络传输方法、装置和系统 |
| CN109327375A (zh) * | 2017-08-01 | 2019-02-12 | 中国电信股份有限公司 | 用于建立vxlan隧道的方法、装置和系统 |
| CN112995007A (zh) * | 2019-12-18 | 2021-06-18 | 中国移动通信集团陕西有限公司 | 云专线连接方法及系统 |
| CN114844935A (zh) * | 2021-02-01 | 2022-08-02 | 腾讯科技(深圳)有限公司 | 一种云服务接入的方法、相关装置、设备以及存储介质 |
-
2023
- 2023-06-29 CN CN202310793815.9A patent/CN119233364A/zh active Pending
-
2024
- 2024-06-21 WO PCT/CN2024/100535 patent/WO2025001981A1/zh not_active Ceased
-
2025
- 2025-08-19 US US19/303,946 patent/US20250385812A1/en active Pending
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9300487B1 (en) * | 2007-02-06 | 2016-03-29 | Apple Inc. | Re-establishing a direct tunnel between an access node and a gateway router |
| CN106789527A (zh) * | 2016-12-09 | 2017-05-31 | 中国联合网络通信集团有限公司 | 一种专线网络接入的方法及系统 |
| CN109327375A (zh) * | 2017-08-01 | 2019-02-12 | 中国电信股份有限公司 | 用于建立vxlan隧道的方法、装置和系统 |
| CN109151916A (zh) * | 2018-08-28 | 2019-01-04 | 北京佰才邦技术有限公司 | 移动网络业务的网络传输方法、装置和系统 |
| CN112995007A (zh) * | 2019-12-18 | 2021-06-18 | 中国移动通信集团陕西有限公司 | 云专线连接方法及系统 |
| CN114844935A (zh) * | 2021-02-01 | 2022-08-02 | 腾讯科技(深圳)有限公司 | 一种云服务接入的方法、相关装置、设备以及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20250385812A1 (en) | 2025-12-18 |
| CN119233364A (zh) | 2024-12-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11902364B2 (en) | Automatic replacement of computing nodes in a virtual computer network | |
| CN114946222B (zh) | 用于对提供商底层扩展的多运营商接入的方法和系统 | |
| CN112470436B (zh) | 用于提供多云连通性的系统、方法、以及计算机可读介质 | |
| US11140070B2 (en) | Independent datastore in a network routing environment | |
| WO2016146077A1 (zh) | 一种动态路由配置方法、装置及系统 | |
| CN111510310B (zh) | 公有云架构下的网络模式实现方法和装置 | |
| WO2019100266A1 (zh) | 移动边缘主机服务通知方法和装置 | |
| WO2020057445A1 (zh) | 一种通信系统、方法及装置 | |
| CN115379010A (zh) | 一种容器网络构建方法、装置、设备及存储介质 | |
| CN109462537B (zh) | 一种跨网络互通方法和装置 | |
| CN113545130B (zh) | 利用分布式散列的无线客户端的快速漫游和统一策略 | |
| WO2025001981A1 (zh) | 接入控制方法、装置、计算机可读介质及电子设备 | |
| CN115665026A (zh) | 一种集群组网的方法和装置 | |
| CN115834290A (zh) | 一种动态建立隧道的方法、装置、设备及介质 | |
| CN116888940A (zh) | 利用虚拟联网的容器化路由器 | |
| CN117560245A (zh) | 接入控制方法、装置、计算机可读介质及电子设备 | |
| CN115633079A (zh) | 一种基于云平台的云专线实现方法、装置以及介质 | |
| CN117478446A (zh) | 云网络接入方法、设备及存储介质 | |
| CN120825391A (zh) | 一种数据处理方法、装置、计算机设备以及可读存储介质 | |
| CN118631732A (zh) | 基于混合云的通信方法、设备及介质 | |
| JP2023527929A (ja) | 仮想化ネットワーク・サービス配備方法及び装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24830627 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |