WO2019047611A1 - 一种数据传输方法、pnf sdn控制器、vnf sdn控制器及系统 - Google Patents
一种数据传输方法、pnf sdn控制器、vnf sdn控制器及系统 Download PDFInfo
- Publication number
- WO2019047611A1 WO2019047611A1 PCT/CN2018/094709 CN2018094709W WO2019047611A1 WO 2019047611 A1 WO2019047611 A1 WO 2019047611A1 CN 2018094709 W CN2018094709 W CN 2018094709W WO 2019047611 A1 WO2019047611 A1 WO 2019047611A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- sdn controller
- packet
- vnf
- pnf
- address
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5007—Internet protocol [IP] addresses
- H04L61/5014—Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5007—Internet protocol [IP] addresses
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/02—Topology update or discovery
- H04L45/036—Updating the topology between route computation elements, e.g. between OpenFlow controllers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/38—Flow based routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/42—Centralised routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/64—Routing or path finding of packets in data switching networks using an overlay routing layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/74—Address processing for routing
- H04L45/745—Address table lookup; Address filtering
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L49/00—Packet switching elements
- H04L49/70—Virtual switches
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/10—Mapping addresses of different types
- H04L61/103—Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5007—Internet protocol [IP] addresses
- H04L61/503—Internet protocol [IP] addresses using an authentication, authorisation and accounting [AAA] protocol, e.g. remote authentication dial-in user service [RADIUS] or Diameter
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5092—Address allocation by self-assignment, e.g. picking addresses at random and testing if they are already in use
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2101/00—Indexing scheme associated with group H04L61/00
- H04L2101/60—Types of network addresses
- H04L2101/618—Details of network addresses
- H04L2101/622—Layer-2 addresses, e.g. medium access control [MAC] addresses
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5061—Pools of addresses
Definitions
- the application relates to a data transmission method, a PNF SDN controller, a VNF SDN controller and a system.
- the network devices in the user access system may include user equipment, access devices, switches, or Internet Protocol (IP) edge devices.
- IP Internet Protocol
- DHCP Dynamic Host Configuration Protocol
- RS Raster Solicitation
- the access device receives the first DHCP/RS packet sent by the user equipment, generates an access loop identifier, and adds the access loop identifier to the first DHCP/RS packet to generate a second DHCP/RS packet. Then, the second DHCP/RS message is forwarded to the switch, and the second DHCP/RS message is sent to the DHCP server through the switch and an Internet Protocol (IP) edge device to request the DHCP server to allocate the user equipment. IP address or IP address prefix.
- IP Internet Protocol
- the DHCP server allocates an IP address or an IP address prefix to the user equipment, and sends a DHCP/RS response packet carrying the IP address or IP address prefix to the user equipment according to the access loop identifier.
- the format of the access loop identifier corresponding to the user equipment may be different. Therefore, the network equipment needs to be customized for different operators, so that the complexity of the network device is high.
- the present application relates to a data transmission method, a PNF SDN controller, a VNF SDN controller and a system to reduce the complexity of a network device.
- an embodiment of the present application provides a data transmission method, where the data transmission method may include:
- the physical network function software definition network PNF SDN controller receives the first packet and the access loop identifier sent by the first network device, where the access loop identifier is used to identify that the first network device receives the first A physical port or logical port of the first network device of a message.
- the PNF SDN controller generates a second packet according to the access loop identifier and the first packet, where the second packet includes the first packet and the access loop identifier.
- the PNF SDN controller sends the second message to the virtual network function software definition network VNF SDN controller, so that the VNF SDN controller sends the second message to the second network device.
- the second message is used to request the second network device to allocate an internet protocol IP address or an IP address prefix to the user equipment.
- the access device does not need to process the first packet and the access loop identifier after receiving the first packet in the process of processing and transmitting the first packet.
- the first packet and the access loop identifier are sent to the PNF SDN controller, so that the first packet and the access loop identifier are processed by the PNF SDN controller to generate a second packet.
- the second packet is sent to the VNF SDN controller, so that the VNF SDN controller sends the second packet to the DHCP server, and the IP address or IP address prefix is allocated to the user equipment through the DHCP server, thereby reducing the The complexity of the access device.
- the PNF SDN controller can directly send the second packet to the VNF SDN controller, implementing the interaction between the PNF SDN controller and the VNF SDN controller, and avoiding the second report through the access device and the IP edge device.
- the text is forwarded to the VNF SDN controller, thereby improving the efficiency of data transmission.
- the method may further include:
- the PNF SDN controller receives the response packet corresponding to the second packet sent by the VNF SDN controller.
- the response message of the second packet includes the access loop identifier and an IP address or an IP address prefix allocated to the user equipment.
- the PNF SDN controller sends the access loop identifier and the IP address or IP address prefix assigned by the second network device to the user equipment to the first network device.
- the PNF SDN controller sends the second packet to the VNF SDN controller, which may include:
- the PNF SDN controller sends the second packet directly to the VNF SDN controller through the interconnection interface between the PNF SDN controller and the VNF SDN controller, thereby implementing direct interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding
- the second message is forwarded to the VNF SDN controller through the access device and the IP edge device, thereby improving data transmission efficiency.
- the PNF SDN controller sends the second packet to the VNF SDN controller, which may include:
- the PNF SDN controller sends the second message to the VNF SDN controller through the superior controller.
- the method may further include:
- the PNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet.
- the PNF SDN controller sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the first network device, thereby preventing the impersonation of the IP address or the IP address prefix and the impersonation of the MAC address, thereby improving the network device. safety.
- the embodiment of the present application provides a data transmission method, where the data transmission method may include:
- the virtual network function software defines the network VNF SDN controller to receive the second message sent by the PNF SDN controller.
- the second packet is generated by the PNF SDN controller according to the access loop identifier and the first packet.
- the VNF SDN controller sends the second message to the second network device.
- the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment.
- the access loop identifier is used to identify a physical port or a logical port of the first network device that the first network device receives the first packet.
- the VNF SDN controller can directly receive the second packet sent by the PNF SDN controller, and implement direct interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding the connection.
- the ingress device and the IP edge device forward the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- the method may further include:
- the VNF SDN controller receives the response packet corresponding to the second packet sent by the second network device, where the response packet of the second packet includes the access loop identifier and the IP address allocated by the second network device to the user equipment. Address or IP address prefix.
- the VNF SDN controller sends the response message of the second packet to the PNF SDN controller.
- the VNF SDN controller receives the second packet sent by the PNF SDN controller, and may include:
- the VNF SDN controller receives the second packet sent by the PNF SDN controller through the interconnection interface between the VNF SDN controller and the PNF SDN controller, and implements a direct interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding the passage.
- the access device and the IP edge device forward the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- the VNF SDN controller receives the second packet sent by the PNF SDN controller, and may include:
- the VNF SDN controller receives the second packet sent by the PNF SDN controller through the upper controller.
- the method may further include:
- the VNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet.
- the VNF SDN controller sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the third network device, thereby preventing the impersonation of the IP address or the IP address prefix, and impersonating the MAC address, thereby improving the network device. safety.
- the method may further include:
- the VNF SDN controller obtains the access loop identifier in the second packet.
- the VNF SDN controller sends an authentication request packet to the fourth network device, where the authentication request packet includes the access loop identifier.
- the VNF SDN controller receives the authorization response message sent by the fourth network device, thereby completing the verification and authorization of the user identity.
- the embodiment of the present application provides a physical network function software definition network PNF SDN controller, which may include:
- the receiving unit is configured to receive the first packet and the access loop identifier sent by the first network device, where the access loop identifier is used to identify that the first network device receives the first packet of the first packet The physical or logical port of the network device.
- the generating unit is configured to generate a second packet according to the access loop identifier and the first packet, where the second packet includes the first packet and the access loop identifier.
- the sending unit is configured to send the second packet to the virtual network function software definition network VNF SDN controller, so that the VNF SDN controller sends the second packet to the second network device, and the second packet is used to request the second network.
- the device allocates an IP address or an IP address prefix to the user equipment.
- the receiving unit is further configured to receive a response packet of the second packet sent by the VNF SDN controller, where the response packet of the second packet includes the access loop identifier and the The second network device prefixes the IP address or IP address assigned to the user equipment.
- the sending unit is further configured to send, by the first network device, the access loop identifier and an IP address or an IP address prefix allocated by the second network device to the user equipment.
- the sending unit is specifically configured to send the second packet to the VNF SDN controller through an interconnection interface between the PNF SDN controller and the VNF SDN controller.
- the sending unit is specifically configured to send the second packet to the VNF SDN controller by using the upper controller.
- the generating unit is further configured to generate, according to the response message of the second packet, a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment.
- the sending unit is further configured to send, to the first network device, a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment.
- the embodiment of the present application further provides a virtual network function software definition network VNF SDN controller, which may include:
- the receiving unit is configured to receive the second packet sent by the PNF SDN controller.
- the second packet is generated by the PNF SDN controller according to the access loop identifier and the first packet.
- the sending unit is configured to send the second packet to the second network device.
- the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment, where the access loop identifier is used to identify the first network device that the first network device receives the first packet. Physical port or logical port.
- the receiving unit is further configured to receive a response packet corresponding to the second packet sent by the second network device.
- the response message of the second packet includes the access loop identifier and an IP address or an IP address prefix assigned to the user equipment.
- the sending unit is further configured to send the response message of the second packet to the PNF SDN controller.
- the receiving unit is specifically configured to receive the second packet sent by the PNF SDN controller by using an interconnection interface between the VNF SDN controller and the PNF SDN controller.
- the receiving unit is specifically configured to receive, by the upper controller, the second packet sent by the PNF SDN controller.
- the VNF SDN controller may further include a generating unit.
- the generating unit is configured to generate a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet.
- the sending unit is further configured to send a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the third network device.
- the VNF SDN controller may further include:
- the obtaining unit is configured to obtain the access loop identifier in the second packet.
- the sending unit is further configured to send an authentication request message to the fourth network device, where the authentication request message includes the access loop identifier.
- the receiving unit is further configured to receive an authorization response message sent by the fourth network device.
- the embodiment of the present application further provides a physical network function software definition network PNF SDN controller, where the PNF SDN controller may include:
- a communication interface configured to receive the first packet and the access loop identifier sent by the first network device, and send the generated second packet to the VNF SDN controller, where the access loop identifier is used to identify the A network device receives a physical port or a logical port of the first network device of the first packet.
- the communication interface is further configured to receive a response packet of the second packet sent by the VNF SDN controller, where the response packet of the second packet includes the access loop identifier Transmitting the access loop identifier and the IP address or IP address prefix assigned by the user equipment to the first network device, and sending the IP address or the IP address prefix to the first network device A mapping table between the IP address or IP address prefix and the MAC address of the user equipment.
- the PNF SDN controller may further include a memory for storing a program.
- a processor configured to execute a program stored in the memory, when the program is executed, the processor is configured to generate a second packet according to the access loop identifier and the first packet, where the second packet includes the The first packet and the access loop identifier are processed; the response packet of the second packet is processed, and the access loop identifier is separated from the response packet of the second packet.
- the processor is further configured to generate, according to the response message of the second packet, a mapping table between the IP address or an IP address prefix and a MAC address of the user equipment.
- the embodiment of the present application further provides a virtual network function software definition network VNF SDN controller, where the VNF SDN controller may include:
- a communication interface configured to receive a second packet sent by the physical network function software-defined network PNF SDN controller, where the second packet is generated by the PNF SDN controller according to the access loop identifier and the first packet, Sending the second packet to the second network device, where the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment, where the access loop identifier is used. And identifying a physical port or a logical port of the first network device that receives the first packet by the first network device.
- the communication interface is further configured to receive a response packet of the second packet sent by the second network device, where the response packet of the second packet includes the access loop identifier and The IP address or IP address prefix assigned by the user equipment; the response message of the second packet is sent to the PNF SDN controller; the MAC address of the user equipment sent by the PNF SDN controller is received; and the third network device is sent a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment; obtaining the access loop identifier in the second packet; and sending an authentication request packet to the fourth network device, The authentication request packet includes the access loop identifier, and receives an authorization response packet sent by the fourth network device.
- the VNF SDN controller may further include a memory for storing a program.
- the VNF SDN controller may further include a processor, configured to execute a program of the memory storage, when the program is executed, the processor is configured to generate the IP address according to the response message of the second packet or A mapping table between the IP address prefix and the MAC address of the user equipment.
- a processor configured to execute a program of the memory storage, when the program is executed, the processor is configured to generate the IP address according to the response message of the second packet or A mapping table between the IP address prefix and the MAC address of the user equipment.
- the embodiment of the present application further provides a system for data transmission, where the system includes:
- the PNF SDN controller provided by any of the foregoing third aspect or the third aspect, and the VNF SDN controller provided by any of the foregoing fourth or fourth possible implementation manners.
- a further aspect of the present application provides a computer readable storage medium having stored therein instructions that, when executed on a computer, cause the computer to perform the methods described in the above aspects .
- the PNF SDN controller receives the first packet and the access loop identifier sent by the access device;
- the second packet is sent to the VNF SDN controller, and the second packet sent by the PNF SDN controller is sent to the DHCP server.
- the DHCP server is requested to assign an IP address or IP address prefix to the user equipment. Therefore, in the process of processing and transmitting the first packet, the access device receives the first packet in the data transmission method, the PNF SDN controller, the VNF SDN controller, and the data transmission system provided by the embodiment of the present application.
- the first packet and the access loop identifier need not be processed, but only the first packet and the access loop identifier are sent to the PNF SDN controller, so that the first packet is sent by the PNF SDN controller.
- the access loop identifier is processed to generate a second packet, and the second packet is sent to the VNF SDN controller, so that the VNF SDN controller sends the second packet to the network server, and passes the network server.
- the user equipment is assigned an IP address or an IP address prefix, thereby reducing the complexity of the access device.
- the PNF SDN controller sends the message to the VNF SDN controller, and can directly send the second packet to the VNF SDN controller, thereby realizing the interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding the access device and
- the IP edge device forwards the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- FIG. 2 is a schematic diagram of a data transmission method according to an embodiment of the present application.
- FIG. 3 is a schematic diagram of another data transmission method according to an embodiment of the present disclosure.
- FIG. 4 is a schematic diagram of still another data transmission method according to an embodiment of the present application.
- FIG. 5 is a schematic diagram of still another data transmission method according to an embodiment of the present application.
- FIG. 6 is a schematic structural diagram of a PNF SDN controller according to an embodiment of the present application.
- FIG. 7 is a schematic structural diagram of a VNF SDN controller according to an embodiment of the present application.
- FIG. 8 is a schematic structural diagram of another PNF SDN controller according to an embodiment of the present application.
- FIG. 9 is a schematic structural diagram of another VNF SDN controller according to an embodiment of the present application.
- FIG. 10 is a schematic structural diagram of a system for data transmission according to an embodiment of the present application.
- the network system shown in FIG. 1 may be a Digital Subscriber Line (DSL) access system or an Ethernet (Ethernet) access system. Passive Optical Network (PON) access system.
- DSL Digital Subscriber Line
- Ethernet Ethernet
- PON Passive Optical Network
- the access network system mainly includes the user equipment, the access device, the IP edge device, and the DHCP server.
- the user equipment communicates with the IP edge device and the DHCP server through the access device.
- the user device can be a mobile phone (or "cellular" phone) or a computer with a mobile terminal, for example, can be a portable, pocket, handheld, computer built-in or in-vehicle mobile device or the like.
- the user equipment may also be referred to as a terminal device, a mobile station (MS), a terminal, and may also include a subscriber unit, a cellular phone, a smart phone, and wireless data.
- Card personal digital assistant (PDA) computer, tablet computer, wireless modem, handheld, laptop computer, cordless phone or wireless local ring A wireless local loop (WLL) station or a machine type communication (MTC) terminal.
- the access device is mainly used for accessing the network by the user equipment to implement the access of the user equipment to the remote network resource.
- the access device may be a Digital Subscriber Line Access Multiplexer (DSLAM) or an optical network unit (Optical Network Unit (ONU) or Optical Line Termination (OLT).
- DSLAM Digital Subscriber Line Access Multiplexer
- ONU Optical Network Unit
- OLT Optical Line Termination
- IP edge devices are mainly used for data transmission of access devices and network devices. They can be devices such as switches and routers installed at the edge of the network.
- IP edge devices can be Broadband Network Gateway (BNG) broadband access. Server (Broadband Remote Access Server, BRAS), etc.
- BNG Broadband Network Gateway
- Server Broadband Remote Access Server, BRAS
- the DHCP server is mainly responsible for the management and allocation of IP addresses or IP address prefixes.
- the user equipment requests an IP address
- the user equipment sends a DHCP request message to the DHCP server, where the DHCP request message is used to request the DHCP server to allocate an IP address or an IP address prefix to the user equipment.
- the access device receives the DHCP request message sent by the user equipment, and sends the DHCP request message and the access loop identifier corresponding to the DHCP request message to the DHCP server.
- the access loop identifier which is also referred to as an access line identifier, can uniquely identify the physical port or logical port on the access device and the access device that receives the message.
- the DHCP server receives the DHCP request message and the access loop identifier, and sends an IP address or an IP address prefix assigned to the user equipment, and the access loop identifier to the access device. .
- the access device receives the IP address or an IP address prefix, and the access loop identifier, and sends the IP address assigned to the user equipment to the user equipment according to the access loop identifier or IP address prefix.
- the DHCP request packet and the access loop identifier need to be sent to the DHCP server. Therefore, each network device on the DHCP request packet transmission path needs to support the processing function of the DHCP and access loop identifiers.
- a network device such as a DSLAM, a router, a BNG, or a switch on a DHCP packet transmission path needs to have a processing function for the DHCP packet and the access loop identifier, but for different operators, the corresponding interface The format and content of the inbound loop identifier are different. Therefore, the network devices need to be customized for different operators, which makes the network device more complex and suffers from the version and its upgrade.
- FIG. 1 provides a schematic diagram of an application scenario.
- the scenario may be a schematic diagram of an architecture of an access network system.
- the access system of FIG. 1
- the access network system of FIG. 1 includes a Physical Network Function (PNF) Software Defined Network (SDN) controller, and a virtual network function (Virtual Network Function, VNF) Software Defined Network (SDN) controller, user equipment, access device controlled by the PNF SDN management, IP network edge device controlled by the VNF SDN, used to provide an IP address or an IP address prefix DHCP server.
- PNF Physical Network Function
- VNF Virtual Network Function
- SDN Software Defined Network
- the access network system of FIG. 1 may also include a switch that connects the access device and the IP edge device.
- the access device when the access device receives the DHCP request message sent by the user equipment, the access device corresponds the DHCP request message and the DHCP request message.
- the access ring identifier is forwarded to the PNF SDN controller; the PNF SDN controller receives the DHCP request message and the access loop identifier sent by the access device, and the PNF SDN controller is configured according to the The DHCP request message and the access loop identifier generate a second packet.
- the PNF SDN controller receives the access loop identifier and the DHCP request packet, and adds the access loop identifier to the first DHCP.
- the field opt ions (82) of the packet generates a second packet, and the PNF SDN controller integrates the function of the access device to add the access loop identifier to the first DHCP packet.
- the PNF SDN controller sends the second packet to the access device.
- the access device sends the second packet to a next hop on the DHCP service path, such as network device A (not shown). If the network device A is under the control of the VNF SDN controller, the network device A sends the second message to the VNF SDN controller, and the VNF SDN controller processes the second message and generates a new report.
- the new packet is the third packet
- the process of processing the second packet by the VNF SDN controller may be to add content and re-encapsulate the packet, or to parse the packet and separate fields, such as VNF SDN.
- the controller adds the identifier corresponding to the device to the second packet, and the processing procedure of the second packet by the VNF SDN controller is determined according to the service type, and the VNF SDN controller can also forward only the received packet. For any processing, the present application does not limit the above processing.
- the VNF SDN controller sends the third packet to the IP edge device, and the IP edge device sends the third packet to the next hop of the network device A according to the DHCP service path, such as the network device B.
- each network node on the DHCP service path needs to forward the received DHCP request message to the PNF SDN controller or the VNF SDN controller.
- the packet is resent to the network device, and the network device continues to transmit according to the service path of the packet. In this way, the complexity of message transmission is increased, and the network burden is increased, which is not conducive to the simplification of the network node.
- the PNF SDN controller may also send the access loop identifier and the first packet to the VNF SDN controller separately.
- the VNF SDN controller may encapsulate the access loop identifier and the first packet into the same packet and send the packet to the DHCP server, or send the access loop identifier and the first packet to the DHCP server. .
- FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.
- the communication system may include a user equipment, an access device, an IP edge device, a DHCP server, a PNF SDN controller, and a VNF SDN controller.
- the user equipment may communicate with the DHCP server via the access device, and the user equipment may also communicate with the DHCP server via the access device and the relay device; the PNF SDN controller may separately Communicating with each physical network device on the DHCP path, the VNF SDN controller can each communicate with each virtual network device on the DHCP path, the PNF SDN controller communicating with the VNF SDN controller.
- the access device may be referred to as a first network device
- the DHCP server may be referred to as a second network device.
- the method includes: the user equipment sends a first packet to the first network device; the first network device receives the first packet, and corresponds to the first packet and the first packet
- the access loop identifier is sent to the PNF SDN controller, where the access loop identifier is used to identify the physical port of the first network device that the first network device receives the first packet Or a logical port; the PNF SDN controller receives the first packet and the access loop identifier sent by the first network device, and generates a first packet according to the access loop identifier and the first packet Two messages.
- the PNF SDN controller sends the second packet to the VNF SDN controller, where the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment.
- the first network device in the process of processing and transmitting the first packet, receives the first packet, and does not use the first packet.
- the access loop identifier is processed, and only the first packet and the access loop identifier are sent to the PNF SDN controller, and the first packet and the access loop identifier are processed by the PNF SDN controller.
- Generating the second message The PNF SDN controller sends the second packet to the VNF SDN controller, and the VNF SDN controller forwards the second packet to the second network device.
- the second network device will allocate an IP address or an IP address prefix to the user equipment, and the access loop identifier is sent to the VNF SDN controller in the form of a second packet response message, and the VNF SDN controller will obtain the The response message of the second message is sent to the PNF SDN controller.
- the PNF SDN controller parses the response packet of the second packet, and sends the access loop identifier and the assigned IP address or IP address prefix to the access device.
- the network device is no longer needed in the foregoing process, for example, the access device processes the access loop identifier, and the PNF SDN controller can send the generated second packet to the VNF SDN controller, which can implement the PNF SDN controller.
- the communication with the PNF SDN controller eliminates the need to transmit the second packet through the service path between the access device, simplifies the process, reduces the network load, and reduces the complexity of the access device.
- the sending, by the PNF SDN controller, the second packet to the VNF SDN controller includes: the PNF SDN controller passing between the PNF SDN controller and the VNF SDN controller
- the interconnection interface sends the second packet to the VNF SDN controller, or the PNF SDN controller sends the second packet to the VNF SDN controller by using a superior controller.
- direct communication between the PNF SDN controller and the VNF SDN controller can be implemented through configuration.
- the PNF SDN controller and the VNF SDN controller support the same network interworking protocol, so that the PNF SDN controller can transmit messages to and from the VNF SDN controller through the interconnection interface.
- the configuration can implement direct transmission of DHCP messages between the PNF SDN controller and the VNF SDN controller.
- the communication and information between the PNF SDN controller and the VNF SDN controller can be through a proprietary protocol, or Border Gateway Protocol (BGP) or Session Initiation Protocol (SIP) or (Interior Gateway Protocol, IGP). Extended implementation.
- Border Gateway Protocol BGP
- Session Initiation Protocol SIP
- IGP Interior Gateway Protocol
- the PNF SDN controller can transmit messages to and from the VNF SDN controller through a superior management or controller (eg, a collaborator Orchestrator).
- a superior management or controller eg, a collaborator Orchestrator
- the PNF SDN controller, the VNF SDN controller, and the synapse need to be pre-configured so that the PNF SDN controller, the VNF SDN controller, and the synapse can support the same transmission protocol to pass the
- the synchronizer implements message transmission between the PNF SDN controller and the VNF SDN controller. Thereby, the message transmission between the PNF SDN controller and the VNF SDN controller is implemented by the synchronizer.
- FIG. 2 is a schematic diagram of a data transmission method according to an embodiment of the present disclosure.
- the data transmission method may include:
- the S201 the PNF SDN controller receives the first packet and the access loop identifier sent by the access device, where the access loop identifier is used to identify the access device that the access device receives the first packet. Physical port or logical port.
- the access device After receiving the first packet, the access device does not perform the service processing on the first packet, but sends the first packet to the PNF SDN controller, and corresponds to the first packet.
- the access loop identity is also sent to the PNF SDN controller.
- the first packet may be a DHCP packet or an RS packet.
- the first packet and the access loop are identified as two independent packets.
- the packet type of the first packet and the access loop identifier is specifically related to the communication protocol between the first network device and the PNF SDN controller.
- the access device may send the first packet and the access loop identifier together in any one of the following messages to the PNF SDN controller: OpenFlow message, access management or control protocol, Mfc interface pipe message, tunnel message, or metadata as a Service Function Chain.
- the access device creates a first OpenFlow message, and extends the OpenFlow so that the first OpenFlow message (such as a packet-in message) carries the first message and the access ring identifier of the corresponding access device, and the OpenFlow message is
- the first OpenFlow message further carries a Media Access Control (MAC) address of the user side device that sends the first packet.
- MAC Media Access Control
- the user equipment may first send the first packet to the access device in the process of requesting the IP address or the IP address prefix, and the access device generates the first packet after receiving the first packet through the physical port.
- the corresponding access ring identifier is sent, and then the first packet and the access loop identifier are sent to the PNF SDN controller, so that the PNF SDN controller receives the first packet and the access loop identifier. Therefore, after receiving the first packet sent by the user equipment, the access device does not need to process the first packet and the access loop identifier, but only needs to identify the first packet and the access loop identifier. Send to the PNF SDN controller, which reduces the complexity of the access device.
- the format of the access loop identifier of the user equipment is different. Specifically, in the DSL/Ethernet access system, the format of the access loop identifier of the user equipment is as follows:
- the format of the access loop identifier of the user equipment is: Access-Node-Identifier atm slot/port: vpi.vci.
- the format of the access loop identifier of the user equipment is: Access-Node-Identifier eth slot/port[:vlan-id].
- the access-Node-Identifier is an identifier of the access device (such as a DSLAM), and the slot/port is a cabinet number, a rack number, a frame number, a slot number, and a sub-slot number of the access device.
- a combination of one or more of the port numbers; vpi.vci is the virtual path identifier and virtual channel identifier on the DSL line.
- the "[]" in the format indicates optional.
- the access loop identifier corresponding to the access device includes the access loop identifier information of the ONU part, and also includes the access loop identifier information of the OLT part, and the format of the access loop identifier of the user equipment. as follows:
- the access loop identifier corresponding to the ONU is: Access-Node-Identifier atm slot1/port1/ONUID/slot2/port2:vpi.vci.
- the access loop identifier corresponding to the ONU is: Access-Node-Identifier eth slot1/port1/ONUID/slot2/port2[:vlan-id].
- the access-Node-Identifier is the identifier of the OLT
- the slot 1/port1 is a combination of one or more of the cabinet number, the rack number, the frame number, the slot number, the sub-slot number, and the port number on the OLT
- slot2 /port2 is a combination of one or more of the cabinet number, rack number, frame number, slot number, subslot number, and port number on the ONU.
- ONUID/slot2/port2:vpi.vci is the connection of the ONU part.
- Access-Node-Identifier slot1/port1 is the access loop identification information of the OLT part.
- the PNF SDN controller generates a second packet according to the access loop identifier and the first packet, where the second packet includes the first packet and the access loop identifier.
- the PNF SDN controller receives the first packet and the access loop identifier, and adds an access loop identifier to the field of the first packet, thereby generating a second packet.
- the PNF SDN controller obtains the first packet and the access loop identifier, and creates a second packet, where the second packet carries the access loop identifier, thereby implementing control processing on the packet, and the access device
- the first packet and the access loop identifier can be sent to the PNF SDN controller to implement the PNF SDN controller integrated access device function, thereby reducing the complexity of the access device.
- the PNF SDN controller can add the access loop identifier to the field of the first DHCP packet after receiving the first DHCP packet and the access loop identifier.
- a second DHCP message is generated.
- the PNF SDN controller sends the second packet to the VNF SDN controller.
- the PNF SDN controller sends the second packet to the VNF SDN controller, so that the VNF SDN controller sends the second packet to the DHCP server, and the second packet is used to request the DHCP server to allocate an IP address or an IP address to the user equipment. Prefix.
- the PNF SDN controller generates the second packet, and can directly send the second packet to the VNF SDN controller, thereby implementing interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding
- the second packet is forwarded to the VNF SDN controller through the access device and the IP edge device, thereby improving data transmission efficiency and reducing performance requirements and burden on the access device.
- the PNF SDN controller sends the second packet to the VNF SDN controller through two possible implementation manners, as follows:
- the PNF SDN controller sends the second message to the VNF SDN controller through an interconnection interface between the PNF SDN controller and the VNF SDN controller.
- the PNF SDN controller sends the second packet to the VNF SDN controller through the upper controller.
- the upper controller may be a synchronizer, and the synchronizer is separately connected to the PNF SDN controller and the VNF SDN controller, and the PNF SDN controller sends the second packet to the coordinator, and the second report is sent by the collaborator.
- the text is forwarded to the VNF SDN controller.
- the VNF SDN controller may also receive the PNF SDN control through two possible implementation manners. Second message sent by the device:
- the VNF SDN controller receives the second packet sent by the PNF SDN controller by using an interconnection interface between the VNF SDN controller and the PNF SDN controller.
- the VNF SDN controller receives the second packet sent by the PNF SDN controller by using the upper controller.
- the VNF SDN controller receives the second packet sent by the PNF SDN controller through the interconnection interface or the synapse, as shown in the PNF SDN controller and the VNF SDN shown in the foregoing.
- the controllers transmit packets to each other, and no further details are provided herein. Through these two methods, the interaction between the PNF SDN controller and the VNF SDN controller is realized, thereby improving the data transmission efficiency.
- the VNF SDN controller receives two possible implementations of the second packet sent by the PNF SDN controller and two possible implementation manners for the PNF SDN controller to send the second packet to the VNF SDN controller. Similarly, this application will not be repeated here.
- the VNF SDN controller may perform the following S204:
- the VNF SDN controller sends the second packet to the DHCP server.
- the VNF SDN controller sends the second packet to the DHCP server, so that the DHCP server allocates an IP address or an IP address prefix to the user equipment after receiving the second packet, thereby completing the request process of the first packet, that is, the request is The process by which a user device assigns an IP address or an IP address prefix.
- the access device in the process of processing and transmitting the first packet, does not need to perform the first packet and the access loop identifier after receiving the first packet.
- the first packet and the access loop identifier are sent to the PNF SDN controller, so that the first packet and the access loop identifier are processed by the PNF SDN controller to generate the second packet.
- sending the second packet to the VNF SDN controller, so that the VNF SDN controller sends the second packet to the DHCP server, and the IP address or IP address prefix is allocated to the user equipment through the DHCP server, thereby reducing The complexity of the access device.
- the IP address or the IP address prefix may be carried in the response packet of the second packet and sent to the VNF SDN controller.
- the response process of the second packet refer to S205-S207 for details.
- the VNF SDN controller receives a response packet that is sent by the DHCP server and corresponds to the second packet.
- the DHCP server After receiving the second packet of the VNF SDN controller, the DHCP server sends a response packet to the VNF SDN controller.
- the response message corresponding to the second packet includes the access loop identifier and an IP address or an IP address prefix allocated by the DHCP server to the user equipment.
- the VNF SDN controller sends the response message to the PNF SDN controller.
- the PNF SDN controller sends the access loop identifier and an IP address or an IP address prefix allocated by the DHCP server to the user equipment to the access device.
- the PNF SDN controller receives the response packet, and obtains a third packet by separating the access loop identifier, where the third packet includes an IP address that is allocated by the DHCP server for the user equipment or
- the IP address prefix and the access loop identifier are not limited to the type of the third packet, and may or may not be a DHCP packet. .
- the PNF SDN controller receives the response packet, parses the response packet, and separates the access loop identifier, and allocates the user equipment by using the third packet.
- the IP address or IP address prefix and the access loop identifier are sent to the access device.
- the third packet is an OpenFlow message
- the PNF SDN controller allocates an IP address or an IP address prefix to the user equipment through the OpenFlow message. And sending the access loop identifier to the access device.
- the data transmission method provided by the present application the PNF SDN controller receives the first packet and the access loop identifier sent by the access device, generates a second packet according to the access loop identifier and the first packet, and The second message is sent to the VNF SDN control.
- the VNF SDN controller receives the second packet sent by the PNF SDN controller, and sends the second packet to the DHCP server to request the DHCP server to allocate an IP address or an IP address prefix to the user equipment, thereby completing the processing of the first packet. And transmission. It can be seen that, in the data transmission method provided by the present application, in the process of processing and transmitting the first packet, the access device does not need to process the first packet and the access loop identifier after receiving the first packet. The first packet and the access loop identifier are sent to the PNF SDN controller, so that the first packet and the access loop identifier are processed by the PNF SDN controller to generate a second packet.
- the VNF SDN controller sends the second packet to the network server, and the user equipment is assigned an IP address or an IP address prefix through the network server, thereby reducing the access device.
- the complexity the PNF SDN controller sends the second packet to the VNF SDN controller, which implements the interaction between the PNF SDN controller and the VNF SDN controller, avoiding access to the device and the IP edge.
- the device forwards the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- FIG. 3 is a schematic diagram of another data transmission method according to an embodiment of the present disclosure, where S2031-S2033 is a process for the VNF SDN controller to verify and authorize the identity of the user equipment.
- the VNF SDN controller acquires an access loop identifier in the second packet.
- the VNF SDN controller sends an AAA authentication request message to the AAA server.
- the VNF SDN controller adds the obtained access loop identifier to the AAA authentication request packet, and then sends the AAA authentication request packet carrying the access loop identifier to the AAA server.
- the AAA authentication can be authenticated by the Remote Authentication Dial In User Service (RADIUS) protocol or the Diameter protocol.
- RADIUS Remote Authentication Dial In User Service
- the VNF SDN controller after obtaining the access loop identifier in the second packet, the VNF SDN controller carries the access loop identifier in the AAA authentication request packet and sends the AAA authentication request packet to the AAA server, so that the AAA server After receiving the AAA authentication request packet, the identity of the user equipment may be verified and authorized according to the access loop identifier, and after the identity of the user equipment is verified and authorized, the AAA authorization response report is sent to the VNF SDN controller. Text.
- the VNF SDN controller receives the AAA authorization response packet sent by the AAA server.
- the access loop identifier is obtained from the second packet by using the VNF SDN controller. And sending an AAA authentication request packet to the AAA server, and after receiving the authentication and authorization of the user equipment, receiving the AAA authorization response packet sent by the AAA server, thereby completing the authentication and authorization of the user equipment identity, without implementing the IP edge device. , thereby reducing the complexity of the IP edge device and improving the network transmission efficiency.
- the S204VNF SDN controller After determining, by S2031-S2033, that the identity of the user equipment is verified and authorized, the S204VNF SDN controller performs the second message to the DHCP server, so that the DHCP server allocates an IP address or an IP address prefix to the user equipment. After the IP address or IP address prefix is assigned to the user equipment, the DHCP server can carry the assigned IP address or IP address prefix in the response packet of the second packet to the VNF SDN controller to enable the VNF SDN controller. The response message of the received second packet is sent to the PNF SDN controller.
- the S205PNF SDN controller prevents the IP address or IP address prefix from impersonating, and the MAC address is impersonated, and the VNF SDN controller monitors
- the response packet of the second packet is generated according to the response packet of the second packet, and the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment is generated; and then the IP address or IP address prefix is used with the user.
- the mapping table between the MAC addresses of the devices is sent to the virtual data plane of the IP edge device, thereby improving the security of the network device.
- the VNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet, so that the VNF SDN controller sends the IP address or the IP address to the IP edge device.
- the VNF SDN controller may obtain the MAC address of the user equipment in advance before the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment is generated by the response packet of the second packet.
- the specific process may be: the first packet sent by the user equipment to the access device is carried in an Ethernet frame, and the source MAC address in the frame header of the Ethernet frame is the MAC address of the user equipment.
- the access device After receiving the first packet, the access device extracts the source MAC address from the frame header of the Ethernet frame, and then sends the MAC address to the PNF SDN controller, and the PNF SDN controller sends the MAC address of the user equipment.
- the VNF SDN controller is configured to generate a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the IP address or the IP address prefix and the MAC address of the user equipment.
- the MAC address of the user equipment may be the MAC address of the customer premise equipment (CPE) or the MAC address of the user equipment UE.
- CPE customer premise equipment
- obtaining the MAC address of the user equipment by the PNF SDN controller may be implemented in step S201, or may be implemented separately.
- the VNF SDN controller can send the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the IP edge.
- the VNF SDN controller can send a mapping table between the IP address or IP address prefix and the MAC address of the user equipment to the IP edge device through the OpenFlow or the Network Configuration Protocol (NETCONF) management or control protocol.
- Virtual data plane so that the IP edge device generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment. Therefore, the impersonation of the IP address or the IP address prefix and the impersonation of the MAC address are prevented, thereby improving the security of the network device.
- NETCONF Network Configuration Protocol
- the PNF SDN controller After receiving the response message of the second packet sent by the VNF SDN controller, the PNF SDN controller listens to the second report in order to prevent the IP address or IP address prefix from impersonating and the MAC address from impersonating.
- the response packet of the text is generated according to the response packet of the second packet, and the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment is generated; and then the IP address or IP address prefix is matched with the MAC address of the user equipment.
- the mapping table between the addresses is sent to the access device, thereby improving the security of the network device. For details, see S209-S210:
- the PNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet.
- the PNF SDN controller sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the access device.
- the PNF SDN controller needs to obtain the MAC address of the user equipment in advance before generating the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second packet.
- the process may be: the first packet sent by the user equipment to the access device is carried on the Ethernet frame, and the source MAC address in the frame header of the Ethernet frame is the MAC address of the user equipment, and the access device receives the first packet.
- the packet extracts the source MAC address from the frame header of the Ethernet frame and sends the MAC address to the PNF SDN controller.
- the PNF SDN controller generates an IP address based on the IP address or IP address prefix and the MAC address of the user equipment. Or a mapping table between the IP address prefix and the MAC address of the user equipment.
- the PNF SDN controller can send the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the access table. device.
- the PNF SDN controller can send the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the access device through the OpenFlow or NETCONF management or control protocol, so that the access device receives the A mapping table between the IP address or the IP address prefix and the MAC address of the user equipment generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment, thereby preventing the impersonation of the IP address or the IP address prefix, and The impersonation of the MAC address improves the security of the network device.
- any one of a PNF SDN controller and an NVF SDN controller may generate a mapping table between an IP address allocated to the user equipment and a MAC address of the user equipment, and send the generated mapping table. Save it to the other party.
- the first packet is used as the first DHCP packet as an example.
- FIG. 4 is further provided by the embodiment of the present application.
- a schematic diagram of a data transmission method which may include:
- the access device receives the first DHCP packet sent by the user equipment.
- the first DHCP message is used to request the DHCP server to allocate an IP address or an IP address prefix to the user equipment.
- the access device sends the first DHCP packet and the access loop identifier to the PNF SDN controller, where the access loop identifier is used to identify that the access device receives the first DHCP packet.
- the physical port or logical port of the access device is used to identify that the access device receives the first DHCP packet.
- the access device receives the first DHCP packet to generate an access loop identifier corresponding to the first DHCP packet, where the access loop identifier is used to identify the physical port of the access device that receives the first DHCP packet. Or logical port.
- the access device receives the first DHCP packet sent by the user equipment, and generates the corresponding access loop identifier in the format of: Access-Node-Identifier eth slot/ Port[:vlan-id].
- the access device creates a first OpenFlow message, and extends the OpenFlow so that the first OpenFlow message (such as a packet-in message) carries the first DHCP message and the access ring identifier of the corresponding access device;
- the first OpenFlow message also carries the MAC address of the user equipment that sends the first DHCP message.
- the PNF SDN controller generates a second DHCP packet according to the access loop identifier and the first DHCP packet.
- the PNF SDN controller receives the access loop identifier and the first DHCP packet from the first OpenFlow message, and adds the access loop identifier to the field options(82) of the first DHCP packet, thereby generating
- the second DHCP message or the PNF SDN controller obtains the access loop identifier and the first DHCP packet from the first OpenFlow message, and creates a second DHCP message.
- the DHCP packet can be a DHCP Discover message or a DHCP Request.
- the access loop identifier is added in the field options(82) of the first DHCP Discover message, so that the second DHCP Discover message is generated.
- the PNF SDN controller sends the second DHCP message to the VNF SDN controller.
- the second DHCP packet includes an access loop identifier.
- the PNF SDN controller sends the second packet to the VNF SDN controller through two possible implementation manners, as follows:
- the PNF SDN controller sends the second message to the VNF SDN controller through an interconnection interface between the PNF SDN controller and the VNF SDN controller.
- the PNF SDN controller and the VNF SDN controller are interconnected by a commonly supported communication protocol.
- the PNF SDN controller sends the second packet to the VNF SDN controller through the upper controller.
- the upper controller may be a synapse, and the PNF SDN controller forwards the first OpenFlow message to the VNF SDN controller through the synoplator.
- the access device After receiving the first DHCP packet, the access device does not need to process the first DHCP packet and the access loop identifier, but only needs to send the first DHCP packet and the access loop identifier.
- the PNF SDN controller is configured to process the first DHCP message and the access loop identifier by the PNF SDN controller to generate a second DHCP message, and then send the second DHCP message to the VNF SDN control.
- the VNF SDN controller sends the second DHCP message to the DHCP server, and the IP address or IP address prefix is allocated to the user equipment through the DHCP server, thereby reducing the complexity of the access device.
- the PNF SDN controller sends a second DHCP message to the VNF SDN controller, and the PNF SDN controller interacts with the VNF SDN controller to prevent the second DHCP message from being accessed by the access device and the IP edge device. Forwarded to the VNF SDN controller, which improves the efficiency of data transmission.
- the VNF SDN controller acquires the access loop identifier in the second DHCP packet.
- the VNF SDN controller sends an AAA authentication request message to the AAA server.
- the AAA authentication request packet includes an access loop identifier.
- AAA authentication can be RADIUS or DIAMETER for authentication.
- the VNF SDN controller receives the AAA authorization response packet sent by the AAA server.
- the VNF SDN controller sends the second DHCP packet to the DHCP server. Therefore, in the embodiment of the present application, the VNF SDN controller can directly receive the second packet sent by the PNF SDN controller, and implement direct interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding the connection. The ingress device and the IP edge device forward the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- the DHCP server allocates an IP address or an IP address prefix to the user equipment according to the second DHCP message.
- the DHCP server sends a response packet of the second DHCP packet to the VNF SDN controller.
- the response packet of the second DHCP packet includes an access loop identifier and an IP address or an IP address prefix allocated to the user equipment.
- the VNF SDN controller sends the response packet of the second DHCP packet to the PNF SDN controller.
- the PNF SDN controller separates and obtains an access loop identifier from the response packet of the second DHCP packet.
- the PNF SDN controller separates and obtains the access loop identifier from the response packet of the second DHCP packet, and generates a third DHCP packet, where the third DHCP packet includes a DHCP server to allocate the user equipment. IP address or IP address prefix.
- the PNF SDN controller sends the access loop identifier and the IP address or IP address prefix assigned by the user equipment to the access device.
- the PNF SDN controller sends a second OpenFlow message to the access device, where the second OpenFlow message includes an access loop identifier and a prefix of an IP address or an IP address assigned to the user equipment.
- the access device sends an IP address or an IP address prefix to the user equipment according to the access loop identifier, so as to complete processing and transmission of the first DHCP packet.
- the S411VNF SDN controller may further include:
- the VNF SDN controller generates and sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second DHCP message.
- the IP edge device generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment, thereby preventing the mapping table.
- the impersonation of the IP address or IP address prefix and the impersonation of the MAC address improve the security of the network device.
- the VNF SDN controller needs to obtain the MAC address of the user equipment in advance, and obtain the MAC address of the user equipment. For the acquisition, refer to S208, and the description is not repeated here.
- the S413PNF SDN controller may further include:
- the PNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second DHCP message.
- the PNF SDN controller sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the access device.
- the access device generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment.
- the access device can generate a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment. Therefore, the impersonation of the IP address or the IP address prefix and the impersonation of the MAC address are prevented, thereby improving the security of the network device.
- the PNF SDN controller needs to obtain the MAC address of the user equipment in advance, and obtain the MAC address of the user equipment. For the acquisition, refer to S208, and the description is not repeated here.
- the first packet may be an RS packet, and the first packet may be the first RS packet as an example.
- FIG. 5 A schematic diagram of a data transmission method, which may include:
- the access device receives the first RS packet sent by the user equipment.
- the first RS packet is used to request the DHCP server to allocate an IP address or an IP address prefix to the user equipment.
- the access device sends the first RS packet and the access loop identifier to the PNF SDN controller.
- the access loop identifier is used to identify a physical port or a logical port that the access device receives the first RS packet. For example, in the DSL/Ethernet access system, the access device receives the first RS packet sent by the user equipment, and generates the corresponding access loop identifier in the format of: Access-Node-Identifier eth slot/ Port[:vlan-id].
- the access device creates a first OpenFlow message, and extends the OpenFlow so that the first OpenFlow message (such as a packet-in message) carries the first RS message and the access ring identifier of the corresponding access device;
- the first OpenFlow message also carries the MAC address of the user equipment that sends the first RS message.
- the PNF SDN controller generates a second RS packet according to the access loop identifier and the first RS packet.
- the PNF SDN controller receives the access loop identifier and the first RS packet, and adds the access loop identifier to the field options(82) of the first RS packet to generate the second RS packet.
- the PNF SDN controller obtains the access loop identifier and the first RS packet from the first OpenFlow message, and creates a second RS packet.
- the RS packet can be an RS Discover message or an RS Request.
- the access loop identifier is added in the field options (82) of the first RS Discover message, thereby generating a second RS Discover message.
- the PNF SDN controller sends the second RS message to the VNF SDN controller.
- the second RS packet includes an access loop identifier.
- the PNF SDN controller sends the second RS packet to the VNF SDN controller through two possible implementation manners, as follows:
- the PNF SDN controller sends the second RS message to the VNF SDN controller through an interconnection interface between the PNF SDN controller and the VNF SDN controller.
- the PNF SDN controller and the VNF SDN controller are interconnected by a commonly supported communication protocol.
- the PNF SDN controller sends the second RS message to the VNF SDN controller through the upper controller.
- the upper controller may be a synapse, and the PNF SDN controller forwards the first OpenFlow message to the VNF SDN controller through the synoplator.
- the access device After receiving the first RS packet, the access device does not need to process the first RS packet and the access loop identifier, but only needs to send the first RS packet and the access loop identifier.
- the PNF SDN controller is configured to process the first RS packet and the access loop identifier by the PNF SDN controller to generate a second RS packet, and then send the second RS packet to the VNF SDN control.
- the VNF SDN controller sends the second RS packet to the DHCP server, and the IP address or IP address prefix is allocated to the user equipment through the DHCP server, thereby reducing the complexity of the access device.
- the PNF SDN controller sends a second RS packet to the VNF SDN controller, and the PNF SDN controller interacts with the VNF SDN controller to avoid the second RS packet passing through the access device and the IP edge device. Forwarded to the VNF SDN controller, which improves the efficiency of data transmission.
- the VNF SDN controller acquires the access loop identifier in the second RS packet.
- the VNF SDN controller sends an AAA authentication request message to the AAA server.
- the AAA authentication request packet includes an access loop identifier.
- the VNF SDN controller receives the AAA authorization response packet sent by the AAA server.
- the VNF SDN controller sends the second RS packet to the DHCP server.
- the VNF SDN controller can directly receive the second packet sent by the PNF SDN controller, and implement direct interaction between the PNF SDN controller and the VNF SDN controller, thereby avoiding the connection.
- the ingress device and the IP edge device forward the second packet to the VNF SDN controller, thereby improving data transmission efficiency.
- the DHCP server allocates an IP address or an IP address prefix to the user equipment according to the second RS message.
- the DHCP server sends a response packet of the second RS packet to the VNF SDN controller.
- the response packet of the second RS packet includes an access loop identifier and an IP address or an IP address prefix allocated to the user equipment.
- the VNF SDN controller sends the response packet of the second RS packet to the PNF SDN controller.
- the S512 and the PNF SDN controller obtain the access loop identifier by separating from the response packet of the second RS packet.
- the PNF SDN controller sends the access loop identifier and an IP address or an IP address prefix allocated by the user equipment to the access device.
- the PNF SDN controller sends a second OpenFlow message to the access device, where the second OpenFlow message includes an access loop identifier and a prefix of an IP address or an IP address assigned to the user equipment.
- the access device sends an IP address or an IP address prefix to the user equipment according to the access loop identifier, so as to complete processing and transmission of the first RS packet.
- the method further includes:
- the VNF SDN controller generates and sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second RS packet.
- the IP edge device generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment, thereby preventing the mapping table.
- the impersonation of the IP address or IP address prefix and the impersonation of the MAC address improve the security of the network device.
- the VNF SDN controller needs to obtain the MAC address of the user equipment in advance before the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment is generated according to the response packet of the second RS packet.
- the mapping table between the IP address or the IP address prefix and the MAC address of the user equipment is generated according to the response packet of the second RS packet.
- the S513PNF SDN controller may further include:
- the PNF SDN controller generates a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response packet of the second RS packet.
- the PNF SDN controller sends a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment to the access device.
- the access device generates a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment.
- the access device can generate a mapping table between the local IP address or the IP address prefix and the MAC address of the user equipment according to the mapping table between the received IP address or the IP address prefix and the MAC address of the user equipment. Therefore, the impersonation of the IP address or the IP address prefix and the impersonation of the MAC address are prevented, thereby improving the security of the network device.
- the PNF SDN controller needs to obtain the MAC address of the user equipment in advance, and obtain the MAC address of the user equipment. For the acquisition, refer to S208, and the description is not repeated here.
- FIG. 6 is a schematic structural diagram of a PNF SDN controller 60 according to an embodiment of the present disclosure.
- the PNF SDN controller 60 may include:
- the receiving unit 601 is configured to receive the first packet and the access loop identifier sent by the first network device, where the access loop identifier is used to identify that the first network device receives the first packet The physical or logical port of a network device.
- the generating unit 602 is configured to generate a second packet according to the access loop identifier and the first packet.
- the sending unit 603 is configured to send the second packet to the virtual network function software definition network VNF SDN controller, so that the VNF SDN controller sends the second packet to the second network device, and the second packet is used to request the second packet.
- the network device assigns an IP address or an IP address prefix to the user equipment.
- the receiving unit 601 is further configured to receive a response packet of the second packet sent by the VNF SDN controller, where the response packet of the second packet includes an access loop identifier, and the second network device is The IP address or IP address prefix assigned to the user device.
- the sending unit 603 is further configured to send the access loop identifier and the IP address or IP address prefix allocated by the user equipment to the first network device.
- the sending unit 603 is specifically configured to send the second packet to the VNF SDN controller by using an interconnection interface between the PNF SDN controller 60 and the VNF SDN controller.
- the sending unit 603 is specifically configured to send the second packet to the VNF SDN controller by using the upper controller.
- the generating unit 602 is further configured to generate, according to the response message of the second packet, a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment.
- the sending unit 603 is further configured to send, to the first network device, a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment.
- the receiving unit 601 receives the first packet and the access loop identifier sent by the access device, for example, the first DHCP packet and the access loop identifier or the first RS packet.
- the ingress loop identifier where the access loop identifier is an identifier of a physical port or a logical port on the access device capable of uniquely identifying the access device and receiving the message.
- the generating unit 602 adds the access loop identifier to the first packet to generate a second packet; or, the generating unit 602 identifies the access loop according to the The first packet is a new packet, and the second packet carries the access loop identifier and the first packet.
- the types of the first packet and the second packet may be the same or different.
- the sending unit 603 may send the second packet to the VNF SDN controller through the interconnection interface between the PNF SDN controller 60 and the VNF SDN controller, and send the second packet to the VNF SDN controller, and the sending unit 603 sends the second packet to the VNF SDN controller.
- the second packet may be the same as the first packet type, or may be different.
- the type of the second packet may be determined according to a communication protocol between the PNF SDN controller 60 and the VNF SDN controller.
- the sending unit 603 may specifically send the second packet to the VNF SDN controller by using the upper controller.
- the PNF SDN controller 60 sends the second message to the VNF SDN controller via the synapse.
- the receiving unit 601 is specifically configured to receive the MAC address of the user equipment that is sent by the access device, and the method for obtaining the MAC address of the user equipment by the access device may refer to the method in FIG.
- the first packet and the access loop identifier may be included in the OpenFlow OpenFlow message.
- the PNF SDN controller 60 can be operated on a server device or a telecommunication device, for example, in a product form, or can be a standalone device.
- the PNF SDN controller in the foregoing embodiment of the present invention is applicable to the PNF SDN60 controller of the present embodiment.
- the foregoing detailed description of the packet processing method can be clearly understood by those skilled in the art.
- the implementation method of the PNF SDN60 controller in this embodiment is known, so for the sake of brevity of the description, it will not be described in detail herein.
- FIG. 7 is a schematic structural diagram of a VNF SDN controller 70 according to an embodiment of the present disclosure.
- the VNF SDN controller 70 may include:
- the receiving unit 701 is configured to receive the second packet sent by the PNF SDN controller, where the second packet is generated by the PNF SDN controller according to the access loop identifier and the first packet.
- the sending unit 702 is configured to send the second packet to the second network device, where the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment, where the access loop identifier is used to identify A network device receives a physical port or a logical port of the first network device of the first packet.
- the receiving unit 701 is further configured to receive a response packet of the second packet sent by the second network device, where the response packet of the second packet includes an access loop identifier, and the second network device is The IP address or IP address prefix assigned to the user device.
- the sending unit 702 is further configured to send the response message of the second packet to the PNF SDN controller.
- the receiving unit 701 is specifically configured to receive, by using an interconnection interface between the VNF SDN controller 70 and the PNF SDN controller, a second packet sent by the PNF SDN controller.
- the receiving unit 701 is specifically configured to receive, by using the upper controller, the second packet sent by the PNF SDN controller.
- the VNF SDN controller 70 may further include:
- the generating unit 703 is configured to generate a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment according to the response message of the second packet.
- the sending unit 702 is further configured to send, to the third network device, a mapping table between the IP address or the IP address prefix and the MAC address of the user equipment.
- the VNF SDN controller 70 may further include:
- the obtaining unit 704 is configured to obtain an access loop identifier in the second packet.
- the sending unit 702 is further configured to send an authentication request message to the fourth network device, where the authentication request message includes an access loop identifier.
- the receiving unit 701 is further configured to receive an authorization response message sent by the fourth network device.
- the VNF SDN controller 70 can be operated on a server device or a telecommunication device, for example, in a product form, or can be a standalone device.
- FIG. 8 is a schematic structural diagram of another PNF SDN controller 80 according to an embodiment of the present disclosure.
- the PNF SDN controller 80 may include:
- the communication interface 803 is configured to receive the first packet and the access loop identifier sent by the first network device, where the access loop identifier is used to identify that the first network device receives the first packet.
- the physical port or the logical port of the first network device sends the generated second packet to the VNF SDN controller.
- the communication interface 803 is further configured to receive a response packet of the second packet sent by the VNF SDN controller, where the response packet of the second packet includes the access loop Identifying an IP address or an IP address prefix assigned to the user equipment, and sending the access loop identifier and the IP address or IP address prefix assigned by the user equipment to the first network device, to the first network device Sending a mapping table between the IP address or IP address prefix and the MAC address of the user equipment.
- a processor 802 configured to execute a program stored in the memory, when the program is executed, the processor is configured to generate a second packet according to the access loop identifier and the first packet, where the second packet includes The first packet and the access loop identifier are processed; the response packet of the second packet is processed, and the access loop identifier is separated from the response packet of the second packet, and the first packet is generated.
- the third packet includes the access loop identifier and the response packet of the second packet.
- the processor 802 is further configured to generate, according to the response message of the second packet, a mapping table between the IP address or an IP address prefix and a MAC address of the user equipment.
- the PNF SDN controller may further include a memory 801 for storing a program.
- bus architecture (represented by bus 804), which may include any number of interconnected buses and bridges, the bus 804 will include memory and communications represented by one or more processors 802 and memory 801 represented by processor 802.
- the various circuits of interface 803 are linked together.
- the bus 804 can also link various other circuits, such as peripherals, voltage regulators, and power management circuits, as is known in the art, and therefore, will not be further described herein.
- FIG. 9 is a schematic structural diagram of another VNF SDN controller 90 according to an embodiment of the present disclosure.
- the VNF SDN controller 90 may include:
- the communication interface 903 is configured to receive a second packet sent by the PNF SDN controller of the physical network function software definition network, where the second packet is generated by the PNF SDN controller according to the access loop identifier and the first packet. Sending the second packet to the second network device, where the second packet is used to request the second network device to allocate an IP address or an IP address prefix to the user equipment, where the access loop identifier is used for Identifying a physical port or a logical port of the first network device that the first network device receives the first packet.
- the communication interface 903 is further configured to receive a response packet of the second packet sent by the second network device, where the response packet of the second packet includes the access loop identifier and The IP address or IP address prefix assigned to the user equipment; the response message of the second packet is sent to the PNF SDN controller; the MAC address of the user equipment sent by the PNF SDN controller is received; and the third network device is sent to the third network device.
- the authentication request packet includes the access loop identifier, and receives an authorization response packet sent by the fourth network device.
- the VNF SDN controller may further include a memory 901, configured to store a program.
- the VNF SDN controller may further include a processor 902, configured to execute a program stored in the memory, when the program is executed, the processor is configured to generate the IP address according to the response message of the second packet. Or a mapping table between the IP address prefix and the MAC address of the user equipment.
- bus 904 can include any number of interconnected buses and bridges, and bus 904 will include one or more processors 902 represented by processor 902 and memory 901 represented by memory 901 and The various circuits of communication interface 903 are linked together.
- the bus 904 can also link various other circuits, such as peripherals, voltage regulators, and power management circuits, as is known in the art, and therefore, will not be further described herein.
- VNF SDN controller in the foregoing embodiment of the present invention is applicable to the VNF SDN controller 90 of the present embodiment.
- the foregoing detailed description of the packet processing method may be used by those skilled in the art.
- the implementation method of the VNF SDN controller 90 in this embodiment is clearly known, so for the sake of brevity of the description, it will not be described in detail herein.
- FIG. 10 is a schematic structural diagram of a data transmission system 100 according to an embodiment of the present disclosure.
- the data transmission system 100 may include:
- the PNF SDN controller 1001 in the foregoing embodiment of the present invention, the message processing method, the VNF SDN controller 1002, the message processing method, and the specific example are also applicable to the data transmission system of the embodiment, and the packet processing is performed by the foregoing.
- the implementation method of the data transmission system 100 in this embodiment can be clearly understood by those skilled in the art, and therefore, for the sake of brevity of the description, it will not be described in detail herein.
- embodiments of the present application can be provided as a method, system, or computer program product.
- the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment in combination of software and hardware.
- the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
- the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
- These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
- the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
- the above embodiments it may be implemented in whole or in part by software, hardware, firmware, or any combination thereof.
- software it may be implemented in whole or in part in the form of a computer program product.
- the computer program product includes one or more computer instructions.
- the computer program instructions When the computer program instructions are loaded and executed on a computer, the processes or functions described in accordance with embodiments of the present invention are generated in whole or in part.
- the computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable device.
- the computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be from a website site, computer, server or data center Transfer to another website site, computer, server, or data center by wire (eg, coaxial cable, fiber optic, digital subscriber line (DSL), or wireless (eg, infrared, wireless, microwave, etc.).
- the computer readable storage medium can be any available media that can be accessed by a computer or a data storage device such as a server, data center, or the like that includes one or more available media.
- the usable medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (such as a solid state disk (SSD)).
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Theoretical Computer Science (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Computer Security & Cryptography (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本申请提供一种数据传输方法、PNF SDN控制器、VNF SDN控制器及系统,该数据传输方法包括:PNF SDN控制器接收第一网络设备发送的第一报文和接入环路标识;PNF SDN控制器根据接入环路标识和第一报文生成第二报文;PNF SDN控制器将第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使VNF SDN控制器将第二报文发送给第二网络设备,第二报文用于请求第二网络设备为用户设备分配IP地址或IP地址前缀,降低网络设备的复杂度。
Description
本申请要求于2017年9月11日提交中国专利局、申请号为201710814496.X、申请名称为“一种数据传输方法、PNF SDN控制器、VNF SDN控制器及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及一种数据传输方法、PNF SDN控制器、VNF SDN控制器及系统。
用户接入系统中的网络设备可以包括用户设备、接入设备、交换机或、互联网协议(Internet Protocol,IP)边缘设备。以处理和传输动态主机配置协议(Dynamic Host Configuration Protocol,DHCP)消息/路由器请求(Router Solicitation,RS)消息为例:
接入设备在接收到用户设备发送的第一DHCP/RS报文,生成接入环路标识,并将接入环路标识添加在第一DHCP/RS报文中,生成第二DHCP/RS报文,再将第二DHCP/RS报文转发给交换机,以通过交换机及互联网协议(Internet Protocol,IP)边缘设备将第二DHCP/RS报文发送给DHCP服务器,以请求DHCP服务器为用户设备分配IP地址或IP地址前缀。DHCP服务器为用户设备分配IP地址或IP地址前缀,并根据接入环路标识将携带有IP地址或IP地址前缀的DHCP/RS响应报文发送给用户设备。
然而,对于不同的运营商而言,用户设备对应的接入环路标识的格式会有所不同,因此,网络设备均需要针对不同运营商进行定制,使得网络设备的复杂度较高。
发明内容
本申请涉及一种数据传输方法、PNF SDN控制器、VNF SDN控制器及系统,以降低网络设备的复杂度。
第一方面,本申请实施例提供一种数据传输方法,该数据传输方法可以包括:
物理网络功能软件定义网络PNF SDN控制器接收第一网络设备发送的第一报文和接入环路标识,其中,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
PNF SDN控制器根据所述接入环路标识和第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识。
PNF SDN控制器将第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使VNF SDN控制器将第二报文发送给第二网络设备。第二报文用于请求第二网络设备为所述用户设备分配互联网协议IP地址或IP地址前缀。
由此可见,在本申请实施例中,在处理和传输第一报文的过程中,接入设备在接收到第一报文之后,无需对该第一报文和接入环路标识进行处理,而只需要将第一报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一报文和接入环路标识进行处理,以生成第 二报文,之后,再将第二报文发送给VNF SDN控制器,以使VNF SDN控制器将第二报文发送给DHCP服务器,并通过该DHCP服务器为用户设备分配IP地址或IP地址前缀,从而降低了接入设备的复杂度。此外,PNF SDN控制器可以直接将第二报文发送给VNF SDN控制器,实现了PNF SDN控制器与VNF SDN控制器之间的交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
在一种可能的实现方式中,PNF SDN控制器将第二报文发送给所述VNF SDN控制器之后,该方法还可以包括:
PNF SDN控制器接收VNF SDN控制器发送的对应第二报文的响应报文。第二报文的响应报文包括所述接入环路标识及为所述用户设备分配的IP地址或IP地址前缀。
PNF SDN控制器向第一网络设备发送所述接入环路标识和所述第二网络设备为用户设备分配的IP地址或IP地址前缀。
由此可见,实现了PNF SDN控制器与VNF SDN控制器之间的交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
在一种可能的实现方式中,PNF SDN控制器将第二报文发送给VNF SDN控制器,可以包括:
PNF SDN控制器通过PNF SDN控制器与VNF SDN控制器之间的互联接口将第二报文直接发送给VNF SDN控制器,实现了PNF SDN控制器与VNF SDN控制器之间的直接交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
在一种可能的实现方式中,PNF SDN控制器将第二报文发送给VNF SDN控制器,可以包括:
PNF SDN控制器通过上级控制器将第二报文发送给VNF SDN控制器。
在一种可能的实现方式中,PNF SDN控制器接收VNF SDN控制器发送的第二报文的响应报文之后,该方法还可以包括:
PNF SDN控制器根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
PNF SDN控制器向第一网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
第二方面,本申请实施例提供一种数据传输的方法,该数据传输方法可以包括:
虚拟网络功能软件定义网络VNF SDN控制器接收PNF SDN控制器发送的第二报文。第二报文是PNF SDN控制器根据接入环路标识和第一报文生成的。
VNF SDN控制器将第二报文发送给第二网络设备。第二报文用于请求第二网络设备为用户设备分配IP地址或IP地址前缀。所述接入环路标识用于标识第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
由此可见,在本申请实施例中,VNF SDN控制器可以直接接收PNF SDN控制器发送的第二报文,实现了PNF SDN控制器与VNF SDN控制器之间的直接交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
在一种可能的实现方式中,VNF SDN控制器将第二报文发送给第二网络设备之后,该方法还可以包括:
VNF SDN控制器接收第二网络设备发送的对应第二报文的响应报文,第二报文的响应报文包括所述接入环路标识及所述第二网络设备为用户设备分配的IP地址或IP地址前缀。
VNF SDN控制器将第二报文的响应报文发送给PNF SDN控制器。
在一种可能的实现方式中,VNF SDN控制器接收PNF SDN控制器发送的第二报文,可以包括:
VNF SDN控制器通过VNF SDN控制器与PNF SDN控制器之间互联接口接收PNF SDN控制器发送的第二报文,实现了PNF SDN控制器与VNF SDN控制器之间的直接交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
在一种可能的实现方式中,VNF SDN控制器接收PNF SDN控制器发送的第二报文,可以包括:
VNF SDN控制器通过上级控制器接收PNF SDN控制器发送的第二报文。
在一种可能的实现方式中,VNF SDN控制器接收第二网络设备发送的第二报文的响应报文之后,该方法还可以包括:
VNF SDN控制器根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
VNF SDN控制器向第三网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
在一种可能的实现方式中,VNF SDN控制器将第二报文发送至第第二网络设备之前,该方法还可以包括:
VNF SDN控制器获取第二报文中的所述接入环路标识。
VNF SDN控制器向第四网络设备发送认证请求报文,认证请求报文包括所述接入环路标识。
VNF SDN控制器接收第四网络设备发送的授权响应报文,从而完成用户身份的验证和授权。
第三方面,本申请实施例提供一种物理网络功能软件定义网络PNF SDN控制器,可以包括:
接收单元用于接收第一网络设备发送的第一报文和接入环路标识,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
生成单元用于根据所述接入环路标识和第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识。
发送单元用于将第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使VNF SDN控制器将第二报文发送给第二网络设备,第二报文用于请求第二网络设备为所述用户设备分配IP地址或IP地址前缀。
在一种可能的实现方式中,接收单元还用于接收VNF SDN控制器发送的第二报文的响应报文,第二报文的响应报文包括所述接入环路标识及所述第二网络设备为所述为用户设备分配的IP地址或IP地址前缀。
发送单元还用于向第一网络设备发送所述接入环路标识和所述第二网络设备为用户设备分配的IP地址或IP地址前缀。
在一种可能的实现方式中,发送单元具体用于通过PNF SDN控制器与VNF SDN控制器之间的互联接口将第二报文发送给VNF SDN控制器。
在一种可能的实现方式中,发送单元具体用于通过上级控制器将第二报文发送给VNF SDN控制器。
在一种可能的实现方式中,生成单元还用于根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
发送单元,还用于向第一网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
第四方面,本申请实施例还提供一种虚拟网络功能软件定义网络VNF SDN控制器,可以包括:
接收单元用于接收PNF SDN控制器发送的第二报文。第二报文是PNF SDN控制器根据接入环路标识和第一报文生成的。
发送单元用于将第二报文发送给第二网络设备。第二报文用于请求第二网络设备为用户设备分配IP地址或IP地址前缀,所述接入环路标识用于标识第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
在一种可能的实现方式中,接收单元还用于接收第二网络设备发送的对应第二报文的响应报文。第二报文的响应报文包括所述接入环路标识及为用户设备分配的IP地址或IP地址前缀。
发送单元,还用于将第二报文的响应报文发送给PNF SDN控制器。
在一种可能的实现方式中,接收单元具体用于通过VNF SDN控制器与PNF SDN控制器之间互联接口接收PNF SDN控制器发送的第二报文。
在一种可能的实现方式中,接收单元具体用于通过上级控制器接收PNF SDN控制器发送的第二报文。
在一种可能的实现方式中,该VNF SDN控制器还可以包括生成单元。
生成单元用于根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
发送单元还用于向第三网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
在一种可能的实现方式中,该VNF SDN控制器还可以包括:
获取单元用于获取第二报文中的所述接入环路标识。
发送单元还用于向第四网络设备发送认证请求报文,认证请求报文包括所述接入环路标识。
接收单元还用于接收第四网络设备发送的授权响应报文。
第五方面,本申请实施例还提供一种物理网络功能软件定义网络PNF SDN控制器,该PNF SDN控制器可以包括:
通信接口,用于接收第一网络设备发送的第一报文和接入环路标识,将生成的第二报文发送给VNF SDN控制器,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
可选的,所述通信接口还可以用于接收所述VNF SDN控制器发送的所述第二报文的响应报文,所述第二报文的响应报文包括所述接入环路标识及为用户设备分配的IP地址或IP地址前缀,向所述第一网络设备发送所述接入环路标识和所述用户设备分配的IP地址或IP地址前缀,向所述第一网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
可选的,所述PNF SDN控制器还可以包括存储器,用于存储程序。
处理器,用于执行存储器存储的程序,当程序被执行时,处理器用于根据所述接入环路标识和所述第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识;处理所述第二报文的响应报文,将所述接入环路标识分理出所述第二报文的响应报文。
可选的,所述处理器还用于根据所述第二报文的响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
第六方面,本申请实施例还提供一种虚拟网络功能软件定义网络VNF SDN控制器,该VNF SDN控制器可以包括:
通信接口,用于接收物理网络功能软件定义网络PNF SDN控制器发送的第二报文,所述第二 报文是所述PNF SDN控制器根据接入环路标识和第一报文生成的,将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为用户设备分配IP地址或IP地址前缀,其中,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
可选的,所述通信接口还可以用于接收所述第二网络设备发送的第二报文的响应报文,所述第二报文的响应报文包括所述接入环路标识及为用户设备分配的IP地址或IP地址前缀;将所述第二报文的响应报文发送给所述PNF SDN控制器;接收PNF SDN控制器发送的用户设备的MAC地址;向第三网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;获取所述第二报文中的所述接入环路标识;向第四网络设备发送认证请求报文,所述认证请求报文包括所述接入环路标识;接收所述第四网络设备发送的授权响应报文。
可选的,所述VNF SDN控制器还可以包括存储器,用于存储程序。
可选的,所述VNF SDN控制器还可以包括处理器,用于执行存储器存储的程序,当程序被执行时,处理器用于根据所述第二报文的响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
第七方面,本申请实施例还提供一种数据传输的系统,其特征在于,该系统包括:
上述第三方面或者第三方面任意一种可能的实现方式提供的PNF SDN控制器和上述第四方面或者第四方面任意一种可能的实现方式提供的VNF SDN控制器。
第八方面,本申请的又一方面提供了一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行上述各方面所述的方法。
本申请实施例提供的数据传输方法、PNF SDN控制器、VNF SDN控制器及系统中,PNF SDN控制器接收接入设备发送的第一报文和接入环路标识;根据接入环路标识和第一报文生成第二报文;并将第二报文发送给VNF SDN控制器,VNF SDN控制器接收PNF SDN控制器发送的第二报文,将第二报文发送给DHCP服务器,以请求DHCP服务器为用户设备分配IP地址或IP地址前缀。由此可见,本申请实施例提供的数据传输方法、PNF SDN控制器、VNF SDN控制器及数据传输系统,在处理和传输第一报文的过程中,接入设备在接收到第一报文之后,无需对该第一报文和接入环路标识进行处理,而只需要将第一报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一报文和接入环路标识进行处理,以生成第二报文,将第二报文发送给VNF SDN控制器,以使VNF SDN控制器将第二报文发送给网络服务器,并通过该网络服务器为用户设备分配IP地址或IP地址前缀,从而降低了接入设备的复杂度。此外,PNF SDN控制器在向VNFSDN控制器发送,可以直接将第二报文发送给VNF SDN控制器,实现了PNF SDN控制器与VNF SDN控制器之间的交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
图1为本申请提供的系统架构图;
图2为本申请实施例提供的一种数据传输方法的示意图;
图3为本申请实施例提供的另一种数据传输方法的示意图;
图4为本申请实施例提供的再一种数据传输方法的示意图;
图5为本申请实施例提供的又一种数据传输方法的示意图;
图6为本申请实施例提供的一种PNF SDN控制器的结构示意图;
图7为本申请实施例提供的一种VNF SDN控制器的结构示意图;
图8为本申请实施例提供的另一种PNF SDN控制器的结构示意图;
图9为本申请实施例提供的另一种VNF SDN控制器的结构示意图。
图10为本申请实施例提供的一种数据传输的系统的结构示意图。
在用户设备接入网络的场景中,图1所示的网络系统可以为数字用户线(Digital Subscriber Line,DSL)接入系统,也可以为以太网(Ethernet)接入系统,当然,也可以为无源光网络(Passive Optical Network,PON)接入系统。以用户设备请求获取IP地址的场景为例,接入网系统主要包括用户设备、接入设备、IP边缘设备、DHCP服务器等设备,用户设备经接入设备分别与IP边缘设备和DHCP服务器通信,接入设备与DHCP服务器之间可以有一个或多个中继设备,接入设备经一个或多个中继设备与DHCP服务器通信;接入设备也可以不经过中继设备而与DHCP服务器直接通信。用户设备可以为移动电话(或称为“蜂窝”电话)或具有移动终端的计算机,例如,可以是便携式、袖珍式、手持式、计算机内置的或者车载的移动装置等。用户设备也可以称为终端设备,移动台(mobile station,简称MS),终端(terminal),还可以包括用户单元(subscriber unit)、蜂窝电话(cellular phone)、智能电话(smart phone)、无线数据卡、个人数字助理(personal digital assistant,简称PDA)电脑、平板型电脑、无线调制解调器(modem)、手持设备(handheld)、膝上型电脑(laptop computer)、无绳电话(cordless phone)或者无线本地环路(wireless local loop,简称WLL)台、机器类型通信(machine type communication,简称MTC)终端等。接入设备主要用于用户设备接入网络实现用户设备对远程网络资源的访问,例如:接入设备可以为数字用户线接入复用器(Digital Subscriber Line Access Multiplexer,DSLAM)、光网络单元(Optical Network Unit,ONU)或光路终结点(Optical Line Termination,OLT)等。IP边缘设备主要用于接入设备和网络设备的数据包传输,可以是安装在网络边缘的交换机、路由器等设备,例如,IP边缘设备可以为宽带网络网关(Broadband Network Gateway,BNG)宽带接入服务器(Broadband Remote Access Server,BRAS)等。DHCP服务器主要负责IP地址或IP地址前缀的管理和分配等业务。
以上述用户设备请求IP地址为例,所述用户设备向DHCP服务器发送DHCP请求报文,该DHCP请求报文用于请求所述DHCP服务器为该用户设备分配IP地址或IP地址前缀。所述接入设备接收所述用户设备发送的所述DHCP请求报文,将所述DHCP请求报文以及与所述DHCP请求报文对应的接入环路标识发送给DHCP服务器。其中,接入环路标识(access loop identifier),又被称为接入线路标识(access line identifier),能够唯一标识接入设备和接收消息的接入设备上的物理端口或逻辑端口。所述DHCP服务器接收所述DHCP请求报文和所述接入环路标识,将分配给所述用户设备的IP地址或者IP地址前缀,以及所述接入环路标识发送给所述接入设备。所述接入设备接收所述IP地址或者IP地址前缀,以及所述接入环路标识,根据所述接入环路标识向所述用户设备发送所述分配给所述用户设备的IP地址或者IP地址前缀。在此过程中,由于需要将DHCP请求报文和接入环路标识一起发送给DHCP服务器,因此DHCP请求报文传输路径上的每个网络设备都需要支持DHCP和接入环路标识的处理功能,即例如DHCP报文传输路径上的DSLAM、路由器、BNG、交换机等网络设备都需要具备对DHCP报文和接入环路标识的处理功能,但对于不同 的运营商而言,其对应的接入环路标识的格式和内容并不相同,因此,网络设备均需要针对不同运营商进行定制,使得网络设备的复杂度较高,同时也深受版本及其升级的困扰。
为了简化网络设备的复杂程度,避免网络设备由于处理业务的原因变得更加复杂,软件定义网络(Software Defined Network,SDN)技术得到了广泛的应用。SDN技术可以使网络设备实现对业务的简单转发和处理,实现对网络设备的简化。而复杂的业务处理由控制器实现,这样就可以实现转发和控制相分离。同样,随着虚拟网络功能(Virtual Network Function,VNF)技术的发展,网络设备也在逐渐实现虚拟化。基于这些技术的发展,图1为本申请提供了一种应用场景示意图。该场景可以是接入网系统的架构示意图,图1的接入系统包括物理网络功能(Physical Network Function,PNF)软件定义网络(Software Defined Network,SDN)控制器、虚拟网络功能(Virtual Network Function,VNF)软件定义网络(Software Defined Network,SDN)控制器、用户设备、所述PNF SDN管理控制的接入设备、所述VNF SDN管理控制的IP网络边缘设备、用于提供IP地址或IP地址前缀的DHCP服务器。可选地,图1的接入网系统也可以包括连接所述接入设备和所述IP边缘设备的交换机。
在用户设备发送DHCP请求报文的场景中,当所述接入设备接收到所述用户设备发送的DHCP请求报文,所述接入设备将所述DHCP请求报文及该DHCP请求报文对应的接入环路标识转发给PNF SDN控制器;所述PNF SDN控制器接收所述接入设备发送的所述DHCP请求报文和所述接入环路标识,所述PNF SDN控制器根据所述DHCP请求报文和所述接入环路标识生成第二报文,例如,PNF SDN控制器接收所述接入环路标识和DHCP请求报文,将接入环路标识添加在第一DHCP报文的字段opt ions(82)中,从而生成第二报文,PNF SDN控制器集成了接入设备将所述接入环路标识添加到所述第一DHCP报文的功能。PNF SDN控制器将所述第二报文发送给所述接入设备。所述接入设备将所述第二报文发送到DHCP业务路径上的下一跳,比如网络设备A(图未示)。如果网络设备A由VNF SDN控制器控制管理,则网络设备A将所述第二报文发送给所述VNF SDN控制器,所述VNF SDN控制器处理所述第二报文并生成新的报文,例如,新的报文为第三报文,VNF SDN控制器对第二报文的处理过程可以是对报文添加内容并重新封装,也可以是解析报文并分离字段,例如VNF SDN控制器将设备对应的标识添加到第二报文中,VNF SDN控制器对第二报文的处理过程根据业务类型而确定,VNF SDN控制器也可以仅对接收到的报文进行转发不做任何处理,本申请对上述处理过程不做限定。VNF SDN控制器将第三报文发送给IP边缘设备,IP边缘设备将第三报文按照DHCP业务路径发送给网络设备A的下一跳,比如网络设备B。由此可知,用户设备发送的DHCP请求报文在业务路径上传输的过程中,DHCP业务路径上的各个网络节点需要将接收到的DHCP请求报文转发给PNF SDN控制器或者VNF SDN控制器,经过PNF SDN控制器或者VNF SDN控制器处理后将报文再发送给所述网络设备,由所述网络设备继续按照报文的业务路径传输。这样,会增加报文传输的复杂程度,增加网络负担,不利于对网络节点的简化。
可选地,PNF SDN控制器也可将所述接入环路标识和第一报文分别发送给VNF SDN控制器。VNF SDN控制器可以将所述接入环路标识和第一报文封装到同一个报文里发送给DHCP服务器,也可以分别将所述接入环路标识和第一报文发送给DHCP服务器。
为了简化报文传输流程,也为了降低网络设备的复杂度,减少网络负担,本申请提供了一种数据传输的方法。图1为本申请实施例提供一种应用场景示意图,具体请参见图1所示,该通信系统可以包括用户设备、接入设备、IP边缘设备、DHCP服务器、PNF SDN控制器及VNF SDN控制器,所述用户设备可以经由所述接入设备与所述DHCP服务器通信,所述用户设备也可以经由所述 接入设备和中继设备与所述DHCP服务器通信;所述PNF SDN控制器可以分别与DHCP路径上的每个物理网络设备通信,所述VNF SDN控制器可以分别与DHCP路径上的每个虚拟网络设备通信,所述PNF SDN控制器与所述VNF SDN控制器通信。其中,接入设备可以称为第一网络设备,DHCP服务器可以称为第二网络设备。该方法包括:所述用户设备向第一网络设备发送第一报文;所述第一网络设备接收所述第一报文,并将所述第一报文以及与所述第一报文对应的接入环路标识发送给所述PNF SDN控制器,其中,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口;所述PNF SDN控制器接收所述第一网络设备发送的所述第一报文和所述接入环路标识,并根据该接入环路标识和该第一报文生成第二报文。该PNF SDN控制器将该第二报文发送给所述VNF SDN控制器,所述第二报文用于请求第二网络设备为所述用户设备分配IP地址或IP地址前缀。由此可见,本申请实施例提供的数据传输方法,在处理和传输所述第一报文的过程中,所述第一网络设备接收到所述第一报文,不对该第一报文和接入环路标识进行处理,而只将第一报文和接入环路标识发送给PNF SDN控制器,由该PNF SDN控制器对所述第一报文和接入环路标识进行处理,生成所述第二报文。所述PNF SDN控制器将所述第二报文发送给VNF SDN控制器,VNF SDN控制器将第二报文转发给第二网络设备。该第二网络设备将为用户设备分配IP地址或IP地址前缀以及所述接入环路标识以第二报文响应报文的形式发送给VNF SDN控制器,VNF SDN控制器将获得的所述第二报文的响应报文发送给PNF SDN控制器。PNF SDN控制器解析所述第二报文的响应报文,将所述接入环路标识和分配的IP地址或IP地址前缀发送给所述接入设备。在上述过程中不再需要网络设备,例如接入设备对接入环路标识进行处理,并且该PNF SDN控制器可以将生成的第二报文发送给VNF SDN控制器,可以实现PNF SDN控制器与PNF SDN控制器的通信,不需要再通过接入设备与的之间的业务路径传输第二报文,简化流程,减小网络负担,并且降低了接入设备的复杂度。
可选的,所述PNF SDN控制器将所述第二报文发送给所述VNF SDN控制器包括:所述PNF SDN控制器通过所述PNF SDN控制器与所述VNF SDN控制器之间的互联接口将所述第二报文发送给所述VNF SDN控制器,或者所述PNF SDN控制器通过上级控制器将所述第二报文发送给所述VNF SDN控制器。
在一个可能的实现方式中,可以通过配置实现PNF SDN控制器和VNF SDN控制器之间的直接通信。例如通过对该互联接口进行配置使得PNF SDN控制器和VNF SDN控制器支持相同网络互通协议,从而使得PNF SDN控制器可以通过该互联接口与VNF SDN控制器相互传输报文。举例来说,通过配置实现PNF SDN控制器与VNF SDN控制器之间能够直接传输DHCP报文。PNF SDN控制器和VNF SDN控制器之间的通信和信息可以通过私有协议,或者边界网关协议(Border Gateway Protocol,BGP)或会话初始协议(Session Initiation Protocol,SIP)或(Interior Gateway Protocol,IGP)扩展实现。
在另一种可能的实现方式中,PNF SDN控制器可以通过上级管理或控制器(例如协同器Orchestrator)与VNF SDN控制器相互传输报文。
在通过第二种可能的方式实现时,需要预先配置PNF SDN控制器、VNF SDN控制器和协同器,使得PNF SDN控制器、VNF SDN控制器和协同器能够支持相同的传输协议,以通过该协同器实现PNF SDN控制器和VNF SDN控制器之间的报文传输。从而通过该协同器实现PNF SDN控制器和VNF SDN控制器之间的报文传输。
图2为本申请实施例提供的一种数据传输方法的示意图,请参见图2所示,该数据传输方法 可以包括:
S201、PNF SDN控制器接收接入设备发送的第一报文和接入环路标识,所述接入环路标识用于标识接入设备接收所述第一报文的所述接入设备的物理端口或逻辑端口。
接入设备在接收到第一报文不对所述第一报文进行业务处理,而是将所述第一报文发送给所述PNF SDN控制器,并将与所述第一报文对应的接入环路标识也发送给所述PNF SDN控制器。
举例来说,所述第一报文可以为DHCP报文或RS报文。需要说明的是,在本申请实施例中,第一报文和接入环路标识为独立的两个报文。在本申请实施例中接入设备发送第一报文和接入环路标识的报文类型具体与第一网络设备和PNF SDN控制器之间的通信协议相关。示例的,接入设备可以将所述第一报文和所述接入环路标识一起承载在以下任意一种消息中发送给所述PNF SDN控制器:OpenFlow消息、接入管理或控制协议、Mfc接口管道消息、隧道消息、或作为业务功能链(Service Function Chain)的元数据(metadata)。例如,接入设备创建第一OpenFlow消息,并扩展OpenFlow使得第一OpenFlow消息(如packet-in消息)携带有第一报文和对应的接入设备的接入环路标识,并将该OpenFlow消息发送给所述PNF SDN控制器;可选的,第一OpenFlow消息还携带发送第一报文的用户侧设备的媒体介入控制(Media Access Control,MAC)地址。
在本申请实施例中,用户设备在请求IP地址或IP地址前缀的过程中,可以先将第一报文发送给接入设备,接入设备通过物理端口接收到该第一报文之后,生成相应的接入环路标识,之后,再将第一报文和接入环路标识发送给PNF SDN控制器,以使PNF SDN控制器接收到第一报文和接入环路标识。由此可见,接入设备在接收到用户设备发送的第一报文之后,无需对该第一报文和接入环路标识进行处理,而只需要将第一报文和接入环路标识发送给PNF SDN控制器,从而降低了接入设备的复杂度。
需要说明的是,对于不同的接入系统,用户设备的接入环路标识的格式不同。具体的,在DSL/Ethernet接入系统中,用户设备的接入环路标识的格式如下:
当接入设备位于基于异步传输模式(Asynchronous Transfer Mode,ATM)的DSL线路时,用户设备的接入环路标识的格式为:Access-Node-Identifier atm slot/port:vpi.vci。
当接入设备位于基于以太网的DSL/Ethernet线路时,用户设备的接入环路标识的格式为:Access-Node-Identifier eth slot/port[:vlan-id]。
其中,Access-Node-Identifier为所述接入设备(如DSLAM)的标识,slot/port为所述接入设备上的机柜号、机架号、框号、槽位号、子槽位号、端口号的一种或多种的组合;vpi.vci为DSL线路上的虚路径标识符和虚通道标识符。格式中的“[]”表示可选。
在PON接入系统中,接入设备对应的接入环路标识包含ONU部分的接入环路标识信息,也包含OLT部分的接入环路标识信息,用户设备的接入环路标识的格式如下:
当ONU作为用户设备且位于基于ATM的DSL线路时,ONU对应的接入环路标识为:Access-Node-Identifier atm slot1/port1/ONUID/slot2/port2:vpi.vci。
当ONU作为用户设备且位于基于Ethernet的DSL/Ethernet线路时,ONU对应的接入环路标识为:Access-Node-Identifier eth slot1/port1/ONUID/slot2/port2[:vlan-id]。
其中,Access-Node-Identifier为OLT的标识,slot1/port1为OLT上的机柜号、机架号、框号、槽位号、子槽位号、端口号的一种或多种的组合;slot2/port2为ONU上的机柜号、机架号、框号、槽位号、子槽位号、端口号的一种或多种的组合;ONUID/slot2/port2:vpi.vci为ONU部分的接入环路标识信息,Access-Node-Identifier slot1/port1为OLT部分的接入环路标识信 息。
S202、PNF SDN控制器根据所述接入环路标识和所述第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识。
举例来说,PNF SDN控制器在接收到所述第一报文和所述接入环路标识,可以将接入环路标识添加在第一报文的字段中,从而生成第二报文,或者,PNF SDN控制器获得第一报文和接入环路标识,创建第二报文,所述第二报文携带接入环路标识,进而实现对报文的控制处理,而接入设备只需要将第一报文和接入环路标识发送给PNF SDN控制器即可,实现PNF SDN控制器集成接入设备的功能,从而降低了接入设备的复杂度。
示例的,若第一报文为第一DHCP报文,PNF SDN控制器在接收到第一DHCP报文和接入环路标识,可以将接入环路标识添加在第一DHCP报文的字段options82中,从而生成第二DHCP报文。
S203、PNF SDN控制器将第二报文发送给VNF SDN控制器。
PNF SDN控制器将第二报文发送给VNF SDN控制器,以使VNF SDN控制器将第二报文发送给DHCP服务器,第二报文用于请求DHCP服务器为用户设备分配IP地址或IP地址前缀。
在本申请实施例中,PNF SDN控制器生成第二报文,可以直接将该第二报文发送给VNF SDN控制器,实现了PNF SDN控制器与VNF SDN控制器之间的交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率,并且可以降低对接入设备的性能要求及负担。可选的,PNF SDN控制器将第二报文发送给VNF SDN控制器可以通过两种可能的实现方式,具体如下:
在第一种可能的实现方式中,PNF SDN控制器通过PNF SDN控制器与VNF SDN控制器之间的互联接口将第二报文发送给VNF SDN控制器。
在第二种可能的实现方式中,PNF SDN控制器通过上级控制器将第二报文发送给VNF SDN控制器。示例的,上级控制器可以为协同器,协同器与PNF SDN控制器和VNF SDN控制器分别连接通信,PNF SDN控制器将第二报文发送给协同器,由协同器将所述第二报文转发给VNF SDN控制器。
需要说明的是,在本申请实施例中,对于PNF SDN控制器如何通过互联接口或协同器将第二报文发送给VNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。通过这两种方式,实现了PNF SDN控制器与VNF SDN控制器之间的交互通信,从而提高了数据的传输效率。
需要说明的是,在本申请实施例中,S203PNF SDN控制器将第二报文发送给VNF SDN控制器之后,可选的,VNF SDN控制器也可以通过两种可能的实现方式接收PNF SDN控制器发送的第二报文:
在第一种可能的实现方式中,VNF SDN控制器通过VNF SDN控制器与PNF SDN控制器之间互联接口接收PNF SDN控制器发送的第二报文。
在第二种可能的实现方式中,VNF SDN控制器通过上级控制器接收PNF SDN控制器发送的第二报文。
需要说明的是,在本申请实施例中,对于VNF SDN控制器如何通过互联接口或协同器接收PNF SDN控制器发送的第二报文,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。通过这两种方式,实现了PNF SDN控制器与VNF SDN控制器之间的交互,从而提高了数据的传输效率。
需要说明的是,VNF SDN控制器接收PNF SDN控制器发送的第二报文的两种可能的实现方式与PNF SDN控制器将第二报文发送给VNF SDN控制器的两种可能的实现方式类似,在此,本申请不再进行赘述。VNF SDN控制器在接收到PNF SDN控制器发送的第二报文,可以执行下述S204:
S204、VNF SDN控制器将第二报文发送给DHCP服务器。VNF SDN控制器将第二报文发送给DHCP服务器,使得DHCP服务器在接收到第二报文之后,为用户设备分配IP地址或IP地址前缀,从而完成第一报文的请求过程,即请求为用户设备分配IP地址或IP地址前缀的过程。
由此可见,本申请提供的数据传输方法,在处理和传输第一报文的过程中,接入设备在接收到第一报文之后,无需对该第一报文和接入环路标识进行处理,而只需要将第一报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一报文和接入环路标识进行处理,以生成第二报文,之后,再将第二报文发送给VNF SDN控制器,以使VNF SDN控制器将第二报文发送给DHCP服务器,并通过该DHCP服务器为用户设备分配IP地址或IP地址前缀,从而降低了接入设备的复杂度。进一步地,DHCP服务器在为用户设备分配IP地址或IP地址前缀之后,可以将分配好的IP地址或IP地址前缀携带在第二报文的响应报文中发送给VNF SDN控制器,该过程即为第二报文的响应过程,具体请参见S205-S207:
S205、VNF SDN控制器接收DHCP服务器发送的对应于第二报文的响应报文。
DHCP服务器在接收到VNF SDN控制器的第二报文后,向VNF SDN控制器发送响应报文。其中,对应于第二报文的响应报文包括所述接入环路标识及所述DHCP服务器为用户设备分配的IP地址或IP地址前缀。
S206、VNF SDN控制器将所述响应报文发送给PNF SDN控制器。
需要说明的是,在本申请实施例中,对于VNF SDN控制器如何将第二报文的响应报文发送给PNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。
S207、PNF SDN控制器向所述接入设备发送所述接入环路标识和所述DHCP服务器为所述用户设备分配的IP地址或IP地址前缀。
具体的,PNF SDN控制器接收到所述响应报文,通过分离所述接入环路标识获得第三报文,所述第三报文包括包括所述DHCP服务器为用户设备分配的IP地址或IP地址前缀和所述接入环路标识,对所述第三报文的类型不做限制,可以是DHCP报文,也可以不是DHCP报文。。
举例来说,PNF SDN控制器接收到所述响应报文,对所述响应报文进行解析,并分离出所述接入环路标识,通过所述第三报文将所述为用户设备分配的IP地址或IP地址前缀和所述接入环路标识发送给接入设备,例如,第三报文为OpenFlow消息,PNF SDN控制器通过OpenFlow消息将为用户设备分配的IP地址或IP地址前缀和所述接入环路标识发送给接入设备。本申请提供的数据传输方法,PNF SDN控制器在接收接入设备发送的第一报文和接入环路标识,根据接入环路标识和第一报文生成第二报文,并将第二报文发送给VNF SDN控制。VNF SDN控制器在接收PNF SDN控制器发送的第二报文,将第二报文发送给DHCP服务器,以请求DHCP服务器为用户设备分配IP地址或IP地址前缀,从而完成第一报文的处理和传输。由此可见,本申请提供的数据传输方法,在处理和传输第一报文的过程中,接入设备在接收到第一报文,无需对该第一报文和接入环路标识进行处理,而只需要将第一报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一报文和接入环路标识进行处理,以生成第二报文,将第二报文发送给VNF SDN控制器,以使VNF SDN控制器将第二报文发送给网络服务器,并通过该网络服务器为用户设备分配IP 地址或IP地址前缀,从而降低了接入设备的复杂度。此外,PNF SDN控制器在向VNF发送,可以直接将第二报文发送给VNF SDN控制器,实现了PNF SDN控制器与VNF SDN控制器之间的交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
基于图2对应的实施例,可选的,S204之前,可以对所述用户设备的身份进行验证和授权,在所述用户设备的身份通过验证和授权之后,VNF SDN控制器才会将第二报文发送给DHCP服务器,以请求DHCP服务器为用户设备分配IP地址或者IP地址前缀。请参见图3所示,图3为本申请实施例提供的另一种数据传输方法的示意图,其中,S2031-S2033为VNF SDN控制器对用户设备的身份进行验证和授权的过程。
S2031、VNF SDN控制器获取第二报文中的接入环路标识。
S2032、VNF SDN控制器向AAA服务器发送AAA认证请求报文。
VNF SDN控制器将获得的接入环路标识添加在AAA认证请求报文中,然后将携带有接入环路标识的AAA认证请求报文发送给AAA服务器。AAA认证可以是拨号用户远程认证(Remote Authentication Dial In User Service,RADIUS)协议或Diameter协议进行认证。
在本申请实施例中,VNF SDN控制器在获取到第二报文中的接入环路标识之后,将该接入环路标识携带在AAA认证请求报文中发送给AAA服务器,使得AAA服务器在接收到该AAA认证请求报文之后,可以根据接入环路标识对用户设备的身份进行验证和授权,在确定用户设备的身份通过验证和授权之后,向VNF SDN控制器发送AAA授权响应报文。
S2033、VNF SDN控制器接收AAA服务器发送的AAA授权响应报文。
由此可见,在本申请实施例中,是通过VNF SDN控制器从第二报文中获取接入环路标识。并向AAA服务器发送AAA认证请求报文,在用户设备的身份通过验证和授权之后,接收AAA服务器发送的AAA授权响应报文,从而完成用户设备身份的验证和授权,而无需通过IP边缘设备实现,从而降低了IP边缘设备的复杂度,提高网络传输效率。
在通过S2031-S2033确定用户设备的身份通过验证和授权之后,执行S204VNF SDN控制器才会将第二报文发送给DHCP服务器,以便DHCP服务器为用户设备分配IP地址或IP地址前缀。DHCP服务器在为用户设备分配IP地址或IP地址前缀之后,可以将分配好的IP地址或IP地址前缀携带在第二报文的响应报文中发送给VNF SDN控制器,以使VNF SDN控制器将接收到的第二报文的响应报文发送给PNF SDN控制器。可选的,S205PNF SDN控制器在接收VNF SDN控制器发送的第二报文的响应报文之后,为了防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,VNF SDN控制器会通过监听第二报文的响应报文,从而根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表;之后,再将IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至IP边缘设备的虚拟数据面,从而提高网络设备的安全性。具体请参见S208所示:
S208、VNF SDN控制器根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,以使VNF SDN控制器向IP边缘设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
在本申请实施例中,VNF SDN控制器可以通过侦听第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,具体过程可以为:用户设备发送给接入设备的第一报文承载在以太网帧中,该以太网帧帧头内的源MAC地 址就是用户设备的MAC地址。接入设备接收到第一报文后,从其所在的以太网帧帧头中提取源MAC地址,然后将MAC地址发送给PNF SDN控制器,并由PNF SDN控制器将用户设备的MAC地址发送给VNF SDN控制器,使得VNF SDN控制器根据IP地址或IP地址前缀及用户设备的MAC地址,生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。其中,用户设备的MAC地址,可以是用户驻地设备(customer premise equipment,CPE)的MAC地址,也可以是用户设备UE的MAC地址。可选的,PNF SDN控制器获得用户设备的MAC地址可以在步骤S201中实现,也可以单独实现。
在生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表后,VNF SDN控制器可以将该IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至IP边缘设备的虚拟数据面。可选的,VNF SDN控制器可以通过OpenFlow或网络配置协议(Network Configuration Protocol,NETCONF)管理或控制协议将IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至IP边缘设备的虚拟数据面,以使IP边缘设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
PNF SDN控制器在接收到VNF SDN控制器发送的第二报文的响应报文之后,为了防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,PNF SDN控制器会通过监听第二报文的响应报文,从而根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表;之后,再将IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至接入设备,从而提高网络设备的安全性。具体请参见S209-S210所示:
S209、PNF SDN控制器根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
S210、PNF SDN控制器向接入设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
在本申请实施例中,PNF SDN控制器根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,具体过程可以为:用户设备发送给接入设备的第一报文是承载在以太网帧上的,该以太网帧帧头内的源MAC地址就是用户设备的MAC地址,接入设备接收到第一报文,从其所在的以太网帧帧头中提取源MAC地址,将MAC地址发送给PNF SDN控制器;使得PNF SDN控制器根据IP地址或IP地址前缀及用户设备的MAC地址,生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
在生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表后,PNF SDN控制器可以将该IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至接入设备。可选的,PNF SDN控制器可以通过OpenFlow或NETCONF管理或控制协议将IP地址或IP地址前缀与用户设备的MAC地址之间的映射表下发至接入设备,以使接入设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
可选地,上述实施例中,PNF SDN控制器和NVF SDN控制器中的任意一个可以生成分配给用户设备的IP地址与用户设备的MAC地址之间的映射表,并将生成的映射表发给另一方保存。
为了更清楚地说明本申请实施例提供的数据传输方法,以第一报文为第一DHCP报文为例进行说明,具体请参见图4所示,图4为本申请实施例提供的再一种数据传输方法的示意图,该数据 传输方法可以包括:
S401、接入设备接收用户设备发送的第一DHCP报文。
其中,第一DHCP报文用于请求DHCP服务器为用户设备分配IP地址或IP地址前缀。
S402、接入设备将第一DHCP报文和接入环路标识发送给PNF SDN控制器,所述所述接入环路标识用于标识接入设备接收所述第一DHCP报文的所述接入设备的物理端口或逻辑端口。
接入设备接收到第一DHCP报文会生成与所述第一DHCP报文对应的接入环路标识,其中,接入环路标识用于标识接入设备接收第一DHCP报文的物理端口或逻辑端口。举例来说,在DSL/Ethernet接入系统中,接入设备接收到用户设备发送的第一DHCP报文,可以生成其对应的接入环路标识的格式为:Access-Node-Identifier eth slot/port[:vlan-id]。
举例来说,接入设备创建第一OpenFlow消息,并扩展OpenFlow使得第一OpenFlow消息(如packet-in消息)携带有第一DHCP报文和对应的接入设备的接入环路标识;可选的,第一OpenFlow消息还携带发送第一DHCP报文的用户设备的MAC地址。
S403、PNF SDN控制器根据所述接入环路标识和第一DHCP报文生成第二DHCP报文。
示例的,PNF SDN控制器从第一OpenFlow消息接到接入环路标识和第一DHCP报文,可以将接入环路标识添加在第一DHCP报文的字段options(82)中,从而生成第二DHCP报文或者,PNF SDN控制器从第一OpenFlow消息获得接入环路标识和第一DHCP报文,创建第二DHCP报文。其中,DHCP报文可以为DHCP Discover报文,也可以为DHCP Request。例如,当第一DHCP报文为第一DHCP Discover报文,将接入环路标识添加在第一DHCP Discover报文的字段options(82)中,从而生成第二DHCP Discover报文。
S404、PNF SDN控制器将第二DHCP报文发送给VNF SDN控制器。
其中,第二DHCP报文包括接入环路标识。
可选的,PNF SDN控制器将第二报文发送给VNF SDN控制器可以通过两种可能的实现方式,具体如下:
在第一种可能的实现方式中,PNF SDN控制器通过PNF SDN控制器与VNF SDN控制器之间的互联接口将第二报文发送给VNF SDN控制器。示例的,PNF SDN控制器与VNF SDN控制器之间通过共同支持的通信协议互联。
在第二种可能的实现方式中,PNF SDN控制器通过上级控制器将第二报文发送给VNF SDN控制器。示例的,上级控制器可以为协同器,PNF SDN控制器将第一OpenFlow消息通过协同器转发给VNF SDN控制器。
需要说明的是,在本申请实施例中,对于PNF SDN控制器如何将第二DHCP报文发送给VNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。
由此可见,接入设备在接收到第一DHCP报文之后,无需对该第一DHCP报文和接入环路标识进行处理,而只需要将第一DHCP报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一DHCP报文和接入环路标识进行处理,以生成第二DHCP报文,之后,再将第二DHCP报文发送给VNF SDN控制器,以使VNF SDN控制器将第二DHCP报文发送给DHCP服务器,并通过该DHCP服务器为用户设备分配IP地址或IP地址前缀,从而降低了接入设备的复杂度。此外,PNF SDN控制器在向VNF SDN控制器发送第二DHCP报文,PNF SDN控制器是与VNF SDN控制器之间进行交互,避免了通过接入设备和IP边缘设备将第二DHCP报文转发给VNF SDN控制器,从而提高 了数据的传输效率。
S405、VNF SDN控制器获取第二DHCP报文中的所述接入环路标识。
S406、VNF SDN控制器向AAA服务器发送AAA认证请求报文。
其中,AAA认证请求报文包括接入环路标识。AAA认证可以是RADIUS协议或DIAMETER协议进行认证。
S407、VNF SDN控制器接收AAA服务器发送的AAA授权响应报文。
通过上述S405-S407,可以实现对用户设备身份的验证和授权,在用户设备的身份通过验证和授权之后,才会执行S408。
S408、VNF SDN控制器将第二DHCP报文发送给DHCP服务器。由此可见,在本申请实施例中,VNF SDN控制器可以直接接收PNF SDN控制器发送的第二报文,实现了PNF SDN控制器与VNF SDN控制器之间的直接交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
S409、DHCP服务器根据第二DHCP报文为用户设备分配IP地址或IP地址前缀。
S410、DHCP服务器将第二DHCP报文的响应报文发送给VNF SDN控制器。
其中,第二DHCP报文的响应报文包括接入环路标识及为用户设备分配的IP地址或IP地址前缀。
S411、VNF SDN控制器将第二DHCP报文的响应报文发送给PNF SDN控制器。
需要说明的是,在本申请实施例中,对于VNF SDN控制器如何将第二DHCP报文的响应报文发送给PNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。
S412、PNF SDN控制器从第二DHCP报文的响应报文中分离获取接入环路标识。
具体的,PNF SDN控制器从第二DHCP报文的响应报文中分离获取接入环路标识,并生成第三DHCP报文,所述第三DHCP报文包括DHCP服务器为所述用户设备分配的IP地址或IP地址前缀。
S413、PNF SDN控制器将所述接入环路标识和用户设备分配的IP地址或IP地址前缀发送给所述接入设备。
举例来说,PNF SDN控制器向接入设备发送第二OpenFlow消息,第二OpenFlow消息包括接入环路标识和为用户设备分配的IP地址或者IP地址的前缀。
S414、接入设备根据接入环路标识向用户设备发送IP地址或IP地址前缀,从而完成第一DHCP报文的处理和传输。
可选的,S411VNF SDN控制器将第二DHCP报文的响应报文发送给PNF SDN控制器之前,还可以包括:
S415、VNF SDN控制器根据第二DHCP报文的响应报文生成并下发IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
通过S415,使得IP边缘设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
需要说明的是,VNF SDN控制器根据第二DHCP报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,其获取获取请参见 S208所示,在此,本申请不再进行赘述。
可选的,S413PNF SDN控制器向接入设备发送用户设备分配的IP地址或IP地址前缀之前,还可以包括:
S416、PNF SDN控制器根据第二DHCP报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
S417、PNF SDN控制器向接入设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
S418、接入设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
通过S416-S418,使得接入设备可以根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
需要说明的是,PNF SDN控制器根据第二DHCP报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,其获取获取请参见S208所示,在此,本申请不再进行赘述。
当然,第一报文也可以为RS报文,以第一报文也可以为第一RS报文为例进行说明,具体请参见图5所示,图5为本申请实施例提供的又一种数据传输方法的示意图,该数据传输方法可以包括:
S501、接入设备接收用户设备发送的第一RS报文。
其中,第一RS报文用于请求DHCP服务器为用户设备分配IP地址或IP地址前缀。
S502、接入设备将第一RS报文和接入环路标识发送给PNF SDN控制器。
其中,接入环路标识用于标识接入设备接收第一RS报文的物理端口或逻辑端口。举例来说,在DSL/Ethernet接入系统中,接入设备接收到用户设备发送的第一RS报文,可以生成其对应的接入环路标识的格式为:Access-Node-Identifier eth slot/port[:vlan-id]。
举例来说,接入设备创建第一OpenFlow消息,并扩展OpenFlow使得第一OpenFlow消息(如packet-in消息)携带有第一RS报文和对应的接入设备的接入环路标识;可选的,第一OpenFlow消息还携带发送第一RS报文的用户设备的MAC地址。
S503、PNF SDN控制器根据所述接入环路标识和第一RS报文生成第二RS报文。
示例的,PNF SDN控制器接到接入环路标识和第一RS报文,可以将接入环路标识添加在第一RS报文的字段options(82)中,从而生成第二RS报文,或者,PNF SDN控制器从第一OpenFlow消息获得接入环路标识和第一RS报文,创建第二RS报文。。其中,RS报文可以为RS Discover报文,也可以为RS Request。例如,当第一RS报文为第一RS Discover报文,将接入环路标识添加在第一RS Discover报文的字段options(82)中,从而生成第二RS Discover报文。
S504、PNF SDN控制器将第二RS报文发送给VNF SDN控制器。
其中,第二RS报文包括接入环路标识。
可选的,PNF SDN控制器将第二RS报文发送给VNF SDN控制器可以通过两种可能的实现方式,具体如下:
在第一种可能的实现方式中,PNF SDN控制器通过PNF SDN控制器与VNF SDN控制器之间的互联接口将第二RS报文发送给VNF SDN控制器。示例的,PNF SDN控制器与VNF SDN控制器之间 通过共同支持的通信协议互联。
在第二种可能的实现方式中,PNF SDN控制器通过上级控制器将第二RS报文发送给VNF SDN控制器。示例的,上级控制器可以为协同器,PNF SDN控制器将第一OpenFlow消息通过协同器转发给VNF SDN控制器。
需要说明的是,在本申请实施例中,对于PNF SDN控制器如何将第二RS报文发送给VNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。
由此可见,接入设备在接收到第一RS报文之后,无需对该第一RS报文和接入环路标识进行处理,而只需要将第一RS报文和接入环路标识发送给PNF SDN控制器,从而通过该PNF SDN控制器对第一RS报文和接入环路标识进行处理,以生成第二RS报文,之后,再将第二RS报文发送给VNF SDN控制器,以使VNF SDN控制器将第二RS报文发送给DHCP服务器,并通过该DHCP服务器为用户设备分配IP地址或IP地址前缀,从而降低了接入设备的复杂度。此外,PNF SDN控制器在向VNF SDN控制器发送第二RS报文,PNF SDN控制器是与VNF SDN控制器之间进行交互,避免了通过接入设备和IP边缘设备将第二RS报文转发给VNF SDN控制器,从而提高了数据的传输效率。
S505、VNF SDN控制器获取第二RS报文中的所述接入环路标识。
S506、VNF SDN控制器向AAA服务器发送AAA认证请求报文。
其中,AAA认证请求报文包括接入环路标识。
S507、VNF SDN控制器接收AAA服务器发送的AAA授权响应报文。
通过上述S405-S407,可以实现对用户设备身份的验证和授权,在用户设备的身份通过验证和授权之后,才会执行S408。
S508、VNF SDN控制器将第二RS报文发送给DHCP服务器。
由此可见,在本申请实施例中,VNF SDN控制器可以直接接收PNF SDN控制器发送的第二报文,实现了PNF SDN控制器与VNF SDN控制器之间的直接交互,避免了通过接入设备和IP边缘设备将第二报文转发给VNF SDN控制器,从而提高了数据的传输效率。
S509、DHCP服务器根据第二RS报文为用户设备分配IP地址或IP地址前缀。
S510、DHCP服务器将第二RS报文的响应报文发送给VNF SDN控制器。
其中,第二RS报文的响应报文包括接入环路标识及为用户设备分配的IP地址或IP地址前缀。
S511、VNF SDN控制器将第二RS报文的响应报文发送给PNF SDN控制器。
需要说明的是,在本申请实施例中,对于VNF SDN控制器如何将第二RS报文的响应报文发送给PNF SDN控制器,具体请参见上述所示的PNF SDN控制器和VNF SDN控制器相互传输报文的两种可能的实现方式,在此,本申请不再进行赘述。
S512、PNF SDN控制器从第二RS报文的响应报文中通过分离获取接入环路标识。
S513、PNF SDN控制器向接入设备发送所述接入环路标识和用户设备分配的IP地址或IP地址前缀。
举例来说,PNF SDN控制器向接入设备发送第二OpenFlow消息,第二OpenFlow消息包括接入环路标识和为用户设备分配的IP地址或者IP地址的前缀。
S514、接入设备根据接入环路标识向用户设备发送IP地址或IP地址前缀,从而完成第一RS报文的处理和传输。
可选的,S511VNF SDN控制器将第二RS报文的响应报文发送给PNF SDN控制器之前,还可以包括:
S515、VNF SDN控制器根据第二RS报文的响应报文生成并下发IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
通过S515,使得IP边缘设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
需要说明的是,VNF SDN控制器根据第二RS报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,其获取获取请参见S208所示,在此,本申请不再进行赘述。
可选的,S513PNF SDN控制器向接入设备发送用户设备分配的IP地址或IP地址前缀之前,还可以包括:
S516、PNF SDN控制器根据第二RS报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
S517、PNF SDN控制器向接入设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
S518、接入设备根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
通过S516-S518,使得接入设备可以根据接收到IP地址或IP地址前缀与用户设备的MAC地址之间的映射表生成本地的IP地址或IP地址前缀与用户设备的MAC地址之间的映射表,从而防止IP地址或IP地址前缀的冒充,及MAC地址的冒充,提高了网络设备的安全性。
需要说明的是,PNF SDN控制器根据第二RS报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表之前,需要预先获取用户设备的MAC地址,其获取获取请参见S208所示,在此,本申请不再进行赘述。
图6为本申请实施例提供的一种PNF SDN控制器60的结构示意图,请参见图6所示,该PNF SDN控制器60可以包括:
接收单元601用于接收第一网络设备发送的第一报文和接入环路标识,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
生成单元602用于根据接入环路标识和第一报文生成第二报文。
发送单元603用于将第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使VNF SDN控制器将第二报文发送给第二网络设备,第二报文用于请求第二网络设备为用户设备分配IP地址或IP地址前缀。
可选的,接收单元601还用于接收VNF SDN控制器发送的第二报文的响应报文,第二报文的响应报文包括接入环路标识及所述第二网络设备为所述为用户设备分配的IP地址或IP地址前缀。
发送单元603还用于向第一网络设备发送所述接入环路标识和用户设备分配的IP地址或IP地址前缀。
可选的,发送单元603具体用于通过PNF SDN控制器60与VNF SDN控制器之间的互联接口将第二报文发送给VNF SDN控制器。
可选的,发送单元603具体用于通过上级控制器将第二报文发送给VNF SDN控制器。
可选的,生成单元602还用于根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
发送单元603还用于向第一网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
在一种可能实施的实现方式中,接收单元601接收接入设备发送的第一报文和接入环路标识,例如第一DHCP报文和接入环路标识或者第一RS报文和接入环路标识,其中,接入环路标识是能够唯一标识接入设备和接收消息的接入设备上的物理端口或逻辑端口的标识。
在另一种可能实施的实现方式中,生成单元602将所述接入环路标识添加到所述第一报文中,生成第二报文;或者,生成单元602根据接入环路标识和第一报文,创建新的第二报文,第二报文携带接入环路标识和第一报文,第一报文和第二报文的类型可以相同,也可以不同。
进一步,发送单元603具体可以通过PNF SDN控制器60与VNF SDN控制器之间的互联接口将第二报文发送给VNF SDN控制器将第二报文发送给VNF SDN控制器,发送单元603发送的第二报文可以与第一报文类型相同,也可以不同,举例来说,第二报文的类型可以根据PNF SDN控制器60与VNF SDN控制器之间通信协议确定。
进一步,发送单元603具体可以通过上级控制器将第二报文发送给VNF SDN控制器。例如,PNF SDN控制器60通过协同器将第二报文发送给VNF SDN控制器。
结合以上各实施方式,接收单元601具体还用于接收接入设备发送发热用户设备的MAC地址,接入设备获得用户设备的MAC地址的方式可以参考图2方法中
结合以上各实现方式,第一报文和接入环路标识可以包括于开放流OpenFlow消息中。
PNF SDN控制器60在产品形态上,举例来说,可以运行于服务器设备或者电信设备,也可以是独立设备。
前述图1-5实施例中的PNF SDN控制器对报文处理方法和具体实例同样适用于本实施例的PNF SDN60控制器,通过前述对报文处理方法的详细描述,本领域技术人员可以清楚的知道本实施例中PNF SDN60控制器的实施方法,所以为了说明书的简洁,在此不再详述。
图7为本申请实施例提供的一种VNF SDN控制器70的结构示意图,请参见图7所示,该VNF SDN控制器70可以包括:
接收单元701用于接收PNF SDN控制器发送的第二报文,其中,第二报文是PNF SDN控制器根据接入环路标识和第一报文生成的。
发送单元702用于将第二报文发送给第二网络设备,第二报文用于请求第二网络设备为用户设备分配IP地址或IP地址前缀,所述接入环路标识用于标识第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
可选的,接收单元701还用于接收第二网络设备发送的第二报文的响应报文,第二报文的响应报文包括接入环路标识及所述第二网络设备为所述为用户设备分配的IP地址或IP地址前缀。
发送单元702还用于将第二报文的响应报文发送给PNF SDN控制器。
可选的,接收单元701具体用于通过VNF SDN控制器70与PNF SDN控制器之间互联接口接收PNF SDN控制器发送的第二报文。
可选的,接收单元701具体用于通过上级控制器接收PNF SDN控制器发送的第二报文。
可选的,该VNF SDN控制器70还可以包括:
生成单元703用于根据第二报文的响应报文生成IP地址或IP地址前缀与用户设备的MAC地 址之间的映射表。
发送单元702还用于向第三网络设备发送IP地址或IP地址前缀与用户设备的MAC地址之间的映射表。
可选的,该VNF SDN控制器70还可以包括:
获取单元704用于获取第二报文中的接入环路标识。
发送单元702还用于向第四网络设备发送认证请求报文,认证请求报文包括接入环路标识。
接收单元701还用于接收第四网络设备发送的授权响应报文。
VNF SDN控制器70在产品形态上,举例来说,可以运行于服务器设备或者电信设备,也可以是独立设备。
前述图1-5实施例中的VNF SDN控制器对报文处理方法和具体实例同样适用于本实施例的VNF SDN控制器70,通过前述对报文处理方法的详细描述,本领域技术人员可以清楚的知道本实施例中VNF SDN70控制器的实施方法,所以为了说明书的简洁,在此不再详述。图8为本申请实施例提供的另一种PNF SDN控制器80的结构示意图,请参见图8所示,该PNF SDN控制器80可以包括:
通信接口803,用于接收第一网络设备发送的第一报文和接入环路标识,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口,将生成的第二报文发送给VNF SDN控制器。
可选的,所述通信接口803还可以用于接收所述VNF SDN控制器发送的所述第二报文的响应报文,所述第二报文的响应报文包括所述接入环路标识及为用户设备分配的IP地址或IP地址前缀,向所述第一网络设备发送所述接入环路标识和所述用户设备分配的IP地址或IP地址前缀,向所述第一网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
处理器802,用于执行存储器存储的程序,当程序被执行时,处理器用于根据所述接入环路标识和所述第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识;处理所述第二报文的响应报文,将所述接入环路标识分理出所述第二报文的响应报文,生成第三报文,所述第三报文包括所述接入环路标识和所述第二报文的响应报文。
可选的,所述处理器802还用于根据所述第二报文的响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
可选的,所述PNF SDN控制器还可以包括存储器801,用于存储程序。
其中,总线架构(用总线804来代表),总线804可以包括任意数量的互联的总线和桥,总线804将包括由处理器802代表的一个或多个处理器802和存储器801代表的存储器以及通信接口803的各种电路链接在一起。总线804还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。
前述图1-5实施例中的PNF SDN控制器对报文处理方法和具体实例同样适用于本实施例的PNF SDN80控制器,通过前述对报文处理方法的详细描述,本领域技术人员可以清楚的知道本实施例中PNF SDN控制器的实施方法,所以为了说明书的简洁,在此不再详述。图9为本申请实施例提供的另一种VNF SDN控制器90的结构示意图,请参见图9所示,该VNF SDN控制器90可以包括:
通信接口903,用于接收物理网络功能软件定义网络PNF SDN控制器发送的第二报文,所述第二报文是所述PNF SDN控制器根据接入环路标识和第一报文生成的,将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为用户设备分配IP地址或IP地址前缀, 所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
可选的,所述通信接口903还可以用于接收所述第二网络设备发送的第二报文的响应报文,所述第二报文的响应报文包括所述接入环路标识及为用户设备分配的IP地址或IP地址前缀;将所述第二报文的响应报文发送给所述PNF SDN控制器;接收PNF SDN控制器发送的用户设备的MAC地址;向第三网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;获取所述第二报文中的所述接入环路标识;向第四网络设备发送认证请求报文,所述认证请求报文包括所述接入环路标识;接收所述第四网络设备发送的授权响应报文。
可选的,所述VNF SDN控制器还可以包括存储器901,用于存储程序。
可选的,所述VNF SDN控制器还可以包括处理器902,用于执行存储器存储的程序,当程序被执行时,处理器用于根据所述第二报文的响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
其中,总线架构(用总线904来代表),总线904可以包括任意数量的互联的总线和桥,总线904将包括由处理器902代表的一个或多个处理器902和存储器901代表的存储器901以及通信接口903的各种电路链接在一起。总线904还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。
前述图1-5实施例中的VNF SDN控制器对报文处理方法和具体实例同样适用于本实施例的VNF SDN控制器90,通过前述对报文处理方法的详细描述,本领域技术人员可以清楚的知道本实施例中VNF SDN控制器90的实施方法,所以为了说明书的简洁,在此不再详述。
图10为本申请实施例提供的一种数据传输系统100的结构示意图,请参见图10所示,该数据传输系统100可以包括:
上述任一实施例所示的PNF SDN控制器1001和上述任一实施例所示的VNF SDN控制器1002。
前述图1-5实施例中的PNF SDN控制器1001对报文处理方法、VNF SDN控制器1002对报文处理方法及具体实例同样适用于本实施例的数据传输系统,通过前述对报文处理方法的详细描述,本领域技术人员可以清楚的知道本实施例中数据传输系统100的实施方法,所以为了说明书的简洁,在此不再详述。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该 指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行所述计算机程序指令时,全部或部分地产生按照本发明实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如固态硬盘Solid State Disk(SSD))等。
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。
Claims (23)
- 一种数据传输方法,其特征在于,包括:物理网络功能软件定义网络PNF SDN控制器接收第一网络设备发送的第一报文和接入环路标识,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口;所述PNF SDN控制器根据所述接入环路标识和所述第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识;所述PNF SDN控制器将所述第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使所述VNF SDN控制器将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为所述用户设备分配互联网协议IP地址或IP地址前缀。
- 根据权利要求1所述的方法,其特征在于,所述PNF SDN控制器将所述第二报文发送给所述VNF SDN控制器之后,该方法还包括:所述PNF SDN控制器接收所述VNF SDN控制器发送的对应所述第二报文的响应报文,所述响应报文包括所述接入环路标识及为所述用户设备分配的IP地址或IP地址前缀;所述PNF SDN控制器向所述第一网络设备发送所述接入环路标识和所述第二网络设备为所述用户设备分配的IP地址或IP地址前缀。
- 根据权利要求1或2所述的方法,其特征在于,所述PNF SDN控制器将所述第二报文发送给所述VNF SDN控制器,包括:所述PNF SDN控制器通过所述PNF SDN控制器与所述VNF SDN控制器之间的互联接口将所述第二报文发送给所述VNF SDN控制器。
- 根据权利要求1或2所述的方法,其特征在于,所述PNF SDN控制器将所述第二报文发送给VNF SDN控制器,包括:所述PNF SDN控制器通过上级控制器将所述第二报文发送给所述VNF SDN控制器。
- 根据权利要求2所述的方法,其特征在于,所述PNF SDN控制器接收所述VNF SDN控制器发送的所述响应报文之后,该方法还包括:所述PNF SDN控制器根据所述响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;所述PNF SDN控制器向所述第一网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
- 一种数据传输的方法,其特征在于,包括:虚拟网络功能软件定义网络VNF SDN控制器接收物理网络功能软件定义网络PNF SDN控制器发送的第二报文,所述第二报文是所述PNF SDN控制器根据接入环路标识和第一报文生成的;所述VNF SDN控制器将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为用户设备分配IP地址或IP地址前缀,所述接入环路标识用于标识第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
- 根据权利要求6所述的方法,其特征在于,所述VNF SDN控制器将所述第二报文发送给第二网络设备之后,该方法还包括:所述VNF SDN控制器接收所述第二网络设备发送的对应第二报文的响应报文,所述响应报文包括所述接入环路标识及所述第二网络设备为用户设备分配的IP地址或IP地址前缀;所述VNF SDN控制器将所述响应报文发送给所述PNF SDN控制器。
- 根据权利要求6或7所述的方法,其特征在于,所述VNF SDN控制器接收PNF SDN控制器发送的第二报文,包括:所述VNF SDN控制器通过所述VNF SDN控制器与所述PNF SDN控制器之间互联接口接收所述PNF SDN控制器发送的所述第二报文。
- 根据权利要求6或7所述的方法,其特征在于,所述VNF SDN控制器接收PNF SDN控制器发送的第二报文,包括:所述VNF SDN控制器通过上级控制器接收所述PNF SDN控制器发送的所述第二报文。
- 根据权利要求7所述的方法,其特征在于,所述VNF SDN控制器接收所述第二网络设备发送的第二报文的响应报文之后,该方法还包括:所述VNF SDN控制器根据所述响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;所述VNF SDN控制器向第三网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
- 根据权利要求6或7所述的方法,其特征在于,所述VNF SDN控制器将所述第二报文发送至第所述第二网络设备之前,该方法还包括:所述VNF SDN控制器获取所述第二报文中的所述接入环路标识;所述VNF SDN控制器向第四网络设备发送认证请求报文,所述认证请求报文包括所述接入环路标识;所述VNF SDN控制器接收所述第四网络设备发送的授权响应报文。
- 一种物理网络功能软件定义网络PNF SDN控制器,其特征在于,包括:接收单元,用于接收第一网络设备发送的第一报文和接入环路标识,所述接入环路标识用于标识所述第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口;生成单元,用于根据所述接入环路标识和所述第一报文生成第二报文,所述第二报文包括所述第一报文和所述接入环路标识;发送单元,用于将所述第二报文发送给虚拟网络功能软件定义网络VNF SDN控制器,以使所述VNF SDN控制器将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为所述用户设备分配IP地址或IP地址前缀。
- 根据权利要求12所述的控制器,其特征在于,所述接收单元,还用于接收所述VNF SDN控制器发送的所述第二报文的响应报文,所述第二报文的响应报文包括所述接入环路标识及所述第二网络设备为所述用户设备分配的IP地址或IP地址前缀;所述发送单元,还用于向所述第一网络设备发送所述接入环路标识和所述第二网络设备为所述用户设备分配的IP地址或IP地址前缀。
- 根据权利要求12或13所述的控制器,其特征在于,所述发送单元,具体用于通过所述PNF SDN控制器与所述VNF SDN控制器之间的互联接口将所述第二报文发送给所述VNF SDN控制器。
- 根据权利要求12或13所述的控制器,其特征在于,所述发送单元,具体用于通过上级控制器将所述第二报文发送给所述VNF SDN控制器。
- 根据权利要求13所述的控制器,其特征在于,所述生成单元,还用于根据所述响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;所述发送单元,还用于向所述第一网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
- 一种虚拟网络功能软件定义网络VNF SDN控制器,其特征在于,包括:接收单元,用于接收物理网络功能软件定义网络PNF SDN控制器发送的第二报文,所述第二报文是所述PNF SDN控制器根据接入环路标识和第一报文生成的;发送单元,用于将所述第二报文发送给第二网络设备,所述第二报文用于请求所述第二网络设备为用户设备分配IP地址或IP地址前缀,所述接入环路标识用于标识第一网络设备接收所述第一报文的所述第一网络设备的物理端口或逻辑端口。
- 根据权利要求17所述的控制器,其特征在于,所述接收单元,还用于接收所述第二网络设备发送的对应第二报文的响应报文,所述响应报文包括所述接入环路标识及所述第二网络设备为所述用户设备分配的IP地址或IP地址前缀;所述发送单元,还用于将所述响应报文发送给所述PNF SDN控制器。
- 根据权利要求17或18所述的控制器,其特征在于,所述接收单元,具体用于通过所述VNF SDN控制器与所述PNF SDN控制器之间互联接口接收所述PNF SDN控制器发送的所述第二报文。
- 根据权利要求17或18所述的控制器,其特征在于,所述接收单元,具体用于通过上级控制器接收所述PNF SDN控制器发送的所述第二报文。
- 根据权利要求18所述的控制器,其特征在于,还包括生成单元,其中所述生成单元,用于根据所述响应报文生成所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表;所述发送单元,还用于向第三网络设备发送所述IP地址或IP地址前缀与所述用户设备的MAC地址之间的映射表。
- 根据权利要求17或18所述的控制器,其特征在于,还包括:获取单元,用于获取所述第二报文中的所述接入环路标识;所述发送单元,还用于向第四网络设备发送认证请求报文,所述认证请求报文包括所述接入环路标识;所述接收单元,还用于接收所述第四网络设备发送的授权响应报文。
- 一种数据传输系统,其特征在于,包括:前述权利要求12至16任一所述的PNF SDN控制器和前述权利要求17至22任一所述的VNF SDN控制器。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP18854338.3A EP3672208A4 (en) | 2017-09-11 | 2018-07-05 | DATA TRANSMISSION METHOD, PNN SDN CONTROLLER, VNF SDN CONTROLLER AND SYSTEM |
| US16/815,454 US11265244B2 (en) | 2017-09-11 | 2020-03-11 | Data transmission method, PNF SDN controller, VNF SDN controller, and data transmission system |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201710814496.X | 2017-09-11 | ||
| CN201710814496.XA CN109495594B (zh) | 2017-09-11 | 2017-09-11 | 一种数据传输方法、pnf sdn控制器、vnf sdn控制器及系统 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/815,454 Continuation US11265244B2 (en) | 2017-09-11 | 2020-03-11 | Data transmission method, PNF SDN controller, VNF SDN controller, and data transmission system |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2019047611A1 true WO2019047611A1 (zh) | 2019-03-14 |
Family
ID=65633512
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2018/094709 Ceased WO2019047611A1 (zh) | 2017-09-11 | 2018-07-05 | 一种数据传输方法、pnf sdn控制器、vnf sdn控制器及系统 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US11265244B2 (zh) |
| EP (1) | EP3672208A4 (zh) |
| CN (1) | CN109495594B (zh) |
| WO (1) | WO2019047611A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115017278A (zh) * | 2022-05-10 | 2022-09-06 | 深圳市疾病预防控制中心(深圳市卫生检验中心、深圳市预防医学研究所) | 基于会话服务客户端的数据处理方法及会话服务客户端 |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12192052B2 (en) * | 2019-06-10 | 2025-01-07 | Apple Inc. | End-to-end radio access network (RAN) deployment in open ran (O-RAN) |
| WO2021095226A1 (ja) * | 2019-11-15 | 2021-05-20 | 日本電信電話株式会社 | エッジ切替システム、エッジ切替装置、エッジ切替方法およびプログラム |
| CN114531320B (zh) * | 2020-11-02 | 2026-03-27 | 华为技术有限公司 | 通信方法、装置、设备、系统及计算机可读存储介质 |
| EP4224804B1 (en) * | 2020-11-02 | 2025-03-26 | Huawei Technologies Co., Ltd. | Communication method, apparatus, device, system, and computer readable storage medium |
| CN113766481B (zh) * | 2021-10-14 | 2023-11-28 | 山东鑫泽网络科技有限公司 | 一种网络通信装置及方法 |
| JP7598896B2 (ja) * | 2022-03-31 | 2024-12-12 | 古河電気工業株式会社 | 通信システム、プログラム及び通信方法 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102088391A (zh) * | 2009-12-07 | 2011-06-08 | 华为技术有限公司 | 一种IPv6报文的处理方法、设备和系统 |
| CN104917849A (zh) * | 2014-03-11 | 2015-09-16 | 华为技术有限公司 | 一种消息处理方法、接入控制器及网络节点 |
| US20170104609A1 (en) * | 2015-10-09 | 2017-04-13 | Openet Telecom Ltd. | System and Method for Enabling Service Lifecycle Based Policy, Licensing, and Charging in a Network Function Virtualization Ecosystem |
| WO2017101970A1 (en) * | 2015-12-14 | 2017-06-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Optimized dynamic software defined network |
Family Cites Families (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1897589B (zh) * | 2005-07-13 | 2010-12-15 | 上海贝尔阿尔卡特股份有限公司 | IPv6无状态地址配置中的接入装置、路由设备及方法 |
| CN101547383B (zh) * | 2008-03-26 | 2013-06-05 | 华为技术有限公司 | 一种接入认证方法及接入认证系统以及相关设备 |
| US8224946B2 (en) * | 2009-04-24 | 2012-07-17 | Rockstar Bidco, LP | Method and apparatus for accommodating duplicate MAC addresses |
| CN102148748B (zh) * | 2010-10-26 | 2014-05-21 | 华为技术有限公司 | 伪线路由扩散方法、系统和汇聚节点设备 |
| US9204290B2 (en) * | 2010-11-03 | 2015-12-01 | Telefonaktiebolaget L M Ericsson (Publ) | Method and system for constructing a domain name for a radio network node in a cellular communication system |
| CN103095667B (zh) * | 2011-11-08 | 2015-03-11 | 华为技术有限公司 | 授权信息传递方法、中继设备及服务器 |
| US10263848B2 (en) * | 2013-03-20 | 2019-04-16 | Wolting Holding B.V. | Compiler for and method for software defined networks |
| KR102295394B1 (ko) * | 2014-08-27 | 2021-09-01 | 아씨아 에스피이, 엘엘씨 | 액세스 노드의 가상화 구현을 위한 시스템, 방법 및 장치 |
| CN105391568B (zh) | 2014-09-05 | 2019-07-23 | 华为技术有限公司 | 一种软件定义网络sdn的实现方法、装置和系统 |
| CN104486103B (zh) * | 2014-12-03 | 2018-03-16 | 新华三技术有限公司 | 一种报文传输的方法和设备 |
| CN105791175B (zh) * | 2014-12-26 | 2019-04-12 | 电信科学技术研究院 | 软件定义网络中控制传输资源的方法及设备 |
| WO2017131285A1 (ko) * | 2016-01-25 | 2017-08-03 | 쿨클라우드(주) | 컨테이너 네트워크 관리 시스템 및 컨테이너 네트워킹 방법 |
| CN107040441B (zh) * | 2016-02-04 | 2020-01-21 | 华为技术有限公司 | 跨数据中心的数据传输方法、装置及系统 |
| CN109845201A (zh) * | 2016-08-08 | 2019-06-04 | 西门子股份公司 | 用于对不同技术领域的信息物理网络、特别是工业自动化网络进行软件定义联网的方法、软件代理、联网设备和sdn控制器 |
| US10505870B2 (en) * | 2016-11-07 | 2019-12-10 | At&T Intellectual Property I, L.P. | Method and apparatus for a responsive software defined network |
| US10673751B2 (en) * | 2017-04-27 | 2020-06-02 | At&T Intellectual Property I, L.P. | Method and apparatus for enhancing services in a software defined network |
-
2017
- 2017-09-11 CN CN201710814496.XA patent/CN109495594B/zh active Active
-
2018
- 2018-07-05 EP EP18854338.3A patent/EP3672208A4/en not_active Ceased
- 2018-07-05 WO PCT/CN2018/094709 patent/WO2019047611A1/zh not_active Ceased
-
2020
- 2020-03-11 US US16/815,454 patent/US11265244B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN102088391A (zh) * | 2009-12-07 | 2011-06-08 | 华为技术有限公司 | 一种IPv6报文的处理方法、设备和系统 |
| CN104917849A (zh) * | 2014-03-11 | 2015-09-16 | 华为技术有限公司 | 一种消息处理方法、接入控制器及网络节点 |
| US20170104609A1 (en) * | 2015-10-09 | 2017-04-13 | Openet Telecom Ltd. | System and Method for Enabling Service Lifecycle Based Policy, Licensing, and Charging in a Network Function Virtualization Ecosystem |
| WO2017101970A1 (en) * | 2015-12-14 | 2017-06-22 | Telefonaktiebolaget Lm Ericsson (Publ) | Optimized dynamic software defined network |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP3672208A4 |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115017278A (zh) * | 2022-05-10 | 2022-09-06 | 深圳市疾病预防控制中心(深圳市卫生检验中心、深圳市预防医学研究所) | 基于会话服务客户端的数据处理方法及会话服务客户端 |
| CN115017278B (zh) * | 2022-05-10 | 2023-10-20 | 深圳市疾病预防控制中心(深圳市卫生检验中心、深圳市预防医学研究所) | 基于会话服务客户端的数据处理方法及会话服务客户端 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP3672208A1 (en) | 2020-06-24 |
| CN109495594A (zh) | 2019-03-19 |
| US20200213226A1 (en) | 2020-07-02 |
| US11265244B2 (en) | 2022-03-01 |
| CN109495594B (zh) | 2022-03-29 |
| EP3672208A4 (en) | 2020-06-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN109495594B (zh) | 一种数据传输方法、pnf sdn控制器、vnf sdn控制器及系统 | |
| CN108566451B (zh) | 一种消息处理方法、接入控制器及网络节点 | |
| US6901079B1 (en) | Providing different quality of services (QOS) to different point-to-point sessions | |
| CN101729500B (zh) | 一种ip会话标识方法、装置和系统 | |
| US8804562B2 (en) | Broadband network system and implementation method thereof | |
| CN106878199B (zh) | 一种接入信息的配置方法和装置 | |
| CN105357180B (zh) | 网络系统、攻击报文的拦截方法、装置和设备 | |
| CN112104757A (zh) | Ip地址的配置方法、设备及系统 | |
| WO2017114157A1 (zh) | 一种在光接入网中建立虚拟接入节点的方法和设备 | |
| WO2014114058A1 (zh) | 一种数据报文转发方法、用户驻地设备和系统 | |
| WO2012109849A1 (zh) | Mac地址分配方法和设备 | |
| CN103095667B (zh) | 授权信息传递方法、中继设备及服务器 | |
| CN112398800A (zh) | 一种数据处理方法及装置 | |
| CN114125995A (zh) | 数据传输方法及装置 | |
| JP7842920B2 (ja) | Ipネットワークにアクセスするための通信サービスを提供するための装置、方法及びそのためのプログラム | |
| WO2012041168A1 (zh) | 用于IPv6网络的网络连接处理方法及其装置 | |
| CN107257558B (zh) | 报文转发方法及装置 | |
| JP2023002448A (ja) | Ipネットワークにアクセスするための通信サービスを提供するための装置、方法及びそのためのプログラム | |
| CN102026164A (zh) | 一种获取终端身份标识的方法及系统 | |
| CN107547467B (zh) | 一种电路认证处理方法、系统及控制器 | |
| CN105516376A (zh) | 一种移动终端接入家庭网关的控制方法及家庭网关 | |
| WO2014201783A1 (zh) | 一种自组网的加密鉴权方法、系统及终端 | |
| CN106357483A (zh) | 消息传输方法、接入节点、接入控制器及接入系统 | |
| KR101683013B1 (ko) | Dhcp 옵션 60, 61 및 82를 이용한 ip 주소 할당 방법 및 이를 위한 시스템 | |
| WO2014169590A1 (zh) | 一种数据业务通信方法、设备及系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 18854338 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2018854338 Country of ref document: EP Effective date: 20200318 |