Summary of the invention
The embodiment of the present invention provides method for building up, the apparatus and system of a kind of network special line, establishes network to reduce
Operation complexity when special line.
In order to achieve the above objectives, the embodiment of the present invention adopts the following technical scheme that
In a first aspect, the embodiment of the present invention provides a kind of method for building up of network special line, comprising: determining user's Caytoniales
When marking the network private line service of client, the first policy information is received;First policy information, which is used to indicate, establishes target customer's
Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;It receives at least two CPE
What any one request CPE was sent establishes connection request message;Wherein, this is established connection request message and is used to indicate foundation request
Interface channel in CPE and at least one opposite end CPE between each opposite end CPE;According to connection request message is established, obtains and meet
The mark of first vCPE of the demand information of the network special line of the target customer and the first virtual expansible local area network VxLAN
Configuration;The configuration of the mark of first vCPE and the first VxLAN are sent to the request CPE and each opposite end
The corresponding vCPE of CPE.
A kind of method for building up of network special line provided in an embodiment of the present invention is determining that user is open-minded by SDN controller
When the network private line service of target customer, the first policy information is received;First policy information, which is used to indicate, establishes target customer
Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;SDN controller receive to
What any one request CPE was sent in few two CPE establishes connection request message;Wherein, this is established connection request message and is used for
It indicates to establish the interface channel in request CPE and at least one opposite end CPE between each opposite end CPE;SDN controller is according to foundation
Connection request message obtains the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN;Wherein, first
VCPE is the vCPE for meeting the demand information of network special line of target customer;The mark of first vCPE is sent to by SDN controller
The corresponding vCPE of each opposite end CPE, and the configuration of the first VxLAN is sent to request CPE and the first vCPE, the present invention can be real
The plug and play of existing cpe device, it is automatic open-minded, reduce human cost;It introduces SDN controller and increases special line flexibility, it can be with
It is tactful quickly to modify product bandwidth and QoS etc. for centralized control;Cpe device only needs to have basic function, and additional function is by vCPE
It realizes, cpe device cost and the cost of manual maintenance can be reduced.
With reference to first aspect, in the first possible implementation of the first aspect, side provided in an embodiment of the present invention
Method further include: receive target service configuration information, carry target requirement information in the target service configuration information, which needs
Ask information for being updated to the network special line of target customer;Target service configuration information is parsed, generation strategy is matched
Confidence breath;The strategy configuration information is used to indicate request CPE and each opposite end CPE and is updated to its existing configuration information;
To request CPE, the corresponding vCPE of request CPE, the corresponding vCPE sending strategy configuration information of each opposite end CPE, so as to call request
Its existing configuration information update is tactful configuration information by CPE and each opposite end CPE, and the CPE that makes to call request corresponding
VCPE and the corresponding vCPE of each opposite end CPE reformulate the plan for meeting target requirement information according to tactful configuration information
Slightly.
With reference to first aspect or the first possible implementation of first aspect, second in first aspect are possible
In implementation, before the network private line service for determining target customer is opened, the method provided in the embodiment of the present invention includes:
The first authentication request message of the identification information for carrying the first CPE of the first CPE transmission is received, the first CPE is institute
State any one at least two CPE;If it is determined that the identification information of the first CPE carried in the first authentication request message and pre-
If the information matches in database, then the first certification instruction message is sent to the first CPE, and show service fulfillment prompting message,
The first certification instruction message is used to indicate the first CPE and authenticates successfully, and whether which is used for prompt
Open the network private line service of target customer;If it is determined that receiving the first instruction message, it is determined that the network special line of target customer
Service fulfillment.
Any one possible implementation with reference to first aspect or in second of possible implementation of first aspect,
In a third possible implementation of the first aspect, it is sent by the configuration of the mark of the first vCPE and the first VxLAN
After the corresponding vCPE of opposite end CPE each in request CPE and at least one opposite end CPE, side provided in an embodiment of the present invention
Method further include: if it is determined that the corresponding vCPE of request CPE vCPE phase corresponding with the first opposite end CPE in the CPE of at least one opposite end
Together, then the request CPE being used to indicate to request CPE transmission, message to be sent is directly sent to the first opposite end CPE's
Second indication information;If it is determined that the corresponding vCPE of request CPE is corresponding with the first opposite end CPE in the CPE of at least one opposite end
VCPE is not identical, then is used to indicate the request CPE to request CPE transmission and the message to be sent is sent to request CPE's
VCPE, so that the message to be sent is transmitted to the corresponding vCPE's of the first opposite end CPE by the vCPE of the request CPE
Third indicates information.
The third possible implementation with reference to first aspect, in the 4th kind of possible implementation of first aspect
In, it requests in the vCPE and at least one opposite end CPE of CPE between the corresponding vCPE of each opposite end CPE through VxLAN or GRE
Tunnel is communicated.
Second aspect, what the embodiment of the present invention provided a kind of network special line establishes device, comprising: the first receiving unit is used
In when determining that user opens the network private line service of target customer, reception is used to indicate the network special line for establishing target customer
First policy information;The network special line of the target customer includes at least two customer terminal equipment CPE;Second receiving unit is used
What any one request CPE was sent at least two CPE of reception establishes connection request message, this establishes connection request message use
The interface channel in request CPE and at least one opposite end CPE between each opposite end CPE is established in instruction;Selecting unit is used for root
According to connection request message is established, the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN are obtained;Its
In, the first vCPE is the vCPE for meeting the demand information of network special line of the target customer;First transmission unit, for by the
The mark of one vCPE is sent to the corresponding vCPE of each opposite end CPE, and by the configuration of the first VxLAN be sent to request CPE and
First vCPE.
In conjunction with the first possible implementation of second aspect, in second of possible implementation of second aspect
In, the device in the embodiment of the present invention further include: third receiving unit, the target service that reception carries target requirement information are matched
Confidence breath, the target requirement information is for being updated the network special line of the target customer;Resolution unit, for target
Service configuration information is parsed, generation strategy configuration information;The strategy configuration information is used to indicate request CPE and each opposite end
CPE is updated its existing configuration information;Second transmission unit is used for request CPE, requests the corresponding vCPE of CPE, every
The corresponding vCPE sending strategy configuration information of a opposite end CPE, so that the request CPE and each opposite end CPE are had
Configuration information update be tactful configuration information, and the corresponding vCPE of CPE and each opposite end CPE that makes to call request corresponding
VCPE reformulates the strategy for meeting target requirement information according to the tactful configuration information.
In conjunction with the possible implementation of the first of second aspect or second aspect, second in second aspect is possible
In implementation, device provided in an embodiment of the present invention further include: the 4th receiving unit, for receiving taking for the first CPE transmission
First authentication request message of the identification information with the first CPE, the first CPE are appointing at least two CPE
Meaning one;First judging unit, the identification information and present count of the first CPE for judging to carry in the first authentication request message
Whether matched according to the information in library;Third transmission unit is taken for determining in the first authentication request message in the first judging unit
When information matches in the identification information and presetting database of the first CPE of band, the first certification instruction is sent to the first CPE and is disappeared
Breath, and show service fulfillment prompting message, which is used to indicate the first CPE and authenticates successfully, which opens
Logical prompting message is used to prompt whether to open the network private line service of target customer;Determination unit, for receiving the determining
When one instruction message, determine that the network private line service of target customer is open-minded.
In second of possible implementation in conjunction with second aspect to second aspect, the third in second aspect may
Implementation in, device provided in an embodiment of the present invention further include: second judgment unit, for judge request CPE it is corresponding
Whether vCPE vCPE corresponding with the first opposite end CPE in the CPE of at least one opposite end be identical;4th transmission unit, for the
Two judging units determine the corresponding vCPE of the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of request CPE
When identical, sent to request CPE and be used to indicate the second finger that message to be sent is directly sent to the first opposite end CPE by request CPE
Show information;5th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit
In the corresponding vCPE of the first opposite end CPE it is not identical when, to request CPE transmission be used to indicate the request CPE will be described pending
Text of delivering newspaper is sent to the vCPE of request CPE, so that the message to be sent is transmitted to described the by the vCPE of the request CPE
The third of the corresponding vCPE of a pair of end CPE indicates information.
In conjunction with the third possible implementation of second aspect, in the 4th kind of possible implementation of second aspect
In, it requests in the vCPE and at least one opposite end CPE of CPE between the corresponding vCPE of each opposite end CPE through VxLAN or GRE
Tunnel is communicated.
The third aspect, what the embodiment of the present invention provided a kind of network special line establishes system, comprising: network layer, arranging service
Layer and control layer;Operation has VNFM (Virtual Network Function Management, virtual net on control layer
Network function management unit) and as any one is possible into the 5th kind of possible implementation of second aspect for second aspect
Network special line establishes device described in implementation;Operation has request CPE in network layer, corresponding with request CPE
VCPE, at least one opposite end CPE and the corresponding vCPE of each opposite end CPE;Wherein, arranging service layer, for receiving user's hair
The first business request information sent carries the demand letter for opening the network special line of target customer in first business request information
Breath, and for generating the first plan for meeting the demand information of network special line of target customer according to first business request information
Slightly information, and device and VNFM are established for what the first policy information was sent to network special line, first policy information
In including at least two CPE identification information and the target customer network special line demand information;VNFM is used for
The first policy information is received, and establishes the network special line for meeting target customer in data center according to first policy information
The vCPE of demand information;Network special line establishes device, for establishing the request CPE in network layer according to the first policy information
Interface channel between vCPE corresponding with request CPE is established in the corresponding vCPE and at least one opposite end CPE of request CPE
Channel between the corresponding vCPE of each opposite end CPE;And establish each opposite end CPE and institute in the CPE of at least one opposite end
The channel between the corresponding vCPE of opposite end CPE is stated, and sends control instructions information to network layer, control instructions information is for referring to
Show that the request CPE sends message each opposite end CPE at least one opposite end CPE;Network layer refers to for receiving control
Show information, and according to the control instructions information, message is sent to each opposite end in the CPE of at least one opposite end from request CPE
CPE。
In conjunction with the third aspect, in the first possible implementation of the third aspect, arranging service layer is also used to, and is received
The second business request information that 2nd CPE is sent, the second business request information are used to indicate the network special line for updating target customer,
And for generating target service configuration information according to the second business request information;And target service configuration information is sent to
The network special line establishes device, and the 2nd CPE is any one at least two CPE.
In conjunction with the first possible implementation of the third aspect, in second of possible implementation of the third aspect
In, arranging service layer is also used to generate the first authentication url request message, first certification chain according to the first business request information
It connects request message and is used to indicate the certification completed to the 2nd CPE.
In conjunction with the first possible implementation of the third aspect or second of possible implementation of the third aspect,
In the third possible implementation of the third aspect, control instructions information is second indication information, then requests CPE directly will report
Text is sent to each opposite end CPE in the CPE of at least one opposite end;The control instructions information is that third indicates information, then requests
The message is transmitted to the vCPE of the opposite end CPE by CPE by the vCPE of request CPE, so that the vCPE of the opposite end CPE
After the message is carried out decapsulation and encapsulated again, it is transmitted to the opposite end CPE.
In conjunction with the third aspect to the third aspect the third possible implementation in any one possible implementation,
In the fourth possible implementation of the third aspect, VNFM is also used to: receiving the target service configuration information;According to mesh
Mark service configuration information, however, it is determined that there is no the target service configuration information resources of virtual machine is met, then according to the target
Service configuration information establishes the first resources of virtual machine, and the first resources of virtual machine is meet the target service configuration information virtual
Machine resource.
Specific embodiment
For the ease of clearly describing the technical solution of the embodiment of the present invention, in an embodiment of the present invention, use " the
One ", the printed words such as " second ", " third " distinguish function and the essentially identical identical entry of effect or similar item, this field skill
Art personnel are understood that the printed words such as " first ", " second ", " third " are not defined quantity and execution order.
The method for building up of network special line provided in an embodiment of the present invention can be applied to the establishing in system of network special line, such as
Shown in Fig. 1, the system of establishing of the network special line includes: that arranging service layer 10, network special line establish device 20 and network layer
30, wherein the device 20 of establishing of network special line includes SND (Software Defined Networking, software defined network)
Controller 201 and VNFM (Virtualised Network Function Manager, the network function module pipe of virtualization
Manage device) 202.
Wherein, arranging service layer 10 can carry out policy distribution and the management of business, can be to 201 He of SDN controller
VNFM202 is managed collectively.For example, arranging service layer 10 and Operation Support System (Operations Support
System, OSS)/business support system (Business support system, BSS) docking, pass through for receiving user
The first business request information and the second business request information that OSS/BSS is sent.
VNFM202 is the functional module of the network function module life cycle management for being virtualized.
Network layer 30 includes at least two CPE (Customer Premise Equipment, customer terminal equipment) (as schemed
CPEA301 and CPEB303 shown in 1) and data center, wherein data center includes one or more VCPE, the VCPE
It is established by VNFM according to the first policy information, wherein there are at least one to request CPE and opposite end at least two CPE
CPE, request CPE and opposite end CPE be it is opposite, when message from CPEA301 to CPEB303 send when, CPEA301 be request CPE,
CPEB303 is the opposite end CPE of CPEA301;When message is sent from CPEB303 to CPEA301, CPEB303 is request CPE,
CPEA301 be opposite end CPE, when between CPEB303 and CPEA301 network special line establish after, message can from CPEB303 to
CPEA301 is sent, and can also be sent from CPEA301 to CPEB303.
CPE uses general X86-based in the embodiment of the present invention, has basic routing function, supports DHCP, VxLAN tunnel
Road is established and the functions such as ipsec encryption, and vCPE carries out Virtual Private Line foundation under the management of SDN controller, supports QoS
(Quality of Service, service quality), the functions such as ACL (Access Control List, accesses control list), net
Network special line establish SDN controller 301 in device 20 it is equal in network layer 30 each CPE (for example, CPEA301 and
The centralized management control of the equipment such as the vCPE CPEB303) and in data center, VNFM202 are responsible for the foundation and deletion of virtual machine.
Specifically, a kind of method for building up of network special line is provided in conjunction with Fig. 1 embodiment of the present invention, as shown in Fig. 2, this method
Include:
S301, SDN controller receive the first strategy letter when determining that user opens the network private line service of target customer
Breath;First policy information is used to indicate the network special line for establishing target customer;Wherein, the network special line of target customer includes extremely
Few two customer terminal equipment CPE;
What any one request CPE was sent at least two CPE of S302, SDN controller reception establishes connection request message;
Wherein, this is established connection request message and is used to indicate in foundation request CPE and at least one opposite end CPE between each opposite end CPE
Interface channel;
According to connection request message is established, the mark and first for obtaining the first vCPE can virtually expand S303, SDN controller
Open up the configuration of local area network VxLAN;Wherein, the first vCPE is the vCPE for meeting the demand information of network special line of target customer;
The mark of first vCPE is sent to the corresponding vCPE of each opposite end CPE by S304, SDN controller, and by first
The configuration of VxLAN is sent to request CPE and the first vCPE.
A kind of method for building up of network special line provided in an embodiment of the present invention is determining that user is open-minded by SDN controller
When the network private line service of target customer, the first policy information is received;First policy information, which is used to indicate, establishes target customer
Network special line;Wherein, the network special line of target customer includes at least two customer terminal equipment CPE;SDN controller receive to
What any one request CPE was sent in few two CPE establishes connection request message;Wherein, this is established connection request message and is used for
It indicates to establish the interface channel in request CPE and at least one opposite end CPE between each opposite end CPE;SDN controller is according to foundation
Connection request message obtains the mark of the first vCPE and the configuration of the first virtual expansible local area network VxLAN;Wherein, first
VCPE is the vCPE for meeting the demand information of network special line of target customer;SDN controller is by the mark of the first vCPE and
The configuration of one VxLAN is sent to the request CPE and corresponding vCPE of each opposite end CPE, and what cpe device can be achieved in the present invention is
Plug-and-play, it is automatic open-minded, reduce human cost;It introduces SDN controller and increases special line flexibility, it can be with centralized control, quickly
It is tactful to modify product bandwidth and QoS etc.;Cpe device only needs to have basic function, and additional function is realized by vCPE, can reduce
Cpe device cost and the cost of manual maintenance.
Specifically, the first policy information in the embodiment of the present invention includes the demand information of the network special line of target customer,
The demand information of the network special line of target customer can be QoS (Quality of Service, Service Quality in the embodiment of the present invention
Amount) information, for example, bandwidth required for target user, the information such as priority.
Wherein, request CPE can establish connection request message to the transmission of SND controller by openflow agreement.
Specifically, the embodiment of the present invention is to the identification information of above-mentioned CPE without restriction, the identification information use of each CPE
In the unique identification CPE, illustratively, which can be MAC (the Medium Access of any one CPE
Control, media access control protocol) address;Or the product identification code of the CPE.
VCPE is located at data center, and IP address is relatively fixed, so SDN controller meeting retrieved beforehand knows the IP of vCPE
Address (or static addition), when receive that request CPE sends establishes connection request message, SDN controller can obtain CPE
IP address, VxLAN establish element include information, the SDN controllers such as interface name, VNI (mark), far-end IP can be according to foundation
Connection request message creates VxLAN, and distributes a VNI, and issue configuration message, informs its opposite end CPE and vCPE IP respectively
The information such as address and VNI, to establish the first VxLAN.
Illustratively, the mark of the first vCPE in the embodiment of the present invention can be the IP address of the first vCPE.
As long as VxLAN IP is up to can transmit in the embodiment of the present invention, as long as knowing in the starting point of VxLAN and clearing end
The mutual interface in road, IP address and VNI can establish the tunnel VxLAN, and the VxLAN of different sections is that previous VxLAN removes UDP
Behind packet header, as starting point, the tunnel VxLAN is re-established with next clearing end, VNI can change can also be constant, therefore
Property associated with each other is little, therefore carries out the IP management between the IP management and domain of same area, is not necessarily intended to know the IP address of the whole network.
Wherein, the network special line of target customer refers to the communication channel of linking objective Client Enterprise branch, so that target
It can be communicated, should be included at least each positioned at the target customer by the communication channel between the enterprise branch of client
CPE at enterprise branch.For example, the enterprise branch of target customer is located at different districts and cities, then the network of the target customer is special
The enterprise branch that line will also be located at different address is connected by specific communication channel, so that being located at different districts and cities
Enterprise branch can be communicated by the communication channel.Illustratively, if the enterprise branch of a target customer is located at
Then a CPE should be arranged at the enterprise branch in Xi'an in Beijing and Xi'an, and the enterprise branch at Beijing should also be set
A CPE is set, the network special line of the target customer in this way, which also refers to, will be located at the CPE of Xi'an bifurcation and be located at Beijing bifurcation
CPE connected by communication channel.
It can be from the vCPE of data center's acquisition the first policy information of satisfaction, the data center in specific step S302
Including at least one vCPE.Wherein, vCPE can be had more powerful processing function, can be used based on server with better function
In the forward process of mass data.VCPE in the data center is what VNFM was established according to the first policy information.
In order to facilitate the business change request etc. to the bandwidth of target network special line or QoS required for it of user voluntarily
It changes, method provided in an embodiment of the present invention further include:
S305, target service configuration information is received, carries target requirement information in the target service configuration information, the mesh
Mark demand information is for being updated the network special line of target customer;
Wherein, above-mentioned target service configuration information is sent by arranging service layer.
S306, target service configuration information is parsed, generation strategy configuration information;The strategy configuration information is for referring to
Show that request CPE and each opposite end CPE is updated its existing configuration information;
S307, match confidence to request CPE, the corresponding vCPE of request CPE, the corresponding vCPE sending strategy of each opposite end CPE
Breath so that its existing configuration information update is tactful configuration information by the CPE and each opposite end CPE that calls request, and makes
Request CPE corresponding vCPE and the corresponding vCPE of each opposite end CPE are reformulated according to tactful configuration information and are met the mesh
Mark the strategy of demand information.
The change to target network special line can be thus achieved in S306-S307 to the embodiment of the present invention through the above steps, thus
Improve the operating efficiency for establishing network special line.
The embodiment of the present invention is before step S301 further include:
S308, the first authentication request message that the first CPE is sent is received, is carried in first authentication request message
State the identification information of the first CPE;First CPE is any one at least two CPE;
S309, if it is determined that the first CPE carried in first authentication request message identification information and present count
According to the information matches in library, then the first certification instruction message is sent to the first CPE, and show service fulfillment prompting message,
The first certification instruction message is used to indicate the first CPE and authenticates successfully, and the service fulfillment prompting message is for prompting
Whether the network private line service of target customer is opened;
S310, if it is determined that receiving the first instruction message, it is determined that the network private line service of the target customer is open-minded.
Specifically, arranging service layer buys demand information when product business according to user after user buys product business
Corresponding policy information is generated, SDN controller and VNFM are sent to, and generates First Certificate message and is sent to user.
Wherein, which can generate in the form of a link, while be sent to user's in the form of mail
The mailbox registered when buying product business is sent to user in the form of short message and buys the mobile phone registered when product business
Number after user takes cpe device, accesses LAN mouthfuls by WAN mouthfuls of access networks, then with equipment such as PCs, cpe device meeting
It addresses the Dynamic Host Configuration Protocol server of default and distributes to one IP address of cpe device after Dynamic Host Configuration Protocol server certification.User logs in browser,
The authentication informations such as the MAC Address of cpe device are reported to SDN controller, SDN controller and database ratio by input authentication link
It after errorless, sent to cpe device and authenticates successful message, if it is not, sending the message of authentification failure.Cpe device is recognized
After demonstrate,proving successfully, the prompt for opening private line service whether at once can be jumped to, if SDN controller receives the first of user's transmission
Instruction message, it is determined that target network special line is opened in user's agreement, then opens target network special line immediately.
Illustratively, which can be that target network is opened in " agreement " being shown on PC webpage
Special line and " disagreeing " open the printed words of target network special line, for example, " YES " or " NO " printed words, the embodiment of the present invention is to this
Without limiting.
After step S304, method provided in an embodiment of the present invention further include:
S311, if it is determined that the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of the request CPE
Corresponding vCPE is identical, then sends second indication information to the request CPE, and the second indication information is used to indicate described ask
Ask CPE that message to be sent is directly sent to the first opposite end CPE;
S314, if it is determined that the first opposite end CPE in the corresponding vCPE and at least one opposite end CPE of the request CPE
Corresponding vCPE is not identical, then sends third to the request CPE and indicate that information, the third instruction information are used to indicate described
The message to be sent is sent to the vCPE of request CPE by request CPE, so that the vCPE of the request CPE will be described pending
Text of delivering newspaper is transmitted to the corresponding vCPE of the first opposite end CPE.
Specifically, requesting CPE pairs of each opposite end in the vCPE and at least one opposite end CPE of CPE in the embodiment of the present invention
It is communicated between the vCPE answered by VxLAN or gre tunneling.
As shown in figure 3, illustrating a kind of network special line provided in an embodiment of the present invention below by another specific embodiment
Method for building up.
Order when S401, arranging service layer buy service product according to user generates the network special line for meeting target customer
Demand information the first policy information and generate the first authentication url request message, wherein first authentication url request
Message is used to indicate the certification completed to CPE;
Wherein, SDN controller IP address and relevant policy information are carried in the first authentication url request message.
S402, the first policy information is sent to SDN controller and VNFM, and by the first authentication url request message
The mailing address registered when being sent to user's transacting business.
S403, SDN controller receive user by above-mentioned first certification connection request message transmission comprising request CPE's
First authentication request message of identification information;
Whether S404, SDN controller judge to store in the identification information and presetting database of request CPE consistent;
S405, SDN controller determine stored in the identification information and presetting database of request CPE it is consistent, then to asking
It asks CPE to send the first certification instruction message, and shows service fulfillment prompting message, which is used to indicate the
One CPE is authenticated successfully, which is used to prompt whether to open the network private line service of target customer;
Wherein, which is shown in user's checking first in the form of the page and authenticates connection request message
Window in.
S406, SDN controller determine stored in the identification information and presetting database of request CPE it is inconsistent, then to
CPE is requested to send authentification failure message;
After sending authentification failure message, it can carry in the authentification failure message in the embodiment of the present invention and request again
The message that user authenticates cpe device.After user's confirmation no longer authenticates cpe device, this certification is terminated.
S407, VNFM establish the need for meeting the network special line of the target customer according to the first policy information in data center
Seek the vCPE of information;
For S408, SDN controller after receiving the first instruction message, SDN controller then determines that user opens target visitor
The network private line service at family, and the demand for meeting the network special line of target customer is obtained from data center according to the first policy information
The IP address of the virtual client terminal device vCPE of information;
What any one request CPE was sent at least two CPE of S409, SDN controller reception establishes connection request message;
Wherein, the identification information that at least one opposite end CPE is carried in connection request message is established;
Illustratively, target customer's network special line includes positioned at the CPE in Xi'an and positioned at Pekinese CPE, then target is objective
Family network special line namely establish the CPE in Xi'an and the network special line between Pekinese CPE, if then request CPE be positioned at
What the CPE in Xi'an was sent, then the identification information positioned at Pekinese CPE should be carried by establishing in connection request message.
Specifically, each cpe device in target network special line should access and establish target in the actual operation process
In the network specified when network special line.,
S410, SDN controller can virtually expand according to the mark and first that establish the link the first vCPE of request message acquisition
Open up the configuration of local area network VxLAN;Wherein, the first vCPE is the demand information for meeting the network special line of the target customer
vCPE;
The mark of first vCPE is sent to the corresponding vCPE of each opposite end CPE by S411, SDN controller, and by first
The configuration of VxLAN is sent to the request CPE and the first vCPE.
As shown in figure 4, the embodiment of the present invention a kind of network special line is provided establish device, comprising:
First receiving unit 501, for receiving the first plan when determining that user opens the network private line service of target customer
Slightly information;First policy information is used to indicate the network special line for establishing target customer;Wherein, the network special line of the target customer
Including at least two customer terminal equipment CPE;
Second receiving unit 502 is asked for receiving the connection of establishing that any one request CPE is sent at least two CPE
Seek message, this establish connection request message be used to indicate foundation request CPE and at least one opposite end CPE in each opposite end CPE it
Between interface channel;
Selecting unit 503, for according to connection request message is established, the mark and first for obtaining the first vCPE virtually may be used
Extend the configuration of local area network VxLAN;Wherein, the first vCPE is the vCPE for meeting the demand information of network special line of target customer;
First transmission unit 504, for the mark of the first vCPE to be sent to the corresponding vCPE of each opposite end CPE, and
The configuration of first VxLAN is sent to request CPE and the first vCPE.
Optionally, device provided in an embodiment of the present invention further include:
Third receiving unit receives target service configuration information, carries target requirement in the target service configuration information
Information, the target requirement information is for being updated the network special line of target customer;
Resolution unit, for being parsed to target service configuration information, generation strategy configuration information;The strategy configuration
Information be used to indicate in the request CPE and at least one opposite end CPE each opposite end CPE to its existing configuration information into
Row updates;
Second transmission unit, for being sent out to request CPE, the corresponding vCPE of request CPE, the corresponding vCPE of each opposite end CPE
Tactful configuration information is sent, so that its existing configuration information update is strategy configuration by the CPE and each opposite end CPE that calls request
Information, and the corresponding vCPE of the CPE and corresponding vCPE of each opposite end CPE that makes to call request make again according to tactful configuration information
Surely meet the strategy of target requirement information.
Optionally, device provided in an embodiment of the present invention further include:
4th receiving unit, for receiving the first authentication request message of the first CPE transmission, first authentication request message
In carry the identification information of the first CPE;First CPE is any one at least two CPE;
First judging unit, the identification information of the first CPE for judging to carry in the first authentication request message and default
Whether the information in database matches;
Third transmission unit, for determining the first CPE's carried in the first authentication request message in the first judging unit
When information matches in identification information and presetting database, the first certification instruction message is sent to the first CPE, and show that business is opened
Logical prompting message, the first certification instruction message are used to indicate the first CPE and authenticate successfully, which uses
The network private line service of target customer whether is opened in prompt;
Determination unit, for determining the network special line industry of the target customer when determination receives the first instruction message
It is engaged in open-minded.
Optionally, shown device further include:
Second judgment unit requests the first opposite end in CPE corresponding vCPE and at least one opposite end CPE for judging
Whether the corresponding vCPE of CPE is identical;
4th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit
In the corresponding vCPE of the first opposite end CPE it is identical when, send second indication information to request CPE, which is used for
Message to be sent is directly sent to the first opposite end CPE by instruction request CPE;
5th transmission unit, for determining the corresponding vCPE and at least one opposite end CPE of request CPE in second judgment unit
In the corresponding vCPE of the first opposite end CPE it is not identical when, to request CPE send third indicate information, the third indicate information use
Message to be sent is sent to the vCPE of request CPE in instruction request CPE, so that the vCPE for the CPE that calls request is by message to be sent
It is transmitted to the corresponding vCPE of the first opposite end CPE.
Optionally, it requests to lead between the corresponding vCPE of each opposite end CPE in the vCPE and at least one opposite end CPE of CPE
It crosses VxLAN or gre tunneling is communicated.
As shown in figure 5, the embodiment of the present invention, which provides a kind of network special line, establishes system, including arranging service layer, control layer
And network layer.
Wherein, the arranging service layer, for the first business request information of reception, and for according to the first service request
Message generates the first policy information for meeting the demand information of network special line of target customer, and by first policy information
Be sent to the network special line establishes device and the VNFM, includes described at least two in first policy information
The demand information of the identification information of CPE and the network special line of the target customer;Wherein, it is carried in the first business request information
There is the demand information for the network special line for opening target customer;
VNFM meets institute in data center's foundation for receiving first policy information, and according to the first policy information
State the vCPE of the demand information of the network special line of target customer;
Network special line establishes device (namely SDN controller), for establishing in network layer according to the first policy information
The interface channel between CPE and vCPE corresponding with request CPE is requested, it is right at least one to establish the corresponding vCPE of request CPE
Hold the channel in CPE between the corresponding vCPE of each opposite end CPE;And establish each opposite end in the CPE of at least one opposite end
Channel between CPE vCPE corresponding with the opposite end CPE, and control instructions information, control instructions letter are sent to network layer
Breath is used to indicate the request CPE and sends message each opposite end CPE at least one opposite end CPE;
Network layer, for receiving control instructions information, and according to control instructions information, by message from the request CPE
It is sent to each opposite end CPE at least one opposite end CPE.
Optionally, arranging service layer is also used to, and receives the second business request information that the 2nd CPE is sent, second industry
Business request message is used to indicate the network special line for updating the target customer, and for according to second business request information
Generate target service configuration information;And device is established by what the target service configuration information was sent to the network special line,
2nd CPE is any one at least two CPE.
Optionally, arranging service layer is also used to generate the request of the first authentication url according to first business request information
Message, the first authentication url request message are used to indicate the certification completed to the 2nd CPE.
Optionally, control instructions information is second indication information, then the message is directly sent to institute by the request CPE
State each opposite end CPE in the CPE of at least one opposite end;
The control instructions information is that third indicates information, then the message is passed through the request CPE by the request CPE
VCPE be transmitted to the vCPE of the opposite end CPE so that the vCPE of the opposite end CPE carries out decapsulation and again to the message
After encapsulation, it is transmitted to the opposite end CPE.
Optionally, VNFM is also used to:
Receive the target service configuration information;
According to the target service configuration information, however, it is determined that there is no meet the target service configuration information virtual machine money
Source, then establish the first resources of virtual machine according to the target service configuration information, and first resources of virtual machine is described in satisfaction
The resources of virtual machine of target service configuration information.
In several embodiments provided herein, it should be understood that disclosed system, device and method can be with
It realizes by another way.For example, the apparatus embodiments described above are merely exemplary, for example, the unit
It divides, only a kind of logical function partition, there may be another division manner in actual implementation, such as multiple units or components
It can be combined or can be integrated into another system, or some features can be ignored or not executed.Another point, it is shown or
The mutual coupling, direct-coupling or communication connection discussed can be through some interfaces, the indirect coupling of device or unit
It closes or communicates to connect, can be electrical property, mechanical or other forms.
The unit as illustrated by the separation member may or may not be physically separated, aobvious as unit
The component shown may or may not be physical unit, it can and it is in one place, or may be distributed over multiple
In network unit.It can select some or all of unit therein according to the actual needs to realize the mesh of this embodiment scheme
's.
It, can also be in addition, the functional units in various embodiments of the present invention may be integrated into one processing unit
It is that the independent physics of each unit includes, can also be integrated in one unit with two or more units.Above-mentioned integrated list
Member both can take the form of hardware realization, can also realize in the form of hardware adds SFU software functional unit.
The above-mentioned integrated unit being realized in the form of SFU software functional unit can store and computer-readable deposit at one
In storage media.Above-mentioned SFU software functional unit is stored in a storage medium, including some instructions are used so that a computer
Equipment (can be personal computer, server or the network equipment etc.) executes the portion of each embodiment the method for the present invention
Step by step.And storage medium above-mentioned includes: USB flash disk, mobile hard disk, read-only memory (Read-Only Memory, abbreviation
ROM), random access memory (Random Access Memory, abbreviation RAM), magnetic or disk etc. are various can store
The medium of program code.
Finally, it should be noted that the above embodiments are merely illustrative of the technical solutions of the present invention, rather than its limitations;Although
Present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that: it still may be used
To modify the technical solutions described in the foregoing embodiments or equivalent replacement of some of the technical features;
And these are modified or replaceed, technical solution of various embodiments of the present invention that it does not separate the essence of the corresponding technical solution spirit and
Range.