TWI774215B - Terminal device management system and method thereof - Google Patents
Terminal device management system and method thereof Download PDFInfo
- Publication number
- TWI774215B TWI774215B TW110103062A TW110103062A TWI774215B TW I774215 B TWI774215 B TW I774215B TW 110103062 A TW110103062 A TW 110103062A TW 110103062 A TW110103062 A TW 110103062A TW I774215 B TWI774215 B TW I774215B
- Authority
- TW
- Taiwan
- Prior art keywords
- terminal equipment
- packet
- label
- switches
- switch
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 37
- 238000001514 detection method Methods 0.000 claims description 46
- 238000006243 chemical reaction Methods 0.000 claims description 15
- 238000004891 communication Methods 0.000 claims description 2
- 230000008859 change Effects 0.000 abstract description 2
- 230000006870 function Effects 0.000 description 15
- 238000005516 engineering process Methods 0.000 description 8
- 230000008569 process Effects 0.000 description 8
- 230000006855 networking Effects 0.000 description 6
- 238000010276 construction Methods 0.000 description 5
- 238000002955 isolation Methods 0.000 description 4
- 238000010586 diagram Methods 0.000 description 3
- 230000008676 import Effects 0.000 description 3
- 238000012544 monitoring process Methods 0.000 description 3
- 238000012545 processing Methods 0.000 description 3
- 230000008901 benefit Effects 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000009471 action Effects 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 238000012423 maintenance Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000009467 reduction Effects 0.000 description 1
- 238000010845 search algorithm Methods 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Images
Landscapes
- Alarm Systems (AREA)
- Computer And Data Communications (AREA)
- Electrical Discharge Machining, Electrochemical Machining, And Combined Machining (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
本發明係關於一種管控技術,尤其關於一種終端設備管控系統與方法。 The present invention relates to a management and control technology, in particular to a terminal equipment management and control system and method.
在越來越多企業開放BYOD(Bring Your Own Device,自攜電子設備)後,管控不同型態的終端設備以符合資訊安全規範已成為不可或缺的功能。在傳統網路架構中,連網管控可由兩種方法達成,其一是藉由在接取端交換器上設定網際網路協定(IP,Internet Protocol)位址與媒體存取控制位址(MAC address,medium access control address)之綁定而達成,但終端設備如果有跨交換器移動需求,則需要事先(proactive)在多台交換器上做相同的設定才能確保終端設備移動至不同交換器後可以連網。另一種方法則是在匯集端防火牆設定防火牆規則,將不允許連網設備發出的封包過濾丟棄,這種方法因只要在單一機器設定,相較於前者較為方便,但此方法僅能防止終端設備連線至外部網路,內部網路間還是可以互相傳輸資料。此外,在集中管控的網路架構中,網路控制器可以透過終端設備偵測功能,偵測終端設備位置並動態(reactive)在其連接的交換器增加規則,進而在接取端達到連網管控功能,簡化網路管理人員需手動 至各交換器設定的流程,並減少交換器間的無效流量。然而由於目前多數可控制交換器價格仍然比傳統網路交換器(以下簡稱傳統交換器)高,所以如何在有限的經費中,整合多種異質的網路交換器並達到終端設備位置偵測、連網管控與網路切片功能(Network Slicing)已成為亟待解決之問題。 After more and more enterprises open up BYOD (Bring Your Own Device), it has become an indispensable function to control different types of terminal devices to comply with information security regulations. In the traditional network architecture, network management and control can be achieved in two ways. One is by setting an Internet Protocol (IP, Internet Protocol) address and a media access control address (MAC address) on the access switch. address, medium access control address), but if the terminal device needs to move across switches, it needs to make the same settings on multiple switches in advance to ensure that the terminal device moves to different switches. Can connect to the Internet. Another method is to set firewall rules on the firewall at the sink to filter and discard the packets sent by the devices that are not allowed to connect to the network. This method is more convenient than the former because it only needs to be set on a single machine, but this method can only prevent the terminal equipment Connected to the external network, the internal network can still transfer data to each other. In addition, in the centralized management and control network architecture, the network controller can detect the location of the terminal device through the terminal device detection function, and dynamically (reactively) add rules to the switch connected to it, so as to achieve network connection at the access end. Management and control functions, simplify network management personnel need to manually to the flow set by each switch, and reduce invalid traffic between switches. However, since the price of most controllable switches is still higher than that of traditional network switches (hereinafter referred to as traditional switches), how to integrate a variety of heterogeneous network switches and achieve terminal device location detection, connection The network management and control and network slicing function (Network Slicing) have become problems to be solved urgently.
目前有一種技術,係利用主從(Client/Server)架構,於終端設備安裝監控元件,並利用此元件分別與內網伺服器/外網伺服器(中央控管主機)之通訊界面建立連線過程中,判斷該設備位於內網或外網,並將該設備的網際網路協定位址及主機保管者等資訊傳送給控管主機,自控管主機取得對應的控管政策並套用。此方法雖可判斷該設備位於內網環境或外網環境中,並依照環境及主機保管者資訊取得並套用控管政策以達到連網管控目的,但此方法須於終端設備安裝監控元件才能使用,對網路管理人員與使用者而言皆不方便;另一方面,此方法即使是在內網環境,網路管理人員於查測網路時,也無法精確得知該設備之精確位置,進而造成管理維運上的不方便。 At present, there is a technology that uses a master-slave (Client/Server) architecture to install monitoring components on terminal devices, and use this component to establish a connection with the communication interface of the internal network server/external network server (central control host) respectively. During the process, it is determined that the device is located on the internal network or the external network, and information such as the Internet protocol address of the device and the host custodian is sent to the control host, and the control host obtains the corresponding control policy and applies it. Although this method can determine whether the device is located in the internal network environment or the external network environment, and obtain and apply the control policy according to the environment and host custodian information to achieve the purpose of network management and control, but this method requires the installation of monitoring components on the terminal device to be used. , which is inconvenient for both network administrators and users; on the other hand, even in an intranet environment, network administrators cannot accurately know the exact location of the device when checking the network. This leads to inconvenience in management and maintenance.
目前有另一種技術,係整合軟體定義網路與傳統網路,於混合式環境中提供網路切片與隔離功能。此技術係以電腦網路中的虛擬區域網路(VLAN,Virtual Local Area Network)功能為基底,實作一使用網路組構協定(NETCONF)的控制器,以控制傳統網路交換器,並以一虛擬區域網路標籤(VLAN Tag)代表一網路切片的方式,動態地在傳統網路交換器間建立多條分屬不同網路切片的虛擬路徑(Virtual Link)。另一方面,支援開放流量協定(OpenFlow)的交換器(可控制交換器)則由OpenFlow控制器設定,將傳統網路交換器間的虛擬路徑串接,以達成接取在不同交換器底下的終端設備能夠在相同網路切片的功能。此技術提出一可節省成本且具備網路切片功能之方法, 但受限於虛擬網路標籤欄位僅有12位元,最多只能切割出4096個網路切片,且此技術需完整的控制拓樸中所有的交換器,才能建立出網路切片功能,若網路拓樸因需求變得日漸複雜時,網路控制器的負擔也會逐漸增加,會造成控制層效能問題。 There is another technology that integrates software-defined networking and traditional networking to provide network slicing and isolation in a hybrid environment. This technology is based on the virtual local area network (VLAN, Virtual Local Area Network) function in the computer network, and implements a controller using the network configuration protocol (NETCONF) to control the traditional network switch, and In a way of representing a network slice by a VLAN Tag, a plurality of virtual links (Virtual Links) belonging to different network slices are dynamically established between traditional network switches. On the other hand, switches (controllable switches) supporting Open Flow Protocol (OpenFlow) are set by the OpenFlow controller to concatenate virtual paths between traditional network switches to achieve access under different switches. End devices are capable of slicing functions in the same network. This technology proposes a cost-saving method with network slicing function, However, due to the fact that the virtual network label field is only 12 bits, only 4096 network slices can be cut at most, and this technology requires complete control of all switches in the topology to establish the network slice function. If the network topology becomes more and more complex due to the demand, the burden on the network controller will gradually increase, which will cause the performance problem of the control layer.
傳統網路中,終端設備資訊是以分散式且片斷的方式記錄於各台交換器中,或甚至出口端僅知道該網路環境中有終端設備,但不知道實際位置;此外,終端設備管控只能在出口端使用防火牆進行,終端設備在內部網路中是不被管控的。 In traditional networks, terminal equipment information is recorded in each switch in a decentralized and fragmented manner, or even the egress only knows that there are terminal equipment in the network environment, but does not know the actual location; in addition, terminal equipment management and control The firewall can only be used at the egress, and the terminal device is not controlled in the internal network.
本發明係透過集中式網路架構,將位於異質網路交換器的終端設備,將其資訊匯集至中央控制器,取得終端設備所屬的正確位置,且根據終端設備資訊,套用政策到可控制交換器上,讓網路管理者可便利且彈性的管控終端設備網路存取。 The present invention collects the information of terminal equipment located in heterogeneous network switches to a central controller through a centralized network structure, obtains the correct location of the terminal equipment, and applies a policy to the controllable switch according to the terminal equipment information. On the server, network administrators can conveniently and flexibly control network access of terminal devices.
本發明提出一種終端設備管控系統與方法,係於建置網路環境後,透過自動偵測或手動匯入網路拓樸資訊至中央控制器,並定義標籤與位置對應資訊。當中央控制器偵測到具有標籤之封包時,依據該具有標籤之封包的資料,取得終端設備資訊,並根據標籤資訊,計算出終端設備所屬的正確位置。當網路管理員要允許該終端設備使用網路時,根據先前取得的終端設備資訊組成連網政策,透過中央控制器再根據終端設備的位置,派送政策至對應的可控制交換器,以達到終端設備連網管控。此外,當終端設備移動位置時,中央控制器亦可偵測終端設備移動,自動更新終端設備資訊並派送政策至對應的 可控制交換器。因此,網路管理員僅須操作中央控制器,即可控管全域異質網路架構下的終端設備,讓網路管理員容易管理網路外,亦提供用戶網路安全性與便利性。 The present invention provides a terminal equipment management and control system and method. After the network environment is established, the network topology information is imported to the central controller through automatic detection or manual operation, and the corresponding information of tags and locations is defined. When the central controller detects a packet with a tag, it obtains terminal equipment information according to the data of the packet with a tag, and calculates the correct location of the terminal equipment according to the tag information. When the network administrator wants to allow the terminal device to use the network, a networking policy is formed according to the terminal device information obtained previously, and the central controller sends the policy to the corresponding controllable switch according to the location of the terminal device, so as to achieve Terminal equipment network management and control. In addition, when the terminal equipment moves, the central controller can also detect the movement of the terminal equipment, automatically update the terminal equipment information and send the policy to the corresponding controllable switch. Therefore, the network administrator only needs to operate the central controller to control the terminal devices under the global heterogeneous network structure, which makes it easy for the network administrator to manage outside the network, and also provides network security and convenience for the user.
本發明之終端設備管控系統與方法,係結合集中式管控與傳統網路設備成本較低的優點,在終端設備無須安裝軟體,且僅需額外導入並控制少量的可控制交換器,即可達成終端設備位置偵測、連網管控與網路切片之功能。 The terminal equipment management and control system and method of the present invention combines the advantages of centralized management and control and the low cost of traditional network equipment, no software needs to be installed in the terminal equipment, and only a small number of controllable switches need to be imported and controlled. The functions of terminal device location detection, network management and control and network slicing.
再者,本發明係著重於統一管控接入異質網路交換器之終端設備,即使終端設備從中央控制器無控制之傳統網路交換器接入網路,仍然可以被中央控制器所偵測並取得正確的位置,再由中央控制器派發政策至中央控制器可控制之網路交換器(以下簡稱可控制交換器),達到終端設備連網管控需求,並在終端設備移動位置後,中央控制器亦可依據終端設備位置,自動變更終端設備政策,維持終端設備網路設定。本發明適用但不限於軟體定義網路。本發明在異質網路下管控終端設備,除了原本可控制交換器外,進而將控管範圍延伸到傳統交換器,使網路管理者可取得正確的終端設備位置,提升管理準確性,並於可控制交換器進行終端設備連網管控,而提升網路安全性。此外,終端設備移動位置後,中央控制器亦可偵測且自動派送政策至對應的可控制交換器,達到網址可攜性。 Furthermore, the present invention focuses on the unified management and control of terminal equipment connected to heterogeneous network switches. Even if the terminal equipment accesses the network from a traditional network switch that is not controlled by the central controller, it can still be detected by the central controller. And get the correct location, and then the central controller distributes policies to the network switches that the central controller can control (hereinafter referred to as the controllable switches) to meet the network management and control requirements of the terminal equipment, and after the terminal equipment moves The controller can also automatically change the terminal device policy according to the location of the terminal device and maintain the network settings of the terminal device. The present invention is applicable to, but not limited to, software-defined networking. The present invention manages and controls terminal equipment under heterogeneous network, in addition to originally controlling switches, it further extends the control range to traditional switches, so that network administrators can obtain the correct terminal equipment positions, improve management accuracy, and improve management accuracy. The switch can be controlled to perform network management and control of terminal equipment, thereby improving network security. In addition, after the terminal device is moved, the central controller can also detect and automatically dispatch the policy to the corresponding controllable switch to achieve website portability.
1:終端設備 1: Terminal equipment
2:傳統交換器 2: traditional switch
3:可控制交換器 3: Controllable switch
4:閘道器 4: Gateway
5:中央控制器 5: Central controller
6:網際網路 6: Internet
100:拓樸管理單元 100: Topology Management Unit
110:可控制交換器管理模組 110: Controllable switch management module
120:傳統交換器管理模組 120: Traditional switch management module
130:連線管理模組 130:Connection management module
140:標籤註冊模組 140: Tag Registration Module
200:終端設備資訊管理單元 200: Terminal equipment information management unit
210:偵測模組 210: Detection Module
220:標籤轉換模組 220: Label Conversion Module
230:終端設備資訊管理模組 230: Terminal equipment information management module
300:終端設備政策管理單元 300: Terminal Device Policy Management Unit
310:終端設備政策管理模組 310: Terminal device policy management module
500:終端設備管控系統 500: Terminal equipment management and control system
S11~S18:終端設備偵測與記錄之流程步驟 S11~S18: Process steps of terminal equipment detection and recording
S21,S22,S24,S25:終端設備政策套用之流程步驟 S21, S22, S24, S25: Process steps for terminal device policy application
請參閱以下有關本發明之詳細說明及其附圖,將可進一步瞭解本發明之技術內容及其目的功效,其中: Please refer to the following detailed description of the present invention and its accompanying drawings, the technical content of the present invention and its purpose and effect will be further understood, wherein:
圖1為本發明之終端設備管控系統與方法之網路架構示意圖; FIG. 1 is a schematic diagram of the network architecture of the terminal equipment management and control system and method of the present invention;
圖2為本發明之終端設備管控系統與方法之架構圖; FIG. 2 is a structural diagram of the terminal equipment management and control system and method of the present invention;
圖3為本發明之終端設備管控系統與方法之終端設備偵測與記錄流程圖;以及 FIG. 3 is a flowchart of terminal device detection and recording of the terminal device management and control system and method of the present invention; and
圖4為本發明之終端設備管控系統與方法之終端設備政策套用流程圖。 FIG. 4 is a flowchart of the terminal device policy application of the terminal device management and control system and method of the present invention.
本發明提供一種適用於異質網路的終端設備管控系統與方法,其中,異質網路係指包含傳統交換器及可控制交換器之網路,而可控制交換器係指中央控制器可控制之交換器,傳統交換器係指中央控制器無控制之交換器。本發明的終端設備管控系統與方法,係透過自動偵測或手動設定的方式,預先定義標籤所代表的網路位置,其中標籤為終端設備網路封包中可識別的欄位,例如虛擬區域網路(vlan)欄位,當中央控制器偵測到具有標籤之封包時,根據網路拓樸及標籤資訊,定位終端設備所屬的正確位置,最後中央控制器再根據終端設備資訊,將終端設備政策派送至可控制交換器,以達到終端設備連網管控。此外,當終端設備移動位置時,中央控制器亦可偵測到設備移動並重新派送政策至對應的可控制交換器,使用者無需修改終端設備設定,以達到網址可攜性。 The present invention provides a terminal equipment management and control system and method suitable for heterogeneous networks, wherein the heterogeneous network refers to a network including traditional switches and controllable switches, and the controllable switches refers to the controllable switches of the central controller. Switches, traditional switches refer to switches that are not controlled by a central controller. The terminal equipment management and control system and method of the present invention predefines the network location represented by the label by means of automatic detection or manual setting, wherein the label is an identifiable field in the network packet of the terminal equipment, such as a virtual local area network In the vlan field, when the central controller detects a packet with a label, it will locate the correct location of the terminal device according to the network topology and label information. Finally, the central controller will assign the terminal device according to the terminal device information Policies are dispatched to controllable switches for network management and control of end devices. In addition, when the terminal device moves, the central controller can also detect the device movement and redistribute the policy to the corresponding controllable switch, so that the user does not need to modify the terminal device settings to achieve website portability.
請參照圖1所示之本發明之網路架構示意圖。圖1中之網路包括複數傳統交換器2、複數可控制交換器3、複數閘道器4、以及中央控制器5等網路設備。終端設備1的流量從傳統交換器2經可控制交換器3後,再到閘道器4進入到網際網路6中。首先在環境建置階段,網路管理員將網路設備設定
完成,包含可控制交換器3、傳統交換器2、以及其餘網路設備之間的連線,其中,傳統交換器2在預計會接入終端設備1的連接埠上綁定標籤。完成建置後,透過中央控制器5自動偵測或網路管理員手動匯入的方式,將網路拓樸資訊記錄在系統中,該網路拓樸資訊包含可控制交換器3的編號及連接埠資訊、傳統交換器2的網址(例如網際網路協定位址及/或媒體存取控制位址)及連接埠、所有交換器的連線狀態及標籤與網路位置的對應關係。
Please refer to the schematic diagram of the network structure of the present invention shown in FIG. 1 . The network in FIG. 1 includes network devices such as a plurality of conventional switches 2 , a plurality of
如圖2所示,本發明的終端設備管控系統500包括拓樸管理單元100、終端設備資訊管理單元200、以及終端設備政策管理單元300。
As shown in FIG. 2 , the terminal device management and
拓樸管理單元100包括可控制交換器管理模組110、傳統交換器管理模組120、連線管理模組130、以及標籤註冊模組140,用於管理網路中的可控制交換器資訊、傳統交換器資訊、所有交換器間的連線關係,以及標籤與傳統交換器連接埠之間的對應關係。
The
終端設備資訊管理單元200包括偵測模組210、標籤轉換模組220、以及終端設備資訊管理模組230,用於管理終端設備資訊,以及記錄終端設備所在的傳統交換器連接埠位置。在一實施例中,終端設備資訊管理模組230係用於記錄終端設備之網址、標籤及連接埠。
The terminal equipment
終端設備政策管理單元300包括終端設備政策管理模組310,用於管控終端設備連網政策,以允許或阻擋終端設備連網功能。在一實施例中,終端設備政策管理模組310係用於根據終端設備資訊管理模組230之記錄(如終端設備之網址、標籤及連接埠)組成允許終端設備連網之政策。
The terminal device
圖2所示的終端設備管控系統500係實施於網路之中央控制器中,例如圖1中的中央控制器5。圖2中之各模組均可為軟體、硬體或韌體;若為硬體,則可為具有資料處理與運算能力之處理單元或處理器;若為軟體或韌體,則可包括處理單元或處理器可執行之電腦指令。
The terminal equipment management and
首先在環境建置階段,網路管理員將網路設備設定完成,包含可控制交換器、傳統交換器、以及其他網路設備間的連線,其中,傳統交換器在預計會接入終端設備的連接埠上綁定標籤。完成建置後,拓樸管理單元100透過自動偵測或手動匯入的方式,將網路拓樸資訊分散記錄在可控制交換器管理模組110、傳統交換器管理模組120、連線管理模組130以及標籤註冊模組140中,其中,可控制交換器管理模組110記錄網路拓樸中所有可控制交換器的資訊,包含可控制交換器的編號及連接埠資訊,可用預設順序的序號做為可控制交換器的編號,或者,可用其他方式決定可控制交換器的編號,例如可用可控制交換器的網址做為可控制交換器的編號,而該連接埠資訊包括各連接埠的編號以及有無連線的狀態。傳統交換器管理模組120記錄網路拓樸中所有傳統交換器的資訊,包含傳統交換器的網址及連接埠資訊,該連接埠資訊同樣包括各連接埠的編號以及有無連線的狀態。連線管理模組130記錄網路設備間的連線,包含每一個可控制交換器及每一個傳統交換器的每一個連接埠之間的連線關係。標籤註冊模組140記錄傳統交換器連接埠與標籤之間的對應關係。
First, in the environment construction stage, the network administrator completes the settings of the network equipment, including the controllable switch, the traditional switch, and the connection between other network equipment. The traditional switch is expected to be connected to the terminal equipment. Binding label on the port. After completing the construction, the
完成網路拓樸資訊建立後,由終端設備資訊管理單元200偵測並記錄終端設備資訊,其中,偵測模組210開啟每一個可控制交換器的偵測功能,以分析所偵測的封包的資訊,包含終端設備的網址及標籤資訊。標籤轉換模組220根據網路拓樸資訊及標籤資訊,計算出終端設備所在的傳統交換器連接埠位置。終端設備資訊管理模組230記錄終端設備資訊及其所在位置。完成終端設備資訊建立後,當網路管理員允許終端設備使用網路時,由終端設備政策管理單元300套用政策進行開通,其中,終端設備政策管理模組310透過終端設備資訊及其所在位置組成政策,並依據網路連線資訊,將政策套用在可控制交換器上,以達到終端設備管控。
After completing the establishment of the network topology information, the terminal equipment
由圖3所示的終端設備偵測與記錄資訊流程可以更加了解本發明的運作,此流程係由終端設備資訊管理單元200中的各模組執行。
The operation of the present invention can be better understood from the process of detecting and recording information of the terminal device shown in FIG. 3 , and this process is executed by each module in the terminal device
首先,當完成網路拓樸資訊建立後,在步驟S11,偵測模組210開啟每一個可控制交換器的終端設備偵測功能。開啟終端設備偵測功能後,當可控制交換器收到終端設備的封包(以下將此封包簡稱為偵測封包),會檢查該可控制交換器中是否有適用於偵測封包的政策。如果有適用的政策,可控制交換器會依照該政策轉送偵測封包,以助偵測封包到達其目的地。如果沒有適用的政策,可控制交換器會將偵測封包轉送至中央控制器。
First, after completing the establishment of the network topology information, in step S11, the
接著,在步驟S12,當終端設備接入至傳統交換器時,流量會從傳統交換器流經可控制交換器。當可控制交換器收到流量中的偵測封包,由於初始時可控制交換器中不會有適用的政策,所以可控制交換器會將偵測封包轉送至中央控制器。在轉送偵測封包之前,可控制交換器會在偵測封包中附上該可控制交換器接收到偵測封包的連接埠的編號(以下將該連接埠與其編號簡稱為偵測連接埠)。 Next, in step S12, when the terminal device is connected to the conventional switch, the traffic flows from the conventional switch through the controllable switch. When the controllable switch receives the detection packet in the traffic, since there is no applicable policy in the controllable switch initially, the controllable switch will forward the detection packet to the central controller. Before forwarding the detection packet, the controllable switch will attach the number of the port where the controllable switch received the detection packet (hereinafter referred to as the detection port for short) in the detection packet.
然後,在步驟S13,中央控制器中的標籤轉換模組220接收可控制交換器轉送的偵測封包,並判斷偵測封包是否包含標籤,若是,則流程進入步驟S14,若否,則流程進入步驟S18。網路中的每一個傳統交換器的每一個連接埠都有一個對應的標籤,每當有封包通過一個傳統交換器的連接埠,該傳統交換器就會在該封包內附上該連接埠所對應的標籤。因此,若偵測封包曾通過傳統交換器的連接埠,就會包含該連接埠所對應的標籤,若偵測封包不曾通過傳統交換器的連接埠,就不會包含標籤。
Then, in step S13, the
在步驟S14,標籤轉換模組220判斷偵測封包中的標籤是否在先前的環境建置階段時已被註冊在中央控制器的終端設備管控系統500中,也就是判斷標籤註冊模組140是否有記錄該標籤與某一個傳統交換器的某一個連接
埠之間的對應關係,若是,則流程進入步驟S15,若否,則流程進入步驟S18。
In step S14, the
在步驟S15,標籤轉換模組220根據偵測封包中的偵測連接埠及網路拓樸資訊,計算出與偵測連接埠相關(直接或間接連線)的所有傳統交換器。
In step S15, the
接著,在步驟S16,標籤轉換模組220根據偵測封包中的標籤,從相關的傳統交換器中找到全網路中唯一對應該標籤的傳統交換器連接埠。
Next, in step S16, the
在本實施例中,採用VLAN編號做為標籤,因此,不同的傳統交換器可能有相同的標籤。在另一實施例中,可用其他編號方式,為每一個傳統交換器連接埠設定一個在整個網路中唯一的標籤,如此就可省略步驟S15,且在步驟S16,標籤轉換模組220可根據偵測封包中的標籤,從所有傳統交換器中找到唯一對應該標籤的傳統交換器連接埠。
In this embodiment, the VLAN number is used as the label, so different conventional switches may have the same label. In another embodiment, other numbering methods can be used to set a unique label in the entire network for each conventional switch port, so step S15 can be omitted, and in step S16, the
在步驟S17,終端設備資訊管理模組230記錄發送該偵測封包的終端設備的網址、該偵測封包中的標籤、以及步驟S16中所找到的唯一對應該標籤的傳統交換器連接埠,該終端設備的網址可自該偵測封包取得,該傳統交換器連接埠相當於該終端設備的網路位置,該標籤亦可對應或代表該終端設備的網路位置。
In step S17, the terminal device
步驟S18則是當偵測封包不含標籤,或標籤未在中央控制器註冊時,標籤轉換模組220直接丟棄該偵測封包,不進行動作,因此,發送該偵測封包的終端設備不能連網。
In step S18, when the detection packet does not contain a label, or the label is not registered in the central controller, the
由圖4所示的終端設備政策套用流程可以更加了解本發明的運作情形,此流程係由終端設備政策管理單元300的終端設備政策管理模組310執行。
The operation of the present invention can be better understood from the terminal device policy application process shown in FIG. 4 , which is executed by the terminal device
首先,完成圖3所示的終端設備資訊建立流程後,當網路管理員要允許一終端設備連網時,在步驟S21,以該終端設備的網路位置所在的傳統交換器為鄰居探索的起點。 First, after completing the process of establishing terminal equipment information shown in FIG. 3, when the network administrator wants to allow a terminal equipment to connect to the network, in step S21, the traditional switch where the network location of the terminal equipment is located is used as a neighbor search method. starting point.
在步驟S22開始進行鄰居探索,以找尋最接近該終端設備的可控制交換器。凡有連線關係之交換器,無論可控制交換器或傳統交換器,均為彼此之鄰居。在一實施例中,鄰居探索演算法可使用但不限於廣度優先探索(breadth-first search)或深度優先探索(depth-first search)。 In step S22, a neighbor search is started to find a controllable switch closest to the terminal device. All switches with a connection relationship, whether controllable switches or traditional switches, are neighbors to each other. In one embodiment, the neighbor search algorithm may use, but is not limited to, breadth-first search or depth-first search.
經過鄰居探索後,在步驟S24,取得最接近該終端設備的可控制交換器,且該可控制交換器中與該終端設備的網路位置所在的該傳統交換器連線的連接埠將會是該終端設備的封包進入該可控制交換器的連接埠。 After neighbor search, in step S24, the controllable switch closest to the terminal device is obtained, and the port of the controllable switch connected to the traditional switch where the network location of the terminal device is located will be The packets of the terminal equipment enter the port of the controllable switch.
接著,在步驟S25,依據該終端設備的網址、該終端設備所對應的標籤(該終端設備的網路位置所在的傳統交換器連接埠的標籤)、以及該可控制交換器的該連接埠,組成對應該終端設備的政策,並將該政策套用至該可控制交換器。該政策即為在圖3步驟S11的說明中所述的適用於偵測封包的政策。該政策包括該終端設備的網址、該終端設備所對應的標籤、以及該可控制交換器的該連接埠。此後,每當該可控制交換器自該連接埠收到符合該政策中的網址及標籤的封包,就會根據該政策轉送該封包,以助該終端設備連網,而不會將該封包轉送至中央控制器。 Next, in step S25, according to the website address of the terminal device, the label corresponding to the terminal device (the label of the traditional switch port where the network location of the terminal device is located), and the port of the controllable switch, Form a policy for the terminal device and apply the policy to the controllable switch. The policy is the policy applicable to the detection packet described in the description of step S11 in FIG. 3 . The policy includes the URL of the terminal device, the label corresponding to the terminal device, and the port of the controllable switch. After that, whenever the controllable switch receives a packet from the port that matches the URL and label in the policy, it will forward the packet according to the policy to help the terminal device connect to the Internet without forwarding the packet. to the central controller.
除了首次接入網路的終端設備之外,本發明亦可偵測移動後的終端設備以進行動態的管控。終端設備移動後,例如改連線至另一傳統交換器或改連線至同一傳統交換器的另一連接埠後,圖3及圖4的流程依然適用。詳言之,可透過偵測模組210開啟可控制交換器的偵測功能,接著透過標籤轉換模組220計算出終端設備所在的傳統交換器連接埠,然後由終端設備資訊管理
模組230記錄終端設備網址及所在的網路位置,最後由終端設備政策管理模組310更新該終端設備的政策並套用至對應的可控制交換器,以達到動態管控。
In addition to the terminal equipment accessing the network for the first time, the present invention can also detect the terminal equipment after moving for dynamic management and control. After the terminal device is moved, for example, after reconnecting to another conventional switch or reconnecting to another port of the same conventional switch, the processes of FIGS. 3 and 4 are still applicable. Specifically, the detection function of the controllable switch can be enabled through the
本發明系統係在於異質網路的終端設備管控,經由自動偵測或手動匯入的方式,定義標籤所代表的傳統交換器連接埠,即使中央控制器無法控制傳統交換器,亦可透過標籤機制,將從可控制交換器上偵測到的終端設備正確定位在傳統交換器及其連接埠上,並透過在可控制交換器上的終端設備政策管控,達成在傳統交換器上無法進行的終端設備管控,而提升網路安全性。 The system of the present invention is based on the terminal equipment control of heterogeneous networks, through automatic detection or manual import, the traditional switch port represented by the label is defined, even if the central controller cannot control the traditional switch, the label mechanism can be used. , the terminal equipment detected from the controllable switch is correctly positioned on the traditional switch and its port, and through the terminal equipment policy control on the controllable switch, the terminal equipment that cannot be carried out on the traditional switch can be achieved. Device control, and improve network security.
本發明的終端設備管控系統與方法具備下列優點: The terminal equipment management and control system and method of the present invention have the following advantages:
一、易管理:本發明不須在終端設備上安裝監控元件,即可精確偵測傳統交換器下終端設備的正確位置;另一方面,本發明僅需在中央控制器設定,無需在交換器設定,便可派送管控政策至可控制交換器並套用至終端設備,且終端設備移動位置後,無需修改終端設備設定。 1. Easy to manage: the present invention can accurately detect the correct position of the terminal device under the traditional switch without installing monitoring components on the terminal device; After setting, the control policy can be dispatched to the controllable switch and applied to the terminal device, and after the terminal device moves, there is no need to modify the terminal device settings.
二、高安全:相較於傳統網路於匯集端進行連網管控之解決方案,本發明於可控制交換器實施政策管控,能防止終端設備連線至內部網路及外部網路,並在傳統交換器藉由各連接埠的VLAN進行網路隔離,以提供完整網路切片與隔離功能;另外,本發明不需額外控制器去控制傳統交換器,且網路切片隔離技術並不受到虛擬區域網路標籤最大僅能支援4096的限制,可支援更多的網路切片。 2. High security: Compared with the traditional solution of network management and control at the collection end, the present invention implements policy management and control at the controllable switch, which can prevent terminal equipment from connecting to the internal network and external network. The traditional switch performs network isolation through the VLAN of each connection port to provide complete network slicing and isolation functions; in addition, the present invention does not require an additional controller to control the traditional switch, and the network slicing isolation technology is not affected by virtual The LAN label can only support the maximum limit of 4096, which can support more network slices.
三、降成本:相較於集中化同質網路全網導入可控制交換器之解決方案,本發明以傳統交換器做為終端接取端之交換器,在管控大量終端設備之場域,可大幅減少可控制交換器之需求,而降低網路成本支出。 3. Cost reduction: Compared with the solution of introducing controllable switches in the entire network of a centralized homogeneous network, the present invention uses traditional switches as the switches at the terminal access end, and can control a large number of terminal devices in the field Significantly reduces the need for controllable switches and reduces network costs.
上列詳細說明乃針對本發明之一可行實施例進行具體說明,惟該實施例並非用以限制本發明之專利範圍,凡未脫離本發明技藝精神所為之等效實施或變更,均應包含於本案之專利範圍中。 The above detailed description is for a specific description of a feasible embodiment of the present invention, but this embodiment is not intended to limit the patent scope of the present invention. Any equivalent implementation or modification that does not depart from the technical spirit of the present invention shall be included in the within the scope of the patent in this case.
綜上所述,本案不僅於技術思想上確屬創新,並具備其他現有相關技術所不及之上述多項功效,已充分符合新穎性及進步性之法定發明專利要件,爰依法提出申請,懇請 貴局核准本件發明專利申請案,以勵發明,至感德便。 To sum up, this case is not only innovative in technical ideas, but also has many of the above-mentioned effects that other existing related technologies cannot achieve. It has fully met the requirements of the statutory invention patent for novelty and progress. Approval of this patent application for invention, in order to encourage invention, is very convenient.
100:拓樸管理單元 100: Topology Management Unit
110:可控制交換器管理模組 110: Controllable switch management module
120:傳統交換器管理模組 120: Traditional switch management module
130:連線管理模組 130:Connection management module
140:標籤註冊模組 140: Tag Registration Module
200:終端設備資訊管理單元 200: Terminal equipment information management unit
210:偵測模組 210: Detection Module
220:標籤轉換模組 220: Label Conversion Module
230:終端設備資訊管理模組 230: Terminal equipment information management module
300:終端設備政策管理單元 300: Terminal Device Policy Management Unit
310:終端設備政策管理模組 310: Terminal device policy management module
500:終端設備管控系統 500: Terminal equipment management and control system
Claims (12)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW110103062A TWI774215B (en) | 2021-01-27 | 2021-01-27 | Terminal device management system and method thereof |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW110103062A TWI774215B (en) | 2021-01-27 | 2021-01-27 | Terminal device management system and method thereof |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TW202231026A TW202231026A (en) | 2022-08-01 |
| TWI774215B true TWI774215B (en) | 2022-08-11 |
Family
ID=83782453
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW110103062A TWI774215B (en) | 2021-01-27 | 2021-01-27 | Terminal device management system and method thereof |
Country Status (1)
| Country | Link |
|---|---|
| TW (1) | TWI774215B (en) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1357725A2 (en) * | 2002-04-27 | 2003-10-29 | Samsung Electronics Co., Ltd. | An internet protocol based communication system and method for setting host address and selecting source address therein |
| US6847644B1 (en) * | 2000-02-23 | 2005-01-25 | Cypress Semiconductor Corp. | Hybrid data transport scheme over optical networks |
| TW201840164A (en) * | 2017-04-21 | 2018-11-01 | 思銳科技股份有限公司 | Network topology real machine simulation method and system |
-
2021
- 2021-01-27 TW TW110103062A patent/TWI774215B/en active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6847644B1 (en) * | 2000-02-23 | 2005-01-25 | Cypress Semiconductor Corp. | Hybrid data transport scheme over optical networks |
| EP1357725A2 (en) * | 2002-04-27 | 2003-10-29 | Samsung Electronics Co., Ltd. | An internet protocol based communication system and method for setting host address and selecting source address therein |
| TW201840164A (en) * | 2017-04-21 | 2018-11-01 | 思銳科技股份有限公司 | Network topology real machine simulation method and system |
Also Published As
| Publication number | Publication date |
|---|---|
| TW202231026A (en) | 2022-08-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11171914B2 (en) | Systems and methods for automatic inventory and DNS record generation | |
| CN101552697B (en) | Network access apparatus upgrade system and network access apparatus upgrade method | |
| JP5738379B2 (en) | Network operating system for managing and securing a network | |
| RU2562438C2 (en) | Network system and network management method | |
| CN103179599B (en) | The method for supervising of WLAN performance, equipment and system | |
| RU2576492C2 (en) | Control device, communication system, communication method and recording medium with communication programme recorded thereon | |
| JP6193473B2 (en) | Computer-implemented method, computer program product and computer | |
| CN103596290A (en) | Wireless multi-network integration method | |
| EP3588859B1 (en) | Network device configuration versioning | |
| EP3576347A1 (en) | Network device snapshots | |
| CN101662393A (en) | Inter-domain prefix hijack detection and location method | |
| CN100414890C (en) | Method and system for centrally configurating terminal equipment | |
| US20150236920A1 (en) | Method and apparatus for determining connection information of a link | |
| US10560284B2 (en) | System and methods for mapping a network service path | |
| CN103873372B (en) | Domain name based policy routing system and setting method | |
| JP2006262193A (en) | Control device, packet transfer method, and packet processing device | |
| WO2012037762A1 (en) | Method and apparatus for configuring address resolution protocol entry | |
| TWI774215B (en) | Terminal device management system and method thereof | |
| CN103391232B (en) | Virtual machine connection method in cloud system | |
| EP3262802A1 (en) | Automatic discovery and provisioning of multi-chassis etherchannel peers | |
| CN104885417A (en) | Control apparatus, communication system, communication node control method and program | |
| EP3432518B1 (en) | Remote management method and circuitry for mobile broadband router | |
| CN107659446B (en) | WAF migration method and device | |
| Zhou et al. | Discovery algorithm for network topology based on SNMP | |
| US20260032040A1 (en) | Device access location obtaining method and apparatus |