Network element with control device and control method
Abstract
The network element (NE1) has a controller with a processor performing access requests (REQ3, REQ4), a memory containing managed objects (MO2, MO3) and an access unit for receiving the access request. The controller controls the network element with the managed objects, which represent static and dynamic properties of the network element resources. A service profile (PRO) stored in the memory contains information about the managed objects access rights which are checked before carrying out the request. Independent claims are also included for a method of controlling a network element and for a controller.

Term
Term ended
Projected expiry passed 30 April 2019, 7.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 3 independent, 6 dependent
- 1Network element (NE) of a communications network, with a Control means (CT), a processor (CPU) for executing a Access request (REQ), a memory (MEM) in the managed Objects (MO1, MO2, MO3, MO) are stored, and an access unit (ACC) for receiving the access request (REQ), in which method the controller, the network element by means of managed objects (MO1, MO2, MO3, MO) controls and wherein the managed objects a Mapping of the static and dynamic properties of resources the network element (NE) are, characterized, that in the memory (MEM) a service profile (PRO) is stored, which Information on access rights for the managed objects (MO1, MO2, MO3, MO), and that the processor (CPU) before execution of the Access request (REQ) checks whether access rights to perform the Access request (REQ) required managed objects (MO) available are.
- 7A method for controlling a network element for a communications network, with the following steps:Emfangen (S1) an access request (REQ) from a user (U1, U2, U3, MGMT), Check (S2), whether in a service profile (PRO) access rights to Execution of the access request (REQ) required managed objects (MO1, MO2, MO3, MO) for the user (U1, U2, U3, MGMT) available, Performing (S3) of the access request (REQ) if this is the case, and Decline (S4) of the access request if it is not the case.
- 9Control means (CT) for controlling a network element (NE) of a News Network via managed objects (MO1, MO2, MO3, MO), wherein the managed objects an image of static and dynamic properties of resources of the network element (NE) are, with a processor (CPU) for executing an access request (REQ), a memory (MEM) in the managed objects (MO1, MO2, MO3, MO) are stored, and an access unit (ACC) for receiving the Access request (REQ) characterized, that in the memory (MEM) a service profile (PRO) is stored, which Information on access rights for the managed objects (MO1, MO2, MO3, MO), and that the processor (CPU) before execution of the Access requests (REQ) checks whether access rights to perform the Access request (REQ) required managed objects (MO1, MO2, MO3, MO) are present.
Independent claims3
34 paragraphs, as filed
0001The invention relates to a network element according to the preamble of claim 1, a method for controlling a network element according to claim 7 and a control device for a network element according to the preamble of Claim 9.
0002Under a network element means a communication network understood that serve, for example, compounds within the Network set up to provide access to the network connections in the power to convey or the transmission format of messages be transmitted in the network to change. In a synchronous digital communications network of the synchronous digital hierarchy (SDH) or the <i>Synchronous Optical Networks</i> (SONET) are among the Network elements cross-connect, add / drop and Mutliplexer Line multiplexer.
0003Such network elements contain a control means for controlling and monitoring of the network element-specific tools. In the article "Technology of SDH network elements: the software platform" of S. Colombo et al., Electrical Communication 4th quarter 1993 S.322-328 is described that the network elements according to an object-oriented Specification work and are controlled by international Standardization bodies such as CCITT (now ITU-T), ETSI or ANSI set has been. Functions of the network elements are managed in the form of Objects (Mon - Managed Objects) described and implemented.
0004Managed objects are real existing images - and thus Descriptions of static and dynamic properties - of physical or virtual components (resources) of the managed Network element. According to the CCITT Recommendation X.720 (1/92) is under a managed object a for the purpose of management existing abstraction of computers and Data communication resources (eg log state automata, denotes compounds or modems).
0005The control device contains a network element according to the above mentioned article by S. Colombo et al .:<ul><li>a processor hardware of CPU, memory and persistent storage,</li><li>a processor platform with OSI stack, operating system, data management, Inter-process communication and protection functions,</li><li>a framework, called Framework, which includes a general Programming Interface (API - Application Programming Interface) to Implementation of managed objects (MO - Managed Objects) has, and</li><li>a number of network element functions managed by objects are realized.</li></ul>
0006The framework includes an attribute library, access to the services managed objects offers as SET, GET, REPLACE, CREATE or DELETE. The framework further comprises an inter-object communication, the Communication between different managed objects governs.
0007There is the disadvantage that access rights that govern which Access Services for each managed object are allowed, for each considered each individual case when programming the network element functions be and in the source code of the object classes (applications) encoding have to. This is complicated and prone to errors.
0008The object of the invention is a network element, a control device for a network element and a method for controlling a network element indicate that the more flexible and less error-prone administration Access rights of managed objects allow.
0009The object is in terms of the network element achieved by the Features of claim 1, as regards the method by the Features of claim 7 and with respect to the control means are by the features of claim 9. Advantageous embodiments the dependent claims.
0010It has proven advantageous that the control of access rights in the Simplifies communication between managed objects among themselves is.
0011A particular advantage of the invention is that the functionality expanding a network element with identical hardware and software or may be restricted only by loading new service profiles will. Thereby, it is possible for an identical hardware and software, one Network element version with standard functions and a version with enhanced features to create.
0012Another advantage of the invention is that it with the aid of service profiles is possible, all classes of managed objects in front of one or more to hide user groups and this class, for example only one closed user group accessible and thus more "visible".
0013In the following the invention with reference to Figures 1 to 5 is in two Embodiments described. It shows:<dl tsize="8" compact="compact"><dt>Figure 1:</dt><dd>an inventive network element of a first Embodiment, </dd><dt>Figure 2:</dt><dd>a first example of the operation of the invention Network element in the first embodiment,</dd><dt>Figure 3:</dt><dd>a second example of the operation of the invention Network element in the first embodiment,</dd><dt>Figure 4:</dt><dd>a third example of the operation of the invention Network element in a second embodiment and</dd><dt>Figure 5:</dt><dd>a flow chart of the control method according to the invention.</dd></dl>
0014Managed objects are images of physical or virtual Components of the network element which the static and dynamic describe properties of each component. A managed Object is an instance of a managed object class. One such class managed object is defined by its attributes of their objects executable operations (eng. operations), the messages (eng. notifications), which can produce their objects, and their behavior (eng. related behavior). Each managed object has a unique Name. From the standpoint of the management system of an exist managed object if it has a unique name, and if It supports the operations and messages that define for its class are.
0015The totality of existing in a network element managed Objects together with their attributes is as <i>Managed information base</i>Shortly MIB called, and reflects the current configuration of the Network element resist. The managed objects are stored in a memory (Typically a RAM) and in a database that is a Only memory (eg a hard disk) of the network element is, redundantly backed up. This database is also with the English Expression <i>persistency</i> or <i>persistency database</i> designated.
0016The access to a managed object will consist of a Access request. The access requirements of external users, For example, queries the parent management system have, a fixed structure and language, namely <i>Common management</i><i>Information system element,</i> Soon CMISE and Protocol <i>Common Management Information Protocol,</i> Soon CMIP. Also possible are internal Access requests between managed objects among themselves.
0017On managed objects, various access requests be applied, as described in CCITT Recommendation X.720 (01/92) is described, namely, inter alia:<dl tsize="6" compact="compact"><dt>GET</dt><dd>to the value of an attribute of a managed object to read,</dd><dt>SET</dt><dd>to an attribute of a managed object has a value assign,</dd><dt>ACTION</dt><dd>an operation of a managed object to execute,</dd><dt>CREATE</dt><dd>a new managed object of a specified class generate managed objects, and</dd><dt>DELETE</dt><dd>To delete an existing managed object.</dd></dl>What access requests possible in principle to a managed object are its object class is defined in the definition.
0018A basic idea of the invention is, managed access rights for define objects and their attributes in advance and in a Service profile store. These service profiles are tabulated used. If an access request to a managed object be run and be accessed, it is based on the Service profile determine whether the accessing user to access the necessary has access right or not. If the required access rights, as is the run access request, otherwise an error message produced and refused access. An advantageous development of Erfi invention is to provide different categories of users and the access rights for each user category to each managed define object in the form of service profiles.
0019A first embodiment of the invention is shown schematically in Figure 1 shown. A network element NE has a controller CT a memory MEM, a processor CPU and an access unit ACC. In the memory MEM, the Management Information Base MIB is stored. The MIB comprises a number of managed objects. In the memory MEM is also a service profile stored PRO that the includes access to the managed objects and their attributes.
0020In the first embodiment is in the network element NE a cross-connect for a synchronous digital Communications network of the synchronous digital hierarchy. Examples for managed objects of the crossconnect are objects for switched Compounds for endpoints (eng. Termination points) of the switching matrix Cross-connects, for physical modules and boards as well as for Result files of regular monitoring operations in the Network Element (performance monitoring).
0021About the access unit ACC are access requests REQ from one external Managemeneinrichtung MGMT in the form of the above received addressed CMISE requests. In the memory is the Service profile stored. The service profile contains information on PRO Access rights of user groups for the managed objects and their Attributes. In the first embodiment, two external User groups are provided, namely Q-interface and user F-interface user and a user group for interen Access requests between managed objects among themselves. For the groups Q-interface users are all Administrative functions be permitted to QIF for the Q-interface Network Mangements in the recommendations for synchronous digital Hierarchy (SDH) are defined. The user group F-interface user uses a proprietary advanced Q-interface Network element, which is referred to as F-FIF interface, and has erweitertere access rights. The F interface is the embodiment of a local terminal TERM for operations have in use. For the internal Groups include all managed objects themselves.
0022In the figure 2 is a first example of the operation of the network element shown in the first embodiment. A user U1 Groups Q interface Q user sends via the access unit a first access request REQ1 to the network element. The aim is to a first managed object MO1 be accessed and its attribute A be set to a specified value, for example 100. by means of the processor CPU is now checked in the service profile PRO which Privilege the user U1 of the groups Q-interface users Q has the attribute A of the managed object MO1: He has only the Access right GET, so it can only read the attribute A. Since the user U1 privilege SET for the attribute A has not, the denied access request and the error message RES1 <i>"invalid surgery"</i> as a result returned to the user U1. So he can not perform the desired access request.
0023Another user U2 also sends an access request REQ 2 to the network element NE1. The second user U2 belongs Groups F-interface user F and wants his Access request also the attribute A of the managed object MO1 put on 100th In the service profile PRO is recorded that the Groups F-interface user F for the attribute A, Access rights GET and SET has. The user U2 may therefore attribute A both read as change its value. Since all of the implementation of Access request REQ 2 required access rights are present, the access request REQ 2 run. The value of the attribute A is set to 100 and as a result, the message RES 2 <i>"OK"</i> to the User U2 returned.
0024Based on this example, it becomes clear how an access control and realized restriction of access rights using the service profile can be. An example of a reasonable access control is the Creating a new object manage ended on a hardware board of Cross connectés. Here it may be useful to the external Management means creating such a managed object not to permit, by the groups Q-interface users the access right CREATE failed for this object class, while the The object is created on the local terminal of the Cross on the connectés F interface is permitted by the user group F-interface user the privilege is granted CREATE. Thereby ensures that a new hardware board only by the operating staff can be installed and configured locally. In this way, different functionality for different user groups will be realized. The external management device is usually not be interested in Hardwaredatails individual network elements, while the operating personnel on site for the purpose of servicing additional services can run on network element must.
0025A second, shown in Figure 3. Example of the operation of the Network element in the first embodiment relates to internal Communication between managed objects. A user sends U3 an access request REQ3 to the network element NE1. By should REQ3 access request the attribute X of the managed object MO2 be changed. The user U3 is part of the user group Q-interface user Q. The controller of the Network element verified on the service profile PRO, which access rights the user U2 has, noting that he managed for the attribute X of Object MO2 only the access right GET, but not SET has. Therefore denied the controller executing the Access request REQ3 and sends the error message RES 3 <i>"invalid surgery</i>"As a result of the access request to the user U3 back.
0026Due sends a program running in the controller process another managed object MO3 an internal access request REQ 4 changed with the also the attribute X of the managed object MO2 shall be. The managed object MO3 belongs to the internal Groups INT on the intrinsic process sequences are assigned. According to the entry in the service profile consisting permissions GET and SET. The access request is therefore carried out, because the Required privilege SET for intere groups INT exists. As Answer is a RES4 "<i>OK</i>"Managed object to the requesting MO3 returned.
0027is from the second example of the operation of the network element shows how the control of access rights in the communication among themselves realized between managed objects in a simple manner is without each individual case a separate routine in the inter-object communications encodes the framework of the network element control must become.
0028From the figure 4 is now in a second embodiment third example of the operation of the invention network elements discussed. In the second embodiment, two network elements NE21 and NE22 of a synchronous digital Night Set transmission system shown. Both are of a Management facility MGMT controlled. is In the network elements it respectively to the network elements of the type shown in Figure 1, thereby both network elements NE21 and NE22 identical with the single Except that it with different service profiles Pro21, PRO22 equipped.
0029The management facility MGMT sends to the first network element NE21 a first access request REQ21, the attribute A of the managed to set object MO to a specified value. The Control means of the first network element checks in the NE21 Service profile Pro21 permissions that managed the object MO Sorry, notes that for the attribute A of the managed object only the access right GET, but not SET is available and denied therefore the execution of the access request. It will be one Error message RES21 <i>"Invalial operational</i>"To the management device returned.
0030On the second network element NE22 sends the management device MGMT also an access request REQ22, the attribute of the A to set the managed object MO to a specified value. Now checks the controller of the second network element NE22 in their Service profile PRO22 the access rights for the managed object MO are registered and notes that for the attribute A of the managed Object access rights GET and SET are granted. Since the required SET privilege exists, the access request is executed the attribute A is set to the specified value and as a result of Instruction sends the control device to the Management means the message RES22 <i>"OK".</i>
0031From the third example of the operation of an inventive The network element will be seen that the network elements with different Functionality can be implemented in different hardware and software can, merely by different service profiles are loaded. So , a device version with standard functions and a device version with an extended or with a restricted set of functions be realized with the same hardware and software.
0032It is particularly advantageous if the service profile dynamically at runtime loadable, that is, when it replaced the loaded network element or in operation can be. A check for access rights will then always with the current service profile instead, so that the functionality of a network element changed during operation, eg: B. can be extended.
0033Another advantage arises when the service profile in tabular form is present and is encoded as ASCII file. The service profile can then be read in any text editor and also changed. Thereby is the maintenance personnel possible to the service profile check set set of possible functions of the network element and change it. The service profile would be improved by Royalty mechanism also protect against changes.
0034According to an advantageous development of the invention is a private Service profile for each class of managed objects provided. This only need the service profiles to be loaded in memory to whose associated class a managed object exists currently. The carried out mapping of managed object and associated service profile in this case the object class to which it belongs is a managed object.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1170900A3 | Cited by | European Patent Office (EPO) | Search report |
| EP1170900A2 | Cited by | European Patent Office (EPO) | Search report |
| US7590125B2 | Cited by | United States of America | Applicant |
| EP1379092A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1379092A1 | Cited by | European Patent Office (EPO) | Search report |
5 members in 4 offices; this record represents the family
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 19822553 | Germany | A | |
| 19822553 | Germany | – | |
| DE1998122553 | – | – | – |
| 19822553 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| CA2272182A1 | Canada | A1 | |
| EP0959588A2This record | European Patent Office (EPO) | A2 | |
| DE19822553A1 | Germany | A1 | |
| US6499059B1 | United States of America | B1 | |
| EP0959588A3 | European Patent Office (EPO) | A3 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Designation fees paidAKX | AKX | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0959588
- Publication, DOCDB
- 0959588
- Publication, EPODOC
- EP0959588
- Application
- 99440096
- Application, DOCDB
- 99440096
- Application, EPODOC
- EP19990440096
Titles3
- German
- Netzelement mit einer Steuerungseinrichtung und Steuerungsverfahren
- English
- Network element with control device and control method
- French
- Elément de réseau avec le dispositif de commande et la méthode de contrÔle
Classification
- CPC, 6
- H04L63/102
- G06F21/6218
- G06F21/71
- G06F2221/2141
- H04L41/0213
- H04L41/28
- IPC, 1
- H04L12 24
Designated states25
- Contracting states, 19
- Germany
- Finland
- France
- United Kingdom
- Italy
- Sweden
- Austria
- Belgium
- Switzerland
- Cyprus
- Denmark
- Spain
- Greece
- Ireland
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Extension states, 6
- Albania
- Lithuania
- Latvia
- North Macedonia
- Romania
- Slovenia