A data processing method and related device

Through the network controller to determine the message forwarding path of the data flow and the segmentation strategy of each network device in the SDN, and generate and publish data flow execution rules, solving the problems of low orchestration efficiency and high complexity in the prior art, and achieving efficient execution of unified orchestration and business functions.

CN116938666BActive Publication Date: 2025-06-13SHENZHEN HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310725938.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-16
Publication Date
2025-06-13
Estimated Expiration
2043-06-16

AI Technical Summary

Technical Problem

In the existing software-defined network (SDN), users need to arrange the service functions of each network device in the message forwarding path one by one, which is low efficiency and high complexity.

Method used

The network controller determines the message forwarding path of the data flow and the segmentation policy of each network device, generates data flow execution rules, including the identification of the traffic subspace and corresponding service functions, and publishes these rules to multiple network devices, so that each network device can perform corresponding service functions.

Benefits of technology

The service function of uniformly orchestrating each network device in the message forwarding path according to user needs is realized, without the need for users to orchestrate one by one, reducing the orchestration complexity and improving efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116938666B_ABST
    Figure CN116938666B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a data processing method and related devices for distributing data flow execution rules in a packet forwarding path. In the present application, a network controller can determine the packet forwarding path of a data flow and determine the segmentation policies of each of multiple network devices to obtain a data flow execution rule. Then, the network controller can publish the data flow execution rule to the multiple network devices so that each of the multiple network devices can obtain the corresponding segmentation policy in the data flow execution rule and perform corresponding service functions on the data flow, achieving unified orchestration of the service functions of each network device in the packet forwarding path according to user requirements, without the need for the user to orchestrate each network device one by one, reducing the complexity of orchestrating service functions and improving the efficiency of orchestrating service functions at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication networks, and in particular, to a data processing method and related devices. Background Art

[0002] In the existing communication network, when a client device wants to access a server device, it needs to pass through a packet forwarding path composed of multiple different types of network devices (for example, routers, switches, firewalls, etc.). Multiple network devices on the packet forwarding path are provided by different manufacturers and have different service characteristics (for example, blacklist, speed limit, packet capture, etc.).

[0003] Currently, in a software defined network (SDN), the network controller can determine the packet forwarding path for the data stream. If you want to orchestrate the service functions of the packet forwarding path according to the user's needs, you need to orchestrate each network device in the packet forwarding path one by one, which is inefficient. Summary of the Invention

[0004] Embodiments of this application provide a data processing method and related devices for distributing data stream execution rules in a packet forwarding path.

[0005] In the first aspect of this application, a data processing method is provided. In this method, the network controller can determine the packet forwarding path of the data stream and determine the segmentation strategy of each network device among multiple network devices to obtain the data stream execution rule. Among them, the segmentation strategy includes the identifier of at least one traffic subspace and the corresponding service function. The identifier of the traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The traffic space includes N-tuples, and N is a positive integer. Then, the network controller can publish the data stream execution rule to multiple network devices, so that each network device among the multiple network devices obtains the corresponding segmentation strategy in the data stream execution rule and executes the corresponding service function on the data stream, realizing the unified orchestration of the service functions of each network device in the packet forwarding path according to the user's needs, without the user having to orchestrate each network device one by one, reducing the complexity of orchestrating service functions and improving the efficiency of orchestrating service functions at the same time.

[0006] In some possible implementation manners, the network controller can obtain the communication quality between any two network devices in the communication network to obtain a communication quality matrix. The multiple network devices on the packet forwarding path all belong to the communication network, and determine the packet forwarding path of the data stream based on the communication quality matrix, so as to select the packet forwarding path with the best communication quality for the data stream.

[0007] In some possible implementations, the communication quality includes communication latency, and the communication quality can be reflected by the communication latency.

[0008] In some possible implementations, the network controller may send a control message to a first network device among the multiple network devices, where the control message includes the data flow execution rule, so that the first network device can obtain a corresponding first segmentation policy from the data flow execution rule and forward the control message to other network devices among the multiple network devices, thereby enabling each network device in the message forwarding path to obtain the data flow execution rule.

[0009] In some possible implementations, if the first network device is the ingress network device of the message forwarding path, then the first network device can forward the data flow execution rule along the message forwarding path, so that each network device in the message forwarding path can obtain the data flow execution rule.

[0010] In some possible implementations, the service function includes at least one of rate limiting, blacklisting, and packet capture, so that the network device that obtains the data flow execution rule can process and forward the data flow according to the set service function.

[0011] In some possible implementations, the identifier of the traffic space is a network identifier (VXLAN network identifier, VNI) to identify the traffic space.

[0012] In some possible implementations, the segmentation policy further includes information about the next hop, and the information about the next hop is used to indicate to the network device the next hop for forwarding the control message, so that the network device corresponding to the segmentation policy can continue to distribute the data flow execution rule based on the information about the next hop.

[0013] In some possible implementations, the data flow execution rule further includes at least one of a rule identifier, a data source required for executing the data flow execution rule, a preset time period for executing the data flow execution rule, the traffic space, the number of segments of the segmentation policy in the data flow execution rule, and the current hop count. The current hop count is used to indicate to the network device to obtain a corresponding segmentation policy in the data flow execution rule, so that the network device can process and forward the data packets of the data flow according to the data flow execution rule.

[0014] The second aspect of this application provides a data processing method. In this method, a first network device obtains a data flow execution rule for a data flow. The data flow execution rule includes a segmentation strategy for the data flow by each network device among the multiple network devices. The multiple network devices include the first network device, and the multiple network devices are connected in sequence to form a packet forwarding path. The segmentation strategy includes the identifier of at least one traffic subspace and the corresponding service function. The identifier of the traffic subspace includes the traffic space where the data flow is located and the identifier of the traffic space. The traffic space includes N-tuples, where N is a positive integer. Then, the first network device can obtain the corresponding first segmentation strategy from the data flow execution rule and execute the first segmentation strategy on the data flow, so that the first network device can execute the corresponding service function on the data flow according to the first segmentation strategy, realizing the unified orchestration of the service functions of the first network device in the packet forwarding path according to the user's requirements, without the user having to separately orchestrate the first network device, reducing the complexity of orchestrating service functions and at the same time improving the efficiency of orchestrating service functions.

[0015] In some possible implementation manners, the data flow execution rule includes the current hop count. The first network device determines the corresponding first segmentation strategy in the data flow execution rule based on the current hop count, so that the first network device can process and forward the data packets of the data flow according to the data flow execution rule.

[0016] In some possible implementation manners, the first network device receives a control packet, and the control packet includes the data flow execution rule, so that each network device in the packet forwarding path can obtain the data flow execution rule.

[0017] In some possible implementation manners, the data flow execution rule includes the information of the next hop. The first network device modifies the value of the current hop count in the data flow execution rule and forwards the control packet based on the information of the next hop, so that the next-hop network device can obtain the corresponding segmentation strategy from the data flow execution rule.

[0018] In some possible implementation manners, the service function includes at least one of rate limiting, blacklisting, and packet capturing, so that the network device that obtains the data flow execution rule can process and forward the data flow according to the set service function.

[0019] In some possible implementation manners, the identifier of the traffic space is VNI to identify the traffic space.

[0020] In some possible implementations, the data flow execution rule further includes a rule identifier, a data source required to execute the data flow execution rule, a preset time period for executing the data flow execution rule, the traffic space, and the number of segments of the segmentation policy in the data flow execution rule, so that the network device can process and forward data packets of the data flow according to the data flow execution rule.

[0021] In some possible implementations, the first network device receives a data packet, determines that the data packet belongs to the data flow according to the information of the N-tuple of the data packet, and determines the traffic space where the data flow is located and the identifier of the corresponding traffic space according to the information of the N-tuple, so as to obtain the identifier of the traffic subspace, so that the first network device determines the first segmentation policy corresponding to the data flow according to the identifier of the traffic subspace.

[0022] The third aspect of this application provides a network controller for executing the method described in any one of the foregoing first aspects.

[0023] The fourth aspect of this application provides a network device for executing the method described in any one of the foregoing second aspects.

[0024] The fifth aspect of this application provides a computer-readable storage medium, in which instructions are stored. When the instructions are run on a computer, the computer is made to execute the method described in any one of the foregoing first aspect or second aspect.

[0025] The sixth aspect of this application provides a computer program product, which includes computer-executable instructions stored in a computer-readable storage medium; at least one processor of the device can read the computer-executable instructions from the computer-readable storage medium, and at least one processor executes the computer-executable instructions to enable the device to implement the method provided by any possible implementation of the foregoing first aspect or second aspect.

[0026] The seventh aspect of this application provides a communication device, which may include at least one processor, a memory, and a communication interface. At least one processor is coupled to the memory and the communication interface. The memory is used to store instructions, at least one processor is used to execute the instructions, and the communication interface is used to communicate with other communication devices under the control of at least one processor. When the instructions are executed by at least one processor, at least one processor executes the method in any possible implementation of the first aspect or the second aspect.

[0027] The eighth aspect of this application provides a chip system, which includes a processor for supporting the implementation of the functions involved in any possible implementation of the foregoing first aspect or second aspect.

[0028] In a possible design, the chip system may further include a memory for storing necessary program instructions and data. The chip system may be composed of chips or may include chips and other discrete devices.

[0029] Among them, for the technical effects brought by the third to eighth aspects or any one of the possible implementation manners, reference may be made to the technical effects brought by different possible implementation manners of the first aspect or the second aspect, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1-1 It is a schematic diagram of the composition structure of a system architecture provided by an embodiment of the present application;

[0031] Figure 1-2 It is a schematic diagram of the composition structure of a communication network provided by an embodiment of the present application;

[0032] Figure 1-3 It is a schematic diagram of a network device provided by an embodiment of the present application;

[0033] Figure 1-4 It is a schematic diagram of a network device and a rule execution component provided by an embodiment of the present application;

[0034] Figure 2-1 It is a schematic diagram of the flowchart of a data processing method provided by an embodiment of the present application;

[0035] Figure 2-2 It is a schematic diagram of distributing a data flow execution rule provided in an embodiment of the present application;

[0036] Figure 2-3 It is a schematic diagram of forwarding a data packet provided in an embodiment of the present application;

[0037] Figure 3 It is a schematic diagram of the structure of a network controller provided by an embodiment of the present application;

[0038] Figure 4 It is a schematic diagram of the structure of a network device provided by an embodiment of the present application;

[0039] Figure 5 It is a schematic diagram of the structure of a communication device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] Embodiments of the present application provide a data processing method and related devices for distributing data flow execution rules in a packet forwarding path.

[0041] The embodiments of the present application will be described below with reference to the accompanying drawings.

[0042] The terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of this application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device comprising a series of units does not have to be limited to those units, but may include other units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0043] Please refer to Figure 1-1 , which shows a schematic diagram of a system architecture involved in an embodiment of this application. The system architecture includes a communication network 100, a client device 200 and a server 300. The communication network 100 includes a plurality of network devices, and data packets can be transmitted between the client device 200 and the server device 300 through the network devices in the communication network 100.

[0044] In some possible implementation manners, the client device 200 or the server device 300 may be a terminal device or a server. In some possible implementation manners, the client device 200 or the server device 300 may be a physical device, a virtual device, or a container instance. The client device 200 and the server device 300 may be the same type of communication device (terminal device or server, physical device or virtual device or container instance), or different communication devices.

[0045] Among them, the terminal device can be referred to as a terminal, user equipment (UE), mobile station (MS), mobile terminal (MT), etc. The terminal device can be a mobile phone, a tablet (pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, and so on. The embodiments of this application do not limit the specific technologies and specific device forms adopted by the terminal device.

[0046] Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, and big data and artificial intelligence platforms.

[0047] Since the server needs to respond to service requests and process them to provide reliable services, generally speaking, the server should have the ability to undertake and guarantee services, and this server needs to have strong processing capabilities, high stability, high reliability, high security, scalability, and manageability. In the embodiments of this application, the server can be an x86 server. The x86 server is also called a complex instruction set computer (CISC) architecture server, that is, the so-called personal computer (PC) server. It is a server based on the PC architecture, using a processor chip of Intel or other compatible x86 instruction sets and the windows operating system.

[0048] Exemplarily, please refer to Figure 1-2 , the communication network 100 may include M network devices (M is a positive integer), where the M network devices are used to forward data packets between the client device 200 and the server device 300.

[0049] Exemplarily, the multiple network devices include network devices 102 to 107 (that is, network device 102, network device 103, network device 104, network device 105, network device 106, and network device 107). Based on the flow direction of the data packet, a packet forwarding path can be determined. The packet forwarding path can include an ingress network device and an egress network device. Optionally, the packet forwarding path can further include at least one transit network device located between the ingress network device and the egress network device.

[0050] Exemplarily, as Figure 1-2 In the example where the client device 200 transmits a packet to the server device 300 through the communication network 100, if the packet forwarding path is network device 102 -> network device 103 -> network device 104 -> network device 107, then network device 102 is the ingress network device, network devices 102 and 103 are transit network devices, and network device 107 is the egress network device. As Figure 1-2 The two network devices shown in can be directly communicatively connected or communicatively connected through the Internet.

[0051] Among them, each of the network devices 102 to 107 can be a switch (virtual switch or physical switch) or a router (virtual router or physical router), etc., which are devices used for forwarding packets in the communication network 100. The network devices 102 to 107 can be network devices of the same type. For example, the network devices 102 to 107 can all be routers. Or, the network devices 102 to 107 can be network devices of different types. For example, some of the network devices 102 to 107 are routers and the other part are switches, which is not limited here.

[0052] Among them, a router is a hardware device that connects two or more user devices and acts as a gateway between the user devices. A router is a dedicated intelligent network device that can read the destination address in the packet and determine how to transmit the packet according to the destination address; a router can understand different protocols, such as the Ethernet protocol used by a local area network and the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol used by the Internet, etc. In this way, the router can analyze the destination addresses of packets transmitted from various different types of networks, convert non-TCP / IP addresses into TCP / IP addresses, or vice versa; and then, according to the routing algorithm, transmit each packet to the destination address along the best transmission path. Therefore, a router can connect a non-TCP / IP network to the Internet.

[0053] It should be noted that the above Figure 1-1 、 Figure 1-2 The system architecture shown is only for illustration and is not used to limit the technical solutions of the embodiments of the present application. In the specific implementation process, the communication network 100 may further include other devices, and the number of network devices can be configured according to needs.

[0054] In the existing communication network, when a client device wants to access a server device, it needs to go through a packet forwarding path composed of multiple different types of network devices (for example, routers, switches, firewalls, etc.). Multiple network devices on the packet forwarding path are provided by different manufacturers and have different service characteristics (for example, blacklist, speed limit, packet capture, etc.).

[0055] Currently, in a software defined network (SDN), the network controller can determine the packet forwarding path for the data flow. If you want to orchestrate the service functions of the packet forwarding path according to the user's needs, the user needs to orchestrate each network device in the packet forwarding path one by one, with low efficiency.

[0056] The network controller can determine the packet forwarding path of the data flow and determine the segmentation policy of each network device among multiple network devices to obtain the data flow execution rule. Among them, the segmentation policy includes the identifier of at least one traffic subspace and the corresponding service function. The identifier of the traffic subspace includes the traffic space where the data flow is located and the identifier of the traffic space. The traffic space includes N-tuples, and N is a positive integer. Then, the network controller can publish the data flow execution rule to multiple network devices, so that each network device among the multiple network devices can obtain the corresponding segmentation policy in the data flow execution rule and execute the corresponding service function on the data flow, realizing the unified orchestration of the service functions of each network device in the packet forwarding path according to the user's needs, without the user having to orchestrate each network device one by one, reducing the complexity of orchestrating service functions and improving the efficiency of orchestrating service functions at the same time.

[0057] In some possible implementation manners, a rule execution component can be embedded in the network device, and the rule execution component can execute the data flow execution rule, as Figure 1-3 shown.

[0058] In some possible implementation manners, the network device can be connected to a third-party rule execution component. Through traffic traction technology, the rule execution component extracts the data flow from the network device, executes the corresponding data flow execution rule on the data flow, and then sends it back to the network device, as Figure 1-4 shown.

[0059] The foregoing embodiments introduced the communication network provided by this application. Next, a data processing method executed based on this communication network will be introduced.

[0060] Please refer to Figure 2-1 As shown, the data processing method provided by the embodiments of this application mainly includes the following steps:

[0061] 201. The network controller obtains the communication quality between any two network devices in the communication network, and obtains a communication quality matrix. The multiple network devices on the packet forwarding path all belong to the communication network.

[0062] In some possible implementation manners, the communication quality between any two network devices can be represented by the communication delay between these two network devices. Exemplarily, as Figure 1-2 shown, the network controller can obtain the communication delay between network device 102 and network device 103, and use this communication delay as the communication quality between network device 102 and network device 103. In some possible implementation manners, the network controller can also perform certain mathematical processing on this communication delay, and use the obtained value as the communication quality. For example, perform normalization processing, which is not limited herein.

[0063] In some possible implementation manners, the network controller can instruct a network device in the communication network to send a data packet to another network device, and then obtain this communication quality from the feedback of the network device that receives the data packet. In some possible implementation manners, the network quality can also be measured by other means, which is not limited herein. In some possible implementation manners, the network controller can obtain the communication quality in segments through a dial test or a telemetry component.

[0064] In some possible implementation manners, the communication network can be a local area network (LAN), a metropolitan area network (MAN), or a wide area network (WAN), or can also be an autonomous system (AS), or other forms of communication networks, which is not limited herein.

[0065] In some possible implementation manners, after the network controller obtains the communication quality between any two network devices in the communication network, it can form a communication quality matrix with the communication quality between each network device in the communication network.

[0066] Exemplarily, as shown in Table 1, it is an example of the communication quality matrix:

[0067] Table 1

[0068] Network Device 1 Network Device 2 Network Device 3 Network Device 4 Network Device 1 - Q21 Q31 Q41 Network Device 2 Q12 - Q32 Q42 Network Device 3 Q13 Q23 - Q43 Network Device 4 Q14 Q24 Q34 -

[0069] Among them, Qij represents the communication quality from network device i to network device j.

[0070] In some possible implementation manners, the network controller can perform real-time monitoring on the communication network, obtain in real time the communication quality between any two network devices in the communication network, and update the communication quality matrix in real time. For example, if there is a link failure from network device 1 to network device 2, the obtained communication quality matrix is shown in Table 2:

[0071] Table 2

[0072] Network Device 1 Network Device 2 Network Device 3 Network Device 4 Network Device 1 - Q21 Q31 Q41 Network Device 2 - - Q32 Q42 Network Device 3 Q13 Q23 - Q43 Network Device 4 Q14 Q24 Q34 -

[0073] In some possible implementation manners, step 201 is optional, that is, step 201 can be executed or not, and there is no limitation here.

[0074] 202. The network controller determines the packet forwarding path of the data stream based on the communication quality matrix, and the packet forwarding path includes multiple network devices connected in sequence.

[0075] Exemplarily, as Figure 1-2 shown, packet forwarding path 1: network device 102 -> network device 103 -> network device 104 -> network device 107; or, packet forwarding path 2: network device 102 -> network device 105 -> network device 106 -> network device 107. It should be noted that two adjacent network devices in the packet forwarding path can be adjacent or not, as long as they are reachable, and there is no limitation here. Exemplarily, packet forwarding path 3: network device 102 -> network device 105 -> network device 107.

[0076] In some possible implementation manners, the network controller can calculate the communication quality of a packet forwarding path, and the communication quality of a packet forwarding path is calculated from the network quality from other network devices except the last-hop network device to the next-hop.

[0077] For example, the communication quality of packet forwarding path 1 can be calculated based on the following communication quality: the network quality from network device 102 to network device 103, the network quality from network device 103 to network device 104, and the network quality from network device 104 to network device 107.

[0078] Exemplarily, if the network quality is communication delay, the communication quality of a packet forwarding path is the sum of the communication delays from other network devices except the last-hop network device to the next hop indicated by the packet forwarding path. For example, for the communication quality of packet forwarding path 1: the sum of the communication delays from network device 102 to network device 103, from network device 103 to network device 104, and from network device 104 to network device 107. Then, the network controller can select the packet forwarding path with the optimal communication quality from the source device to the destination device, such as selecting the packet forwarding path with the lowest total communication delay.

[0079] In some possible implementation manners, the network controller can determine the packet forwarding path of the data stream based on the communication quality matrix, or can also receive user input to generate the packet forwarding path, which is not limited herein.

[0080] 203. The network controller determines the segmentation strategy of each network device among multiple network devices to obtain the data stream execution rule.

[0081] In some possible implementation manners, the segmentation strategy includes the identifier of at least one traffic subspace and the corresponding service function. The identifier of the traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The traffic space includes N-tuples, and N is a positive integer.

[0082] In some possible implementation manners, the service function includes at least one of rate limiting, blacklist, and packet capture. In some possible implementation manners, the data stream execution rule further includes at least one of a rule identifier, the data source required to execute the data stream execution rule, the preset time period for executing the data stream execution rule, the traffic space, the number of segments of the segmentation strategy in the data stream execution rule, and the current hop count.

[0083] Among them, the rule identifier can be the unique identifier of the data stream execution rule; when a network device needs to execute the data stream execution rule, it can obtain the required data based on the data source and execute the data stream execution rule based on the required data, such as protocol variables, uniform resource identifier (URI) (for example, objects introduced by globally shared keys, certificates, geographic libraries, reputation libraries, etc.); the preset time period (schedule) is used to indicate the time period or cycle for running the data stream execution rule; the number of segments of the segmentation strategy in the data stream execution rule can be the number of network devices on the packet forwarding path; the current hop count is used to indicate to the network device to obtain the corresponding segmentation strategy in the data stream execution rule. In some possible implementation manners, the data stream execution rule further includes a rule label, which is the display name of the data stream execution rule.

[0084] In some possible implementation manners, a traffic space may be defined as an N-tuple information (N is a positive integer). For example, the five-tuple information of "source Internet Protocol (IP) address + source port + protocol + destination IP address + destination port", or the three-tuple information of "protocol + destination IP address + destination port".

[0085] In some possible implementation manners, the identifier of a traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The identifier of the traffic space may be a VXLAN network identifier (VNI).

[0086] Exemplarily, a traffic space may correspond to a traffic space identifier (TSID). Exemplarily, an overlay network built on a virtual extensible local area network (VXLAN) may use a VNI to identify different traffic spaces.

[0087] It should be noted that the same or different VNIs may be assigned to different traffic spaces (N-tuples). Then, a VNI can be uniquely determined based on the traffic space (N-tuple). The traffic space (N-tuple) and the VNI form a traffic subspace. It should be noted that different traffic spaces (N-tuples) may also correspond to the same VNI. However, the same traffic space (N-tuple) cannot correspond to different VNIs.

[0088] In some possible implementation manners, the data stream execution rule may adopt an open definition. For example, it is expressed using an extended language such as xml or json. The actual scenario can expand new service capabilities as needed, and each network device dynamically expands the new service capabilities in a hot-pluggable manner.

[0089] In some possible implementation manners, the fragmentation policy further includes the information of the next hop, and the information of the next hop is used to indicate the next hop for forwarding the control packet to the network device.

[0090] In some possible implementation manners, the data stream execution rule further includes at least one of a rule identifier, a data source required to execute the data stream execution rule, a preset time period for executing the data stream execution rule, a traffic space, the number of segments of the fragmentation policy in the data stream execution rule, and the current hop count. The current hop count is used to indicate to the network device to obtain the corresponding fragmentation policy in the data stream execution rule.

[0091] Exemplarily, taking xml as an example, the data stream execution rule may be defined as:

[0092] <rule id="1" data-source="packet" schedule="01:00-06:00 every day" tag="filter"> / / Indicates that the rule identifier (rule id) for the execution rule of this data stream is "1"; the data source (data-source) is "packet" (data packet), that is, the data packet received by the data source; the preset time period (schedule) is from 01:00 to 06:00 every morning; the display tag for the execution rule of this data stream is "filter" (filter)

[0093] <traffic-space id="10" scope="dip+proto+dport"> / / Indicates that the identifier of the traffic space (traffic-space id) is "10", and the range definition (scope) of this traffic space is "dip+proto+dport", that is, the triple of the value of the destination IP address (dip), the specific protocol (proto), and the destination port (dport)

[0094] <segment-policylist num=3 cur=1> / / Indicates that the execution rule of this data stream has 3 segment policies (num=3), and the currently to-be-distributed is the segment policy with the current hop count being the 1st hop (cur=1)

[0095] <segment-policy id=1 nexthop="1.1.1.1"> / / Indicates that the identifier of the segment policy is 1, and the next-hop information is the IP address "1.1.1.1"

[0096] <sub-traffic-space="vni+dip+proto+dport" function-list="qos:ratelimit100mbps|capture:redirect to 3.3.3.3"> / / Indicates that the traffic subspace of this data flow is represented by "vni+dip+proto+dport", which represents the value of the VXLAN Network Identifier (VNI) of the virtual extensible local area network (VXLAN), the value of the destination IP address (dip), the specific protocol (proto), and the value of the destination port (dport). Its corresponding service functions in the function list include quality of Service (QoS) with a rate limit of 100 megabits per second (Mbps), capturing data packets and forwarding them according to the IP address "3.3.3.3"

[0097] <sub-traffic-space="default" function-list="qos:rate limit 100mbps"> / / Among them, "default" indicates that for data packets in other traffic subspaces except sub-traffic-space="vni+dip+proto+dport", the executed service functions in the function list include quality of Service (QoS) with a rate limit of 100 megabits per second (Mbps)

[0098] / / The above is the segmentation policy (i.e., the terminator of the above segmentation policy)

[0099] <segment-policy id=2 nexthop=“1.1.2.1”> / / Indicates that the identifier of the segmentation policy is 1 and the next hop is "1.1.2.1"

[0100] <sub-traffic-space="default" function-list="blacklist:2.2.2.2,3.3.3.3"> / / where "default" means that for any data packet from the traffic space of sub-traffic-space="dip+proto+dport", the service function is executed. The function list (function-list) includes the blacklist (blacklist) for data packets with IP addresses "2.2.2.2" and "3.3.3.3". That is, when data packets with source IP addresses "2.2.2.2" and "3.3.3.3" are received, they are discarded

[0101] / / The above is the segmentation policy

[0102] <segment-policy id=3 nexthop="null"> / / Indicates that the identifier of the segmentation policy is 1 and the next hop is null, that is, this network device is the last hop of the packet forwarding path

[0103] <sub-traffic-space="default" function-list="qos:rate limit 100mbps"> / /

[0104] / / The above is the service function

[0105] / / The above is the segmentation policy (i.e., the terminator of the above segmentation policy)

[0106] / / The above is the traffic space (i.e., the terminator of the above traffic space)

[0107] / / The above is the data flow execution rule (i.e., the terminator of the above data flow execution rule)

[0108] 204. The network controller sends a control packet to the first network device among multiple network devices, and the control packet includes the data flow execution rule.

[0109] In the embodiment of the present application, the network controller can publish the data flow execution rule to multiple network devices, so that each network device among the multiple network devices obtains the corresponding segmentation policy in the data flow execution rule and executes the corresponding service function on the data flow. In some possible implementation manners, the first network device is the ingress network device of the packet forwarding path. Exemplarily, if the packet forwarding path is packet forwarding path 3: network device 102 -> network device 105 -> network device 107, then the first network device can be network device 102.

[0110] 205. The first network device obtains a first segmentation policy for a data stream from a control message.

[0111] It should be noted that the segmentation policy includes the identifier of at least one traffic subspace and the corresponding service function. The identifier of the traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The traffic space includes N-tuples, and N is a positive integer.

[0112] In some possible implementation manners, the first network device may receive a control message, where the control message includes a data stream execution rule, and obtain the first segmentation policy from the data stream execution rule. The first segmentation policy is one of multiple segmentation policies assigned to the first network device in the data stream execution rule. In some possible implementation manners, the data stream execution rule includes a current hop count, and the first network device may determine the corresponding first segmentation policy based on the current hop count.

[0113] Exemplarily, continuing the above example, after the first network device obtains the data stream execution rule from the control message, it determines the first segmentation policy based on "cur = 1" in the data stream execution rule. The identifier of the first segmentation policy is 1 (segment-policy id = 1), and the next hop is "1.1.1.1" (nexthop = "1.1.1.1"); the list of service functions (function-list) in the first segmentation policy includes that the quality of Service (QoS) is rate-limited to 100 megabits per second (Mbps), the data packet is obtained and forwarded according to the IP address "3.3.3.3" (function-list = "qos:rate limit100mbps|capture:redirect to 3.3.3.3").

[0114] In addition, the first network device may determine that the rule identifier (rule id) of the data stream execution rule is "1", the data source (data-source) is "packet" (data packet), the preset time period (schedule) is from 01:00 to 06:00 in the early morning every day, and the display label of the data stream execution rule is "filter" (filter) (<rule id = "1" data-source = "packet" schedule = "01:00-06:00 every day" tag = "filter">).

[0115] In some possible implementation manners, the first network device may attempt to execute the first segmentation policy. If the execution is successful, the first segmentation policy is localised, and a success message is sent to the network controller, and data streams corresponding to respective service functions in the first segmentation policy are processed; if the execution is unsuccessful, the first network device returns a failure message to the network controller.

[0116] 206. The first network device forwards a control message to the second network device.

[0117] In some possible implementation manners, the first network device may modify the value of the current hop count in the data stream execution rule and forward the control message based on information of the next hop. Continuing with the above example, the first network device may set cur = cur + 1 in the data stream execution rule, that is, change cur = 1 to cur = 2.

[0118] In some possible implementation manners, the control message carries a data stream execution rule, and the second network device is the next network device of the first network device in the message forwarding path. Exemplarily, if the message forwarding path is Message Forwarding Path 3: Network Device 102 -> Network Device 105 -> Network Device 107, then the first network device is Network Device 102, and the second network device is Network Device 103.

[0119] 207. The second network device obtains a second segmentation policy for the data stream from the control message.

[0120] Exemplarily, continuing with the above example, after the second network device obtains the data stream execution rule from the control message, it determines the second hop, that is, the second segmentation policy, based on "cur = 2" in the data stream execution rule. The identifier of this second segmentation policy is 2 (segment - policy id = 2), and the next hop is "1.1.2.1" (nexthop = "1.1.2.1"); this second segmentation policy also indicates that the list of service functions (function - list) of this second segmentation policy includes blacklists "2.2.2.2" and "3.3.3.3" (function - list = "blacklist = 2.2.2.2,3.3.3.3").

[0121] In addition, the second network device may determine that the rule identifier (rule id) of the data flow execution rule is "1", the data source is "packet", the preset time period (schedule) is from 01:00 to 06:00 every morning, and the display tag of the data flow execution rule is "filter" (<rule id="1" data-source="packet" schedule="01:00-06:00 every day" tag="filter">).

[0122] In some possible implementation manners, the second network device may attempt to execute the second segmentation policy. If the execution is successful, the second segmentation policy is localised, and a message indicating successful execution is sent to the network controller, and the corresponding data flow is processed based on each service function in the second segmentation policy; if the execution is unsuccessful, the second network device returns a message indicating failed execution to the network controller.

[0123] 208. The second network device forwards a control message to the third network device.

[0124] In some possible implementation manners, the second network device may modify the value of the current hop count in the data flow execution rule and forward the control message based on the information of the next hop. Continuing with the above example, the second network device may set cur = cur + 1 in the data flow execution rule, that is, change cur = 2 to cur = 3.

[0125] In some possible implementation manners, the control message carries the data flow execution rule, and the third network device is the next network device of the second network device in the message forwarding path. Exemplarily, if the message forwarding path is message forwarding path 3: network device 102 -> network device 105 -> network device 107, then the second network device is network device 105, and the third network device is network device 107.

[0126] 209. The third network device obtains a third segmentation policy for the data flow from the control message.

[0127] Exemplarily, continuing with the above example, after the third network device obtains the data flow execution rule from the control message, it determines the third hop, i.e., the third segmentation policy, based on "cur = 3" in the data flow execution rule. The identifier of this third segmentation policy is 3 (segment - policy id = 3), and the next hop is "1.1.3.1" (nexthop = "1.1.3.1"); this third segmentation policy also indicates that the list of service functions (function - list) of the second segmentation policy includes quality of service (QoS) with a speed limit of 100 megabits per second (mbps) (function - list = "qos:rate limit 100mbps").

[0128] In addition, the third network device can determine that the rule identifier (rule id) of the data flow execution rule is "1", the data source (data - source) is "packet" (data packet), the preset time period (schedule) is from 01:00 to 06:00 in the early morning every day, and the display label of the data flow execution rule is "filter" (<rule id = "1" data - source = "packet" schedule = "01:00 - 06:00 every day" tag = "filter">).

[0129] In some possible implementation manners, the third network device can attempt to execute the third segmentation policy. If the execution is successful, it localizes the third segmentation policy, sends a success message to the network controller, and processes the corresponding data flow based on each service function in the third segmentation policy; if the execution is unsuccessful, the third network device returns a failure message to the network controller.

[0130] Exemplarily, as Figure 2-2 shown, the network controller can generate a data flow execution rule and send it to the first network device. Then the first network device obtains the first segmentation policy from the data flow execution rule and localizes it, and forwards the data flow execution rule to the second network device. Then the second network device obtains the second segmentation policy from the data flow execution rule and localizes it, and forwards the data flow execution rule to the third network device. Then the third network device obtains the third segmentation policy from the data flow execution rule and localizes it.

[0131] 210. The first user device sends a data packet to the first network device.

[0132] In an embodiment of the present application, when each network device in the data flow execution rule obtains the corresponding segmentation policy and localizes it, the first user device may send a data packet to the first network device. It should be noted that the data packet carries the effective information of the application layer and is a message sent from the first user device to the second user device.

[0133] 211. The first network device executes the first segmentation policy on the data packet and forwards the data packet to the second network device.

[0134] In some possible implementation manners, after receiving the data packet, the first network device may determine the information of the N-tuple according to the data packet, and determine the traffic space where the data flow is located and the identifier of the corresponding traffic space according to the information of the N-tuple, obtain the identifier of the traffic subspace, and determine the first segmentation policy corresponding to the data flow according to the identifier of the traffic subspace, and execute the first segmentation policy on the data packet and forward the data packet to the second network device.

[0135] Exemplarily, when the first network device receives the data packet, the first network device obtains the information of the triple (dip+proto+dport) in the data packet, and queries the identifier of the traffic space based on the information of the triple, and obtains vni. Among them, the information of the triple (dip+proto+dport) and vni can jointly define the traffic subspace. Then, the first network device queries the local function list based on vni and the information of the triple (dip+proto+dport), and obtains the first segmentation policy corresponding to the traffic subspace. Then, the first network device may process and forward the data packet based on the first segmentation policy.

[0136] Continuing the above example, the identifier of the first segmentation policy corresponding to the first network device is 1 (segment-policyid = 1), the next hop is "1.1.1.1" (nexthop = "1.1.1.1"), and the function list (function-list) of the first segmentation policy includes that the quality of service (QoS) is rate limited to 100 megabits per second (Mbps), obtain the data packet and forward it according to the IP address "3.3.3.3" (function-list = "qos:rate limit100mbps|capture:redirect to 3.3.3.3>"). Then, when the first network device receives the data packet, it can rate limit the data flow of the data packet (100 megabits per second (Mbps)), and copy the data packet and forward it to the IP address "3.3.3.3" (i.e., packet capture).

[0137] Next, the first network device may forward the data packet to the next hop "1.1.1.1" (nexthop = "1.1.1.1") indicated in the first service function.

[0138] 212. The second network device executes a second segmentation policy on the data packet and forwards the data packet to the third network device.

[0139] In some possible implementation manners, after receiving the data packet, the second network device may determine the information of the N - tuple according to the data packet, and determine the traffic space where the data flow is located and the identifier of the corresponding traffic space according to the information of the N - tuple, obtain the identifier of the traffic subspace, and determine the second segmentation policy corresponding to the data flow according to the identifier of the traffic subspace, and then execute the second segmentation policy on the data packet and forward the data packet to the third network device.

[0140] Exemplarily, when the second network device receives the data packet, the second network device obtains the information of the triple (dip + proto + dport) in the data packet, and queries the identifier of the traffic space based on the information of the triple, and obtains the vni. Among them, the information of the triple (dip + proto + dport) and the vni can jointly define the traffic subspace. Then, the second network device queries the local function list based on the vni and the information of the triple (dip + proto + dport), and obtains the second segmentation policy corresponding to the traffic subspace. Then, the second network device can process and forward the data packet based on the second segmentation policy.

[0141] Continuing the above example, the identifier of the second segmentation policy corresponding to the second network device is 2 (segment - policyid = 2), the next hop is "1.1.2.1" (nexthop = "1.1.2.1"), and the function list of the second segmentation policy (function - list) is the blacklist "2.2.2.2" and "3.3.3.3" (function - list = "blacklist = 2.2.2.2,3.3.3.3"). Then, when the second network device receives the data packet, if the source IP address of the data packet is "2.2.2.2" or "3.3.3.3", the second network device discards the data packet.

[0142] If the source IP address of the data packet is not "2.2.2.2" or "3.3.3.3", the second network device may forward the data packet to the next hop "1.1.2.1" (nexthop = "1.1.2.1") indicated in the second service function.

[0143] 213. The third network device executes a third segmentation policy on the data packet and forwards the data packet to the second user device.

[0144] In some possible implementation manners, after receiving the data packet, the third network device may determine the information of the N-tuple according to the data packet, and determine the traffic space where the data flow is located and the identifier of the corresponding traffic space according to the information of the N-tuple, obtain the identifier of the traffic subspace, and determine the third segmentation policy corresponding to the data flow according to the identifier of the traffic subspace, and execute the third segmentation policy on the data packet and forward the data packet to the second user device.

[0145] Exemplarily, when the third network device receives the data packet, the third network device obtains the information of the triple (dip + proto + dport) in the data packet, and queries the identifier of the traffic space based on the information of the triple, and obtains the vni. Among them, the information of the triple (dip + proto + dport) and the vni can jointly define the traffic subspace. Then, the third network device queries the local function list based on the vni and the information of the triple (dip + proto + dport), and obtains the third service function corresponding to the traffic subspace. Then, the third network device can process and forward the data packet based on the third service function.

[0146] Continuing the above example, the identifier of the third segmentation policy corresponding to the third network device is 3 (segment-policyid = 3), the next hop is "1.1.3.1" (nexthop = "1.1.3.1"), and the list of service functions (function-list) of the third segmentation policy includes that the quality of service (QoS) is rate limited to 100 megabits per second (mbps) (function-list = "qos:rate limit 100mbps"). Then, when the third network device receives the data packet, the data flow of the data packet is rate limited to 100 megabits per second (mbps).

[0147] Then, if the next hop indicated in the third service function is "null" (nexthop = "null"), the third network device sends the data packet to the second user device, and the second user device is the destination device of the data packet.

[0148] Exemplarily, such as Figure 2-3As shown, the first user device sends a data packet to the first network device. Then, the first network device processes the data packet based on the first segmentation policy and forwards it to the second network device. Next, the second network device processes the data packet based on the second segmentation policy and forwards it to the third network device. Then, the third network device processes the data packet based on the third segmentation policy and forwards it to the second user device.

[0149] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0150] To facilitate better implementation of the above solutions of the embodiments of this application, the following also provides related devices for implementing the above solutions.

[0151] Please refer to Figure 3 As shown, a network controller 300 provided by an embodiment of this application may include:

[0152] A processing module 301, configured to determine a packet forwarding path of a data stream, where the packet forwarding path includes a plurality of network devices connected in sequence;

[0153] The processing module 301 is further configured to determine a segmentation policy for each of the plurality of network devices to obtain a data stream execution rule. The segmentation policy includes at least one identifier of a traffic subspace and a corresponding service function. The identifier of the traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The traffic space includes an N-tuple, and N is a positive integer;

[0154] A transceiver module 302, configured to publish the data stream execution rule to the plurality of network devices, so that each of the plurality of network devices obtains the corresponding segmentation policy in the data stream execution rule and performs the corresponding service function on the data stream.

[0155] In some possible implementation manners, the processing module 301 is specifically configured to:

[0156] Obtain the communication quality between any two network devices in the communication network to obtain a communication quality matrix. The plurality of network devices in the packet forwarding path all belong to the communication network;

[0157] Determine the packet forwarding path of the data stream based on the communication quality matrix.

[0158] In some possible implementations, the transceiver module 302 is specifically configured to:

[0159] Send a control message to a first network device among the multiple network devices, where the control message includes the data flow execution rule, so that the first network device obtains a corresponding first segmentation policy from the data flow execution rule, and forwards the control message to other network devices among the multiple network devices.

[0160] Please refer to Figure 4 As shown, a network device 400 provided in an embodiment of the present application, used as the first network device, may include:

[0161] A transceiver module 401, configured to obtain a data flow execution rule for a data flow, where the data flow execution rule includes the segmentation policies of each network device among the multiple network devices for the data flow, the multiple network devices include the first network device, the multiple network devices are connected in sequence to form a message forwarding path, the segmentation policy includes the identifier of at least one traffic subspace and the corresponding service function, the identifier of the traffic subspace includes the traffic space where the data flow is located, and the identifier of the traffic space, the traffic space includes an N-tuple, and N is a positive integer;

[0162] A processing module 402, configured to obtain a corresponding first segmentation policy from the data flow execution rule;

[0163] The processing module 402 is further configured to execute the first segmentation policy on the data flow.

[0164] In some possible implementations, the data flow execution rule includes a current hop count, and the processing module 402 is specifically configured to: determine the corresponding first segmentation policy in the data flow execution rule based on the current hop count.

[0165] In some possible implementations, the transceiver module 401 is specifically configured to: receive a control message, where the control message includes the data flow execution rule.

[0166] In some possible implementations, the data flow execution rule includes information about the next hop;

[0167] The processing module 402 is further configured to modify the value of the current hop count in the data flow execution rule;

[0168] The transceiver module 401 is further configured to forward the control message based on the information about the next hop.

[0169] In some possible implementations, the transceiver module 401 is further configured to receive a data message;

[0170] The processing module 402 is further configured to determine that the data packet belongs to the data flow according to the information of the N-tuple of the data packet;

[0171] The processing module 402 is further configured to determine the traffic space where the data flow is located and the identifier of the corresponding traffic space according to the information of the N-tuple, so as to obtain the identifier of the traffic subspace;

[0172] The processing module 402 is further configured to determine the first segmentation policy corresponding to the data flow according to the identifier of the traffic subspace.

[0173] It should be noted that the information interaction, execution process, etc. between the above-mentioned device modules / units, due to being based on the same concept as the method embodiment of the present application, bring the same technical effects as the method embodiment of the present application. For the specific content, reference can be made to the description in the method embodiment shown above in the present application, and details will not be repeated here.

[0174] The embodiment of the present application further provides a computer storage medium, where the computer storage medium stores a program, and the program executes some or all of the steps recorded in the above method embodiment.

[0175] Next, another communication device provided by the embodiment of the present application will be introduced. Please refer to Figure 5 As shown, the communication device 500 includes: a receiver 501, a transmitter 502, a processor 503, and a memory 504. In some embodiments of the present application, the receiver 501, the transmitter 502, the processor 503, and the memory 504 can be connected through a bus or other means, where Figure 5 taking the connection through the bus as an example.

[0176] The memory 504 may include a read-only memory and a random access memory, and provide instructions and data to the processor 503. A part of the memory 504 may also include a non-volatile random access memory (NVRAM). The memory 504 stores an operating system and operation instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof. Among them, the operation instructions may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and processing hardware-based tasks.

[0177] The processor 503 controls the operation of the communication device 500. The processor 503 may also be referred to as a central processing unit (CPU). In a specific application, the various components of the communication device 500 are coupled together through a bus system. The bus system may include, in addition to a data bus, a power bus, a control bus, a status signal bus, etc. However, for the sake of clear illustration, all kinds of buses are referred to as the bus system in the figure.

[0178] The method disclosed in the embodiments of the present application described above can be applied to the processor 503 or implemented by the processor 503. The processor 503 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method can be completed by the integrated logic circuit in the hardware of the processor 503 or instructions in the form of software. The above-mentioned processor 503 may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 504, and the processor 503 reads the information in the memory 504 and combines its hardware to complete the steps of the above method.

[0179] The receiver 501 can be used to receive input digital or character information and generate signal inputs related to relevant settings and function controls. The transmitter 502 may include a display device such as a display screen. The transmitter 502 can be used to output digital or character information through an external interface.

[0180] In the embodiments of the present application, the processor 503 is used to execute the aforementioned data processing method.

[0181] In another possible design, when the network controller 300, the network device 400 or the communication device 500 is a chip, it includes a processing unit and a communication unit. The processing unit may be, for example, a processor, and the communication unit may be, for example, an input / output interface, a pin or a circuit, etc. The processing unit can execute the computer-executable instructions stored in the storage unit to enable the chip in the terminal to execute the method for sending wireless report information according to any one of the above first aspects. Optionally, the storage unit is a storage unit inside the chip, such as a register, a cache, etc. The storage unit can also be a storage unit outside the chip in the terminal, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.

[0182] Among them, the processor mentioned anywhere above can be a general-purpose central processing unit, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the above methods.

[0183] In addition, it should be noted that the device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the accompanying drawings of the device embodiments provided in this application, the connection relationships between the modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines.

[0184] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware. Of course, it can also be implemented by dedicated hardware including application specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures for implementing the same function can also be diverse, such as analog circuits, digital circuits or dedicated circuits, etc. However, for the present application, software program implementation is a better embodiment in more cases. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk or optical disc of a computer, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0185] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.

[0186] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

Claims

1. A data processing method, characterized in that, it includes: A network controller determines a packet forwarding path of a data stream, and the packet forwarding path includes a plurality of network devices connected in sequence; The network controller determines a segmentation policy for each network device among the plurality of network devices to obtain a data stream execution rule. The segmentation policy includes at least one identifier of a traffic subspace and a corresponding service function. The identifier of the traffic subspace includes the traffic space where the data stream is located and the identifier of the traffic space. The traffic space includes an N-tuple, and N is a positive integer; The network controller publishes the data stream execution rule to the plurality of network devices, so that each network device among the plurality of network devices obtains the corresponding segmentation policy in the data stream execution rule and executes the corresponding service function on the data stream.

2. The method according to claim 1, characterized in that, The network controller determining the packet forwarding path of the data stream includes: The network controller obtains the communication quality between any two network devices in the communication network to obtain a communication quality matrix. The plurality of network devices on the packet forwarding path all belong to the communication network; The network controller determines the packet forwarding path of the data stream based on the communication quality matrix.

3. The method according to claim 2, characterized in that, The communication quality includes communication delay.

4. The method according to any one of claims 1-3, characterized in that, The network controller publishing the data stream execution rule to each network device in the packet forwarding path includes: The network controller sends a control packet to a first network device among the plurality of network devices. The control packet includes the data stream execution rule, so that the first network device obtains a corresponding first segmentation policy from the data stream execution rule and forwards the control packet to other network devices among the plurality of network devices.

5. The method according to claim 4, characterized in that, The first network device is the ingress network device of the packet forwarding path.

6. The method according to any one of claims 1-3, characterized in that, The service function includes at least one of rate limiting, blacklisting, and packet capture.

7. The method according to any one of claims 1-3, characterized in that, The identifier of the traffic space is a network identifier VNI.

8. The method according to claim 4, characterized in that, The segmentation policy further includes information about the next hop, and the information about the next hop is used to indicate the next hop for a network device to forward the control packet.

9. The method according to any one of claims 1-3, characterized in that, The data stream execution rule further includes at least one of a rule identifier, a data source required to execute the data stream execution rule, a preset time period for executing the data stream execution rule, the traffic space, the number of segments of the segmentation policy in the data stream execution rule, and the current hop count. The current hop count is used to indicate to a network device to obtain a corresponding segmentation policy in the data stream execution rule.

10. A data processing method, characterized in that, it includes: The first network device obtains a data flow execution rule for a data flow. The data flow execution rule includes a segmentation strategy for the data flow by each network device among multiple network devices. The multiple network devices include the first network device, and the multiple network devices are connected in sequence to form a packet forwarding path. The segmentation strategy includes at least one identifier of a traffic subspace and a corresponding service function. The identifier of the traffic subspace includes the traffic space where the data flow is located and the identifier of the traffic space. The traffic space includes an N-tuple, where N is a positive integer; The first network device obtains a corresponding first segmentation strategy from the data flow execution rule; The first network device executes the first segmentation strategy on the data flow.

11. The method according to claim 10, wherein, the data flow execution rule includes a current hop count. The first network device obtaining a corresponding first segmentation strategy from the data flow execution rule includes: The first network device determines the corresponding first segmentation strategy in the data flow execution rule based on the current hop count.

12. The method according to claim 11, wherein, the first network device obtaining a data flow execution rule for a data flow includes: The first network device receives a control packet, and the control packet includes the data flow execution rule.

13. The method according to claim 12, wherein, the data flow execution rule includes information about the next hop. After the first network device receives the control packet, it further includes: The first network device modifies the value of the current hop count in the data flow execution rule and forwards the control packet based on the information about the next hop.

14. The method according to any one of claims 10-13, wherein, the service function includes at least one of rate limiting, blacklisting, and packet capture.

15. The method according to any one of claims 10-13, wherein, the identifier of the traffic space is a network identifier VNI.

16. The method according to any one of claims 10-13, wherein, the data flow execution rule further includes a rule identifier, a data source required to execute the data flow execution rule, a preset time period for executing the data flow execution rule, the traffic space, and the number of segments of the segmentation strategy in the data flow execution rule.

17. The method according to any one of claims 10-13, wherein, before the first network device executes the first segmentation strategy on the data flow, it further includes: The first network device receives a data packet; The first network device determines that the data packet belongs to the data flow according to the information of the N-tuple of the data packet; The first network device determines the traffic space where the data flow is located and the corresponding identifier of the traffic space according to the information of the N-tuple, and obtains the identifier of the traffic subspace; The first network device determines the corresponding first segmentation strategy of the data flow according to the identifier of the traffic subspace.

18. A network controller, wherein, comprising: A processing module, configured to determine a packet forwarding path of a data stream, where the packet forwarding path includes a plurality of network devices connected in sequence; The processing module is further configured to determine a segmentation policy for each of the plurality of network devices in the plurality of network devices, and obtain a data stream execution rule, where the segmentation policy includes at least one identifier of a traffic subspace and a corresponding service function, and the identifier of the traffic subspace includes the traffic space where the data stream is located, and an identifier of the traffic space, and the traffic space includes an N-tuple, and N is a positive integer; A transceiver module, configured to publish the data stream execution rule to the plurality of network devices, so that each of the plurality of network devices in the plurality of network devices obtains the corresponding segmentation policy in the data stream execution rule and executes the corresponding service function on the data stream.

19. The network controller according to claim 18, wherein, The processing module is specifically configured to: Obtain the communication quality between any two network devices in a communication network to obtain a communication quality matrix, and the plurality of network devices in the packet forwarding path all belong to the communication network; Determine the packet forwarding path of the data stream based on the communication quality matrix.

20. The network controller according to claim 18 or 19, wherein, The transceiver module is specifically configured to: Send a control packet to a first network device among the plurality of network devices, where the control packet includes the data stream execution rule, so that the first network device obtains a corresponding first segmentation policy from the data stream execution rule and forwards the control packet to other network devices among the plurality of network devices.

21. A network device, wherein, Used as a first network device, including: A transceiver module, configured to obtain a data stream execution rule for a data stream, where the data stream execution rule includes a segmentation policy for each of the plurality of network devices in the plurality of network devices, the plurality of network devices include the first network device, and the plurality of network devices are connected in sequence to form a packet forwarding path, and the segmentation policy includes at least one identifier of a traffic subspace and a corresponding service function, and the identifier of the traffic subspace includes the traffic space where the data stream is located, and an identifier of the traffic space, and the traffic space includes an N-tuple, and N is a positive integer; A processing module, configured to obtain a corresponding first segmentation policy from the data stream execution rule; The processing module is further configured to execute the first segmentation policy on the data stream.

22. The network device according to claim 21, wherein, The data stream execution rule includes a current hop count, and the processing module is specifically configured to: Determine the corresponding first segmentation policy in the data stream execution rule based on the current hop count.

23. The network device according to claim 22, wherein, The transceiver module is specifically configured to: Receive a control packet, where the control packet includes the data stream execution rule.

24. The network device according to claim 23, wherein, The data stream execution rule includes information about the next hop; The processing module is further configured to modify the value of the current hop count in the data stream execution rule; The transceiver module is further configured to forward the control message based on the information of the next hop.

25. The network device according to any one of claims 21-24, wherein, The transceiver module is further configured to receive a data message; The processing module is further configured to determine that the data message belongs to the data stream according to the information of the N-tuple of the data message; The processing module is further configured to determine the traffic space where the data stream is located and the identifier of the corresponding traffic space according to the information of the N-tuple, and obtain the identifier of the traffic subspace; The processing module is further configured to determine the first segmentation policy corresponding to the data stream according to the identifier of the traffic subspace.

26. A computer-readable storage medium, wherein, The computer-readable storage medium stores a program, and the program causes a computer device to execute the method according to any one of claims 1-17.

27. A computer program product, wherein, The computer program product includes computer execution instructions, and the computer execution instructions are stored in a computer-readable storage medium; at least one processor of the device reads the computer execution instructions from the computer-readable storage medium, and the at least one processor executes the computer execution instructions to cause the device to execute the method according to any one of claims 1-17.

28. A communication device, wherein, The communication device includes at least one processor, a memory, and a communication interface; The at least one processor is coupled to the memory and the communication interface; The memory is used to store instructions, the processor is used to execute the instructions, and the communication interface is used to communicate with other communication devices under the control of the at least one processor; When the instructions are executed by the at least one processor, the at least one processor is caused to execute the method according to any one of claims 1-17.

29. A chip system, wherein, The chip system includes a processor and a memory, the memory and the processor are interconnected by a line, the memory stores instructions, and the processor is used to execute the method according to any one of claims 1-17.

Citation Information

Patent Citations

  • Switch control method and device, control equipment and storage medium

    CN114500354A

  • Creating and maintaining segment routed traffic engineering policies via border gateway protocol

    US20180109450A1