Traffic forwarding method and device, computer device and storage medium

By generating new forwarding paths for SRv6 service traffic and configuring appropriate uRPF detection modes, the traffic forwarding problem caused by the failure of strict uRPF detection in IPv6 networks was solved, and normal traffic forwarding was achieved.

CN117041127BActive Publication Date: 2026-01-13CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311063154.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-22
Publication Date
2026-01-13
Estimated Expiration
2043-08-22

AI Technical Summary

Technical Problem

In IPv6 networks, the failure of strict uRPF detection leads to the inability of SRv6 service traffic to be forwarded normally.

Method used

Generate a new forwarding path and configure uRPF detection in the new forwarding path. Determine whether the detection mode is loose or strict uRPF detection based on the packet type to ensure normal traffic forwarding.

Benefits of technology

By replacing the original forwarding path and adopting an appropriate detection mode, the normal forwarding of SRv6 service traffic is ensured, avoiding traffic interruptions caused by detection failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117041127B_ABST
    Figure CN117041127B_ABST
Patent Text Reader

Abstract

The application discloses a flow forwarding method and device, computer equipment and a storage medium. The method can be applied to the field of information security technology, and specifically can include: in the case that the original forwarding path of target message flow cannot forward the target message flow, generating a new forwarding path for the target message flow; querying whether a unicast reverse path forwarding (uRPF) detection is configured in a new forwarding interface in the new forwarding path; if yes, determining a detection mode of the uRPF detection of the new forwarding interface according to the message type of the target message flow; and controlling the new forwarding interface to perform forwarding processing on the target message flow according to the detection mode. The above scheme can ensure normal flow forwarding.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and in particular to a traffic forwarding method and device, computer equipment and a storage medium. BACKGROUND

[0002] With the promotion of the IPv6(Internet Protocol Version 6) network strategy, the IP(Internet Protocol) network gradually adopts IPv6 as the network foundation, and gradually adopts SRv6((Segment Routing IPv6, Segment Routing based on IPv6)) technology as the service carrying tunnel, that is, SR(Segment Routing) + IPv6 is a new generation of IP carrying protocol.

[0003] To ensure the normal forwarding of network SRv6 service traffic, the network node of the existing network generally deploys strict uRPF(Unicast Reverse Path Forwarding) detection on the interconnection link interface. When the forwarding interface on the forwarding path fails, for example, when the network SRv6 service traffic is inconsistent between the entry interface of the device and the route exit interface of the source address of the SRv6 outer IPv6 message, the strict uRPF detection is invalid, resulting in the network SRv6 service traffic being unable to be normally forwarded. SUMMARY

[0004] Therefore, it is necessary to provide a traffic forwarding method, device, computer equipment and storage medium capable of ensuring the normal forwarding of network SRv6 service traffic in view of the above technical problems.

[0005] In a first aspect, the present application provides a traffic forwarding method, which comprises:

[0006] In the case that the original forwarding path of the target message traffic cannot forward the target message traffic, a new forwarding path is generated for the target message traffic;

[0007] It is inquired whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection;

[0008] If yes, the detection mode of the uRPF detection of the new forwarding interface is determined according to the message type of the target message traffic;

[0009] The new forwarding interface is controlled to perform forwarding processing on the target message traffic according to the detection mode.

[0010] In one of the embodiments, the detection mode of the uRPF detection of the new forwarding interface is determined according to the message type of the target message traffic, which comprises:

[0011] If the message type of the target message flow is a segment routing header (SRH) encapsulated message, a determination is made that the detection mode of the uRPF detection of the new forwarding interface is loose uRPF detection.

[0012] If the message type of the target message flow is not an SRH encapsulated message, a determination is made that the detection mode of the uRPF detection of the new forwarding interface is strict uRPF detection.

[0013] In one embodiment, a new forwarding path is generated for the target message flow, including:

[0014] A new forwarding path is generated for the target message flow based on a fast re-route (FRR) mechanism.

[0015] In one embodiment, the new forwarding interface is controlled to perform forwarding processing on the target message flow according to the detection mode, including:

[0016] The new forwarding interface is controlled to perform uRPF security detection on the target message flow according to the detection mode.

[0017] If the uRPF security detection passes, the new forwarding interface is controlled to forward the target message flow based on the new forwarding path.

[0018] In one embodiment, the method further includes:

[0019] If the original forwarding interface in the original forwarding path of the target message flow fails or the original forwarding interface has other traffic scheduling tasks, a determination is made that the original forwarding path of the target message flow cannot forward the target message flow.

[0020] In one embodiment, the method further includes:

[0021] If it is detected that the original forwarding interface has returned to normal, future message flows corresponding to the target message flow are scheduled to be forwarded by the original forwarding path.

[0022] In a second aspect, the present application also provides a traffic forwarding device, including:

[0023] A generating module is configured to generate a new forwarding path for a target message flow if an original forwarding path of the target message flow cannot forward the target message flow.

[0024] A querying module is configured to query whether a unicast reverse path forwarding (uRPF) detection is configured for a new forwarding interface in the new forwarding path.

[0025] A first determining module is configured to determine a detection mode of the uRPF detection of the new forwarding interface according to a message type of the target message flow if the uRPF detection is configured for the new forwarding interface.

[0026] The first forwarding module is configured to control the new forwarding interface, and perform forwarding processing on the target message flow according to the detection mode.

[0027] In a third aspect, the present application provides a computer device, which comprises a memory and a processor. The memory stores a computer program, and the processor implements the steps of the above-mentioned message forwarding method when executing the computer program.

[0028] In a fourth aspect, the present application provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the above-mentioned message forwarding method.

[0029] In a fifth aspect, the present application provides a computer program product, which comprises a computer program. The computer program is executed by a processor to implement the steps of the above-mentioned message forwarding method.

[0030] The above-mentioned message forwarding method, device, computer device and storage medium generate a new forwarding path for the target message flow when the original forwarding path of the target message flow cannot forward the target message flow, query whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding (uRPF) detection, determine the detection mode of the uRPF detection of the new forwarding interface according to the message type of the target message flow when the new forwarding interface is configured with the uRPF detection, and then control the new forwarding interface to perform forwarding processing on the target message flow according to the detection mode. In the message forwarding method of the present application, the new forwarding path generated for the target message flow replaces the original forwarding path, and the corresponding detection mode is used for forwarding the target message flow, so that the technical effect of ensuring normal forwarding of the message is achieved. BRIEF DESCRIPTION OF DRAWINGS

[0031] Figure 1 A flowchart of a message forwarding method in an embodiment;

[0032] Figure 2 A flowchart of forwarding processing on a target message flow in an embodiment;

[0033] Figure 3 A forwarding flowchart of a message forwarding method in an embodiment;

[0034] Figure 4 A structural block diagram of a message forwarding device in an embodiment;

[0035] Figure 5 An internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION

[0036] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0037] With the advancement of the IPv6 (Internet Protocol Version 6) network strategy, IP (Internet Protocol) networks are gradually adopting IPv6 as their network foundation and SRv6 (Segment Routing IPv6, i.e., SR (Segment Routing) + IPv6, a next-generation IP bearer protocol) technology as service transport tunnels. To ensure the normal forwarding of SRv6 service traffic, existing network nodes typically deploy strict uRPF (Unicast Reverse Path Forwarding) detection on interconnection links. When a forwarding interface on the forwarding path fails—for example, when the ingress interface of the SRv6 service traffic on a device is inconsistent with the outgress interface of the routing source address of the outer IPv6 packet—the strict uRPF detection fails, resulting in the inability to forward the SRv6 service traffic normally. Based on this, this application provides a traffic forwarding method to improve the above-mentioned technical problems.

[0038] In one embodiment, Figure 1 This is a flowchart illustrating a traffic forwarding method according to an embodiment of this application. The method can be executed by a server, specifically by an AI (Artificial Intelligence) controller within the server. The method includes the following steps:

[0039] S101: If the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic.

[0040] Optionally, the target packet traffic can be packet traffic to be forwarded. The original forwarding path can be a forwarding path pre-configured for forwarding the target packet traffic. The new forwarding path can be a forwarding path that replaces the original forwarding path to complete the task of forwarding the target packet traffic.

[0041] Furthermore, there are many reasons why the original forwarding path may fail to forward the target packet traffic. It can be determined that the original forwarding path cannot forward the target packet traffic if the original forwarding interface in the original forwarding path of the target packet traffic is faulty or has other traffic scheduling tasks. For example, a faulty original forwarding interface could be caused by a mismatch between the ingress interface of the network SRv6 service traffic and the outgress interface of the routing for the source address of the SRv6 outer IPv6 packet; a faulty original forwarding interface could be caused by the original forwarding interface performing other traffic forwarding tasks. Other situations may also exist, and this application embodiment does not limit the type of faulty original forwarding interface or the type of other traffic scheduling tasks performed by the original forwarding interface.

[0042] Furthermore, there are many methods for generating new forwarding paths for target packet traffic. For example, a new forwarding path can be generated for target packet traffic based on the Fast Rerouting (FRR) mechanism. Alternatively, a new forwarding path can be generated for target packet traffic based on other mechanisms or methods, such as interface configuration and uRPF detection deployment. This application embodiment does not limit the type of mechanism or method.

[0043] Specifically, when the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path generation mechanism or method is selected, and a new forwarding path is generated for the target packet traffic according to the mechanism or method.

[0044] S102, Query whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection.

[0045] Optionally, the new forwarding interface can be a routing interface in the new forwarding path used to forward the target packet traffic. The number of new forwarding interfaces on the new forwarding path can be one or more, and this embodiment does not limit this. Further, this embodiment describes the number of new forwarding interfaces on the new forwarding path as one. uRPF detection can be a necessary mechanism for performing uRPF security detection on the target packet traffic. uRPF security detection on the target packet traffic can only be performed if uRPF detection is configured on the new forwarding interface in the new forwarding path.

[0046] S103, if so, then determine the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic.

[0047] Optionally, the detection mode can be a type of uRPF security inspection performed on the target packet traffic.

[0048] Furthermore, the detection mode of uRPF detection for the new forwarding interface can be determined based on various mechanisms or methods. For example, the packet type of the target packet traffic can be used to determine the detection mode of uRPF detection for the new forwarding interface. If the packet type of the target packet traffic is a packet encapsulated with a segment route extension header (SRH), then the detection mode of uRPF detection for the new forwarding interface is determined to be loose uRPF detection; if the packet type of the target packet traffic is not a packet encapsulated with an SRH, then the detection mode of uRPF detection for the new forwarding interface is determined to be strict uRPF detection. For example, if the next header of IPv6 is 43 and the routing type of the routing extension header is 4, then the packet type of the target packet traffic can be determined to be an SRH-encapsulated packet, and the detection mode of uRPF detection on the new forwarding interface can be determined to be loose uRPF detection. If the next header of IPv6 is not 43 and / or the routing type of the routing extension header is not 4, then the packet type of the target packet traffic can be determined to be an SRH-encapsulated packet, and the detection mode of uRPF detection on the new forwarding interface can be determined to be strict uRPF detection.

[0049] It's important to note that loose uRPF detection is a method that can pass detection if the target traffic has a route to the source IP address, regardless of whether the IP packet of the target traffic was received from the interface corresponding to the next hop in the routing table. Loose uRPF detection, on the other hand, only requires that the target traffic has a route to the source IP address and that the IP packet of the target traffic was received from the interface corresponding to the next hop in the routing table. Furthermore, if strict uRPF is causing traffic to fail to forward, resulting in an infinite loop of calculating forwarding paths, then the traffic forwarding process needs to be restarted.

[0050] Another possible approach is to determine the uRPF detection mode of the new forwarding interface based on the packet type and quantity of the target packet traffic. This can be achieved by comparing the packet quantity with a preset threshold and combining this with the packet type. For example, if the packet type is a packet encapsulated with a segment routing extension header (SRH) and the packet quantity is less than the preset threshold, or if the packet type is not encapsulated with a segment routing extension header (SRH) but the packet quantity is greater than or equal to the preset threshold, then the uRPF detection mode of the new forwarding interface is determined to be loose uRPF detection. Conversely, if the packet type is a packet encapsulated with a segment routing extension header (SRH) and the packet quantity is greater than or equal to the preset threshold, or if the packet type is not encapsulated with a segment routing extension header (SRH) but the packet quantity is less than the preset threshold, then the uRPF detection mode of the new forwarding interface is determined to be strict uRPF detection. The detection mode of uRPF detection for a new forwarding interface can also be determined according to other rules. This application embodiment does not restrict the rules for determining the detection mode of uRPF detection for a new forwarding interface.

[0051] Furthermore, if the new forwarding interface in the new forwarding path is configured with uRPF detection, in addition to determining the detection mode of uRPF detection of the new forwarding interface, it is also possible to determine whether there is a link failure at the forwarding interface.

[0052] Specifically, after determining the packet type of the target packet traffic, the detection mode of uRPF detection for the new forwarding interface is determined according to the packet type of the target packet traffic and the preset rules.

[0053] S104 controls the new forwarding interface to forward target packet traffic according to the detection mode.

[0054] Specifically, after determining the detection mode of uRPF detection for the new forwarding interface, the new forwarding interface is controlled to perform preset detection on the target packet traffic according to the detection mode, and forward the target packet traffic after the detection is passed.

[0055] In the aforementioned traffic forwarding method, when the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic. The method then queries whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection. If unicast reverse path forwarding uRPF detection is configured on the new forwarding interface, the detection mode of the uRPF detection on the new forwarding interface is determined according to the packet type of the target packet traffic. This allows the new forwarding interface to be controlled, and the target packet traffic is forwarded according to the detection mode. In the traffic forwarding method of this application, by generating a new forwarding path for the target packet traffic to replace the original forwarding path and using a corresponding detection mode to forward the target packet traffic, the technical effect of ensuring normal traffic forwarding is achieved.

[0056] In one embodiment, if the original forwarding interface fails or has other traffic scheduling tasks, a new forwarding interface needs to be selected to replace the original forwarding interface for forwarding the target packet traffic. However, since the original forwarding interface on the original forwarding path is the optimal forwarding interface for forwarding the target packet traffic, if the original forwarding interface is detected to have recovered, the future packet traffic corresponding to the target packet traffic needs to be scheduled to the original forwarding path for forwarding.

[0057] Based on the above embodiments, by Figure 2 The steps for forwarding target packet traffic have been broken down and refined. Optional, such as... Figure 2 As shown, the implementation process includes the following:

[0058] S201 controls the new forwarding interface to perform uRPF security detection on the target packet traffic according to the detection mode.

[0059] Specifically, after determining the new forwarding interface in the forwarding path and the detection mode of the new forwarding interface's uRPF detection, the new forwarding interface is controlled to perform uRPF security detection on the target packet traffic according to the detection mode and the preset uRPF security detection standard, so as to determine the security of the target packet traffic.

[0060] S202, if the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0061] Specifically, if the uRPF security check on the target packet traffic passes, the target packet traffic is forwarded through the new forwarding interface of the new forwarding path. If the uRPF security check on the target packet traffic fails, the forwarding process for the target packet traffic is terminated, and the security of the target packet traffic is improved through a preset security mechanism. When the target packet traffic passes the uRPF security check, the forwarding process for the target packet traffic is re-initiated.

[0062] It is understood that in this embodiment, by performing uRPF security detection on the target packet traffic and forwarding the target packet traffic that passes the uRPF security detection, the security of the forwarded target packet traffic is ensured.

[0063] Based on the above embodiments, by Figure 3 A flowchart illustrating the traffic forwarding method is shown. Optional, such as... Figure 3 As shown, the implementation process includes the following:

[0064] S301: When the original forwarding path cannot forward the target packet traffic, the AI ​​controller generates a new forwarding path for the target packet traffic based on the interface configuration, uRPF detection deployment status, etc.

[0065] In S302, the AI ​​controller determines whether the next header of IPv6 is 43 and whether the routing type of the routing extension header is 4, in order to determine whether the target packet type is an SRH encapsulated packet. If not, S303 is executed; if so, S304 is executed.

[0066] Optionally, if the next header of IPv6 is 43 and the routing type of the routing extension header is 4, it can be determined that the packet type of the destination packet traffic is an SRH encapsulated packet; if the next header of IPv6 is not 43 and / or the routing type of the routing extension header is not 4, it can be determined that the packet type of the destination packet traffic is not an SRH encapsulated packet.

[0067] S303, the AI ​​controller sends a strict uRPF inspection command to the new forwarding interface of the new forwarding path to perform strict uRPF inspection on the target packet traffic passing through the new forwarding interface. Execute S305.

[0068] S304, the AI ​​controller sends a loose uRPF detection command to the new forwarding interface of the new forwarding path to perform loose uRPF detection on the target packet traffic passing through the new forwarding interface. Execute S305.

[0069] S305 controls the new forwarding interface and performs uRPF security detection on the target packet traffic according to the detection mode.

[0070] S306 If the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0071] Optionally, if the uRPF security check on the target packet traffic fails, the forwarding process for the target packet traffic is terminated, and the security of the target packet traffic is improved through a preset security mechanism. When the target packet traffic passes the uRPF security check, the forwarding process for the target packet traffic is re-initiated.

[0072] S307 If the original forwarding interface is detected to have returned to normal, the future packet traffic corresponding to the target packet traffic will be scheduled to the original forwarding path for forwarding.

[0073] In the traffic forwarding method of this application, the original forwarding path is replaced by a new forwarding path generated for the target packet traffic, and the target packet traffic is forwarded using a corresponding detection mode, thereby achieving the technical effect of ensuring normal traffic forwarding.

[0074] The specific processes of S301-S307 described above can be found in the description of the above method embodiments. Their implementation principles and technical effects are similar, and will not be repeated here.

[0075] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0076] Based on the same inventive concept, this application also provides a traffic forwarding device for implementing the traffic forwarding method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more traffic forwarding device embodiments provided below can be found in the limitations of the traffic forwarding method described above, and will not be repeated here.

[0077] In one embodiment, by Figure 4 A block diagram of a traffic forwarding device in one embodiment is shown. Figure 4 As shown, a traffic forwarding device 4 is provided, which includes: a generation module 40, a query module 41, a first determination module 42, and a first forwarding module 43, wherein:

[0078] The generation module 40 is used to generate a new forwarding path for the target packet traffic when the original forwarding path of the target packet traffic cannot forward the target packet traffic.

[0079] Query module 41 is used to query whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection;

[0080] The first determining module 42 is used to determine the detection mode of uRPF detection of the new forwarding interface according to the packet type of the target packet traffic if the condition is met.

[0081] The first forwarding module 43 is used to control the new forwarding interface and forward the target packet traffic according to the detection mode.

[0082] The aforementioned traffic forwarding device generates a new forwarding path for the target packet traffic when the original forwarding path cannot forward the target packet traffic. It then checks whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection. If unicast reverse path forwarding uRPF detection is configured on the new forwarding interface, the detection mode of the uRPF detection on the new forwarding interface is determined according to the packet type of the target packet traffic. This allows the new forwarding interface to be controlled, and the target packet traffic is forwarded according to the detection mode. In the traffic forwarding method of this application, by replacing the original forwarding path with a new forwarding path generated for the target packet traffic and employing a corresponding detection mode for forwarding the target packet traffic, the technical effect of ensuring normal traffic forwarding is achieved.

[0083] In one embodiment, the determining module 42 is specifically used for:

[0084] If the target packet traffic is a packet encapsulated with a segment route extension header (SRH), then the uRPF detection mode of the new forwarding interface is determined to be loose uRPF detection; if the target packet traffic is not a packet encapsulated with an SRH, then the uRPF detection mode of the new forwarding interface is determined to be strict uRPF detection.

[0085] In one embodiment, the generation module 40 is specifically used for:

[0086] Based on the Fast Rerouting (FRR) mechanism, a new forwarding path is generated for the target packet traffic.

[0087] In one embodiment, the forwarding module 43 is specifically used for:

[0088] Control the new forwarding interface and perform uRPF security checks on the target packet traffic according to the detection mode; if the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0089] In one embodiment, the device 4 further includes:

[0090] The second determining module is used to determine that the original forwarding path of the target packet traffic cannot forward the target packet traffic if the original forwarding interface in the original forwarding path of the target packet traffic is faulty or the original forwarding interface has other traffic scheduling tasks.

[0091] In one embodiment, the device 4 further includes:

[0092] The second forwarding module is used to schedule the future packet traffic corresponding to the target packet traffic to the original forwarding path for forwarding if the original forwarding interface is detected to have returned to normal.

[0093] Each module in the aforementioned traffic forwarding device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0094] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows. Figure 5 As shown, the computer device includes a processor, memory, network interface, and transceiver connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The transceiver, under the control of the processor, performs operations to receive or send data. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data such as sample data. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements a traffic forwarding method.

[0095] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specifically, the computer device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0096] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0097] If the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic;

[0098] Check if the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection;

[0099] If so, determine the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic;

[0100] Control the new forwarding interface and forward the target packet traffic according to the detection mode.

[0101] In one embodiment, when the processor executes the logic in the computer program that determines the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic, it specifically implements the following steps:

[0102] If the target packet traffic is a packet encapsulated with a segment route extension header (SRH), then the uRPF detection mode of the new forwarding interface is determined to be loose uRPF detection; if the target packet traffic is not a packet encapsulated with an SRH, then the uRPF detection mode of the new forwarding interface is determined to be strict uRPF detection.

[0103] In one embodiment, when the processor executes the logic in the computer program to generate a new forwarding path for the target packet traffic, it specifically implements the following steps:

[0104] Based on the Fast Rerouting (FRR) mechanism, a new forwarding path is generated for the target packet traffic.

[0105] In one embodiment, when the processor executes the logic in the computer program to control the new forwarding interface and forward the target packet traffic according to the detection mode, it specifically implements the following steps:

[0106] Control the new forwarding interface and perform uRPF security checks on the target packet traffic according to the detection mode; if the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0107] In one embodiment, when the processor executes the logic in the computer program, it also specifically implements the following:

[0108] If the original forwarding interface in the original forwarding path of the target packet traffic is faulty or the original forwarding interface has other traffic scheduling tasks, then it is determined that the original forwarding path of the target packet traffic cannot forward the target packet traffic.

[0109] In one embodiment, when the processor executes the logic in the computer program, it further implements the following steps:

[0110] If the original forwarding interface is detected to have returned to normal, the future packet traffic corresponding to the target packet traffic will be scheduled to the original forwarding path for forwarding.

[0111] The principles and specific processes of the computer equipment provided above in implementing the various embodiments can be found in the description of the traffic forwarding method embodiments in the foregoing embodiments, and will not be repeated here.

[0112] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0113] If the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic;

[0114] Check if the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection;

[0115] If so, determine the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic;

[0116] Control the new forwarding interface and forward the target packet traffic according to the detection mode.

[0117] In one embodiment, when the logic in the computer program that determines the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic is executed by the processor, the following steps are specifically implemented:

[0118] If the target packet traffic is a packet encapsulated with a segment route extension header (SRH), then the uRPF detection mode of the new forwarding interface is determined to be loose uRPF detection; if the target packet traffic is not a packet encapsulated with an SRH, then the uRPF detection mode of the new forwarding interface is determined to be strict uRPF detection.

[0119] In one embodiment, when the logic in the computer program that generates a new forwarding path for the target packet traffic is executed by the processor, the following steps are also specifically implemented:

[0120] Based on the Fast Rerouting (FRR) mechanism, a new forwarding path is generated for the target packet traffic.

[0121] In one embodiment, when the logic in the computer program that controls the new forwarding interface and forwards the target packet traffic according to the detection mode is executed by the processor, the following steps are specifically implemented:

[0122] Control the new forwarding interface and perform uRPF security checks on the target packet traffic according to the detection mode; if the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0123] In one embodiment, when the logic in the computer program is executed by the processor, the following is also specifically implemented:

[0124] If the original forwarding interface in the original forwarding path of the target packet traffic is faulty or the original forwarding interface has other traffic scheduling tasks, then it is determined that the original forwarding path of the target packet traffic cannot forward the target packet traffic.

[0125] In one embodiment, when the logic in the computer program is executed by the processor, the following steps are also specifically implemented:

[0126] If the original forwarding interface is detected to have returned to normal, the future packet traffic corresponding to the target packet traffic will be scheduled to the original forwarding path for forwarding.

[0127] The principles and specific processes of the computer-readable storage medium provided above in implementing the various embodiments can be found in the descriptions of the traffic forwarding method embodiments in the foregoing embodiments, and will not be repeated here.

[0128] The principles and specific processes of the computer-readable storage medium provided above in implementing the various embodiments can be found in the descriptions of the target detection method embodiments in the foregoing embodiments, and will not be repeated here.

[0129] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:

[0130] If the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic;

[0131] Check if the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection;

[0132] If so, determine the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic;

[0133] Control the new forwarding interface and forward the target packet traffic according to the detection mode.

[0134] In one embodiment, when the logic in the computer program that determines the detection mode of uRPF detection for the new forwarding interface based on the packet type of the target packet traffic is executed by the processor, the following steps are specifically implemented:

[0135] If the target packet traffic is a packet encapsulated with a segment route extension header (SRH), then the uRPF detection mode of the new forwarding interface is determined to be loose uRPF detection; if the target packet traffic is not a packet encapsulated with an SRH, then the uRPF detection mode of the new forwarding interface is determined to be strict uRPF detection.

[0136] In one embodiment, when the logic in the computer program that generates a new forwarding path for the target packet traffic is executed by the processor, the following steps are also specifically implemented:

[0137] Based on the Fast Rerouting (FRR) mechanism, a new forwarding path is generated for the target packet traffic.

[0138] In one embodiment, when the logic in the computer program that controls the new forwarding interface and forwards the target packet traffic according to the detection mode is executed by the processor, the following steps are specifically implemented:

[0139] Control the new forwarding interface and perform uRPF security checks on the target packet traffic according to the detection mode; if the uRPF security check passes, control the new forwarding interface and forward the target packet traffic based on the new forwarding path.

[0140] In one embodiment, when the logic in the computer program is executed by the processor, the following is also specifically implemented:

[0141] If the original forwarding interface in the original forwarding path of the target packet traffic is faulty or the original forwarding interface has other traffic scheduling tasks, then it is determined that the original forwarding path of the target packet traffic cannot forward the target packet traffic.

[0142] In one embodiment, when the logic in the computer program is executed by the processor, the following steps are also specifically implemented:

[0143] If the original forwarding interface is detected to have returned to normal, the future packet traffic corresponding to the target packet traffic will be scheduled to the original forwarding path for forwarding.

[0144] The principles and specific processes of implementing the computer program products provided above can be found in the descriptions of the target detection method embodiments in the foregoing embodiments, and will not be repeated here.

[0145] It should be noted that the data involved in this application (including but not limited to data during the traffic forwarding process, such as target packet traffic) is all data that has been fully authorized by all parties.

[0146] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0147] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0148] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A traffic forwarding method, characterized in that, include: If the original forwarding path of the target packet traffic cannot forward the target packet traffic, a new forwarding path is generated for the target packet traffic; Check whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection; If so, then if the packet type of the target packet traffic is a packet encapsulated with a segment route extension header SRH, the detection mode of uRPF detection of the new forwarding interface is determined to be loose uRPF detection; or if the packet type of the target packet traffic is not a packet encapsulated with SRH, the detection mode of uRPF detection of the new forwarding interface is determined to be strict uRPF detection. Control the new forwarding interface to perform uRPF security detection on the target packet traffic according to the detection mode; If the uRPF security check passes, the new forwarding interface is controlled to forward the target packet traffic based on the new forwarding path.

2. The method according to claim 1, characterized in that, The step of generating a new forwarding path for the target packet traffic includes: Based on the Fast Rerouting (FRR) mechanism, a new forwarding path is generated for the target packet traffic.

3. The method according to claim 1, characterized in that, The method further includes: If the original forwarding interface in the original forwarding path of the target packet traffic is faulty or the original forwarding interface has other traffic scheduling tasks, then it is determined that the original forwarding path of the target packet traffic cannot forward the target packet traffic.

4. The method according to claim 3, characterized in that, The method further includes: If the original forwarding interface is detected to have returned to normal, the future packet traffic corresponding to the target packet traffic will be scheduled to the original forwarding path for forwarding.

5. A traffic forwarding device, characterized in that, The device includes: The generation module is used to generate a new forwarding path for the target packet traffic when the original forwarding path of the target packet traffic cannot forward the target packet traffic. The query module is used to query whether the new forwarding interface in the new forwarding path is configured with unicast reverse path forwarding uRPF detection; The first determining module is configured to, if the packet type of the target packet traffic is a packet encapsulated with a segment routing extension header (SRH), determine that the detection mode of the uRPF detection of the new forwarding interface is loose uRPF detection; or, if the packet type of the target packet traffic is not a packet encapsulated with an SRH, determine that the detection mode of the uRPF detection of the new forwarding interface is strict uRPF detection. The first forwarding module is used to control the new forwarding interface to perform uRPF security detection on the target packet traffic according to the detection mode; if the uRPF security detection passes, the module controls the new forwarding interface to forward the target packet traffic based on the new forwarding path.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Unicast message processing method and device, computer equipment and readable medium

    CN114124816A

  • Single broadcast reverse path repeating method

    CN1750512A