General calculation method for forwarding rule effective domain
Through the ternary radix tree data structure and recursive algorithm, the problem of calculating the effective domain of forwarding rules under arbitrary wildcard patterns in network devices is solved, and efficient wildcard pattern matching and intersection query are achieved, which is suitable for scenarios such as IoT devices and IPv6 addresses.
Patent Information
- Application Number
- CN202511263490.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Existing technologies make it difficult to efficiently calculate the effective domain of forwarding rules under any wildcard pattern in network devices, and the prefix tree structure cannot adapt to more general wildcard pattern matching requirements.
The ternary radix tree data structure is used to store and forward rules. Through insertion, deletion and query operations, the effective domain calculation under any wildcard mode is realized. The node structure and recursive algorithm of the ternary radix tree are used to perform matching query and intersection set maintenance.
It realizes the rapid calculation of the effective domain of forwarding rules in any wildcard mode, improves the compatibility and efficiency of network devices, and is suitable for more general matching scenarios such as IoT device IDs and IPv6 addresses.
Smart Images

Figure CN120750849A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network device configuration, and in particular to a universal calculation method for a forwarding rule effective domain. Background Art
[0002] In network devices, the effective domain of each forwarding rule refers to the set of data packets that can be matched by the rule during the actual forwarding process.
[0003] The traditional calculation method is: subtract the matching sets of all rules with higher priorities and intersecting with its matching set from the matching set of the rule.
[0004] To speed up this process, existing technologies usually use data structures such as prefix trees to optimize prefix matching. However, such structures are only applicable to prefix-based matching (such as IP prefixes) and are difficult to adapt to more general wildcard pattern matching requirements. Summary of the Invention
[0005] To solve the above technical problems existing in the prior art, the present invention provides a general method for calculating the effective range of forwarding rules. The technical solution includes:
[0006] Step S1: insert all forwarding rules into the ternary radix tree according to the matching;
[0007] Step S2: Query all matches in the ternary radix tree that intersect with the forwarding rule M, and determine the forwarding rule corresponding to each match to form a rule set;
[0008] Among them, the priority of forwarding rule M is P;
[0009] Step S3: Use the matches corresponding to forwarding rule M to subtract the matches corresponding to all forwarding rules with a higher priority than P in the rule set in turn to obtain the valid domain of forwarding rule M;
[0010] The forwarding rules are the rules in the network device that determine whether to receive a data packet and the target forwarding location of the received data packet.
[0011] Compared with the existing technology, the technical solution provided by the present invention is not only suitable for prefix matching, but also can quickly realize the effective domain calculation under any wildcard mode, and has good compatibility; the provided ternary radix tree can efficiently support intersection matching queries under any wildcard mode, and has good compatibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 Schematic diagram of the tree structure for storing the forwarding table in the radix tree.
[0013] Figure 2Schematic diagram of the structure of a ternary radix tree storing five matches in one embodiment of the present invention.
[0014] Figure 3 Schematic diagram of the state of a ternary radix tree after multiple insertions and deletions in one embodiment of the present invention.
[0015] Figure 4 Flowchart of a general calculation method for a rule validity domain in one embodiment of the present invention. DETAILED DESCRIPTION
[0016] Hereinafter, the technical solution provided by the present invention will be further elaborated in combination with embodiments and drawings.
[0017] Example 1:
[0018] In computer networks, data packet forwarding is based on forwarding rule matching, triggering corresponding forwarding actions. The matching field often consists of a binary string and the wildcard character "*," known as a wildcard pattern match. If the wildcard appears only consecutively at the end of the string (for example, 011**), it's called a prefix match; if the wildcard is absent from the matching string, it's called an exact match (for example, 01100); and if the wildcard is followed by specific bits (for example, 01*1*), it's called a general wildcard pattern match. When modeling and analyzing the forwarding behavior of network devices, it's necessary to calculate the effective domain of each rule. A rule's effective domain is defined as the set of packets that actually match the rule on that network device. Therefore, a "match" is actually a character representation of a network address range. A forwarding rule is a set of conditions and actions pre-set in a network device (such as a router, firewall, switch, or load balancer) that determines whether to accept or reject each packet. Furthermore, for received packets, it determines how to process or forward them to a specific forwarding destination.
[0019] As shown in Table 1, the match set for rule 3 is the entire 0.0.0.0 / 1 network segment. However, because rule 1 has a higher priority and overlaps with 0.0.0.0 / 2, the effective domain for rule 3 is 0.0.0.0 / 1 minus 64.0.0.0 / 2. The effective domain for rule 4 is the domain minus the match sets of the first three higher-priority rules.
[0020] Table 1 Example of device forwarding table .
[0021] If the intersection relationship between rules and matches is unknown, the method to calculate the effective range of a rule is to subtract the matches of the rule from the matches of all rules with higher priority than the rule. The time complexity is O(N), where N is the number of rules with higher priority than the forwarding rule. In practical applications, in order to avoid N calculations, such as Figure 1As shown, a data structure such as a prefix tree is often used to optimize the storage of prefix matching. The prefix inclusion property can be used to obtain the intersection rule set by traversing the prefix path.
[0022] However, the prefix tree data structure can only store prefix matches. In reality, many matching scenarios in computer networks require more general wildcard pattern matching, such as IoT device IDs, MAC addresses, and IPv6 addresses. In such scenarios, different bit regions in the ID string / address string have specific meanings. Taking the IoT device ID as an example, its format is usually:
[0023] “[Region: 4 digits][Batch: 4 digits][Type: 4 digits][Serial number: 4 digits]”
[0024] If you need to match a certain type of IoT device, the wildcard pattern match might be:
[0025] “[****][****]
[1010] [****]”.
[0026] To store more general wildcard pattern matches, this first embodiment proposes a ternary radix tree data structure based on an expanded wildcard, for storing wildcard pattern matches and providing insertion, deletion, and query interfaces. Based on this data structure, a general and fast method for calculating the valid domain of forwarding rules is further proposed.
[0027] First, we model wildcard pattern matching. Undoubtedly, the term "match" that appears alone in the following text represents "wildcard pattern matching."
[0028] In this embodiment, a matching common prefix is defined as the string remaining after removing the consecutive * characters at the end. For example, the common prefixes of 011**, 01100, and 01*1* are 011, 01100, and 01*1, respectively. Two matching common common prefixes are consecutive substrings starting from the first digit and existing in both matching common prefixes. For example, the common prefixes of 011** and 01*1* are 0 and 01. The longest of these common common prefixes is the longest common common prefix.
[0029] 1. Ternary radix tree;
[0030] Based on the concept of common prefix, this embodiment provides a ternary radix tree. The node content of the ternary radix tree consists of three fields: segment, match, and intersection set. Each node also has three pointers representing 0, 1, and *, pointing to three nodes, namely, child node 0, child node 1, and child node *. Among them, the segment is a substring in the match, and the intersection set is all matches in the subtree with the node as the root that intersect with the matches stored in the node. Specifically, the segment of the current node is the substring obtained by removing the longest common prefix of the current node and the parent node from the common prefix of the current node, and the segment of the root node is its own common prefix.
[0031] like Figure 2 As shown, the ternary radix tree stores 5 matches, which are stored as 0****, 01***, 010**, 01*1*, and 011** on nodes 1 to 5 respectively. For each match in the ternary radix tree, there is a unique node to store it. The ternary radix tree guarantees: given a node that stores a match, there is a unique path from the root node to the node, and the string formed by the concatenation of the segment contents on all nodes (including the beginning and the end) passed through the path is the common prefix of the node match. For example, from node 1 to node 4, passing through nodes 1, 2, and 4, the segments are 0, 1, and *1 respectively, and the concatenation result 01*1 is the common prefix of the match stored in node 4. Each node in the ternary radix tree stores all matches in the subtree with the node as the root that intersect with the match stored in the node.
[0032] 2. Insertion of ternary radix tree;
[0033] The insertion operation of the ternary radix tree inserts a match into the ternary radix tree. The recursive algorithm flow is described as follows:
[0034] Input: match match, matched common prefix prefix and root node root;
[0035] Output: New root node.
[0036] Step 1: If the root node root is empty, create a new node. Set the match of the new node to match, set the segments to the common prefix prefix, initialize the intersection set to empty, and return the new node. If the root node root is not empty, calculate the longest common prefix lcp of the common prefix prefix and the segments of the root node root.
[0037] Step 2: Perform the following operations based on the length of the longest common prefix (lcp):
[0038] If the length of the longest common prefix lcp is equal to the segment length of the root node root, it means that the match should be inserted into the subtree with the root node root as the root, and the current node is recorded as node newRoot.
[0039] Otherwise, insert a new node before the root node root , set its segment to the longest common prefix lcp , set its match to empty, and inherit the intersection set of the root node root . At the same time, update the root node root 's segment to the remainder after truncating the longest common prefix lcp , and set the root node root as a child of the new node. This new node is denoted as node newRoot .
[0040] Step 3: Add the match match to the intersection set of the node newRoot.
[0041] Step 4: Perform the following operations based on the length of the common prefix prefix and the length of the longest common prefix lcp:
[0042] If the length of the common prefix prefix is equal to the length of the longest common prefix lcp, it means that the node newRoot is the node that stores the match match. The match of the node newRoot is set to match match, and the node newRoot is returned.
[0043] Otherwise, remove the longest common prefix lcp from the common prefix prefix, update the common prefix prefix, and select the child pointer childNode corresponding to the node newRoot according to the first character (0, 1 or *) of the updated common prefix prefix.
[0044] Recursively execute steps 1 to 4, inputting the match, the common prefix, and the child pointer childNode, obtaining a new child pointer newChildNode, and updating the child pointer of the node newRoot. Return the set node newRoot.
[0045] 3. Deletion of ternary radix tree;
[0046] The delete operation of the ternary radix tree deletes a match from the tree. The recursive algorithm flow is described as follows:
[0047] Input: match match, matched common prefix prefix, root node root;
[0048] Output: New root node.
[0049] Step 1: If the root node is empty, return empty directly.
[0050] Step 2: If the segment of the root node root is not a prefix of the common prefix prefix, it means that there is no match match in the ternary radix tree, and the root node root is returned directly.
[0051] Step 3: Delete the match from the intersection set of the root node root.
[0052] Step 4: Perform the following operations based on the length of the common prefix prefix and the segment length of the root node root:
[0053] If the length of the common prefix prefix is equal to the segment length of the root node root, it means that the root node root stores the node that matches match. Set the match of the root node root to be empty, and perform the following operations based on the three child nodes of the root node root:
[0054] All empty: delete the root node root and return empty;
[0055] If only one child node is non-empty: prepend the segment of the root node to the segment of the only child node, delete root, and return the child node;
[0056] If two or three child nodes are not empty, the root node is returned directly.
[0057] Otherwise, it means the target node is in a descendant node. After removing the segment of the root node root from the common prefix prefix, update the common prefix prefix. Select the child pointer childNode corresponding to the root node root according to the first character of the updated common prefix prefix (0, 1, or *);
[0058] Recursively execute steps 1 to 4, inputting the match, the common prefix, and the child pointer childNode, obtaining the child pointer newChildNode, and updating the child pointer of the root node root. Return the root node root.
[0059] 4. Query of ternary radix tree;
[0060] The query operation is used to obtain all matches that intersect with a given match. The recursive algorithm flow is described as follows:
[0061] Input: match match, matched common prefix prefix, root node root;
[0062] Output: A set whose elements are matches.
[0063] Step 1: If the root node root is empty, return an empty set. If not empty, let rootLen be the length of the segment of the root node root.
[0064] Step 2: Compare the rootLen bits before the common prefix prefix with the segment of the root node root: If there is a conflicting bit (one side is 0 and the other side is 1), return an empty set.
[0065] Step 3: If the length of the common prefix prefix is less than or equal to rootLen, return the intersection set of the root node root.
[0066] Step 4: Create the set. If a match exists for the root node, add it to the set. Update the common prefix prefix by removing the segment of the root node from the common prefix prefix, and then match the first character of the updated common prefix prefix.
[0067] Recursively execute steps 1 to 4, input matching match, the common prefix prefix, and the * child node of the root node root, and add the set returned by the algorithm to the set set.
[0068] If the first character of the updated common prefix prefix is 0: recursively execute steps 1 to 4, input the matching match, the common prefix prefix and the 0th child node of the root node root, add the set set0 returned by the algorithm to the set set, and return the set set.
[0069] If the first character of the updated common prefix prefix is 1: recursively execute steps 1 to 4, input matching match, the common prefix prefix and the 1st child node of the root node root, add the set set1 returned by the algorithm to the set set, and return the set set.
[0070] If the first character of the updated common prefix prefix is *: recursively execute steps 1 to 4 twice, inputting parameters with the first character being 0 and 1 respectively, obtaining sets set0 and set1 at the same time, adding them all to set set, and returning set set.
[0071] An example showing the state of a ternary radix tree after multiple insertions and deletions is Figure 3 shown.
[0072] 5. A general and fast calculation method for the effective domain of forwarding rules;
[0073] Based on the ternary radix tree, this embodiment proposes a general calculation method for the effective range of a forwarding rule.
[0074] Before calculation, it is necessary to first use the insert operation to insert all forwarding rules into the tree according to the matching of the forwarding rules, and maintain the one-to-one mapping relationship between the matching and the forwarding rules.
[0075] The general calculation method for calculating a forwarding rule M with a priority of P is described as follows Figure 4 shown.
[0076] Step 1: Use the query operation to query all matching sets in the ternary radix tree that intersect with the forwarding rule M, and obtain the rule set through the mapping relationship (that is, determine the forwarding rules corresponding to all matches in the matching set to form the rule set).
[0077] Step 2: The matches of forwarding rule M are subtracted from the matches of rules with a higher priority than P in the rule set. The forwarding rule M after the subtraction operation is the effective domain of forwarding rule M.
[0078] From the above embodiments and accompanying drawings, it can be seen that the technical solution provided by the present invention overcomes the limitations of the existing technical solutions. It is not only suitable for prefix matching, but also can quickly realize the calculation of valid domains under any wildcard mode, and has good compatibility; the provided ternary radix tree can efficiently support intersection matching queries under any wildcard mode, and has good compatibility.
Claims
1. A general calculation method for the effective range of a forwarding rule, characterized in that: The following steps are involved: Step S1: insert all forwarding rules into the ternary radix tree according to the matching; Step S2: Query all matches in the ternary radix tree that intersect with the forwarding rule M, and determine the forwarding rule corresponding to each match to form a rule set; Among them, the priority of forwarding rule M is P; Step S3: Use the matches corresponding to forwarding rule M to subtract the matches corresponding to all forwarding rules with a higher priority than P in the rule set in turn to obtain the valid domain of forwarding rule M; The forwarding rules are the rules in the network device that determine whether to receive a data packet and the target forwarding location of the received data packet.
2. A general calculation method for the effective range of a forwarding rule according to claim 1, characterized in that: The ternary radix tree comprises: Each node includes three fields: segment, match, and intersection set, and three pointers representing 0, 1, and * respectively; The segment of the current node is the substring obtained by removing the longest common prefix of the current node and its parent node from the common prefix of the current node; the segment of the root node is its own common prefix; The intersection set includes all matches in the subtree with the current node as the root node that intersect with the match in the root node; the three pointers point to the three nodes in a one-to-one correspondence.
3. A general calculation method for the effective range of a forwarding rule according to claim 2, characterized in that: It also includes a method for inserting a match into a ternary radix tree: (1) If the root node of the ternary radix tree is empty, create a new node; set the match of the new node to match match, set the segment to the common prefix prefix of match match, set the intersection set to empty, and return the new node; (2) If the root node root of the ternary cardinality tree is not empty, calculate the longest common prefix lcp between the common prefix prefix and the middle segment of the root node root; If the length of the longest common prefix lcp is equal to the length of the middle segment of the root node root, then the match match is inserted into the subtree whose root node is the root node root, and the current node is recorded as the node newRoot; Add the match match to the intersection set of the node newRoot; If the lengths of the longest common prefix lcp and the common prefix prefix are equal, set the match of the node newRoot to match match and return the node newRoot; Otherwise, remove the longest common prefix lcp from the common prefix prefix and update the common prefix prefix; Select the child node childNode corresponding to the node newRoot according to the first character of the updated common prefix prefix; Take the child node childNode as the new root node and the updated common prefix prefix as the common prefix that matches match, and perform recursive calculations; replace the child node childNode with the obtained child node newChildNode; Returns the node newRoot.
4. A general calculation method for the effective range of a forwarding rule according to claim 2, characterized in that: It also includes a method to remove a match from the ternary radix tree: (1) If the root node is empty, return an empty node; (2) If the segment of the root node root is not a common prefix prefix, return the root node root; Delete the matching match from the intersection set of the root node root; If the length of the common prefix prefix is equal to the length of the middle segment of the root node root, the matching of the root node root is set to empty, including: 1) If the three child nodes of the root node are all empty, delete the root node and return an empty node; 2) If the root node root has only one non-empty child node, prepend the segment of the root node root to the segment of the non-empty child node, delete the root node root, and return the non-empty child node; 3) If the root node root has at least two non-empty child nodes, return the root node root; Otherwise, remove the segment of the root node from the common prefix prefix and update the common prefix prefix; select the child node childNode corresponding to the root node root according to the first character of the updated common prefix prefix; Perform recursive calculation with the child node childNode as the new root node and the updated common prefix prefix as the common prefix that matches match; replace the child node childNode with the obtained child node newChildNode; and return the root node root.
5. A general calculation method for the effective range of a forwarding rule according to claim 2, characterized in that: Also included are methods for querying the ternary radix tree for matches that intersect with the match match: (1) If the root node root is empty, an empty set is returned; (2) If the root node root is not empty, compare the first rootLen bits of the common prefix prefix with the segment of the root node root; where rootLen is the length of the segment in the root node root; If there is a conflicting bit, an empty set is returned; If the length of the common prefix prefix is less than or equal to rootLen, then the intersection set of the root node root is returned; If there is a match for the root node root, add the match for the root node root to the set; Remove the segment of the root node root from the common prefix prefix and update the common prefix prefix; Take the * child node of the root node root as the new root node, use the common prefix prefix as the common prefix that matches match, perform recursive calculation, and add the returned set to the set; If the first character of the common prefix prefix is 0, then take the 0th child node of the root node root as the new root node, take the common prefix prefix as the common prefix to match match, perform recursive calculation, add the returned set to the set, and return the set; If the first character of the common prefix prefix is 0, take the 1st child node of the root node root as the new root node, take the common prefix prefix as the common prefix to match, perform recursive calculation, add the returned set to the set, and return the set; If the first character of the common prefix prefix is *, then recursive calculations are performed on each of the 0th and 1st child nodes of the root node root as new root nodes, and the common prefix prefix as the common prefix to match match. The returned sets are added to the set, and the set set is returned.
Citation Information
Patent Citations
Improved method of adaptive radix tree supporting any Key value
CN113626432A
Routing forwarding method for virtual private network
CN116319555A
Method for IP Longest Prefix Match Using Prefix Length Sorting
US20140086248A1
Tracking Prefixes of Values Associated with Different Rules to Generate Flows
US20150092778A1