Network exit scheduling method and device, electronic equipment and storage medium

By using network egress scheduling rule sets and key-value pair matching technology in the scheduling server, the problem of hardware performance limitations of gateway devices is solved, enabling efficient output of data packets to the external network, simplifying the rule change process, and improving data packet transmission efficiency.

CN121037296APending Publication Date: 2025-11-28BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511209137.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

In the existing technology, the hardware performance of gateway devices is limited, resulting in low packet processing efficiency and a long iptables rule matching process. The efficiency is limited, especially when processing a large number of packets, and rule changes are complex and time-consuming.

Method used

By pre-setting network egress scheduling rule sets in the scheduling server, the transmission path of data packets is determined by key-value pair matching, and a target scheduling label is set for the data packets. This directly instructs the gateway device to transmit data packets through the specified network egress, reducing the data processing volume and rule matching frequency of the gateway device.

Benefits of technology

It improves the efficiency of data packets being output to the external network, reduces the processing load on gateway devices, simplifies the rule change process, and enhances the determination efficiency of data packet transmission and the overall processing speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037296A_ABST
    Figure CN121037296A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network exit scheduling method and device, electronic equipment and a storage medium, and relates to the technical field of data processing. According to the specific implementation scheme, address information of a specified type of a to-be-transmitted target data packet is determined, and target address information is obtained; determining a target value corresponding to the target address information based on a preset network exit scheduling rule set; and setting a target scheduling label included in the target value for the target data packet, so that when the scheduling server transmits the target data packet, data transmission processing is performed on the target data packet based on a transmission path indicated by the target scheduling label. Therefore, according to the scheme of the invention, the efficiency of outputting the data packet to the external network can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a network exit scheduling method and device, electronic equipment and storage medium. BACKGROUND

[0002] A network exit is a data exit through which a data packet leaves a current network domain (such as an enterprise intranet, a data center network, etc.) and enters another network domain (such as the public Internet or a network of another operator). Different network exits are used to transmit data packets, and the network domains into which the data packets enter are different. In any network domain, a scheduling server in the network domain can transmit each data packet to a gateway device, so that the gateway device transmits the data packet to another network domain through a network exit.

[0003] In related technologies, a gateway device usually uses iptables to determine a network exit required by a data packet, so as to transmit the data packet to another network domain through the network exit. Iptables is a commonly used data packet processing tool in a Linux system. Specifically, iptables manages various processing rules for data packets through a rule chain. The processing rules are rules for indicating a network exit to which a data packet needs to be transmitted. The core working mechanism of iptables is that after a data packet enters a network stack, the data packet is sequentially matched according to the order of the processing rules managed by the rule chain of iptables, and the data packet is processed by using the matched rule. The network stack is a software architecture system in a system kernel responsible for processing data packets.

[0004] However, in related technologies, the hardware performance of a gateway device is limited, and the processing efficiency is limited by the hardware performance when a large number of data packets are processed. In addition, when a rule is matched based on iptables, the matching is stopped only after a data packet matches a rule. Therefore, if the position of the rule matched by the data packet is late, the matching process is long. It can be seen that how to improve the efficiency of outputting data packets to an external network is a problem to be solved. SUMMARY

[0005] The purpose of the embodiments of the present application is to provide a network exit scheduling method and device, electronic equipment and storage medium, so as to improve the efficiency of outputting data packets to an external network. The specific technical solutions are as follows:

[0006] In a first aspect of the embodiments of the present application, a network exit scheduling method is first provided, which is applied to a scheduling server, and the method comprises the following steps.

[0007] Determining address information of a specified type of a target data packet to be transmitted to obtain target address information;

[0008] determine a target value corresponding to the target address information based on a preset network egress scheduling rule set, wherein the network egress scheduling rule set comprises at least one key-value pair, in each key-value pair, the key comprises IP information and the value comprises a scheduling tag, the scheduling tag is used to indicate a transmission path of a data packet of a specified type of address information matching the IP information comprised in the key, the transmission path is a path containing a network egress for data packet transmission to a gateway device, and the target value is a value in a target key-value pair, the IP information comprised in the key of the target key-value pair matches the target address information;

[0009] set a target scheduling tag comprised in the target value for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is subjected to data transmission processing based on the transmission path indicated by the target scheduling tag;

[0010] The data transmission processing is configured to enable a gateway device receiving the target data packet to output the target data packet through a network egress in the transmission path indicated by the target scheduling tag.

[0011] In a second aspect of the embodiments of the present application, a network egress scheduling apparatus is also provided, which is applied to a scheduling server, and the method comprises:

[0012] a first determination module configured to determine a specified type of address information of a target data packet to be transmitted to obtain target address information;

[0013] a second determination module configured to determine a target value corresponding to the target address information based on a preset network egress scheduling rule set, wherein the network egress scheduling rule set comprises at least one key-value pair, in each key-value pair, the key comprises IP information and the value comprises a scheduling tag, the scheduling tag is used to indicate a transmission path of a data packet of a specified type of address information matching the IP information comprised in the key, the transmission path is a path containing a network egress for data packet transmission to a gateway device, and the target value is a value in a target key-value pair, the IP information comprised in the key of the target key-value pair matches the target address information;

[0014] a setting module configured to set a target scheduling tag comprised in the target value for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is subjected to data transmission processing based on the transmission path indicated by the target scheduling tag;

[0015] The data transmission processing is configured to enable a gateway device receiving the target data packet to output the target data packet through a network egress in the transmission path indicated by the target scheduling tag.

[0016] In a third aspect of the present application, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus;

[0017] a memory for storing a computer program;

[0018] a processor for executing the program stored on the memory to implement any of the network egress scheduling methods described above.

[0019] In another aspect of the present application, a computer readable storage medium is also provided, which stores a computer program, and the computer program is executed by a processor to implement any of the network egress scheduling methods described above.

[0020] In another aspect of the present application, a computer program product containing instructions, which, when run on a computer, causes the computer to perform any of the network egress scheduling methods described above.

[0021] In the present solution, a set of network egress scheduling rules is preset; for a target data packet to be transmitted, the scheduling server can determine the address information of the specified type of the target data packet to be transmitted, obtain the target address information, and set a target scheduling tag for the target data packet based on the preset set of network egress scheduling rules and the target address information, so that when the scheduling server transmits the target data packet, it performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag, and the data transmission processing is used to make the gateway device receiving the target data packet output the target data packet through the network egress in the transmission path indicated by the target scheduling tag.

[0022] As can be seen, in the present solution, the scheduling server sets the target scheduling tag for the target data packet, so that when the scheduling server transmits the target data packet, it performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag; in this way, the process of determining the network egress is performed by the scheduling server, and the gateway device does not need to perform the process of determining the network egress, thereby reducing the data processing amount of the gateway device, so that the processing efficiency of the gateway device for data packets can be improved; and in the process of determining the network egress, the key-value pair mode is used, which has higher determination efficiency than the rule chain mode without sequential matching. Therefore, through the present solution, the efficiency of outputting data packets to the external network can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiments or prior art description will be briefly introduced below.

[0024] Figure 1 A flowchart of a network egress scheduling method provided in an embodiment of the present application;

[0025] Figure 2 A flowchart of a data transmission process for a target data packet provided in an embodiment of the present application;

[0026] Figure 3 A flowchart of a system architecture corresponding to the network egress scheduling method provided in an embodiment of the present application;

[0027] Figure 4 A structural diagram of a network egress scheduling apparatus provided in an embodiment of the present application;

[0028] Figure 5 A structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0029] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application.

[0030] In the related art, a gateway device usually determines a network egress required by a data packet by using iptables, so as to transmit the data packet to other network domains through the network egress. The iptables is a commonly used data packet processing tool in a Linux system, and specifically, the iptables manages various processing rules about data packets by using rule chains, and the processing rules are rules for indicating a network egress to which the data packet needs to be transmitted. The core working mechanism of the iptables is that, after a data packet enters a network stack, a netfilter module (a kernel firewall framework) of a kernel will sequentially match the processing rules managed by the rule chains of the iptables according to the order of the processing rules, and processes the data packet by using the matched rules. The network stack is a software architecture system in the kernel of the system, which is responsible for processing data packets.

[0031] However, in the related art, the hardware performance of the gateway device is limited, and when a large amount of data packets are processed, the processing efficiency is limited by the hardware performance. In addition, when the rule matching is performed based on the iptables, the matching will be stopped only after the data packet matches the rule, and therefore, once the position of the rule matched by the data packet is late, the matching process will be long, and at most n times of matching are required, where n is the number of rules. It can be seen that how to improve the efficiency of outputting the data packet to the external network is a problem to be solved urgently.

[0032] In addition, iptables is a user mode component, the processing rules managed by the rule chain of iptables are stored in the user space, and the netfilter module is a kernel mode component, when the netfilter module performs rule matching, the rules need to be copied from the user space to the kernel space, thereby involving the switching between the user mode and the kernel mode, and after the rule execution is completed in the kernel, the user mode needs to be switched back again for the record of the log, therefore, when the rule matching is performed based on iptables, the switching between the user mode and the kernel mode exists, and the switching between the user mode and the kernel mode has a time overhead, thereby affecting the efficiency of the output of the data packet to the external network.

[0033] The rule chain of iptables in the prior art is a linear linked list structure, which leads to the fact that a certain rule cannot be directly modified, and all rules (including the rules that are not changed) need to be added again after the old rule chain is emptied, thereby the changing mode of the rules of iptables is relatively complex, and the changing efficiency is low.

[0034] Furthermore, in the prior art, iptables is usually used in combination with an ipset table, one iptables rule usually corresponds to one ipset table, and each ipset table contains the IP address to which the rule corresponding to the table is applicable, therefore, multiple ipset tables need to be maintained when the rule is changed, thereby the rule changing efficiency is low.

[0035] Next, the professional terms involved in the present application are explained:

[0036] Kernel mode and user mode: the operating system (such as Windows, Linux, macOS, etc.) usually divides the permission level of CPU execution code into kernel mode and user mode. The permission level corresponding to the user mode is low; the running of the application program (such as a browser, a text editor, etc.) usually corresponds to the user mode; the kernel mode has a high permission level, and the running of the operating system kernel itself and the device driver corresponds to the kernel mode.

[0037] Kernel: the kernel of the operating system is the most core part of the operating system, and the kernel can directly manage the hardware resources (CPU, memory, disk, network, etc.) of the computer and provide basic services for the application program.

[0038] Kernel space and user space: the physical memory of the target scheduling server is divided into two parts: kernel space: only for the operating system kernel code and data (such as the scheduler, the driver, the interrupt handler, etc.); user space: for all user mode application programs (such as a browser, a text editor, etc.).

[0039] The routing table is a core data table stored in a network device, which is used to determine how the data packet is forwarded from the network device to the target address.

[0040] Firstly, a network egress scheduling method provided by the embodiments of the present disclosure is introduced below. The network egress scheduling method provided by the embodiments of the present application can be applied to a scheduling server, and specifically, the scheduling server is any server.

[0041] The network egress scheduling method provided by the embodiments of the present application can include:

[0042] determining address information of a specified type of the target data packet to be transmitted to obtain target address information;

[0043] determining a target value corresponding to the target address information based on a preset network egress scheduling rule set; wherein the network egress scheduling rule set includes at least one key-value pair, in each key-value pair, the key includes IP information and the value includes a scheduling label, the scheduling label is used to indicate the transmission path of the data packet whose address information of a specified type matches the IP information included in the key, the transmission path is the path containing the network egress for data packet transmission to the gateway device; and the target value is the value in the target key-value pair, the IP information included in the key of the target key pair matches the target address information;

[0044] setting a target scheduling label included in the target value for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is processed based on the transmission path indicated by the target scheduling label for data transmission;

[0045] The data transmission processing is used to make the gateway device receiving the target data packet output the target data packet through the network egress in the transmission path indicated by the target scheduling label.

[0046] In this scheme, a network egress scheduling rule set is preset; for the target data packet to be transmitted, the scheduling server can determine the address information of a specified type of the target data packet to be transmitted to obtain the target address information, and based on the preset network egress scheduling rule set and the target address information, set a target scheduling label for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is processed based on the transmission path indicated by the target scheduling label for data transmission, and the data transmission processing is used to make the gateway device receiving the target data packet output the target data packet through the network egress in the transmission path indicated by the target scheduling label.

[0047] It can be seen that, in the scheme, the target scheduling server sets the target scheduling label for the target data packet, so that the target scheduling server performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling label when transmitting the target data packet. In this way, the process of determining the network exit is performed by the scheduling server, and the gateway device does not need to perform the process of determining the network exit, thereby reducing the data processing amount of the gateway device, so that the processing efficiency of the gateway device for the data packet can be improved. Moreover, in the process of determining the network exit, the key-value pair mode is adopted, which has higher determination efficiency than the rule chain mode without sequential matching. Therefore, the efficiency of outputting the data packet to the external network can be improved by the scheme.

[0048] As shown in Figure 1 The network exit scheduling method provided by the embodiment of the disclosure includes:

[0049] S101, determining the address information of a specified type of the target data packet to be transmitted to obtain target address information.

[0050] The scheduling server can receive the data packet sent by the previous transmission node, perform security detection, exit scheduling and other processing on the data packet, and then send the processed target data packet to the next transmission node.

[0051] The network exit scheduling method of the present application can be executed at any time during the process of receiving the target data packet from the previous transmission node to transmitting the data packet to the next transmission node by the scheduling server.

[0052] The target data packet to be transmitted can be any data packet received by the scheduling server.

[0053] The address information of the specified type can be the source IP (Protocol, Internet Protocol Internet) address and / or target IP address of the target data packet. The source IP address of the target data packet refers to the IP address of the device generating the data packet, and the target IP address can refer to the IP address of the device to which the data packet is to be sent.

[0054] S102, determine a target value corresponding to the target address information based on a preset network egress scheduling rule set; wherein the network egress scheduling rule set comprises at least one key-value pair, in each key-value pair, the key comprises IP information and the value comprises a scheduling tag, the scheduling tag is used to indicate a transmission path of a data packet of a specified type of address information matching the IP information comprised in the key, the transmission path is a path containing a network egress for data packet transmission to a gateway device; and the target value is the value in a target key-value pair, the IP information comprised in the key in the target key-value pair matches the target address information.

[0055] After processing the data packet, the scheduling server can send it to the gateway device as the next node, and the gateway device corresponds to a network egress, and the gateway device can send the data packet to an external network through the network egress. The path of the data packet through the gateway device and the network egress for transmission is the transmission path.

[0056] Different gateway devices can correspond to different network egresses. For example, gateway device 1 corresponds to network egress 1 and network egress 2, and gateway device 2 corresponds to network egress 1 and network egress 3.

[0057] Each transmission path corresponds to a scheduling tag. The scheduling tag can be used to indicate the transmission path of the data packet of the specified type of address information matching the IP information comprised in the key. Further, the scheduling tag can represent the relationship between a simple scheduling tag and a corresponding egress: for example, scheduling tag 0x110 corresponds to network egress 2 provided by a certain network operator, and scheduling tag 0x111 corresponds to network egress 11 provided by a certain network operator. In this application, the network egress can be a network egress provided by a certain network operator or other.

[0058] The value in any key-value pair included in the network egress scheduling rule set comprises a scheduling tag. Thus, the key-value pair can represent the correspondence between IP information and a transmission path.

[0059] The key-value pair can usually be stored in a map data structure, which is a collection of key-value pairs. Its core idea is to establish an association relationship: each unique key is accurately mapped to a value.

[0060] When each key-value pair is matched, it can be matched without following the order of the key-value pairs, thereby effectively improving the matching efficiency.

[0061] Optionally, each key-value pair can be matched in parallel, thereby effectively improving the matching efficiency.

[0062] The map type can be various, and the key-value pair is stored according to the specified map type, and the matching efficiency can be further improved when the key-value matching is performed. Optionally, in an implementation manner, the map type is specifically a hash table type. In this implementation manner, the key can be a source IP and / or destination IP combination pair, and the value is a label mark value. The rule can be mapped as (srcip and / or dstip) -> mark. Specifically, the preset policy is stored in the data table in the form of a key-value pair, such as a key-value pair corresponding to a rule: (10.10.10.10, 202.108.14.60) -> 0x101, which indicates that a data packet with a source IP address of 10.10.10.10 and a destination IP address of 202.108.14.60 is transmitted through a network outlet 1 provided by a network operator according to a network provided by a network operator, and 0x101 is a label of the China Unicom outlet 1. When the data packet comes, the source IP address and the destination IP address of the data packet are obtained to match the corresponding value, if the value is matched, the label included in the value is marked, if the value is not matched, no processing is performed, and the subsequent data packet can be transmitted through any network outlet.

[0063] The hash table is based on a fixed-length array (referred to as a bucket array), and the number of buckets = the length of the array. Each array element is referred to as a "bucket", which is a basic unit for storing data. The storage position of the key-value pair is determined by the index. The calculation method of the index is: hash (key) % bucket number. Key is the key in the key-value pair, hash () is a hash function, and % is a modulo calculation. For example, the length of the array is 4, the key-value pair (k1, v1), hash (k1) % bucket number = 2, and the key-value pair (k1, v1) is stored in the address of the index 2 in the array, for example, ([], [], [k1, v1], []).

[0064] To find the value corresponding to a key key, the index can be calculated first, and then the array address corresponding to the index is directly accessed. The position stored is the key-value pair including the key.

[0065] Specifically, for the target data packet to be transmitted, a hash function can be used to calculate the hash value of the target address information, and the hash value and the number of buckets of the hash table are used to perform a modulo calculation to obtain an index. The array address indicated by the index is the storage address of the target key-value pair including the IP information matched with the target address information. Through the hash table, the target value can be determined usually only by one lookup.

[0066] Optionally, in an implementation, the map type is specifically a Longest Prefix Match (LPM) Trie tree type. In this implementation, the key can be a source IP network segment and / or a destination IP network segment combination pair, and the value is a label mark value. The rule can be mapped as (srcip net and / or dstip net) -> mark. Specifically, the preset rule can be stored in the data table in the form of a key-value pair. For example, a key-value pair corresponding to a rule is (10.10.10.0 / 24, 202.108.14.0 / 24) -> 0x102, which indicates that a data packet with a source IP belonging to the network segment 10.10.10.0 / 24 and a destination IP belonging to the network segment 202.108.14.0 / 24 is transmitted through a network outlet 1 provided by a network operator, and 0x102 is the label of the network outlet 1 provided by the network operator. When the data packet arrives at the scheduling server, the scheduling server can obtain the source IP address and the destination IP address of the data packet to match the corresponding value. If a match is found, the label included in the value is marked. If no match is found, no processing is performed, and the subsequent data packet can be sent through any outlet.

[0067] The LPM Trie uses a binary prefix tree to achieve efficient matching, and includes multiple nodes in the tree. Each node can share a prefix, each node can have branches, and each node can store a rule, that is, a key-value pair. For any combination of source IP and / or destination IP of a data packet, the specific lookup process is as follows: starting from the root node, comparing the bit positions, matching the corresponding node, and returning the value stored in the node.

[0068] If the key in the key-value pair is in the form of a combination of a source IP network segment and / or a destination IP network segment, the prefix can be determined based on the IP network segment. For example, a key-value pair (10.10.0.0 / 16, 20.20.0.0 / 16) -> 0xA indicates that the prefix bit number is 16+16=32. If the first 16 bits of the source IP address and the first 16 bits of the destination IP address of a data packet are the same as the prefix combination corresponding to the key-value pair, the rule represented by the key-value pair is satisfied. When the source IP network segment is empty or the destination IP network segment is empty, that is, the source IP network segment is not limited to be empty or the destination IP network segment is not limited to be empty, the prefix part corresponding to the source IP network segment or the destination IP network segment can be set as a wildcard representing emptiness. Therefore, if the key-value pair represents an empty source IP network segment, the prefix combination is a wildcard + a destination IP prefix. If the key-value pair represents an empty destination IP network segment, the prefix combination is a source IP prefix + a wildcard. In matching, the source IP part in the prefix tree is a wildcard representing that any source IP prefix matches, and the destination IP part is a wildcard representing that any destination IP prefix matches. The wildcard can be set as needed, for example, as 32 bits of 0.

[0069] In the implementation, each node corresponds to a combination of a source IP network segment and / or a destination IP network segment prefix, and in the implementation, the query result can be obtained by querying at most 64 times.

[0070] It can be seen that the key-value pair can be expressed by using a hash table type and a longest prefix matching tree type of data structure, so that the target value corresponding to the target address information of any data packet can be obtained by querying at most 64 times or at least once, and the number of queries and the number of rules are irrelevant.

[0071] The IP address / prefix length is a network segment expression form, the IP address can be a network address (such as 192.168.1.0), or any IP in the network segment (such as 192.168.1.100); the prefix length is represented by “ / n” (n is an integer from 0 to 32), which represents that the first n bits of the IP address are network bits, and the remaining (32-n) bits are host bits.

[0072] S103, set the target scheduling label included in the target value for the target data packet, so that the scheduling server performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling label when transmitting the target data packet.

[0073] The data transmission processing is configured to enable the gateway device receiving the target data packet to output the target data packet through a network exit in the transmission path indicated by the target scheduling label.

[0074] The target data packet provided with the target value can be transmitted to the gateway device of the next node by the scheduling server after the processing of the target data packet in the scheduling server is completed, and at this time, the transmission path corresponding to the target scheduling label can be determined by identifying the target scheduling label included in the target value set for the target data packet, so that the target data packet can be transmitted to the gateway device indicated by the transmission path indicated by the target scheduling label, so that the gateway device outputs the target data packet through a network exit in the transmission path indicated by the target scheduling label.

[0075] The scheme of the embodiment determines a network egress scheduling rule set in advance, the network egress scheduling rule set includes at least one key-value pair, in each key-value pair, the key includes IP information and the value includes a scheduling tag, so that for target address information of a target data packet to be transmitted, a target value can be quickly obtained through key-value matching, the target value is the value in the target key-value pair, and the IP information included in the key in the target key-value pair matches the target address information. The target scheduling tag included in the target value is set for the target data packet, so that when the scheduling server transmits the target data packet, a transmission path indicated by the target scheduling tag is used, so that a gateway device receiving the target data packet outputs the target data packet through a network egress in the transmission path indicated by the target scheduling tag. Moreover, only the target scheduling tag is used to determine the transmission path.

[0076] It can be seen that the scheme of the application can improve the efficiency of determining the transmission path of the data packet, thereby effectively improving the efficiency of outputting the data packet to the external network. Moreover, the scheme of the application is applied to the scheduling server, and the hardware performance of the scheduling server can support processing a large amount of data packets, thereby further improving the efficiency of outputting the data packet to the external network.

[0077] Optionally, the scheduling server performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag, such as Figure 2 As shown, the method includes steps A1-A2.

[0078] In step A1, the scheduling server determines a routing table corresponding to the target scheduling tag according to a preset routing rule; wherein the routing rule is a corresponding relationship between each scheduling tag and a routing table; and the routing table corresponding to each scheduling tag records routing information of a gateway device in the transmission path indicated by the scheduling tag.

[0079] In the scheduling server, a plurality of routing tables can be preset in advance, each routing table is used to indicate a transmission path of a data packet, including a next transmission node and a network egress, and the next transmission node can be the gateway device.

[0080] In the scheme of the embodiment, the routing rule representing the corresponding relationship between the scheduling tag and the routing table is preset. Therefore, when the scheduling server transmits the target data packet, the routing table corresponding to the scheduling tag set on the target data packet can be determined through the identified scheduling tag. Therefore, the target data packet can be transmitted to the gateway device indicated by the routing information through the routing information of the gateway device recorded in the routing table. The routing information can be identification and / or address information of the gateway device.

[0081] Step A2, adding an egress label in the target data packet, and forwarding the target data packet added with the egress label to a gateway device in the transmission path indicated by the scheduling label according to the determined routing table, so that the gateway device receiving the target data packet transmits the target data packet through a network egress represented by the egress label.

[0082] Since different network egresses can correspond to different gateway devices, the gateway device can determine the network egress to be used for transmitting the data packet by identifying the egress label in the data packet.

[0083] The embodiment can add an egress label representing a network egress in the transmission path indicated by the target scheduling label in the target data packet before transmitting the target data packet, so that the gateway device in the transmission path indicated by the target scheduling label transmits the target data packet through the network egress represented by the egress label according to the egress label.

[0084] Optionally, in each key-value pair, the value further includes a traffic label indicating a traffic allocation weight.

[0085] The method further includes:

[0086] The target data packet sets the traffic label in the target value, so that the scheduling server transmits the target data packet according to the traffic allocation weight represented by the traffic label when transmitting the target data packet.

[0087] The data transmission processing of the target data packet based on the transmission path indicated by the target scheduling label includes:

[0088] The data transmission processing of the target data packet based on the transmission path indicated by the target scheduling label according to the allocated transmission bandwidth.

[0089] During the processing, the scheduling server can simultaneously receive a large number of data packets for processing, and different users have different requirements for data transmission. For example, voice call data packets require low latency, and regular file download data packets have high tolerance for latency. Therefore, different data packets can be set with corresponding traffic labels to indicate the traffic allocation weight of the data.

[0090] For example, the traffic allocation weight can be divided into 80% and 20%. The data packet set with the traffic label of 80% can be transmitted using 80% of the bandwidth, and the data packet set with the traffic label of 20% can be transmitted using 20% of the bandwidth.

[0091] Therefore, the scheme of the embodiment can dynamically allocate transmission bandwidth for different data packets, thereby improving the processing quality of the data packets and enhancing user experience.

[0092] Optionally, the determining the target value corresponding to the target address information based on the preset network egress scheduling rule set comprises:

[0093] If the target key value pair containing the target key is determined, the target value is extracted from the target key value pair.

[0094] If the target key value pair containing the target key is determined, the target value is extracted from the target key value pair.

[0095] The IP information included in the key in any key value pair of the network egress scheduling rule set can be an IP address or an IP address segment.

[0096] Specifically, the key value pair can be stored in a hash table and / or a longest prefix matching tree type data structure.

[0097] The determination of whether there is a target key for representing the target address information can be based on the calculation of an index based on the target address information. If the index does not exist in the hash table or the address indicated by the index is empty, it can be determined that there is a target key for representing the target address information. Otherwise, there is no target key.

[0098] When it exists, the target key value pair containing the target key comprises:

[0099] The address indicated by the index in the hash table is determined as the storage address of the target key value pair containing the target key.

[0100] The target value is extracted from the target key value pair.

[0101] The value of the key value pair in the address indicated by the index is extracted as the target value.

[0102] Correspondingly, when it does not exist, the target address information can be subjected to prefix matching processing with the IP address segment in the longest prefix matching Trie tree, and the IP address segment with the most bits matched is determined.

[0103] An IP address can match multiple IP address segments, but each IP address segment in the multiple IP address segments corresponds to a different prefix length. Among the multiple IP address segments obtained through matching, the IP address segment corresponding to the longest prefix is taken as the IP address segment obtained through matching. For example, an IP address can match address segment 192.168.0.0 / 16 and address segment 192.168.1.0 / 24, but the first 16 bits of the IP address are the same as those of the address segment 192.168.0.0 / 16, and the first 24 bits of the IP address are the same as those of the address segment 192.168.0.0 / 16. Therefore, the final matching result is 192.168.0.0 / 24.

[0104] In this embodiment, each network segment in the network egress scheduling rule set can be stored in the structure of a Trie tree. Specifically, the network segment can be stored in the data structure of BPF_MAP_TYPE_LPM_TRIE. Thus, prefix matching can be performed in the manner of a Trie tree (prefix tree). Each node in the Trie tree represents one bit of an IP address, and the branches are child[0]=path of next bit being 0 and child[1]=path of next bit being 1.

[0105] During matching, the IP address to be matched can be converted into binary, and bit matching is started from the root node. When a certain bit node does not have a branch matching the bit or each bit of the IP address is completely matched, the matching is stopped, the matching result is obtained, and the node at which the matching is completed is the node corresponding to the IP address segment with the most bits. The value in the key-value pair stored in the node can be taken as the target value.

[0106] If the longest prefix matching Trie tree does not match the corresponding IP address segment, no subsequent network egress scheduling processing can be performed on the data packet, and the data packet can be transmitted from any network egress.

[0107] Optionally, the preset network egress scheduling rule set is stored in the kernel space of the scheduling server, and the network egress scheduling rule set stored in the kernel space is updated in response to a rule set update condition.

[0108] The method is specifically applied to a functional module deployed in the kernel of the scheduling server.

[0109] The user can configure a management component of the functional module in the user space. Thus, in response to a rule set update condition, the interface of the management component can be called to update the network egress scheduling rule set stored in the user kernel space.

[0110] Specifically, the function module can be an eBPF (a kernel technology) bytecode program. Although eBPF is a kernel technology, its complete ecosystem includes components deployed in user space, which can be responsible for compiling, loading, managing, and monitoring eBPF bytecode programs. The management component is one or more components deployed in user space for compiling, loading, managing, and monitoring eBPF bytecode programs.

[0111] Through the management component, the bytecode program can be deployed in the kernel of the system. At the hardware level, the bytecode program can act on the network card of the scheduling server. At the software level, the bytecode program can be deployed at the Hook point of the kernel. The Hook point is a specific code location reserved by the system (kernel, library, framework, etc.). These locations usually correspond to key events or key points of the execution flow (such as before / after function call, when event triggers, during data transmission, etc.). When the program executes to these locations, it checks whether there are externally registered callback functions or processing logic, and if so, executes them.

[0112] The bytecode program can be deployed at the XDP (eXpress Data Path, a high-performance packet processing framework implemented in the Linux kernel), TC ingress (tc, which stands for Traffic Control, is a network traffic control and management tool) module, which is a powerful network traffic control and management tool), or TC egress hook point. Among them, XDP is located before the data packet enters the protocol stack, that is, at the stage when the network card driver just receives the data packet. TC ingress is located before the data packet enters the protocol stack (after XDP), and TC egress is located before the data packet is sent from the protocol stack and leaves the current device.

[0113] In specific implementation scenarios, due to differences in different scheduling server hardware and software, for different scheduling servers, the Hook point can be selected to deploy the bytecode program according to the actual situation.

[0114] The data structure of the network exit scheduling rule set can be a Map data structure. For example, the Map data structure includes ip_mark_map, src_ip_map, and dst_ip_map. ip_mark_map: stores mark values, the key is {src_ip, dst_ip} combination, and the value is mark; src_ip_map: stores the source IP network segment, which is of type BPF_MAP_TYPE_LPM_TRIE; and dst_ip_map: stores the destination IP network segment, which is of type BPF_MAP_TYPE_LPM_TRIE.

[0115] Specifically, as the key of the {src_ip, dst_ip} combination, the src_ip and the dst_ip can be an IP segment or a specific IP address. When the IP address of the data packet to be processed does not exist in the network egress scheduling rule set, prefix matching can be performed based on the src_ip_map and / or the dst_ip_map to determine the IP segment corresponding to the IP address of the data packet, thereby determining the corresponding value. The specific implementation is described in the foregoing embodiments, and thus will not be described here.

[0116] Since the network egress scheduling rule set of the application is stored in the kernel space, and the network egress scheduling method is executed by the functional module deployed in the kernel of the scheduling server, the kernel state can be maintained during the implementation of the network egress scheduling method, and switching to the user state is not involved, thereby reducing the time consumption of switching between the user state and the kernel state, and effectively improving the efficiency of outputting the data packet to the external network.

[0117] In addition, the method for updating the network egress scheduling rule set stored in the user kernel space is simple and convenient, and the rule updating efficiency is high.

[0118] The rule set updating condition can be various. In an optional implementation, the user can issue a rule set updating instruction to the control end. The rule set updating instruction can include source IP data and / or destination IP data, and a network egress. The source IP data can be a source IP address or a source IP address segment, and the destination IP data can be a destination IP address or a destination IP address segment.

[0119] The controller can generate a control policy based on the source IP data and / or the destination IP data, and the network egress. The control policy includes the corresponding relationship between the source IP data and / or the destination IP data and the scheduling label of the network egress.

[0120] For example, the controller can generate a control policy policy based on the source IP address 192.168.1.2 included in the rule set updating instruction and the network egress 1.

[0121]

[0122]

[0123] The control policy represents that the source IP is 192.168.1.2, the destination address is any address (0.0.0.0), the scheduling label is 0x111, and the protocol is tcp (Transmission Control Protocol).

[0124] The controller issues a control strategy by calling an interface of a management component of the function module, so that the management component updates the network egress scheduling rule set according to the control strategy.

[0125] Optionally, in an implementation, in response to a rule set update condition, the process of updating the network egress scheduling rule set stored in the kernel space includes:

[0126] The scheduling server determines a scheduling label for indicating a default transmission path, obtains a first scheduling label, and determines a scheduling label for indicating a transmission path containing the network egress, obtains a second scheduling label, in response to receiving data sent by the control end and indicating that a state of any network egress changes, and replaces the second scheduling label contained in the value of the network egress scheduling rule set stored in the user space with the first scheduling label.

[0127] In the present application, the control end can monitor each network egress in real time, and if a network egress fails, in order to ensure that data packets can be transmitted, the data packets that originally need to be transmitted through the failed network egress can be transmitted through any default network egress.

[0128] For example, the scheduling label of the transmission path containing the failed network egress is A, the scheduling label of the default transmission path is B, and the values of key-value pair 1, key-value pair 2 and key-value pair 3 in the network egress scheduling rule set contain A, so A contained in the values of key-value pair 1, key-value pair 2 and key-value pair 3 is replaced with B.

[0129] Therefore, through the scheme of the present embodiment, the influence of the change of the network egress on the transmission of data packets can be reduced.

[0130] Figure 3 A schematic diagram of a system architecture corresponding to the egress scheduling method is shown in FIG. 1. Figure 3 As shown in FIG. 1, the system architecture includes a control plane and a forwarding plane. The control plane includes a controller, and the forwarding plane includes an access layer, a control layer and a forwarding layer.

[0131] The controller can be used for system construction, policy management, operation and maintenance management, monitoring and warning, and an API (Application Programming Interface) interface. Specifically, the API interface is a function module of the controller, which is used to implement deployment of bytecode and change of rules by using an API interface provided by an ebpf-mark program.

[0132] The access layer includes an IDC (Internet Data Center), which is a physical facility with power, network bandwidth, and computer room environment, used to deploy servers and other resources, and is a place for enterprises or institutions to host business systems and process data traffic. Figure 3 The IDC can have multiple IDCs, such as IDC1 and IDC2 in the embodiment, and each IDC has the same function.

[0133] The controller can set the transmission strategy of the IDC gateway, so that the data packets transmitted by the IDC to the IDC gateway are transmitted by the IDC gateway to the server.

[0134] The access layer can route the data packets transmitted by the IDC to the server by default.

[0135] Figure 3 The server in the embodiment corresponds to the scheduling server in the above embodiment, and the ebpf-mark program is deployed on the server.

[0136] The control layer and the forwarding layer are connected through a gateway, which is a gateway device in the transmission path in the above embodiment.

[0137] The routing protocol between the IDC and the IDC gateway, between the IDC gateway and the server, between the server and the gateway device, and between the gateway device and the network exit is a BGP (Border Gateway Protocol) protocol.

[0138] Figure 3 In the embodiment, GRE (Generic Routing Encapsulation) is an important network layer tunneling protocol, and its core function is to implement data encapsulation transmission in different network protocols or different network environments.

[0139] IDC gateway and server can have one or more, when there are multiple IDC gateway and server, data packets can be sent to any server through any IDC gateway for processing.

[0140] The server and gateway device transmit data packets through MPLS (Multiprotocol Label Switching). MPLS is a technology used for efficient data transmission in communication networks, the core of which is to replace the traditional IP network based on "IP address" hop-by-hop routing decision with "label" to realize fast forwarding of data. When data packets enter the MPLS network, they are assigned labels, and intermediate routing devices only forward according to the label table, without the need to parse IP addresses. In the above embodiment, the egress label is the label of MPLS, so when the target data packet with the added egress label is forwarded to the gateway device in the transmission path indicated by the scheduling label, the gateway device can directly obtain the network egress based on the egress label, and transmit the data packet through the found network egress (such as Figure 3 China Telecom egress 1, China Unicom egress 1 and other egresses).

[0141] The control layer can be used for destination IP policy routing and MPLS path egress selection.

[0142] The controller can pre-set IP rules and corresponding routing tables, the IP rules are used to indicate the correspondence between the scheduling label and the routing table, and the routing table is used to indicate the next transmission device of the data packet.

[0143] Figure 3 The middle SNAT cluster is a technical architecture for realizing the SNAT (Source Network Address Translation) function through multiple devices in cooperation.

[0144] The scheme of the embodiment has higher execution efficiency and kernel-level flexibility, can complete complex packet policy judgment with lower overhead, reduces the switching between the kernel mode and the user mode, and improves the overall system performance. Compared with the policy configuration of iptables+ipset in the prior art, the scheme of the embodiment can greatly simplify the policy maintenance and deployment process, thereby reducing the configuration requirements for network operation and maintenance personnel, reducing human configuration errors, and improving system stability and security. The scheme of the embodiment can realize multi-combination scheduling capability based on source IP and destination IP, enhance the automation policy management capability, and support more refined and dynamic access control policies, for example, can flexibly specify the link or operator channel that some source accesses some destination address, thereby improving resource utilization and access efficiency. The scheme of the embodiment can improve the packet forwarding efficiency and solve the performance bottleneck of the control end. The scheme of the embodiment can reduce the problem of performance degradation caused by too many rules, and still maintain high-performance forwarding capability in a high-concurrency cloud host environment, thereby improving the overall service quality.

[0145] In addition, in the scheme of the embodiment, the eBPF program is specifically used to set the scheduling label for the packet. Because the eBPF program has programmability and kernel mounting characteristics, combined with the user space control program, the automatic loading, updating, and unloading of policy logic can be realized, the management complexity is reduced, and the automation degree of the system is improved. The dependence on traditional physical outlets can be eliminated, and more flexible outlet scheduling can be realized. The business system is no longer bound to the operator outlet resources of a specific physical room, and can flexibly schedule different public network outlets according to the policy, thereby enhancing the network flexibility and expansion capability.

[0146] Corresponding to the above network outlet scheduling method, the application also provides a network outlet scheduling device applied to a scheduling server, as shown in Figure 4 The device includes:

[0147] A first determination module 401 is configured to determine the specified type of address information of a target data packet to be transmitted, and obtain target address information.

[0148] A second determination module 402 is configured to determine a target value corresponding to the target address information based on a preset network outlet scheduling rule set. The network outlet scheduling rule set includes at least one key-value pair. In each key-value pair, the key includes IP information and the value includes a scheduling label. The scheduling label is used to indicate the transmission path of a data packet whose specified type of address information matches the IP information included in the key. The transmission path is a path for transmitting a data packet to a gateway device and containing a network outlet. The target value is the value in the target key-value pair. The IP information included in the key of the target key-value pair matches the target address information.

[0149] The setting module 403 is configured to set a target scheduling label included in the target value for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is subjected to data transmission processing based on a transmission path indicated by the target scheduling label.

[0150] The data transmission processing is configured to enable a gateway device receiving the target data packet to output the target data packet through a network exit in the transmission path indicated by the target scheduling label.

[0151] In this solution, a set of network exit scheduling rules is preset. The scheduling server can determine address information of a specified type of the target data packet to be transmitted, obtain target address information, and set a target scheduling label for the target data packet based on the set of preset network exit scheduling rules and the target address information, so that when the scheduling server transmits the target data packet, the target data packet is subjected to data transmission processing based on a transmission path indicated by the target scheduling label. The data transmission processing is configured to enable a gateway device receiving the target data packet to output the target data packet through a network exit in the transmission path indicated by the target scheduling label.

[0152] As can be seen, in this solution, the scheduling server sets a target scheduling label for the target data packet, so that when the scheduling server transmits the target data packet, the target data packet is subjected to data transmission processing based on a transmission path indicated by the target scheduling label. In this way, the process of determining a network exit is performed by the scheduling server, and the gateway device does not need to perform the process of determining a network exit, thereby reducing the data processing amount of the gateway device and improving the processing efficiency of the gateway device for data packets. In addition, in the process of determining a network exit, the key-value pair mode is used, which has a higher determination efficiency than the rule chain mode, because it does not need to be matched in sequence according to the order. Therefore, this solution can improve the efficiency of outputting data packets to an external network.

[0153] Optionally, the scheduling server subjects the target data packet to data transmission processing based on a transmission path indicated by the target scheduling label, including:

[0154] The scheduling server determines a routing table corresponding to the target scheduling label according to a preset routing rule. The routing rule is a correspondence between each scheduling label and a routing table. The routing table corresponding to each scheduling label records routing information of a gateway device in a transmission path indicated by the scheduling label.

[0155] add an egress label to the target data packet, and forward the target data packet with the added egress label to a gateway device in a transmission path indicated by the scheduling label according to the determined routing table, so that the gateway device receiving the target data packet transmits the target data packet through a network egress represented by the egress label.

[0156] Optionally, in each key-value pair, the value further includes a traffic label used to indicate a traffic distribution weight.

[0157] The apparatus further includes:

[0158] The allocation module is configured to set the traffic label in the target value for the target data packet, so that the scheduling server transmits the target data packet according to a traffic distribution weight represented by the traffic label when transmitting the target data packet.

[0159] The data transmission processing of the target data packet based on the transmission path indicated by the target scheduling label includes:

[0160] The data transmission processing of the target data packet based on the transmission path indicated by the target scheduling label and according to the allocated transmission bandwidth.

[0161] Optionally, the second determination module includes:

[0162] The extraction unit is configured to determine a target key-value pair containing the target key, and extract a target value from the target key-value pair, if the target key used to represent the target address information exists in the network egress scheduling rule set.

[0163] The matching unit is configured to perform prefix matching processing on the target address information and an IP address segment if at least one key used to represent the IP address segment exists in the network egress scheduling rule set, determine an IP address segment with the largest number of bits obtained through the matching processing, and determine a key-value pair to which a key representing the determined IP address segment belongs as a target key-value pair, and extract a target value from the target key-value pair.

[0164] Optionally, the preset network egress scheduling rule set is stored in a kernel space of the scheduling server, and the network egress scheduling rule set stored in the kernel space is updated in response to a rule set update condition.

[0165] The method is specifically applied to a functional module deployed in a kernel of the scheduling server.

[0166] Optionally, in response to the rule set updating condition, the process of updating the network egress scheduling rule set stored in the user space comprises:

[0167] The scheduling server, in response to receiving the data sent by the control end and representing that the state of any network egress has changed, determines a scheduling label for indicating a default transmission path, obtaining a first scheduling label, and determines a scheduling label for indicating a transmission path containing the network egress, obtaining a second scheduling label; and replaces the second scheduling label contained in the value of the network egress scheduling rule set stored in the user space with the first scheduling label.

[0168] The embodiments of the present application also provide an electronic device, such as Figure 5 As shown in the figure, the electronic device comprises a processor 501, a communication interface 502, a memory 503 and a communication bus 504, wherein the processor 501, the communication interface 502 and the memory 503 complete mutual communication through the communication bus 504,

[0169] The memory 503 is used for storing a computer program.

[0170] The processor 501 is used for executing the program stored in the memory 503, and realizes the network egress scheduling method mentioned above.

[0171] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0172] The communication interface is used for communication between the terminal and other devices.

[0173] The memory can comprise a Random Access Memory (RAM) and can also comprise a non-volatile memory, for example at least one disk memory. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.

[0174] The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; or can be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.

[0175] In yet another embodiment provided in the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the network egress scheduling method in any of the above embodiments.

[0176] In yet another embodiment provided in the present application, a computer program product containing instructions is provided, and the computer program product, when executed on a computer, causes the computer to perform the network egress scheduling method in any of the above embodiments.

[0177] In the above embodiments, the implementation can be achieved by software, hardware, firmware or any combination thereof, entirely or partially. When implemented by software, the implementation can be in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are entirely or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0178] It is to be noted that, in the present document, relational terms such as first and second and the like can be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element.

[0179] Each of the embodiments in the present specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments.

[0180] The above only describes the preferred embodiments of the present application and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement and the like made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A network egress scheduling method, characterized in that, Applied to a scheduling server, the method includes: Determine the address information of the specified type of the target data packet to be transmitted, and obtain the target address information; Based on a preset network egress scheduling rule set, a target value corresponding to the target address information is determined; wherein, the network egress scheduling rule set includes at least one key-value pair, in each key-value pair, the key includes IP information and the value includes a scheduling tag, the scheduling tag is used to indicate: the transmission path of a data packet whose address information of a specified type matches the IP information included in the key, the transmission path being a path for data packet transmission to a gateway device that includes a network egress; the target value is the value in the target key-value pair, where the IP information included in the key of the target key pair matches the target address information; Set a target scheduling tag including the target value for the target data packet, so that when the scheduling server transmits the target data packet, it performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag; The data transmission processing is configured to enable the gateway device that receives the target data packet to output the target data packet by indicating the network exit in the transmission path through the target scheduling tag.

2. The method according to claim 1, characterized in that, The scheduling server performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag, including: The scheduling server determines the routing table corresponding to the target scheduling label according to the preset routing rules; wherein, the routing rules are the correspondence between each scheduling label and the routing table; the routing table corresponding to each scheduling label records the routing information of the gateway device in the transmission path indicated by the scheduling label. An exit tag is added to the target data packet, and the target data packet with the exit tag is forwarded to the gateway device in the transmission path indicated by the scheduling tag according to the determined routing table, so that the gateway device receiving the target data packet will transmit the target data packet through the network exit represented by the exit tag; wherein, the exit tag is used to represent: the network exit in the transmission path indicated by the target scheduling tag.

3. The method according to claim 1, characterized in that, Each key-value pair also includes a traffic label that indicates the traffic allocation weight; The method further includes: The target data packet is set with a traffic label in the target value so that when the scheduling server transmits the target data packet, it allocates transmission bandwidth according to the traffic allocation weight represented by the traffic label. The data transmission processing of the target data packet based on the transmission path indicated by the target scheduling tag includes: Based on the transmission path indicated by the target scheduling tag, and according to the allocated transmission bandwidth, the target data packet is processed for data transmission.

4. The method according to any one of claims 1-3, characterized in that, The determination of the target value corresponding to the target address information based on the preset network egress scheduling rule set includes: If there is a target key containing the target address information in the network egress scheduling rule set, determine the target key-value pair containing the target key, and extract the target value from the target key-value pair; If it does not exist, and the network egress scheduling rule set includes at least one key representing an IP address segment, the target address information is prefix matched with the IP address segment to determine the IP address segment with the most bits obtained from the match. The key-value pair to which the key representing the determined IP address segment belongs is determined as the target key-value pair, and the target value is extracted from the target key-value pair.

5. The method according to claim 1, characterized in that, The preset network egress scheduling rule set is stored in the kernel space of the scheduling server, and in response to the rule set update condition, the network egress scheduling rule set stored in the kernel space is updated. Furthermore, the method is specifically applied to functional modules of the kernel deployed on the scheduling server.

6. The method according to claim 5, characterized in that, The process of updating the network egress scheduling rule set stored in the kernel space in response to rule set update conditions includes: In response to receiving data from the control terminal indicating a change in the status of any network exit, the scheduling server determines a scheduling label for indicating a default transmission path, obtaining a first scheduling label, and determines a scheduling label for indicating a transmission path containing that network exit, obtaining a second scheduling label; and replaces the second scheduling label contained in the value stored in the network exit scheduling rule set in the user space with the first scheduling label.

7. A network egress scheduling device, characterized in that, The device, applied to a scheduling server, includes: The first determining module is used to determine the address information of a specified type of the target data packet to be transmitted, and obtain the target address information; The second determining module is used to determine the target value corresponding to the target address information based on a preset network egress scheduling rule set; wherein, the network egress scheduling rule set includes at least one key-value pair, in each key-value pair, the key includes IP information and the value includes a scheduling tag, the scheduling tag is used to indicate: the transmission path of a data packet whose address information of a specified type matches the IP information included in the key, the transmission path is a path for data packet transmission to a gateway device and includes a network egress; the target value is the value in the target key-value pair, where the IP information included in the key of the target key pair matches the target address information; The setting module is used to set the target scheduling tag included in the target value for the target data packet, so that when the scheduling server transmits the target data packet, it performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag; The data transmission processing is configured to enable the gateway device that receives the target data packet to output the target data packet by indicating the network exit in the transmission path through the target scheduling tag.

8. The apparatus according to claim 7, characterized in that, The scheduling server performs data transmission processing on the target data packet based on the transmission path indicated by the target scheduling tag, including: The scheduling server determines the routing table corresponding to the target scheduling label according to the preset routing rules; wherein, the routing rules are the correspondence between each scheduling label and the routing table; the routing table corresponding to each scheduling label records the routing information of the gateway device in the transmission path indicated by the scheduling label. An exit tag is added to the target data packet, and the target data packet with the exit tag is forwarded to the gateway device in the transmission path indicated by the scheduling tag according to the determined routing table, so that the gateway device receiving the target data packet will transmit the target data packet through the network exit represented by the exit tag; wherein, the exit tag is used to represent: the network exit in the transmission path indicated by the target scheduling tag.

9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the method of any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.