A message forwarding method, device and related equipment

By dynamically generating and distributing END-DT SIDs in the SRv6 L3VPN service, the large workload and automatic adjustment issues caused by static configuration are resolved, achieving efficient and scalable service function chain forwarding.

CN122316976APending Publication Date: 2026-06-30NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NEW H3C TECH CO LTD
Filing Date
2026-06-03
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

In SRv6-based L3VPN services, the configuration of static END-DT4 requires manual binding, which results in a large workload and the inability to automatically adjust according to topology changes, making it impossible to achieve an efficient and scalable service function chain.

Method used

By establishing a neighbor relationship with a preset routing protocol between the service chain forwarding node (SFF) and the tail node, pre-configuring the cache list, and dynamically generating and distributing the mapping relationship when the EEND-DT of the VPN instance changes, the forwarding table entries are automatically updated, thus realizing the automatic generation and distribution of dynamic END-DT SIDs.

Benefits of technology

It reduces configuration workload, supports automatic adaptation when new PEs are added or VPNs are changed, and SIDs can be dynamically adjusted according to topology or policies, simplifying the network expansion process and reducing forwarding interruption time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122316976A_ABST
    Figure CN122316976A_ABST
Patent Text Reader

Abstract

This application relates to the field of network communication technology, and in particular to a message forwarding method, apparatus, and related equipment. The method is applied to a service chain forwarding node (SFF), where the SFF and tail node have established a neighbor relationship based on a preset routing protocol. The last SID in at least one pre-configured Cache List on the SFF is the identifier of the VPN instance corresponding to that Cache List. The method includes: receiving a mapping relationship between the identifier of a target VPN instance and the END-DT of the target VPN instance published by the tail node; and generating a target forwarding table entry based on the mapping relationship between the identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, wherein the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to a message forwarding method, apparatus and related equipment. Background Technology

[0002] In building L3VPN (Layer 3 Virtual Private Network) services based on static proxies using SRv6 (Segment Routing over IPv6), we typically focus on how to implement efficient and scalable Service Function Chaining (SFC) within the network.

[0003] Taking a typical IPv4 L3VPN over SRV6 SFC static proxy network as an example, since the SF (Service Function, application service node) cannot recognize SRv6 packets, the SFF (Service Function Forwarder, service chain forwarding node) needs to decapsulate the SRv6 packets and forward the original data packets of the user network to the SF for processing. After processing the original packets, the SF forwards them back to the SFF node, which needs to recapsulate the SRv6 header for the processed service packets according to the manually configured SID list. This requires the VPN instance of the tail node to specify a static END-DT4 (a local SID (Segment Identifier) ​​in SRv6). The disadvantages of static END-DT4 are obvious: each VPN instance or route needs to be manually bound to a SID, which is labor-intensive. When adding a new node or VPN, SID planning needs to be coordinated across the entire network, and it cannot automatically adjust SID allocation according to topology changes. Summary of the Invention

[0004] This application provides a message forwarding method, apparatus, and related equipment.

[0005] Firstly, this application provides a message forwarding method applied to a service chain forwarding node (SFF), wherein the SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol, and the SFF is pre-configured with at least one cache list, wherein the last SID in a cache list is the VPN identifier of the VPN instance corresponding to that cache list; the method includes: The tail node receives the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance published by the preset routing protocol. When the tail node detects a change in the EEND-DT of any VPN instance, it sends the mapping relationship between the VPN instance and the EEND-DT of the target VPN instance to the SFF through the preset routing protocol. Based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, a target forwarding table entry is generated, wherein the last hop in the SRH header of the target forwarding table entry is the EEND-DT of the target VPN instance.

[0006] Optionally, the method further includes: Receive the original packets belonging to the target VPN instance returned by the application service node SF; Based on the SRH header in the target forwarding table entry, the original message is encapsulated in SRV6 to obtain the encapsulated SRV6 message. The encapsulated SRV6 message is sent to the tail node.

[0007] Optionally, the step of generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance and the Cache List corresponding to the target VPN instance includes: Based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the EEND-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

[0008] Optionally, the preset routing protocol is Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP).

[0009] Secondly, this application provides a message forwarding method applied to the tail node of a service chain path, wherein the tail node and the service chain forwarding node SFF have established a neighbor relationship based on a preset routing protocol, and the SFF is pre-configured with at least one Cache List, wherein the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List; the method includes: Monitor whether the EEND-DT of each VPN instance has changed; When a change in the EEND-DT of any VPN instance is detected, the SFF is sent a mapping relationship between the VPN instance and its EEND-DT via the preset routing protocol. This allows the SFF to generate a target forwarding table entry based on the mapping relationship between the VPN identifier and the EEND-DT of the target VPN instance published by the tail node via the preset routing protocol. The last hop in the SRH header of the target forwarding table entry is the EEND-DT of the target VPN instance.

[0010] Optionally, the steps to detect changes in the EEND-DT of a VPN instance include: When a new VPN instance is detected being created, and an EEND-DT is dynamically allocated to the new VPN instance, it is determined that the EEND-DT of the VPN instance has changed; or, When a change in the SRV6 Locator is detected, and EEND-DT is dynamically reassigned to each VPN instance, it is determined that the EEND-DT of the VPN instance has changed.

[0011] Optionally, if the preset routing protocol is BGP, the step of sending the mapping relationship between the VPN instance and the EEND-DT of the VPN instance to the SFF through the preset routing protocol includes: The EEND-DT of the VPN instance is carried through the BGP extended field; If the preset routing protocol is IGP, the step of sending the mapping relationship between the VPN instance and the EEND-DT of the VPN instance to the SFF through the preset routing protocol includes: The EEND-DT of this VPN instance is carried via the IGP extended TLV.

[0012] Thirdly, this application provides a message forwarding device applied to a service chain forwarding node (SFF), wherein the SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol, and the SFF is pre-configured with at least one cache list, wherein the last SID in a cache list is the VPN identifier of the VPN instance corresponding to that cache list; the device includes: The first receiving unit is used to receive the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance published by the tail node through the preset routing protocol, wherein when the tail node detects that the EEND-DT of any VPN instance has changed, it sends the mapping relationship between the VPN instance and the EEND-DT of the VPN instance to the SFF through the preset routing protocol. The generation unit is used to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, wherein the last hop in the SRH header of the target forwarding table entry is the EEND-DT of the target VPN instance.

[0013] Optionally, the device further includes: The second receiving unit is used to receive the original packets belonging to the target VPN instance returned by the application service node SF. An encapsulation unit is used to encapsulate the original message with SRV6 based on the SRH header in the target forwarding table entry to obtain an encapsulated SRV6 message. The sending unit is used to send the encapsulated SRV6 message to the tail node.

[0014] Optionally, when generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, the generation unit is specifically used for: Based on the mapping relationship between the VPN identifier of the target VPN instance and the EEND-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the EEND-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

[0015] Optionally, the preset routing protocol is Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP).

[0016] Fourthly, this application provides a message forwarding device applied to the tail node of a service chain path. The tail node and the service chain forwarding node (SFF) have a neighbor relationship established with a preset routing protocol. The SFF is pre-configured with at least one cache list, wherein the last SID in a cache list is the VPN identifier of the VPN instance corresponding to that cache list. The device includes: The monitoring unit is used to monitor whether the EEND-DT of each VPN instance has changed; When the monitoring unit detects a change in the EEND-DT of any VPN instance, the sending unit is configured to send a mapping relationship between the VPN instance and its EEND-DT to the SFF via the preset routing protocol. This enables the SFF to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and its EEND-DT and the Cache List corresponding to the target VPN instance when it receives the mapping relationship between the VPN identifier of the target VPN instance and its EEND-DT published by the tail node via the preset routing protocol. The last hop in the SRH header of the target forwarding table entry is the EEND-DT of the target VPN instance.

[0017] Optionally, when a change in the EEND-DT of a VPN instance is detected, the monitoring unit is specifically used to: When a new VPN instance is detected being created, and an EEND-DT is dynamically allocated to the new VPN instance, it is determined that the EEND-DT of the VPN instance has changed; or, When a change in the SRV6 Locator is detected, and EEND-DT is dynamically reassigned to each VPN instance, it is determined that the EEND-DT of the VPN instance has changed.

[0018] Optionally, if the preset routing protocol is BGP, then when sending the mapping relationship between the VPN instance and the EEND-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit is specifically used for: The EEND-DT of the VPN instance is carried through the BGP extended field; If the preset routing protocol is IGP, then when sending the mapping relationship between the VPN instance and the EEND-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit is specifically used for: The EEND-DT of this VPN instance is carried via the IGP extended TLV.

[0019] Fifthly, embodiments of this application provide a message forwarding apparatus, which includes: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of the first aspects above, according to the obtained program instructions.

[0020] In a sixth aspect, embodiments of this application also provide a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the steps of the method as described in any of the first aspects above.

[0021] Seventhly, embodiments of this application provide a message forwarding apparatus, the message forwarding apparatus comprising: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of the second aspects above, according to the obtained program instructions.

[0022] Eighthly, embodiments of this application also provide a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the steps of the method as described in any of the second aspects above.

[0023] In summary, the packet forwarding method provided in this application is applied to a service chain forwarding node (SFF). The SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol. The SFF is pre-configured with at least one Cache List, where the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List. The method includes: receiving a mapping relationship between the VPN identifier of a target VPN instance and the END-DT of the target VPN instance published by the tail node through the preset routing protocol; wherein, when the tail node detects a change in the END-DT of any VPN instance, it sends the mapping relationship between the VPN instance and its END-DT to the SFF through the preset routing protocol; and generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and its END-DT and the Cache List corresponding to the target VPN instance, wherein the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

[0024] The packet forwarding method provided in this application automatically generates and distributes dynamic END-DT SIDs, and can automatically learn the dynamic END-DT of VPN instances, significantly reducing configuration workload. It automatically adapts when a new PE is added or the VPN changes. The SID can be dynamically adjusted according to the topology or policy, supporting more flexible traffic engineering, avoiding manual configuration errors, and simplifying the network expansion process. When the END-DT SID of the TAIL device changes dynamically, the SFF forwarding table updates faster, reducing forwarding interruption time. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments of this application or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings of the embodiments of this application.

[0026] Figure 1 A detailed flowchart of a message forwarding method provided for an embodiment of this application; Figure 2 A detailed flowchart of another message forwarding method provided in this application embodiment; Figure 3a This application provides a schematic diagram of a dynamic END-DT4 process by which TAIL announces a VPN to SFF via BGP, as provided in an embodiment of the present application. Figure 3b This application provides a schematic diagram of a cache list configuration for a VPN instance on an SFF. Figure 3c This is a schematic diagram of the SFF message forwarding process provided in an embodiment of this application; Figure 3d This is a schematic diagram illustrating the updating of SRV6 forwarding table entries on SFF, provided in an embodiment of this application. Figure 4a A schematic diagram illustrating the process by which TAIL announces a VPN dynamic END-DT4 to SFF via IGP, provided in an embodiment of this application; Figure 4b This application provides a schematic diagram of a cache list configuration for a VPN instance on an SFF. Figure 4c This is a schematic diagram of the SFF message forwarding process provided in an embodiment of this application; Figure 4d This is a schematic diagram illustrating the updating of SRV6 forwarding table entries on SFF, provided in an embodiment of this application. Figure 5 This is a schematic diagram of the structure of a message forwarding device provided in an embodiment of this application; Figure 6 A schematic diagram of another message forwarding device provided in the embodiments of this application; Figure 7 A schematic diagram of the hardware architecture of a message forwarding device provided in this application embodiment; Figure 8 This is a schematic diagram of the hardware architecture of another message forwarding device provided in an embodiment of this application. Detailed Implementation

[0027] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to limit the application. The singular forms “a,” “the,” and “the” as used in this application and claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to any and all possible combinations comprising one or more of the associated listed items.

[0028] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" may also be interpreted as "when," "when," or "in response to a determination."

[0029] For example, see Figure 1 The diagram shown is a detailed flowchart of a packet forwarding method provided in an embodiment of this application. This method is applied to a service chain forwarding node (SFF). The SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol. The SFF is pre-configured with at least one Cache List, where the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List. The method includes the following steps: Step 100: Receive the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance published by the tail node through the preset routing protocol.

[0030] In this embodiment of the application, the SFF is pre-configured with a corresponding Cache List template for at least one VPN instance (service chain policy), and the last SID in the Cache List is the VPN identifier of the VPN instance corresponding to the Cache List.

[0031] In practical applications, END-DT can be either END-DT4 or END-DT6. That is, in an IPv4 network where the original packet is an IPv4 packet, END-DT is END-DT4; in an IPv6 network where the original packet is an IPv6 packet, END-DT is END-DT6. In this embodiment, a typical IPv4 L3VPN over SRV6 SFC network (i.e., the tail node's SID type is END-DT4) is used as an example for illustration: In the SFF-configured cache list, the forwarding path SIDs at the beginning remain unchanged, and the last SID is no longer configured with the static END-DT4 of the tail node VPN instance, but instead is configured with the VPN instance name identifier. For example, the pre-configured cache list for VPN1 is as follows: [SID1, SID2, ..., vpn-instance:VPN1]; The pre-configured cache list for VPN2 is as follows: [SID1, SID2, ..., vpn-instance:VPN2]; ...

[0032] In practical applications, for each tail node, a cache list with the last SID being the VPN instance name can be pre-configured for all VPNs, or a cache list with the last SID being the VPN instance name can be pre-configured for some VPNs. In this embodiment of the application, no specific limitation is made here.

[0033] In this embodiment of the application, when the tail node detects a change in the END-DT of any VPN instance, it sends a mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol.

[0034] In this embodiment of the application, the preset routing protocol is either Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP).

[0035] Specifically, if the SFF and the tail node belong to different ASs (Autonomous Systems), the SFF establishes a BGP neighbor relationship with the tail node. In this way, when the tail node detects a change in the END-DT4 of any VPN instance, it can send a mapping relationship carrying the END-DT4 of the VPN instance to the SFF via BGP. If the SFF and the tail node belong to the same AS, the SFF establishes a BGP neighbor relationship with the tail node. In this way, when the tail node detects a change in the END-DT4 of any VPN instance, it can send a mapping relationship carrying the END-DT4 of the VPN instance to the SFF via IGP.

[0036] Step 110: Generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance.

[0037] Wherein, the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

[0038] In this embodiment of the application, when generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, a preferred implementation is as follows: Based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the END-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

[0039] In practical applications, if the target forwarding table does not maintain a target forwarding table entry corresponding to the target VPN instance (e.g., the target VPN instance is a newly added VPN instance), then a new target forwarding table entry will be added to the forwarding table; if the target forwarding table already maintains a target forwarding table entry corresponding to the target VPN instance (e.g., the END-DT4 of the target VPN instance has changed), then the target forwarding table entry will be updated.

[0040] In practical applications, the specific process of generating target forwarding table entries on SFF is as follows: Step 1: SFF parses the cache list and identifies the last hop as the VPN instance identifier vpn-instance:VPN1; Step 2: SFF looks up the dynamic END-DT4 SID (e.g., 5000:1001) corresponding to VPN1 in the mapping table between the VPN instance identifier learned by BGP / IGP and the END-DT4 of the VPN instance. Step 3: SFF fills the last hop position of the SRH header in the SRv6SFF forwarding table entry with the dynamic END-DT4 SID; Step 4: SFF forwards packets according to the forwarding table entries. After the packet reaches the tail node, the tail node decapsulates it according to END-DT4SID and forwards it from the corresponding VPN instance.

[0041] Furthermore, in this embodiment of the application, the above-mentioned message forwarding method further includes the following steps: Receive the original packets belonging to the target VPN instance returned by the application service node SF; Based on the SRH header in the target forwarding table entry, the original message is encapsulated in SRV6 to obtain the encapsulated SRV6 message. The encapsulated SRV6 message is sent to the tail node.

[0042] In practical applications, after the SFF obtains the original SRv6 packet, it sends it to the SF for processing. After completing the packet processing, the SF returns the packet to the SFF through the interface associated with the target VPN to which the original packet belongs. After receiving the original packet through this interface, the SFF determines the target VPN instance based on this interface, and then performs SRv6 encapsulation on the original packet according to the target forwarding table entry corresponding to the target VPN instance in the forwarding table to obtain the encapsulated SRv6 packet, and sends the SRv6 packet to the tail node.

[0043] For example, see Figure 2 The diagram shown is a detailed flowchart of another packet forwarding method provided in this application embodiment. This method is applied to the tail node of a service chain path. The tail node and the service chain forwarding node (SFF) have a neighbor relationship established with a preset routing protocol. The SFF is pre-configured with at least one Cache List, where the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List. The method includes the following steps: Step 200: Monitor whether the END-DT of each VPN instance has changed.

[0044] Step 210: When a change in the END-DT of any VPN instance is detected, send a mapping relationship between the VPN instance and its END-DT to the SFF through the preset routing protocol.

[0045] Thus, when the SFF receives the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance published by the tail node through the preset routing protocol, it generates a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance. In the target forwarding table entry, the last hop in the SRH header is the END-DT of the target VPN instance.

[0046] In this embodiment of the application, the situations in which the END-DT of the VPN instance is detected to change include: The first scenario: When a new VPN instance is detected to have been created, and an END-DT is dynamically allocated to the new VPN instance, it is determined that the END-DT of the VPN instance has changed.

[0047] The second scenario: When a change in the SRV6 Locator is detected, and END-DT is dynamically reallocated to each VPN instance, it is determined that the END-DT of the VPN instance has changed.

[0048] In this embodiment of the application, if the preset routing protocol is BGP, then when sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol, a preferred implementation is as follows: The END-DT of the VPN instance is carried through the BGP extended field.

[0049] In practical applications, the tail node acts as the BGP Speaker, sending BGP Update messages to its neighbors (i.e., SFFs). Key message content: NLRI (Network Layer Reachability Information): Contains reachable IPv4 VPN routes (belonging to VPN1).

[0050] BGP extended field attributes (e.g., SRv6 SID Information Sub-TLV): carry the service SID (END-DT4) associated with this VPN route.

[0051] This attribute explicitly states that the SID serving this VPN route is 5000:1001, and its behavior is END-DT4.

[0052] When the SFF's BGP process receives the Update message, it parses the message and extracts the key mapping relationship: VPN1 -> Dynamic END-DT4 SID (5000:1001). It then stores this mapping relationship in its local "VPN instance-dynamic SID mapping table" for the forwarding module to query.

[0053] If the preset routing protocol is IGP, the step of sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol includes: The END-DT of this VPN instance is carried via the IGP extended TLV.

[0054] In practical applications, after the tail node generates the SRv6 dynamic END-DT4 of the VPN instance locally, it adds an SFC-Proxy-End-DT4 Sub-TLV through the SRv6 Locator TLV extension of the IGP protocol (such as OSPFv3 or IS-IS), carrying the following information: VPN instance identifier (VPN Instance ID or VPN instance name, such as VPN1); The dynamic END-DT4 SID value corresponding to the VPN instance; Route Distinguisher (RD) of VPN instance; The tail node will flood the SRv6 Locator LSP carrying the SFC-Proxy-End-DT4 Sub-TLV within the IGP domain. All devices within the domain (including SFF) can learn the mapping relationship between the tail node's VPN instance and the dynamic END-DT4 through the IGP LSDB.

[0055] The message forwarding method provided in this application embodiment will be described in detail below with reference to specific application scenarios.

[0056] This explanation uses the establishment of a BGP neighbor connection between the tail node (TAIL) and the SFF as an example. For an example, please refer to [link to relevant documentation]. Figure 3a The diagram illustrates a process by which TAIL announces the dynamic END-DT4 of a VPN to SFF via BGP, according to an embodiment of this application. SFF and TAIL establish a BGP neighbor relationship. TAIL publishes the dynamic END-DT4 of a VPN instance (e.g., VPN1) to SFF via BGP. SFF can find that the dynamic END-DT4 corresponding to TAIL's VPN instance is 5000:1001.

[0057] For example, see Figure 3b The diagram shown is a schematic of the Cachelist configuration of a VPN instance on an SFF provided in an embodiment of this application. In the Cache List configured by the SFF, the forwarding path SID at the beginning remains unchanged, and the last SID is no longer configured with the static END-DT4 of the tail node VPN instance, but is configured with the VPN instance name.

[0058] For example, see Figure 3c The diagram shows the SFF forwarding process provided in this application embodiment. The SFF (forwarding module) generates an SRV6SFF forwarding table based on the dynamic END-DT4 of the VPN instance received from the tail node. The SRV6SFF forwarding module forwards the packets according to the entries in the forwarding table. In the forwarding table, the last hop in the SRH header is the dynamic END-DT4 of the TAIL VPN1 instance. After the flow goes from the SFF to TAIL, it will be forwarded out from the corresponding VPN.

[0059] For example, see Figure 3d The diagram shown illustrates the updating of SRV6 forwarding table entries on the SFF provided in this embodiment of the application. When the dynamic END-DT4 of the SRV6 Locator of the tail node or the VPN instance changes dynamically, the SFF can detect the dynamic END-DT4 change in a timely manner through BGP. Without changing the configuration, the SRV6 forwarding table entries will be updated, and forwarding will not be affected.

[0060] This explanation uses the establishment of an IGP neighbor connection between the tail node (TAIL) and the SFF as an example. For an example, please refer to [link to relevant documentation]. Figure 4a The diagram illustrates a process by which TAIL advertises a dynamic END-DT4 VPN to SFF via IGP, according to an embodiment of this application. After TAIL generates the SRv6 dynamic END-DT4 of the VPN instance locally, it extends the SRv6 Locator TLV via the IGP protocol (OSPFv3 or IS-IS), specifically by adding an SFC-Proxy-End-DT4 Sub-TLV carrying the following information: VPN instance identifier (VPN Instance ID or VPN instance name); The dynamic END-DT4 SID value corresponding to the VPN instance; Route Distinguisher (RD) of VPN instance; TAIL will flood the SRv6 Locator LSP carrying SFC-Proxy-End-DT4 Sub-TLV within the IGP domain. All devices within the domain (including SFF) can learn the mapping relationship between the tail node VPN instance and the dynamic END-DT4 through the IGP LSDB.

[0061] For example, see Figure 4b The diagram shown illustrates a cachelist configuration for a VPN instance on an SFF provided in this application embodiment. In the SFF-configured cachelist, the forwarding path SID remains unchanged at the beginning, and the last SID is no longer configured with the static END-DT4 of the tail node VPN instance (e.g., VPN1), but instead is configured with the VPN instance identifier. For example: Cache list: [SID1, SID2, ..., vpn-instance:VPN1] Among them, vpn-instance:VPN1 indicates that the last hop needs to find the dynamic END-DT4SID corresponding to the VPN1 instance.

[0062] For example, see Figure 4c The diagram illustrates the SFF packet forwarding process provided in this embodiment. The SFF generates an SRv6SFF forwarding table based on the VPN instance and dynamic END-DT4 mapping learned through IGP, and the VPN instance name configured in the cache list. The last hop in the SRH header of the forwarding table is the dynamic END-DT4 SID of the TAIL VPN1 instance. After traffic travels from the SFF to TAIL, it will be forwarded from the corresponding VPN instance.

[0063] The specific process of generating the forwarding table is as follows: 1. SFF parses the cache list and identifies the last hop as the VPN instance name identifier vpn-instance:VPN1; 2. SFF looks up the dynamic END-DT4SID (e.g., 5000:1001) corresponding to VPN1 in the VPN instance → END-DT4 mapping table learned by IGP. 3. SFF fills the last hop position of the SRH header in the SRv6SFF forwarding table entry with the dynamic END-DT4 SID; 4. SFF forwards packets according to the forwarding table entries. After the packet arrives at TAIL, it is decapsulated according to the END-DT4 SID and forwarded from the corresponding VPN instance.

[0064] For example, see Figure 4d The diagram illustrates the SRV6 forwarding table update process on the SFF provided in this embodiment. When the SRv6 Locator of the TAIL device or the dynamic END-DT4 of the VPN instance changes, the TAIL device re-floods the updated SFC-Proxy-End-DT4 Sub-TLV via IGP. After receiving the IGP update message, the SFF triggers an SRv6 SFF forwarding table refresh. 1. The IGP protocol detects a change in the END-DT4 SID value in the SFC-Proxy-End-DT4 Sub-TLV; 2. The IGP module notifies the SRv6 module to update the VPN instance and END-DT4 mapping table; 3. The SRv6 module regenerates the SRv6SFF forwarding table entry and fills the new dynamic END-DT4 SID into the last hop of the SRH header; 4. Since the IGP convergence time is in the millisecond range, forwarding interruptions during SID changes are minimized.

[0065] Based on the same inventive concept as the above-described method embodiments applied to SFF, see, for example, the following... Figure 5 The diagram shown is a structural schematic of a packet forwarding device provided in an embodiment of this application. This device is applied to a service chain forwarding node (SFF). The SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol. The SFF is pre-configured with at least one cache list, where the last SID in a cache list is the VPN identifier of the VPN instance corresponding to that cache list. The device includes: The first receiving unit 50 is used to receive the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance published by the tail node through the preset routing protocol, wherein when the tail node detects that the END-DT of any VPN instance has changed, it sends the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol. The generation unit 51 is used to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, wherein the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

[0066] Optionally, the device further includes: The second receiving unit is used to receive the original packets belonging to the target VPN instance returned by the application service node SF. An encapsulation unit is used to encapsulate the original message with SRV6 based on the SRH header in the target forwarding table entry to obtain an encapsulated SRV6 message. The sending unit is used to send the encapsulated SRV6 message to the tail node.

[0067] Optionally, when generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, the generation unit 51 is specifically used for: Based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the END-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

[0068] Optionally, the preset routing protocol is Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP).

[0069] Based on the same inventive concept as the above-described method embodiments applied to tail nodes, see, for example, the following... Figure 6The diagram shown is a structural schematic of a packet forwarding device provided in an embodiment of this application. This device is applied to the tail node of a service chain path. The tail node and the service chain forwarding node (SFF) establish a neighbor relationship based on a preset routing protocol. The SFF is pre-configured with at least one Cache List, where the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List. The device includes: Monitoring unit 60 is used to monitor whether the END-DT of each VPN instance has changed; When the monitoring unit 60 detects a change in the END-DT of any VPN instance, the sending unit 61 is configured to send a mapping relationship between the VPN instance and its END-DT to the SFF via the preset routing protocol. This enables the SFF to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and its END-DT, and the Cache List corresponding to the target VPN instance, when receiving the mapping relationship between the VPN identifier of the target VPN instance and its END-DT published by the tail node via the preset routing protocol. The last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

[0070] Optionally, when a change in the END-DT of a VPN instance is detected, the monitoring unit 60 is specifically used to: When a new VPN instance is detected being created, and an END-DT is dynamically allocated to the new VPN instance, it is determined that the END-DT of the VPN instance has changed; or, When a change in the SRV6 Locator is detected, and END-DT is dynamically reassigned to each VPN instance, it is determined that the END-DT of the VPN instance has changed.

[0071] Optionally, if the preset routing protocol is BGP, then when sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit 61 is specifically used for: The END-DT of the VPN instance is carried through the BGP extended field; If the preset routing protocol is IGP, then when sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit is specifically used for: The END-DT of this VPN instance is carried via the IGP extended TLV.

[0072] These units can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more digital signal processors (DSPs), or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when one of these units is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these units can be integrated together to form a system-on-a-chip (SOC).

[0073] Furthermore, regarding the packet forwarding device provided in this application embodiment, from a hardware perspective, the hardware architecture diagram of the packet forwarding device can be found in [reference needed]. Figure 7 As shown, the message forwarding device may include: a memory 70 and a processor 71. The memory 70 is used to store program instructions; the processor 71 calls the program instructions stored in the memory 70 and executes the method embodiment applied to SFF according to the obtained program instructions. The specific implementation method and technical effect are similar, and will not be described again here.

[0074] Optionally, this application also provides an SFF device, including at least one processing element (or chip) for performing the above-described method embodiments applied to SFF.

[0075] Optionally, this application also provides a program product, such as a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the above-described method embodiments applied to SFF.

[0076] Furthermore, regarding the packet forwarding device provided in this application embodiment, from a hardware perspective, the hardware architecture diagram of the packet forwarding device can be found in [reference needed]. Figure 8 As shown, the message forwarding device may include: a memory 80 and a processor 81. The memory 80 is used to store program instructions; the processor 81 calls the program instructions stored in the memory 80 and executes the method embodiment applied to the tail node according to the obtained program instructions. The specific implementation method and technical effect are similar, and will not be described in detail here.

[0077] Optionally, this application also provides a tail node device, including at least one processing element (or chip) for performing the above-described method embodiments applied to the tail node.

[0078] Optionally, this application also provides a program product, such as a computer-readable storage medium storing computer-executable instructions for causing the computer to perform the above-described method embodiments applied to the tail node.

[0079] Here, a machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, a machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.

[0080] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which can take the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email sending and receiving device, game console, tablet computer, wearable device, or any combination of these devices.

[0081] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.

[0082] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0083] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0084] Furthermore, these computer program instructions can also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in the process. Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0085] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0086] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A message forwarding method, characterized in that, The method is applied to a Service Chain Forwarding Node (SFF), where the SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol. The SFF is pre-configured with at least one Cache List, where the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List. The method includes: The tail node receives the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance published by the preset routing protocol. When the tail node detects that the END-DT of any VPN instance has changed, it sends the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol. Based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, a target forwarding table entry is generated, wherein the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

2. The method as described in claim 1, characterized in that, The method further includes: Receive the original packets belonging to the target VPN instance returned by the application service node SF; Based on the SRH header in the target forwarding table entry, the original message is encapsulated in SRV6 to obtain the encapsulated SRV6 message. The encapsulated SRV6 message is sent to the tail node.

3. The method as described in claim 1 or 2, characterized in that, The steps for generating target forwarding entries based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance include: Based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the END-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

4. The method as described in claim 1 or 2, characterized in that, The preset routing protocol is either Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP).

5. A message forwarding method, characterized in that, The method is applied to the tail node of the service chain path, wherein the tail node and the service chain forwarding node SFF have established a neighbor relationship with a preset routing protocol, and the SFF is pre-configured with at least one CacheList, wherein the last SID in a CacheList is the VPN identifier of the VPN instance corresponding to that CacheList; the method includes: Monitor whether the END-DT of each VPN instance has changed; When a change in the END-DT of any VPN instance is detected, the SFF is sent a mapping relationship between the VPN instance and its END-DT via the preset routing protocol. This allows the SFF to generate a target forwarding table entry based on the mapping relationship between the VPN identifier and the END-DT of the target VPN instance published by the tail node via the preset routing protocol. The last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

6. The method as described in claim 5, characterized in that, The steps to detect changes in the END-DT of a VPN instance include: When a new VPN instance is detected being created, and an END-DT is dynamically allocated to the new VPN instance, it is determined that the END-DT of the VPN instance has changed; or, When a change in the SRV6 Locator is detected, and END-DT is dynamically reassigned to each VPN instance, it is determined that the END-DT of the VPN instance has changed.

7. The method as described in claim 5 or 6, characterized in that, If the preset routing protocol is BGP, the step of sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol includes: The END-DT of the VPN instance is carried through the BGP extended field; If the preset routing protocol is IGP, the step of sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol includes: The END-DT of this VPN instance is carried via the IGP extended TLV.

8. A message forwarding device, characterized in that, An application is made to a Service Chain Forwarding Node (SFF), wherein the SFF establishes a neighbor relationship with the tail node of the service chain path using a preset routing protocol, and the SFF is pre-configured with at least one Cache List, wherein the last SID in a Cache List is the VPN identifier of the VPN instance corresponding to that Cache List; the device includes: The first receiving unit is used to receive the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance published by the tail node through the preset routing protocol, wherein when the tail node detects that the END-DT of any VPN instance has changed, it sends the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol. The generation unit is used to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, wherein the last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

9. The apparatus as claimed in claim 8, characterized in that, The device further includes: The second receiving unit is used to receive the original packets belonging to the target VPN instance returned by the application service node SF. An encapsulation unit is used to encapsulate the original message with SRV6 based on the SRH header in the target forwarding table entry to obtain an encapsulated SRV6 message. The sending unit is used to send the encapsulated SRV6 message to the tail node.

10. The apparatus as claimed in claim 8 or 9, characterized in that, When generating a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance and the Cache List corresponding to the target VPN instance, the generation unit is specifically used for: Based on the mapping relationship between the VPN identifier of the target VPN instance and the END-DT of the target VPN instance, the VPN identifier in the Cache List corresponding to the target VPN instance is replaced with the END-DT of the target VPN instance to generate a complete SID list; Based on the complete list of SIDs, generate the target forwarding table entry.

11. A message forwarding device, characterized in that, The device is applied to the tail node of the service chain path, wherein the tail node and the service chain forwarding node (SFF) have established a neighbor relationship with a preset routing protocol, and the SFF is pre-configured with at least one CacheList, wherein the last SID in a CacheList is the VPN identifier of the VPN instance corresponding to that CacheList; the device includes: The monitoring unit is used to monitor whether the END-DT of each VPN instance has changed; When the monitoring unit detects a change in the END-DT of any VPN instance, the sending unit is configured to send a mapping relationship between the VPN instance and its END-DT to the SFF via the preset routing protocol. This enables the SFF to generate a target forwarding table entry based on the mapping relationship between the VPN identifier of the target VPN instance and its END-DT, and the Cache List corresponding to the target VPN instance, when receiving the mapping relationship between the VPN identifier of the target VPN instance and its END-DT published by the tail node via the preset routing protocol. The last hop in the SRH header of the target forwarding table entry is the END-DT of the target VPN instance.

12. The apparatus as claimed in claim 11, characterized in that, When a change in the END-DT of a VPN instance is detected, the monitoring unit is specifically used for: When a new VPN instance is detected being created, and an END-DT is dynamically allocated to the new VPN instance, it is determined that the END-DT of the VPN instance has changed; or, When a change in the SRV6 Locator is detected, and END-DT is dynamically reassigned to each VPN instance, it is determined that the END-DT of the VPN instance has changed.

13. The apparatus as claimed in claim 11 or 12, characterized in that, If the preset routing protocol is BGP, then when sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit is specifically used for: The END-DT of the VPN instance is carried through the BGP extended field; If the preset routing protocol is IGP, then when sending the mapping relationship between the VPN instance and the END-DT of the VPN instance to the SFF through the preset routing protocol, the sending unit is specifically used for: The END-DT of this VPN instance is carried via the IGP extended TLV.

14. A message forwarding device, characterized in that, The message forwarding device includes: Memory, used to store program instructions; A processor is configured to invoke program instructions stored in the memory and execute the steps of the method as described in any one of claims 1-7 according to the obtained program instructions.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing the computer to perform the steps of the method as described in any one of claims 1-7.