Fault protection method and device, storage medium and electronic device

By configuring protection relationships and generating protection entries on backup nodes, the difficulties in device deployment caused by the different protection technologies for intermediate and tail nodes in SR/SRv6 networks are resolved, enabling seamless path switching and function preservation after a failure.

CN112822100BActive Publication Date: 2026-04-28ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZTE CORP
Filing Date
2021-02-05
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In SR/SRv6 networks, intermediate node protection and tail node protection typically employ different technologies, leading to difficulties in equipment deployment.

Method used

Configure protection relationships on the standby node, receive Segment Identifier (SID) information announced by the master node, and generate protection entries when the SID network programming function type matches the SID network programming function type of the standby node and the SID value matches the protection relationship. Then, when the master node or the link connected to the master node fails, the standby node forwards the received packets.

Benefits of technology

This solves the problem of difficult equipment deployment caused by using different technologies for intermediate node protection and tail node protection, and enables the switching path to provide the same functionality as the original path after a fault.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112822100B_ABST
    Figure CN112822100B_ABST
Patent Text Reader

Abstract

The application provides a fault protection method and device, a storage medium and an electronic device. The method comprises the following steps: configuring a protection relationship on a backup node, wherein the protection relationship is used to indicate an object that needs to be protected by the backup node; receiving segment identifier (SID) information announced by a master node, wherein the SID information at least comprises a SID network programming function type and a SID value; matching the SID network programming function type with a SID network programming function type possessed by the backup node, matching the SID value with the protection relationship, and generating a protection table item in the case that the SID network programming function type and the SID network programming function type possessed by the backup node are matched successfully and the SID value and the protection relationship are matched successfully; and forwarding a received message according to the protection table item in the case that the master node or a link connected with the master node fails.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention mainly relates to the field of communications, and more specifically, to a fault protection method and apparatus, a storage medium, and an electronic device. Background Technology

[0002] With the continuous development of technology, networks are becoming larger and larger. Network failures can lead to interruptions in business transmission and data loss, resulting in serious consequences. However, in real life, network failures are unavoidable due to various reasons. Therefore, fault protection for business transmission has become very important.

[0003] In the existing technology, fault protection schemes in SR / SRv6 networks mainly include the following schemes:

[0004] 1) draft-chen-rtgwg-srv6-midpoint-protection: This scheme mainly skips the failed node and continues forwarding after a node failure. This method mainly protects the reachability of the entire link, but it cannot guarantee that the backup path can provide the same functionality.

[0005] 2) `draft-hu-spring-segment-routing-proxy-forwarding`: This solution introduces a method for fault protection of intermediate nodes using proxy nodes. By introducing proxy nodes, they can forward packets to all or some neighboring nodes. The proxy nodes maintain local proxy forwarding entries. When they receive a packet from an upstream node containing the SID of the protected node, they can look up the proxy entry in the proxy table and forward it. In this solution, the proxy node needs to advertise its SR proxy capabilities externally via IGP (Interior Gateway Protocol), and the upstream device must also be able to receive new advertising messages.

[0006] 3) `draft-ietf-rtgwg-srv6-egress-protection` introduces a method for egress protection using mirrored SIDs. In a dual-tail node scenario, two tail nodes can provide the same VPN forwarding service. This pair of tail nodes can be configured as a mirror group, and the mirror relationship can be propagated throughout the network via IGP (Interior Gateway Protocol). When a node in the mirror group fails, it can reach other nodes in the mirror group via FRR (Failure Regression), achieving rapid convergence. In the SRv6 tail node protection method, the primary egress node is the designated egress node of the SRv6 path, and it has a corresponding SID in the SRH (Signal Regression Header) to indicate this primary egress node, called the primary egress node SID. There is also a backup egress node and a local protection node (PLR) hop above the primary egress node to provide protection support for the primary egress node. This scheme defines a new type of mirrored SID. The backup node and the local protection node (PLR) need to support this new type of SID and related IGP extensions, therefore, it is not very friendly to older devices.

[0007] 4) `draft-hegde-rtgwg-egress-protection-sr-networks` introduces an egress protection method. In a dual-tail node scenario, two tail nodes can provide the same VPN forwarding service. For the same service, they are assigned the same VPNSID, and the prefix advertisement corresponding to the SID is an anycast prefix, forming anycast fast rerouting (anycast frr) protection. The drawback of this method is that it requires statically specifying the VPN SID, as the VPN SIDs of the two PEs need to be consistent, which is not conducive to practical deployment.

[0008] In the relevant technologies, different technologies are generally used for intermediate node protection and tail node protection during the fault protection process, which leads to difficulties in equipment deployment. No effective technical solution has yet been proposed. Summary of the Invention

[0009] This invention provides a fault protection method, apparatus, storage medium, and electronic device to at least address the problem that, during the fault protection process, intermediate node protection and tail node protection generally employ different technologies, leading to difficulties in equipment deployment.

[0010] This invention provides a fault protection method, comprising: configuring a protection relationship on a backup node, wherein the protection relationship is used to indicate the objects that the backup node needs to protect; receiving segment identifier (SID) information announced by a primary node, wherein the SID information includes at least: SID network programming function type and SID value; matching the SID network programming function type with the SID network programming function type possessed by the backup node, and matching the SID value with the protection relationship; generating a protection entry when both the SID network programming function type and the SID value match successfully; and forwarding received packets by the backup node according to the protection entry when the primary node or the link connected to the primary node fails, wherein when the primary node and the link connected to the primary node are not failed, other nodes send the packets to the primary node; when the primary node and the link connected to the primary node fail, other nodes send the packets directly to the backup node, wherein the other nodes are nodes other than the primary node and the backup node.

[0011] Optionally, the protection relationship is configured on the standby node, including at least one of the following: configuring a prefix on the primary node to be protected on the standby node; configuring the primary node to be protected on the standby node; configuring the segment identifier (SID) value on the primary node to be protected on the standby node; configuring the SID network programming function type on the primary node to be protected on the standby node.

[0012] Optionally, after the SID network programming function type and the SID network programming function type of the backup node are successfully matched, and the SID value and the protection relationship are successfully matched, the method further includes: instructing the backup node to flood the prefix of the primary node externally with a low priority, wherein the low priority is lower than the priority when the primary node floods itself.

[0013] Optionally, after instructing the backup node to flood the prefix of the primary node externally with low priority, the method further includes: if the backup node no longer has the ability to protect the prefix on the primary node, the primary node, the segment identifier SID value on the primary node, or the SID network programming function type on the primary node, the backup node cancels the external flooding of the primary node's prefix.

[0014] Optionally, if the SID information announced by the primary node also carries service function information, the method further includes: if the SID network programming function type is segment routing SR proxy function, matching the SID network programming function type of the backup node with the segment routing SR proxy function; if the SID network programming function type of the backup node matches the segment routing SR proxy function, matching the service function information of the backup node SR proxy with the service function information corresponding to the primary node segment routing SR proxy function; and if the service function information of the backup node SR proxy successfully matches the service function information corresponding to the primary node segment routing SR proxy function, generating the protection entry.

[0015] Optionally, if the SID information announced by the primary node also carries VPN service information, the method further includes: after the backup node receives the VPN route encapsulated by the primary node, matching the SID network programming function type in the VPN route with the SID network programming function type possessed by the backup node; if the SID network programming function type in the VPN route matches the SID network programming function type possessed by the backup node, matching the VPN service information possessed by the backup node's SID network programming function with the VPN service information corresponding to the SID network programming function type in the primary node's VPN route; and if the VPN service information possessed by the backup node's SID network programming function matches the VPN service information corresponding to the SID network programming function type in the primary node's VPN route, generating the protection entry.

[0016] Optionally, if the SID information announced by the primary node also carries link information, the method further includes: the backup node matching the SID network programming function type with the SID network programming function type possessed by the backup node; if the SID network programming function type matches successfully with the SID network programming function type possessed by the backup node, the backup node matching the link information with the link information possessed by the backup node; and if the link information matches successfully with the link information possessed by the backup node, generating a protection entry.

[0017] Optionally, if the primary node does not fail, but the link connecting the primary node to the VPN network fails, the method further includes: a backup node receiving a target packet encapsulated by the primary node in a preset manner, wherein the target packet includes: a VPNSID assigned by the primary node to the VPN network; if the VPN SID matches the protection entry, the backup node forwards the received packet according to the protection entry, wherein if the primary node and the link connected to the primary node do not fail, other nodes send the packet to the primary node; if the primary node and the link connected to the primary node fail, other nodes send the packet directly to the backup node, wherein the other nodes are nodes other than the primary node and the backup node.

[0018] According to another embodiment of the present invention, a fault protection device is also provided, comprising: a configuration module, configured to configure a protection relationship on a standby node, wherein the protection relationship is used to indicate the object that the standby node needs to protect; a receiving module, configured to receive segment identifier (SID) information announced by a master node, wherein the segment identifier (SID) information includes at least: a SID network programming function type and a SID value; a matching module, configured to match the SID network programming function type with the SID network programming function type possessed by the standby node, and match the SID value with the protection relationship; wherein, if both the SID network programming function type and the SID network programming function type possessed by the standby node and the SID value and the protection relationship are successfully matched, a protection entry is generated; and a forwarding module, configured to, in the event of a fault in the master node or a link connected to the master node, wherein, if the master node and the link connected to the master node are not faulty, other nodes send the message to the master node, and if the master node and the link connected to the master node are faulty, other nodes directly send the message to the standby node, wherein the other nodes are nodes other than the master node and the standby node.

[0019] According to yet another embodiment of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored therein, wherein the computer program is configured to perform the steps in any of the above method embodiments when executed.

[0020] According to yet another embodiment of the present invention, an electronic device is also provided, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0021] Through the above technical solution, protection relationships are configured on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect; segment identifier (SID) information announced by the master node is received, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value; the SID network programming function type is matched with the SID network programming function type possessed by the backup node, and the SID value is matched with the protection relationship; if the SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated; if the master node or the link connected to the master node fails, the backup node forwards the received packets according to the protection entry, wherein if the master node and the link connected to the master node do not fail, other nodes send the packets to the master node. In the event of a failure of the primary node and the link connected to the primary node, other nodes directly send the message to the backup node. These other nodes are those other than the primary and backup nodes. Specifically, by configuring a protection relationship on the backup node, and ensuring that the SID network programming function type matches the backup node's SID network programming function type and the SID value matches the protection relationship, a protection entry is generated. Then, in the event of a failure of the primary node or the link connected to the primary node, the backup node forwards the received message according to the protection entry. This technical solution solves the problem in related fault protection technologies where intermediate node protection and tail node protection typically employ different technologies, leading to difficulties in equipment deployment. The technical solution of this invention is applicable to fault protection of both intermediate and exit nodes, and the switched path after a failure can provide the same functionality as the original path. Attached Figure Description

[0022] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0023] Figure 1 This is a hardware structure block diagram of a computer terminal for a fault protection method according to an embodiment of the present invention.

[0024] Figure 2 This is a flowchart of a fault protection method according to an embodiment of the present invention;

[0025] Figure 3 This is a schematic diagram of the intermediate node protection network of the fault protection method according to an optional embodiment of the present invention;

[0026] Figure 4This is a schematic diagram of a business chain protection scenario for a fault protection method according to an optional embodiment of the present invention;

[0027] Figure 5 This is a schematic diagram of a tail node / link fault protection network according to an optional embodiment of the fault protection method of the present invention;

[0028] Figure 6 This is a structural block diagram of a fault protection device according to an embodiment of the present invention. Detailed Implementation

[0029] The present invention will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the present application can be combined with each other.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0031] The methods provided in this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking running on a computer terminal as an example... Figure 1 This is a hardware structure block diagram of a computer terminal for a fault protection method according to an embodiment of the present invention. Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. Optionally, the computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 Equivalent functions or ratios shown Figure 1The illustrated functionality includes various configurations. Memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the fault protection method in this embodiment. Processor 102 executes various functional applications and data processing by running the computer program stored in memory 104, thus implementing the aforementioned method. Memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, memory 104 may further include memory remotely located relative to processor 102, which can be connected to the computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Transmission device 106 is used to receive or send data via a network. Specific examples of such networks may include wireless networks provided by the computer terminal's communication provider. In one example, transmission device 106 includes a Network Interface Controller (NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0032] According to an embodiment of the present invention, a fault protection method is provided, applied to the aforementioned computer terminal. Figure 2 This is a flowchart of a fault protection method according to an embodiment of the present invention, such as... Figure 2 As shown, it includes:

[0033] Step S202: Configure protection relationships on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect;

[0034] Step S204: Receive the segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value;

[0035] Step S206: Match the SID network programming function type with the SID network programming function type of the backup node, match the SID value with the protection relationship, and generate a protection entry when the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched.

[0036] It should be noted that if the SID does not explicitly specify the network programming function type, but has a default network programming function type END, then the SID information is also considered to contain network programming function type information.

[0037] Step S208: In the event of a failure of the primary node or a link connected to the primary node, the backup node forwards the received message according to the protection table entry. Wherein, if the primary node and the link connected to the primary node are not at fault, other nodes send the message to the primary node. If the primary node and the link connected to the primary node are at fault, other nodes send the message directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

[0038] Through the above technical solution, protection relationships are configured on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect; segment identifier (SID) information announced by the master node is received, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value; the SID network programming function type is matched with the SID network programming function type possessed by the backup node, and the SID value is matched with the protection relationship; if the SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated; if the master node or the link connected to the master node fails, the backup node forwards the received packets according to the protection entry, wherein if the master node and the link connected to the master node do not fail, other nodes send the packets to the master node. In the event of a failure in the primary node and the link connected to the primary node, other nodes directly send the packets to the backup node. These other nodes are those other than the primary and backup nodes. Specifically, by configuring protection relationships on the backup node, and ensuring that the SID network programming function type matches the backup node's SID network programming function type and the SID value matches the protection relationship, a protection entry is generated. Then, in the event of a failure in the primary node or the link connected to the primary node, the backup node forwards the received packets according to the protection entry. This technical solution solves the problem in related fault protection technologies where intermediate node protection and tail node protection typically employ different technologies, leading to difficulties in equipment deployment. The technical solution of this invention is applicable to fault protection of both intermediate and exit nodes / links, and the switched path after a failure can provide the same functionality as the original path.

[0039] It should be noted that the solution of this invention is only applicable to networks where both primary and backup nodes support SRv6, excluding SR-MPLS scenarios. Furthermore, other nodes in the network do not necessarily need to support SRv6. After configuring protection relationships on the backup node, if the SID information received by the backup node from the primary node is within the protection range, but the backup node lacks protection capabilities, it can perform actions such as discarding packets or generating alarms. These actions can be default or configured according to requirements.

[0040] In step S208, because the backup node floods the prefix of the primary node with a lower priority than the primary node, other nodes send the message to the primary node if the primary node and the link connected to the primary node are not faulty, and other nodes send the message directly to the backup node if the primary node and the link connected to the primary node are faulty.

[0041] Optionally, protection relationships can be configured on the backup node by configuring the prefix of the primary node to be protected on the backup node; configuring the primary node to be protected on the backup node; configuring the segment identifier (SID) value of the primary node to be protected on the backup node; configuring the SID network programming function type of the primary node to be protected on the backup node, etc.

[0042] In other words, when configuring protection relationships on a backup node, the prefix of the primary node to be protected can be configured on the backup node. The prefix can cover the SID of the primary node to be protected. The prefix of the primary node to be protected configured on the backup node can be one or more prefixes. For example, if the primary node's prefix is ​​LOC2, then the primary node to be protected can be configured with the prefix LOC2. Alternatively, the primary node to be protected can be configured on the backup node. Alternatively, the segment identifier SID value of the primary node to be protected can be configured on the backup node. In addition, the network programming function type of the SID of the primary node to be protected can be configured on the backup node. For example, if the primary node's SID type is END, then the SID of type END to be protected can be configured on the backup node. This invention does not limit the SID information, the primary node's prefix, etc.

[0043] In an exemplary embodiment, after the SID network programming function type and the SID network programming function type of the backup node are successfully matched, and the SID value and the protection relationship are successfully matched, the backup node is instructed to flood the prefix of the primary node externally with a low priority, wherein the low priority is lower than the priority when the primary node floods itself.

[0044] In other words, the master node announces the segment identifier (SID) information on the master node. The announcement method can be IGP (Interior Gateway Protocol), BGP, etc., which are not limited in this embodiment of the invention. The announcement message includes the segment identifier (SID) value and the type of segment identifier (SID) information. When the segment identifier (SID) information announced by the master node matches the protection relationship stored by the backup node, the backup node floods the prefix of the master node with a lower priority than the master node itself. The flooding method can be IGP (Interior Gateway Protocol), which is not limited in this embodiment of the invention, so that the packet is first sent to the master node, and in the event of a failure of the master node, the packet is forwarded to the backup node again.

[0045] Furthermore, after instructing the backup node to flood the prefix of the primary node externally with low priority, if the backup node no longer has the ability to protect the prefix on the primary node, the primary node, the segment identifier SID value on the primary node, or the SID network programming function type on the primary node, the backup node will withdraw the externally flooded prefix of the primary node, and thus the backup node will no longer have the protection relationship.

[0046] Optionally, if the SID information announced by the primary node also carries service function information, and if the SID network programming function type is segment routing SR proxy function, the backup node's SID network programming function type is matched with the segment routing SR proxy function; if the backup node's SID network programming function type matches the segment routing SR proxy function, the backup node's SR proxy service function information is matched with the service function information corresponding to the primary node's segment routing SR proxy function; if the backup node's SR proxy service function information matches the primary node's segment routing SR proxy function, the protection entry is generated.

[0047] Specifically, if the notification message also carries the SID network programming function type as segment routing SR proxy function, the segment routing SR proxy function is first matched. If the backup node also has SR proxy function, the match is successful. Then, the business function information corresponding to the SR proxy function needs to be matched. If the backup node also has the corresponding business function information, the match is successful, and a protection entry can be generated. It should be noted that if either the primary node's SR proxy function or the corresponding business function information does not match, a protection entry cannot be generated. After the corresponding protection entry is generated, the prefix corresponding to the primary node is flooded out with low priority through methods such as IGP (Interior Gateway Protocol). For example, if the business function information corresponding to the segment routing SR proxy is a firewall, the backup node will further match the firewall type with the business function information it possesses. If both match, the corresponding protection entry is generated.

[0048] Furthermore, if the firewall node represents a device that does not support SRv6, the primary and backup nodes have proxy functions, which means they can process packets in place of the firewall. Before the packet is sent to the firewall, the packet header is stripped off. After the firewall processes the packet and sends it back to the proxy, the proxy re-encapsulates the packet header and continues to forward it.

[0049] In an exemplary embodiment, where the SID information announced by the primary node also carries VPN service information, the method further includes: after the backup node receives the VPN route encapsulated by the primary node, matching the SID network programming function type in the VPN route with the SID network programming function type possessed by the backup node; if the SID network programming function type in the VPN route matches the SID network programming function type possessed by the backup node, matching the VPN service information possessed by the backup node's SID network programming function with the VPN service information corresponding to the SID network programming function type in the primary node's VPN route; and if the VPN service information possessed by the backup node's SID network programming function matches the VPN service information corresponding to the SID network programming function type in the primary node's VPN route, generating the protection entry.

[0050] Specifically, after the backup node receives the VPN route sent by the master node, the backup node performs a longest match based on the VPN SID information in the VPN route and the prefix address in the protection relationship. If the VPN service information possessed by the backup node matches the VPN service information in the VPN route, the backup node generates the protection entry and forwards the traffic to the target object. If the match cannot be completed, no protection entry is generated, and the backup node will not forward the master node's packets when the master node fails.

[0051] Optionally, if the SID information announced by the primary node also carries link information, the backup node matches the SID network programming function type with the SID network programming function type possessed by the backup node; if the SID network programming function type matches the SID network programming function type possessed by the backup node successfully, the backup node matches the link information with the link information possessed by the backup node; if the link information matches the link information possessed by the backup node successfully, a protection entry is generated.

[0052] Specifically, after the backup node receives the link information carried in the SID information sent by the master node, the backup node matches the SID network programming function type with the SID network programming function type it possesses, and matches the link information with the link information it possesses. If both matches are successful, the backup node generates the protection entry and instructs the message to be sent to the target object along the link.

[0053] In an exemplary embodiment, if the primary node is not faulty, but the link connecting the primary node to the VPN network is faulty, the backup node receives a target packet encapsulated by the primary node in a preset manner. The target packet includes a VPN SID assigned by the primary node to the VPN network. If the VPN SID matches a protection entry, the backup node forwards the received packet according to the protection entry. If the primary node and the link connected to it are not faulty, other nodes send the packet to the primary node. If the primary node and the link connected to it are faulty, other nodes send the packet directly to the backup node. These other nodes are nodes other than the primary node and the backup node.

[0054] This can be understood as follows: To prevent loops, if the primary node's link fails, traffic forwarded to the primary node will detect the failure. The primary node will then forward the packet to the backup node, carrying the VPN SID assigned to it. To ensure the packet isn't retransmitted back to the primary node during forwarding, the primary node cannot directly use the VPN SID for forwarding. Instead, it sends the packet carrying the VPN SID to the backup node via an additional encapsulated path or tunnel. Upon receiving the traffic, the backup node will check the protection entry for the primary node's VPN SID. The protection entry's action is as follows: if the backup node's link is valid, it will forward the traffic to the target; otherwise, it will discard the packet.

[0055] Specifically, the above encapsulation method can be as follows: the VPN SID is encapsulated in the innermost layer of the tunnel and forwarded by matching the tunnel through the tunnel policy configured on the master node or by the preset conditions in the BGP route. When the forwarding tunnel is an SR path, the VPN SID is added to the last SID list for forwarding; or forwarding is performed by IP in IP, with the destination IP of the outer IP header filled with the PE3 BGP connection address and the destination IP of the inner IP header filled with the local VPN SID. This embodiment of the invention does not limit the encapsulation method of the VPN SID.

[0056] To better understand the process of the above fault protection method, the following explanation of the above technical solution is provided in conjunction with optional embodiments, but it is not intended to limit the technical solution of the embodiments of the present invention.

[0057] The following explanations of the terms used in the optional embodiments of the present invention are provided to facilitate a better understanding of the solutions in these optional embodiments.

[0058] SR is a source address-based routing method that uses a segment routing header (SRheader) in the header of existing Multi-Protocol Label Switching (MPLS) networks or Internet Protocol Version 6 (IPv6) packets. The SRH contains a series of instruction operations (also known as segment operations) for data routing and transmission in the network.

[0059] An SRv6 segment is a 128-bit number, often referred to as an SRv6 SID or SID. The core idea of ​​SRv6 network programming is to treat the SRv6 SID as a network instruction. It consists of a Locator, a Function, and an optional Argument. The Locator primarily handles routing functions and therefore must be unique within the SR domain. The Function can identify any function of the device, such as a forwarding action or a specific service. The structure of the SRv6 SID is more conducive to network programming.

[0060] SRv6 VPN (SRv6-based Virtual Private Network) mainly refers to the transmission of VPN data based on SRv6 tunnels. SRv6 tunnels include SRv6 BE and SRv6-TE tunnels. SRv6 Service SID refers to a SID on the PE with specific business behavior, such as finding a specific VRF or forwarding to a specific next hop.

[0061] The following explanation of the fault protection method is based on several optional embodiments, but is not intended to limit the technical solutions of the embodiments of the present invention.

[0062] Example 1:

[0063] Figure 3 This is a schematic diagram of the intermediate node protection network of the fault protection method according to an optional embodiment of the present invention, as shown below. Figure 3 As shown, intermediate node P2 is the master node and P3 is the backup node. The prefix of P2 is LOC2, and an END type segment identifier SID21 is assigned to P2. An END.X type SID22 is assigned to link P2-PE4. Similarly, the prefix of P3 is LOC3, and an END type SID31 is assigned to P3. An END.X type SID32 is assigned to link P3-PE4. Protection relationships are configured on P3.

[0064] P3 acts as a backup node for P2, and the protection relationship is configured using at least one of the following methods:

[0065] Method 1: Configure by prefix;

[0066] Specifically, in an optional embodiment of the present invention, P3 needs to protect the segment identifier (SID) on P2. A prefix to be protected is configured on P3, covering the SID to be protected. The number of prefixes is not limited; it can be one or more prefixes. In this embodiment, the prefix of P2 is LOC2. Therefore, the protection relationship configured on P3 is the prefix LOC2 of P2. After configuring the SID protection relationship on P3, LOC2 is flooded out with low priority via IGP (Interior Gateway Protocol), BGP, etc., forming an Anycast Fast Rerouting (ARR) on P, where the primary node is P2 and the backup node is P3. The SID information on P2 is advertised via IGP, etc. The advertisement message includes the Locator prefix corresponding to the SID and information such as the SID type. When P3 discovers that the learned P2 Locator Prefix is ​​the same as or included in the locally configured SID protection prefix, it generates a corresponding RemoteSID entry based on the type of the P2 SID. For example, for SID21 of type END, a Remote END SID entry is generated; for SID22 of type END.X, PE3 finds that SID22 is assigned to link PE2-PE4, and PE3, as the protection node of PE2, also exists on the link to PE4, so a Remote END.X SID entry is generated, and the action is to send the packet to PE4.

[0067] It should be noted that after configuring the protection relationship, if the SID of the primary node's notification is within the protection range, but the backup node does not have the protection capability, actions such as discarding packets and generating alarms can be taken. These actions may be default or configurable.

[0068] Method 2: Configure by node.

[0069] Specifically, in an optional embodiment of the present invention, P3 needs to protect the SID on P2. The node to be protected is configured on P3, which is P2 in this embodiment. Optionally, protection can also be added for specific types of SIDs (equivalent to the SID network programming function type in the above embodiments), such as protecting only END type SIDs. The SID information on P2 will be advertised through IGP (Interior Gateway Protocol) and other means. The advertisement message contains the Locator prefix corresponding to the SID and the function type of the SID. When P3 learns the P2 Locator prefix, and P2 is the node to be protected, and the SID of this type is the type to be protected, then a corresponding Remote SID entry is generated according to the SID type of P2, and then the PE2 Locator prefix is ​​flooded out with low priority through IGP (Interior Gateway Protocol).

[0070] For the same prefix LOC2, P received two announcement messages. The entry with higher priority is the destination address LOC2 and the next hop is P2; the entry with lower priority is the destination address LOC2 and the next hop is P3.

[0071] Correspondingly, when the backup node no longer has the ability to protect a specific node, prefix, or SID, it can choose to revoke the already announced information.

[0072] Normally, when CE1 sends traffic to CE2, the routing prefix corresponding to the SID advertised by P2 has higher priority, such as the corresponding segment list.<SID-PE1,SID-P,SID21,SID-PE4> When P2 fails, the packet arrives at P with a destination address of SID21, hitting a lower-priority prefix entry, and will be sent to P3. The packet hits a Remote ENDSID entry and continues forwarding. If the corresponding segment list is...<SID-PE1,SID-P,SID22,SID-PE4> The message hits the Remote END.X SID entry and continues to be forwarded, sending the message to PE4 along the link P3-PE4.

[0073] The SID types mentioned above are just examples and are not limited to protecting the END and END.X types.

[0074] Example 2:

[0075] Figure 4 This is a schematic diagram of a service chain protection scenario for a fault protection method according to an optional embodiment of the present invention, such as... Figure 4As shown, CE1 needs to pass through the firewall to send data to CE2. Under normal circumstances, the service flow is CE1->PE1->P->P2->FW->P2->PE4->CE2. The firewall FW is a device that does not support SRv6. P2 and P3 have SRv6 proxy functions (such as END.AS), which can replace the FW in processing SRv6 packets. Before the packet is sent to the FW, the SRv6 packet header is stripped. After the FW processes the packet and sends it back to the proxy, the proxy re-encapsulates the SRv6 packet header and continues to forward it.

[0076] In Example 2, protection relationships are configured on P3. P3 needs to protect the SID (Segment Identifier) ​​on P2. The node P2 to be protected is configured on P3, specifying that only static proxy type SIDs are protected. The SIDs of the service chain proxy type on P2 will be advertised through various methods, such as IGP (Interior Gateway Protocol) or BGP (Border Gateway Protocol). The advertisement message includes the SID's function type and may also include the service function information corresponding to the SR proxy. In this example, the service function is a firewall. When P3 learns the SID information advertised by P2, and P2 is the node to be protected, and the static proxy type SID is the type to be protected, if the advertisement message also carries the service function information corresponding to the SR proxy (firewall), P3 will further match the service function information with the service function information it possesses. If all the above information matches, a corresponding Remote END.AS SID entry is generated, and then the Locator prefix corresponding to the P2 SID is flooded out with low priority through methods such as IGP (Interior Gateway Protocol).

[0077] Example 3:

[0078] Figure 5 This is a schematic diagram of a tail node / link fault protection network according to an optional embodiment of the fault protection method of the present invention, as shown below. Figure 5 As shown, it should be noted that the prefixes on PE1, PE2, and PE3 are LOC1, LOC2, and LOC3, respectively; IPv6 VPN neighbors are deployed between PE1 and PE2, PE1 and PE3, and PE2 and PE3. VPN instance VPN1 is configured on PE2 and PE3, carrying the RT (remote) parameter and SRv6 VPN SID. The VPN SIDs on PE2 and PE3 are assigned as SID2 and SID3, respectively; after receiving the private network route published by CE2, PE2 encapsulates it into a VPN route and sends it to PE3. The route carries the VPN SID, RT, RD, and possible constraints.

[0079] In an SR-TE scenario, CE1 sends traffic to CE2 sequentially through PE1, P, and PE2 along a designated SR-TE tunnel. The possible format of the message sent by PE1 is: DA = SID-P, SRH<SID-PE1,SID-P,SID-PE2,SID2;SL=3> SID-PE1, SID-P, and SID-PE2 correspond to the SIDs on PE1, P, and PE2, respectively.

[0080] In Example 3, PE3 needs to protect the SID on PE2. The prefix to be protected is configured on PE3, covering the SID to be protected. This prefix can be one or more prefixes; in this example, it's LOC2. After configuring SID protection on PE3, LOC2 is flooded out with low priority via IGP (Interior Gateway Protocol), forming an Anycast FRR on P. The primary node is PE2, and the backup node is PE3. After receiving the VPN route from PE2, PE3 cross-connects to VPN1 according to RT. PE3 uses the VPN SID information of the remote route and performs a longest-last-match test with the prefix address in the SID protection configuration. If a match is found, a Remote SRv6 VPN SID entry is generated, and the forwarding behavior is to forward the traffic to CE2. SIDs on PE2 other than the VPN SID are advertised via IGP. The advertisement message includes the Locatorprefix corresponding to the SID and the function type of the SID. When PE3 detects that the learned PE2 Locator prefix is ​​the same as the locally configured SID protection prefix, it generates a corresponding Remote SID entry based on the type of PE2SID. For example, if an END type SID exists on PE2, then the END SIDs within the PE2 Locator range will be used to generate a Remote SRv6END SID entry locally, with the function being of type END.

[0081] After configuring the protection relationship on the standby node, under normal circumstances, the traffic path is CE1-PE1-P-PE2-CE2, and the packets sent by PE1 are DA=SID-P,SRH.<SID-P,SID-PE2,SID2;SL=2> When PE2 node fails, P detects that the next hop of PE2 is unreachable, switches to the FRR path, and forwards traffic to PE3. At this time, the packet sent by P is DA = SID - PE2, SRH.<SID-PE1,SID-P,SID-PE2,SID2;SL=1> PE3 reads the packet, parses it and finds that SID-PE2 matches the Remote SRv6 END SID. It first executes the END operation, and the next SID to be processed is SID2, which matches the Remote SRv6 VPN SID, thus forwarding the traffic to CE2.

[0082] Example 4:

[0083] In the SR-BE scenario, PE1 forwards the traffic sent from CE1 to CE2 via the SR-BE tunnel. The traffic is forwarded via the SR-BE tunnel, and the destination address of the packets sent by PE1 is directly the VPN SID (SID2). The nodes along the way forward the traffic according to the IPv6 forwarding table. After PE2 fails, the traffic is transferred to the PE3 node, and SID2 directly matches the Remote SRv6 VPN SID, thus forwarding the traffic to CE2.

[0084] Example 5:

[0085] After PE3 receives the private network route from PE2, it cross-connects it to VPN1 according to the RT, forming a PE Protection Direct Connection Fast Rerouting (FRR) entry. The primary next hop is CE2, the backup next hop is PE2, and it carries the PE2 VPN SID. After PE2 receives the private network route, it cross-connects it to VPN1 according to the RT, forming a PE Protection Direct Connection Fast Rerouting (FRR) entry. The primary next hop is CE2, the backup next hop is PE3, and it carries the PE3 VPN SID. When both the PE2-CE2 and PE3-CE2 links fail simultaneously, traffic forwarded from P is first sent to PE2. PE2 detects the link failure and triggers the PE Protection CE FRR switch, forwarding the traffic to PE3 using the SID advertised by PE3. Upon receiving the traffic, PE3 also detects a local link failure and sends the packet back to PE2, causing a traffic loop. Therefore, the tail node link failure protection scheme needs to consider preventing loops.

[0086] This embodiment is mainly based on the primary node detecting a link failure and triggering the primary node protection CE FRR switch. After that, the primary node forwards traffic to the backup node using its own SID. After receiving the SID, the backup node matches the Remote SID protection entry. If the Remote SID entry is valid, it continues to forward the traffic according to the entry. If the Remote SID entry is invalid, the packet is directly discarded.

[0087] PE3 acts as the protection node for PE2. Protection relationships are configured on PE3 and a Remote VPN SID entry is generated. PE2 receives private network routes from CE2. In addition, after receiving private network routes from CE2, PE3 encapsulates them into VPN routes and sends them to PE2. After receiving the routes from PE3, PE2 cross-connects them to VPN1 according to RT, thus forming a PE protection direct connection FRR entry. The primary next hop is CE2, the backup next hop is PE3, and it carries the local VPN SID2.

[0088] In the event of a failure in the PE2-CE2 link, after traffic is forwarded to PE2, the main link failure is detected in the FRR table entry, and the traffic is forwarded to PE3. When forwarding, the VPN SID used is the VPN SID2 assigned locally by PE2. When PE2 forwards traffic to PE3, in order to ensure that the traffic is not sent back to PE2 by other nodes during the forwarding process, the packets sent by PE2 cannot be directly forwarded with VPN SID2 as the destination address. Instead, the VPN SID can be encapsulated in the innermost layer of the tunnel through the tunnel policy configured on PE2 or by matching the tunnel color in the BGP route, or forwarded via IP in IP. The destination IP of the outer IP header is filled with the PE3 BGP link establishment address, and the destination IP of the inner IP header is filled with the local VPN SID. That is, the additional encapsulation of forwarding information is responsible for sending the packet to PE3, and the inner VPN SID is responsible for preventing loops. After PE3 receives the packet, VPNSID2 matches the local Remote VPN SID entry. If the link between PE3 and CE2 is valid, the traffic is forwarded to CE2. If the link between PE3 and CE2 is also faulty, the packet is discarded.

[0089] In the above embodiments, after the first node (backup node) receives the SID information announced by the second node (primary node), if the SID information matches the protection information, it generates a corresponding remote SID protection entry. The remote SID protection entry provides the same functionality as the original SID, such as END, END.X, END.DT4, END.AS, etc. The first node needs to flood the prefix that covers the second node's SID externally through protocols such as IGP (Interior Gateway Protocol), with a lower priority than the second node's own flooding priority. This allows the upstream protection node to switch over in case of failure, even when it only has basic IPv6 routing and forwarding functions, and the backup path can provide the same functionality as the primary path. Specifically, when the method of the above optional embodiments is used for fault protection of the tail node link in the SRv6VPN scenario, the master node receives the VPN route advertised by the CE and the backup node, generates an FRR entry, where the primary next hop is the CE and the backup next hop is the backup node, carrying the master node's own VPN SID; after the primary link fails, the master node additionally encapsulates forwarding information to send the packet to the backup node, carrying its own VPN SID to prevent loops; after the backup node receives the packet, the VPN SID matches the remote SID entry, and if the backup link also fails, the packet is discarded, thereby achieving the purpose of preventing loops.

[0090] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0091] This embodiment also provides a fault protection device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, hardware implementations, or a combination of software and hardware, are also possible and contemplated.

[0092] Figure 6 This is a structural block diagram of a fault protection device according to an embodiment of the present invention, such as... Figure 6 As shown, the device includes:

[0093] Configuration module 62 is used to configure protection relationships on the standby node, wherein the protection relationships are used to indicate the objects that the standby node needs to protect;

[0094] The receiving module 64 is used to receive the segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value;

[0095] It should be noted that if the SID does not explicitly specify the network programming function type, but has a default network programming function type END, then the SID information is also considered to contain network programming function type information.

[0096] The matching module 66 is used to match the SID network programming function type with the SID network programming function type of the backup node, and to match the SID value with the protection relationship. If the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated.

[0097] Forwarding module 68 is used to forward received packets to the backup node according to the protection table entry in the event of a failure of the primary node or the link connected to the primary node. In the event that the primary node and the link connected to the primary node are not at fault, other nodes send the packets to the primary node. In the event that the primary node and the link connected to the primary node are at fault, other nodes send the packets directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

[0098] Through the above technical solution, protection relationships are configured on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect; segment identifier (SID) information announced by the master node is received, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value; the SID network programming function type is matched with the SID network programming function type possessed by the backup node, and the SID value is matched with the protection relationship; if the SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated; if the master node or the link connected to the master node fails, the backup node forwards the received packets according to the protection entry, wherein if the master node and the link connected to the master node do not fail, other nodes send the packets to the master node. In the event of a failure of the primary node and the link connected to the primary node, other nodes directly send the message to the backup node. These other nodes are those other than the primary and backup nodes. Specifically, by configuring a protection relationship on the backup node, and ensuring that the SID network programming function type matches the backup node's SID network programming function type and the SID value matches the protection relationship, a protection entry is generated. Then, in the event of a failure of the primary node or the link connected to the primary node, the backup node forwards the received message according to the protection entry. This technical solution solves the problem in related fault protection technologies where intermediate node protection and tail node protection typically employ different technologies, leading to difficulties in equipment deployment. The technical solution of this invention is applicable to fault protection of both intermediate and exit nodes, and the switched path after a failure can provide the same functionality as the original path.

[0099] It should be noted that the solution of this invention is only applicable to networks where both primary and backup nodes support SRv6, excluding SR-MPLS scenarios. Furthermore, other nodes in the network do not necessarily need to support SRv6. After configuring protection relationships on the backup node, if the SID information received by the backup node from the primary node is within the protection range, but the backup node lacks protection capabilities, it can perform actions such as discarding packets or generating alarms. These actions can be default or configured according to requirements.

[0100] Optionally, the configuration module is also used to configure protection relationships on the backup node by configuring the prefix of the master node to be protected on the backup node; configuring the master node to be protected on the backup node; configuring the segment identifier SID value of the master node to be protected on the backup node; configuring the SID network programming function type of the master node to be protected on the backup node, etc.

[0101] In other words, when configuring protection relationships on a backup node, the prefix of the primary node to be protected can be configured on the backup node. The prefix can cover the SID of the primary node to be protected. The prefix of the primary node to be protected configured on the backup node can be one or more prefixes. For example, if the primary node's prefix is ​​LOC2, then the primary node to be protected can be configured with the prefix LOC2. Alternatively, the primary node to be protected can be configured on the backup node. Alternatively, the segment identifier SID value of the primary node to be protected can be configured on the backup node. In addition, the network programming function type of the SID of the primary node to be protected can be configured on the backup node. For example, if the primary node's SID type is END, then the SID of type END to be protected can be configured on the backup node. This invention does not limit the SID information, the primary node's prefix, etc.

[0102] In one exemplary embodiment, the above apparatus further includes: a flooding module, which instructs the backup node to flood the prefix of the master node externally with a low priority, wherein the low priority is lower than the priority when the master node floods itself.

[0103] In other words, the master node announces the segment identifier (SID) information on the master node. The announcement method can be IGP (Interior Gateway Protocol) or other methods, which are not limited in this embodiment of the invention. The announcement message includes the segment identifier (SID) value and the type of segment identifier (SID) information. When the segment identifier (SID) information announced by the master node matches the protection relationship stored by the backup node, the backup node floods the prefix of the master node with a lower priority than the master node itself. The flooding method can be IGP (Interior Gateway Protocol) or BGP, which are not limited in this embodiment of the invention, so that the traffic is first sent to the master node, and in the event of a failure of the master node, the traffic is forwarded to the backup node again.

[0104] Furthermore, the aforementioned device also includes a revocation module, used to instruct the backup node to flood the prefix of the master node with a low priority, and then, if the backup node no longer has the ability to protect the prefix on the master node, the master node, the segment identifier SID value on the master node, or the SID network programming function type on the master node, the backup node will revoke the flooded prefix of the master node, and thus the backup node will no longer have the protection relationship.

[0105] Optionally, the matching module is further configured to: when the SID information announced by the primary node also carries service function information, and when the SID network programming function type is segment routing SR proxy function, match the backup node's SID network programming function type with the segment routing SR proxy function; when the backup node's SID network programming function type matches the segment routing SR proxy function, match the backup node's SR proxy service function information with the service function information corresponding to the primary node's segment routing SR proxy function; and when the backup node's SR proxy service function information and the primary node's segment routing SR proxy function are successfully matched, generate the protection entry.

[0106] Specifically, if the notification message also carries the SID network programming function type as segment routing SR proxy function, the segment routing SR proxy function is first matched. If the backup node also has SR proxy function, the match is successful. Then, the business function information corresponding to the SR proxy function needs to be matched. If the backup node also has the corresponding business function information, the match is successful, and a protection entry can be generated. It should be noted that if either the primary node's SR proxy function or the corresponding business function information does not match, a protection entry cannot be generated. After the corresponding protection entry is generated, the prefix corresponding to the primary node is flooded out with low priority through methods such as IGP (Interior Gateway Protocol). For example, if the business function information corresponding to the segment routing SR proxy is a firewall, the backup node will further match the firewall type with the business function information it possesses. If both match, the corresponding protection entry is generated.

[0107] Furthermore, if the firewall node represents a device that does not support SRv6, the primary and backup nodes have proxy functions, which means they can process packets in place of the firewall. Before the packet is sent to the firewall node, the packet header is stripped off. After the firewall processes the packet and sends it back to the proxy, the proxy re-encapsulates the packet header and continues to forward it.

[0108] In an exemplary embodiment, the matching module is further configured to, when the SID information announced by the primary node also carries VPN service information, further include: after the backup node receives the VPN route encapsulated by the primary node, matching the network programming function type in the VPN route with the SID network programming function type possessed by the backup node; if the network programming function type in the VPN route matches the SID network programming function type possessed by the backup node, matching the VPN service information possessed by the backup node's SID network programming function with the VPN service information corresponding to the SID network programming function type in the primary node's VPN route; and if the VPN service information possessed by the backup node's SID network programming function matches the VPN service information corresponding to the SID network programming function type in the primary node's VPN route, generating the protection entry.

[0109] Specifically, after the backup node receives the VPN route sent by the master node, the backup node performs a longest match based on the VPN SID information in the VPN route and the prefix address in the protection relationship. If the VPN service information possessed by the backup node matches the VPN service information in the VPN route, the backup node generates the protection entry and forwards the traffic to the target object.

[0110] Optionally, the matching module is further configured to, when the SID information announced by the primary node also carries link information, match the SID network programming function type with the SID network programming function type possessed by the backup node; if the SID network programming function type successfully matches the SID network programming function type possessed by the backup node, match the link information with the link information possessed by the backup node; and if the link information successfully matches the link information possessed by the backup node, generate a protection entry.

[0111] Specifically, after the backup node receives the link information carried in the SID information sent by the master node, the backup node matches the SID network programming function type with the SID network programming function type it possesses, and matches the link information with the link information it possesses. If both matches are successful, the backup node generates the protection entry and instructs the message to be sent to the target object along the link.

[0112] In an exemplary embodiment, the forwarding module is further configured to, in the case where the primary node is not faulty but the link connecting the VPN network to which the primary node is connected is faulty, receive a target packet encapsulated in a preset manner by the primary node, wherein the target packet includes: a VPNSID assigned by the primary node to the VPN network; if the VPN SID matches the protection entry, the backup node forwards the received packet according to the protection entry, wherein, when the primary node and the link connected to the primary node are not faulty, other nodes send the packet to the primary node; when the primary node and the link connected to the primary node are faulty, other nodes send the packet directly to the backup node, wherein the other nodes are nodes other than the primary node and the backup node.

[0113] This can be understood as follows: To prevent loops, if the primary node's link fails, traffic forwarded to the primary node will detect the failure. The primary node will then forward the packet to the backup node, carrying the VPN SID assigned to it. To ensure the packet isn't retransmitted back to the primary node during forwarding, the primary node cannot directly use the VPN SID for forwarding. Instead, it sends the packet carrying the VPN SID to the backup node via an additional encapsulated path or tunnel. Upon receiving the traffic, the backup node will check the protection entry for the primary node's VPN SID. The protection entry's action is as follows: if the backup node's link is valid, it will forward the traffic to the target; otherwise, it will discard the packet.

[0114] Specifically, the above encapsulation method can be: by matching the tunnel through the tunnel policy configured on the master node or by matching the Yushu condition in the BGP route, the VPN SID is encapsulated in the innermost layer of the tunnel for forwarding; or by forwarding in the IP-in-IP manner, the destination IP of the outer IP header is filled with the PE3 BGP connection address, and the destination IP of the inner IP header is filled with the local VPN SID. This embodiment of the invention does not limit the encapsulation method of the VPN SID.

[0115] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0116] Embodiments of the present invention also provide a storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.

[0117] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:

[0118] S1, Configure protection relationships on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect;

[0119] S2, Receive the segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value;

[0120] S3, match the SID network programming function type with the SID network programming function type of the backup node, match the SID value with the protection relationship, and generate a protection entry if the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched.

[0121] S4, in the event of a failure in the primary node or the link connected to the primary node, the backup node forwards the received message according to the protection entry. Wherein, if the primary node and the link connected to the primary node are not at fault, other nodes send the message to the primary node. If the primary node and the link connected to the primary node are at fault, other nodes send the message directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

[0122] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0123] Embodiments of the present invention also provide an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.

[0124] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0125] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:

[0126] S1, Configure protection relationships on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect;

[0127] S2, Receive the segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value;

[0128] S3, match the SID network programming function type with the SID network programming function type of the backup node, match the SID value with the protection relationship, and generate a protection entry if the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched.

[0129] S4, in the event of a failure in the primary node or the link connected to the primary node, the backup node forwards the received message according to the protection entry. Wherein, if the primary node and the link connected to the primary node are not at fault, other nodes send the message to the primary node. If the primary node and the link connected to the primary node are at fault, other nodes send the message directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

[0130] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0131] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated here.

[0132] It is obvious to those skilled in the art that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented herein, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the present invention is not limited to any particular combination of hardware and software.

[0133] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the invention by those skilled in the art. Any modifications, equivalent substitutions, or improvements made within the principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A fault protection method, characterized in that, include: Configure protection relationships on the backup node, wherein the protection relationships are used to indicate the objects that the backup node needs to protect; Receive segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value; The SID network programming function type is matched with the SID network programming function type of the backup node, and the SID value is matched with the protection relationship. If the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated. In the event of a failure of the primary node or the link connected to the primary node, the backup node forwards the received message according to the protection table entry. If the primary node and the link connected to the primary node are not at fault, other nodes send the message to the primary node. If the primary node and the link connected to the primary node fail, other nodes send the message directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

2. The method according to claim 1, characterized in that, Configure protection relationships on the standby node, including at least one of the following: Configure the prefix on the backup node that needs to be protected, which is the same as the prefix on the primary node. Configure the primary node that needs protection on the backup node; Configure the segment identifier (SID) value on the standby node that needs to be protected, which is the same as the SID value on the primary node. Configure the SID network programming feature type on the standby node that needs to be protected, which is the same as the SID on the primary node.

3. The method according to claim 1, characterized in that, After the SID network programming function type and the backup node's SID network programming function type, as well as the SID value and the protection relationship, are successfully matched, the method further includes: The backup node is instructed to flood the prefix of the master node externally with a low priority, wherein the low priority is lower than the priority when the master node floods itself.

4. The method according to claim 3, characterized in that, After instructing the backup node to flood the prefix of the primary node externally with low priority, the method further includes: If the backup node no longer has the ability to protect the prefix on the master node, the master node, the segment identifier SID value on the master node, or the SID network programming function type on the master node, the backup node shall remove the prefix of the master node from external flooding.

5. The method according to claim 1, characterized in that, If the SID information announced by the master node also carries business function information, the method further includes: When the SID network programming function type is segment routing SR proxy function, the SID network programming function type of the backup node is matched with the segment routing SR proxy function; If the SID network programming function type of the backup node matches the segment routing SR proxy function, the service function information of the backup node SR proxy is matched with the service function information corresponding to the segment routing SR proxy function of the primary node. If the service function information of the backup node SR agent is successfully matched with the service function information corresponding to the segment routing SR agent function of the primary node, the protection entry is generated.

6. The method according to claim 1, characterized in that, If the SID information announced by the master node also carries VPN service information, the method further includes: After the backup node receives the VPN route encapsulated by the master node, it matches the SID network programming function type in the VPN route with the SID network programming function type possessed by the backup node. If the SID network programming function type in the VPN route matches the SID network programming function type of the backup node, the VPN service information of the backup node's SID network programming function is matched with the VPN service information corresponding to the SID network programming function type in the VPN route of the master node. The protection entry is generated when the VPN service information provided by the backup node's SID network programming function matches the VPN service information corresponding to the SID network programming function type in the VPN route of the master node.

7. The method according to claim 1, characterized in that, If the SID information announced by the master node also carries link information, the method further includes: The backup node matches the SID network programming function type with the SID network programming function type possessed by the backup node; If the SID network programming function type is successfully matched with the SID network programming function type of the backup node, the backup node will match the link information with the link information of the backup node. If the link information matches the link information of the backup node, a protection entry is generated.

8. The method according to claim 6, characterized in that, If the master node does not fail, but the link connecting the VPN network to which the master node is connected fails, the method further includes: The backup node receives a target message sent by the master node and encapsulated in a preset manner, wherein the target message includes: the VPN SID assigned by the master node to the VPN network; If the VPN SID matches the protection entry, the backup node forwards the received packet according to the protection entry. If the primary node and the link connected to the primary node are not faulty, other nodes send the packet to the primary node. If the primary node and the link connected to the primary node are faulty, other nodes send the packet directly to the backup node. The other nodes are nodes other than the primary node and the backup node.

9. A fault protection device, characterized in that, include: A configuration module is used to configure protection relationships on a standby node, wherein the protection relationship is used to indicate the objects that the standby node needs to protect. The protection relationship is also used to indicate that in the event of a failure of the primary node, the standby node will forward the packets received by the primary node. The receiving module is used to receive the segment identifier (SID) information announced by the master node, wherein the segment identifier (SID) information includes at least: SID network programming function type and SID value; The matching module is used to match the SID network programming function type with the SID network programming function type of the backup node, and to match the SID value with the protection relationship. If the SID network programming function type and the backup node's SID network programming function type and the SID value and the protection relationship are both successfully matched, a protection entry is generated. The forwarding module is used to instruct the backup node to forward the received packets according to the protection table entry in the event of a failure of the primary node or the link connected to the primary node. In the event that the primary node and the link connected to the primary node are not at fault, other nodes send the packets to the primary node. In the event that the primary node and the link connected to the primary node are at fault, other nodes send the packets directly to the backup node. These other nodes are nodes other than the primary node and the backup node.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the method described in any one of claims 1 to 8 when it is run.

11. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to perform the method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method, network node and system for determining message forwarding path

    CN109981458A

  • Transmission path fault processing method, device and system

    CN110661706A