A High-Performance Kernel-Bypass Transparent Proxy System
By adopting transparent proxy technology with multi-process mode and user-state protocol stack in the proxy system, the performance loss problem caused by the traditional kernel protocol stack is solved, and the linear relationship between hardware performance improvement and proxy system performance improvement is achieved.
Patent Information
- Application Number
- CN202110331100.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-26
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2041-03-26
AI Technical Summary
Traditional transparent middlemen use the kernel protocol stack, resulting in lock conflicts and switching performance loss between user state and kernel state, making it difficult to improve the performance of the proxy system.
A transparent proxy system that uses data shunt and user-state protocol stack in multi-process mode, diversion of data packets by diversion processes and work processes, and creates virtual network cards in user-state and sets virtual IP addresses to realize TCP connection and data transmission proxy.
By improving hardware performance, linearly improving the performance of the proxy system, the performance losses caused by the kernel protocol stack are avoided.
Smart Images

Figure CN113079209B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and particularly to a high-performance Kernel-Bypass transparent proxy system. Background Art
[0002] With the popularization of the SSL / TLS protocol, network DLP systems need to take over all data traffic in order to inspect the data. Currently, traditional transparent middlemen use the kernel protocol stack to implement TCP connection proxy. However, due to lock conflicts in the use of the kernel protocol stack and performance losses caused by the switching between the user space and the kernel space, it is very difficult to improve performance, including local modification algorithms or increasing the hardware specifications.
[0003] Therefore, a proxy system is needed that can linearly increase performance by increasing the hardware specifications. Summary of the Invention
[0004] To solve the above technical problems, the present invention provides a high-performance Kernel-Bypass transparent proxy system that linearly improves the performance of the proxy system by enhancing the hardware performance.
[0005] A high-performance Kernel-Bypass transparent proxy system of the present invention includes data shunting in a multi-process mode and a transparent proxy using a user-space protocol stack;
[0006] The data shunting in the multi-process mode is divided into a shunting process and a working process. The shunting process receives data packets through the receive queue of the network card and shunts the data packets to different working processes through a shunting algorithm;
[0007] The transparent proxy using the user-space protocol stack creates a virtual network card through the user-space protocol stack. A virtual IP address is set on the virtual network card. A TCP proxy session is divided into four directions, and the four directions respectively correspond to four conversions. The four conversions are: c2p, the destination address is replaced with the proxy IP; p2c, the source address is replaced with the Server IP; p2s, the source address is replaced with the Client IP; and s2p, the destination address is replaced with the proxy IP.
[0008] A high-performance Kernel-Bypass transparent proxy system of the present invention, the establishment of a TCP connection includes the following steps:
[0009] S1. The client initiates a TCP connection, and the data packet is: from the client to the server, SYN;
[0010] S2. The transparent proxy module determines that it is a SYN packet, queries the ACL table, and determines that this connection requires proxy. Then, according to the four-tuple information in the data packet and the information in the ACL table, it creates c2p and p2c tables;
[0011] S3. After the transparent proxy accepts the connection from the client, it creates p2s and s2p tables according to the address information returned by the client and the server address information.
[0012] S4. Then the transparent proxy initiates a connection to the server. The address information at this time is: proxy address to server address.
[0013] S5. The transparent proxy modifies the data in the data packet according to the previously established p2s table entry, and modifies it to: client address to server address, and sends it to the server.
[0014] A high-performance Kernel-Bypass transparent proxy system of the present invention, wherein the TCP data transmission includes the following steps:
[0015] Client to server process:
[0016] 1). For the data sent from the client to the server, the address in the data packet is: client address to server address.
[0017] 2). The bridge queries the c2p table, replaces the address in the data packet with: client address to proxy address, and then sends the data to the proxy.
[0018] 3). The data is processed sequentially through each protocol module from bottom to top, and then processed sequentially through each protocol module from top to bottom, and sent to the bridge through the system protocol stack. At this time, the address in the data packet is: proxy address to server address.
[0019] 4). The bridge queries the p2s table, replaces the address in the data packet with: client address to server address.
[0020] Server to client process:
[0021] a). For the data sent from the server to the client, the address in the data packet is: server address to client address.
[0022] b). The bridge queries the s2p table, replaces the address in the data packet with: server address to proxy address, and then sends the data to the proxy.
[0023] c). The data is processed sequentially through each protocol module from bottom to top, and then processed sequentially through each protocol module from top to bottom, and sent to the bridge through the system protocol stack. At this time, the address in the data packet is: proxy address to client address.
[0024] d). The bridge queries the p2c table, replaces the address in the data packet with: server address to client address.
[0025] The beneficial effects of the present invention compared with the prior art are as follows: By improving the hardware performance, the performance of the proxy system is linearly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 is the logical flowchart of data shunting in the multi-process mode of the present invention;
[0027] Figure 2 is the logical flowchart of the TCP connection establishment phase of the present invention;
[0028] Figure 3 is the logical flowchart of the TCP data transmission phase of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0029] The following combines the drawings and embodiments to further describe in detail the specific implementation manners of the present invention. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0030] The technical solution of a high-performance Kernel-Bypass transparent proxy system includes two aspects: data shunting in the multi-process mode and transparent proxy using a user-space protocol stack;
[0031] Data shunting in the multi-process mode
[0032] As Figure 1 shown, for performance considerations, the protocol stack used in the present invention is a user-space protocol stack. However, most of the existing user-space protocol stacks are modified from the protocol stacks of existing operating systems. For example, f-stack (FreeBSD) and lkl (Linux) have many global data structures that are not suitable for multi-threaded structures. Therefore, the present invention uses a multi-process structure.
[0033] The system is divided into a shunting process (Distributor) and a working process (Worker). The shunting process receives data packets through the receive queue of the network card and shunts the data packets to different working processes through a shunting algorithm. For example, Figure 1 shown, the system includes two multi-queue network cards (NIC0, NIC1). The read queue (rx) of each network card is 1, and the number of write queues (tx) is 3 (the number of write queues = the number of shunting processes + the number of working processes). There is one shunting process Distributor and two working processes worker0 and worker1;
[0034] Among them, the shunting algorithm is generally a user integrity algorithm, which uses the tcp syn source ip for hashing.
[0035] The specific steps of the data stream take Figure 1 as an example
[0036] 1. The shunting process first needs to be bound to CPU CORE0, and read the read queues rx0 of network card NIC0 and the read queue rx0 of network card NIC1 in real-time polling. Two work queues, worker0 and worker1, are respectively bound to CPU CORE1 and CPU CORE2;
[0037] 2. After the shunting process reads a data packet, it uses a shunting algorithm to determine which worker process (worker0 or worker1) the data packet is shunted to, and the data packet is transmitted to the worker process through a lock-free queue (ring) for inter-process communication;
[0038] 3. After the worker process receives the data packet through the lock-free queue (ring), it submits the data packet to the transparent proxy module. The transparent proxy module is responsible for the transparent processing of the data and the processing of the upper-layer user-mode protocol stack. After processing the data, the proxy may spit out data packets in two directions, one direction is NIC0, and the other direction is NIC1. The worker process will send the data packet to the corresponding send queue of the corresponding network card according to the sending direction of the data packet.
[0039] Transparent proxy using the user-mode protocol stack
[0040] TCP transparency principle
[0041] The user-mode protocol stack will create a virtual network card, and a virtual IP address will be set on the virtual network card, which we call the proxy IP. A TCP proxy session is divided into four directions, and these four directions respectively correspond to four conversion tables:
[0042]
[0043] TCP connection establishment phase
[0044] As Figure 2 shown:
[0045] 1. The client initiates a TCP connection, and the data packet is: (client to server, SYN);
[0046] 2. The transparent proxy module determines that it is a SYN packet, queries the ACL table, and determines that this connection requires proxy. Then, it creates c2p and p2c tables according to the quadruple information in the data packet and the information in the ACL table;
[0047] 3. After the transparent proxy accepts the client's connection (ACCEPT), it creates p2s and s2p tables according to the address information returned by the client and the server address information;
[0048] 4. Then the transparent proxy initiates a connection to the server, and the address information at this time is: proxy address to server address;
[0049] 5. The transparent proxy modifies the data in the data packet according to the previously established p2s entry, and the modification is: from the client address to the server address, and then sends it to the server.
[0050] TCP data transmission phase
[0051] As Figure 3 shown
[0052] Client-to-server process
[0053] 1. For the data sent from the client to the server, the address in the data packet is: from the client address to the server address;
[0054] 2. The bridge queries the c2p table, replaces the address in the data packet with: from the client address to the proxy address, and then sends the data to the proxy;
[0055] 3. The data is processed successively through each protocol module from bottom to top, and then processed successively through each protocol module from top to bottom, and is sent to the bridge through the system protocol stack. At this time, the address in the data packet is: from the proxy address to the server address;
[0056] 4. The bridge queries the p2s table and replaces the address in the data packet with: from the client address to the server address.
[0057] Server-to-client process
[0058] 1. For the data sent from the server to the client, the address in the data packet is: from the server address to the client address;
[0059] 2. The bridge queries the s2p table, replaces the address in the data packet with: from the server address to the proxy address, and then sends the data to the proxy;
[0060] 3. The data is processed successively through each protocol module from bottom to top, and then processed successively through each protocol module from top to bottom, and is sent to the bridge through the system protocol stack. At this time, the address in the data packet is: from the proxy address to the client address;
[0061] The bridge queries the p2c table and replaces the address in the data packet with: from the server address to the client address.
[0062] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and modifications can still be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. A high-performance Kernel-Bypass transparent proxy system, characterized in that, it includes data shunting in the multi-process mode and a transparent proxy using a user-space protocol stack; The data shunting in the multi-process mode is divided into a shunting process and a working process. The shunting process receives data packets through the receive queue of the network card and shunts the data packets to different working processes through a shunting algorithm; The transparent proxy using the user-space protocol stack creates a virtual network card through the user-space protocol stack. A virtual IP address is set on the virtual network card. A TCP proxy session is divided into four directions, and these four directions respectively correspond to four conversions. The four conversions are: c2p, replacing the destination address with the proxy IP; p2c, replacing the source address with the Server IP; p2s, replacing the source address with the Client IP; s2p, replacing the destination address with the proxy IP.
2. A high-performance Kernel-Bypass transparent proxy system according to claim 1, characterized in that, wherein the establishment of a TCP connection includes the following steps: S1. The client initiates a TCP connection, and the data packet is: from the client to the server, SYN; S2. The transparent proxy module determines that it is a SYN packet, queries the ACL table, and if it determines that this connection requires proxy, creates c2p and p2c tables according to the quadruple information in the data packet and the information in the ACL table; S3. After the transparent proxy accepts the connection from the client, it creates p2s and s2p tables according to the address information returned by the client and the server address information; S4. Then the transparent proxy initiates a connection to the server, and the address information at this time is: from the proxy address to the server address; S5. The transparent proxy modifies the data in the data packet according to the previously established p2s table entry, and modifies it to: from the client address to the server address, and sends it to the server.
3. A high-performance Kernel-Bypass transparent proxy system according to claim 2, characterized in that, wherein the TCP data transmission includes the following steps: Client-to-server process: 1). For the data sent from the client to the server, the address in the data packet is: from the client address to the server address; 2). The bridge queries the c2p table, replaces the address in the data packet with: from the client address to the proxy address, and then sends the data to the proxy; 3). The data is processed sequentially through each protocol module from bottom to top, and then processed sequentially through each protocol module from top to bottom, and is sent to the bridge through the system protocol stack. At this time, the address in the data packet is: from the proxy address to the server address; 4). The bridge queries the p2s table, replaces the address in the data packet with: from the client address to the server address; Server-to-client process: a). For the data sent from the server to the client, the address in the data packet is: from the server address to the client address; b). The bridge queries the s2p table, replaces the address in the data packet with: from the server address to the proxy address, and then sends the data to the proxy; c), The data is processed sequentially through each protocol module from bottom to top, and then processed sequentially through each protocol module from top to bottom, and sent to the bridge through the system protocol stack. At this time, the address in the data packet is: proxy address to client address; d), The bridge queries the p2c table and replaces the address in the data packet with: server address to client address.
Citation Information
Patent Citations
Transparent proxy and transparent proxy realization method
CN103491065A
System and method for user side to access intranet through VPN
CN103840994A