Routing processing method and device

By carrying role identification information in routing messages to set routing priorities, the problem of message forwarding errors caused by abnormal devices in centralized network architecture is solved, ensuring the normal operation and security of the network.

CN113556282BActive Publication Date: 2025-09-12HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010632264.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-04-23
Filing Date
2020-07-03
Publication Date
2025-09-12
Estimated Expiration
2040-07-03

AI Technical Summary

Technical Problem

In a centralized network architecture, the presence of abnormal devices prevents distributed devices from correctly sending messages to the central device, causing the network to malfunction.

Method used

By carrying role identification information in routing messages and using the role identification information to set routing priorities, abnormal devices and central devices can be distinguished to ensure correct message forwarding.

Benefits of technology

This ensures that when there are abnormal devices, distributed devices can correctly distinguish and send messages to the central device, improving the reliability and security of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113556282B_ABST
    Figure CN113556282B_ABST
Patent Text Reader

Abstract

The present application discloses a routing processing method and device, which includes: a first device receiving a first routing message sent by a second device, the first routing message carrying first role identification information, the first role identification information being used to indicate the role of the second device in the network, and the first routing message being used to publish a first route; the first device determining a first routing priority for the first route based on the first role identification information. By carrying the role identification information of the second device in the routing message, the first device can perceive the role of the second device in the network, thereby correspondingly setting the routing priority of the routes it publishes. Even if there are abnormal devices in the network, the first device can distinguish between the routes published by the abnormal device and the routes published by the second device, overcome the impact of the abnormal device on the network operation, enable the network to operate stably, improve the reliability of the network with a centralized network architecture, and thus achieve network security.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on April 23, 2020, with application number 202010326321.6, and invention name “A Communication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of network communication technology, and in particular to a routing processing method and device. Background Art

[0003] As network demands increase and the number of devices in a network continues to grow, many network deployments prioritize centralized network architectures. A centralized network architecture involves at least one central device connecting multiple distributed devices. A small number of central devices can, for example, control and manage these connected devices, acting as gateways for these devices.

[0004] In a centralized network architecture, all distributed devices are connected to a central device. However, if a device with an abnormal Internet Protocol (IP) address is the same as the central device's, such as a network device that has been misconfigured with the central device's IP address or an attacker's device that has spoofed the central device's IP address, each distributed device will receive two routes with the same routing prefix. Consequently, messages intended for the central device may be sent to the abnormal device instead, causing the centralized network to malfunction.

[0005] Based on this, there is an urgent need to provide a routing processing method for networks with a centralized network architecture to avoid the problem that messages sent by distributed devices cannot be delivered to the central device due to device misconfiguration or attack messages, so as to ensure the normal operation of the network with a centralized network architecture. Summary of the Invention

[0006] Based on this, an embodiment of the present application provides a routing processing method and device. In a network with a centralized network architecture, even if there are abnormal devices, each distributed device can distinguish between the abnormal devices and the central device, ensuring that the central device effectively controls each distributed device, or ensures that the central device effectively forwards the messages of each distributed device to ensure that the network with a centralized network architecture can operate normally.

[0007] In a first aspect, an embodiment of the present application provides a routing processing method, which is implemented by a first device. The method may, for example, include: the first device receives a first routing message that complies with a first routing protocol and is sent by a second device, the first routing message carrying first role identification information, the first role identification information being used to indicate the role of the second device in the network, and the first routing message being used to publish a first route; then, the first device determines a first routing priority of the first route based on the first role identification information. It can be seen that in order to overcome the impact of abnormal devices on the network, role identification information is carried in the routing message sent by the second device. The role identification information is used to indicate the role of the second device in the network, so that the first device receiving the routing message can perceive the role of the second device in the network, and set the routing priority of the route published by the second device based on the role identification information. Even if the first device also receives a routing message sent by an abnormal device with the same IP address as the second device, the first device can distinguish the routes published by the abnormal device and the second device. Therefore, when the first device sends a protocol message with the destination address being the IP address of the second device, although there are two routes with the same routing prefix, the protocol message can still be sent to the second device based on the route published by the second device, and the protocol message will not be sent to the abnormal device. For example, for a network with a centralized network architecture, each distributed device can be stably managed or controlled by a trusted central device, or each distributed device can stably communicate with a trusted central device, thereby improving the reliability of the network with a centralized network architecture and achieving network security.

[0008] In an embodiment of the present application, the network has a centralized network architecture, that is, the network may include at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, the at least one central device includes the second device, and the first device is a distributed device connected to the second device. As an example, the network is a control-forwarding separation network, the second device is a controller in the control-forwarding separation network, and the first device is any forwarding device connected to the controller. As another example, the network is a center Hub-backbone Spine network, the second device is a Hub device in the Hub-Spine network, and the first device is any Spine device connected to the Hub device. As another example, the network is a backbone Spine-leaf Leaf network, the second device is a Spine device in the Spine-Leaf network, and the first device is any Leaf connected to the Spine device. As yet another example, the network is a CU separation network with control plane CP-user plane UP separation, the second device is a CP device in the CU separation network, and the first device is any UP device connected to the CP device. As another example, the network is a virtual extended local area network VXLAN network, the second device is a Vxlan gateway in the VXLAN network, and the first device is any endpoint device connected to the Vxlan gateway.

[0009] The first routing protocol may be, for example, the Open Shortest Path First (OSPF) protocol, the Intermediate System to Intermediate System (ISIS) protocol, the Border Gateway Protocol (BGP) or the Path Computation Element Protocol (PCEP).

[0010] As an example, the first routing message carries the first role identification information through a newly added extended group attribute or a newly added type-length-value TLV field. For example, the first routing message carries the first role identification information through a newly added extended group attribute or the type field in the newly added TLV field, that is, the first routing message is used to identify the role of the second device in the network through the value of the newly added extended group attribute or the type field in the newly added TLV field.

[0011] In some possible implementations, the first routing message may also carry priority association information, which is used to determine the first routing priority. The priority association information includes one or more of the following information: first indication information, used to indicate that the first routing priority is configured to be higher than the routing priority of other routes published by other devices through the first routing protocol, and the first route and the other routes have the same routing prefix; second indication information, used to indicate that the first device needs to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; third indication information, used to indicate that the first device does not need to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; fourth indication information, used to indicate that the second device is a backup device; fifth indication information, used to indicate that the second device is an active device; sixth indication information, used to indicate that the first device authenticates the second device; and seventh indication information, used to indicate routing attribute information in the first routing message. It should be noted that the priority association information can be carried in the newly added extended community attribute or the newly added type-length-value TLV field of the first routing message.

[0012] In addition, the first routing message may also carry one or more of the following information: eighth indication information, used to indicate the autonomous system in which the second device is located; ninth indication information, used to indicate the network entity within the autonomous system in which the second device is located; and tenth indication information, used to indicate the device identifier of the second device, where the device identifier is used to uniquely identify the second device. It should be noted that the eighth to tenth indication information may be carried in the newly added extended community attribute or the newly added type-length-value TLV field of the first routing message.

[0013] It should be noted that the newly added type-length-value TLV field (or extended group attribute) used to carry the three parts of information, namely, the first role identification information, the priority association information, and the eighth indication information to the tenth indication information, can be the same TLV field (or extended group attribute), or two or three different TLV fields (or extended group attributes), which is not specifically limited in the embodiments of the present application.

[0014] As an example, when the network includes one central device, or when multiple central devices included in the network are all master central devices, the first role identification information may be used to indicate that the role of the second device in the network is a central device.

[0015] As another example, when a network includes multiple central devices, and the multiple central devices include a primary central device and a backup central device, if the role of the second device in the network is a primary central device, the first role identification information can be used to indicate that the role of the second device in the network is the primary central device. If the role of the second device in the network is a backup central device, the first role identification information can be used to indicate that the role of the second device in the network is the backup central device.

[0016] In some specific implementations, the method may also include: the first device receives a second routing message sent by the third device, the second routing message carries second role identification information, the second role identification information is used to indicate that the role of the third device in the network is a backup center device, and the second routing message is used to publish a second route; the first device determines the second routing priority of the second route based on the second role identification information.

[0017] Among them, the second device and the third device can be one master and one backup respectively. Then, the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is the master center device. In this case, the data message sent by the first device is forwarded through the master center device, and when the master center device fails, it switches to the backup center device, and the backup center device forwards the data message.

[0018] Alternatively, the second device and the third device may both be backup center devices. In this case, the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is a backup center device. In this case, the data packet sent by the first device is forwarded through the main center device, and when the main center device fails, it is switched to the second device or the third device, and the second device or the third device serves as the backup center device to forward the data packet; or, it is switched to the second device and the third device, and the second device and the third device serve as the backup center devices to load share the data packet.

[0019] Alternatively, the second device and the third device may both be main center devices. In this case, the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is the main center device, and the second role identification information or the fifth indication information in the second routing message is also used to indicate that the role of the third device in the network is the main center device. In this case, the data message sent by the first device is load-shared by the second device and the third device.

[0020] To increase security, before the first device determines the first route priority of the first route based on the first role identification information, the method may further include: the first device authenticating the second device. The first device authenticating the second device may include: the first device authenticating the second device based on the first role identification information. In one case, the first device authenticating the second device based on the first role identification information may mean that the first device determines the role of the second device in the network based on the first role identification information, and the first device's locally configured policy requires authentication of devices in this role, so the first device determines that authentication is required for the second device. In another case, the first device authenticating the second device based on the first role identification information may also mean that the first device determines the role of the second device in the network based on the first role identification information, and the newly added TLV field (or extended community attribute) in the first routing message used to carry the first role identification information also carries sixth indication information, the first sixth indication information instructing the first device to authenticate the second device, so the first device determines that authentication is required for the second device.

[0021] As an example, if the first routing message also carries a digital signature, then the first device authenticating the second device may, for example, include: the first device authenticating the second device based on the digital signature. The first routing message may carry a digital signature obtained by a trusted signature system signing the target field of the first routing message, where the target field may contain part or all of the content of the first routing message. Authenticating the second device may, for example, include: the first device determining that authentication of the second device is required based on the first role identification information or sixth indication information in the first routing message; the first device verifying the digital signature using the first public key; and, upon successful digital signature verification, the first device determining that the second device is a legitimate central device. In this example, to further enhance the security of the routing processing method, the first routing message may also carry a first public key corresponding to the first private key used to sign the target field. The first device may locally store a first baseline value corresponding to the first public key. For example, the first baseline value may be the first public key or a hash value of the first public key. Then, the above identity authentication process may further include: the first device verifies the first public key in the first routing message based on the locally stored first baseline value. Only after the verification is passed, the first device may use the verified first public key to verify the digital signature.

[0022] As another example, if the first routing message carries a first hash check value, then the first device authenticates the second device, for example, including: the first device authenticates the second device based on the first hash check value. The first hash check value is a hash value obtained by hashing the target field of the first routing message, and the target field may contain part or all of the content of the first routing message. Then, authenticating the second device may include, for example: the first device determines that the second device needs to be authenticated based on the first role identification information or the sixth indication information in the first routing message; the first device hashes the target field of the first routing message to obtain a second hash value; if the second hash value is the same as the first hash check value, then the first device determines that the second device is a central device with a legitimate identity.

[0023] Regarding the first device determining the first routing priority of the first route based on the first role identification information, some possible implementations may include, for example: the first device determining the role of the second device in the network based on the first role identification information; and the first device determining the first routing priority based on the correspondence between the local preset policy and the role of the second device in the network. In this way, the first routing message does not need to carry routing attribute information, and the first device can determine the first routing priority based on the preset policy corresponding to the role of the second device in the local preset policy, which saves the message space of the first routing message and network transmission resources to a certain extent, and improves routing processing efficiency.

[0024] In other possible implementations, if the first routing message carries seventh indication information, then determining the first routing priority of the first route by the first device based on the first role identification information may, for example, include: the first device determining the first routing priority based on the first role identification information and the seventh indication information. The seventh indication information is routing attribute information carried in the first routing message, which may be carried in the first routing message via a newly added extended community attribute or a newly added TLV field. The routing attribute information includes one or more of the following parameters: link cost, local preference (Local_preference), routing source (Origin), and multi-exit identifier (MED). For example, for the BGP protocol, routing attribute information includes, but is not limited to, one or more of the following parameters: Local_preference, Origin, and MED; for another example, for the ISIS protocol, routing attribute information includes, but is not limited to, link cost. Thus, the first routing message needs to carry routing attribute information, and the first device can determine the first routing priority of the first route based on the first role identification information and the routing attribute information, without requiring local configuration on the first device, thereby saving storage space on the first device to a certain extent.

[0025] In some possible implementations, the method may further include: a first device receiving a third routing message from a fourth device, the IP address of the fourth device being the same as the IP address of the second device, the third routing message being used to publish a third route, the first route and the third route having the same routing prefix; the first device determining, based on the third routing message, that the fourth device and the second device have different roles in the network; and the first device determining a third routing priority for the third route, the third routing priority being different from the first routing priority. The third routing priority may be lower than the first routing priority.

[0026] As an example, if the third routing message complies with the first routing protocol, that is, the routing message used to publish two routes with the same routing prefix complies with the same routing protocol, if the two sending devices have different roles in the network, then the receiving device determines different routing priorities for the two routes.

[0027] As another example, if the third routing message complies with the second routing protocol, that is, the routing message for publishing two routes with the same routing prefix complies with different routing protocols, if the two sending devices have different roles in the network, then the way in which the receiving device determines different routing priorities for the two routes may include: setting different protocol priorities for the two routing protocols, for example, the protocol priority of the first routing protocol is higher than the protocol priority of the second routing protocol.

[0028] In some other possible implementations, the method may further include: the first device receiving a fourth routing message from a fifth device, the fifth device having the same IP address as the second device, the fourth routing message being used to advertise a fourth route, the first route and the fourth route having the same routing prefix; the first device determining that the fourth route is an invalid route; and the first device not storing the fourth route. The first device may determine that the fourth route advertised by the fourth routing message is an invalid route based on the fourth routing message not carrying the role identification information, and thus not store the fourth route, thereby conserving resources of the first device. In one case, the first device not storing the fourth route may mean that, when the first device first receives the first routing message, or when the first device simultaneously receives the first routing message and the fourth routing message, the first device determines that the fourth route is an invalid route and does not store the fourth route locally. In another case, the first device not storing the fourth route may also mean that, when the first device first receives the fourth routing message, the first device stores the fourth route, and then, upon subsequently receiving the first routing message carrying the first role identification information, determines that the fourth route is an invalid route, deletes or sets the locally stored routing table entry corresponding to the fourth route to an invalid state, and revoks the fourth route.

[0029] As an example, the method may further include: the first device obtaining a first message, the destination address of the first message being the IP address of the second device; and the first device sending the first message to the second device based on the first route. The first message may be a protocol message.

[0030] In the second aspect, an embodiment of the present application provides a routing processing method, which is implemented by a second device. The routing processing method may, for example, include: the second device generates a first routing message, which carries first role identification information, and the first role identification information is used to indicate the role of the second device in the network; then, the second device sends the first routing message to the first device, and the first routing message is used to publish a first route, and the first routing message complies with a first routing protocol.

[0031] As an example, the first routing message carries the first role identification information through a newly added extended community attribute or a newly added type-length-value TLV field.

[0032] As an example, the newly added extended community attribute or the type field in the newly added TLV field is used to carry the first role identification information.

[0033] As an example, the first routing message further carries priority association information, and the priority association information is used to determine the first routing priority corresponding to the first route.

[0034] As an example, the priority association information includes one or more of the following information: first indication information, used to indicate that the first route priority is configured to be higher than the route priority of other routes published by other devices through the first routing protocol, and the first route and the other routes have the same routing prefix; second indication information, used to indicate that the first device needs to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; third indication information, used to indicate that the first device does not need to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; fourth indication information, used to indicate that the second device is a backup device; fifth indication information, used to indicate that the second device is an active device; sixth indication information, used to instruct the first device to authenticate the second device; seventh indication information, used to indicate the routing attribute information in the first routing message.

[0035] As an example, the first routing message also carries one or more of the following information: eighth indication information, used to indicate the autonomous system where the second device is located; ninth indication information, used to indicate the network entity within the autonomous system where the second device is located; and tenth indication information, used to indicate the device identifier of the second device, which is used to uniquely identify the second device.

[0036] As an example, the first role identification information is used to indicate that the role of the second device in the network is a central device.

[0037] As another example, the role of the second device in the network is a primary center device or a backup center device.

[0038] Wherein, the network has a centralized network architecture, and the network includes at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, and the at least one central device includes the second device. For example, the network is a control-forwarding separation network, the second device is the controller in the control-forwarding separation network, and the first device is any forwarding device connected to the controller. For another example, the network is a center Hub-backbone Spine network, the second device is the Hub device in the Hub-Spine network, and the first device is any Spine device connected to the Hub device. For another example, the network is a backbone Spine-leaf Leaf network, the second device is the Spine device in the Spine-Leaf network, and the first device is any Leaf connected to the Spine device. For example, the network is a CU separation network with control plane CP-user plane UP separation, the second device is the CP device in the CU separation network, and the first device is any UP device connected to the CP device. For another example, the network is a virtual extended local area network VXLAN network, the second device is a Vxlan gateway in the VXLAN network, and the first device is any endpoint device connected to the Vxlan gateway.

[0039] As an example, the first routing message further carries a digital signature or a hash check value, and the digital signature or the hash check value is used to authenticate the second device.

[0040] As an example, the first routing message includes a newly added extended community attribute or a newly added TLV field, and the newly added extended community attribute or the newly added TLV field is used to carry routing attribute information, and the routing attribute information is used by the first device to determine a first routing priority corresponding to the first route. The routing attribute information includes one or more of the following parameters: link cost, local priority (Local_preference), routing source (Origin), and multi-exit identifier (MED).

[0041] The first routing protocol is the Open Shortest Path First (OSPF) protocol, the Intermediate System to Intermediate System (ISIS) protocol, the Border Gateway Protocol (BGP), or the Path Computation Element Protocol (PCEP).

[0042] It should be noted that the method provided in the second aspect corresponds to the method provided in the first aspect. For the specific implementation method and the effects achieved, please refer to the relevant instructions in the method provided in the first aspect above.

[0043] In a third aspect, an embodiment of the present application further provides a communication device, which includes a transceiver unit and a processing unit. The transceiver unit is used to perform the transceiver operation implemented by the first device in the method provided in the first aspect; the processing unit is used to perform other operations implemented by the first device in the method provided in the first aspect except for the transceiver operation. For example: when the device executes the method implemented by the first device in the first aspect, the transceiver unit can be used to receive a first routing message sent by the second device; the processing unit can be used to determine the first routing priority of the first route based on the first role identification information.

[0044] In a fourth aspect, an embodiment of the present application further provides a communications device comprising a transceiver unit and a processing unit. The transceiver unit is configured to perform the transceiver operations implemented by the second device in the method provided in the second aspect above; and the processing unit is configured to perform other operations implemented by the second device in the method provided in the second aspect above, except for the transceiver operations. For example, when the device executes the method implemented by the second device in the second aspect above, the transceiver unit may be configured to send the first routing message to the first device; and the processing unit may be configured to generate the first routing message.

[0045] In a fifth aspect, embodiments of the present application further provide a communication device comprising a communication interface and a processor. The communication interface is configured to perform the transceiver operations described in the method described in the first aspect, and the processor is configured to perform operations other than the transceiver operations described in the method described in the first aspect or any possible implementation of the first aspect.

[0046] In a sixth aspect, embodiments of the present application further provide a communication device comprising a communication interface and a processor. The communication interface is configured to perform the transceiver operations described in the method described in the second aspect, and the processor is configured to perform operations other than the transceiver operations described in the method described in the second aspect or any possible implementation of the second aspect.

[0047] In a seventh aspect, embodiments of the present application further provide a communications device comprising a memory and a processor. The memory comprises computer-readable instructions; the processor, in communication with the memory, is configured to execute the computer-readable instructions, thereby enabling the communications device to perform the method provided in the first aspect or any possible implementation of the first aspect.

[0048] In an eighth aspect, an embodiment of the present application further provides a communication device comprising a memory and a processor. The memory comprises computer-readable instructions; the processor, in communication with the memory, is configured to execute the computer-readable instructions, so that the communication device performs the method provided in the second aspect or any possible implementation of the second aspect.

[0049] In a ninth aspect, embodiments of the present application further provide a communication system. The communication system includes a first device and a second device, wherein the first device may specifically be the communication device provided in the third, fifth, or seventh aspects above; and correspondingly, the second device may specifically be the communication device provided in the fourth, sixth, or eighth aspects above.

[0050] In the tenth aspect, an embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, it enables the computer to execute the method provided by the first aspect or any possible implementation of the first aspect, or enables the computer to execute the method provided by the second aspect or any possible implementation of the second aspect.

[0051] In the eleventh aspect, an embodiment of the present application also provides a computer program product, including a computer program or computer-readable instructions. When the computer program or the computer-readable instructions are run on a computer, the computer executes the method provided by the aforementioned first aspect or any possible implementation of the first aspect, or the computer executes the method provided by the aforementioned second aspect or any possible implementation of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0053] Figure 1 A schematic diagram of a star topology network structure in an embodiment of the present application;

[0054] Figure 2 A schematic diagram of a tree topology network structure in an embodiment of the present application;

[0055] Figure 3a This is a schematic diagram of the structure of a control-forwarding separation network in an embodiment of the present application;

[0056] Figure 3b This is a schematic diagram of the structure of a central Hub-backbone Spine network in an embodiment of the present application;

[0057] Figure 3c This is a schematic diagram of the structure of a backbone Spine-Leaf Leaf network in an embodiment of the present application;

[0058] Figure 3dThis is a schematic diagram of the structure of a VXLAN network in an embodiment of the present application;

[0059] Figure 3e This is a schematic diagram of the structure of a CU separation network in an embodiment of the present application;

[0060] Figure 4a In the embodiment of this application Figure 3e Schematic diagram of a scenario where misconfiguration occurs in the network shown;

[0061] Figure 4b In the embodiment of this application Figure 3e Schematic diagram of a scenario in which an attacking device appears in the network;

[0062] Figure 5 This is a signaling interaction diagram of a routing processing method 100 in an embodiment of the present application;

[0063] Figure 6a This is a schematic diagram of the format of a newly added extended community attribute or TLV field in a BGP message in an embodiment of the present application;

[0064] Figure 6b This is a schematic diagram of the format of a newly added TLV field in an ISIS protocol message or an OSPF protocol message in an embodiment of the present application;

[0065] Figure 7a In the embodiment of this application Figure 6a or Figure 6b Schematic diagram of the Flags field in the format shown;

[0066] Figure 7b In the embodiment of this application Figure 6a or Figure 6b A schematic diagram of the format of Optional Para in the format shown;

[0067] Figure 8 This is a structural diagram of a CU separation network in an embodiment of the present application;

[0068] Figure 9a Schematic diagram of a flow chart of a method for authenticating a CP device 341 in an embodiment of the present application;

[0069] Figure 9b Schematic diagram of another method for authenticating the CP device 341 in an embodiment of the present application;

[0070] Figure 10 This is a flowchart of a routing processing method 200 in an embodiment of the present application;

[0071] Figure 11This is a signaling interaction diagram of another routing processing method 300 in an embodiment of the present application;

[0072] Figure 12 This is a schematic structural diagram of a communication device 1200 according to an embodiment of the present application;

[0073] Figure 13 This is a schematic structural diagram of another communication device 1300 in an embodiment of the present application;

[0074] Figure 14 This is a structural diagram of a communication device 1400 in an embodiment of the present application;

[0075] Figure 15 This is a schematic structural diagram of another communication device 1500 in an embodiment of the present application;

[0076] Figure 16 This is a schematic structural diagram of a communication device 1600 according to an embodiment of the present application;

[0077] Figure 17 This is a schematic structural diagram of another communication device 1700 in an embodiment of the present application;

[0078] Figure 18 18 is a structural diagram of a communication system 1800 in an embodiment of the present application. DETAILED DESCRIPTION

[0079] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings. The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions in the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0080] In this application, ordinal numbers such as "1", "2", "3", "first", "second" and "third" are used to distinguish multiple objects and are not used to limit the order of multiple objects.

[0081] “A and / or B” mentioned in this application should be understood to include the following situations: only A, only B, or both A and B.

[0082] At present, networks with centralized network architecture are favored by many users. In a network with a centralized network architecture, for example, it can include at least one central device and multiple distributed devices, and at least one central device establishes a connection with each of the multiple distributed devices. In a specific application scenario, in a centralized network architecture, at least one central device can manage or control multiple distributed devices. For example, in a software-defined network (English: Software Defined Network, abbreviated as: SDN), the at least one central device is the controller in the SDN, and the distributed device is the forwarding device in the SDN network, and the controller manages or controls multiple forwarding devices. In another application scenario, in a centralized network architecture, one or more distributed devices establish a communication connection with other devices via the at least one central device. For example, the at least one central device is a gateway device, and the multiple distributed devices are network devices connected to the gateway device. Then, the above-mentioned network devices establish a communication connection with other devices through the gateway device. In a specific example, the centralized network architecture can have a star topology or a tree topology.

[0083] It should be noted that, in the embodiment of the present application, the central device in a network with a centralized network architecture may also be referred to as the core device of the network.

[0084] Figure 1 A schematic diagram showing a network structure with a star topology is shown. Figure 1 This star topology network includes: central node 1, distributed device 2, distributed device 3, ..., distributed device N (N is an integer greater than 1). Central node 1 is the central device in a centralized network architecture, and each distributed device is connected only to central node 1. In this network, central node 1 can manage or control each distributed device; alternatively, central node 1 can serve as a bridge for each distributed device to communicate with other devices. For example, in a VXLAN network, central node 1 can serve as a VXLAN gateway, and each distributed device communicates with network-side devices through central node 1.

[0085] Figure 2 A schematic diagram showing a network structure with a tree topology is shown. Figure 2, the network with the tree topology structure includes: root node 20, branch node 21, branch node 22, leaf node 23, branch node 24, leaf node 25, branch node 26... The network with the tree topology structure can be regarded as several networks with a centralized network architecture. In each network with a centralized network architecture, the central device can manage or control each distributed device, or each distributed device can also communicate with other devices through the central node. When the root node 20 is the central device in the network with a centralized network architecture, all other branch nodes that establish a communication connection with the root node 20 can be used as distributed devices in the centralized architecture; when a branch node other than the leaf node is used as the central device, all other branch nodes that establish a communication connection with the branch node can be used as distributed devices in the network with the centralized network architecture, for example: branch node 21 is the central device, and leaf node 23 and branch node 24 can both be distributed devices.

[0086] Those skilled in the art will understand that Figure 1 , Figure 2 These are just examples of star and tree topologies. A network structure with a star topology can have any number of distributed devices. Similarly, a network architecture with a tree topology can have any number of root nodes, branch nodes, and leaf nodes.

[0087] The following introduces several commonly used networks with centralized network architecture.

[0088] Figure 3a A control-forwarding separation network is shown, which includes a controller 301, a forwarding device 302, a forwarding device 303, ..., a forwarding device 307. Each forwarding device establishes a communication connection with the controller 301. The controller 301 serves as a central device responsible for controlling or managing each forwarding device. Figure 3b A central Hub-backbone Spine network is shown, which includes Hub 311, Spine 312, Spine 313 and Spine 314. Each Spine establishes a communication connection with Hub 311. Hub 311, as a central device, is responsible for controlling and managing each Spine or forwarding messages from each Spine. Figure 3cA backbone Spine-Leaf network is shown, which includes Spine 321, Spine 322, Leaf 323, Leaf 324, Leaf 325 and Leaf 326. The four Leafs establish communication connections with Spine 321 and Spine 322 respectively. Spine 321 serves as the main center device and is responsible for controlling, managing or forwarding messages from Leaf 323, Leaf 324, Leaf 325 and Leaf 326. Spine 322 serves as the backup center device and controls, manages or forwards messages from Leaf 323, Leaf 324, Leaf 325 and Leaf 326 when Spine 321 fails. Figure 3d A virtual eXtensible Local Area Network (VXLAN) network is shown, which includes a VXLAN gateway 331, an endpoint device 332, an endpoint device 333, and an endpoint device 334. Each endpoint device establishes a communication connection with the VXLAN gateway 331. The VXLAN gateway 331 acts as a central device responsible for forwarding messages sent by each endpoint device. Figure 3e The figure shows a control plane (CP)-user plane (UP) separated network (also called a CU separation network). The network includes a CP device 341, an UP device 342, an UP device 343, ..., and an UP device 349. Each UP device establishes a communication connection with the CP device 341. The CP device 341 serves as a central device responsible for controlling and managing each UP device or forwarding messages from each UP device.

[0089] It should be noted that Figure 3e The CP device 341 and each UP device in the embodiment may be, for example, a network device such as a switch or a router. Figure 3a The controller 301 in the embodiment can be an entity for implementing control and management functions, and can be deployed on a separate server, in a forwarding device, or in a separate network device. Each forwarding device can be, for example, a network device such as a switch or a router. Figure 3a and Figure 3e The difference between the network architecture is that when a server is required to act as a controller to uniformly manage or control multiple forwarding devices, it is usually used Figure 3a The network shown in the figure is usually used when the computational complexity between network devices is high and the computational tasks are heavy. Figure 3eIn the network shown, multiple UP devices are responsible for processing computing tasks respectively, and the CP device performs unified management or control on each UP device, or the CP device forwards messages sent by each UP device.

[0090] It can be seen that networks with centralized network architecture are widely used in reality, building a stable one-to-many network model and providing convenience for users' centralized management and control.

[0091] In the following text Figure 3e The network shown in the figure is used as an example to illustrate the routing processing methods of other networks with centralized network architecture. Figure 3e Routing for the networks shown is handled similarly.

[0092] Currently, CP device 341 and each UP device establish a connection through a routing protocol. Taking CP device 341 and UP device 342 as an example, the process of establishing a connection between UP device 342 and CP device 341 may include: UP device 342 receives routing message 1 sent by CP device 341. Routing message 1 is used to advertise route 1. Thus, when UP device 342 receives protocol message 1, whose destination address is IP address 1, UP device 342 may send protocol message 1 to CP device 341 based on route 1. However, if there is an abnormal device in the network, and this abnormal device is configured with the same IP address as CP device 341 (that is, IP address 1), UP device 342 will also receive routing message 2 sent by the abnormal device. Routing message 2 carries the abnormal device's IP address 1 and is used to advertise route 2. In this way, there will be two routes in the network, both pointing to IP address 1. When UP device 342 receives protocol packet 2, whose destination address is IP address 1, UP device 342 will select a route. If the routing priority of route 2 is higher than the routing priority of route 1, UP device 342 will send protocol packet 2 to the abnormal device based on route 2. In this way, the presence of an abnormal device is likely to cause many UP devices in a network with a centralized network architecture to send protocol packets intended for CP device 341 to the abnormal device, causing many UP devices to lose the control of CP device 341, or many UP devices to be unable to send packets to other devices through CP device 341, causing serious impact on the network.

[0093] The scenarios where abnormal devices appear include but are not limited to: Scenario 1: At least one UP device in the network is misconfigured with the IP address of the CP device 341, e.g. Figure 4aIn the scenario shown, the UP device 345 is configured with the same IP address as the CP device 341: 192.168.100.100; Scenario 2: An attack device appears in the network and impersonates the IP address of CP341. The attack source establishes a communication connection with at least one device in the network, such as Figure 4b In the scenario shown, the attack device 350 is configured with the same IP address as the CP device 341: 192.168.100.100, and the attack device 350 establishes a communication connection with the UP device 348, and publishes its own route in the network through the UP device 348 to attack the network.

[0094] Based on this, an embodiment of the present application provides a routing processing method. In order to overcome the impact of abnormal devices on central devices, role identification information is carried in the routing message sent by the central device. The role identification information is used to indicate the role of the central device in the network, so that the distributed devices that receive the routing message can perceive the role of the central device in the network, and set the routing priority of the route published by the central device based on the role identification information. Even if the distributed device also receives the routing message sent by the abnormal device with the same IP address as the central device, the distributed device can distinguish the routes published by the abnormal device and the central device. Therefore, when the distributed device sends a protocol message with the destination address being the IP address of the central device, although there are two routes with the same routing prefix, the protocol message can still be sent to the central device based on the route published by the central device, and the protocol message will not be sent to the abnormal device. It can be seen that through this routing processing method, each distributed device can be stably managed or controlled by a trusted central device, or each distributed device can stably communicate with a trusted central device, thereby improving the reliability of the network with a centralized network architecture, thereby achieving network security.

[0095] For example, Figure 4aTaking the network shown as an example, in a specific implementation, CP device 341 sends a routing message 1 to UP device 342. This routing message carries role identification information 1, indicating that CP device 341 is a CP device (i.e., a central device in a centralized network architecture). This routing message 1 is used to advertise route 1. UP device 342 then determines route priority 1 for route 1 based on role identification information 1 in received routing message 1. Assume that UP device 345 is mistakenly configured with the same IP address as CP device 341, 192.168.100.100. UP device 345 then sends a routing message 2 to UP device 342. This routing message 2 does not carry role identification information 2, indicating that UP device 345 has the same role as CP device 341 in the network. This routing message 2 is used to advertise route 2, which has the same routing prefix as route 1. UP device 342 then determines route priority 2 for route 2, which is lower than route priority 1. In this way, when the destination address of the protocol message 1 of the UP device 342 is 192.168.100.100, the UP device 342 selects route 1 corresponding to route priority 1 with a higher routing priority based on the routing priorities corresponding to routes 1 and 2 with the same routing prefix, and thus sends the protocol message 1 to the CP device 341 based on route 1.

[0096] It can be seen that by carrying role identification information 1 in the routing message 1 sent by the CP device 341, the UP device 342 that receives the routing message 1 can perceive the role of the CP device 341 in the network, and thus set the routing priority 1 of the route 1 published by the CP device 341 based on the role identification information 1. Even if there is an abnormal device in the network that is configured with the same IP address as the CP device 341, the UP device 342 can distinguish between the abnormal device and the routes published by the CP device 341, thereby enabling each UP device to be stably managed or controlled by the CP device 341, or enabling each UP device to stably communicate with the CP device 341, thereby improving the reliability of the CU separation network and achieving network security.

[0097] It can be understood that the above scenario is only an example scenario provided by the embodiment of the present application, and the embodiment of the present application is not limited to this scenario.

[0098] The following combination Figure 5 , the routing processing method 100 provided in an embodiment of the present application is introduced.

[0099] It should be noted that the routing processing method 100 provided in the embodiment of the present application can be applied to a network with a centralized network architecture, which may include at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections. Specifically, the network with a centralized network architecture includes but is not limited to: Figure 3a to Figure 3e The network shown in Figure 1. Figure 3a In the network shown, the central device is the controller 301, and the distributed device that performs routing processing can be any one of the forwarding devices 302 to 307; Figure 3b In the network shown, the central device is Hub 311, and the distributed device that performs routing processing can be any one of Spine 312, Spine 313, and Spine 314; Figure 3c In the network shown, when the central device is Spine 321, the distributed device that performs routing processing can be either Leaf 323 or Leaf 324. When the central device is Spine 322, the distributed device that performs routing processing can be either Leaf 325 or Leaf 326. Figure 3d In the network shown, the central device is VXLAN gateway 331, and the distributed device performing routing processing can be any one of endpoint device 332, endpoint device 333, and endpoint device 334; Figure 3e In the network shown, the central device is the CP device 341 , and the distributed device that performs routing processing can be any one of the UP devices 342 to 349 .

[0100] by Figure 3e In the CU separation network shown in FIG, an attack device 350 that counterfeits the IP address of the CP device 341 appears as an example, that is, Figure 4b Taking the illustrated scenario as an example, the routing processing method 100 provided in an embodiment of the present application is introduced. Figure 5 This is a signaling interaction diagram of a routing processing method 100 provided in an embodiment of the present application. Figure 5 The method 100 may include, for example, the following S101 to S104:

[0101] S101 , the CP device 341 obtains a routing message 1 , which carries a role identifier 1 , which indicates the role of the CP device 341 in the network. The routing message 1 is used to publish a route 1 , and the routing message 1 complies with a routing protocol 1 .

[0102] In one case, if route message 1 is generated by CP device 341, route 1 may be the route to CP device 341. In another case, if route message 1 is forwarded by another device to UP device 342 via CP device 341, route 1 may be the route to the other device that generated route message 1.

[0103] S102 , the CP device 341 sends a routing message 1 to the UP device 342 .

[0104] S103 , the UP device 342 receives the routing message 1 sent by the CP device 341 .

[0105] Routing protocol 1 may include, but is not limited to, an Interior Gateway Protocol (IGP), an Exterior Gateway Protocol (EGP), or a Path Computation Element Protocol (PCEP). If routing protocol 1 is an IGP, routing protocol 1 may be, for example, Open Shortest Path First (OSPF) or Intermediate System to Intermediate System (ISIS). If routing protocol 1 is an EGP, routing protocol 1 may be, for example, Border Gateway Protocol (BGP).

[0106] The CP device 341 can add an extended community attribute or a new type-length value (English: TypeLength Value, abbreviated as: TLV) field to the routing message 1. The newly added extended community attribute or the newly added TLV field is used to carry the role identification information 1. For example, the value of the Type field in the extended community attribute or the newly added TLV field is used to represent the role identification information 1.

[0107] As an example, if the routing protocol 1 followed by routing message 1 is BGP, then routing message 1 is a BGP message, and the BGP message can carry role identification information 1 through the newly added extended community attribute or TLV field. Figure 6aThe format of the extended community attribute or TLV field newly added in the routing message 1 for carrying role identification information 1 is shown. The extended community attribute or TLV field includes at least a Type field and a Length field. In addition, the extended community attribute or TLV field may also include one or more of the following information: a Flags field, a Reserved field, an Autonomous System Number (AS) field, a Router ID field, and an optional Para field.

[0108] As another example, if the routing protocol 1 followed by the routing message 1 is the ISIS protocol or the OSPF protocol, then the routing message 1 is an ISIS protocol message or an OSPF protocol message, and the ISIS protocol message or the OSPF protocol message can carry the role identification information 1 through the newly added TLV field. Figure 6b The format of the newly added TLV field for carrying role identification information 1 in the routing message 1 shown in the figure includes at least: a type field and a length field. In addition, the extended community attribute or TLV field may also include one or more of the following information: a flag field, a reserved field, a network ID field, a router ID field, and an optional field OptionalPara.

[0109] It should be noted that Figure 6a and Figure 6b The difference is that: Figure 6a The BGP message shown may span multiple ASs. Therefore, Figure 6a The newly added extended community attribute or TLV field may include an AS number, which indicates the AS to which the sender device that advertises the route using the BGP message belongs. The receiving device can determine the AS to which the sender device belongs based on the AS number in the BGP message, and determine whether there is a cross-AS situation based on its own AS and the AS to which the sender device belongs. Figure 6b The ISIS protocol message or OSPF protocol message shown only involves the network entities within one AS. Therefore, Figure 6b The newly added TLV field shown may include a Network ID, which is used to indicate the sender device that uses the ISIS protocol message or OSPF protocol message to publish the route. The receiving device can determine the sender device based on the Network ID in the ISIS protocol message or OSPF protocol message.

[0110] In a specific implementation, in the newly added extended community attribute or the newly added TLV field, the Type field can be used to carry role identification information 1. For example: Figure 6a In the format shown, the Type field is defined as 0x01, which is used to indicate that the role of the CP device 341 in the network is a central device. For another example: Figure 6b In the format shown, the Type field is defined as 0x169, which is used to indicate that the role of the CP device 341 in the network is a central device.

[0111] In another specific implementation, the role identification information 1 may also be carried by one or more bits included in a newly added extended community attribute or a newly added TLV field.

[0112] In some possible implementations, the route message 1 may also carry priority association information, which is used to instruct the receiving device to determine a corresponding route priority for route 1. The priority association information may be carried, for example, via a newly added TLV field or a newly added extended community attribute.

[0113] In a specific implementation, the priority association information includes one or more of the following information:

[0114] (1) Instruction information 1 is used to indicate that route priority 1 is configured to be higher than the route priority of other routes published by other devices through routing protocol 1, and route 1 and other routes have the same routing prefix. In this way, even if the attack device 350 publishes route 2 in routing message 2 and also complies with routing protocol 1, it can be ensured that the CP device 341 has the highest route priority among all routes published using routing protocol 1, thereby ensuring the control or transmission function of the CP device 341 on each UP device.

[0115] (2) Indication information 2, used to indicate that the protocol priority of routing protocol 1 in routing among multiple routing protocols needs to be modified, and indication information 3, used to indicate that the protocol priority of routing protocol 1 in routing among multiple routing protocols does not need to be modified. In one case, indication information 2 and indication information 3 can be carried by two different bits or two different sub-TLV fields in a newly added TLV field or a newly added extended community attribute. In another case, indication information 2 and indication information 3 can also be carried by a bit or a sub-TLV field in a newly added TLV field or a newly added extended community attribute, and the two different values ​​of the bit or sub-TLV field are used to reflect indication information 2 and indication information 3 respectively. For example: when the value of the Value field of the bit or sub-TLV field is the first value, it means that the indication information 2 is carried, which is used to indicate that the protocol priority of routing protocol 1 in routing among multiple routing protocols needs to be modified; when the value of the Value field of the bit or sub-TLV field is the second value, it means that the indication information 3 is carried, which is used to indicate that the protocol priority of routing protocol 1 in routing among multiple routing protocols does not need to be modified. Thus, when routing message 1 includes indication information 2, even if routing message 2 of route 2 published by attacking device 350 complies with routing protocol 2, and the default protocol priority of routing protocol 2 is higher than the protocol priority of routing protocol 1, the receiving device can modify the protocol priority of routing protocol 1 in selecting routes between multiple routing protocols based on indication information 2, so that the protocol priority of routing protocol 1 is higher than the protocol priority of routing protocol 2. This ensures that routing priority 1 is higher than routing priority 2, thereby ensuring that the CP device 341 can manage or control each UP device, or ensure that each UP device forwards packets to other devices through the CP device 341. For example, by default, the protocol priority of the ISIS protocol is lower than the protocol priority of the OSPF protocol. If routing message 1 that complies with the ISIS protocol includes indication information 2, the protocol priority of the ISIS protocol can be adjusted to be higher than the protocol priority of the OSPF protocol, so that the routing priority 1 of route 1 published by the ISIS protocol can be higher than the routing priority of routes published by the OSPF protocol.

[0116] (3) Indication information 4 is used to indicate that the CP device 341 is a backup device (when it is assumed by default that only routes advertised by the central device carry role identification information, the backup device may also be called a backup core device or a backup central device), and indication information 5 is used to indicate that the CP device 341 is a primary device (when it is assumed by default that only routes advertised by the central device carry role identification information, the primary device may also be called a primary core device or a primary central device). In one case, indication information 4 and indication information 5 may be carried by two different bits or two different sub-TLV fields in a newly added TLV field or a newly added extended community attribute. In another case, indication information 4 and indication information 6 can also be carried by a bit or a sub-TLV field in a newly added TLV field or a newly added extended group attribute. The two different values ​​of the bit or sub-TLV field are used to reflect indication information 4 and indication information 5 respectively. For example: when the value of the Value field of the bit or sub-TLV field is the third value, it means that the indication information 4 is carried, which is used to indicate that the sending device is a backup device; when the value of the Value field of the bit or sub-TLV field is the fourth value, it means that the indication information 5 is carried, which is used to indicate that the sending device is a primary device. In this way, when a centralized network architecture with multiple CP devices appears, the more detailed role of each CP device in the network can be effectively identified. For related descriptions, please refer to the following Figure 8 Relevant instructions in the shown scenario.

[0117] (4) Instruction information 6 is used to instruct the UP device 342 to authenticate the CP device 341. In this way, by authenticating the device that claims to be the CP device, the trusted CP device 341 can be more securely confirmed, thereby ensuring the security of the network. For related descriptions, please refer to the following Figure 9a and 9b The relevant instructions are shown.

[0118] (5) Indication information 7 is used to indicate the routing attribute information in routing message 1. The indication information 7 is the data basis for determining the routing priority 1 of route 1 in the following S102. For related descriptions, please refer to the following Figure 7b The relevant instructions are shown.

[0119] In addition, the routing message 1 may also carry device association information, which is used to indicate device-related information of the sending device. The device association information may be carried, for example, in a newly added TLV field or a newly added extended community attribute.

[0120] In a specific implementation, the device association information includes one or more of the following information:

[0121] (1) Indication information 8, used to indicate the autonomous system where the CP device 341 is located, and indication information 9, used to indicate the network entity within the autonomous system where the CP device 341 is located. Indication information 8, for example, can be the ASNumber of the AS where the CP device 341 is located, and indication information 9, for example, can be the Network ID within the AS where the CP device 341 is located. For example: if routing message 1 is a BGP message, then, since BGP messages may involve cross-AS situations, routing message 1 can include indication information 8 to inform the receiving device of the AS to which the CP device 341 belongs; for another example: if routing message 1 is an ISIS protocol message or an OSPF protocol message, then, since the ISIS protocol message or the OSPF protocol message only involves one AS, routing message 1 can include indication information 9 to inform the receiving device of which network entity the CP device 341 is.

[0122] (2) Indication information 10, used to indicate the device identifier of CP device 341. The device identifier is used to uniquely identify CP device 341. For example, indication information 10 may be the Router ID of CP device 341. Indication information 10 may carry any information required for subsequent expansion, and is not specifically addressed or explained in this embodiment.

[0123] As an example, the newly added TLV field or extended community attribute used to carry at least one of the indication information can be a TLV field or extended community attribute used to carry role identification information, that is, by adding an extended community attribute or TLV field, role identification information 1 and at least one of the indication information can be carried. For example, a new TLV field 1 is added to routing message 1, the Type field of the TLV field 1 is used to carry the role identification information 1, and the Value field of the TLV field 1 is used to carry at least one of the indication information.

[0124] As another example, the newly added TLV field or extended group attribute used to carry at least one of the indication information may not be a TLV field or extended group attribute used to carry role identification information, that is, the newly added extended group attribute 1 or TLV field 1 is used to carry role identification information 1, and the newly added extended group attribute 2 or TLV field 2 is used to carry at least one of the indication information. It should be noted that if two different extended group attributes or TLV fields are added to carry role identification information and indication information respectively, in a specific implementation, the two newly added extended group attributes or TLV fields can be associated, which can ensure that the receiving device associates the role identification information and the indication information, making the routing processing method more reliable. Among them, the methods of associating two newly added extended community attributes or TLV fields include but are not limited to: Method 1: adding an identification field to the newly added extended community attribute 1 (or TLV field 1), and the value of the identification field is used to indicate reading the newly added extended community attribute 2 (or TLV field 2); Method 2: adding an identification field to the routing message 1, and the value of the identification field is used to indicate that the newly added extended community attribute 1 (or TLV field 1) and the newly added extended community attribute 2 (or TLV field 2) have an associated relationship.

[0125] Take the example of using the same newly added extended community attribute or TLV to carry role identification information 1 and indication information. As an example, the above indication information 1 to indication information 6 can be carried in Figure 6a or Figure 6b In the Flags field in the format shown, the format of the Flags field is as follows Figure 7aAs shown, the Flags field can include at least four bits: the P bit, the R bit, the S bit, and the B bit. For example, the P bit corresponds to indication information 1. When the P bit is 1, it indicates that route priority 1 should be configured to be higher than the priority of other routes advertised by routing protocol 1. When the P bit is 0, it indicates that route priority 1 for route 1 does not need to be configured. For example, the R bit corresponds to indication information 2 and indication information 3. When the R bit is 1, it corresponds to indication information 2, indicating that the protocol priority of routing protocol 1 in routing among multiple routing protocols needs to be modified. When the P bit is 0, it corresponds to indication information 3, indicating that the protocol priority of routing protocol 1 in routing among multiple routing protocols does not need to be modified. For example, the B bit corresponds to indication information 4 and indication information 5. When the B bit is 1, it corresponds to indication information 4, indicating that CP device 341 is a backup device. When the B bit is 0, it corresponds to indication information 5, indicating that CP device 341 is an active device. For example, the value of the S bit corresponds to indication information 6. When the S bit = 1, it corresponds to indication information 6, indicating that the CP device 341 is authenticated. When the S bit = 0, it indicates that indication information 6 is invalid, and thus, it indicates that the CP device 341 is not authenticated. It should be noted that the bits included in the Flags field can be flexibly set according to actual scenario requirements. For example, any one or more of the P bit, R bit, S bit, and B bit can be set in the Flags field. For example, other bits can also be set in the Reserved field of the Flags field to implement other indication functions according to actual scenario requirements. This is not specifically limited in the embodiments of the present application.

[0126] As an example, the indication information 7 may be carried in Figure 6a or Figure 6b In the Optional Para format shown in the following example, the format of the Optional Para is as follows: Figure 7b As shown, for example, it can be Figure 6a or Figure 6bThe format shown here adds a new sub-TLV. The Priority Type field of this sub-TLV carries the type of routing attribute information used to configure route priority 1. For example, the Priority Type field can carry one or more of the following parameter types: link cost, local preference, origin, or multi-exit discriminator (MED). The Priority Data field (i.e., the Value field of this sub-TLV) carries the specific value of the routing attribute information. For example, when the Priority Type field carries MED, the Priority Data field can be an offset from the MED (e.g., 100). Carrying role identification information 1 and routing attribute information used to configure route priority in the same TLV field or extended community attribute ensures that the role identification information 1 and routing attribute information arrive at the receiving device strictly synchronously, eliminating the need to maintain separate state machines, making the routing processing method simpler and more reliable.

[0127] Regarding S101 to S103 , the role identification information 1 is used to indicate that the role of the CP device 341 in the network is a central device.

[0128] In addition, Figure 8 In the scenario shown, it is assumed that the CU is separated from the network, except for Figure 4b In addition to the devices shown, CP device 341' is also connected to each UP device. In this case, CP device 341 and CP device 341' can both be active devices, or one can be active and the other a standby device. In this case, UP device 342 can also receive routing message 3 sent by CP device 341'. Routing message 3 carries role identification information 3, which indicates the role of CP device 341' in the network. Routing message 3 is used to publish route 3.

[0129] If both CP device 341 and CP device 341' are active devices, then role identification information 1 or indication information 5 in routing message 1 also indicates that CP device 341 is a master center device in the network, and role identification information 3 or indication information 5 in routing message 3 indicates that CP device 341' is a master center device in the network. In this case, data packets sent by UP device 342 are load-balanced between CP device 341 and CP device 341'.

[0130] If CP device 341 is the primary device and CP device 341' is the backup device, then role identification information 1 or indication information 5 in routing message 1 is also used to indicate that CP device 341' is a primary central device in the network, and role identification information 3 or indication information 4 in routing message 3 is used to indicate that CP device 341' is a backup central device in the network; alternatively, role identification information 1 or indication information 4 in routing message 1 is also used to indicate that CP device 341 is a backup central device in the network, and role identification information 5 or indication information 3 in routing message 3 is used to indicate that CP device 341' is a primary central device in the network. In this case, data packets sent by UP device 342 are forwarded by the primary central device. When the primary central device fails, the data packets are switched to the backup central device, which then forwards the data packets.

[0131] In a specific embodiment, to ensure that the device sending routing message 1 is secure and trustworthy, before S104, method 100 may further include: S104a, UP device 342 authenticates CP device 341. S104a may, for example, refer to: UP device 342 authenticates CP device 341 based on role identification information 1; or, S104a may refer to: UP device 342 authenticates CP device 341 based on indication information 6. UP device 342 authenticates CP device 341 based on role identification information 1 or indication information 6, which may mean that UP device 342 determines that authentication of CP device 341 is required based on role identification information 1 or indication information 6.

[0132] As an example, the routing message 1 may carry a digital signature obtained by signing the target field of the routing message 1 by a trusted signature system, wherein the target field may contain part or all of the content of the routing message 1. Then, for example, see S104a. Figure 9a, including: S11, UP device 342 determines that the CP device 341 needs to be authenticated based on the role identification information 1 or indication information 6 in the routing message 1; S12, UP device 342 verifies the digital signature using public key 1; S13, after the digital signature is verified, UP device 342 determines that the CP device 341 is a central device with a legitimate identity. In this example, to further improve the security of the routing processing method, the routing message 1 may also carry the public key 1 corresponding to the private key 1 used to sign the target field. The UP device 342 locally stores a baseline value 1, which corresponds to the public key 1. For example, the baseline value 1 can be the public key 1 or the hash value A of the public key 1. Then, between S11 and S12 of the above S104a, the UP device 342 may also verify the public key 1 in the routing message 1 based on the locally stored baseline value 1. Only after the verification is successful can the UP device 342 use the verified public key 1 to verify the digital signature.

[0133] As another example, routing message 1 may also carry hash check value 1, wherein hash check value 1 is a hash value obtained by performing a hash operation on the target field of routing message 1, and the target field may include part or all of the content of routing message 1. Then, for example, see S104a. Figure 9b , including: S21, the UP device 342 determines that the CP device 341 needs to be authenticated based on the role identification information 1 or the indication information 6 in the routing message 1; S22, the UP device 342 performs a hash operation on the target field of the routing message 1 to obtain a hash value 2; S23, if the hash value 2 is the same as the hash check value 1, then the UP device 342 determines that the CP device 341 is a central device with a legitimate identity.

[0134] In S11 and S21 of the above example, the UP device 342 determines that the CP device 341 needs to be authenticated based on the role identification information 1 in the routing message 1. For example, it can be: the UP device 342 determines that the CP device 341 is the central device based on the role identification information 1, and the UP device 342 is locally configured with a policy: authenticate the central device in the network. Then, when the UP device 342 receives the routing message 1 carrying the role identification information 1, and the role identification information 1 indicates that the sending device CP device 341 is the central device, the UP device 342 determines that the CP device 341 needs to be authenticated.

[0135] S104 , the UP device 342 determines the route priority 1 of route 1 according to the role identification information 1 .

[0136] In one possible implementation, S104 may include: first, the UP device 342 determines the role of the CP device 341 in the network based on the role identification information 1; then, the UP device 342 determines the route priority 1 of route 1 based on the priority association information. The priority association information includes, but is not limited to, indication information 1, indication information 2, or indication information 3. For details about indication information 1 to indication information 3, refer to the relevant content of the priority association information.

[0137] In another possible implementation, S104 may also include: first, the UP device 342 may determine the role of the CP device 341 in the network based on the role identification information 1; then, the UP device 342 may determine the routing priority 1 based on the correspondence between the local preset policy and the role of the CP device 341 in the network. The UP device 342 may, for example, include: a correspondence 1 between the central device and the local preset policy 1, a correspondence 2 between the primary central device and the local preset policy 2, and a correspondence 3 between the backup central device and the local preset policy 3. Then, the UP device 342 may determine the routing priority 1 based on the correspondence between the local preset policy and the role of the CP device 341 in the network. For example, the UP device 342 may determine that the local pre-configured policy 1 corresponds to the central device based on the three sets of correspondences between the local preset policies and the role of the CP device 341 in the network; and the UP device 342 may determine the routing priority 1 based on the local pre-configured policy 1. The specific content of the local pre-configuration policy can be found in the relevant content of the priority association information, that is, the local pre-configuration policy includes: configuring the route priority 1 to be higher than the route priority of other routes published by other devices through routing protocol 1, or modifying the protocol priority of routing protocol 1 in routing between multiple routing protocols to a higher protocol priority, or not modifying the protocol priority of routing protocol 1 in routing between multiple routing protocols. In this implementation, routing message 1 does not need to carry indication information 1, indication information 2, and indication information 3, but the corresponding content is configured locally on UP device 342 in the form of a pre-configuration policy, which can save network resources consumed by transmitting routing message 1.

[0138] In a specific implementation, S104 may include, for example, the UP device 342 determining routing attribute information based on the role of the CP device 341 in the network indicated by the role identification information 1, and determining routing priority 1 based on the routing attribute information. The routing attribute information may be obtained by the UP device 342 from routing message 1, for example, by obtaining the routing attribute information from indication information 7 of routing message 1. Alternatively, the routing attribute information may be locally configured by the UP device 342, for example, if the UP device 342 configures a correspondence between routing attribute information and the device's role in the network, then obtains routing attribute information corresponding to the determined role from the correspondence.

[0139] Regarding the method for determining route priority 1 in S104, in one case, after receiving route message 1, UP device 342 determines route priority 1 based on the route attribute information and role identification information 1. In another case, after receiving route message 1, UP device 342 first determines route priority 1' for route 1. When UP device 342 receives route 2 having the same route prefix as route 1, it compares the route attribute information with route 2 to determine route attribute information that can make route 1 have a higher route priority. Based on the determined route attribute information, the route priority of route 1 is adjusted from route priority 1' to route priority 1.

[0140] For the BGP protocol, route attribute information includes, but is not limited to, one or more of the following parameters: Local_preference, Origin, and MED. Local_preference and MED values ​​are both greater than 1, and Origin values ​​are 0, 1, and 2. If all other parameters are the same, a higher Local_preference value corresponds to a higher route priority; if all other parameters are the same, a lower MED value corresponds to a higher route priority; and if all other parameters are the same, a higher Origin value corresponds to a higher route priority.

[0141] If the routing attribute information includes a parameter (such as MED), then the UP device 342 determines the routing priority 1 based on the routing attribute information specifically as follows: the UP device 342 determines the routing priority 1 based on the unique parameter.

[0142] If the routing attribute information includes multiple parameters, then the UP device 342 determines the routing priority 1 based on the routing attribute information specifically as follows: the UP device 342 determines the routing priority 1 based on all or part of the multiple parameters included in the routing attribute information. The multiple parameters may be respectively carried in a newly added extended community attribute or multiple sub-TLVs in the TLV field.

[0143] Assuming that the routing attribute information carried in the routing message 1 that complies with BGP is MED, when other routing attribute information is not included or the other routing attribute information included is the same, in one case, in order to reduce the probability of being attacked as much as possible, the MED value in the indication information 5 of the routing message 1 sent by the CP device 341 can be set as small as possible, for example: set to 50. Then, if the MED carried in the routing message sent by the attacking device 350 is 150, it can be determined based on this that the routing priority 1 of the CP device 341 is higher than the routing priority 2 of the attacking device 350. Alternatively, in another case, if the MED in routing message 1 is 200, and routing message 1 is also used to indicate that when route 2 with the same routing prefix as route 1 appears, the routing priority of route 1 is adjusted based on the routing priority 2 of route 2. In this case, the UP device 342 determines a lower routing priority 1' for the CP device 341 based on routing message 1. When the MED of the attacking device is 150, then the routing priority 2 of the attacking device 350 is higher than the routing priority 1'. At this time, the MED value can be adjusted to less than 150, for example, to 100, according to the instruction of the routing message 1 sent by the CP device 341, and the routing priority 1' is adjusted to routing priority 1, and the routing priority 1 is higher than the routing priority 2.

[0144] For example, in the ISIS protocol, since link cost is the primary factor in route selection, route attribute information includes link cost. In the shortest path algorithm, when other route attribute information is not included or when other route attribute information is the same, the route with the lower link cost has a higher priority.

[0145] It can be seen that through the method 100 provided in the embodiment of the present application, role identification information is carried in the routing message sent by the central device, and the role identification information is used to indicate the role of the central device in the network, so that the distributed devices that receive the routing message can perceive the role of the central device in the network, and set the routing priority of the route published by the central device based on the role identification information, so that the network with a centralized network architecture including each distributed device and at least one central device can operate stably, thereby improving the reliability of the network with a centralized network architecture, thereby achieving network security.

[0146] In some possible implementations, such as Figure 5 As shown, the method 100 may further include the following S105 to S107:

[0147] S105 , the UP device 342 receives the routing message 2 sent by the attacking device 350 . The IP address of the attacking device 350 is the same as the IP address of the CP device 341 . The routing message 2 is used to publish route 2 . Route 1 and route 2 have the same routing prefix.

[0148] S106 , the UP device 342 determines, based on the routing message 2 , that the attacking device 350 and the UP device 342 have different roles in the network.

[0149] S107 , the UP device 342 determines the route priority 2 of route 2 , which is different from the route priority 1 .

[0150] In a specific implementation, if routing message 2 does not carry role identification information, since routing message 1 carries role identification information 1, the UP device 342 can determine that the sender devices of the two routing messages belong to different roles in the network, thereby determining different routing priorities for the routes corresponding to the two sending devices, such as: the UP device 342 determines routing priority 2 for route 2, where routing priority 2 is lower than routing priority 1.

[0151] In another specific implementation, if the routing message 2 carries role identification information 2, and the role identification information 2 is used to indicate that the role of the attack device 350 in the network is a distributed device, and the role identification information 1 is used to indicate that the role of the CP device 341 in the network is a central device, then the UP device 342 can determine that the sender devices of the two routing messages belong to different roles in the network, thereby determining different routing priorities for the routes corresponding to the two sending devices, specifically: the UP device 342 determines that the routing priority 2 of route 2 is lower than the routing priority 1 of route 1.

[0152] In another specific embodiment, if the routing message 2 carries the role identification information 2, but the role identification information 2 is used to indicate that the role of the attacking device 350 in the network is the same as the role of the CP device 341 in the network, then, in order to ensure network security, the above Figure 9a or Figure 9b In the manner shown, the CP device 341 and the attack device 350 are authenticated, and it is determined that the CP device 341 passes the authentication, while the attack device 350 fails the authentication, thereby determining that the routing priority 1 is higher than the routing priority 2, effectively resisting attacks and enabling the network to operate securely.

[0153] It should be noted that, in order to achieve the purpose of attacking the network, the attack device 350 can access the network through any UP device in the network. The route of the attack device 350 can be flooded in the network, posing a huge hidden danger to network security.

[0154] Typically, the attack device 350 can only impersonate the IP address of the CP device 341, but will not carry role identification information in its routing message 2. Then, although the UP device 342 receives two routing messages, which are used to publish routes with the same routing prefix, the UP device 342 can also perceive which device is the CP device 341 and which device is the attack device 350 based on whether the two routing messages carry role identification information. Thus, the UP device 342 can determine a higher routing priority 1 for route 1 published by routing message 1 sent by the CP device 341, and determine a routing priority 2 lower than routing priority 1 for route 2 published by routing message 2 sent by the attack device 350, providing a reliable data basis for the subsequent normal operation of the network. In addition, if the attacking device 350 not only impersonates the IP address of the CP device 341, but also carries role identification information 2 in its routing message 2, then the UP device 342 distinguishes between the CP device 341 and the attacking device 350 in the following ways: Method 1: Based on the difference in role identification information carried in the two routing messages, the CP device 341 and the attacking device 350 are perceived; Method 2: The CP device 341 and the attacking device 350 are distinguished through identity authentication. Thus, the UP device 342 determines a routing priority 2 lower than the routing priority 1 for the route 2 published by the routing message 2 sent by the attacking device 350, providing a reliable data basis for the subsequent normal operation of the network.

[0155] As an example, if routing message 2 also complies with routing protocol 1, then S104 may specifically include: UP device 342 configures routing priority 1 to be higher than routing priority 2; or, S107 may for example include: UP device 342 configures routing priority 2 to be lower than routing priority 1.

[0156] As another example, if routing message 2 complies with routing protocol 2, then S107 may include, for example: UP device 342 determines routing priority 2 based on the protocol priority of routing protocol 2, where the protocol priority of routing protocol 2 is lower than the protocol priority of routing protocol 1. For example, routing protocol 1 is the ISIS protocol, and routing protocol 2 is the OSPF protocol. Before S107 and S104 are executed, the protocol priority based on the ISIS protocol is lower than the protocol priority based on the OSPF protocol by default. Therefore, in S104, the protocol priority of the ISIS protocol can be set higher than the protocol priority of the OSPF protocol, or, in S107, the protocol priority of the OSPF protocol can be set lower than the protocol priority of the ISIS protocol.

[0157] It should be noted that there is no limitation on the order of execution of the above S101 to S104 and S105 to S107, and they can be executed sequentially or simultaneously.

[0158] In a specific embodiment, if the UP device 342 receives routing message 1 and routing message 2, routing message 1 and routing message 2 are used to publish route 1 and route 2 respectively, route 1 and route 2 have the same routing prefix, and the routing message includes role identification information 1, role identification information 1 is used to indicate that the CP device 341 is a central device, and routing message 2 does not include role identification information, then the UP device 342 can determine that route 2 is an illegal route based on routing message 2 that does not carry the role identification message, and thus does not save route 2 to save the resources of the UP device 342. In one case, the UP device 342 does not save the route 2, which may mean: when the UP device 342 first receives the routing message 1, or when the routing message 1 and the routing message 2 are received at the same time, the route 2 is determined to be an illegal route, and the route 2 is not saved locally; in another case, the UP device 342 does not save the route 2, which may also mean: when the UP device 342 first receives the routing message 2, the route 2 is saved, and when the routing message 1 carrying the role identification information 1 is subsequently received, the route 2 is determined to be an illegal route, the routing table entry corresponding to the locally saved route 2 is deleted or set to an invalid state, and the route 2 is revoked.

[0159] It can be seen that the method 100 provided in the embodiment of the present application carries role identification information in the routing message sent by the central device, and the role identification information is used to indicate the role of the central device in the network, so that the distributed devices that receive the routing message can perceive the role of the central device in the network, and set the routing priority of the route published by the central device based on the role identification information. Even if the distributed device also receives the routing message sent by the abnormal device with the same IP address as the central device, the distributed device can distinguish the routes published by the abnormal device and the central device, thereby setting the routing priority corresponding to the central device higher than the routing priority corresponding to the abnormal device, so that it is possible for the distributed device to subsequently send the protocol message to the central device based on the route published by the central device.

[0160] In some other possible implementations, if the network device determines the illegal route 2 from the two routes 1 and 2 with the same route prefix and only stores the legal route 1, then when the UP device 342 obtains a message with the destination address being the IP address of the CP device 341, it can directly send the message to the CP device 341 based on the legal route 1. If the network device stores two routes 1 and 2 with the same route prefix, then, Figure 5 As shown, the method 100 may further include S108 to S109:

[0161] S108 , the UP device 342 obtains the message 1 , the destination address of which is the IP address of the CP device 341 .

[0162] S109 , the UP device 342 sends message 1 to the CP device 341 based on route 1.

[0163] It should be noted that after the above S101 to S107, there are two routes 1 and 2 with the same routing prefix on the UP device 342. Since the routing message 1 sent by the CP device 341 carries the role identification information 1, the UP device 342 can perceive the CP device 341 and distinguish the CP device 341 from the abnormal device 350. Therefore, the UP device 342 can normally send the protocol message to the CP device 341, so that the network can operate normally.

[0164] In specific implementation, when the UP device 342 obtains the message 1 whose destination address is the IP address of the CP device 341, the UP device 342 needs to select a route and send the message 1 based on a route with a higher routing priority. For example, the route priority 1 with a higher routing priority can be determined, and the message 1 is sent to the CP device 341 based on the route 1 corresponding to the routing priority 1.

[0165] It can be seen that the method 100 provided in the embodiment of the present application carries role identification information in the routing message sent by the central device. The role identification information is used to indicate the role of the central device in the network, so that the distributed devices that receive the routing message can perceive the role of the central device in the network, and set the routing priority of the route published by the central device based on the role identification information. Even if the distributed device also receives the routing message sent by the abnormal device with the same IP address as the central device, the distributed device can distinguish the routes published by the abnormal device and the central device, and overcome the impact of the abnormal device on the central device. Therefore, when the distributed device sends a protocol message with the destination address being the IP address of the central device, although there are two routes with the same routing prefix, the protocol message can still be sent to the central device based on the route published by the central device, and the protocol message will not be sent to the abnormal device. In this way, the network can operate stably, and the reliability of the network with a centralized network architecture is improved, thereby achieving network security.

[0166] Figure 10 A schematic flow chart of a routing processing method 200 in an embodiment of the present application is shown. The method 200 is implemented by a first device. The routing processing method 200 may include, for example:

[0167] S201: A first device receives a first routing message sent by a second device, where the first routing message carries first role identification information, where the first role identification information is used to indicate a role of the second device in a network, and the first routing message is used to publish a first route, where the first routing message complies with a first routing protocol.

[0168] S202: The first device determines a first routing priority of the first route according to the first role identification information.

[0169] In an embodiment of the present application, the network has a centralized network architecture, that is, the network may include at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, the at least one central device includes the second device, and the first device is a distributed device connected to the second device. As an example, the network is a control-forwarding separation network, the second device is a controller in the control-forwarding separation network, and the first device is any forwarding device connected to the controller. As another example, the network is a center Hub-backbone Spine network, the second device is a Hub device in the Hub-Spine network, and the first device is any Spine device connected to the Hub device. As another example, the network is a backbone Spine-leaf Leaf network, the second device is a Spine device in the Spine-Leaf network, and the first device is any Leaf connected to the Spine device. As yet another example, the network is a CU separation network with control plane CP-user plane UP separation, the second device is a CP device in the CU separation network, and the first device is any UP device connected to the CP device. As another example, the network is a virtual extended local area network VXLAN network, the second device is a Vxlan gateway in the VXLAN network, and the first device is any endpoint device connected to the Vxlan gateway.

[0170] Taking the network as a CU separation network as an example, the specific implementation method and the effect achieved in the method 200 can refer to the relevant description in the above-mentioned method 100. The first device in the method 200 can specifically be the UP device 342 in the above-mentioned method 100, and the operations performed by the first device can specifically refer to the operations performed by the UP device 342 in the method 100. Specifically, the relevant descriptions of S201 and S202 can refer to S103 and S104 in the method 100 respectively. Among them, the second device can be the CP device 341 in the method 100, the first routing message can be the routing message 1 in the method 100, the first role identification information can be the role identification information 1 in the method 100, the first route can be the route 1 in the method 100, the first routing protocol can be the routing protocol 1 in the method 100, and the first routing priority can be the routing priority 1 in the method 100.

[0171] The first routing protocol may be, for example, the Open Shortest Path First (OSPF) protocol, the Intermediate System to Intermediate System (ISIS) protocol, the Border Gateway Protocol (BGP) or the Path Computation Element Protocol (PCEP).

[0172] As an example, the first routing message carries the first role identification information through a newly added extended group attribute or a newly added type-length-value TLV field. For example, the first routing message carries the first role identification information through a newly added extended group attribute or the type field in the newly added TLV field, that is, the first routing message is used to identify the role of the second device in the network through the value of the newly added extended group attribute or the type field in the newly added TLV field.

[0173] In some possible implementations, the first routing message may also carry priority association information, which is used to determine the priority of the first route. The priority association information includes one or more of the following: first indication information indicating that the priority of the first route is configured to be higher than the priority of other routes advertised by other devices via the first routing protocol, where the first route and the other routes have the same routing prefix; second indication information indicating that the first device needs to modify the protocol priority of the first routing protocol in route selection between multiple routing protocols; third indication information indicating that the first device does not need to modify the protocol priority of the first routing protocol in route selection between multiple routing protocols; fourth indication information indicating that the second device is a backup device; fifth indication information indicating that the second device is an active device; sixth indication information instructing the first device to authenticate the second device; and seventh indication information indicating route attribute information in the first routing message. For descriptions of the first to seventh indication information, please refer to the corresponding descriptions of indication information 1 to indication information 7 in method 100. It should be noted that the priority association information may be carried in a newly added extended community attribute or a newly added type-length-value TLV field in the first routing message.

[0174] In addition, the first routing message may also carry one or more of the following information: eighth indication information, used to indicate the autonomous system in which the second device is located; ninth indication information, used to indicate a network entity within the autonomous system in which the second device is located; and tenth indication information, used to indicate a device identifier of the second device, wherein the device identifier is used to uniquely identify the second device. For descriptions of the eighth to tenth indication information, please refer to the corresponding descriptions of indication information 8 to indication information 10 in method 100. It should be noted that the eighth to tenth indication information may be carried in the newly added extended community attribute or the newly added type-length-value TLV field of the first routing message.

[0175] It should be noted that the newly added type-length-value TLV field (or extended group attribute) used to carry the three parts of information, namely, the first role identification information, the priority association information, and the eighth indication information to the tenth indication information, can be the same TLV field (or extended group attribute), or two or three different TLV fields (or extended group attributes), which is not specifically limited in the embodiments of the present application.

[0176] As an example, when the network includes one central device, or when multiple central devices included in the network are all master central devices, the first role identification information may be used to indicate that the role of the second device in the network is a central device.

[0177] As another example, when a network includes multiple central devices, and the multiple central devices include a primary central device and a backup central device, if the role of the second device in the network is a primary central device, the first role identification information can be used to indicate that the role of the second device in the network is the primary central device. If the role of the second device in the network is a backup central device, the first role identification information can be used to indicate that the role of the second device in the network is the backup central device.

[0178] In some specific implementations, the method 200 may also include: the first device receives a second routing message sent by the third device, the second routing message carries second role identification information, the second role identification information is used to indicate that the role of the third device in the network is a backup center device, and the second routing message is used to publish a second route; the first device determines the second routing priority of the second route based on the second role identification information. The second device and the third device can be one master and one backup, respectively. Then, the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is a master center device. In this case, the data message sent by the first device is forwarded by the master center device, and when the master center device fails, it switches to the backup center device, and the backup center device forwards the data message. Alternatively, the second device and the third device may both be backup center devices, in which case the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is a backup center device. In this case, the data message sent by the first device is forwarded through the main center device, and when the main center device fails, it is switched to the second device or the third device, and the second device or the third device acts as the backup center device to forward the data message; or, it is switched to the second device and the third device, and the second device and the third device act as the backup center device to load share the data message. Alternatively, the second device and the third device may both be main center devices, in which case the first role identification information or the fifth indication information in the first routing message is also used to indicate that the role of the second device in the network is a main center device, and the second role identification information or the fifth indication information in the second routing message is also used to indicate that the role of the third device in the network is a main center device. In this case, the data message sent by the first device is load shared by the second device and the third device.

[0179] To increase security, before S202, the method 200 may further include: the first device authenticates the second device. The first device authenticates the second device, which may include: the first device authenticates the second device according to the first role identification information. In one case, the first device authenticates the second device according to the first role identification information, which may refer to the first device determining the role of the second device in the network based on the first role identification, and the first device's locally configured policy requires authentication of devices of this role, so the first device determines that the second device needs to be authenticated. In another case, the first device authenticates the second device according to the first role identification information, which may refer to the first device determining the role of the second device in the network based on the first role identification, and the newly added TLV field (or extended community attribute) used to carry the first role identification information in the first routing message also carries sixth indication information, and the first sixth indication information is used to instruct the first device to authenticate the second device, so the first device determines that the second device needs to be authenticated.

[0180] As an example, if the first routing message also carries a digital signature, then the first device authenticates the second device, for example, including: the first device authenticates the second device based on the digital signature. It should be noted that in this case, the process of the first device authenticating the second device can refer to Figure 9a Description of the illustrated embodiment.

[0181] As another example, if the first routing message carries a first hash check value, then the first device authenticates the second device, for example, including: the first device authenticates the second device according to the first hash check value. It should be noted that in this case, the process of the first device authenticating the second device can be referred to. Figure 9b Description of the illustrated embodiment.

[0182] For S202, some possible implementations may include, for example, the first device determining the role of the second device in the network based on the first role identification information; and the first device determining the first routing priority based on the correspondence between a local preset policy and the role of the second device in the network. In this way, the first routing message does not need to carry routing attribute information; the first device can determine the first routing priority based on the preset policy corresponding to the role of the second device in the local preset policy, thereby saving message space and network transmission resources for the first routing message and improving routing processing efficiency. In other possible implementations, if the first routing message carries seventh indication information, S202 may include, for example, the first device determining the first routing priority based on the first role identification information and the seventh indication information. The seventh indication information is the routing attribute information carried in the first routing message, which may be carried in the first routing message via a newly added extended community attribute or a newly added TLV field. The routing attribute information includes one or more of the following parameters: link cost, local preference, origin, and multi-exit identifier (MED). For example, for the BGP protocol, routing attribute information includes but is not limited to one or more of the following parameters: Local_preference, Origin, and MED. For another example, for the ISIS protocol, routing attribute information includes but is not limited to link cost. Thus, the first routing message must carry routing attribute information. The first device can then determine the first routing priority of the first route based on the first role identifier and the routing attribute information, eliminating the need for local configuration on the first device and conserving storage space on the first device to a certain extent.

[0183] In some possible implementations, the method 200 may further include: the first device receives a third routing message from a fourth device, the IP address of the fourth device is the same as the IP address of the second device, the third routing message is used to publish a third route, and the first route and the third route have the same routing prefix; the first device determines, based on the third routing message, that the fourth device and the second device have different roles in the network; the first device determines a third routing priority for the third route, and the third routing priority is different from the first routing priority. The third routing priority may be lower than the first routing priority. As an example, if the third routing message complies with the first routing protocol, that is, if the routing message for publishing two routes with the same routing prefix complies with the same routing protocol, if the two sending devices have different roles in the network, then the receiving device determines different routing priorities for the two routes. As another example, if the third routing message complies with a second routing protocol, that is, if the routing messages used to publish two routes with the same routing prefix comply with different routing protocols, and if the two sending devices have different roles in the network, then the method by which the receiving device determines different routing priorities for the two routes may include: setting different protocol priorities for the two routing protocols, for example, the protocol priority of the first routing protocol is higher than the protocol priority of the second routing protocol. It should be noted that the fourth device in this embodiment may be the attacking device 350 in method 100, the third routing message may be routing message 2 in method 100, the third route may be route 2 in method 100, and the third routing priority may be route priority 2 in method 100. For relevant descriptions of this embodiment, please refer to the corresponding descriptions of S105 to S107 in method 100.

[0184] In other possible implementations, method 200 may further include: the first device receiving a fourth routing message from a fifth device, the fifth device having the same IP address as the second device, the fourth routing message being used to advertise a fourth route, the first route and the fourth route having the same routing prefix; the first device determining that the fourth route is an invalid route; and the first device not storing the fourth route. The first device may determine that the fourth route advertised by the fourth routing message is an invalid route based on the fourth routing message not carrying the role identification information, and thus not store the fourth route, thereby conserving resources of the first device. In one case, the first device not storing the fourth route may mean that, upon first receiving the first routing message, or upon simultaneously receiving the first routing message and the fourth routing message, the first device determines that the fourth route is an invalid route and does not store the fourth route locally. In another case, the first device not storing the fourth route may mean that, upon first receiving the fourth routing message, the first device stores the fourth route, and then, upon subsequently receiving the first routing message carrying the first role identification information, determines that the fourth route is an invalid route, deletes or sets the locally stored routing table entry corresponding to the fourth route to an invalid state, and revoks the fourth route.

[0185] As an example, method 200 may further include: the first device obtaining a first message, where the destination address of the first message is the IP address of the second device; and the first device sending the first message to the second device based on the first route. The first message may be a protocol message. It should be noted that the first message in this embodiment may be message 1 in method 100. For relevant descriptions of this embodiment, please refer to the corresponding descriptions of S108 to S109 in method 100.

[0186] It can be seen that the method 200 provided in the embodiment of the present application carries the first role identification information in the first routing message sent by the second device. The first role identification information is used to indicate the role of the second device in the network, so that the first device that receives the first routing message can perceive the role of the second device in the network, and sets the routing priority of the first route published by the second device based on the first role identification information. Even if the first device also receives a routing message sent by an abnormal device with the same IP address as the second device, the first device can distinguish the routes published by the abnormal device and the second device, and overcome the impact of the abnormal device on the second device. Therefore, when the second device sends a protocol message with the destination address being the IP address of the second device, although there are two routes with the same routing prefix on the first device, the protocol message can still be sent to the second device based on the first route published by the second device, and the protocol message will not be sent to the abnormal device. In this way, the network can operate stably, and the reliability of the network with a centralized network architecture is improved, thereby achieving network security.

[0187] It should be noted that the specific implementation and effect of the method 200 in the embodiment of the present application can be found in the above Figure 5 Related description of method 100 is shown.

[0188] Figure 11 A schematic flow chart of a routing processing method 300 in an embodiment of the present application is shown. The method 300 is implemented by a second device. The routing processing method 300 may include, for example:

[0189] S301: A second device generates a first routing message, where the first routing message carries first role identification information, where the first role identification information is used to indicate a role of the second device in a network.

[0190] S302: The second device sends the first routing message to the first device, where the first routing message is used to publish a first route and complies with a first routing protocol.

[0191] The specific implementation and effects achieved in method 300 may refer to the relevant descriptions in method 100 and method 200. The second device in method 300 may specifically be the CP device 341 in method 100, and the operations performed by the second device may specifically refer to the operations performed by the CP device 341 in method 100. Specifically, the relevant descriptions of S301 and S302 may refer to S101 and S102 in method 100, respectively. The first device may be the UP device 342 in method 100, the first routing message may be routing message 1 in method 100, the first role identification information may be role identification information 1 in method 100, the first route may be route 1 in method 100, the first routing protocol may be routing protocol 1 in method 100, and the first routing priority may be routing priority 1 in method 100.

[0192] As an example, the first routing message carries the first role identification information through a newly added extended community attribute or a newly added type-length-value TLV field.

[0193] As an example, the newly added extended community attribute or the type field in the newly added TLV field is used to carry the first role identification information.

[0194] As an example, the first routing message further carries priority association information, and the priority association information is used to determine the first routing priority corresponding to the first route.

[0195] As an example, the priority association information includes one or more of the following information: first indication information, used to indicate that the first route priority is configured to be higher than the route priority of other routes published by other devices through the first routing protocol, and the first route and the other routes have the same routing prefix; second indication information, used to indicate that the first device needs to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; third indication information, used to indicate that the first device does not need to modify the protocol priority of the first routing protocol in routing between multiple routing protocols; fourth indication information, used to indicate that the second device is a backup device; fifth indication information, used to indicate that the second device is an active device; sixth indication information, used to instruct the first device to authenticate the second device; seventh indication information, used to indicate the routing attribute information in the first routing message.

[0196] As an example, the first routing message also carries one or more of the following information: eighth indication information, used to indicate the autonomous system where the second device is located; ninth indication information, used to indicate the network entity within the autonomous system where the second device is located; and tenth indication information, used to indicate the device identifier of the second device, which is used to uniquely identify the second device.

[0197] As an example, the first role identification information is used to indicate that the role of the second device in the network is a central device.

[0198] As another example, the role of the second device in the network is a primary center device or a backup center device.

[0199] Wherein, the network has a centralized network architecture, and the network includes at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, and the at least one central device includes the second device. For example, the network is a control-forwarding separation network, the second device is the controller in the control-forwarding separation network, and the first device is any forwarding device connected to the controller. For another example, the network is a center Hub-backbone Spine network, the second device is the Hub device in the Hub-Spine network, and the first device is any Spine device connected to the Hub device. For another example, the network is a backbone Spine-leaf Leaf network, the second device is the Spine device in the Spine-Leaf network, and the first device is any Leaf connected to the Spine device. For example, the network is a CU separation network with control plane CP-user plane UP separation, the second device is the CP device in the CU separation network, and the first device is any UP device connected to the CP device. For another example, the network is a virtual extended local area network VXLAN network, the second device is a Vxlan gateway in the VXLAN network, and the first device is any endpoint device connected to the Vxlan gateway.

[0200] As an example, the first routing message further carries a digital signature or a hash check value, and the digital signature or the hash check value is used to authenticate the second device.

[0201] As an example, the first routing message includes a newly added extended community attribute or a newly added TLV field, and the newly added extended community attribute or the newly added TLV field is used to carry routing attribute information, and the routing attribute information is used by the first device to determine a first routing priority corresponding to the first route. The routing attribute information includes one or more of the following parameters: link cost, local priority (Local_preference), routing source (Origin), and multi-exit identifier (MED).

[0202] The first routing protocol is the Open Shortest Path First (OSPF) protocol, the Intermediate System to Intermediate System (ISIS) protocol, the Border Gateway Protocol (BGP), or the Path Computation Element Protocol (PCEP).

[0203] It should be noted that the specific implementation and effect of the method 300 in the embodiment of the present application can be found in the above Figure 5 The method 100 shown and Figure 10 Related description of method 200 is shown.

[0204] In addition, this application also provides a communication device 1200, see Figure 12 As shown. The communication device 1200 includes a transceiver unit 1201 and a processing unit 1202. The transceiver unit 1201 is used to perform the transceiver operation implemented by the distributed device in the embodiment of the present application, such as for implementing the transceiver operation implemented by the UP device 342 in the above method 100, or the transceiver unit 1201 is also used to perform the transceiver operation implemented by the first device in the above method 200; the processing unit 1202 is used to perform other operations other than the transceiver operation implemented by the distributed device in the embodiment of the present application, such as for implementing other operations other than the transceiver operation implemented by the UP device 342 in the above method 100, or the processing unit 1202 is also used to perform other operations other than the transceiver operation implemented by the first device in the above method 200. For example, when the communication device 1200 executes the method implemented by the UP device 342 in the method 100 , the transceiver unit 1201 may be used to receive the routing message 1 sent by the CP device 341 ; the processing unit 1202 may be used to determine the routing priority 1 of route 1 based on the role identification information 1 .

[0205] In addition, this application also provides a communication device 1300, see Figure 13 As shown. The communication device 1300 includes a transceiver unit 1301 and a processing unit 1302. The transceiver unit 1301 is used to perform the transceiver operations implemented by the central device in each embodiment of the present application. For example, the transceiver operation implemented by the CP device 341 in the above method 100 is performed, or the transceiver unit 1301 is also used to perform the transceiver operation implemented by the second device in the above method 300; the processing unit 1302 is used to perform other operations implemented by the central device except the transceiver operation. For example, it is used to perform other operations implemented by the CP device 341 in the above method 100 except the transceiver operation, or the processing unit 1302 is also used to perform other operations implemented by the second device in the above method 300 except the transceiver operation. For example: when the communication device 1300 executes the method implemented by the CP device 341 in the method 100, the transceiver unit 1301 can be used to send routing message 1 to the UP device 342; the processing unit 1302 can be used to obtain routing message 1.

[0206] In addition, the present embodiment also provides a communication device 1400, see Figure 14As shown. The communication device 1400 includes a communication interface 1401 and a processor 1402. Among them, the communication interface 1401 includes a first communication interface 1401a and a second communication interface 1401b. The first communication interface 1401a is used to perform the receiving operation performed by the distributed device in the embodiment of the present application. For example, the receiving operation performed by the UP device 342 in the embodiment shown in the aforementioned method 100, or the first communication interface 1401a is also used to perform the receiving operation performed by the first device in the embodiment shown in the aforementioned method 200. The second communication interface 1401b is used to perform the sending operation performed by the distributed device in the embodiment of the present application. For example, the sending operation performed by the UP device 342 in the embodiment shown in the aforementioned method 100, or the second communication interface 1401b is also used to perform the sending operation performed by the first device in the embodiment shown in the aforementioned method 200. Processor 1402 is configured to perform operations other than the aforementioned receiving and sending operations, such as the operations other than the receiving and sending operations performed by UP device 342 in the embodiment of method 100, or the operations other than the receiving and sending operations performed by the first device in the embodiment of method 200. For example, processor 1402 may perform the operations in the embodiment of method 100: determining, based on role identification information 1, route priority 1 for route 1.

[0207] In addition, the present embodiment also provides a communication device 1500, see Figure 15 As shown. The communication device 1500 includes a communication interface 1501 and a processor 1502. The communication interface 1501 includes a first communication interface 1501a and a second communication interface 1501b. The first communication interface 1501a is used to perform a receiving operation performed by the central device. For example, the receiving operation performed by the CP device 341 in the embodiment shown in the aforementioned method 100, or the first communication interface 1501a is also used to perform the receiving operation performed by the second device in the embodiment shown in the aforementioned method 300. The second communication interface 1501b is used to perform a sending operation performed by the central device. For example, the sending operation performed by the CP device 341 in the embodiment shown in the aforementioned method 100, or the second communication interface 1501b is also used to perform the sending operation performed by the second device in the embodiment shown in the aforementioned method 300. The processor 1502 is used to perform other operations other than the receiving and sending operations performed by the central device. For example, the CP device 341 in the embodiment of the aforementioned method 100 performs other operations in addition to the receiving and sending operations, or the processor 1502 is also configured to perform other operations in addition to the receiving and sending operations performed by the second device in the embodiment of the aforementioned method 300. For example, the processor 1502 may perform the operation of obtaining routing message 1 in the embodiment of the method 100.

[0208] In addition, the present embodiment also provides a communication device 1600, see Figure 16 As shown. The communication device 1600 includes a memory 1601 and a processor 1602 in communication with the memory 1601. The memory 1601 includes computer-readable instructions; the processor 1602 is configured to execute the computer-readable instructions, causing the communication device 1600 to perform the methods described in the above embodiments of this application. For example, it is configured to execute the method executed by the UP device 342 in the above method 100, or to cause the communication device 1600 to execute the method executed by the first device in the above method 200.

[0209] In addition, the present embodiment also provides a communication device 1700, see Figure 17 As shown. The communication device 1700 includes a memory 1701 and a processor 1702 in communication with the memory 1701. The memory 1701 includes computer-readable instructions; the processor 1702 is configured to execute the computer-readable instructions, causing the communication device 1700 to perform the methods described in the above embodiments of this application. For example, the method performed by the CP device 341 in the above method 100, or the method performed by the second device in the above method 300, may be executed.

[0210] It is understood that in the above embodiments, the processor may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor may also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor may refer to one processor or may include multiple processors. Memory can include volatile memory (e.g., random-access memory (RAM)). Memory can also include non-volatile memory (e.g., read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD). Memory can also include a combination of the aforementioned types of memory. Memory can refer to a single memory or multiple memories. In one specific embodiment, the memory stores computer-readable instructions, which include multiple software modules, such as a sending module, a processing module, and a receiving module. After executing each software module, the processor can perform corresponding operations according to the instructions of each software module. In this embodiment, the operations performed by a software module actually refer to the operations performed by the processor according to the instructions of the software module. After executing the computer-readable instructions in the memory, the processor can perform all operations that can be performed by the communication device according to the instructions of the computer-readable instructions.

[0211] It will be understood that in the above embodiment, the communication interface 1401 of the communication device 1400 can be specifically used as the transceiver unit 1201 in the communication device 1200 to implement data communication between the communication device 1200 and other devices. The communication interface 1501 of the communication device 1500 can be specifically used as the transceiver unit 1301 in the communication device 1300 to implement data communication between the communication device 1300 and other devices.

[0212] In addition, the present application embodiment also provides a communication system 1800, see Figure 18 The communication system 1800 includes a first communication device 1801 and a second communication device 1802, wherein the first communication device 1801 can be the communication device 1201, the communication device 1401 or the communication device 1601, and correspondingly, the second communication device 1802 can be the communication device 1301, the communication device 1501 or the communication device 1701.

[0213] In addition, an embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, the computer executes the routing processing method in the embodiment shown in the above method 100, method 200 or method 300.

[0214] In addition, an embodiment of the present application also provides a computer program product, including a computer program or computer-readable instructions. When the computer program or the computer-readable instructions are run on a computer, the computer executes the routing processing method in the embodiments shown in the aforementioned method 100, method 200 or method 300.

[0215] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.

[0216] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments. The device and system embodiments described above are merely schematic. The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.

[0217] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. It should be noted that those skilled in the art may make several improvements and modifications without departing from the scope of protection of the present application, and such improvements and modifications should also be considered as within the scope of protection of the present application.

Claims

1. A routing processing method, characterized in that: include: The first device receives a first routing message sent by the second device, where the first routing message carries first role identification information, where the first role identification information is used to indicate a role of the second device in a network, and the first routing message is used to publish a first route, and the first routing message complies with a first routing protocol; determining, by the first device, a first routing priority of the first route according to the first role identification information; The first device receives a third routing message from a fourth device, where the IP address of the fourth device is the same as the IP address of the second device, the third routing message is used to publish a third route, and the first route and the third route have the same routing prefix; determining, by the first device according to the third routing message, that the fourth device and the second device have different roles in the network; The first device determines a third route priority of the third route, where the third route priority is lower than the first route priority.

2. The method according to claim 1, characterized in that The method further comprises: The first device obtains a first message, where the destination address of the first message is the IP address of the second device; The first device sends the first message to the second device based on the first route.

3. The method according to claim 1, characterized in that The first routing message carries the first role identification information through a newly added extended community attribute or a newly added type-length-value TLV field.

4. The method according to claim 3, characterized in that The newly added extended community attribute or the type field in the newly added TLV field is used to carry the first role identification information.

5. The method according to claim 3, characterized in that The first routing message further carries priority association information, and the priority association information is used to determine the first routing priority.

6. The method according to claim 5, characterized in that The priority association information includes one or more of the following information: first indication information, used to indicate that the first route priority is configured to be higher than the route priority of other routes advertised by other devices through the first routing protocol, and the first route and the other routes have the same routing prefix; The second indication information is used to indicate that the first device needs to modify the protocol priority of the first routing protocol in selecting a path among multiple routing protocols; The third indication information is used to indicate that the first device does not need to modify the protocol priority of the first routing protocol in selecting a path among multiple routing protocols; Fourth indication information, used to indicate that the second device is a backup device; fifth indication information, used to indicate that the second device is an active device; Sixth instruction information, used to instruct the first device to authenticate the second device; The seventh indication information is used to indicate the routing attribute information in the first routing message.

7. The method according to claim 1, characterized in that The first routing message also carries one or more of the following information: Eighth indication information, used to indicate the autonomous system where the second device is located; ninth indication information, used to indicate a network entity within the autonomous system where the second device is located; The tenth indication information is used to indicate the device identifier of the second device, where the device identifier is used to uniquely identify the second device.

8. The method according to claim 1, characterized in that The first role identification information is used to indicate that the role of the second device in the network is a central device.

9. The method according to claim 1, characterized in that The role of the second device in the network is a master center device.

10. The method according to claim 1, characterized in that The role of the second device in the network is a backup center device.

11. The method according to claim 1, wherein The method further comprises: The first device receives a second routing message sent by a third device, where the second routing message carries second role identification information, where the second role identification information is used to indicate that the role of the third device in the network is a backup center device, and the second routing message is used to publish a second route; The first device determines a second route priority of the second route according to the second role identification information.

12. The method according to claim 1, characterized in that The network has a centralized network architecture, and includes at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, and the at least one central device includes the second device.

13. The method according to claim 1, wherein The network is a control-forwarding separation network, and the second device is a controller in the control-forwarding separation network; The network is a central Hub-backbone Spine network, and the second device is a Hub device in the Hub-Spine network; The network is a backbone Spine-Leaf network, and the second device is a Spine device in the Spine-Leaf network; The network is a CU separation network in which a control plane CP and a user plane UP are separated, and the second device is a CP device in the CU separation network; The network is a virtual extended local area network VXLAN network, and the second device is a Vxlan gateway in the VXLAN network.

14. The method according to claim 1, wherein Before the first device determines the first route priority of the first route according to the first role identification information, the method further includes: The first device authenticates the second device.

15. The method according to claim 14, characterized in that The first device authenticates the second device, including: The first device performs the identity authentication on the second device according to the first role identification information.

16. The method according to claim 14, characterized in that The first routing message further carries a digital signature, and the first device authenticates the second device, including: The first device authenticates the second device based on the digital signature.

17. The method according to claim 14, characterized in that The first routing message carries a first hash check value, and the first device authenticates the second device, including: The first device performs the identity authentication on the second device according to the first hash check value.

18. The method according to claim 1, wherein The first device determines, according to the first role identification information, a first route priority of the first route, including: The first device determines, based on the first role identification information, a role of the second device in the network; The first device determines the first routing priority based on a correspondence between a local preset policy and a role of the second device in the network.

19. The method according to any one of claims 1 to 18, characterized in that The third routing message complies with the first routing protocol.

20. The method according to any one of claims 1 to 18, characterized in that The third routing message complies with a second routing protocol, wherein a protocol priority of the first routing protocol is higher than a protocol priority of the second routing protocol.

21. The method according to any one of claims 1 to 18, wherein: The first routing message carries routing attribute information, and the first device determines a first routing priority of the first route according to the first role identification information, including: The first device determines the first routing priority based on the routing attribute information and the first role identification information.

22. The method according to claim 21, characterized in that The first routing message includes a newly added extended community attribute or a newly added TLV field, which is used to carry the routing attribute information.

23. The method according to claim 21, characterized in that The routing attribute information includes one or more of the following parameters: Link cost, local preference, route source (Origin), and multi-egress identifier (MED).

24. The method according to any one of claims 1 to 18, characterized in that The method further comprises: The first device receives a fourth routing message from a fifth device, where the IP address of the fifth device is the same as the IP address of the second device, the fourth routing message is used to publish a fourth route, and the first route and the fourth route have the same routing prefix; The first device determines that the fourth route is an illegal route; The first device does not save the fourth route.

25. The method according to any one of claims 1 to 18, characterized in that The first routing protocol is Open Shortest Path First (OSPF) protocol, Intermediate System to Intermediate System (ISIS) protocol, Border Gateway Protocol (BGP) or Path Computation Element Protocol (PCEP).

26. A routing processing method, characterized in that: include: The second device generates a first routing message, where the first routing message carries first role identification information, where the first role identification information is used to indicate a role of the second device in the network; The second device sends the first routing message to the first device, where the first routing message is used to publish a first route. The first routing message complies with a first routing protocol. A first routing priority of the first route is higher than a third routing priority of a third route on the first device. The third route is a route published by a third routing message sent by a fourth device to the first device. The IP address of the fourth device is the same as the IP address of the second device. The fourth device and the second device have different roles in the network. The first route and the third route have the same routing prefix.

27. The method according to claim 26, characterized in that The first routing message carries the first role identification information through a newly added extended community attribute or a newly added type-length-value TLV field.

28. The method according to claim 27, characterized in that The newly added extended community attribute or the type field in the newly added TLV field is used to carry the first role identification information.

29. The method according to claim 26, wherein The first routing message further carries priority association information, and the priority association information is used to determine a first routing priority corresponding to the first route.

30. The method according to claim 29, wherein The priority association information includes one or more of the following information: first indication information, used to indicate that the first route priority is configured to be higher than the route priority of other routes advertised by other devices through the first routing protocol, and the first route and the other routes have the same routing prefix; Second indication information, used to indicate that the first device needs to modify the protocol priority of the first routing protocol in route selection among multiple routing protocols; The third indication information is used to indicate that the first device does not need to modify the protocol priority of the first routing protocol in selecting a path between multiple routing protocols by the first routing protocol; Fourth indication information, used to indicate that the second device is a backup device; fifth indication information, used to indicate that the second device is an active device; Sixth instruction information, used to instruct the first device to authenticate the second device; The seventh indication information is used to indicate the routing attribute information in the first routing message.

31. The method according to claim 26, wherein The first routing message also carries one or more of the following information: Eighth indication information, used to indicate the autonomous system where the second device is located; ninth indication information, used to indicate a network entity within the autonomous system where the second device is located; The tenth indication information is used to indicate the device identifier of the second device, where the device identifier is used to uniquely identify the second device.

32. The method according to any one of claims 26 to 31, characterized in that The first role identification information is used to indicate that the role of the second device in the network is a central device.

33. The method according to any one of claims 26 to 31, characterized in that The role of the second device in the network is a primary center device or a backup center device.

34. The method according to any one of claims 26 to 31, characterized in that The network has a centralized network architecture, and includes at least one central device and multiple distributed devices, wherein the at least one central device and the multiple distributed devices respectively establish communication connections, and the at least one central device includes the second device.

35. The method according to any one of claims 26 to 31, characterized in that The network is a control-forwarding separation network, and the second device is a controller in the control-forwarding separation network; The network is a central Hub-backbone Spine network, and the second device is a Hub in the Hub-Spine network; The network is a backbone Spine-Leaf network, and the second device is a Spine device in the Spine-Leaf network; The network is a CU separation network in which a control plane CP and a user plane UP are separated, and the second device is a CP device in the CU separation network; The network is a virtual extended local area network VXLAN network, and the second device is a Vxlan gateway in the VXLAN network.

36. The method according to any one of claims 26 to 31, characterized in that The first routing message also carries a digital signature or a hash check value, and the digital signature or the hash check value is used to authenticate the second device.

37. The method according to any one of claims 26 to 31, characterized in that The first routing message includes a newly added extended community attribute or a newly added TLV field, and the newly added extended community attribute or the newly added TLV field is used to carry routing attribute information, and the routing attribute information is used by the first device to determine a first routing priority corresponding to the first route.

38. The method according to claim 37, wherein The routing attribute information includes one or more of the following parameters: Link cost, local preference, route source (Origin), and multi-egress identifier (MED).

39. The method according to any one of claims 26 to 31, characterized in that The first routing protocol is Open Shortest Path First (OSPF) protocol, Intermediate System to Intermediate System (ISIS) protocol, Border Gateway Protocol (BGP) or Path Computation Element Protocol (PCEP).

40. A communication device, characterized in that: include: a memory comprising computer-readable instructions; A processor in communication with the memory, the processor being configured to execute the computer-readable instructions so that the communication device is configured to execute the method of any one of claims 1 to 25.

41. A communication device, characterized in that: include: a memory comprising computer-readable instructions; A processor in communication with the memory, the processor being configured to execute the computer-readable instructions so that the communication device is configured to execute the method of any one of claims 26-39.

42. A communication system, characterized in that Includes the communication device according to claim 40 and the communication device according to claim 41.

43. A computer-readable storage medium, characterized in that The method comprises computer-readable instructions, wherein when the computer-readable instructions are executed on a computer, the computer is caused to implement the method according to any one of claims 1 to 39.

44. A computer program product, characterized in that The method comprises a computer program or a computer-readable instruction, which, when the computer program or the computer-readable instruction is run on a computer, causes the computer to implement the method according to any one of claims 1 to 39.

Citation Information

Patent Citations

  • Method and device for route configuration of virtual private network

    CN103973567A