Access Control List Construction and Data Packet Processing Methods, Apparatus, and Systems
Through matching mask grouping and high-bandwidth memory hashing operation, the problem of low matching efficiency of ACL rules is solved, efficient parallel matching is achieved, and data packet processing is suitable for access control lists.
Patent Information
- Application Number
- CN202211364189.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-02
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-11-02
AI Technical Summary
In the prior art, the matching method of access control list (ACL) rules requires multiple serial searches, resulting in long processing delays and low efficiency, and cannot meet the needs of increasing computer network bandwidth and increasing access devices.
ACL rules are grouped through the match mask, and access control lists of parallel matching are generated. High bandwidth memory and hashing operations are used to achieve fast matching of data packets, reducing the number of serial searches.
It improves the accuracy and efficiency of ACL rule matching, can meet the needs of increasing computer network bandwidth and increasing access equipment, and achieve efficient data packet processing.
Smart Images

Figure CN115695014B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of Internet technologies, and in particular to the field of access control list technologies. Background Art
[0002] An access control list (ACL) is a list of instructions for router and switch interfaces, including one or more access control list (ACL) rules. Each ACL rule is a judgment statement describing the matching conditions of data packets, used for performing rule matching on data packets and executing the execution actions corresponding to the ACL rules that match the data packets, so as to prevent the network from being maliciously attacked, realize the control of network access behavior, limit network traffic, improve network performance, etc.
[0003] In the prior art, the matching method of ACL rules requires multiple serial searches, which will bring multiple memory accesses, increase the processing delay, and have low efficiency. Summary of the Invention
[0004] The present disclosure provides a method, apparatus, system, electronic device, storage medium, computer program product, and network device for constructing an access control list and processing data packets.
[0005] According to a first aspect of the present disclosure, there is provided a method for constructing an access control list, including:
[0006] Grouping the ACL rules included in the access control list (ACL) set according to a matching item mask to obtain at least two rule groups, each rule group corresponding to a matching item mask and the matching items included in the ACL rules in each rule group matching the matching item mask;
[0007] Generating an access control list corresponding to each rule group; the access control list corresponding to each rule group is used to match the ACL rules of data packets in parallel.
[0008] According to a second aspect of the present disclosure, there is provided a method for processing data packets, including:
[0009] Determining the matching items of the data packet;
[0010] According to the matching items of the data packet, parallelly matching the target ACL rules that match the data packet from at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping the ACL rules included in the ACL set according to a matching item mask, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask;
[0011] Perform the execution action corresponding to the target ACL rule on the data packet.
[0012] According to a third aspect of the present disclosure, there is provided a packet processing system, including:
[0013] A processor, configured to determine a matching item of a data packet and send the matching item to a memory storing at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping ACL rules included in an ACL set according to a matching item mask, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask;
[0014] A memory, configured to parallelly match, according to the matching item of the data packet, a target ACL rule that matches the data packet from the at least two access control lists, and send the target ACL rule to the processor;
[0015] The processor is further configured to perform the execution action corresponding to the target ACL rule on the data packet.
[0016] According to a fourth aspect of the present disclosure, there is provided an access control list construction device, including:
[0017] A grouping module, configured to group ACL rules included in an access control list ACL set according to a matching item mask, to obtain at least two rule groups, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask;
[0018] A generating module, configured to generate access control lists corresponding to each rule group; the access control lists corresponding to each rule group are used to parallelly match ACL rules of a data packet.
[0019] According to a fifth aspect of the present disclosure, there is provided a data packet processing device, including:
[0020] A determining module, configured to determine a matching item of a data packet;
[0021] A matching module, configured to parallelly match, according to the matching item of the data packet, a target ACL rule that matches the data packet from at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping ACL rules included in an ACL set according to a matching item mask, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask;
[0022] A processing module, configured to perform an execution action corresponding to the target ACL rule on the data packet.
[0023] According to a sixth aspect of the present disclosure, there is provided an electronic device, including:
[0024] At least one processor; and
[0025] A memory communicatively connected to the at least one processor; wherein,
[0026] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in any one of the above.
[0027] According to a seventh aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method described in any one of the above.
[0028] According to an eighth aspect of the present disclosure, there is provided a computer program product, including a computer program, where the computer program implements the method described in any one of the above when executed by a processor.
[0029] According to a ninth aspect of the present disclosure, there is provided a network device, including:
[0030] At least one processor; and
[0031] A memory communicatively connected to the at least one processor; wherein,
[0032] At least two access control lists are stored in the memory; wherein, the at least two access control lists are obtained according to the access control list construction method described in any one of the above;
[0033] A processor, configured to determine a matching item of a data packet and parallelly match a target ACL rule that matches the data packet from the at least two access control lists according to the matching item of the data packet, and perform an execution action corresponding to the target ACL rule on the data packet.
[0034] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0036] Figure 1Flowchart of a method for constructing an access control list provided by an exemplary embodiment of the present disclosure;
[0037] Figure 2 Flowchart of grouping ACL rules in a method for constructing an access control list provided by an exemplary embodiment of the present disclosure;
[0038] Figure 3 Flowchart of updating an access control list in a method for constructing an access control list provided by an exemplary embodiment of the present disclosure;
[0039] Figure 4 Flowchart of a method for processing packets provided by an exemplary embodiment of the present disclosure;
[0040] Figure 5 Schematic structural diagram of a packet processing system provided by an exemplary embodiment of the present disclosure;
[0041] Figure 6 Schematic diagram of modules of an access control list construction device provided by an exemplary embodiment of the present disclosure;
[0042] Figure 7 Schematic diagram of modules of a data packet processing device provided by an exemplary embodiment of the present disclosure;
[0043] Figure 8 Block diagram of an electronic device provided by an exemplary embodiment of the present disclosure. Detailed implementation manners
[0044] The following makes an explanation of exemplary embodiments of the present disclosure with reference to the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0045] ACL is a network data packet filtering technology, including one or more ACL rules, and each ACL rule is a judgment statement describing the matching conditions of data packets. The matching conditions of data packets can be defined according to actual needs, and the matching items included in the matching conditions of data packets include at least one of the following: source address of the data packet, destination address, source port number, destination port number, fragmentation flag, time period information, protocol type, source MAC (Media Access Control) address, and destination MAC address, etc. Each ACL rule configures a corresponding execution action, and the execution action can be but is not limited to discarding the data packet, forwarding the data packet, etc.
[0046] The matching of ACL rules is divided into range matching and exact matching. For an ACL rule with range matching, it contains a wildcard mask, which determines which fields in the matching items of the ACL rule need to be exactly matched and which fields do not need to be matched, so that an ACL rule corresponds to a matching range. An ACL rule with exact matching does not contain a wildcard mask or the wildcard mask is regarded as 0, and all fields of the matching items need to be exactly matched. The network device matches data packets based on these ACL rules and executes the execution actions corresponding to the ACL rules that match them, and the matching ACL rule is the rule with the highest priority.
[0047] With the continuous improvement of the computer network bandwidth and the explosive growth of the number of network devices accessing the network, the requirements of network devices for the table entry scale and matching rate of ACL rule matching are also getting higher and higher. At present, whether it is the method of ACL matching implemented based on software or the method of ACL matching implemented based on the combination of software and hardware, its matching efficiency can no longer meet the requirements of processing network data packets at line speed.
[0048] The embodiments of the present disclosure provide an access control list construction method, which can improve the matching efficiency of ACL rules.
[0049] Figure 1 The flowchart of an access control list construction method provided for an exemplary embodiment of the present disclosure. The access control list construction method includes the following steps:
[0050] Step 101: Group the ACL rules included in the ACL set according to the matching item mask to obtain at least two rule groups.
[0051] Among them, each rule group corresponds to a matching item mask, and the matching items included in the ACL rules in each rule group match the matching item mask of the rule group.
[0052] The number of ACL rules included in the ACL set can be set according to the actual situation, and can be 1 or multiple. The rule types of the ACL rules included in the ACL set include ACL rules with range matching and / or ACL rules with exact matching. The ACL rules with range matching contain wildcard masks. The matching items of the ACL rules can be set according to the actual situation, including at least one of the following: the source address of the data packet, the destination address, the source port number, the destination port number, the fragmentation flag and time period information, the protocol type, the source MAC (Media Access Control) address, and the destination MAC address, etc.
[0053] The matching item mask determines the number of rule groups.
[0054] In one embodiment, the match item mask is determined according to empirical values.
[0055] In one embodiment, the match item mask is determined according to the wildcard mask of the ACL rule. Grouping the ACL rules according to the match item mask determined based on the wildcard mask can better find the common points of different ACL rules, making the number of rule groups obtained by grouping and the number of ACL rules included in each rule group both more suitable, not too many and not too few. Avoiding the number of rule groups being too large, the subsequent generated access control list occupies a large storage space, thus severely restricting the number of ACL rules that can be matched in parallel. Avoiding the number of rule groups being too small, resulting in too many ACL rules included in each rule group and affecting the matching efficiency.
[0056] Specifically, the match item mask set can be determined according to the distribution characteristics of the wildcard masks of all range-matching ACL rules in the ACL set, and the match item mask set includes at least one match item mask. The distribution characteristics of the wildcard masks include the number of different wildcard masks, the value range of the wildcard masks, etc.
[0057] For example, taking the match items of the source address SIP and the destination address DIP as the data packet matching conditions as an example, assuming that the data packet matching condition of a range-matching ACL rule is [192.168.0.0 / 23, 10.2.0.0 / 23], where 192.168.0.0 represents the source address SIP, 10.2.0.0 represents the destination address DIP, and 23 represents the wildcard mask. If it is split according to the following rule [SIP / 0, DIP / 0], where the match item mask is 0, that is, splitting the range-matching ACL rule into a completely matching ACL rule, we get 9 ×2 9 = 262144 groups of rule groups, and each group of rule groups contains one split ACL rule. And if it is split according to the following rule [SIP / 24, DIP / 24], where 24 represents the match item mask, the range-matching ACL rule is split into 2×2 = 4 groups of rule groups. It is easy to see that the number of ACL rules after splitting is determined by the difference between the wildcard mask and the match item mask in the ACL rule. The smaller the difference, the fewer the number of rule groups.
[0058] In order to obtain a more appropriate number of rule groups, the difference between the match item mask and the wildcard mask is less than the difference threshold. The difference threshold is an integer and can be set according to the actual situation. For example, the value range of the difference threshold is [0, 6].
[0059] In one embodiment, in order to improve the efficiency of rule matching, each access control list obtained in step 102 matches the ACL rules of the data packet through at least one controller. Therefore, when determining the number of rule groups, the number of controllers needs to be considered, that is, the second number of rule groups is determined according to the first number of controllers, so that the second number of rule groups is less than or equal to the first number of controllers. Then, the match item mask is determined according to the second number of rule groups to ensure that there are enough controllers to perform ACL rule matching on the access control list generated in step 102, and further ensure that the ACL rules of the data packet can be matched in parallel.
[0060] In one embodiment, each access control list is deployed in the double data rate synchronous dynamic random access memory of the network device to implement the ACL rule matching of the data packet. The controller used for ACL rule matching is a double data rate synchronous dynamic random access memory DDR controller. Therefore, when determining the number of rule groups, the number of DDR controllers needs to be considered, that is, the second number of rule groups is determined according to the first number of DDR controllers, so that the second number of rule groups is less than or equal to the first number of DDR controllers. Then, the match item mask is determined according to the second number of rule groups to ensure that there are enough DDR controllers to perform ACL rule matching on the access control list generated in step 102, and further ensure that the ACL rules of the data packet can be matched in parallel.
[0061] In one embodiment, the match item mask is determined simultaneously according to the wildcard mask and the number of DDR controllers. Each time the match item mask is determined, it is judged whether the second number of rule groups obtained by grouping based on the match item mask is less than or equal to the first number of DDR controllers; if so, it is determined that the match item mask is more appropriate and the match item mask can be used to group the ACL rules; if not, the match item mask is updated, and it is judged whether the second number of rule groups obtained by grouping based on the updated match item mask is less than or equal to the first number of DDR controllers. The match item mask is iteratively updated until the second number of rule groups obtained by grouping based on the updated match item mask is less than or equal to the first number of DDR controllers.
[0062] Determining the match item mask simultaneously according to the parameters in two dimensions of the wildcard mask and the number of DDR controllers can quickly and accurately determine a more appropriate match item mask.
[0063] It should be noted that when the data packet matching conditions of the ACL rules contain multiple matching items, for each matching item, the matching item mask can be set to the same or different. Taking the matching items included in the data packet matching conditions as SIP and DIP as an example, the setting methods of the matching item mask can include but are not limited to: the matching item mask of SIP is 16, and the matching item mask of DIP is 16; or, the matching item mask of SIP is 16, and the matching item mask of DIP is 24.
[0064] The ACL rules include range-matching ACL rules and / or exact-matching ACL rules. The range-matching ACL rules contain wildcard masks, and the exact-matching ACL rules do not contain wildcard masks or the wildcard masks are regarded as 0. The grouping methods for different types of ACL rules are different. See Figure 2 , and the steps for grouping the ACL rules according to the matching item mask include:
[0065] Step 101-0: Determine the matching item mask.
[0066] Step 101-1: Judge whether the ACL rule contains a wildcard mask.
[0067] If the judgment result of Step 101-1 is yes, it means that the ACL rule is a range-matching ACL rule, and then execute Step 101-2. If the judgment result of Step 101-1 is no, it means that the ACL rule is an exact-matching ACL rule, and then execute Step 101-3.
[0068] It should be noted that the execution order of Step 101-0 and Step 101-1 is not limited to Figure 2 shown as first determining the matching item mask and then judging whether the ACL rule contains a wildcard mask; it can also first judge whether the ACL rule contains a wildcard mask and then determine the matching item mask; or judge whether the ACL rule contains a wildcard mask and determine the matching item mask in parallel.
[0069] Step 101-2: Split the matching items of the range-matching ACL rule according to the matching item mask, and divide the ACL rules corresponding to the split matching items into the rule groups corresponding to the matching item masks that match.
[0070] Split the ACL rule to obtain at least two equivalent rules, and the split ACL rules only belong to specific rule groups.
[0071] Step 101-3: Divide the exact-matching ACL rules into the rule groups corresponding to the matching item masks that match.
[0072] For different types of ACL rules, different grouping methods are adopted to ensure the accuracy of ACL rule grouping.
[0073] Taking the ACL set shown in Table 1 as an example, the ACL set includes 3 ACL rules. Among them, Rule A and Rule B are range matching rules, and Rule C is an exact matching rule.
[0074] Table 1
[0075]
[0076] If the ACL is grouped according to the splitting rule [SIP / 24, DIP / 24], where 24 is the matching item mask, the grouping result is shown in Table 2. The matching items of Rule A are split into 4 equivalent rules, namely [192.168.0.0 / 24, 10.2.0.0 / 24], [192.168.0.0 / 24, 10.2.1.0 / 24], [192.168.1.0 / 24, 10.2.0.0 / 24] and [192.168.1.0 / 24, 10.2.1.0 / 24], corresponding to Group a to Group b respectively. The matching items of Rule B match the matching item mask of Group d and do not need to be split, so Rule B is classified into Group d. Rule C is an ACL rule with exact matching and does not need to consider splitting. Moreover, the matching item masks of Group a to Group d do not match the matching items of Rule C, so Rule C is separately classified into Group e.
[0077] Table 2
[0078]
[0079] Adopting different means to group different types of ACL rules can ensure that the number of rule groups and the number of ACL rules included in each rule group are more appropriate.
[0080] Step 102: Generate access control lists corresponding to each rule group.
[0081] The access control lists corresponding to each rule group are used to match the ACL rules of data packets in parallel.
[0082] It can be understood that the number of access control lists generated in Step 102 is the same as the number of rule groups. Deploying all access control lists on network devices can perform parallel matching of ACL rules for data packets.
[0083] In one embodiment, the access control lists of each rule group generated in step 102 are synchronized to the double-data-rate synchronous dynamic random access memory (DDR) of the high bandwidth memory (HBM). Each access control list corresponds to a double-data-rate synchronous dynamic random access memory, and each DDR executes the matching of ACL rules through at least one controller, and the controllers of each DDR execute the ACL rule matching in parallel. Then, by deploying the HBM on the network device, parallel matching of ACL rules for data packets can be performed.
[0084] It should be noted that the number of DDR controllers used for each access control list can be one or more. The number of DDR controllers used for each access control list can be determined according to the number of entries included in the access control list. For access control lists with a relatively large number of entries, two or more DDR controllers can be used. The number of entries is also the number of ACL rules recorded in the access control list.
[0085] Regarding the synchronization of the access control list, it can be, but is not limited to, implemented through PCIe (peripheral component interconnect express, a high-speed serial computer expansion bus).
[0086] HBM is a high-performance DRAM (dynamic random access memory) based on 3D stacking technology, which stacks many DDRs together to form a large-capacity and high-performance DDR combined array. Each DDR has an independent controller and can access concurrently without interference. The embodiments of the present disclosure utilize HBM multi-channel concurrency to implement ACL rule matching, which can support range matching and exact matching of millions of rules, and the matching rate can reach more than 180 million times per second at most.
[0087] Referring to Table 1, generally each ACL rule has a priority. In one embodiment, each access control list constructs an ordered linked list for management in the order of the priorities of the ACL rules from high to low. Referring to Table 2, the equivalent rules of Rule A and Rule B are both classified into Group d. The length of the ordered linked list of Group d is 2. The priority of Rule A is lower than that of Rule B. Therefore, the priority of the equivalent condition of Rule A is lower than that of the equivalent condition of Rule B. That is to say, if the matching item of a data packet matches the matching item mask of Group d, the execution action corresponding to Rule B is executed.
[0088] In the embodiments of the present disclosure, by using a match item mask to group ACL rules and generating access control lists corresponding to each rule group, it is possible to perform parallel matching of ACL rules for data packets, improve the accuracy and matching efficiency of ACL rule matching, and meet the continuous increase in computer network bandwidth and the explosive growth in the number of network access devices.
[0089] The embodiments of the present disclosure are particularly applicable to an ACL set containing a large number of ACL rules. By using a match item mask to group ACL rules, a smaller number of rule groups can be obtained, and correspondingly, a smaller number of access control lists can be obtained. Each access control list uses a parallel matching method, so that the target ACL rule of the data packet can be matched by performing one parallel match or a small number of parallel matches on each access control list, without the need for multiple serial matches, greatly improving the accuracy and matching efficiency.
[0090] In one embodiment, an access control list is generated through a linear list, and this method is simple to implement and has a small computational amount.
[0091] In one embodiment, an access control list is generated through hash operations. Specifically, hash operations are respectively performed on the match items of the ACL rules in each rule group to generate access control lists corresponding to each rule group.
[0092] In the embodiments of the present disclosure, all or part of the match items of the ACL rules are used as key contents and stored in a specific address using a target hash function (which can be set according to actual situations). The access control list lookup algorithm is a widely used algorithm for implementing exact match lookups, and has characteristics such as fast lookup speed and large capacity. In the embodiments of the present disclosure, an access control list is generated through hash operations, so that when performing ACL rule matching, the ACL rule that matches the data packet can be quickly and accurately matched.
[0093] In one embodiment, hash operations are respectively performed on the exact match items of the ACL rules in each rule group to generate access control lists corresponding to each rule group. The exact match item is the part of the match item excluding the number of bits corresponding to the match item mask. Taking the match item of the ACL rule SIP as 192.168.0.0 and the match item mask as 24 as an example, the number of bits of the match item SIP is 32 bits, and the match item mask is 24, which means that the first 24 bits in the number of bits of SIP must be exactly matched, and the last 8 bits can be matched or not. Then, 192.168.0 can be used as the exact match item of the ACL rule.
[0094] The access control list entry index of the access control list is the result of the hash operation of all the exact match items of the split ACL rules within the rule group, and the access control list entry content is the content of the unique or highest-priority ACL rule corresponding to these exact match items, including the exact match items, execution actions, priorities, etc.
[0095] It should be noted that the matching item mask can correspond to the preceding bits in the matching item, the following bits in the matching item, or the middle bits in the matching item. The embodiments of the present disclosure do not make special limitations on this.
[0096] Using exact match items for hash operation can greatly reduce the number of entries in the access control list. For access control lists with a large number of entries, two or more DDR controllers can be used, and each DDR controller can use different hash algorithms to calculate the storage address.
[0097] In one embodiment, there may be hash collisions in the hash operation, that is, different matching items obtain the same storage address through the hash operation. The impact of hash collisions can be reduced by means of multi-bucket hashing. For some rule groups with a large number of split ACL rules, cuckoo hashing can also be used to solve the problem.
[0098] In one implementation, the user can update the access control list in the network device according to actual needs, including adding ACL rules and deleting ACL rules in the access control list. The implementation method of modifying ACL rules is similar to that of adding ACL rules.
[0099] For adding an ACL rule and the ACL rule to be added is a range-matching ACL rule, see Figure 3 After step 102, the following steps are further included:
[0100] Step 103-1: In response to the rule addition instruction, obtain the ACL rule to be added, and determine the rule group into which the ACL rule to be added is to be divided according to the wildcard mask of the ACL rule to be added.
[0101] Step 103-2: Split the ACL rule to be added according to the matching item mask of the rule group to be divided into.
[0102] The ACL rule is split into one or more rules according to the preset mask of the rule group, and the matching items of these split ACL rules are streamlined through the matching item mask, that is, the part of the matching item excluding the bits corresponding to the matching item mask is used as the exact match item of the ACL rule, realizing the streamlining of the matching items.
[0103] The specific implementation method of step 103-2 is similar to that of step 10-2, and will not be elaborated here.
[0104] Step 103-3: Incorporate the split ACL rules to be added into the rule groups to be incorporated to update the rule groups, and update the access control list according to the updated rule groups.
[0105] For the added ACL rules where the ACL rules to be added are exact match ACL rules, determine the rule groups to which the ACL rules to be added are to be incorporated according to the ACL rules to be added, directly incorporate the ACL rules to be added into the rule groups to be incorporated to update the rule groups, and update the access control list according to the updated rule groups, without splitting the ACL rules to be added.
[0106] In the embodiments of the present disclosure, arbitrary expansion of the ACL set can be achieved, with convenient operation, high flexibility, and can meet the requirements for the scale of the table entries for ACL rule matching due to the continuous increase in the current computer network bandwidth and the explosive growth in the number of network devices accessing the network.
[0107] In one embodiment, the updated access control list is also synchronized to the HBM. Since each ACL rule only belongs to a specific rule group, adding a single ACL rule only requires updating the corresponding access control list, with simple operation, small computational load, and no interference with other access control lists.
[0108] In one embodiment, before updating the access control list, first determine whether there is a replacement rule in the access control list that is the same as the matching item of the split ACL rule to be added; if not, that is, there is no replacement rule in the access control list that is the same as the matching item of the split ACL rule to be added, then perform the step of updating the access control list according to the updated rule group; if there is, that is, there is a replacement rule in the access control list that is the same as the matching item of the split ACL rule to be added, then determine the priorities of the split ACL rule to be added and the replacement rule respectively, and retain the one with the higher priority among the split ACL rule to be added and the same rules in the access control list. That is to say, if there is a replacement rule in the access control list that is the same as the matching item of the split ACL rule to be added, it is necessary to further determine whether the priority of the split ACL rule to be added is higher than that of the replacement rule; if so, that is, the priority of the split ACL rule to be added is higher than that of the replacement rule, then delete the replacement rule from the access control list and add the split ACL rule to be added to the access control list; if not, that is, the priority of the split ACL rule to be added is lower than that of the replacement rule, then do nothing, that is, the replacement rule remains in the access control list. By judging the priorities, the accuracy of the priorities of the ACL rules in the access control list can be ensured, avoiding matching incorrect ACL rules.
[0109] Regarding adding the ACL rules to be newly added after splitting to the access control list, it is achieved by performing a hash operation on the ACL rules to be newly added after splitting. The specific implementation method is similar to that of generating the access control list and will not be elaborated here.
[0110] In one embodiment, the access control list is represented by a sequential linked list. The sequential linked list consists of multiple ACL rules with the same matching items in the same rule group. The head node is the ACL rule with the highest priority, and the remaining nodes are connected in the order of the priority of the rules from high to low. The length of the sequential linked list is the number of ACL rules in the rule group. Taking group d in Table 2 as an example, which contains 2 ACL rules, the corresponding length of the sequential linked list is 2. Update the access control list according to the updated rule group, that is, update the sequential linked list according to the matching items or exact matching items of the split ACL rules. For the newly added rules, determine whether there are the same exact matching items in the access control list of this rule group. If not, directly write the split ACL rule (equivalent rule) to the access control list. If so, determine whether the priority of the split ACL rule is higher than the existing entry in the hash access control list. If it is higher, write the split ACL rule to the hash access control list to overwrite the original entry. If not, insert the split ACL rule into the sequential linked list according to the priority to ensure that the ACL rules in the sequential linked list are arranged in the order of the priority from high to low. And through the sequential list method, the ACL rule matching the data packet can be quickly found.
[0111] In one embodiment, synchronize the access control lists of each rule group to the HBM. When new entry content needs to be written, if there is a vacancy in the DDR storage location corresponding to the DDR controller, it can be directly written. If all the DDR storage locations corresponding to the DDR controllers are full, randomly select one DDR controller to kick out the originally stored entry, and then write the new entry. The kicked-out entry is then written to the DDR storage locations corresponding to other DDR controllers in the same rule group until no entry is kicked out.
[0112] For deleting an ACL rule, in response to the rule deletion instruction, first determine the access control list where the ACL rule to be deleted is located and determine whether the ACL rule to be deleted is the ACL rule with the highest priority in the access control list. If so, that is, the deleted ACL rule is the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list, and re-determine the priority of the ACL rules in the access control list after deleting the ACL rule to be deleted; if not, that is, the ACL rule to be deleted is not the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list.
[0113] The implementation method of the access control list where the ACL rule to be deleted is located is similar to the implementation method of the access control list to which the ACL rule to be added is to be assigned, and will not be elaborated here.
[0114] In one embodiment, when the access control list is represented by a sequential linked list, for deleting a rule, it is determined whether the length of the sequential linked list corresponding to its exact match item is 1. If the length of the sequential linked list is 1, the access control list entry and the sequential linked list corresponding to the exact match item can be directly deleted. If the length of the sequential linked list is greater than 1, it is necessary to determine whether the ACL rule is the head node of the sequential linked list. If it is the head node, it needs to be deleted from the sequential linked list and the head node of the sequential linked list is updated, and at the same time, the rule of the new head node is written into the access control list to overwrite the original entry. If it is not the head node, it only needs to be deleted from the sequential linked list, and there is no need to update the access control list separately.
[0115] In one embodiment, the access control list after deleting the ACL rule to be deleted is also synchronized to the HBM.
[0116] When the ACL set changes, such as adding or deleting an ACL rule, the embodiments of the present disclosure can calculate the access control list that needs to be changed. Since each ACL rule only belongs to a specific rule group, the addition or deletion of an ACL rule only needs to update the corresponding access control list, and when updating the access control list, other access control lists will not be interfered with.
[0117] The embodiments of the present disclosure also provide a data packet processing method. Refer to Figure 4 This data packet processing method includes the following steps:
[0118] Step 401: Determine the matching item of the data packet.
[0119] The matching item of the data packet corresponds to the matching item of the ACL rule, and includes at least one of the following: the source address of the data packet, the destination address, the source port number, the destination port number, the fragmentation flag and time period information, the protocol type, the source MAC (Media Access Control) address, and the destination MAC address, etc.
[0120] In one embodiment, after receiving the data packet, the network device first parses the data packet, extracts the matching item therefrom, and at the same time stores the data packet in the packet buffer.
[0121] Step 402: According to the matching item of the data packet, parallelly match the target ACL rule that matches the data packet from at least two access control lists.
[0122] Each group achieves exact matching through an access control list search algorithm, and finally summarizes and outputs the matching results of each group.
[0123] At least two access control lists in step 402 are generated according to the access control list provided in any of the above embodiments, and the specific implementation process will not be elaborated here.
[0124] If multiple ACL rules matching the data packet are matched in parallel from at least two access control lists, the ACL rule with the highest priority among the multiple matching ACL rules is determined as the target ACL rule.
[0125] Step 403: Execute the execution action corresponding to the target ACL rule on the data packet.
[0126] In the embodiments of the present disclosure, the access control list corresponding to each rule group generated by grouping the ACL rules through the matching item mask can implement parallel matching of the ACL rules of the data packet, improve the accuracy and matching efficiency of the ACL rule matching, and can meet the continuous improvement of the computer network bandwidth and the explosive growth of the number of access network devices.
[0127] If the access control list is generated by performing a hash operation on the matching items of the ACL rules in each rule group respectively, when matching the ACL rules, a hash operation is performed on the matching items of the data packet, and the target ACL rule matching the data packet is matched in parallel from at least two access control lists according to the operation result of the hash operation.
[0128] In the embodiments of the present disclosure, the access control list is generated by a hash operation, so that when performing ACL rule matching, the ACL rule matching the data packet can be quickly and accurately matched.
[0129] If the access control list is generated by performing a hash operation on the exact matching items of the ACL rules in each rule group respectively, when matching the ACL rules, first determine the exact matching items from the matching items of the data packet according to the matching item mask corresponding to each rule group, perform a hash operation on the exact matching items of the data packet, and match the target ACL rule matching the data packet in parallel from at least two access control lists according to the operation result of the hash operation.
[0130] Using the exact matching items for hash operation can greatly reduce the number of entries in the access control list. For an access control list with a large number of entries, two or more DDR controllers can be used, and each DDR controller can use different hash algorithms to calculate the storage address.
[0131] In one embodiment, before performing ACL rule matching, it is first determined whether the access control list of this rule group is valid. If it is invalid, an invalid result is directly output. If it is valid, a hash operation is performed on the matching item or exact matching item of the data packet (depending on whether a matching item or an exact matching item is used when constructing the access control list). The result after the hash operation is used as the address for reading the access control list to obtain the corresponding table entry. After comparing the matching item or exact matching item with the matching item or exact matching item stored in the access control list, the matching ACL rule is determined.
[0132] In one embodiment, the access control lists of each rule group are synchronized to the HBM, and parallel matching of ACL rules is implemented by means of the HBM.
[0133] Since the HBM is a memory implemented based on synchronous dynamic random access memory (SDRAM), it needs to be continuously refreshed and precharged during use, which limits the access bandwidth of the memory interface. To ensure the search efficiency, each DDR controller in the HBM uses table entry replication, that is, multiple copies of the access control list are replicated, and the multiple copies of the access control list are stored on multiple row banks of the double data rate synchronous dynamic random access memory. These banks are polled when performing table entry lookup, thereby avoiding long waiting times caused by refreshing and precharging and improving the bandwidth utilization rate.
[0134] The embodiments of the present disclosure also provide a packet processing system. Refer to Figure 5 and this packet processing system includes:
[0135] A processor 51, configured to determine a matching item of a data packet and send the matching item to a memory storing at least two access control lists.
[0136] Wherein, at least two access control lists are generated by the access control list construction method provided in any of the above embodiments.
[0137] A memory 52, configured to parallelly match a target ACL rule matching the data packet from the at least two access control lists according to the matching item of the data packet, and send the target ACL rule to the processor;
[0138] The processor 51 is further configured to perform an execution action corresponding to the target ACL rule on the data packet.
[0139] In the embodiments of the present disclosure, ACL matching is implemented by combining software and hardware, which has a relatively low cost, is simple and reliable to implement, and can simultaneously meet the requirements of network devices for the entry scale and matching rate of ACL rule matching. Through an efficient hash search algorithm, multiple received data packets can be timely subjected to ACL rule matching, realizing continuous processing of data packets, and the matching efficiency can reach more than 180 million times per second at most, meeting the line speed processing capabilities for 100G small packets and 1T large packets.
[0140] Optionally, the memory is a high-bandwidth memory, and the high-bandwidth memory includes at least two double data rate synchronous dynamic random access memories, and each double data rate synchronous dynamic random access memory is used to store an access control list;
[0141] The controller of each double data rate synchronous dynamic random access memory is used to perform ACL rule matching from the corresponding double data rate synchronous dynamic random access memory.
[0142] Optionally, the controller is further used to copy multiple copies of the access control list and store the multiple copies of the access control list on multiple rows of the double data rate synchronous dynamic random access memory.
[0143] Since HBM is a memory implemented based on synchronous dynamic random access memory, it needs to be continuously refreshed and precharged during use, which limits the access bandwidth of the memory interface. To ensure the search efficiency, each DDR controller in HBM uses entry replication, that is, copies multiple copies of the access control list and stores the multiple copies of the access control list on multiple row banks of the double data rate synchronous dynamic random access memory. When performing entry search, these banks are polled, thereby avoiding long waiting times caused by refreshing and precharging and improving the bandwidth utilization rate.
[0144] Optionally, the processor is an FPGA (Field-Programmable Gate Array).
[0145] In the embodiments of the present disclosure, ACL matching is implemented by combining software and hardware, which has a relatively low cost, is simple and reliable to implement, and can simultaneously meet the requirements of network devices for the entry scale and matching rate of ACL rule matching. Through an efficient hash search algorithm, the matching efficiency can reach more than 180 million times per second at most, meeting the line speed processing capabilities for 100G small packets and 1T large packets.
[0146] Corresponding to the foregoing embodiments of the access control list construction method and the data packet processing method, the present disclosure also provides embodiments of an access control list construction device and a data packet processing device.
[0147] Figure 6A schematic diagram of modules of an access control list construction device provided by an exemplary embodiment of the present disclosure. The access control list construction device includes:
[0148] A grouping module 61, configured to group the access control list (ACL) rules included in the ACL set according to a match item mask, to obtain at least two rule groups, each rule group corresponding to a match item mask and the match items included in the ACL rules in each rule group matching the match item mask;
[0149] A generation module 62, configured to generate access control lists corresponding to the respective rule groups; the access control lists corresponding to the respective rule groups are used to match the ACL rules of the data packet in parallel.
[0150] Optionally, it further includes:
[0151] A determination module, configured to determine the match item mask according to the wildcard mask of each ACL rule and / or the first quantity of the controller; each controller is used to match the ACL rules of the data packet from an access control list.
[0152] Optionally, the difference between the match item mask and the wildcard mask is less than a difference threshold.
[0153] Optionally, the second quantity of the rule groups obtained according to the match item mask is less than or equal to the first quantity.
[0154] Optionally, the grouping module includes:
[0155] A first determination unit, configured to determine the first quantity of the controllers; each controller is used to match the ACL rules of the data packet from an access control list;
[0156] A second determination unit, configured to determine the second quantity of the rule groups obtained by grouping the ACL rules according to the match item mask;
[0157] A judgment unit, configured to judge whether the second quantity is greater than the first quantity;
[0158] A grouping module, configured to update the match item mask when the second quantity is greater than the first quantity, and regroup the ACL rules according to the updated match item mask, so that the second quantity of the regrouped rule groups is less than or equal to the first quantity.
[0159] Optionally, the grouping module includes:
[0160] A judgment unit, configured to judge whether the ACL rules include a wildcard mask;
[0161] If the ACL rule contains a wildcard mask, the determination unit calls the first grouping unit; if the ACL rule does not contain a wildcard mask, the determination unit calls the second grouping unit;
[0162] The first grouping unit is configured to split the matching items of the ACL rule according to the matching item mask, and divide the ACL rules corresponding to the split matching items into the rule groups corresponding to the matching item masks that match;
[0163] The second grouping unit is configured to divide the ACL rule into the rule group corresponding to the matching item mask that matches.
[0164] Optionally, the generation module is specifically configured to:
[0165] Perform a hash operation on the matching items or exact matching items of the ACL rules in each rule group respectively to generate an access control list corresponding to each rule group; wherein, the exact matching item is the part of the matching item excluding the number of bits corresponding to the matching item mask.
[0166] Optionally, it further includes:
[0167] An update module, configured to, in response to a rule addition instruction, obtain the ACL rule to be added, determine the rule group to which the ACL rule to be added is to be divided according to the wildcard mask of the ACL rule to be added, and split the ACL rule to be added according to the matching item mask of the rule group to be divided, and divide the split ACL rule to be added into the rule group to be divided to update the rule group, and update the access control list according to the updated rule group.
[0168] Optionally, the ACL rules in the access control list are arranged in descending order of priority; when updating the access control list according to the updated rule group, the update module is configured to:
[0169] Determine whether there is a rule to be replaced in the access control list whose matching item is the same as the matching item of the split ACL rule to be added:
[0170] If not, perform the step of updating the access control list according to the updated rule group;
[0171] If so, determine whether the priority of the split ACL rule to be added is higher than the priority of the rule to be replaced;
[0172] If so, delete the rule to be replaced from the access control list, and add the split ACL rule to be added to the access control list.
[0173] Optionally, the ACL rules in the access control list are arranged in descending order of priority; the access control list construction device further includes:
[0174] An update module, configured to, in response to a rule deletion instruction, determine whether the ACL rule to be deleted is the ACL rule with the highest priority in the access control list where the ACL rule to be deleted is located; if the ACL rule to be deleted is the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list, and re-determine the priority of the ACL rules in the access control list after deleting the ACL rule to be deleted; if the ACL rule to be deleted is not the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list.
[0175] Optionally, it further includes:
[0176] A synchronization module, configured to synchronize the access control lists of the respective rule groups to a double data rate synchronous dynamic random access memory in high bandwidth memory, and each access control list corresponds to a double data rate synchronous dynamic random access memory.
[0177] Figure 7 The figure is a schematic diagram of modules of a data packet processing device provided by an exemplary embodiment of the present disclosure. The data packet processing device includes:
[0178] A determination module 71, configured to determine a matching item of a data packet;
[0179] A matching module 72, configured to, according to the matching item of the data packet, parallelly match a target ACL rule that matches the data packet from at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping the ACL rules included in the ACL set according to a matching item mask, each rule group corresponds to a matching item mask, and the matching items included in the ACL rules in each rule group match the matching item mask;
[0180] A processing module 73, configured to perform an execution action corresponding to the target ACL rule on the data packet.
[0181] Optionally, the access control list is generated by performing a hash operation on the ACL rules in each rule group respectively;
[0182] The matching module is specifically configured to:
[0183] Perform a hash operation on the matching item of the data packet, and parallelly match a target ACL rule that matches the data packet from the at least two access control lists according to the operation result of the hash operation.
[0184] For the apparatus embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the descriptions of the method embodiments. The apparatus embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0185] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0186] Figure 8 FIG. is a block diagram of an electronic device provided by an exemplary embodiment of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0187] As Figure 8 shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the device 800 can also be stored. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0188] A plurality of components in the device 800 are connected to the I / O interface 805, including: an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the device 800 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0189] The computing unit 801 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 executes the various methods and processes described above, such as the access control list building method and the data packet processing method. For example, in some embodiments, the access control list building method and the data packet processing method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the access control list building method and the data packet processing method described above can be executed. Alternatively, in other embodiments, the computing unit 801 can be configured to execute the access control list building method and the data packet processing method in any other suitable way (e.g., by means of firmware).
[0190] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-a-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0191] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0192] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0193] For providing interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).
[0194] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0195] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server incorporating a blockchain.
[0196] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. No limitation is imposed herein.
[0197] Embodiments of this disclosure also provide a network device, which includes:
[0198] At least one processor; and
[0199] A memory communicatively connected to the at least one processor; wherein,
[0200] At least two access control lists are stored in the memory; wherein, the at least two access control lists are obtained according to the access control list construction method provided in any of the above embodiments;
[0201] The processor is configured to determine a matching item of a data packet and match in parallel from the at least two access control lists a target ACL rule that matches the data packet according to the matching item of the data packet, and perform an execution action corresponding to the target ACL rule on the data packet.
[0202] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. An access control list construction method, comprising: Grouping the access control list (ACL) rules included in the ACL set according to a match item mask to obtain at least two rule groups, where each rule group corresponds to a match item mask and the match items included in the ACL rules in each rule group match the corresponding match item mask; Generating access control lists corresponding to each of the rule groups; the access control lists corresponding to each of the rule groups are used to match the ACL rules of the data packet in parallel; Before grouping the ACL rules included in the ACL set according to the match item mask, it further includes: Determining the match item mask according to the wildcard mask of each ACL rule and / or the first quantity of the controller; where each controller is used to match the ACL rules of the data packet from an access control list; The difference between the match item mask and the wildcard mask is less than a difference threshold.
2. The access control list construction method according to claim 1, where the second quantity of the rule groups is less than or equal to the first quantity.
3. The access control list construction method according to claim 1, where grouping the ACL rules included in the ACL set according to the match item mask includes: Determining the first quantity of the controller; Each controller is used to match the ACL rules of the data packet from an access control list; Determining the second quantity of the rule groups obtained by grouping the ACL rules according to the match item mask; Judging whether the second quantity is greater than the first quantity; If the second quantity is greater than the first quantity, updating the match item mask and regrouping the ACL rules according to the updated match item mask so that the second quantity of the rule groups obtained by regrouping is less than or equal to the first quantity.
4. The access control list construction method according to claim 1, where grouping the ACL rules according to the match item mask includes: Judging whether the ACL rule includes a wildcard mask; If the ACL rule includes a wildcard mask, splitting the match items of the ACL rule according to the match item mask and dividing the ACL rules corresponding to the split match items into the rule groups corresponding to the matching match item masks; If the ACL rule does not include a wildcard mask, dividing the ACL rule into the rule group corresponding to the matching match item mask.
5. The access control list construction method according to claim 1, wherein, Generating the access control lists corresponding to each of the rule groups includes: Performing a hash operation on the match items or exact match items of the ACL rules in each of the rule groups respectively to generate access control lists corresponding to each of the rule groups; where the exact match item is the part of the match item excluding the number of bits corresponding to the match item mask.
6. The access control list construction method according to claim 1, further includes: In response to a rule addition instruction, obtaining the to-be-added ACL rule and determining the rule group to which the to-be-added ACL rule is to be assigned according to the wildcard mask of the to-be-added ACL rule; Splitting the to-be-added ACL rule according to the match item mask of the rule group to which it is to be assigned; The split ACL rules to be newly added are classified into the rule groups to be classified to update the rule groups, and the access control list is updated according to the updated rule groups.
7. The access control list construction method according to claim 6, wherein the ACL rules in the access control list are arranged in descending order of priority; the updating the access control list according to the updated rule groups includes: Determining whether there is a rule to be replaced in the access control list that is the same as the matching item of the split ACL rule to be newly added; If not, performing the step of updating the access control list according to the updated rule groups; If so, determining whether the priority of the split ACL rule to be newly added is higher than the priority of the rule to be replaced; If so, deleting the rule to be replaced from the access control list and adding the split ACL rule to be newly added to the access control list.
8. The access control list construction method according to claim 1, wherein the ACL rules in the access control list are arranged in descending order of priority; The access control list construction method further includes: In response to a rule deletion instruction, determining whether the ACL rule to be deleted is the ACL rule with the highest priority in the access control list where the ACL rule to be deleted is located; If the ACL rule to be deleted is the ACL rule with the highest priority in the access control list, deleting the ACL rule to be deleted in the access control list and re-determining the priority of the ACL rules in the access control list after deleting the ACL rule to be deleted; If the ACL rule to be deleted is not the ACL rule with the highest priority in the access control list, deleting the ACL rule to be deleted in the access control list.
9. The access control list construction method according to any one of claims 1-8 further includes: Synchronizing the access control lists of the respective rule groups to a double data rate synchronous dynamic random access memory of a high bandwidth memory, with each access control list corresponding to a double data rate synchronous dynamic random access memory.
10. A data packet processing method, including: Determining a matching item of a data packet; According to the matching item of the data packet, parallelly matching target ACL rules that match the data packet from at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping the ACL rules included in an ACL set according to a matching item mask, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask; the matching item mask is determined according to the wildcard mask of each ACL rule and / or the first quantity of a controller, and the difference between the matching item mask and the wildcard mask is less than a difference threshold; each controller is used to match the ACL rules of the data packet from one access control list; Performing an execution action corresponding to the target ACL rule on the data packet.
11. The data packet processing method according to claim 10, wherein the access control list is generated by respectively performing a hash operation on the matching items of the ACL rules in each rule group. Parallelly matching, from at least two access control lists, a target ACL rule that matches the data packet according to the matching item of the data packet includes: Performing a hash operation on the matching item of the data packet, and parallelly matching, from the at least two access control lists, a target ACL rule that matches the data packet according to the operation result of the hash operation; Alternatively, the access control list is generated by performing a hash operation on the exact matching items of the ACL rules in each rule group respectively; Parallelly matching, from at least two access control lists, a target ACL rule that matches the data packet according to the matching item of the data packet includes: Determining an exact matching item from the matching items of the data packet according to the matching item mask corresponding to each rule group; the exact matching item is the part of the matching item excluding the number of bits corresponding to the matching item mask; Performing a hash operation on the exact matching item of the data packet, and parallelly matching, from the at least two access control lists, a target ACL rule that matches the data packet according to the operation result of the hash operation.
12. A packet processing system, comprising: A processor, configured to determine a matching item of a data packet and send the matching item to a memory storing at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, the at least two rule groups are obtained by grouping the ACL rules included in an ACL set according to a matching item mask, each rule group corresponds to a matching item mask and the matching items included in the ACL rules in each rule group match the matching item mask; the matching item mask is determined according to the wildcard mask of each ACL rule and / or the first quantity of a controller, and the difference between the matching item mask and the wildcard mask is less than a difference threshold; each controller is configured to match the ACL rule of the data packet from one access control list; A memory, configured to parallelly match, from the at least two access control lists, a target ACL rule that matches the data packet according to the matching item of the data packet, and send the target ACL rule to the processor; The processor is further configured to perform an execution action corresponding to the target ACL rule on the data packet.
13. The message processing system according to claim 12, wherein, The memory is a high-bandwidth memory, and the high-bandwidth memory includes at least two double data rate synchronous dynamic random access memories, and each double data rate synchronous dynamic random access memory is configured to store an access control list; The controller of each double data rate synchronous dynamic random access memory is configured to perform ACL rule matching from the corresponding double data rate synchronous dynamic random access memory.
14. The packet processing system according to claim 13, wherein the controller is further configured to copy multiple copies of the access control list and store the multiple copies of the access control list on multiple rows of the double data rate synchronous dynamic random access memory.
15. An access control list construction device, comprising: A grouping module, configured to group the ACL rules included in the access control list (ACL) set according to a match item mask, so as to obtain at least two rule groups, where each rule group corresponds to a match item mask and the match items included in the ACL rules in each rule group match the match item mask; A generating module, configured to generate access control lists corresponding to the respective rule groups; the access control lists corresponding to the respective rule groups are used to match the ACL rules of the data packet in parallel; The access control list construction device further includes: A determining module, configured to determine the match item mask according to the wildcard mask of each ACL rule and / or the first quantity of the controllers; where each controller is used to match the ACL rules of the data packet from one access control list; The difference between the match item mask and the wildcard mask is less than a difference threshold.
16. The access control list construction device according to claim 15, wherein, The second quantity of the rule groups is less than or equal to the first quantity.
17. The access control list construction device according to claim 15, where the grouping module includes: A first determining unit, configured to determine the first quantity of the controllers; Each controller is used to match the ACL rules of the data packet from one access control list; A second determining unit, configured to determine the second quantity of the rule groups obtained by grouping the ACL rules according to the match item mask; A judging unit, configured to judge whether the second quantity is greater than the first quantity; A grouping module, configured to update the match item mask in the case that the second quantity is greater than the first quantity, and re-group the ACL rules according to the updated match item mask, so that the second quantity of the rule groups obtained by re-grouping is less than or equal to the first quantity.
18. The access control list construction device according to claim 15, where the grouping module includes: A judging unit, configured to judge whether the ACL rule includes a wildcard mask; If the ACL rule includes a wildcard mask, the judging unit calls a first grouping unit; if the ACL rule does not include a wildcard mask, the judging unit calls a second grouping unit; The first grouping unit is configured to split the match items of the ACL rule according to the match item mask, and divide the ACL rules corresponding to the split match items into the rule groups corresponding to the matching match item masks; The second grouping unit is configured to divide the ACL rules into the rule groups corresponding to the matching match item masks.
19. The access control list construction device according to claim 15, wherein, The generating module is specifically configured to: Perform a hash operation on the match items or exact match items of the ACL rules in each rule group respectively to generate access control lists corresponding to the respective rule groups; where the exact match item is the part of the match item excluding the bits corresponding to the match item mask.
20. The access control list construction device according to claim 15, further includes: An update module, configured to, in response to a rule addition instruction, obtain an ACL rule to be added, determine a rule group into which the ACL rule to be added is to be classified according to a wildcard mask of the ACL rule to be added, split the ACL rule to be added according to a matching item mask of the rule group to be classified, and classify the split ACL rule to be added into the rule group to be classified to update the rule group, and update the access control list according to the updated rule group.
21. The access control list construction apparatus according to claim 20, wherein the ACL rules in the access control list are arranged in descending order of priority; when updating the access control list according to the updated rule group, the update module is configured to: Determine whether there is a rule to be replaced in the access control list that has the same matching item as the split ACL rule to be added; If not, update the access control list according to the updated rule group; If so, determine whether the priority of the split ACL rule to be added is higher than the priority of the rule to be replaced; If so, delete the rule to be replaced from the access control list, and add the split ACL rule to be added to the access control list.
22. The access control list construction device according to claim 15, wherein the ACL rules in the access control list are arranged in descending order of priority; The access control list construction apparatus further includes: An update module, configured to, in response to a rule deletion instruction, determine whether the ACL rule to be deleted is the ACL rule with the highest priority in the access control list where the ACL rule to be deleted is located; If the ACL rule to be deleted is the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list, and re-determine the priorities of the ACL rules in the access control list after deleting the ACL rule to be deleted; if the ACL rule to be deleted is not the ACL rule with the highest priority in the access control list, delete the ACL rule to be deleted in the access control list.
23. The access control list construction apparatus according to any one of claims 15-22, further includes: A synchronization module, configured to synchronize the access control lists of the respective rule groups to a double data rate synchronous dynamic random access memory of a high-bandwidth memory, and each access control list corresponds to a double data rate synchronous dynamic random access memory.
24. A data packet processing apparatus, including: A determination module, configured to determine a matching item of a data packet; A matching module, configured to match, according to the matching items of the data packet, a target ACL rule that matches the data packet in parallel from at least two access control lists; wherein, the at least two access control lists are generated according to at least two rule groups, and the at least two rule groups are obtained by grouping the ACL rules included in the ACL set according to a matching item mask, each rule group corresponds to a matching item mask, and the matching items included in the ACL rules in each rule group match the matching item mask; the matching item mask is determined according to the wildcard mask of each ACL rule and / or the first quantity of the controller, and the difference between the matching item mask and the wildcard mask is less than a difference threshold; each controller is configured to match the ACL rule of the data packet from one access control list; A processing module, configured to perform an execution action corresponding to the target ACL rule on the data packet.
25. The data packet processing apparatus according to claim 24, wherein the access control list is generated by performing a hash operation on the ACL rules in each rule group respectively; The matching module is specifically configured to: Perform a hash operation on the matching items of the data packet, and match, according to the operation result of the hash operation, a target ACL rule that matches the data packet in parallel from the at least two access control lists; Alternatively, the access control list is generated by performing a hash operation on the exact matching items of the ACL rules in each rule group respectively; The matching module is specifically configured to: Determine an exact matching item from the matching items of the data packet according to the matching item mask corresponding to each rule group; the exact matching item is the part of the matching item excluding the bits corresponding to the matching item mask; Perform a hash operation on the exact matching items of the data packet, and match, according to the operation result of the hash operation, a target ACL rule that matches the data packet in parallel from the at least two access control lists.
26. An electronic device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-11.
27. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-11.
28. A computer program product, comprising a computer program, where the computer program, when executed by a processor, implements the method according to any one of claims 1-11.
29. A network device, comprising: At least one processor; And A memory communicatively connected to the at least one processor; wherein, At least two access control lists are stored in the memory; wherein, the at least two access control lists are obtained according to the access control list construction method according to any one of claims 1-9; A processor, configured to determine matching items of a data packet and, based on the matching items of the data packet, parallelly match, from the at least two access control lists, a target ACL rule that matches the data packet, and perform an execution action corresponding to the target ACL rule on the data packet.
Citation Information
Patent Citations
ACL (access control list) query method and device
CN106027459A
Technologies for access control
US20160191530A1