A method, device and medium for service chain orchestration for SYN proxy

By identifying and processing network element devices that enable SYN proxy in the service chain orchestration device, constructing and sending ACK packets, the traffic forwarding problem caused by SYN proxy is solved, and support for more network element devices and topological scenarios is achieved.

CN115695527BActive Publication Date: 2025-05-16QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211372074.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-03
Publication Date
2025-05-16
Estimated Expiration
2042-11-03

AI Technical Summary

Technical Problem

In service chain orchestration, when the network element device enables the SYN proxy function, the service chain orchestration device cannot forward traffic normally because the SYN proxy changes the order of the TCP handshake packets, resulting in the service chain orchestration device being unable to determine how to handle subsequent data packets.

Method used

By identifying the network element device that enables the SYN proxy in the service chain, constructing an ACK data packet, and sending the data packet to the relevant network element devices to ensure that the order of the TCP handshake process between the service chain orchestration device and the network element device is consistent.

Benefits of technology

Even if the SYN proxy is enabled for the network element device, the service chain orchestration device can still correctly forward traffic, supporting more network element devices and adapting to a wider topological scenario.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115695527B_ABST
    Figure CN115695527B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a method, device, and medium for service chain orchestration for SYN proxy, the method comprising: identifying a target network element device on any service chain, wherein the any service chain is used to characterize a plurality of sequentially arranged network element devices corresponding to any business logic; constructing an ACK packet according to a SYN‑ACK packet received from the target network element device; and sending the ACK packet to at least one network element device on the service chain to ensure the order in which the service chain orchestration device and each network element device on the any service chain process the TCP protocol handshake process. Through the embodiments of the present application, even if the network element device on the service chain has the SYN proxy function enabled, traffic forwarding can be achieved through the service chain orchestration device, so that the service chain orchestration device can support more network element devices and adapt to a wider range of topology scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of service chain orchestration. Specifically, embodiments of the present application relate to a method, device, and medium for service chain orchestration for a SYN proxy. Background Art

[0002] Service Function Chaining (SFC) means that network traffic passes through various network element devices (Network Function, NF) in sequence according to business logic requirements to form an orderly network service combination.

[0003] SYN Proxy is a lightweight proxy in the TCP handshake phase, usually using SYN-Cookie to ensure that only connections that complete the entire TCP handshake with itself are considered normal connections. SYN Proxy is mainly used to defend against SYN flood attacks.

[0004] With the development of cloud computing, the Internet of Things, and mobile smart devices, network traffic is growing rapidly and network services are constantly changing. In order to ensure network traffic security and network service stability, various network element devices need to be dynamically adjusted. Therefore, there is a strong demand for service chain orchestration.

[0005] The service chain orchestration device forwards traffic through the diversion strategy, and introduces user traffic from one network element device to another network element device in the defined orchestration order. In the case of non-SYN proxy, the existing service chain orchestration devices can realize traffic forwarding, such as Figure 1 As shown in the figure, a TCP link three-way handshake process between the service chain orchestration device and a single network element device (the numbers in the figure indicate the forwarding order of data packets).

[0006] If a network element device in the service chain turns on SYN proxy, the traffic arranged by the service chain cannot be forwarded normally, because the order in which the network element device with SYN proxy turned on processes the TCP protocol three-way handshake packets between each network element changes, such as Figure 2 As shown in the figure (the numbers in the figure indicate the order in which data packets are forwarded), after the service chain orchestration device sends the SYN packet to the network element device through the service chain intranet interface, it was originally expected that the SYN packet returned by the network element device would be received from the service chain external network interface. As a result, the SYN_ACK packet of the network element device was received from the service chain intranet interface of the service chain device. Since the session lacks certain information (such as reverse traffic information, etc.), the service chain orchestration device does not know how to forward subsequent data packets, whether to send this SYN_ACK to the client device or the server device, or to perform other operations. This puts forward new requirements for the service chain orchestration device. Summary of the invention

[0007] The purpose of the embodiments of the present application is to provide a method, device, and medium for service chain orchestration for SYN proxy. Through the embodiments of the present application, even if the network element device on the service chain has the SYN proxy function enabled, traffic forwarding can be achieved through the service chain orchestration device, thereby enabling the service chain orchestration device to support more network element devices and adapt to a wider range of topology scenarios.

[0008] In a first aspect, an embodiment of the present application provides a method for service chain orchestration for a SYN proxy, which is applied to a service chain orchestration device, the method comprising: identifying a target network element device on any service chain, wherein the any service chain is used to represent a plurality of sequentially arranged network element devices corresponding to any business logic, if there is only one network element device with a SYN proxy enabled on the any service chain, the target network element device is the network element device with the SYN proxy enabled, if there are a plurality of network element devices with a SYN proxy enabled on the any service chain, the target network element device is the network element device with the SYN proxy enabled that is ranked highest among the plurality of network element devices with the SYN proxy enabled; constructing an ACK packet based on a SYN-ACK packet received from the target network element device; and sending the ACK packet to at least one network element device on the any service chain to ensure the order in which the service chain orchestration device and each network element device on the any service chain process a TCP protocol handshake process corresponding to a first session.

[0009] Some embodiments of the present application can ensure that the service chain orchestration device can still correctly forward traffic after the network element device turns on the SYN proxy by generating an ACK packet and providing the ACK packet to the network element device on the service chain when confirming the first network element device that turns on the SYN service on any service chain.

[0010] In some embodiments, sending the ACK data packet to at least one network element device on any one of the service chains includes: sending the ACK data packet to at least one network element device starting from a first network element device on any one of the service chains.

[0011] Some embodiments of the present application provide ACK data packets generated by a service chain orchestration device starting from the first network element device on any service chain to ensure that each network element device on the service chain establishes a valid connection.

[0012] In some embodiments, the identifying of the target network element device on any service chain includes: identifying the target network element device by determining the source of the target SYN-ACK data packet, wherein the target SYN-ACK data packet is the first SYN-ACK data packet used to establish a TCP connection corresponding to the first session.

[0013] Some embodiments of the present application can determine the target network element device that starts the SYN proxy and ranks first in the service chain by identifying the source of the first SYN-ACK data packet used to establish a TCP connection, thereby ensuring that the TCP handshake is completed in an orderly manner between the service chain orchestration and the network element devices.

[0014] In some embodiments, the target network element device is identified by determining the source of the target SYN-ACK data packet, including: if the first SYN-ACK data packet comes from the i-th network element device on any of the service chains, then the i-th network element device is confirmed to be the target network element device, wherein i is an integer greater than or equal to 1, and i is used to represent the arrangement order of the corresponding network element devices on any of the service chains.

[0015] Some embodiments of the present application can find the target network element device by identifying the network element device that sends the first SYN-ACK data packet to the service chain orchestration device for establishing a TCP connection between the client and the server, thereby ensuring that the TCP handshake between the service chain orchestration and the network element device is completed in an orderly manner.

[0016] In some embodiments of the present application, the first session is a session between a client and a server, wherein, after sending the ACK data packet to at least one network element device on any one of the service chains, the method further includes: generating a target data packet if it is confirmed that the server or the client is faulty; and providing the target data packet to at least each network element device on any one of the service chains.

[0017] Some embodiments of the present application generate relevant data packets and provide corresponding data packets to each network element device on the service chain and the other end of the faulty device when confirming that the client or server is faulty and cannot establish a session, so that each network element device can delete and establish data related to the session.

[0018] In some embodiments, if the server failure is confirmed, generating a target data packet includes: sending a SYN data packet to the server, wherein the SYN data packet is provided by a network element device with a SYN proxy enabled on any one of the service chains; if the SYN-ACK data packet sent by the server is not received within a set time period, confirming the server failure; constructing an RST data packet; providing the target data packet to at least each network element device on any one of the service chains includes: sending the RST data packet to each network element device and the client on any one of the service chains.

[0019] Some embodiments of the present application confirm a server failure when a SYN-ACK packet from the server is not received, and then the service chain orchestration device generates a RST packet and sends the packet to each network element device and the client, so that all devices can immediately delete data related to the session.

[0020] In some embodiments, sending the RST data packet to each network element device and the client on any one of the service chains includes: sending the RST data packet in sequence along each of the network element devices on any one of the service chains starting from the last network element device in the service chain until the RST data packet is sent to the first network element device and the client on any one of the service chains.

[0021] The service chain orchestration device of some embodiments of the present application has the ability to forward data packets in a certain order required by the user. The embodiments of the present application provide RST data packets to each network element device on the service chain starting from the last network element device on the service chain to ensure that the data packet message is provided to each network element device as quickly as possible.

[0022] In some embodiments, if the SYN-ACK data packet sent by the server is not received within a set time period, the method also includes: confirming receipt of the pending data packet sent by the client device, wherein the pending data packet is used to establish a TCP connection for a second session; and not providing the pending data packet to any network element device on the service chain.

[0023] Some embodiments of the present application perform a deletion operation on the request data received from the client for establishing a TCP connection for a new session when a server failure is confirmed, which can save resources of the service chain orchestration device and the network element device to the greatest extent.

[0024] In some embodiments, if the client failure is confirmed, generating a target data packet includes: confirming receipt of the SYN-ACK data packet from the server; sending the SYN-ACK data packet to the client, and confirming that the ACK data packet sent by the client device is not received within a set time period, then confirming the client failure; constructing an RST data packet; providing the target data packet to at least each network element device on any one of the service chains includes: sending the RST data packet to each network element device and the server on any one of the service chains.

[0025] When it is confirmed that a client failure cannot establish a TCP connection, some embodiments of the present application enable each network element device to clear data related to the session by generating an RST packet on a service chain orchestration device and sending the RST packet to each device on the service chain.

[0026] In some embodiments, sending the RST data packet to each network element device and the server on any one of the service chains includes: starting from the first network element device on any one of the service chains, sending the RST data packet in sequence along each network element device on any one of the service chains until the RST data packet is sent to the last network element device and the server included in any one of the service chains.

[0027] When a client failure is confirmed, some embodiments of the present application send RST packets to each network element device on the service chain one by one starting from the network element device closest to the client, and send them in a timely manner to ensure that each network element device receives the packet.

[0028] In some embodiments, the identifying of the target network element device on any service chain includes: identifying that the p-th network element device belongs to the target network element device, wherein the p-th network element device belongs to the network element device on any service chain, and the p-th network element device is not ranked first in any service chain; constructing an ACK data packet according to the SYN-ACK data packet received from the target network element device includes: constructing the ACK data packet according to the SYN-ACK data packet received from the p-th network element device; before sending the ACK data packet to at least one network element device on any service chain, the method also includes: forwarding the SYN-ACK data packet of the p-th network element device to the network element device ranked first on any service chain; receiving the SYN-ACK data packet sent by the first network element device; sending the ACK data packet to at least one network element device on any service chain includes: sending the ACK data packet to the first network element device.

[0029] Some embodiments of the present application need to receive in advance a SYN-ACK packet sent by the first network element device to the service chain orchestration device when sending an ACK packet generated by the service chain orchestration device to the first network element device in the service chain, to ensure that the connection between each network element device and the service chain orchestration device is normal and valid.

[0030] In some embodiments, any one of the service chains also includes an nth network element device with SYN proxy enabled, and the nth network element device is located after the target network element device on any one of the service chains. After constructing an ACK packet based on the SYN-ACK packet received from the target network element device, the method also includes: confirming receipt of the SYN-ACK packet sent by the nth device; sending the SYN-ACK packet sent by the nth device to at least some interfaces of each network element device located before the nth network element device on any one of the service chains, and receiving ACK packets sent by each network element device; sending an ACK packet to the nth network element device, and receiving a SYN packet sent by the nth network element device; and continuing to forward the SYN packet sent by the nth network element device until the SYN packet sent by the nth network element device is forwarded to the server, or until the SYN packet sent by the nth network element device is forwarded to the next network element device with SYN proxy enabled.

[0031] In some embodiments of the present application, for a network element device that is not the first to enable the SYN proxy service, it is necessary to first forward the SYN-ACK data packet generated by the device to all network element devices before the network element device, and then send an ACK data packet to the network element device. After that, the network element device will send the SYN message for establishing a session to the service chain orchestration device, and then the service chain orchestration device will forward the SYN to the server to complete the establishment of the TCP connection. This can ensure that after the SYN proxy is enabled, the service chain orchestration device can still send each data packet normally, thereby ensuring the normal establishment of the TCP connection.

[0032] In some embodiments, the first network element device includes an intranet interface and an extranet interface, wherein sending the ACK data packet to at least one network element device starting from the first network element device on any service chain includes: sending the ACK data packet to the intranet interface.

[0033] In some embodiments of the present application, the ACK data packet generated by the service chain orchestration device first needs to be sent to the intranet interface of the first network element device to ensure that subsequent messages are sent smoothly.

[0034] In some embodiments, the target network element device belongs to a network element device different from the first network element device, and the target network element device includes an internal network interface and an external network interface, wherein sending the ACK data packet to at least one network element device on any one of the service chains includes: sending the ACK data packet to the internal network interface of the target network element device; receiving the SYN data packet sent by the external network interface of the target network element device; continuing to forward the SYN data packet sent by the external network interface of the target network element device along the remaining network element devices on any one of the service chains until the SYN data packet sent by the external network interface of the target network element device is forwarded to the server, or until the SYN data packet sent by the external network interface of the target network element device is forwarded to the next network element device on any one of the service chains with the SYN proxy enabled.

[0035] Some embodiments of the present application provide an implementation method for how to generate an ACK packet according to a service chain orchestration device to continue a subsequent forwarding process.

[0036] In a second aspect, some embodiments of the present application provide a service chain orchestration device, the device comprising: a target network element device identification module, configured to identify a target network element device on any service chain, wherein any service chain is used to represent a plurality of sequentially arranged network element devices corresponding to any business logic, if there is only one network element device with SYN proxy enabled on any service chain, then the target network element device is the network element device with SYN proxy enabled, if there are multiple network element devices with SYN proxy enabled on any service chain, then the target network element device is the network element device with the highest order among the multiple network element devices with SYN proxy enabled; a data packet construction module, configured to construct an ACK data packet according to a SYN-ACK data packet received from the target network element device; a forwarding module, configured to send the ACK data packet to at least one network element device on any service chain to ensure the order in which the service chain orchestration device and each network element device on any service chain process the TCP protocol handshake process.

[0037] In a third aspect, some embodiments of the present application provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, can implement the method described in any of the embodiments of the first aspect above.

[0038] In a fourth aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in any embodiment of the first aspect above can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0040] Figure 1 A three-way handshake process diagram of a TCP link between a service chain orchestration device and a single network element device provided for related technologies;

[0041] Figure 2 A diagram of a TCP three-way handshake process between a service chain orchestration device and a network element device after a network element device provides related technologies and starts a SYN proxy;

[0042] Figure 3 A flow chart of a method for service chain orchestration for a SYN proxy provided in an embodiment of the present application;

[0043] Figure 4 One of the three-way handshake process diagrams of a TCP link between a service chain orchestration device and two network element devices provided in an embodiment of the present application;

[0044] Figure 5 Figure 2 of a TCP three-way handshake process between a service chain orchestration device and two network element devices provided in an embodiment of the present application;

[0045] Figure 6 Figure 3 of a TCP link three-way handshake process between a service chain orchestration device and two network element devices provided in an embodiment of the present application;

[0046] Figure 7 A block diagram of the composition of the device for service chain orchestration provided in an embodiment of the present application;

[0047] Figure 8 A schematic diagram of the composition of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0048] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0049] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0050] At least in order to solve the problems in the background technology part, in order to allow the service chain orchestration device to support more network element devices and adapt to a wider range of topology scenarios, for example, even if the network element device has the SYN proxy function turned on, traffic forwarding can be achieved. Some embodiments of the present application first identify whether the network element device has the SYN proxy turned on, and then construct and send a specific type of data packet (for example, construct an ACK data packet or a RST data packet) to the network element device that has the SYN proxy turned on, to ensure the order in which the service chain orchestration device and each network element device process the TCP protocol handshake process, so that the service chain orchestration device supports traffic forwarding when the network element device has the SYN proxy turned on. The embodiments of the present application can be implemented on the service chain orchestration device without modifying the way the network element device handles traffic.

[0051] Please see Figure 3 , Figure 3 A service chain orchestration method is performed by a service chain orchestration device in some embodiments of the present application.

[0052] like Figure 3 As shown, an embodiment of the present application provides a method for service chain orchestration for a SYN proxy, which is applied to a service chain orchestration device, and the method includes:

[0053] S101, identify the target network element device on any service chain, wherein any service chain is used to represent multiple sequentially arranged network element devices corresponding to any business logic, if there is only one network element device with SYN proxy enabled on any service chain, then the target network element device is the network element device with SYN proxy enabled, if there are multiple network element devices with SYN proxy enabled on any service chain, then the target network element device is the network element device with the highest order among the multiple network element devices with SYN proxy enabled. S102, construct an ACK packet based on the SYN-ACK packet received from the target network element device. S103, send the ACK packet to at least one network element device on the service chain to ensure the order in which the service chain orchestration device and each network element device on any service chain process the TCP protocol handshake process.

[0054] It should be noted that some embodiments of the present application generate an ACK packet and provide the ACK packet to the network element device on the service chain when confirming the first network element device that enables the SYN service on any service chain, thereby ensuring that the service chain orchestration device can still correctly forward traffic after the network element device turns on the SYN proxy.

[0055] The implementation principle or implementation process of S101 is described below by way of example.

[0056] The service chain orchestration device determines whether the first SYN-ACK packet of a TCP connection is sent from the network element device or the server, and then identifies whether the network element device has the SYN proxy turned on. If the network element device does not have the SYN proxy turned on, after the service chain orchestration device sends a SYN packet of a TCP connection to a certain network element device, the network element device will process and forward this SYN packet. After processing is completed in the service chain orchestration sequence, the service chain orchestration device sends this SYN packet to the server, and the server returns a SYN-ACK packet to the service chain orchestration device, and then continues to send this SYN-ACK packet to each network element device in turn in the service chain orchestration sequence, and finally reaches the client device. If the network element has the SYN proxy turned on, after the service chain orchestration device sends a SYN packet of a TCP connection to a certain network element device, it will receive the SYN-ACK packet returned by the network element device before the server returns the SYN-ACK packet. For service chain orchestration devices, if the first SYN-ACK packet of a TCP connection is received from the server, it is considered that the network element device does not have the SYN proxy enabled; if the first SYN-ACK packet of a TCP connection is received from the network element device, it is considered that the network element device has the SYN proxy enabled.

[0057] That is, in some embodiments of the present application, S101 exemplarily includes: identifying the target network element device by determining the source of the target SYN-ACK packet, wherein the target SYN-ACK packet is the first SYN-ACK packet used to establish a TCP connection corresponding to the first session. Some embodiments of the present application can determine the target network element device with the SYN proxy enabled that is ranked first in the service chain by identifying the source of the first SYN-ACK packet used to establish a TCP connection, thereby ensuring that the TCP handshake is completed in an orderly manner between the service chain orchestration and the network element device.

[0058] For example, in some embodiments of the present application, the target network element device is identified by determining the source of the target SYN-ACK data packet, including: if the first SYN-ACK data packet comes from the i-th network element device on any of the service chains, then the i-th network element device is confirmed to be the target network element device, wherein i is an integer greater than or equal to 1, and i is used to represent the arrangement order of the corresponding network element devices on any of the service chains.

[0059] Some embodiments of the present application can find the target network element device by identifying the network element device that sends the first SYN-ACK data packet to the service chain orchestration device for establishing a TCP connection between the client and the server, thereby ensuring that the TCP handshake between the service chain orchestration and the network element device is completed in an orderly manner.

[0060] The implementation principle and process of S103 are exemplarily described below.

[0061] After the network element device starts the SYN proxy, it receives the SYN packet from the service chain orchestration device and then sends a SYN-ACK packet to the service chain orchestration device. After the service chain orchestration device receives the SYN-ACK packet, it constructs an ACK packet according to the TCP protocol and then sends it from the first network element device in the service chain orchestration sequence. After the network element device receives the ACK packet, it sends subsequent packets according to its functional logic, and the service chain orchestration device continues to forward traffic in sequence.

[0062] For example, in some embodiments of the present application, S103 exemplarily includes: sending the ACK data packet to at least one network element device starting from the network element device ranked first on any one of the service chains.

[0063] It should be noted that in some embodiments of the present application, the first network element device is the target network element device, and at this time, the ACK message is provided to one or more network element devices starting from the target network element device. In some embodiments of the present application, the first network element device and the target network element device belong to different network element devices, then the ACK message needs to be first sent to the first network element device through the service chain orchestration device, and then transmitted backward in sequence.

[0064] Some embodiments of the present application provide ACK data packets generated by a service chain orchestration device starting from the network element device ranked first on the service chain to ensure that each network element device on the service chain establishes a valid connection.

[0065] It should be noted that if the client or server fails during the establishment of a TCP session, in order to immediately clear the relevant data on each network element device and the client or server on the service chain, some embodiments of the present application also require the service chain orchestration device to generate corresponding data packets and send the data packets.

[0066] That is, in some embodiments of the present application, the first session is a session between the client and the server, and after S103, the method further includes:

[0067] The first step is to generate a target data packet if the server or client fails.

[0068] The second step is to provide the target data packet to at least each network element device on the service chain.

[0069] Some embodiments of the present application generate relevant data packets and provide corresponding data packets to each network element device and the other end on the service chain when it is confirmed that the client or server fails and the session cannot be established, so that each network element device can delete and establish data related to the session.

[0070] The following is an example of the operations that need to be performed by the service chain orchestration setting when a server fails.

[0071] If, under certain conditions, the service chain orchestration device does not receive the SYN-ACK packet sent by the server-side device, nor does it receive other packets sent by the client device (for example, ACK packets used to establish TCP connections for other sessions), after the service chain orchestration device sends a SYN packet to the server, then the service chain orchestration device considers that the TCP connection establishment has failed and constructs a corresponding RST packet. Because there is a problem with the server-side device, for example, RST packets can be sent starting from the last network element device in the order of service chain orchestration to each network element device and client device so that the network element device and client device can clear the session in time. If the service chain orchestration device does not receive the SYN-ACK packet sent by the server-side device, but receives other packets sent by the client device, it means that the user's upstream traffic and downstream traffic are sent to different service chain orchestration devices respectively, and the subsequent packets of this TCP connection can be not sent to the network element device.

[0072] For example, in some embodiments of the present application, the process of the first step exemplarily includes: sending a SYN packet to the server, wherein the SYN packet is provided by the network element device that enables the SYN proxy on the service chain; if the SYN-ACK packet sent by the server is not received within the set time, the server failure is confirmed; and an RST packet is constructed. The second step exemplarily includes: sending the RST packet to each network element device and the client on the service chain. In some embodiments of the present application, when the SYN-ACK packet from the server is not received, the server failure is confirmed, and then the service chain orchestration device generates an RST packet and sends the packet to each network element device and the client, so that all devices can immediately delete the data related to the session. For example, in some embodiments of the present application, the process of sending the RST packet to each network element device and the client on the service chain exemplarily includes: starting from the last network element device of the service chain, the RST packet is sent in sequence along each network element device on the service chain until the RST packet is sent to the first network element device on the service chain. Some embodiments of the present application provide RST data packets to each network element device on the service chain starting from the last network element device on the service chain to ensure that the data packet message is provided to each network element device as quickly as possible.

[0073] For example, in some embodiments of the present application, if the SYN-ACK data packet sent by the server is not received within the set time period, the method also includes: confirming receipt of the pending data packet sent by the client device, wherein the pending data packet is used to establish a TCP connection for the second session; and not providing the pending data packet to the network element device on the service chain.

[0074] It should be noted that in some embodiments of the present application, the first session is between the client and the server, and data is exchanged in accordance with the TCP protocol. The client and the server respectively construct a session formed by data packets; the second session is between the service chain orchestration device and the network element device. In order to ensure normal TCP data interaction, the service chain orchestration device and the network element device will construct certain data packets to form a session; (for example, the network element device constructs a SYN data packet, and the service chain orchestration device constructs a SYN-ACK packet, etc.).

[0075] The following is an example of the operations that need to be performed by the service chain orchestration setting when a client fails.

[0076] If the client sends a SYN packet and receives a SYN-ACK packet sent by the service chain orchestration device, and under certain conditions the service chain orchestration device does not receive the ACK packet sent by the client, the service chain orchestration device considers that the TCP connection establishment has failed and needs to construct a corresponding RST packet (for example, setting the RST mark in accordance with the TCP protocol to construct the corresponding packet, refer to the process of constructing a SYN-ACK packet) because there is a problem with the client. For example, some embodiments of the present application may send messages starting from the first network element device in the order of service chain orchestration to each network element device and server device so that the network element device and server device can clear the session in time.

[0077] For example, in some embodiments of the present application, the first step exemplarily includes: confirming receipt of the SYN-ACK packet of the server; sending the SYN-ACK packet to the client, and confirming that the ACK packet sent by the client device is not received within the set time, then confirming that the client fails; constructing an RST packet. The second step exemplarily includes: sending the RST packet to each network element device and the server on the service chain. In some embodiments of the present application, when confirming that the client fails and the TCP connection cannot be established, the RST packet generated on the service chain orchestration device is sent to each device on the service chain to enable each network element device to clear the data related to the session. For example, in some embodiments of the present application, sending the RST packet to each network element device and the server on the service chain includes: starting from the first network element device on the service chain, the RST packet is sent in sequence along each network element device on the service chain until the RST packet is sent to the last network element device included in the service chain. When a client failure is confirmed, some embodiments of the present application send RST packets to each network element device on the service chain one by one starting from the network element device closest to the client, and send them in a timely manner to ensure that each network element device receives the packet.

[0078] Combine the following Figure 4 , Figure 5 as well as Figure 6 The three examples of the present invention illustrate the service chain arrangement method for SYN proxy provided by some embodiments of the present invention. It should be noted that: Figure 4 , Figure 5 as well as Figure 6 The numbers in the middle indicate the order in which the data packets are forwarded.

[0079] Example 1

[0080] Assume that the service chaining device performs traffic orchestration on two network element devices, and the first network element device has SYN proxy enabled. The service chaining device processes a TCP connection three-way handshake as follows: Figure 4 The specific execution steps are as follows:

[0081] Step 1: A user accesses a server. Assuming that TCP is used to establish a connection, the client device first sends a SYN (i.e. Figure 4 "1SYN") data packet to the service chaining device (i.e. Figure 4 SFC Orchestration).

[0082] Step 2: The service chain arrangement device receives this SYN packet through the ge1 interface and sends the SYN (i.e. Figure 4The "2SYN" data packet is sent to the first network element device (i.e. Figure 4 NF1).

[0083] Step 3: The first network element device receives the SYN packet. Since the first network element device has enabled the SYN proxy, it returns a SYN-ACK (i.e. Figure 4 The "3SYN-ACK" data packet is sent to the service chain orchestration device.

[0084] Step 4: The service chain orchestration device receives a SYN-ACK packet sent by the first network element device from the ge3 interface. The service chain orchestration device determines that this SYN-ACK packet is the first SYN-ACK packet of this TCP connection, and is received from the first network element device, not from the server. Therefore, the service chain orchestration device believes that the first network element device has turned on the SYN proxy (belonging to the target network element device); then the service chain orchestration device saves the relevant data of this SYN-ACK packet (such as TCP sequence number sequence number, TCP acknowledgment number acknowledgment number, TCP option tcp option, etc.), and constructs a corresponding ACK packet (i.e. Figure 4 "4ACK") is sent to the first network element device in the service chain according to the service chain orchestration order, and is sent to the first network element device through the ge3 interface of the service chain orchestration device.

[0085] Step 5: After the first network element device receives the ACK data packet, the first network element device then sends a SYN (i.e. Figure 4 "5SYN") data packet to the service chain orchestration device.

[0086] Step 6: The service chain arrangement device receives the SYN data packet sent by the first network element device from the ge4 interface, and then continues to send the SYN data packet to the second network element device (i.e. Figure 4 "6SYN").

[0087] Step 7: The second network element device receives the SYN packet sent by the service chaining device, processes it, and then sends the SYN packet to the service chaining device (i.e. Figure 4 of "7SYN").

[0088] Step 8: The service chain orchestration device receives a SYN packet (i.e. Figure 4 "7SYN"), and processes it according to the service chain arrangement order. It is found that all network element devices on the service chain have processed this SYN packet, and then sends the SYN packet to the server device through the ge2 interface (that is, Figure 4 "8SYN").

[0089] Step 9: After receiving the SYN packet sent by the service chaining device, the server device returns a SYN-ACK packet to the service chaining device (i.e. Figure 4 of "9SYN-ACK").

[0090] Step 10: The service chain orchestration device receives the SYN-ACK packet sent by the server through the ge2 interface (i.e. Figure 4 The "9SYN-ACK" of step 4 indicates that the server is reachable. The SYN-ACK related data copied and saved in step 4 is taken out, and a new SYN-ACK data packet is constructed (i.e. Figure 4 The "10SYN-ACK" is sent to the client device through the ge1 interface.

[0091] Step 11: The service chain arrangement device receives the SYN-ACK packet sent by the server device from the ge2 interface, and sends the SYN-ACK packet to the second network element device (i.e. Figure 4 of "11SYN-ACK").

[0092] Step 12: After the second network element device receives the SYN-ACK packet sent by the service chaining device (i.e. Figure 4 SYN-ACK), performs relevant processing, and then sends this SYN-ACK packet to the service chain orchestration device (i.e. Figure 4 of "12SYN-ACK").

[0093] Step 13: The service chain arrangement device receives the SYN-ACK data packet sent by the second network element device through the ge5 interface, and sends the SYN-ACK data packet to the first network element device (i.e. Figure 4 of "13SYN-ACK").

[0094] Step 14: After the first network element device receives the SYN-ACK packet sent by the service chaining device (i.e. Figure 4 13SYN-ACK), performs relevant processing, and then returns an ACK packet to the service chain orchestration device (i.e. Figure 4 of "14ACK").

[0095] Step 15: The service chain orchestration device receives an ACK data packet (i.e., Figure 4 According to the service chain arrangement sequence, the ACK data packet is sent to the second network element device (i.e. Figure 4of "15ACK").

[0096] Step 16: After receiving the ACK data packet sent by the service chaining arrangement device, the second network element device performs relevant processing and sends the ACK data packet to the service chaining arrangement device (i.e. Figure 4 of "16ACK").

[0097] Step 17: The service chain orchestration device receives an ACK packet from the client through port ge1 (i.e. Figure 4 The "17ACK" in the TCP connection indicates that the TCP connection is successfully established with the client device.

[0098] Step 18: Because the service chaining arrangement device successfully establishes a connection with the client, the service chaining arrangement device can send the ACK data packet sent by the second network element device to the server device through the ge2 interface (ie Figure 4 The TCP three-way handshake between the service chain orchestration device and the client device, the server device and the two network element devices is successfully established, and data transmission can be carried out subsequently.

[0099] It should be noted that in step 9, if under certain conditions (such as a timeout of 30 seconds), the service chain orchestration device does not receive the SYN-ACK data packet from the server device, and does not receive subsequent data packets from the client, it indicates that the TCP connection establishment failed. At this time, the service chain orchestration device needs to construct an RST data packet, because there is a problem with the server device. It starts from the last network element device in the service chain orchestration sequence, sends it to the second network element device through the ge6 interface, and forwards it to other network element devices in turn, and finally reaches the client device. If the service chain orchestration device does not receive the SYN-ACK data packet from the server device, but the service chain orchestration device receives subsequent data packets sent by the client device, it may be that the user's upstream traffic and downstream traffic are sent to different service chain orchestration devices respectively. At this time, the service chain orchestration device may not send subsequent data packets of this TCP connection to the network element device. In step 10, after receiving the SYN-ACK packet, the client device may immediately return an ACK packet. The ACK packet may reach the service chain orchestration device in step 11, and it does not necessarily have to reach the service chain orchestration device in step 17. This order is not required, as long as it is guaranteed to arrive before step 18 (sent to the server device). In step 17, if under certain conditions (such as a timeout of 30 seconds), the service chain orchestration device does not receive the ACK packet sent by the client, indicating that the TCP connection establishment failed. At this time, the service chain orchestration device needs to construct a RST packet, because there is a problem with the client device. According to the service chain orchestration sequence, starting from the first network element device, it is sent to the first network element device through the ge3 interface, and then forwarded to other network element devices in turn, and finally reaches the server device.

[0100] Example 2

[0101] The difference between Example 2 and Example 1 is that in Example 2, the network element device located in the second position of any service chain belongs to the target network element device. In order to avoid repetition, only the difference from Example 1 is described for this example. It should be noted that in the following description, the step number corresponds to the number of times the message is sent. For example, step 4 corresponds to the fourth data packet sent in the figure.

[0102] like Figure 5 As shown in the example 2, assuming that the service chaining device performs traffic orchestration on two network element devices, the first network element device does not have the SYN proxy enabled, and the second network element device has the SYN proxy enabled, then the processing flow of the TCP three-way handshake of the service chaining device is as follows Figure 5 To avoid duplication, Figure 5 For detailed explanation, please refer to the above Figure 4 Related instructions.

[0103] Figure 5 The first network element device (the network element device at the top of the service chain) does not have the SYN proxy enabled, so it is forwarded in the order of the service chain arrangement.

[0104] Figure 5 After the second network element device NF2 receives the SYN packet sent by the service chain orchestration device, it returns a SYN-ACK packet ( Figure 4 In step 5 of the above, the service chain arrangement device determines that this SYN-ACK packet is the first SYN-ACK packet of this TCP connection, and it is received from the second network element device (the network element device belongs to the target network element device), not from the server, so it is considered that the SYN proxy is enabled. At this time, the service chain arrangement device needs to save the relevant data of the SYN-ACK packet, and then construct the corresponding ACK packet. According to the service chain arrangement order, it needs to receive the SYN-ACK packet from the first network element device (i.e. Figure 5 The first network element device NF1 starts sending, then the ACK data packet is sent to the first network element device through the ge3 interface of the service chain orchestration device (step 7), and the subsequent processing logic is the same as that of Example 1.

[0105] That is, in some embodiments of the present application, the identifying of a target network element device on any service chain includes: identifying a p-th network element device (for example, Figure 5The second network element device) belongs to the target network element device, wherein the pth network element device belongs to the network element device on the service chain, and the pth network element device is not ranked first in the service chain, then S102 constructs an ACK data packet according to the SYN-ACK data packet from the target network element device exemplarily includes: constructs the ACK data packet according to the SYN-ACK data packet received from the pth network element device, and before executing S103, the method further includes: forwarding the SYN-ACK data packet of the pth network element device to the network element device ranked first on the service chain; receiving the SYN-ACK data packet sent by the first network element device; S103 exemplarily includes: sending the ACK data packet to the first network element device. Some embodiments of the present application need to receive in advance the SYN-ACK data packet sent by the first network element device to the service chain orchestration device when sending an ACK packet generated by the service chain orchestration device to the network element device at the first position in the service chain, so as to ensure that the connection between each network element device and the service chain orchestration device is normal and valid.

[0106] Example 3

[0107] The difference between Example 3 and Example 1 is that in Example 3, there are two network element devices with SYN proxy enabled in any service chain, namely, the target network element device and the second network element device with SYN proxy enabled. In order to avoid repetition, only the differences from Example 1 and Example 2 are described for this example. It should be noted that in the following description, the step number corresponds to the number of times the message is sent. For example, step 4 corresponds to the fourth data packet sent in the figure.

[0108] like Figure 6 As shown in Example 3, assuming that the service chain orchestration device performs traffic orchestration on two network element devices, and both network element devices have SYN proxy enabled, the processing flow of the TCP three-way handshake of the service chain orchestration device is as follows: Figure 6 To avoid duplication, Figure 6 For detailed explanation, please refer to the above Figure 4 or Figure 5 Related instructions.

[0109] Figure 6 The first network element device NF1 has the SYN proxy enabled (belonging to the target network element device). After the first network element device receives the SYN packet sent by the service chain orchestration device, it immediately returns a SYN-ACK packet ( Figure 6In step 3), the service chain orchestration device determines that this SYN-ACK packet is the first SYN-ACK packet of this TCP connection, and it is received from the first network element device, not from the server, so it is considered that the SYN proxy is turned on (and the first network element device is the target network element device). At this time, the service chain orchestration device needs to save the relevant data of the SYN-ACK packet, and then construct the corresponding ACK packet. According to the service chain orchestration sequence, it needs to start sending from the first network element device (i.e., the first network element device), then send the ACK packet to the first network element device through the ge3 interface of the service chain orchestration device (step 4, the step number is the same as the number of the sent message), and then the first network element device sends the SYN packet to the service chain orchestration device.

[0110] The service chain arrangement device then sends this SYN packet to the second network element device. Since the second network element device also turns on the SYN proxy, the second network element device will send a SYN-ACK packet to the service chain arrangement device. The service chain arrangement device determines that this SYN-ACK packet is not the first SYN-ACK packet of this TCP connection. Although it is received from the network element device, it does not meet the conditions (it is not the target network element device and therefore no longer constructs an ACK packet). Therefore, the service chain arrangement device will not construct an ACK packet, but only forward the SYN-ACK packet sent by the second network element device to the first network element device ( Figure 5 In step 8), the first network element device then sends an ACK data packet to the service chain orchestration device, and continues to send the ACK packet to the second network element device through the service chain orchestration device according to the service chain orchestration sequence. The subsequent processing logic is similar to that of Example 1, and will not be described in detail to avoid repetition.

[0111] That is, in some embodiments of the present application, any service chain also includes an nth network element device with SYN proxy enabled, and the nth network element device is located after the target network element device on the service chain. After constructing an ACK packet based on the SYN-ACK packet received from the target network element device, the method also includes: confirming receipt of the SYN-ACK packet sent by the nth device; sending the SYN-ACK packet sent by the nth device to at least part of the interfaces of each network element device located before the nth network element device on the service chain, and receiving the ACK packets sent by each network element device; sending an ACK packet to the nth network element device, and receiving a SYN packet sent by the nth network element device; continuing to forward the SYN packet sent by the nth network element device until the SYN packet sent by the nth network element device is forwarded to the server, or until the SYN packet sent by the nth network element device is forwarded to the next network element device with SYN proxy enabled. In some embodiments of the present application, for a network element device that is not the first to enable the SYN proxy service, it is necessary to first forward the SYN-ACK data packet generated by the device to all network element devices before the network element device, and then send an ACK data packet to the network element device. After that, the network element device will send the SYN message for establishing a session to the service chain orchestration device, and then the service chain orchestration device will forward the SYN to the server to complete the establishment of the TCP connection. This can ensure that after the SYN proxy is enabled, the service chain orchestration device can still send each data packet normally, thereby ensuring the normal establishment of the TCP connection.

[0112] In combination with the above examples, it can be understood that in some embodiments of the present application, the first network element device includes an intranet interface and an extranet interface, wherein the sending of the ACK data packet to at least one network element device starting from the first network element device on any service chain includes: sending the ACK data packet to the intranet interface. In some embodiments of the present application, the ACK data packet generated by the service chain orchestration device first needs to be sent to the intranet interface of the first network element device to ensure that subsequent messages are sent smoothly. In some embodiments of the present application, the target network element device belongs to a network element device different from the first network element device, and the target network element device includes an internal network interface and an external network interface, wherein the sending of the ACK packet to at least one network element device on the service chain includes: sending the ACK packet to the internal network interface of the target network element device; receiving a SYN packet sent by the external network interface of the target network element device; and continuing to forward the SYN packet sent by the external network interface of the target network element device along the remaining network element devices on the service chain until the SYN packet sent by the external network interface of the target network element device is forwarded to the server, or until the SYN packet sent by the external network interface of the target network element device is forwarded to the next network element device on the service chain with the SYN proxy enabled. Some embodiments of the present application provide an implementation method for how to generate an ACK packet according to a service chain orchestration device to continue the subsequent forwarding process.

[0113] Please refer to Figure 7 , Figure 7 A device for orchestrating a service chain provided in an embodiment of the present application is shown. It should be understood that the device is similar to the above-mentioned Figure 3 The method embodiment corresponds to the method embodiment and can execute each step involved in the above method embodiment. The specific functions of the device can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here. The device includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the operating system of the device. The device for service chain arrangement includes: a target network element device identification module 101, a data packet construction module 102, and a forwarding module 103.

[0114] The target network element device identification module is configured to identify the target network element device on any service chain, wherein the any service chain is used to represent a plurality of sequentially arranged network element devices corresponding to any business logic; if there is only one network element device with SYN proxy enabled on the any service chain, the target network element device is the network element device with SYN proxy enabled; if there are a plurality of network element devices with SYN proxy enabled on the any service chain, the target network element device is the network element device with the highest order among the plurality of network element devices with SYN proxy enabled.

[0115] The data packet construction module is configured to construct an ACK data packet according to the SYN-ACK data packet received from the target network element device.

[0116] The forwarding module is configured to send the ACK data packet to at least one network element device on the service chain to ensure the order in which the service chain orchestration device and each network element device on any service chain processes the TCP protocol handshake process.

[0117] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0118] Some embodiments of the present application provide a computer storage medium having a computer program stored thereon. When the program is executed by a processor, the method described in any embodiment of the method for service chain orchestration for a SYN proxy can be implemented.

[0119] like Figure 8 As shown, some embodiments of the present application provide an electronic device 500, including a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520, wherein when the processor 520 reads the program from the memory 510 and executes the program, the method described in any embodiment of the method for service chain orchestration for a SYN proxy can be implemented.

[0120] Processor 520 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 520 can be a microprocessor.

[0121] The memory 510 may be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code to implement some or all functions of one or more modules described in the embodiments of the present application. The processor 520 of the present disclosure embodiment may be used to execute the instructions in the memory 510 to implement Figure 3 The memory 510 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory or other memory known to those skilled in the art.

[0122] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0123] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0124] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0125] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0126] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0127] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A method for service chain orchestration for SYN proxy, applied to a service chain orchestration device, characterized in that: The method comprises: Identify a target network element device on any service chain, wherein the any service chain is used to represent a plurality of sequentially arranged network element devices corresponding to any service logic, and if there is only one network element device with SYN proxy enabled on the any service chain, the target network element device is the network element device with SYN proxy enabled, and if there are multiple network element devices with SYN proxy enabled on the any service chain, the target network element device is the network element device with the highest order among the multiple network element devices with SYN proxy enabled; Constructing an ACK data packet according to the SYN-ACK data packet received from the target network element device; Sending the ACK data packet to at least one network element device on any one of the service chains to ensure the order in which the service chain orchestration device and each network element device on any one of the service chains process the TCP protocol handshake process corresponding to the first session; Among them, for the network element device that is not the first to enable the SYN proxy service, the SYN-ACK data packet generated by the network element device is forwarded to all network element devices before the network element device, and then the ACK data packet is sent to the network element device. After that, the network element device will send the SYN message for establishing the session to the service chain orchestration device, and then the service chain orchestration device will forward the SYN to the server to complete the establishment of the TCP connection.

2. The method according to claim 1, characterized in that The sending the ACK data packet to at least one network element device on any one of the service chains includes: The ACK data packet is sent to at least one network element device starting from the network element device that ranks first on any one of the service chains.

3. The method according to claim 1, characterized in that The identifying a target network element device on any service chain includes: The target network element device is identified by determining the source of the target SYN-ACK data packet, wherein the target SYN-ACK data packet is the first SYN-ACK data packet used to establish a TCP connection corresponding to the first session.

4. The method according to claim 3, characterized in that The step of determining the source of the target SYN-ACK data packet and then identifying the target network element device includes: If the first SYN-ACK data packet comes from the i-th network element device on any of the service chains, the i-th network element device is confirmed to be the target network element device, where i is an integer greater than or equal to 1, and i is used to represent the arrangement order of the corresponding network element device on any of the service chains.

5. The method according to claim 1, characterized in that The first session is a session between a client and a server, wherein: After sending the ACK data packet to at least one network element device on any one of the service chains, the method further includes: If it is confirmed that the server or the client fails, generating a target data packet; The target data packet is provided to at least each network element device on any one of the service chains.

6. The method according to claim 5, characterized in that If the server failure is confirmed, generating a target data packet includes: Sending a SYN packet to the server, wherein the SYN packet is provided by a network element device that enables a SYN proxy on any of the service chains; If the SYN-ACK data packet sent by the server is not received within the set time, the server is confirmed to be faulty; Construct a RST packet; The providing the target data packet to at least each network element device on any one of the service chains includes: The RST data packet is sent to each network element device and the client on any service chain.

7. The method according to claim 6, characterized in that The sending the RST data packet to each network element device and the client on any one of the service chains includes: The RST data packet is sent sequentially along each network element device on any service chain starting from the last network element device on any service chain until the RST data packet is sent to the first network element device on any service chain and the client.

8. The method according to claim 6, characterized in that If the SYN-ACK data packet sent by the server is not received within the set time, the method further includes: Acknowledging receipt of a data packet to be processed sent by the client, wherein the data packet to be processed is used to establish a TCP connection for a second session; The to-be-processed data packet is not provided to any network element device on the service chain.

9. The method according to claim 5, characterized in that If the client fails, generating a target data packet includes: Acknowledge receipt of the SYN-ACK packet from the server; Send the SYN_ACK packet to the client, and confirm that the client is faulty if the ACK packet sent by the client is not received within the set time period; Construct a RST packet; The providing the target data packet to at least each network element device on any one of the service chains includes: The RST data packet is sent to each network element device and the server on any service chain.

10. The method according to claim 9, characterized in that The sending the RST data packet to each network element device and the server on any one of the service chains includes: The RST data packet is sent in sequence along each network element device on any service chain starting from the first network element device on any service chain until the RST data packet is sent to the last network element device included in any service chain and the server.

11. The method according to claim 1, characterized in that The identifying a target network element device on any service chain includes: Identify that the p-th network element device belongs to the target network element device, wherein the p-th network element device belongs to the network element device on any one of the service chains, and the p-th network element device is not ranked first in any one of the service chains; The constructing an ACK data packet according to the SYN-ACK data packet received from the target network element device comprises: constructing the ACK data packet according to the SYN-ACK data packet received from the pth network element device; Before sending the ACK data packet to at least one network element device on any one of the service chains, the method further includes: Forwarding the SYN-ACK data packet of the pth network element device to the network element device ranked first on any one of the service chains; Receive a SYN-ACK data packet sent by the first network element device; The sending the ACK data packet to at least one network element device on any one of the service chains includes: Send the ACK data packet to the first network element device.

12. The method according to claim 1, characterized in that Any of the service chains also includes an nth network element device that starts a SYN proxy, and the nth network element device is located after the target network element device on any of the service chains, After constructing the ACK data packet according to the SYN-ACK data packet received from the target network element device, the method further includes: Acknowledging receipt of the SYN-ACK data packet sent by the nth device; Sending the SYN-ACK data packet sent by the nth device to at least some interfaces of each network element device located before the nth network element device on any service chain, and receiving the ACK data packets sent by each network element device; Sending an ACK data packet to the nth network element device, and receiving a SYN data packet sent by the nth network element device; Continue to forward the SYN data packet sent by the nth network element device until the SYN data packet sent by the nth network element device is forwarded to the server, or until the SYN data packet sent by the nth network element device is forwarded to the next network element device with the SYN proxy enabled.

13. The method according to claim 2, characterized in that The first network element device includes an internal network interface and an external network interface, wherein: The sending of the ACK data packet to at least one network element device starting from the first network element device on any one of the service chains includes: Send the ACK data packet to the intranet interface.

14. The method according to claim 13, characterized in that The target network element device is a network element device different from the first network element device, and the target network element device includes an internal network interface and an external network interface, wherein: The sending the ACK data packet to at least one network element device on any one of the service chains includes: Sending the ACK data packet to the intranet interface of the target network element device; Receiving a SYN data packet sent by the external network interface of the target network element device; Continue to forward the SYN data packet sent by the external network interface of the target network element device along the remaining network element devices on any of the service chains until the SYN data packet sent by the external network interface of the target network element device is forwarded to the server, or until the SYN data packet sent by the external network interface of the target network element device is forwarded to the next network element device on any of the service chains with the SYN proxy enabled.

15. A device for service chain orchestration, characterized in that: The device comprises: A target network element device identification module is configured to identify a target network element device on any service chain, wherein the any service chain is used to represent a plurality of sequentially arranged network element devices corresponding to any service logic, and if there is only one network element device with SYN proxy enabled on the any service chain, the target network element device is the network element device with SYN proxy enabled, and if there are a plurality of network element devices with SYN proxy enabled on the any service chain, the target network element device is the network element device with the highest order among the plurality of network element devices with SYN proxy enabled; A data packet construction module, configured to construct an ACK data packet according to the SYN-ACK data packet received from the target network element device; A forwarding module, configured to send the ACK data packet to at least one network element device on any one of the service chains to ensure the order in which the service chain arrangement device and each network element device on any one of the service chains process the TCP protocol handshake process corresponding to the first session; Among them, for the network element device that is not the first to enable the SYN proxy service, the SYN-ACK data packet generated by the network element device is forwarded to all network element devices before the network element device, and then the ACK data packet is sent to the network element device. After that, the network element device will send the SYN message for establishing the session to the service chain orchestration device, and then the service chain orchestration device will forward the SYN to the server to complete the establishment of the TCP connection.

16. A computer storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 14 can be implemented.

17. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 14 can be implemented.

Citation Information

Patent Citations

  • Software-defined NFV-based security service chain arrangement and deployment method and system

    CN114024747A

  • System and method for diverting established communication sessions

    US20150180767A1