Data forwarding method, apparatus, device, and storage medium
By receiving data forwarding requests from user terminals, multiple candidate main paths matching the target transceiver router identifier are obtained. The target data forwarding path is determined according to the user's target path selection strategy, which solves the problem that existing technologies can only select the default shortest path and realizes the flexibility and adaptability of path selection.
Patent Information
- Application Number
- CN202211393383.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-08
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2042-11-08
AI Technical Summary
In existing technologies, users cannot choose a suitable path as the target data forwarding path according to their own needs; they can only choose the default shortest path for data forwarding, which lacks selectivity.
A data forwarding method is provided, which receives a data forwarding request from a user terminal, obtains multiple candidate main paths that match the identifier of the target transceiver router, including the shortest main path, the main path with the maximum bandwidth, the main path with the minimum delay, and the main path with the highest security index, and determines the target data forwarding path from them according to the user's target path selection strategy.
It enables the selection of appropriate data forwarding paths based on user needs, enhancing the flexibility and adaptability of path selection and meeting the forwarding needs of different users.
Smart Images

Figure CN115767663B_ABST
Abstract
Description
Technical Field
[0001] This application relates to mobile Internet technology, and more particularly to a data forwarding method, apparatus, device, and storage medium. Background Technology
[0002] With the development of mobile internet, users have certain requirements for the path selection strategy for data forwarding, which has increased the attention of R&D personnel to the path selection strategy for data forwarding.
[0003] In the prior art, when a user wants to achieve data forwarding, the first step is to determine the target transceiver router identifier, then determine the default path between the target transceiver router identifiers, which is the shortest path between the target transceiver routers, and then select the default shortest path between the target transceiver routers as the target data forwarding path, thereby achieving the forwarding of the target data through the target data forwarding path.
[0004] Therefore, in the existing technology, users cannot choose a suitable path as the target data forwarding path according to their own needs, and can only choose the default shortest path to achieve the forwarding of the target data. Summary of the Invention
[0005] This application provides a data forwarding method, apparatus, device, and storage medium to solve the problem that users cannot choose a suitable path as the target data forwarding path according to their own needs, and can only choose the default shortest path to achieve the forwarding of target data.
[0006] Firstly, this application provides a data forwarding method, including:
[0007] Receive a data forwarding request sent by a user terminal, wherein the data forwarding request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent;
[0008] Multiple candidate main paths matching the target transceiver router identifier are obtained from the pre-stored main paths; the multiple main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path.
[0009] The target primary path is determined from the multiple candidate primary paths according to the target path selection strategy as the target data forwarding path;
[0010] The target data is forwarded using the target data forwarding path.
[0011] In one feasible approach, the target transceiver router identifier includes: a target sending router identifier and a target receiving router identifier;
[0012] The step of obtaining multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths includes:
[0013] Match the target sending router identifier and the target receiving router identifier with the sending router identifier and receiving router identifier in the pre-stored main path, respectively;
[0014] Multiple candidate main paths are selected from the pre-stored main paths, where the target sending router identifier matches the sending router identifier in the pre-stored main path, and the target receiving router identifier matches the receiving router identifier in the pre-stored main path.
[0015] In one feasible approach, determining the target primary path as the target data forwarding path from the plurality of candidate primary paths according to the target path selection strategy includes:
[0016] Match the target path selection strategy with the path determination strategies corresponding to multiple candidate main paths;
[0017] The candidate primary path that matches the target path selection strategy and the path determination strategy is determined as the target primary path, and the target primary path is used as the target data forwarding path.
[0018] In one feasible approach, determining the target primary path as the target data forwarding path from the plurality of candidate primary paths according to the target path selection strategy includes:
[0019] The target main path is determined from the multiple candidate main paths according to the target path selection strategy;
[0020] In response to the target primary path being unoccupied and operating normally, the target primary path is determined as the target data forwarding path.
[0021] In one feasible embodiment, the method further includes:
[0022] In response to the target primary path being occupied or malfunctioning, a target backup path that matches the target transceiver router identifier and is consistent with the path determination strategy corresponding to the target primary path is determined from the backup paths corresponding to the pre-stored primary path as the target data forwarding path.
[0023] In one feasible approach, prior to retrieving multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths, the method further includes:
[0024] Obtain the router identifiers and topology relationships between routers in a pre-built Resource Public Key Infrastructure (RPKI) secure network system;
[0025] Multiple main paths between routers are determined based on the router identifier, the topology between routers, and the path determination strategy; the path determination strategy is any one or more of the following strategies: shortest path strategy, maximum bandwidth strategy, minimum latency strategy, and highest security index strategy;
[0026] Determine the corresponding backup path based on the primary path between each router;
[0027] The primary path and corresponding backup path between each router are stored according to the path determination strategy.
[0028] In one feasible approach, determining multiple primary paths between routers based on the router identifier, the topological relationship between routers, and the path determination strategy includes:
[0029] Based on the router identifiers and the topological relationships between the routers, multiple existing paths between each router are determined;
[0030] From the multiple existing paths, the path that is consistent with the path determination strategy for each path is determined as the main path.
[0031] In one feasible approach, determining the path consistent with each path determination strategy from the corresponding multiple existing paths as the main path includes:
[0032] Calculate the number of routers in each existing path, and select the path with the fewest routers as the shortest main path;
[0033] Calculate the average bandwidth of the routers included in each existing path, and select the path with the largest average bandwidth as the main path with the largest bandwidth;
[0034] Calculate the total delay of the routers contained in each existing path, and select the path with the smallest total delay as the minimum delay main path;
[0035] Calculate the average security index of the routers included in each existing path, and select the path with the highest average security index as the main path with the highest security index.
[0036] In one feasible approach, determining the corresponding backup path based on the primary path between routers includes:
[0037] The main path that is consistent with the path determination strategy for each path is removed from the corresponding multiple existing paths to obtain the remaining paths;
[0038] From the remaining paths, a path consistent with each path determination strategy is selected as a backup path.
[0039] In one feasible approach, before obtaining the router identifiers and topological relationships between routers in the pre-built RPKI secure network system, the method further includes:
[0040] Obtain the binding relationship between router identifiers and corresponding Internet Protocol (IP) addresses stored in each router in the initial network system;
[0041] Determine whether each router is an invalid router based on the binding relationship between the router identifier and the corresponding IP address stored in each router;
[0042] If at least one router is determined to be an invalid router, then the at least one router is deleted, and an RPKI secure network system is built based on the retained routers.
[0043] In one feasible approach, determining whether a router is an invalid router based on the binding relationship between router identifiers and corresponding IP addresses stored in each router includes:
[0044] Obtain a pre-stored real binding relationship filter table, which contains the real binding relationship between the identifier of each router and its IP address;
[0045] If it is determined that the binding relationship between the router identifier and the corresponding IP address stored in a router is consistent with the real binding relationship in the real binding relationship filter table, or if the binding relationship between the router identifier and the corresponding IP address stored in the router does not exist in the real binding relationship filter table, then the router is determined to be a valid router.
[0046] If it is determined that the binding relationship between the router identifier and the corresponding IP address stored in a router is inconsistent with the actual binding relationship in the filtering table, then the router is determined to be an invalid router.
[0047] Secondly, this application provides a data forwarding apparatus, the apparatus comprising:
[0048] The receiving module is used to receive a data forwarding request sent by a user terminal. The data forwarding request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent.
[0049] The acquisition module is used to acquire multiple candidate main paths that match the target transceiver router identifier from the pre-stored main paths; the multiple main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path;
[0050] The determination module is used to determine the target primary path as the target data forwarding path from the multiple candidate primary paths according to the target path selection strategy;
[0051] The forwarding module is used to forward the target data using the target data forwarding path.
[0052] Thirdly, this application provides an electronic device, including: a processor, and a memory and a transceiver communicatively connected to the processor;
[0053] The memory stores computer-executed instructions; the transceiver is used for sending and receiving data.
[0054] The processor executes computer execution instructions stored in the memory to implement the method as described in the first aspect or any feasible method described above.
[0055] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect or any of the feasible methods described above.
[0056] This application provides a data forwarding method, apparatus, device, and storage medium. The method includes receiving a data forwarding request sent by a user terminal, the data forwarding request including a target path selection strategy, a target transceiver router identifier, and target data to be sent; obtaining multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths; the multiple main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path; determining the target main path as the target data forwarding path from the multiple candidate main paths according to the target path selection strategy; and forwarding the target data using the target data forwarding path. In this application, the data forwarding device first receives a data forwarding request sent by a user terminal. This request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent. Next, it retrieves multiple candidate main paths matching the target transceiver router identifier from a pre-stored main path database. Since the pre-stored main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the shortest main path, the maximum bandwidth main path, the minimum latency main path, and the highest security index main path, a target main path can be determined from the multiple candidate main paths based on the user's target path selection strategy. This allows for the forwarding of the target data according to the target data forwarding path. Because multiple candidate main paths matching the target transceiver router identifier are pre-stored, and the user inputs a target path selection strategy according to their needs, a main path meeting their requirements can be determined from the multiple candidate main paths based on the target path selection strategy as the target data forwarding path. Attached Figure Description
[0057] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0058] Figure 1 An application scenario diagram of a data forwarding method provided in this application;
[0059] Figure 2 A flowchart illustrating a data forwarding method provided in Embodiment 1 of this application;
[0060] Figure 3 This is a flowchart illustrating a data forwarding method provided in Embodiment 3 of this application;
[0061] Figure 4 This is a flowchart illustrating a data forwarding method provided in Embodiment 4 of this application;
[0062] Figure 5 This is a flowchart illustrating a data forwarding method provided in Embodiment 5 of this application;
[0063] Figure 6 This is a schematic diagram of a topological relationship provided in Embodiment 5 of this application;
[0064] Figure 7 A flowchart illustrating another data forwarding method provided in Embodiment 5 of this application;
[0065] Figure 8 This is a flowchart illustrating a data forwarding method provided in Embodiment Six of this application;
[0066] Figure 9 This is a flowchart illustrating a data forwarding method provided in Embodiment 7 of this application;
[0067] Figure 10 A flowchart illustrating another data forwarding method provided in Embodiment 7 of this application;
[0068] Figure 11 This is a schematic diagram of a data forwarding device provided in Embodiment 8 of this application;
[0069] Figure 12 This is a schematic diagram of the structure of an electronic device provided in Embodiment 9 of this application.
[0070] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0071] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0072] First, let me explain the terms used in this application:
[0073] Resource Public Key Infrastructure (RPKI) is a public key infrastructure (PKI) framework designed to make internet routing infrastructure more secure.
[0074] In existing technologies, when a user wants to forward data, the first step is to determine the target transceiver router identifiers. Next, a default path is determined between these target transceiver router identifiers; this default path is the shortest path between the target transceiver routers. Then, the default shortest path between the target transceiver routers is selected as the target data forwarding path, and the target data is forwarded through this target data forwarding path. The target transceiver router identifiers include the target sending router identifier and the target receiving router identifier.
[0075] It is understandable that the user sends the target data from the target sending router, and the target data is eventually forwarded to the target receiving router after passing through at least zero routers, thereby realizing the forwarding of the target data.
[0076] However, existing technologies have some drawbacks. Users cannot choose a suitable path as the target data forwarding path according to their own needs; they can only choose the default shortest path to forward the target data. Therefore, users have no choice when determining the target data forwarding path.
[0077] In order to overcome the shortcomings of existing technologies, the inventors of this solution have conducted creative research and designed a new solution. This solution provides a data forwarding method to address the problem that users cannot select a suitable path as the target data forwarding path according to their own needs and can only choose the default shortest path to achieve target data forwarding. The data forwarding device of this application first receives a data forwarding request sent by the user terminal. The data forwarding request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent. The target path selection strategy can be determined by the user according to their own needs. Then, multiple candidate main paths matching the target transceiver router identifier are obtained from the pre-stored main paths. Since the multiple main paths are determined according to different path determination strategies, the main path includes any one or more of the following: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path. Then, the target main path is determined from the multiple candidate main paths as the target data forwarding path according to the target path selection strategy. Since the user can determine the target path selection strategy according to their own needs, and the data forwarding device pre-stores multiple candidate main paths, a target main path can be determined from the multiple candidate main paths as the target data forwarding path according to the user's own needs, and the target data can be forwarded using this target data forwarding path.
[0078] The following describes the application scenarios of the data forwarding method, apparatus, device, and storage medium provided in this application.
[0079] Figure 1 This is a diagram illustrating an application scenario for a data forwarding method provided in this application. For example... Figure 1As shown in the diagram, the application scenario includes a user terminal 101 and an electronic device 102. The electronic device 102 includes a data forwarding device 103, and the data forwarding device 103 includes a storage area 104.
[0080] The user terminal 101 can be a mobile phone, tablet, or other device.
[0081] The user terminal 101 is communicatively connected to the electronic device 102, and the communication connection can be either wired or wireless.
[0082] Specifically, the user terminal 101 is executed by the user. The user inputs the target path selection strategy, the target transceiver router identifier, and the target data to be sent into the user terminal 101, thereby generating a data forwarding request and sending it to the electronic device 102. The electronic device 102 receives the data forwarding request and transmits it to the data forwarding device 103. The data forwarding device 103 includes a storage area 104, which can store multiple main paths formed between any two router identifiers. Each main path is determined according to a different path determination strategy; therefore, each main path corresponds to one path determination strategy. Next, the data forwarding device 103 retrieves multiple main paths matching the target transceiver router identifier from the storage area 104 as multiple candidate main paths. Then, the data forwarding device 103 determines a main path from the multiple candidate main paths whose path determination strategy matches the target path selection strategy, and uses this main path as the target main path.
[0083] Furthermore, the target main path is used as the target data forwarding path, and the target data will be forwarded using this target data forwarding path.
[0084] Furthermore, the data forwarding device 103 can send the target data forwarding path to the user terminal 101 so that the user is aware of the determined target data forwarding path.
[0085] It should be noted that the main path in this application includes any one or more of the following: the shortest main path, the main path with the maximum bandwidth, the main path with the minimum latency, and the main path with the highest security index.
[0086] This application provides a data forwarding method, apparatus, device, and storage medium, which aims to solve the above-mentioned technical problems in the prior art.
[0087] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0088] Example 1
[0089] Figure 2 This is a flowchart illustrating a data forwarding method provided in Embodiment 1 of this application. The execution entity of this embodiment is a data forwarding device, such as... Figure 2 As shown, the specific steps are as follows.
[0090] S201, Receive data forwarding request sent by user terminal. The data forwarding request includes target path selection policy, target transceiver router identifier and target data to be sent.
[0091] The data forwarding request is generated in response to the user's input of the target path selection policy, the target transceiver router identifier, and the target data to be sent on the user terminal.
[0092] Among them, the target path selection strategy is the strategy for selecting the target data forwarding path.
[0093] The target transceiver router identifier is a representation of the transceiver router and can be used to distinguish routers.
[0094] The target data to be sent refers to the data that the user intends to send. It's understandable that when the target data is complex, the user doesn't need to input the target data on their terminal; instead, they can input the target data after determining the forwarding path to achieve data forwarding.
[0095] Specifically, the user inputs the target path selection policy, the target transceiver router identifier, and the target data to be sent into the user terminal, thereby generating a data forwarding request, which is then sent to the data forwarding device, which receives the data forwarding request.
[0096] S202, obtain multiple candidate main paths that match the target transceiver router identifier from the pre-stored main paths; the multiple main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path.
[0097] The path determination strategy is the strategy used to determine the path. It can be understood that the pre-stored main paths contain multiple main paths corresponding to each transceiver router identifier. Each transceiver router identifier can be a combination of any two router identifiers.
[0098] The shortest main path refers to the path with the fewest number of routers under a given transceiver router identifier.
[0099] The maximum bandwidth main path refers to the path with the highest average bandwidth under a certain transceiver router identifier.
[0100] The minimum delay main path refers to the path with the minimum total delay under a certain transceiver router identifier.
[0101] Among them, the main path with the highest security index refers to the path with the highest average security index under a certain transceiver router identifier.
[0102] Specifically, the data forwarding device will identify the target transceiver router identifier, and then find the transceiver router identifier that matches the target transceiver router identifier from the pre-stored main paths based on the target transceiver router identifier. Then, it will obtain multiple main paths corresponding to the transceiver router identifier and use these multiple main paths as multiple candidate main paths corresponding to the target transceiver router identifier.
[0103] S203, determine the target primary path from multiple candidate primary paths as the target data forwarding path according to the target path selection strategy.
[0104] Among them, the path determination strategy corresponding to each main path is marked on multiple candidate main paths.
[0105] The target data forwarding path is the path through which the target data to be sent is forwarded.
[0106] Specifically, the data forwarding device will determine a candidate primary path that is consistent with the target path selection strategy from the path determination strategies marked on multiple candidate primary paths, and use the candidate primary path as the target primary path.
[0107] Furthermore, the primary path of this target is determined as the target data forwarding path.
[0108] S204, Use the target data forwarding path to forward the target data.
[0109] Specifically, after determining the target data forwarding path, the data forwarding device will send a router enable command to all routers in the target data forwarding path, so that each router can enable itself after receiving the router enable command, thereby opening the target data forwarding path.
[0110] Furthermore, the target data forwarding path can be used to achieve target data forwarding.
[0111] This embodiment provides a data forwarding method, specifically including: receiving a data forwarding request sent by a user terminal, the data forwarding request including a target path selection strategy, a target transceiver router identifier, and target data to be sent; obtaining multiple candidate main paths matching the target transceiver router identifier from a pre-stored main path; the multiple main paths corresponding to each transceiver router identifier in the pre-stored main path are determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path; determining the target main path as the target data forwarding path from the multiple candidate main paths according to the target path selection strategy; and forwarding the target data using the target data forwarding path. In this embodiment, the data forwarding device first receives a data forwarding request sent by a user terminal. This request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent. Next, it retrieves multiple candidate main paths matching the target transceiver router identifier from a pre-stored main path database. Since the pre-stored main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, including any one or more of the shortest main path, the maximum bandwidth main path, the minimum latency main path, and the highest security index main path, a target main path can be determined from the multiple candidate main paths based on the user's target path selection strategy. This target main path serves as the target data forwarding path, enabling the forwarding of the target data. Because multiple candidate main paths matching the target transceiver router identifier are pre-stored, and the user inputs a target path selection strategy according to their needs, a main path meeting their requirements can be determined from the multiple candidate main paths as the target data forwarding path.
[0112] Example 2
[0113] This application embodiment is a further refinement of the above embodiment one. The target transceiver router identifier in this embodiment includes: the target sending router identifier and the target receiving router identifier.
[0114] In this system, the target sending router identifier represents the target sending router; the target receiving router identifier indicates the target receiving router. The target sending router is the first router to which data is sent to the next router; the target receiving router is the last router to which data is received.
[0115] For example, the target transceiver router identifier includes: target sending router 1 and target receiving router 4, intermediate router 3, which forwards data from target sending router 1 to intermediate router 3, and then intermediate router 3 sends it to target receiving router 4, completing the data forwarding. The intermediate router is a router located between the sending router and the receiving router.
[0116] This embodiment is an optional method for obtaining multiple candidate main paths that match the target transceiver router identifier from pre-stored main paths, as detailed below.
[0117] The target sending router identifier and the target receiving router identifier are matched with the sending router identifier and receiving router identifier in the pre-stored main path, respectively.
[0118] There can be multiple pre-stored main paths. Each main path is marked with the identifier of the sending router and the identifier of the receiving router, indicating which main path is the sending router and which is the receiving router.
[0119] For example, the sending router of the main path 1 is identified as router 1, and the receiving router is identified as router 3.
[0120] Specifically, the target sending router can be matched with the sending router identifiers in each main path, and the target receiving router identifier can be matched with the receiving router identifiers in each main path.
[0121] Multiple candidate main paths are selected from the pre-stored main paths, where the target sending router identifier matches the sending router identifier in the pre-stored main path, and the target receiving router identifier matches the receiving router identifier in the pre-stored main path.
[0122] Specifically, the data forwarding device can first obtain the sending router identifier from the pre-stored main paths based on the target sending router identifier, find the main path where the target sending router identifier matches the sending router identifier, and retain the main path where the sending router identifier matches the target sending router identifier. Next, the data forwarding device can match multiple main paths where the target receiving router matches the receiving router from the retained main paths where the sending router identifier matches the target sending router identifier, thereby obtaining multiple main paths where the target sending router identifier and the target receiving router identifier match the sending router identifier and the receiving router identifier in the pre-stored main paths, and using these multiple main paths as multiple candidate main paths.
[0123] It is understandable that the receiving router identifiers of multiple candidate primary paths are consistent with the target receiving router identifier.
[0124] In one approach, a routing table can be used to record the identifiers of each receiving router and their corresponding primary paths. Specifically, the data forwarding device can search the routing table for a receiving router identifier that matches the target receiving router identifier, then determine multiple primary paths corresponding to that receiving router identifier, and identify these multiple primary paths as multiple candidate primary paths for the target receiving router.
[0125] This embodiment provides a data forwarding method. When obtaining multiple candidate main paths matching the target transceiver router identifier from a pre-stored main path, the method specifically includes: matching the target transceiver router identifier and the target receiver router identifier with the transceiver router identifier and receiver router identifier in the pre-stored main path, respectively; and filtering out multiple main paths from the pre-stored main path where both the target transceiver router identifier and the target receiver router identifier match as candidate main paths. In this embodiment, the data forwarding device first matches the target transceiver router identifier and the target receiver router identifier with the transceiver router identifier and the receiver router identifier in the pre-stored main path, respectively. Since router identifiers have a one-to-one correspondence, multiple main paths matching both the target transceiver router identifier and the target receiver router identifier in the pre-stored main path can be determined based on the target receiver router identifier. Thus, multiple main paths can be accurately determined based on router identifier matching. Furthermore, these multiple main paths are selected as candidate main paths to determine the target data forwarding path from among them.
[0126] Example 3
[0127] Figure 3 This is a flowchart illustrating a data forwarding method provided in Embodiment 3 of this application. This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method for determining the target primary path from multiple candidate primary paths as the target data forwarding path based on a target path selection strategy, such as... Figure 3 As shown, the specific steps are as follows.
[0128] S301, Match the target path selection strategy with the path determination strategies corresponding to multiple candidate main paths.
[0129] Multiple candidate primary paths can have their corresponding path determination strategies, which can be any one or more of the following: shortest path strategy, maximum bandwidth strategy, minimum latency strategy, and highest security index strategy. The target path selection strategy should be consistent with the path determination strategy.
[0130] For example, if the path determination strategy is the shortest path strategy, the maximum bandwidth strategy, the minimum latency strategy, and the highest security index strategy, then the target path selection strategy is also the shortest path strategy, the maximum bandwidth strategy, the minimum latency strategy, and the highest security index strategy.
[0131] Specifically, the data forwarding device matches the received target path selection strategy with the path determination strategies corresponding to multiple candidate main paths.
[0132] S302, the candidate primary path that matches the target path selection strategy and the path determination strategy is determined as the target primary path, and the target primary path is used as the target data forwarding path.
[0133] Specifically, after matching the target path selection strategy with the path determination strategy, the data forwarding device determines a primary path whose path determination strategy is consistent with the target path selection strategy, and then identifies it as the target primary path.
[0134] For example, there are four candidate main paths: candidate main path 1 corresponds to the shortest path strategy, candidate main path 2 corresponds to the maximum bandwidth strategy, candidate main path 3 corresponds to the minimum latency strategy, and candidate main path 4 corresponds to the highest security index strategy. If the target path selection strategy of the data forwarding device is the minimum latency strategy, then the data forwarding device will match one candidate main path from the four candidate main paths whose path determination strategy is also the minimum latency strategy. Further, the data forwarding device determines that the path determination strategy corresponding to candidate main path 3 is the minimum latency strategy, and thus determines candidate main path 3 as the target main path.
[0135] Furthermore, the target primary path can forward the target data, thus defining the target primary path as the target data forwarding path.
[0136] This embodiment provides a data forwarding method. When determining a target primary path as the target data forwarding path from multiple candidate primary paths according to a target path selection strategy, the method specifically includes: matching the target path selection strategy with the path determination strategies corresponding to the multiple candidate primary paths; determining the candidate primary path whose target path selection strategy matches the path determination strategy as the target primary path, and using the target primary path as the target data forwarding path. In this embodiment, a target primary path is determined from multiple candidate primary paths according to the target path selection strategy. Since each candidate primary path has a corresponding path determination strategy, and the target path selection strategy is consistent with the path determination strategy, the method can accurately determine the candidate primary path whose path determination strategy matches the target path selection strategy by matching the path determination strategies corresponding to the multiple candidate primary paths with the target path selection strategy. This primary path is then determined as the target primary path and used as the target data forwarding path.
[0137] In one approach, the target primary path is determined from multiple candidate primary paths based on a target path selection strategy, which is an optional method for forwarding target data. The specific details are as follows.
[0138] The target main path is determined from multiple candidate main paths based on the target path selection strategy.
[0139] Specifically, each of the multiple candidate main paths has its own path determination strategy. The data forwarding device matches the target path selection strategy with the path determination strategies corresponding to the multiple candidate main paths. If the matching results are consistent, the candidate main path is determined as the target main path.
[0140] In response to the target primary path being unoccupied and operating normally, the target primary path is determined as the target data forwarding path.
[0141] In this context, "unoccupied and operating normally" means that the main path is not occupied by other users, and all routers along the main path are functioning normally. It can be understood that an occupied main path can be stored in the storage area of the data forwarding device.
[0142] Specifically, after the data forwarding device determines the target main path, it will further determine whether the target main path is unoccupied. The data forwarding device can obtain the main paths that are already occupied from its own storage area. If it finds that the main paths already occupied in the storage area do not include the current target main path, the data forwarding device determines that the target main path is unoccupied.
[0143] Furthermore, the data forwarding device will determine whether all routers in the target main path are operating normally. Specifically, the data forwarding device can send a detection message to each router. If a router receives the detection message, it replies with a normal operation message to the data forwarding device. If the data forwarding device receives the normal operation message, it means that the router is operating normally. If a router is not operating normally, it will not receive the detection message and will not reply with a normal operation message. Therefore, the data forwarding device will not receive the normal operation message from that router, and can thus determine that the router is malfunctioning.
[0144] Furthermore, if the data forwarding device determines that the target primary path is unoccupied and operating normally, it will then determine the target primary path as the target data forwarding path in response to the fact that the target primary path is unoccupied and operating normally.
[0145] This method, when determining the target primary path as the target data forwarding path from multiple candidate primary paths according to the target path selection strategy, specifically includes: determining the target primary path from multiple candidate primary paths according to the target path selection strategy; and confirming the target primary path as the target data forwarding path in response to the target primary path being unoccupied and operating normally. In this embodiment, the data forwarding device first determines the target primary path from multiple candidate primary paths, and then determines whether the target primary path is unoccupied and operating normally. Only in response to the target primary path being unoccupied and operating normally is the target primary path confirmed as the target data forwarding path. Since this embodiment requires the target primary path to be unoccupied and operating normally before confirming it as the target data forwarding path, it is only confirmed as the target data forwarding path when the target primary path meets the conditions of being unoccupied and operating normally. This target data forwarding path can be applied to user needs, and because it can operate normally, it can smoothly forward target data, reducing the possibility of target data forwarding interruptions.
[0146] In another approach, which is a further refinement of the above approach, the specific details are as follows.
[0147] In response to the target primary path being occupied or malfunctioning, a target backup path that matches the target transceiver router identifier and is consistent with the path determination policy corresponding to the target primary path is selected from the pre-stored backup paths corresponding to the primary path as the target data forwarding path.
[0148] If the links between routers in the target main path are disconnected, it indicates an operational abnormality, a router malfunction in the target main path, or other reasons that cause the target main path to malfunction; no restrictions are imposed here.
[0149] The data forwarding device's storage area also includes backup paths. These backup paths correspond to the primary paths. For example, a target receiving router may have multiple corresponding primary paths, and each primary path has a corresponding backup path. Therefore, there can be multiple backup paths.
[0150] It is understandable that each backup path can be labeled with the corresponding transceiver router identifier and the corresponding path determination strategy.
[0151] Specifically, in response to the target primary path being occupied or malfunctioning (where malfunction refers to an anomaly in at least one router or link between routers in the target primary path), the data forwarding device retrieves all alternative paths from the storage area and identifies the transceiver router identifiers and corresponding path determination policies for each alternative path. Further, the data forwarding device determines an alternative path whose transceiver router identifier matches the target transceiver router, and whose path determination policy is consistent with the path determination policy for the target primary path. This alternative path is then designated as the target alternative path and used as the target data forwarding path.
[0152] For example, if the target primary path is determined to be candidate primary path 3, but this target primary path is occupied or malfunctioning, a backup path will be selected as the target data forwarding path. If the target transceiver routers are identified as target sending router 1 and target receiving router 3, backup paths for target sending router 1 and target receiving router 3 will be determined, which can be multiple backup paths. If the target path selection policy is the minimum delay policy, and the path determination policy corresponding to the previously determined target primary path is also the minimum delay policy, then one backup path with the minimum delay policy will be determined from among the multiple backup paths. This backup path will be the target backup target and will be used as the target data forwarding path.
[0153] It is understandable that the target data forwarding path can originate from the primary path or from the backup path.
[0154] The specific content of this method includes: in response to the target primary path being occupied or malfunctioning, determining a target backup path from the pre-stored backup paths corresponding to the primary path that matches the target transceiver router identifier and is consistent with the path determination strategy corresponding to the target primary path as the target data forwarding path. In this embodiment, if it is determined that the target primary path is occupied or malfunctioning, a suitable backup path needs to be selected from the backup paths as the target data forwarding path. The data forwarding device first responds to the target primary path being occupied or malfunctioning by determining a target backup path from all the pre-stored backup paths corresponding to the primary path that matches the target transceiver router identifier and is consistent with the path determination strategy corresponding to the target primary path. Since backup paths also have corresponding transceiver router identifiers and path determination strategies, the data forwarding device will determine a backup path whose transceiver router identifier matches the target transceiver router identifier and whose path determination strategy is consistent with the target path selection strategy, thereby accurately determining the target backup path and thus accurately determining the target data forwarding path. Since this embodiment is implemented in response to the target primary path being occupied or malfunctioning, it can find a suitable backup path as the target data forwarding path when the target primary path cannot be used as the target data forwarding path, thus increasing the likelihood of determining the target data forwarding path.
[0155] Example 4
[0156] Figure 4 This is a flowchart illustrating a data forwarding method provided in Embodiment 4 of this application. This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method before obtaining multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths, such as... Figure 4 As shown, the specific steps are as follows.
[0157] S401: Obtain the router identifiers and topology relationships between routers in a pre-built Resource Public Key Infrastructure (RPKI) secure network system.
[0158] Topology refers to the connection relationships between routers, which can be represented by a network diagram.
[0159] In the RPKI secure network system, router identifiers and topology relationships are pre-stored in the storage area of the data forwarding device.
[0160] Specifically, the data forwarding device obtains the router identifier and topology from the storage area.
[0161] S402 determines multiple main paths between routers based on router identifiers, the topology between routers, and path determination strategies. The path determination strategies can be any one or more of the following: shortest path strategy, maximum bandwidth strategy, minimum latency strategy, and highest security index strategy.
[0162] The primary path between routers refers to the primary path between any two routers. For example, if there are routers 1, 2, and 3 in an RPKI secure network system, it is necessary to determine the primary path between router 1 and router 2, the primary path between router 1 and router 3, and the primary path between router 2 and router 3.
[0163] Specifically, the data forwarding device will identify any two routers based on the topology between them and determine multiple main paths based on the path determination strategy.
[0164] S403 determines the corresponding backup path based on the primary path between each router.
[0165] Specifically, the data forwarding device will determine the backup path corresponding to each main path based on the main path and the path determination strategy.
[0166] S404 stores the primary path and corresponding backup path between each router according to the path determination strategy.
[0167] Specifically, the data forwarding device will store the main path and its corresponding backup path that have the same path determination strategy in the storage area.
[0168] For example, if the path determination strategy is the minimum latency strategy, then the main path and backup path of all minimum latency strategies are packaged and stored.
[0169] In one approach, the primary path and its corresponding backup path can be packaged and stored according to the principle that the path determination policy and the transceiver router identifiers are consistent. For example, the transceiver routers are identified as Router 1 and Router 3, where Router 1 can act as the sending router and Router 3 as the receiving router. First, multiple primary paths and multiple backup paths with consistent transceiver router identifiers are determined. Then, a primary path and a backup path with consistent path determination policies are packaged and stored. For example, a primary path and a backup path corresponding to the minimum delay policy with consistent transceiver router identifiers are packaged together. The processing method for other path determination policies is the same and will not be elaborated here.
[0170] This embodiment provides a data forwarding method. Before obtaining multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths, the method specifically includes: obtaining router identifiers and the topology relationships between routers in a pre-built Resource Public Key Infrastructure (RPKI) secure network system; determining multiple main paths between routers based on router identifiers, the topology relationships between routers, and path determination strategies; the path determination strategies are any one or more of the following: shortest path strategy, maximum bandwidth strategy, minimum latency strategy, and highest security index strategy; determining corresponding backup paths based on the main paths between routers; and storing the main paths and corresponding backup paths between routers according to the path determination strategies. In this embodiment, the data forwarding device first obtains router identifiers and topology relationships. Since the topology relationships can characterize the connection relationships between routers, multiple main paths between routers can be accurately determined based on the topology relationships and path determination strategies. These multiple main paths have corresponding path determination strategies. Then, the data forwarding device determines the corresponding backup paths based on each main path and stores the main paths and backup paths according to the path determination strategies. This facilitates the classification of main paths and backup paths according to the path determination strategies. In this embodiment, each primary path is used to determine its corresponding backup path. When a primary path cannot be used as the target data forwarding path, the target data forwarding path can be determined from the backup paths, which is beneficial for finding a suitable target data forwarding path.
[0171] Example 5
[0172] Figure 5 This is a flowchart illustrating a data forwarding method provided in Embodiment 5 of this application. This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method for determining multiple main paths between routers based on router identifiers, the topological relationship between routers, and path determination strategies, such as... Figure 5 As shown, the specific steps are as follows.
[0173] S501 determines multiple existing paths between routers based on router identifiers and the topological relationships between routers.
[0174] Here, "existing path" refers to all paths that exist between any two routers.
[0175] Specifically, the data forwarding device will determine the existing paths between each router based on the router identifier and the router connection relationship in the topology.
[0176] Figure 6 This is a schematic diagram of a topological relationship provided in Embodiment 5 of this application. Figure 6 As shown, the specific content is as follows.
[0177] exist Figure 6 The system includes routers: Router 1, Router 2, Router 3, Router 4, and Router 5. The connections between the routers are as follows: Router 1 is connected to Router 2 and Router 3 respectively; Router 2 is connected to Router 4; Router 3 is connected to Router 5; and Router 4 is connected to Router 5. The connections can be either wired or wireless.
[0178] Furthermore, the data forwarding device needs to determine the existing path between any two routers by combining them pairwise from the five routers mentioned above. A brief explanation is given using router 1 and router 5 as an example, as follows.
[0179] For example, to achieve data forwarding between router 1 and router 5, where router 1 is the sending router and router 5 is the receiving router, there can be multiple paths for data to be forwarded from router 1 to router 5. These are path 1: router 1-router 3-router 5, path 2: router 1-router 2-router 4-router 5, path 3: router 1-router 4-router 5, and path 4: router 1-router 2-router 3-router 5.
[0180] S502, determine the path consistent with each path determination strategy from the multiple existing paths as the main path.
[0181] Specifically, the data forwarding device determines the path corresponding to each path determination strategy from multiple existing paths and uses it as the main path.
[0182] For example, in the exemplary example in S501 above, the path of each path determination strategy will be determined from the four existing paths and used as the main path.
[0183] This embodiment provides a data forwarding method. When determining multiple main paths between routers based on router identifiers, the topological relationship between routers, and path determination strategies, the method specifically includes: determining multiple existing paths between routers based on router identifiers and the topological relationship between routers; and determining the path consistent with each path determination strategy from these multiple existing paths as the main path. The data forwarding device in this embodiment first determines multiple existing paths between routers based on router identifiers and the topological relationship. Since the topological relationship represents the connection relationship between routers, multiple existing paths can be accurately determined based on the topological relationship, and then the path consistent with each path determination strategy is further determined from these multiple existing paths as the main path.
[0184] In one approach, this method is an optional approach that selects the primary path from among the multiple existing paths, choosing the path consistent with the path determination strategy for each type of path. Figure 7 This is a flowchart illustrating another data forwarding method provided in Embodiment 5 of this application. Figure 7 As shown, the specific steps are as follows.
[0185] S701, calculate the number of routers in each existing path, and select the path with the fewest routers as the shortest main path.
[0186] The number of routers in each existing path refers to the sum of the number of transceiver routers and intermediate routers, where the number of intermediate routers can be 0.
[0187] Specifically, the data forwarding device calculates the number of routers in each existing path and selects the existing path with the fewest routers as the shortest main path.
[0188] For example, if there are 4 routers in path 1 and 6 routers in path 2, then path 1 is selected as the shortest main path.
[0189] In one approach, if at least one of the existing paths has the fewest number of routers, then the shortest primary path can be selected from this path based on the user's actual needs. For example, if both storage path 1 and existing path 2 have the fewest number of routers, then the average bandwidth of existing path 1 and existing path 2 can be calculated, and the path with the largest average bandwidth can be selected as the shortest primary path. Alternatively, other principles can be used to select the shortest path from the at least one existing path with the fewest number of routers; this is not a restriction.
[0190] S702, calculate the average bandwidth of the routers included in each existing path, and select the path with the largest average bandwidth as the main path with the largest bandwidth.
[0191] Bandwidth is a performance indicator for each router, and routers can store their own bandwidth values.
[0192] Specifically, the data forwarding device calculates the average bandwidth of the routers in each existing path. Specifically, the data forwarding device will obtain the bandwidth value stored by the routers in each existing path, sum the bandwidth values of the routers in each existing path, calculate the average value, and select the existing path with the largest average bandwidth as the shortest main path.
[0193] S703, calculate the total delay of the routers included in each existing path, and select the path with the smallest total delay as the minimum delay main path.
[0194] Latency is a performance characteristic of each router, and routers can store their own latency. Higher latency indicates a longer time interval between data forwarding to the next router.
[0195] Specifically, the data forwarding device calculates the total latency of the routers in each existing path. Specifically, the data forwarding device will obtain the latency stored by the routers in each existing path, sum the latency of the routers in each existing path, and select the existing path with the smallest total latency as the shortest main path.
[0196] S704 Calculate the average security index of the routers included in each existing path, and select the path with the highest average security index as the main path with the highest security index.
[0197] The security index is a performance indicator for each router, and routers can store their own security index. The higher the security index, the greater the degree of data protection.
[0198] Specifically, the data forwarding device calculates the security index of the routers in each existing path. Specifically, the data forwarding device will obtain the security index stored by the routers in each existing path, sum the security indices of the routers in each existing path, calculate the average value, and select the existing path with the highest average security index as the shortest main path.
[0199] It is understood that the steps in this embodiment are not in any particular order and can be performed simultaneously or sequentially; no restriction is placed here.
[0200] This method, when determining the primary path from multiple existing paths that matches each path determination strategy, specifically includes: calculating the number of routers in each existing path and selecting the path with the fewest routers as the shortest primary path; calculating the average bandwidth of the routers in each existing path and selecting the path with the highest average bandwidth as the maximum bandwidth primary path; calculating the total latency of the routers in each existing path and selecting the path with the smallest total latency as the minimum latency primary path; and calculating the average security index of the routers in each existing path and selecting the path with the highest average security index as the highest security index primary path. In this embodiment, the data forwarding device will calculate the primary path that conforms to each path determination strategy. Since this embodiment can calculate the number of routers, average bandwidth, total latency, and average security index, it can accurately determine the shortest path, the maximum bandwidth primary path, the minimum latency primary path, and the highest security index primary path.
[0201] Example 6
[0202] Figure 8 This is a flowchart illustrating a data forwarding method provided in Embodiment Six of this application. This embodiment is a further refinement of any of the above embodiments, and it is an optional method for determining the corresponding backup path based on the primary path between routers. Figure 8 As shown, the specific steps are as follows.
[0203] S801, remove the main path that is consistent with each path determination strategy from the corresponding multiple existing paths to obtain the remaining paths.
[0204] Specifically, the data forwarding device will remove the main path that is consistent with each path determination strategy from the multiple existing paths, and retain the remaining existing paths.
[0205] For example, assuming there are a total of 8 existing paths, after removing the main paths (4 in total) that are consistent with the four path determination strategies, the remaining 4 existing paths are taken as the remaining paths.
[0206] S802, determine the path from the remaining paths that is consistent with the path determination strategy for each path as the backup path.
[0207] Specifically, the data forwarding device will select the path that is consistent with each path determination strategy from the remaining paths according to the path determination strategy, and designate it as the backup path.
[0208] For example, based on the exemplary example in S801 above, the number of routers, average bandwidth, total latency, and average security index are calculated for each of the four remaining paths. If the number of routers in remaining path 1 is 4, and the number of routers in all other remaining paths is greater than 4, then remaining path 1 is determined to be the shortest backup path. If the average bandwidth of remaining path 2 is the largest, then remaining path 2 is determined to be the largest bandwidth backup path. If the total latency of remaining path 3 is the smallest, then remaining path 3 is determined to be the smallest latency backup path. If the average security index of remaining path 4 is the highest, then remaining path 4 is determined to be the main path with the highest security index. The method for calculating the number of routers, average bandwidth, total latency, and average security index for each remaining path is the same as in S701 to S704, and will not be repeated here.
[0209] In determining the shortest backup path, it is also required that the routers included in the shortest backup path have the lowest similarity to the routers included in the corresponding primary path.
[0210] In one approach, a backup path can satisfy multiple path determination strategies. For example, if the remaining path 1 has the fewest routers and the highest average bandwidth, then the remaining path 1 can be used as both the shortest backup path and the maximum bandwidth backup path. It is understandable that a primary path can also satisfy multiple path determination strategies, just like a backup path; this will not be elaborated upon here.
[0211] This embodiment provides a data forwarding method. When determining corresponding backup paths based on the primary paths between routers, the method specifically includes: removing primary paths consistent with each path determination strategy from multiple existing paths to obtain remaining paths; and determining backup paths from the remaining paths that are consistent with each path determination strategy. In this embodiment, the data forwarding device first removes primary paths consistent with each path determination strategy from multiple existing paths to obtain remaining paths. Then, it determines backup paths from the remaining paths according to the path determination strategy. Since the backup paths are selected from the remaining paths, and each backup path also satisfies the corresponding path determination strategy, the backup paths are superior paths besides the primary paths. Therefore, this embodiment can obtain more suitable and superior backup paths.
[0212] Example 7
[0213] Figure 9 This is a flowchart illustrating a data forwarding method provided in Embodiment 7 of this application. This embodiment is a further refinement of any of the above embodiments. This embodiment is an optional method for obtaining router identifiers and the topological relationships between routers in a pre-built RPKI secure network system, such as... Figure 9 As shown, the specific steps are as follows.
[0214] S901, obtain the binding relationship between the router identifier and the corresponding Internet Protocol IP address stored in each router in the initial network system.
[0215] The initial network system is the first network system built. Within the initial network system, each router has its own router identifier and its corresponding IP address is bound together.
[0216] The IP address binding relationship refers to the binding relationship between routers and networks, with each router corresponding to one network. Routers should correspond to their respective IP addresses. For example, the binding relationship for router 1 is: router 1 and IP address 1.
[0217] In the initial network system, the binding relationship between the router identifier and the corresponding IP address stored in each router is pre-stored in the storage area of the data forwarding device.
[0218] Specifically, the data forwarding device retrieves from the storage area the binding relationship between the router identifier and the corresponding IP address stored in each router in the initial network system.
[0219] S902 determines whether each router is an invalid router based on the binding relationship between the router identifier and the corresponding IP address stored in each router.
[0220] The router itself stores the binding relationship between its own router identifier and its corresponding IP address.
[0221] An invalid router is one that has not obtained security authentication. Such a router may cause data theft or other non-compliant behavior.
[0222] Specifically, the data forwarding device will obtain the binding relationship between the router identifier and the corresponding IP address from the router's storage area. Then, the data forwarding device will compare the obtained binding relationship between the router identifier and the corresponding IP address with the binding relationship between the router identifier and the corresponding IP address stored in its own storage, thereby determining whether the router is an invalid router.
[0223] In one approach, this method is an optional way to determine whether a router is an invalid router based on the binding relationship between the router identifier and the corresponding IP address stored in each router. Figure 10 This is a flowchart illustrating another data forwarding method provided in Embodiment Seven of this application. Figure 10 As shown, the specific steps are as follows.
[0224] S1001, retrieve the pre-stored real binding relationship filter table, which contains the real binding relationship between the identifier of each router and its IP address.
[0225] Here, "real binding relationship" refers to the binding relationship between a securely authenticated router identifier and an IP address. All real binding relationships are compiled into a table, resulting in a real binding relationship filtering table. This filtering table can be pre-stored in the storage area of the data forwarding device.
[0226] Specifically, the data forwarding device retrieves the filter table from the storage area.
[0227] S1002, if it is determined that the binding relationship between the router identifier and the corresponding IP address stored in a router is consistent with the corresponding real binding relationship in the real binding relationship filter table, or if the binding relationship between the router identifier and the corresponding IP address stored in the router does not exist in the real binding relationship filter table, then the router is determined to be a valid router.
[0228] Specifically, the data forwarding device retrieves the binding relationship between the router identifier and its corresponding IP address from the router's storage area. Then, it compares the stored binding relationship between the router identifier and its corresponding IP address with the real binding relationship in the real binding relationship filter table. If they match, or if the stored binding relationship between the router identifier and its corresponding IP address does not exist in the real binding relationship filter table, then the router is determined to be a valid router.
[0229] Specifically, if they match, it means the binding relationship between the stored router identifier and the corresponding IP address is the same as the actual binding relationship, and the router corresponding to that router identifier is a security-authenticated router. If it does not exist in the actual binding relationship filtering table, it cannot be proven that the router has not been security-authenticated. Perhaps the actual binding relationship filtering table has missed the router's actual binding relationship. Therefore, in order to ensure that data passing through this router can be forwarded smoothly, this router is also determined to be a valid router.
[0230] S1003. If it is determined that the binding relationship between the router identifier and the corresponding IP address stored in a router is inconsistent with the corresponding real binding relationship in the real binding relationship filter table, then the router is determined to be an invalid router.
[0231] Specifically, the data forwarding device compares the router identifier and corresponding IP address binding relationship stored in a router with the corresponding real binding relationship in the real binding relationship filtering table. If they do not match, the router is determined to be an invalid router.
[0232] Specifically, since routers with genuine binding relationships in the genuine binding relationship filter table have all undergone security authentication, if the router's own stored router identifier does not match the binding relationship of the corresponding IP address, it means that the router may have had its router identifier or corresponding IP address deliberately tampered with. In this case, the router has not undergone security authentication.
[0233] In one approach, the binding relationship can also be the relationship between the router identifier and the IP address prefix.
[0234] This method, when determining whether a router is invalid based on the binding relationship between router identifiers and corresponding IP addresses stored in each router, specifically includes: obtaining a pre-stored real binding relationship filter table, which contains the real binding relationships between router identifiers and IP addresses; if it is determined that the binding relationship between a router identifier and corresponding IP address stored in a router matches the corresponding real binding relationship in the real binding relationship filter table, or if the stored binding relationship between router identifier and corresponding IP address does not exist in the real binding relationship filter table, then the router is determined to be a valid router; if it is determined that the binding relationship between a router identifier and corresponding IP address stored in a router does not match the corresponding real binding relationship in the real binding relationship filter table, then the router is determined to be an invalid router. In this embodiment, the data forwarding device first obtains the real binding relationship filtering table, and then retrieves the router identifier and corresponding IP address binding relationship stored in the router itself. Since the real binding relationship filtering table contains the real binding relationship between the router identifier and IP address, the stored router identifier and corresponding IP address binding relationship is compared with the real binding relationship in the real binding relationship filtering table. If they match, or if the router identifier and corresponding IP address binding relationship does not exist in the real binding relationship filtering table, the router is determined to be a valid router; if they do not match, the router is determined to be an invalid router. Because the routers and their corresponding IP addresses in the real binding relationship filtering table have all undergone security authentication, it is possible to accurately determine whether a router is valid.
[0235] S903: If at least one router is determined to be an invalid router, at least one router shall be deleted, and an RPKI secure network system shall be built based on the remaining routers.
[0236] Specifically, the data forwarding device will remove at least one invalid router from the entire initial network system, retain the valid routers, and build the RPKI secure network system based on the valid routers.
[0237] It is understandable that there will be no wireless routers in this RPKI secure network system, thus ensuring that data can be securely forwarded within the RPKI secure network system.
[0238] This embodiment provides a data forwarding method. Before obtaining the router identifiers and topology relationships between routers in a pre-built RPKI secure network system, the method specifically includes: obtaining the binding relationship between the router identifiers and corresponding IP addresses stored in each router in the initial network system; determining whether each router is an invalid router based on the binding relationship between the router identifiers and corresponding IP addresses stored in each router; if at least one router is determined to be an invalid router, then at least one router is deleted, and an RPKI secure network system is built based on the retained routers. In this embodiment, the data forwarding device obtains the binding relationship between router identifiers and corresponding IP addresses from the storage area of the routers in the initial network system. Then, it determines whether each router is an invalid router based on the binding relationship between router identifiers and corresponding IP addresses stored in each router. If the data forwarding device determines at least one invalid router, it deletes at least one invalid router from the initial network system, retains the valid routers in the initial network system, and builds an RPKI secure network system based on the retained routers. Since the RPKI secure network system does not contain invalid routers, and since invalid routers can steal data forwarded by other routers, the built RPKI secure network system can ensure that data is not stolen during forwarding. Since invalid routers can also transmit non-compliant data, the built RPKI secure network system can also ensure that the forwarded data is compliant data.
[0239] Example 8
[0240] The following are embodiments of the apparatus described in this application. Figure 11 This is a schematic diagram of a data forwarding device provided in Embodiment 8 of this application. Figure 11 As shown, the device 110 includes the following modules.
[0241] The receiving module 1101 is used to receive a data forwarding request sent by a user terminal. The data forwarding request includes a target path selection strategy, a target transceiver router identifier, and the target data to be sent.
[0242] The acquisition module 1102 is used to acquire multiple candidate main paths that match the target transceiver router identifier from the pre-stored main paths; the multiple main paths corresponding to each transceiver router identifier are pre-stored and determined according to different path determination strategies, including any one or more of the following main paths: shortest main path, maximum bandwidth main path, minimum latency main path, and highest security index main path.
[0243] The determination module 1103 is used to determine the target primary path as the target data forwarding path from multiple candidate primary paths according to the target path selection strategy;
[0244] Forwarding module 1104 is used to forward target data using the target data forwarding path.
[0245] In one feasible approach, the target transceiver router identifier includes: a target sending router identifier and a target receiving router identifier; the acquisition module 1102, when acquiring multiple candidate main paths matching the target transceiver router identifier from pre-stored main paths, is specifically used for:
[0246] The target sending router identifier and the target receiving router identifier are matched with the sending router identifier and the receiving router identifier in the pre-stored main path, respectively. Multiple main paths that match the target sending router identifier with the sending router identifier in the pre-stored main path and the target receiving router identifier with the receiving router identifier in the pre-stored main path are selected as multiple candidate main paths.
[0247] In one feasible approach, the determining module 1103, when determining the target primary path as the target data forwarding path from multiple candidate primary paths according to the target path selection strategy, is specifically used for:
[0248] The target path selection strategy is matched with the path determination strategy corresponding to multiple candidate main paths; the candidate main path that matches the target path selection strategy and the path determination strategy is determined as the target main path, and the target main path is used as the target data forwarding path.
[0249] In one feasible approach, the determining module 1103, when determining the target primary path as the target data forwarding path from multiple candidate primary paths according to the target path selection strategy, is specifically used for:
[0250] The target primary path is determined from multiple candidate primary paths according to the target path selection strategy; if the target primary path is unoccupied and operating normally, the target primary path is determined as the target data forwarding path.
[0251] In one feasible approach, the determining module 1103 is further configured to: in response to the target primary path being occupied or malfunctioning, determine a target backup path from the backup paths corresponding to the pre-stored primary path that matches the target transceiver router identifier and is consistent with the path determination strategy corresponding to the target primary path as the target data forwarding path.
[0252] In one feasible approach, before retrieving multiple candidate main paths matching the target transceiver router identifier from a pre-stored main path, this application provides a data forwarding apparatus, which further includes a storage module.
[0253] The acquisition module 1102 is further used to acquire router identifiers and topological relationships between routers in a pre-built Resource Public Key Infrastructure (RPKI) secure network system; the determination module 1103 is further used to determine multiple primary paths between routers based on router identifiers, topological relationships between routers, and path determination strategies; the path determination strategies are any one or more of the following strategies: shortest path strategy, maximum bandwidth strategy, minimum latency strategy, and highest security index strategy; the determination module 1103 is further used to determine corresponding backup paths based on the primary paths between routers; and the storage module is used to store the primary paths and corresponding backup paths between routers according to the path determination strategies.
[0254] In one feasible approach, the determining module 1103, when determining multiple primary paths between routers based on router identifiers, the topological relationships between routers, and path determination strategies, is specifically used for:
[0255] Based on the router identifier and the topological relationship between the routers, multiple existing paths between each router are determined; from the corresponding multiple existing paths, the path consistent with each path determination strategy is determined as the primary path.
[0256] In one feasible approach, the determining module 1103, when determining the path consistent with each path determination strategy from the corresponding multiple existing paths as the main path, is specifically used for:
[0257] Calculate the number of routers in each existing path and select the path with the fewest routers as the shortest main path; calculate the average bandwidth of the routers in each existing path and select the path with the largest average bandwidth as the maximum bandwidth main path; calculate the total latency of the routers in each existing path and select the path with the smallest total latency as the minimum latency main path; calculate the average security index of the routers in each existing path and select the path with the highest average security index as the highest security index main path.
[0258] In one feasible approach, the determining module 1103, when determining the corresponding backup path based on the primary path between each router, is specifically used to: remove the primary path consistent with each path determination strategy from the corresponding multiple existing paths to obtain the remaining paths; and determine the path consistent with each path determination strategy from the remaining paths as the backup path.
[0259] In one feasible approach, before obtaining the router identifiers and topological relationships between routers in a pre-built RPKI secure network system, this application provides a data forwarding device, which further includes a building module.
[0260] The acquisition module 1102 is further used to acquire the binding relationship between router identifiers and corresponding IP addresses stored in each router in the initial network system; the determination module 1103 is further used to determine whether each router is an invalid router based on the binding relationship between router identifiers and corresponding IP addresses stored in each router; the construction module is used to delete at least one router if it is determined that at least one router is an invalid router, and to build an RPKI secure network system based on the retained router.
[0261] In one feasible approach, the determining module 1103, when determining whether a router is an invalid router based on the binding relationship between the router identifier and the corresponding IP address stored in each router, is specifically used for:
[0262] Retrieve a pre-stored real binding relationship filter table, which contains the real binding relationships between the identifiers and IP addresses of each router. If it is determined that the stored router identifier-to-IP address binding relationship of a router matches the corresponding real binding relationship in the real binding relationship filter table, or if the stored router identifier-to-IP address binding relationship does not exist in the real binding relationship filter table, then the router is determined to be a valid router. If it is determined that the stored router identifier-to-IP address binding relationship of a router does not match the corresponding real binding relationship in the real binding relationship filter table, then the router is determined to be an invalid router.
[0263] Example 9
[0264] Figure 12 This is a schematic diagram of the structure of an electronic device provided in Embodiment 9 of this application. Figure 11 As shown, the electronic device 120 may include: a processor 1201, a memory 1202 and a transceiver 1103 communicatively connected to the processor 1201. The memory 1202 stores computer-executable instructions; the transceiver 1203 is used for sending and receiving data; the processor 1101 executes the computer-executable instructions stored in the memory 1202 to implement any one of the method embodiments 1 to 7 described above. The specific implementation methods and technical effects are similar and will not be repeated here.
[0265] In this embodiment, the memory 1202 and the processor 1201 are connected via a bus. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 12 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0266] Example 10
[0267] This application provides a computer-readable storage medium storing computer-executable instructions. When executed by a processor, the computer-executable instructions are used to implement any one of the method embodiments 1 to 7 described above. The specific implementation methods and technical effects are similar and will not be repeated here.
[0268] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0269] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A data forwarding method, characterized by, The method comprises: receiving a data forwarding request sent by a user terminal, the data forwarding request comprising a target path selection strategy, a target transceiver router identifier and target data to be sent; obtaining router identifiers in a resource public key infrastructure (RPKI) security network system and a topological relationship between routers in the RPKI security network system; the RPKI security network system is built based on the router identifiers and the topological relationship between the routers, and the RPKI security network system is built by deleting at least one invalid router from an initial network system and reserving the other routers in the initial network system, wherein the at least one invalid router is determined based on a binding relationship between the router identifiers and corresponding IP addresses stored in the routers in the initial network system; determining a plurality of main paths between the routers based on the router identifiers, the topological relationship between the routers and a path determination strategy, wherein the path determination strategy is any one or more of a shortest path strategy, a maximum bandwidth strategy, a minimum delay strategy and a highest security index strategy; determining corresponding backup paths between the routers based on the main paths between the routers; storing the main paths and the corresponding backup paths between the routers according to the path determination strategy; obtaining a plurality of candidate main paths matching the target transceiver router identifier from the pre-stored main paths, wherein the plurality of main paths corresponding to each transceiver router identifier are determined according to different path determination strategies, and the main paths include any one or more of a shortest main path, a maximum bandwidth main path, a minimum delay main path and a highest security index main path; determining a target main path as a target data forwarding path from the plurality of candidate main paths according to the target path selection strategy; and forwarding the target data by using the target data forwarding path.
2. The method of claim 1, wherein, The target transceiver router identifier comprises a target sending router identifier and a target receiving router identifier. The method comprises: matching the target sending router identifier and the target receiving router identifier with sending router identifiers and receiving router identifiers in the pre-stored main paths, respectively; selecting, from the pre-stored main paths, a plurality of main paths matching the target sending router identifier and the target receiving router identifier as the plurality of candidate main paths.
3. The method of claim 1, wherein, The method comprises: matching the target path selection strategy with path determination strategies corresponding to the plurality of candidate main paths; determining a candidate main path matching the target path selection strategy and the path determination strategy as the target main path, and determining the target main path as the target data forwarding path.
4. The method of claim 1, wherein, The method comprises: determine a target main path from the multiple candidate main paths according to the target path selection strategy; determine the target main path as the target data forwarding path in response to the target main path being unoccupied and normally operating.
5. The method of claim 4, wherein, The method further comprises: determine a target backup path from the pre-stored backup paths corresponding to the main path in response to the target main path being occupied or abnormally operating, the target backup path matching the target transceiver router identifier and being consistent with the path determination strategy corresponding to the target main path.
6. The method of claim 1, wherein, The method of determining the multiple main paths between the routers based on the router identifiers, the topology relationship between the routers and the path determination strategy comprises: determine the multiple existing paths between the routers according to the router identifiers and the topology relationship between the routers; determine the paths consistent with each path determination strategy from the corresponding multiple existing paths as the main paths.
7. The method of claim 6, wherein, The method of determining the paths consistent with each path determination strategy from the corresponding multiple existing paths as the main paths comprises: calculate the number of routers contained in each existing path, and select the path with the least number of routers as the shortest main path; calculate the bandwidth average of the routers contained in each existing path, and select the path with the largest bandwidth average as the main path with the largest bandwidth; calculate the total delay of the routers contained in each existing path, and select the path with the smallest total delay as the main path with the smallest delay; calculate the security index average of the routers contained in each existing path, and select the path with the highest security index average as the main path with the highest security index.
8. The method of claim 1, wherein, The method of determining the backup paths corresponding to the main paths between the routers comprises: eliminate the main paths consistent with each path determination strategy from the corresponding multiple existing paths to obtain residual paths; determine the paths consistent with each path determination strategy from the residual paths as the backup paths.
9. The method of claim 1, wherein, Before the method of obtaining the router identifiers in the pre-built RPKI secure network system and the topology relationship between the routers, the method further comprises: obtain the binding relationship between the router identifiers stored in each router in the initial network system and the corresponding Internet Protocol (IP) addresses; determine whether each router is an invalid router according to the binding relationship between the router identifiers stored in each router and the corresponding IP addresses; if it is determined that at least one router is an invalid router, delete the at least one router, and build the RPKI secure network system based on the remaining routers.
10. The method of claim 9, wherein, The method of determining whether each router is an invalid router according to the binding relationship between the router identifiers stored in each router and the corresponding IP addresses comprises: obtain a pre-stored real binding relationship filter table, the filter table having the real binding relationship between the identifiers and the IP addresses of each router; if it is determined that the binding relationship between the router identifier stored in a certain router and the corresponding IP address is consistent with the corresponding real binding relationship in the real binding relationship filter table, or the binding relationship between the router identifier stored in the certain router and the corresponding IP address does not exist in the real binding relationship filter table, determine that the certain router is a valid router; If it is determined that the binding relationship between the router identifier and the corresponding IP address stored by the router is inconsistent with the corresponding real binding relationship in the real binding relationship filtering table, the router is determined to be an invalid router.
11. A data forwarding apparatus, characterized by comprising: The apparatus comprises: A receiving module configured to receive a data forwarding request sent by a user terminal, the data forwarding request comprising a target path selection strategy, a target transceiving router identifier, and target data to be sent; An obtaining module configured to obtain a plurality of candidate primary paths matching the target transceiving router identifier from a plurality of primary paths stored in advance, wherein the plurality of primary paths corresponding to each transceiving router identifier are determined according to different path determination strategies, including any one or more of the following primary paths: a shortest primary path, a maximum bandwidth primary path, a minimum latency primary path, and a highest security index primary path; A determining module configured to determine a target primary path as a target data forwarding path from the plurality of candidate primary paths according to the target path selection strategy; A forwarding module configured to forward the target data using the target data forwarding path; The obtaining module is further configured to obtain router identifiers and topological relationships between routers in a resource public key infrastructure (RPKI) secure network system built in advance, wherein the RPKI secure network system is built based on the remaining routers after at least one invalid router is deleted, and the at least one invalid router is determined according to the binding relationship between the router identifier and the corresponding IP address stored in each router in an initial network system; The determining module is further configured to determine a plurality of primary paths between the routers based on the router identifiers, the topological relationships between the routers, and path determination strategies, wherein the path determination strategies include any one or more of the following strategies: a shortest path strategy, a maximum bandwidth strategy, a minimum latency strategy, and a highest security index strategy; The determining module is further configured to determine corresponding backup paths according to the primary paths between the routers; A storage module configured to store the primary paths and the corresponding backup paths between the routers according to the path determination strategies.
12. An electronic device comprising: A processor, a memory, and a transceiver connected to the processor in communication; The memory stores computer execution instructions; and the transceiver is configured to receive and send data. The processor executes the computer execution instructions stored in the memory to implement the method of any one of claims 1-10.
13. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method of any one of claims 1-10.
Citation Information
Patent Citations
Policy routing path determination method and device, network equipment and readable storage medium
CN112333093A
Transmission path determination method and device, server and storage medium
CN114040467A