A data processing method, apparatus, network element device, and readable storage medium

By generating data packet collections in user mode and diversion to corresponding state threads for processing, the problem of limited processing capabilities of network element devices is solved, and more efficient data packet processing is achieved.

CN115834722BActive Publication Date: 2025-07-18TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111087393.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-16
Publication Date
2025-07-18
Estimated Expiration
2041-09-16

AI Technical Summary

Technical Problem

When a network element device receives a large number of data packets, it frequently switches the kernel state and user state space and data copying, resulting in limited processing capabilities.

Method used

A collection of data packets is generated in the worker thread in the user state, and the kernel data packets are diverted to the kernel state thread for processing according to the access control rules, and the business data packets are diverted to the message processing node for flow processing.

Benefits of technology

It improves the processing capability of network element devices on data packets, reduces frequent context switching and mutual copying of data between user state and kernel state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834722B_ABST
    Figure CN115834722B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a data processing method, apparatus, network element device, and readable storage medium. The method includes: in a working thread in the user state, generating a data packet set based on the data packets in the buffer receiving queue; if there are kernel data packets in the data packet set, then in the working thread, shunting the kernel data packets to a kernel state thread according to the access control rules, and performing flow processing on the kernel data packets through the kernel state thread; if there are service data packets in the data packet set, then in the working thread, shunting the service data packets to one or more packet processing nodes in the working thread according to the access control rules, and performing flow processing on the service data packets through the one or more packet processing nodes. By using the present application, it is possible to perform flow processing on the data packets in the data packet set in the user state, thereby improving the processing ability of the network element device for data packets.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a data processing method, apparatus, network element device, and readable storage medium. Background Art

[0002] Currently, when a network element device (e.g., a gateway) receives a data packet, it needs to perform transfer processing on the data packet in the kernel state, and after the transfer processing of the data packet, it switches from the kernel state to the user state. When the gateway receives a large number of data packets, the frequent switching of the gateway (i.e., the frequent switching between the kernel state space and the user state space), and the mutual copying of data between the kernel state space and the user state space will generate a large time overhead and performance overhead, thereby limiting the processing ability of the gateway for data packets. Summary of the Invention

[0003] Embodiments of this application provide a data processing method, apparatus, network element device, and readable storage medium, which can improve the processing ability of the network element device for data packets.

[0004] On the one hand, embodiments of this application provide a data processing method, including:

[0005] In a working thread in the user state, generate a data packet set based on the data packets in the buffer reception queue; the data packets in the same data packet set have the same packet format;

[0006] If there is a kernel data packet in the data packet set, then in the working thread, according to the access control rule, divert the kernel data packet to the kernel state thread, and perform transfer processing on the kernel data packet through the kernel state thread;

[0007] If there is a service data packet in the data packet set, then in the working thread, according to the access control rule, divert the service data packet to one or more packet processing nodes in the working thread, and perform transfer processing on the service data packet through the one or more packet processing nodes.

[0008] On the one hand, embodiments of this application provide a data processing apparatus, including:

[0009] A set generation module, configured to generate a data packet set based on the data packets in the buffer reception queue in a working thread in the user state; the data packets in the same data packet set have the same packet format;

[0010] A first processing module, configured to, if there is a kernel data packet in the data packet set, then in the working thread, according to the access control rule, divert the kernel data packet to the kernel state thread, and perform transfer processing on the kernel data packet through the kernel state thread;

[0011] A second processing module, configured to, if there is a service data packet in the data packet set, in a working thread, split the service data packet to one or more packet processing nodes in the working thread according to access control rules, and perform transfer processing on the service data packet through the one or more packet processing nodes.

[0012] Among them, the set generation module includes:

[0013] A format recognition unit, configured to poll the buffer receiving queue corresponding to the working thread in the working thread in user mode, and recognize the packet format of the data packet obtained by polling; the packet format includes a target packet format.

[0014] A set generation unit, configured to, if the number of data packets with the target packet format is greater than or equal to a quantity threshold, generate a data packet set corresponding to the target packet format based on the data packets with the target packet format.

[0015] Among them, the access control rules include kernel packet matching rules and service packet matching rules belonging to the access control list.

[0016] The apparatus further includes:

[0017] A rule matching module, configured to send the data packet set to an access control node in the working thread, and in the access control node, match the data packets in the data packet set based on the access control list.

[0018] A first matching module, configured to, if there is a data packet in the data packet set that matches the kernel packet matching rule, determine that there is a kernel data packet in the data packet set.

[0019] A second matching module, configured to, if there is a data packet in the data packet set that matches the service packet matching rule, determine that there is a service data packet in the data packet set.

[0020] Among them, the rule matching module includes:

[0021] A packet detection unit, configured to load the data packets in the data packet set into a data cache, and sequentially perform packet detection on the data packets in the data packet set in the data cache.

[0022] A first sending unit, configured to, if it is detected by packet detection that there is a data packet with successful verification in the data packet set, send the data packet with successful verification to an access control node in the working thread.

[0023] Then the rule matching module further includes:

[0024] A second sending unit, configured to send a data packet with failed verification to a failure handling node if a data packet with failed verification is detected in a data packet set.

[0025] Among them, the packet detection unit includes:

[0026] A packet loading subunit, configured to load data packets in a data packet set into a data cache, and obtain a data packet Si in the data packet set from the data cache; i ; i is a positive integer less than or equal to the number of data packets in the data packet set;

[0027] A first detection subunit, configured to obtain a packet processing instruction corresponding to the data packet Si, load the packet processing instruction into an instruction cache, and perform packet detection on the data packet Si through the packet processing instruction in the instruction cache; i corresponding to the packet processing instruction, load the packet processing instruction into the instruction cache, and perform packet detection on the data packet Si through the packet processing instruction in the instruction cache; i for packet detection;

[0028] A second detection subunit, configured to obtain a data packet Si in the data packet set from the data cache, obtain a packet processing instruction from the instruction cache, and perform packet detection on the data packet Si through the packet processing instruction; i+1 from the data cache, obtain a packet processing instruction from the instruction cache, and perform packet detection on the data packet Si through the packet processing instruction; i+1 for packet detection.

[0029] Among them, one or more packet processing nodes include a routing matching node;

[0030] The second processing module includes:

[0031] A packet shunting unit, configured to shunt a service data packet to a routing matching node in a working thread according to an access control rule if there is a service data packet in the data packet set;

[0032] A routing matching unit, configured to perform routing matching on a destination address carried by the service data packet through the routing matching node to obtain a routing data packet corresponding to the service data packet;

[0033] A packet parsing unit, configured to perform packet protocol parsing on the routing data packet.

[0034] Among them, one or more packet processing nodes further include a first packet parsing node and a second packet parsing node;

[0035] The packet parsing unit includes:

[0036] A protocol identification subunit, configured to identify a packet protocol type associated with the routing data packet;

[0037] A first parsing subunit, configured to, if the message protocol type is the Generic Routing Encapsulation (GRE) protocol type, send the routing data message to a first message parsing node, and perform message protocol parsing on the routing data message through the first message parsing node;

[0038] A second parsing subunit, configured to, if the message protocol type is the Virtual Extensible Local Area Network (VXLAN) protocol type, send the routing data message to a second message parsing node, and perform message protocol parsing on the routing data message through the second message parsing node.

[0039] Wherein, the one or more message processing nodes further include a policy node and a tunnel processing node;

[0040] The second processing module further includes:

[0041] A policy control unit, configured to obtain the parsed data message obtained through message protocol parsing, send the parsed data message to the policy node, and perform policy control on the parsed data message through the policy node to obtain a policy-controlled parsed data message;

[0042] A tunnel processing unit, configured to send the policy-controlled parsed data message to the tunnel processing node, and perform tunnel processing on the policy-controlled parsed data message through the tunnel processing node to obtain an encrypted data message;

[0043] A message sending unit, configured to send the encrypted data message to the network card sending queue corresponding to the network card component.

[0044] Wherein, the message sending unit is specifically configured to add the encrypted data message to the buffer sending queue corresponding to the working thread through the tunnel processing node;

[0045] The message sending unit is further specifically configured to obtain the encrypted data message in the buffer sending queue through the network card component, and store the encrypted data message obtained by the network card component into the network card sending queue corresponding to the network card component.

[0046] Wherein, the device further includes:

[0047] A message storage module, configured to obtain a data message through the network card component, and store the data message obtained by the network card component into the network card receiving queue corresponding to the network card component;

[0048] An interception interruption module, configured to perform interception interruption processing on the data message in the network card receiving queue through the network card component, and evenly distribute the data message after interception interruption processing to the buffer receiving queue.

[0049] Wherein, the number of working threads is at least two, and each of the at least two working threads corresponds to a buffer receiving queue;

[0050] The interception interruption module is specifically configured to perform interception interruption processing on data packets in the network card receiving queue through the network card component, and generate a packet identifier for the data packets after the interception interruption processing;

[0051] The interception interruption module is also specifically configured to evenly distribute the data packets after the interception interruption processing to the buffer receiving queues respectively corresponding to at least two working threads according to the packet identifier.

[0052] On the one hand, an embodiment of the present application provides a network element device, including: a processor, a memory, and a network interface;

[0053] The above-mentioned processor is connected to the above-mentioned memory and the above-mentioned network interface. Among them, the above-mentioned network interface is used to provide a data communication network element, the above-mentioned memory is used to store a computer program, and the above-mentioned processor is used to call the above-mentioned computer program so that the network element device executes the method in the embodiment of the present application.

[0054] On the one hand, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is suitable for being loaded and executed by a processor to execute the method in the embodiment of the present application.

[0055] On the one hand, an embodiment of the present application provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the network element device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the network element device executes the method in the embodiment of the present application.

[0056] In an embodiment of the present application, the network element device may generate a data packet set based on the data packets in the buffer receiving queue in a working thread in the user space. Among them, the data packets in the same data packet set have the same packet format. It can be understood that if there are kernel data packets in the data packet set, the network element device may, in the working thread, divert the kernel data packets to the kernel space thread according to the access control rules, and perform transfer processing on the kernel data packets through the kernel space thread. If there are service data packets in the data packet set, the network element device may, in the working thread, divert the service data packets to one or more packet processing nodes in the working thread according to the access control rules, and perform transfer processing on the service data packets through the one or more packet processing nodes. Thus, it can be seen that the network element device can directly encapsulate the received multiple data packets into a data packet set in the working thread in the user space, and then perform transfer processing on the data packets in the data packet set at one time. It can be understood that since the data packets in the data packet set have the same packet format, when performing transfer processing on these data packets through the working thread, the cache hit rate of the instruction cache can be improved. In addition, the network element device in the embodiment of the present application can be compatible with both service data packets and kernel data packets at the same time, and implement transfer processing on service data packets in the user space, thereby reducing frequent context switching and mutual copying of data between the user space and the kernel space, and further improving the processing ability of the network element device for data packets. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0058] Figure 1 is a schematic structural diagram of a network architecture provided by an embodiment of the present application;

[0059] Figure 2 is a schematic diagram of a scenario for data interaction provided by an embodiment of the present application;

[0060] Figure 3 is a schematic flowchart of a data processing method provided by an embodiment of the present application;

[0061] Figure 4 is a schematic flowchart of a packet processing process provided by an embodiment of the present application;

[0062] Figure 5 is a schematic flowchart of a data processing method provided by an embodiment of the present application;

[0063] Figure 6 It is a schematic flowchart of a data processing method provided by an embodiment of the present application;

[0064] Figure 7 It is a schematic structural diagram of a message processing provided by an embodiment of the present application;

[0065] Figure 8a It is a schematic flowchart of a user-mode message pipeline processing provided by an embodiment of the present application;

[0066] Figure 8b It is a schematic flowchart of a user-mode message pipeline processing provided by an embodiment of the present application;

[0067] Figure 9 It is a schematic structural diagram of a data processing device provided by an embodiment of the present application;

[0068] Figure 10 It is a schematic structural diagram of a network element device provided by an embodiment of the present application. Detailed implementation manners

[0069] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0070] Specifically, please refer to Figure 1 , Figure 1 It is a schematic structural diagram of a network architecture provided by an embodiment of the present application. As Figure 1 shown, the network architecture may include an application server cluster, a base station 4000a, a gateway 4000b, and a user equipment cluster. Among them, the application server cluster may specifically include one or more application servers, and the number of application servers in the application server cluster will not be limited here. As Figure 1 shown, the multiple application servers may specifically include application server 2000a, application server 2000b,..., application server 2000n. The application server 2000a, application server 2000b,..., application server 2000n may be respectively connected to the gateway 4000b through dedicated lines, so that each application server can perform data interaction with the gateway 4000b through the dedicated line connection.

[0071] It can be understood that the application servers in the application server cluster can be independent physical servers, or server clusters or distributed systems composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud databases, cloud services, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0072] It can be understood that the above network architecture can be applied to business scenarios that support edge computing (i.e., Mobile Edge Computing, abbreviated as MEC). The application servers in the above application server cluster can be edge application servers in edge computing. Edge computing refers to a platform that integrates network, computing, storage, and application core capabilities on the network edge side close to things or data sources, providing edge intelligent services nearby to meet the key needs of industry digitization in aspects such as agile connection, real-time services, data optimization, application intelligence, security, and privacy protection. Edge computing enables operators and third-party services to be hosted close to the access points of terminal devices, thereby achieving efficient service delivery by reducing the end-to-end latency and load on the transmission network.

[0073] It can be understood that the above network architecture can be applied to the fifth-generation mobile communication technology (5th Generation Mobile Networks, abbreviated as 5G). 5G is a new generation of broadband mobile communication technology with the characteristics of high speed, low latency, and large connection, and is the network infrastructure for realizing the interconnection of humans, machines, and things. In the application scenarios of 5G, the peak rate of 5G services usually exceeds 10 Gbps, and the bandwidth requirement is as high as dozens of Gbps. Therefore, it will cause huge pressure on the wireless mid-haul and backhaul mobile networks. Therefore, the 5G service demand needs to sink the services as much as possible to the network edge to achieve local traffic splitting of the services and reduce the network latency caused by network transmission and multi-level service forwarding.

[0074] Among them, the user equipment cluster can specifically include one or more user equipment (User Equipment, abbreviated as UE), and the number of user equipment in the user equipment cluster will not be limited here. As Figure 1 shown, multiple user equipment can specifically include user equipment 3000a, user equipment 3000b,..., user equipment 3000m. User equipment 3000a, user equipment 3000b,..., user equipment 3000m can respectively communicate with base station 4000a through 5G transmission methods, so that each user equipment can perform data interaction with base station 4000a through this communication connection.

[0075] It can be understood that the user devices in the user device cluster may include terminal application products in the fields of civilian, commercial, industrial, military, etc., such as smart phones, tablet computers, laptop computers, palmtop computers, mobile internet devices (MIDs), wearable devices (such as smart watches, smart bracelets, etc.), smart computers, intelligent vehicles, smart homes, drones, ATMs, cameras, traffic lights, generators, or various types of sensors, etc. It should be understood that, as Figure 1 shown, each user device in the user device cluster can be integrally installed with an application client (i.e., an application program). When the application client runs on each user device, it can perform data interaction with the application servers in the application server cluster shown above Figure 1 through the base station 4000a and the gateway 4000b respectively. Among them, the application client can specifically include: vehicle-mounted client, smart home client, entertainment client (e.g., game client), multimedia client (e.g., video client), social client, and information client (e.g., news client), etc.

[0076] Among them, the number of base stations corresponding to the base station 4000a can be multiple. The multiple base stations can be responsible for the access and management of user devices on the wireless side. Different user devices can correspond to different base stations, and different user devices can also correspond to the same base station. Here, the base station corresponding to each user device is not limited. In the embodiments of the present application, it is taken as an example that the base station corresponding to each user device is the base station 4000a for illustration.

[0077] Among them, the gateway 4000b can be a core network element in the 5G Core (which can be abbreviated as 5GC) (the "network element" can also be called the "network function"). Here, the gateway 4000b can be the UPF (User Plane Function) in the core network element. The 5G UPF can be responsible for data routing and forwarding of the control plane (i.e., the control plane, Control Plane, abbreviated as CP) and the user plane (i.e., the data plane, Data Plane, abbreviated as DP), and is interconnected with an external data network (Data Network), for example, operator services, the Internet, or third-party services, etc. It can be understood that an internal network connection can be realized between the gateway 4000b and the base station 4000a (i.e., the gateway 4000b and the base station 4000a can perform network connection within the same local area network).

[0078] It can be understood that the base station 4000a can establish a "control plane" connection (i.e., the control plane) between the user equipment (e.g., the user equipment 3000a) and the gateway 4000b. This control plane can be used to forward signaling messages (i.e., control instructions in the communication system) between the two, and these signaling messages include mobile phone authentication, registration, mobility management, etc.; the base station can establish a "user plane" connection (i.e., the data plane) between the user equipment 3000a and the gateway 4000b, and this data plane can be used to forward the user's data traffic between the two. Among them, the control plane and the user plane are completely separated, and the gateway 4000b can be distributedly deployed closer to the user side together with edge computing, so as to reduce network latency.

[0079] Among them, the control plane can be used to transmit service packets (i.e., service data packets), and the data plane can be used to transmit kernel packets (i.e., kernel data packets) and some service data packets. For example, some of the service data packets here can be ping packets for health monitoring. Among them, the service data packets can be the above-mentioned signaling messages and some data traffic, and the kernel data packets can be other data traffic except some data traffic.

[0080] It should be understood that in the 5G network, assuming that a certain user equipment (e.g., the user equipment 3000a) hopes to access a data network outside the mobile communication network, this user equipment 3000a can initiate an access request, forward the access request to the base station 4000a, and the base station 4000a can forward the service flow requested by the user equipment 3000a to the core network element UPF in the 5G core network. After being forwarded by the core network element UPF, it is sent to the external data network.

[0081] Among them, in order to obtain more efficient service delivery, edge computing can be used to meet different service requirements. It should be noted that in the edge computing scenario, an application service may be composed of multiple edge application servers usually deployed at different sites (e.g., Figure 1The application servers shown (i.e., application server 2000a, application server 2000b, …, application server 2000n) provide services. To route the traffic flow of a certain application client (e.g., application client Y) to the edge application server, the terminal device needs to know the IP address (Internet Protocol Address) of the edge application server that provides services for the application client Y. The user device can discover the IP address of a suitable edge application server (e.g., the edge application server closest to the user device (e.g., application server 2000a)) so that the traffic can be routed by the core network element UPF to this edge application server, and the service latency, traffic routing path, and user service experience can be optimized. Based on this, edge application server discovery is a process in which the user device uses the Domain Name System to find the IP address of a suitable edge application server. Among them, the Domain Name System (DNS, Domain Name Server) is a service on the Internet. As a distributed database that maps domain names and IP addresses to each other, it enables users to access the Internet more conveniently.

[0082] It should be understood that with the continuous development of communication technologies, many previously non-existent requirements have emerged. For scenarios such as old urban areas where construction and wiring are inconvenient and network quality is required, museums, and remote control of robots in mines, 5G cloudification is a good solution. By accessing 5G on the terminal side and the dedicated line capabilities of the cloud, the network quality and transmission rate can be significantly improved, meeting the network requirements of low latency and high reliability for services. Among them, 5G cloudification means that the user device can upload local data to the application server in the cloud through the 5G network, or the user device can download the previously uploaded local data from the application server in the cloud through the 5G network.

[0083] Among them, if the processing capacity of the 5G core network UPF is insufficient, it will lead to packet loss, a large delay, and affect the stable operation of the service. Therefore, the main product that 5G cloudification solves is to enable the 5G core network UPF to quickly process data packets, meet the 5G peak transmission rate of 10 - 20 Gbit / s, and the latency characteristic of 1 ms (i.e., 1 millisecond) for the air interface (i.e., the interface between the wireless network (i.e., the base station) and the user device).

[0084] It should be understood that the 5G core network UPF is mainly optimized in terms of the control plane and the data plane. The control plane can be used to transmit service data packets, and the data plane can be used to transmit service data packets and kernel data packets. Among them, the optimized UPF in the embodiments of the present application enables service data packets to be processed in the user space, that is, the service data packets are transferred and processed by working threads (i.e., user-space threads) in the user space; the optimized UPF is also compatible to enable kernel data packets to be processed in the kernel space, that is, the kernel data packets are transferred and processed by kernel-space threads.

[0085] It should be understood that the working threads in the 5G core network UPF can be user-space threads or kernel-space threads. In the embodiments of the present application, the case where the working threads are user-space threads is taken as an example for illustration.

[0086] For ease of understanding, further, please refer to Figure 2 , Figure 2 which is a schematic diagram of a scenario for data interaction provided by the embodiments of the present application. As Figure 2 shown, the user equipment 20a can be any one of the user equipment clusters in the corresponding embodiments above, such as Figure 1 shown, the application server 20c can be any one of the application server clusters in the corresponding embodiments above, such as Figure 2 shown, the gateway 20b can be the gateway 4000b in the corresponding embodiments above. For ease of understanding, in the embodiments of the present application, the user equipment 3000a shown above is used as the user equipment 20a, and the application server 2000a shown above is used as the application server 20c, for example, to elaborate Figure 1 shown, the specific process of data interaction among the user equipment 20a, the gateway 20b, and the application server 20c. Figure 2 shown, the gateway 20b can be the gateway 4000b in the corresponding embodiments above. For ease of understanding, in the embodiments of the present application, the user equipment 3000a shown above is used as the user equipment 20a, and the application server 2000a shown above is used as the application server 20c, for example, to elaborate Figure 1 shown, the specific process of data interaction among the user equipment 20a, the gateway 20b, and the application server 20c. Figure 1 shown, the user equipment 3000a is used as the user equipment 20a, and the application server 2000a shown above is used as the application server 20c, for example, to elaborate Figure 1 shown, the specific process of data interaction among the user equipment 20a, the gateway 20b, and the application server 20c. Figure 2 shown, the specific process of data interaction among the user equipment 20a, the gateway 20b, and the application server 20c.

[0087] It can be understood that the user corresponding to the user equipment 20a can be the object 20d; an application client (for example, application client Y) is integrated and installed on the user equipment 20a, and a working thread 21a corresponding to the application client Y runs on the gateway 20b; data communication can be carried out between the user equipment 20a and the gateway 20b through a base station (for example, Figure 1 the base station 4000a in the corresponding embodiments above). Among them, the gateway 20b includes multiple working threads (i.e., user-space threads) running in the user space, and the multiple user-space threads can include Figure 2 the working thread 21a shown.

[0088] It can be understood that, as Figure 2As shown, the object 20d can send a data packet to the gateway 20b through the application client Y in the user device 20a. In this way, the base station 4000a can forward the data packet sent by the application client Y in the user device 20a to the gateway 20b. Therefore, the gateway 20b can receive the data packet sent by the user device 20a through the base station 4000a, and then parse and perform other processing on the data packet to obtain a processed data packet, and then send the processed data packet to the application server 20c.

[0089] As Figure 2 shown, the working thread 21a may include a buffer receiving queue 21b. When the gateway 20b performs data packet transfer processing, it can first load the data packet into the buffer receiving queue 21b of the working thread 21a. Among them, the buffer receiving queue 21b may include multiple data packets. The multiple data packets may specifically include k data packets. Here, k may be a positive integer. The k data packets may specifically include data packet 22a, data packet 22b, data packet 22c, data packet 22d,..., data packet 22k. Among them, the data packet 22a may be Figure 2 the data packet sent by the user device 20a as shown.

[0090] As Figure 2 shown, in the working thread 21a, the working thread 21a can obtain data packets with the same packet format from the buffer receiving queue 21b, and generate a data packet set (for example, data packet set 21c) based on the data packets with the same packet format. For example, the data packets with the same packet format in the buffer receiving queue 21b may be data packet 22a, data packet 22b, data packet 22c, and data packet 22d. Therefore, the data packet set 21c may include data packet 22a, data packet 22b, data packet 22c, and data packet 22d, that is, the working thread 21a can generate the data packet set 21c based on data packet 22a, data packet 22b, data packet 22c, and data packet 22d.

[0091] Furthermore, the working thread 21a can identify the packet execution types of the data packets in the data packet set 21c according to the access control rules. For example, the packet execution types of data packet 22a and data packet 22b may be kernel execution types, and the packet execution types of data packet 22c and data packet 22d may be service execution types. Among them, the data packets corresponding to the kernel execution type are kernel data packets, and the data packets corresponding to the service execution type are service data packets. Therefore, data packet 22a and data packet 22b may be kernel data packets, and data packet 22c and data packet 22d may be service data packets.

[0092] As Figure 2 shown, the working thread 21a can split the kernel data packets in the data packet set 21c to the kernel-mode threads according to the access control rules, that is, the working thread 21a can split the data packet 22a and the data packet 22b to the kernel-mode threads, so as to perform transfer processing on the data packet 22a and the data packet 22b respectively through the kernel-mode threads, and obtain the processed data packet 22a (i.e., the processed data packet 23a) and the processed data packet 22b (i.e., the processed data packet 23b).

[0093] As Figure 2 shown, the working thread 21a can split the service data packets in the data packet set 21c to the packet processing nodes in the working thread 21a according to the access control rules, that is, the working thread 21a can split the data packet 22c and the data packet 22d to the packet processing nodes, so as to perform transfer processing on the data packet 22c and the data packet 22d respectively through the packet processing nodes, and obtain the processed data packet 22c (i.e., the processed data packet 23c) and the processed data packet 22d (i.e., the processed data packet 23d). The number of packet processing nodes can be one or more, and the number of packet processing nodes is not limited here.

[0094] Therefore, the gateway 20b can forward the above-mentioned processed data packet 22a (i.e., the processed data packet 23a) to the application server 20c, so that the application server 20c can receive the processed data packet 23a forwarded by the user device 20a through the gateway 20b.

[0095] Optionally, the object 20d can also request to obtain data packets from the application server 20c through the application client Y in the user device 20a. In this way, the application server 20c can send data packets to the gateway 20b, so that the base station can forward the data packets obtained by the gateway 20b to the application client Y in the user device 20a. The gateway 20b can receive the data packets sent by the application server 20c, and then perform transfer processing on the data packets to obtain the processed data packets, and then send the processed data packets to the user device 20a through the base station.

[0096] It can be seen that the embodiments of the present application can obtain a batch of data packets (i.e., the data packets in the data packet set) from the buffer receiving queue corresponding to the working thread in the user state, and then perform concurrent processing on this batch of data packets. It can be understood that the network element device can be compatible with kernel data packets and service data packets at the same time. Therefore, this batch of data packets can include kernel data packets and service data packets. For data packets with different packet execution types, they can be transferred to different pipelines for processing. Among them, the kernel data packets can be transferred and processed through kernel state threads, and the service data packets can be transferred and processed through the above-mentioned working threads (i.e., user state threads). Therefore, the embodiments of the present application can realize the transfer and processing of the data packets in the data packet set in the user state, thereby improving the processing ability of the network element device for data packets.

[0097] Further, please refer to Figure 3 , Figure 3 which is a schematic flowchart of a data processing method provided by the embodiments of the present application. This method can be executed by a network element device, and the network element device can be a user plane function network element (i.e., the core network network element UPF), and the core network network element UPF can be the gateway 4000b corresponding to the above Figure 1 in the corresponding implementation. Among them, this data processing method can include the following steps S101 - step S103:

[0098] Step S101, in the working thread in the user state, generate a data packet set based on the data packets in the buffer receiving queue;

[0099] Specifically, the user plane function network element can poll the buffer receiving queue corresponding to the working thread in the working thread in the user state (i.e., the user state thread), and identify the packet format of the data packets obtained by polling. Among them, the packet format includes the target packet format. Further, if the number of data packets with the target packet format is greater than or equal to the number threshold, the user plane function network element can generate a data packet set corresponding to the target packet format based on the data packets with the target packet format. Among them, the data packets in the same data packet set have the same packet format.

[0100] It can be understood that the user plane function network element can include multiple user state threads (i.e., multiple working threads). The embodiments of the present application do not limit the number of user state threads in the user plane function network element. Here, any one of the multiple user state threads (for example, user state thread X) is taken as an example for illustration. Among them, each user state thread in the multiple user state threads corresponds to a buffer receiving queue. For example, the buffer receiving queue corresponding to user state thread X can be buffer receiving queue D.

[0101] Among them, it can be understood that the user-mode thread X can periodically poll the buffer receiving queue D according to the time slice size. For example, the user-mode thread X can identify the packet format of the data packet in the buffer receiving queue D at time T1, and the user-mode thread X can also identify the packet format of the data packet in the buffer receiving queue D at time T2. Here, time T2 can be the next moment of time T1, and the time interval between time T1 and time T2 is the size of a time slice. Among them, the data packets corresponding to the buffer receiving queue D at time T1 and time T2 are not necessarily the same, that is, the data packets polled by the user-mode thread X at time T1 and time T2 are not necessarily the same.

[0102] Among them, the packet format of the data packet can be the IPv4 (Internet Protocol Version 4) packet format, or the IPV6 (Internet Protocol Version 6) packet format, or the ARP (Address Resolution Protocal) packet format, or the MPLS (Multi-Protocol Label Switching) packet format, or the LLC (Local Link Control) packet format. It should be understood that the embodiments of the present application do not limit the number of packet formats.

[0103] It can be understood that the packet format can include a first packet format and a second packet format. The user plane function network element can count the number of packets (for example, the first packet number) of the data packet with the first packet format, and count the number of packets (for example, the second packet number) of the data packet with the second packet format. For example, here the first packet format can be the IPv4 packet format, and here the second packet format can be the IPV6 packet format. Among them, if in the buffer receiving queue, the first packet number is greater than or equal to the number threshold, then the first packet format (that is, the IPv4 packet format) is the target packet format; if in the buffer receiving queue, the second packet number is greater than or equal to the number threshold, then the second packet format (that is, the IPV6 packet format) is the target packet format. It should be understood that the embodiments of the present application do not limit the specific value of the number threshold.

[0104] Optionally, if the number of data packets with the first packet format and the number of data packets with the second packet format in the data packets polled by the working thread at a certain moment are both greater than or equal to the quantity threshold, the user plane function network element may respectively use both the first packet format and the second packet format as the target packet format, and then generate a data packet set corresponding to the first packet format (for example, data packet set J1) based on the data packets with the first packet format, and generate a data packet set corresponding to the second packet format (for example, data packet set J2) based on the data packets with the second packet format. Among them, the data packets in the data packet set J1 have the first packet format, and the data packets in the data packet set J2 have the second packet format.

[0105] Optionally, if the number of data packets polled by the working thread at a certain moment is greater than the maximum number included in the data packet set, the working thread may generate two or more data packet sets based on the polled data packets. For example, if the number of data packets with the same packet format polled by the working thread at a certain moment is 300, and the maximum number included in the data packet set is 256, the working thread may generate two data packet sets based on the 300 data packets with the same packet format.

[0106] Optionally, if in the data packets polled at a certain moment, the number of data packets without a certain packet format is greater than or equal to the quantity threshold (that is, the number of data packets corresponding to all packet formats is less than the quantity threshold), the user plane function network element may ignore this poll, without generating a data packet set, and at the next poll, count the packet formats of the polled data packets.

[0107] It should be understood that the data packet set in the embodiments of the present application can implement batch processing of data packets. This batch processing method of packets can form a packet set (i.e., a data packet set) from a group of packets received by a batch of underlying hardware queues (i.e., buffer receive queues), and after the packet set is assembled, it is sent as a whole to the packet processing graph (i.e., a flow graph) in the user space for transfer. This can reduce the number of cache misses to increase the forwarding throughput, and thus can improve the utilization rate of the CPU cache.

[0108] Among them, the message processing graph may include multiple graph nodes. The graph nodes can decompose the entire processing flow into successive service nodes. The data message can flow through the connection lines in the message processing graph. The message set is processed by the task of the first graph node (i.e., the pipeline Input node (i.e., the Ethernet input node)), and then is processed by the tasks of the second graph node in sequence according to the type, and so on. It can be understood that new graph nodes can be introduced into the message processing graph in the form of plugins (i.e., Plugins), or the graph nodes in the message processing graph can be rearranged. When adding the plugin to the plugin directory, the plugin will be automatically loaded when the program runs.

[0109] Among them, the plugin mechanism enables developers to make full use of existing modules and quickly develop new functions. In fact, the essence of the plugin is a graph node that implements a specific function, and this graph node can be inserted into any position in the message processing graph.

[0110] For ease of understanding, for the specific process of the message set flowing through the graph nodes in the message processing graph, reference can be made to Figure 4 , Figure 4 which is a schematic flow diagram of message processing provided by an embodiment of the present application. As Figure 4 shown, the message processing graph may include multiple graph nodes (for example, 10 graph nodes). These 10 graph nodes can be node G1 (i.e., Ethernet-input), node G2 (i.e., MPLS-Ethernet-input), node G3 (i.e., Ip6-input), node G4 (i.e., Ip4-input), node G5 (i.e., Arp-input), node G6 (i.e., llc-input), node G7 (i.e., Ip6-lookup), node G8 (i.e., Ip6-rewrite-transmit), node G9 (i.e., Ip6-local), and node G 10 (i.e., Plugin-node(s)). Among them, node G1 is the first graph node in the message processing graph; node G2, node G3, node G4, node G5, or node G6 is the second graph node in the message processing graph; node G7 is the third graph node in the message processing graph; node G8 and node G9 are the fourth graph nodes in the message processing graph.

[0111] As Figure 4The shown data packet processing diagram (i.e., message processing diagram) can decompose the processing pipeline of data packets into one or more nodes. This modular approach means that anyone can insert new diagram nodes into the data packet processing diagram. The packet processing diagram is applied to the entire packet vector (i.e., the set of data messages) node by node (including plugins). When the network represented by each diagram node is applied to each data packet in turn, the received data packets usually traverse the packet processing diagram nodes in the vector. Among them, node G 10 means that nodes can be added or deleted in the message processing diagram. Among them, data messages are assembled from data packets. When the data message is short, the data message is the data packet.

[0112] Such as Figure 4 the shown set of data messages 40a may include multiple data messages. The multiple data messages can be M data messages. Here, M can be a positive integer. The specific M data messages can specifically include data message B1, data message B2,..., data message B M . Among them, data message B1, data message B2,..., data message B M have the same message format.

[0113] It should be understood that before the working thread transfers the data messages in the set of data messages, it can determine whether there are kernel data messages and service data messages in the set of data messages, and then can determine the execution path of the data messages in the set of data messages. For example, if there are kernel data messages in the set of data messages, the kernel data messages can be executed in the following step S102; if there are service data messages in the set of data messages, the service data messages can be executed in the following step S103. Among them, the specific process of the working thread determining whether there are kernel data messages and service data messages in the set of data messages can be referred to the description of the corresponding embodiment below Figure 5 corresponding embodiment.

[0114] Step S102, if there are kernel data messages in the set of data messages, then in the working thread, according to the access control rules, the kernel data messages are split to the kernel-mode thread, and the kernel-mode thread performs transfer processing on the kernel data messages;

[0115] It can be understood that when the kernel-mode thread performs transfer processing on the kernel data messages, it can parse and encapsulate the data messages layer by layer according to the network communication model (for example, OSI (Open System Interconnection Reference Model, Open System Interconnection Communication Reference Model)).

[0116] Optionally, if there is no kernel data packet in the data packet set, all data packets in the data packet set can be processed by step S103. Here, all the data packets are service data packets.

[0117] Step S103: If there is a service data packet in the data packet set, in the working thread, the service data packet is split to one or more packet processing nodes in the working thread according to the access control rule, and the service data packet is processed by the one or more packet processing nodes.

[0118] Specifically, if there is a service data packet in the data packet set, the user plane function network element can split the service data packet to the route matching node in the working thread according to the access control rule. Here, the one or more packet processing nodes include the route matching node. Further, the user plane function network element can perform route matching on the destination address carried in the service data packet through the route matching node to obtain the route data packet corresponding to the service data packet. Further, the user plane function network element can perform packet protocol parsing on the route data packet.

[0119] It can be understood that the destination address (i.e., the destination IP address) to which the service data packet is to be sent can be obtained from the service data packet. The route matching node can query the routing table and route the service data packet to the network element device corresponding to the destination address according to the destination address. When the user device sends a data packet to the application server, the network element device here can be the application server; when the application server sends a data packet to the user device, the network element device here can be the user device. It should be understood that the embodiments of the present application do not limit the specific process of performing route matching through the route matching node.

[0120] Here, the one or more packet processing nodes may further include a first packet parsing node and a second packet parsing node. It should be understood that the specific process of the user plane function network element performing packet protocol parsing on the route data packet can be described as: the user plane function network element can identify the packet protocol type associated with the route data packet. Further, if the packet protocol type is the generic routing encapsulation protocol type, the user plane function network element can send the route data packet to the first packet parsing node to perform packet protocol parsing on the route data packet through the first packet parsing node. Optionally, if the packet protocol type is the virtual extensible local area network protocol type, the user plane function network element can send the route data packet to the second packet parsing node to perform packet protocol parsing on the route data packet through the second packet parsing node.

[0121] It can be understood that when the packet format of the data packets in the data packet set is the IPv4 packet format, the first packet parsing node can be a gre4-encap node, and the second packet parsing node can be a vxlan4-encap node. Optionally, when the packet format of the data packets in the data packet set is the IPv6 packet format, the first packet parsing node can be a gre6-encap node, and the second packet parsing node can be a vxlan6-encap node. Herein, encap represents unpacking and repacking, which can be used to parse data packets.

[0122] Among them, the generic routing encapsulation protocol type is the packet protocol type corresponding to the Generic Routing Encapsulation (GRE) protocol, and the virtual extensible local area network protocol type is the packet protocol type corresponding to the Virtual eXtensible Local Area Network (vxlan) protocol. It can be understood that the first packet parsing node can perform packet protocol parsing on the routing data packet based on the generic routing encapsulation protocol; the second packet parsing node can perform packet protocol parsing on the routing data packet based on the virtual extensible local area network protocol.

[0123] Among them, one or more packet processing nodes can also include a policy node and a tunnel processing node. It should be understood that after the user plane function network element performs packet protocol parsing on the routing data packet, it can obtain the parsed data packet obtained through the packet protocol parsing, send the parsed data packet to the policy node, perform policy control on the parsed data packet through the policy node, and obtain the parsed data packet after policy control. Further, the user plane function network element can send the parsed data packet after policy control to the tunnel processing node, perform tunnel processing on the parsed data packet after policy control through the tunnel processing node, and obtain the encrypted data packet. Further, the user plane function network element can send the encrypted data packet to the network card sending queue corresponding to the network card component.

[0124] It can be understood that the policy control can be speed limiting. At this time, the policy node can be used to limit the speed of the parsed data packet, and the parsed data packet after policy control can be understood as the parsed data packet after speed limiting.

[0125] It can be understood that the tunnel processing can be encryption processing. At this time, the tunnel processing node can be used to establish an encryption tunnel, perform encryption processing on the parsed data packet after policy control through the encryption tunnel, and obtain the data packet after encryption processing (i.e., the encrypted data packet), thereby ensuring the integrity and privacy of the data packet transmission.

[0126] It should be understood that the specific process of the user plane function network element sending the encrypted data packet to the network card sending queue corresponding to the network card component can be described as follows: The user plane function network element can add the encrypted data packet to the buffer sending queue corresponding to the working thread through the tunnel processing node. Further, the user plane function network element can obtain the encrypted data packet in the buffer sending queue through the network card component (i.e., the network card device), and store the encrypted data packet obtained by the network card component into the network card sending queue corresponding to the network card component.

[0127] It can be understood that each user state thread in multiple user state threads (i.e., working threads) of the user plane function network element corresponds to a buffer sending queue. For example, the buffer sending queue corresponding to the user state thread X can be the buffer sending queue L.

[0128] Optionally, if there is no service data packet in the data packet set, the flow processing can be performed on all the data packets in the data packet set through step S102. Here, all the data packets are kernel data packets.

[0129] It can be seen that the network element device in the embodiment of the present application can directly encapsulate multiple received data packets into a data packet set in the working thread in the user state, and then perform flow processing on the data packets in the data packet set at one time. It can be understood that since the data packets in the data packet set have the same packet format, when performing flow processing on these data packets through the working thread, the cache hit rate of the instruction cache can be improved. In addition, the network element device in the embodiment of the present application can be compatible with both service data packets and kernel data packets at the same time, and implement the flow processing of service data packets in the user state, thereby reducing the frequent context switching and the mutual copying of data between the user state and the kernel state, and further improving the processing ability of the network element device for data packets.

[0130] Further, please refer to Figure 5 , Figure 5 which is a schematic flow chart of a data processing method provided by an embodiment of the present application. This method can be executed by a network element device, and the network element device can be a user plane function network element (i.e., the core network network element UPF), and the core network network element UPF can be the gateway 4000b corresponding to the above Figure 1 corresponding implementation. Among them, this data processing method can include the following steps S201-step S203:

[0131] Step S201, sending the data packet set to the access control node in the working thread, and in the access control node, matching the data packets in the data packet set based on the access control list;

[0132] Specifically, the user plane function network element can load the data packets in the data packet set into the data cache, and sequentially perform packet detection on the data packets in the data packet set in the data cache. Further, if the packet detection finds that there are data packets with successful verification in the data packet set, the user plane function network element can send the data packets with successful verification to the access control node in the working thread.

[0133] It can be understood that the working thread may include an Ethernet input node, which can poll the buffer receiving queue corresponding to the working thread to generate a data packet set corresponding to different packet formats (for example, a data packet set corresponding to the target packet format). Further, the Ethernet input node can transfer the data packet set to different packet input nodes in the working thread according to the packet format of the data packets in the data packet set. In this way, after obtaining the data packet set, the packet input node can load the data packets in the data packet set into the data cache at one time.

[0134] It can be understood that different packet formats can correspond to different packet input nodes. For ease of understanding, please refer to Figure 4 , such as Figure 4 shown, node G2 can be the packet input node corresponding to the MPLS packet format, node G3 can be the packet input node corresponding to the IPV6 packet format, node G4 can be the packet input node corresponding to the IPv4 packet format, node G5 can be the packet input node corresponding to the ARP packet format, and node G6 can be the packet input node corresponding to the LLC packet format.

[0135] It should be understood that the specific process of the user plane function network element sequentially performing packet detection on the data packets in the data packet set in the data cache can be described as: the user plane function network element can load the data packets in the data packet set into the data cache, and obtain the data packet Si of the data packet set from the data cache i . Wherein, i here can be a positive integer less than or equal to the number of packets in the data packet set. Further, the user plane function network element can obtain the packet processing instruction corresponding to the data packet Si i , load the packet processing instruction into the instruction cache, and perform packet detection on the data packet Si through the packet processing instruction in the instruction cache i . Further, the user plane function network element can obtain the data packet Si+1 of the data packet set from the data cache i+1 , obtain the packet processing instruction from the instruction cache, and perform packet detection on the data packet Si+1 through the packet processing instruction i+1 .

[0136] It is understandable that when the packet input node is scheduled, it can use the Dual-Loop and prefetch packet method to process packets in the CPU cache. Among them, the Dual-Loop and prefetch packet method can add the data packet set to the cache through the queue reading method, process the first data packet first, and then process the second data packet after processing the first data packet, and so on until the last data packet is processed.

[0137] Among them, the data packet S i+1 can be the data packet S i 's next data packet. For example, when the data packet S i is the first data packet, the data packet S i+1 can be the second data packet; and for another example, when the data packet S i is the second data packet, the data packet S i+1 can be the third data packet.

[0138] It is understandable that the packet processing instruction can be used to detect the data packet S i . Optionally, when the user plane function network element obtains the packet processing instruction, it can also obtain other processing instructions for processing the data packet S i at the same time, and perform packet detection and packet processing on the data packet S i through the other processing instructions and the packet processing instruction.

[0139] It is understandable that processing data packets in the form of a data packet set can be called the vector packet processing method. This vector packet processing method can actively utilize the temporal locality feature of the cache. If the instruction cache hits, all data packets in the data packet set will hit; otherwise, none of them will hit. When the instruction cache hits, the first data packet in the data packet set is used to warm up the instruction cache mirror and accelerate the cache for the subsequent data packets in the data packet set.

[0140] It should be understood that since the first data packet in the data packet set warms up the instruction cache, the processing performance of the remaining data packets in the data packet set can reach the limit. The fixed overhead of the missing instructions in the instruction cache is amortized over the entire data packet set, significantly reducing the processing overhead of a single data packet. Furthermore, it can solve the problem of instruction cache thrashing, improve the cache throughput, and the data packet set can alleviate the read latency problem, with high performance and greater stability.

[0141] Optionally, if the packet detects that there is a data packet with a verification failure in the data packet set, the user plane function network element can transfer the data packet with the verification failure to the failure processing node (i.e., the Error-drop node).

[0142] It can be understood that the access control rules include the kernel message matching rules and service message matching rules belonging to the Access Control List (ACL for short), that is, the access control list can include access control rules, and the access control rules can include the kernel message matching rules associated with kernel data messages and the service message matching rules associated with service data messages. Among them, the access control list ACL is a set composed of one or more rules. A rule refers to a judgment statement describing the message matching conditions, and these conditions can be the source address, source port, destination address, destination port, and transport layer protocol of the message, etc. Among them, the access control list is a packet filtering-based access control technology, which can filter the data packets on the interface according to the set conditions, allowing them to pass or be discarded. With the help of the access control list, the user's access to the network can be effectively controlled, thus ensuring network security to the greatest extent.

[0143] It should be understood that the working thread can match the data messages in the data message set with the access control rules in the access control list to determine whether there are kernel data messages and service data messages in the data message set. For example, if there is a data message in the data message set that matches the kernel message matching rule, the following step S202 can be executed; if there is a data message in the data message set that matches the service message matching rule, the following step S203 can be executed.

[0144] Step S202, if there is a data message in the data message set that matches the kernel message matching rule, it is determined that there is a kernel data message in the data message set;

[0145] It can be understood that the user plane function network element can use the data message that matches the kernel message matching rule as the kernel data message, that is, the kernel data message is the data message that matches the kernel message matching rule. Among them, the kernel message matching rule can be used to screen the kernel data message in the data message set.

[0146] Step S203, if there is a data message in the data message set that matches the service message matching rule, it is determined that there is a service data message in the data message set.

[0147] It can be understood that the user plane function network element can use the data message that matches the service message matching rule as the service data message, that is, the service data message is the data message that matches the service message matching rule. Among them, the service message matching rule can be used to screen the service data message in the data message set.

[0148] Optionally, if there are data packets in the data packet set that do not match either the kernel packet matching rule or the service packet matching rule, the user plane function network element can determine the unmatched data packets as illegal data packets (i.e., illegal data packets), and then discard the illegal data packets in the data packet set. Optionally, the access control list can also include an illegal access control rule. If there are data packets in the data packet set that match the illegal access control rule, the user plane function network element can determine the data packets that match the illegal access control rule as illegal data packets.

[0149] It can be seen that the embodiment of the present application can identify the packet execution type of the data packet through the packet matching rules in the access control list. Here, the packet matching rules can include the kernel packet matching rule and the service packet matching rule. Therefore, the data packets here can include the kernel data packets corresponding to the kernel packet matching rule and the service data packets corresponding to the service packet matching rule. It can be understood that data packets of different packet execution types can be subsequently diverted to different pipelines for processing, thereby improving the parsing and processing efficiency of the data packets.

[0150] Further, please refer to Figure 6 , Figure 6 which is a schematic flowchart of a data processing method provided by an embodiment of the present application. This method can be executed by a network element device, and the network element device can be a user plane function network element (i.e., the core network network element UPF), and the core network network element UPF can be the gateway 4000b corresponding to the above Figure 1 corresponding implementation. Among them, the data processing method can include the following steps S301 - step S310:

[0151] Step S301, obtain data packets through the network card component, and store the data packets obtained by the network card component into the network card receiving queue corresponding to the network card component;

[0152] Step S302, perform an interception interruption process on the data packets in the network card receiving queue through the network card component, and evenly distribute the data packets after the interception interruption process to the buffer receiving queue;

[0153] Specifically, the user plane function network element can perform an interception interruption process on the data packets in the network card receiving queue through the network card component, and generate a packet identifier for the data packets after the interception interruption process. The number of threads of the working threads is at least two, and each of the at least two working threads corresponds to a buffer receiving queue. Further, the user plane function network element can evenly distribute the data packets after the interception interruption process to the buffer receiving queues corresponding to the at least two working threads according to the packet identifier.

[0154] It can be understood that the packet identifier can be a hash identifier. The network card driver can generate a hash identifier (i.e., hash value) for each data packet. This hash value can be calculated through a quadruple (source IP address, source layer-4 port, destination IP address, destination layer-4 port), and then the place where the interrupt is processed distributes it to the corresponding CPU core (abbreviated as core). Among them, a certain buffer receiving queue of the working thread is assigned to a certain core, and all packets received from this buffer receiving queue should be processed on the specified core.

[0155] It can be understood that UIO (Userspace I / O) is an I / O technology running in the user space, and UIO can implement the interception and interrupt processing of data packets. In the Linux system, general driver devices run in the kernel space and can be called by application programs in the user space, while UIO can run a small part of the driver in the kernel space and implement the vast majority of the driver's functions in the user space.

[0156] Among them, the interception packet processing flow essentially exposes a file interface to the user space. Reading and writing to the file is equivalent to reading and writing to the device memory. In this way, packet reception is based on the polling method, avoiding the interrupt overhead. Since the operating system interrupt is forced to handle packets, it will frequently switch contexts and traverse the call stack, and the CPU cache is frequently scheduled in and out, resulting in the CPU being unable to run other programs and having a large time overhead and high performance overhead. By using the polling mechanism, the continuity of the current packet processing will not be interrupted, and the packet processing tasks can be arranged by the application program according to the resource situation. Such a kernel bypass technology reduces a lot of interrupts and memory copies.

[0157] It can be understood that there can be multiple buffers in the memory of the user plane function network element. A group of queues are created in each buffer of the multiple buffers. Here, a group of queues can include a sending queue (i.e., buffer sending queue) and a receiving queue (i.e., buffer receiving queue), that is, one working thread corresponds to one buffer sending queue and one buffer receiving queue.

[0158] Among them, memory refers to the memory pool, buffer refers to the ring buffer, and queue refers to the cache queue. The memory pool consists of a ring buffer and a group of core-local cache queues. Each core allocates memory blocks from its own cache queue. When the local cache queue decreases to a certain extent, it can apply for memory blocks from the memory ring buffer to supplement the local queue.

[0159] It can be understood that the operating system can implement the scheduling of the CPU, running different working threads on different cores of the CPU. One or more working threads can run on one CPU core, and the appropriate number of working threads can improve the running efficiency of the CPU. Binding a certain working thread to a specific one or more cores for execution without being migrated to other cores. Once the working thread is bound to a certain CPU core, the thread will always run on the specified CPU core, and the operating system will not schedule it to other CPU cores, saving the performance consumption of scheduling and thus improving the execution efficiency of the program. It should be understood that the embodiments of the present application do not limit the number of working threads.

[0160] It should be understood that for a complete TCP connection, the interruption occurs on one CPU core (for example, CPU1), but the application data processing may occur on another core (for example, CPU2). Different CPU cores for processing bring lock competition, frequent context switching, and the CPU cache cannot be immediately hit, which will lead to latency and packet loss.

[0161] For ease of understanding, please refer to Figure 7 , Figure 7 which is a schematic structural diagram for message processing provided by the embodiments of the present application. The user space can include multiple application programs. For example, Figure 7 the 4 application programs shown. Among them, different application programs can be used to process data messages associated with different application clients. As Figure 7 shown, the software and hardware environment abstraction layer provides a general interface that shields the specific platform characteristics for the application program, hiding the relevant details of dealing with the underlying libraries and devices.

[0162] As Figure 7 shown, the network tool library can include queue management, message flow transfer, and polling management. Optionally, the network tool library can also include network protocol tools. Among them, queue management can manage the queue corresponding to each working thread. For example, dynamically expand and contract the queue, queue recycling, etc.; message flow transfer can control the processing flow of messages in the user space. For example, change the processing status of the message; polling management can control the polling of the working thread for messages. For example, control the working thread to assemble and package the messages in the queue every certain period of time; network protocol tools can perform protocol parsing. For example, parse the RIP protocol (Routing Information Protocol), OSPF (Open Shortest Path First) protocol, IP protocol (Internet Protocol), etc.

[0163] It can be understood that the Linux kernel can regard the above application as an ordinary user-mode process. This user-mode process can include a main thread and multiple worker threads. An application can be regarded as a process, which can include a main thread and multiple worker threads. The multiple worker threads can be used to poll the receive queue of the network card, and the main thread can be used to manage the multiple worker threads. The greatest advantage of this design is that it can be customized according to the business scenario, resulting in a significant improvement in performance. Among them, multiple applications can respectively correspond to multiple processes, and different processes can be used to process the data packets sent by different applications on the user equipment received by the user plane function network element.

[0164] As Figure 7 shown, the application runs in the user space, uses network protocol tools to process data packets, and intercepts interrupts through the UIO technology, bypassing the Linux kernel protocol stack for data packet processing. It can be understood that the process of directly processing data packets from the network card component to the kernel can include 9 steps, and these 9 steps can be: (1) Hardware interrupt, (2) Fetch the packet and distribute it to the kernel thread, (3) Software interrupt, (4) The kernel thread processes the packet in the protocol stack, (5) Notify the user layer after processing is completed, (6) The user layer receives the packet, (7) Network layer, (8) Logical layer, (9) Business layer. Among them, the network layer can convert the Ethernet data frame into an IP packet; the logical layer can implement logical address addressing and distribute it to different applications or different modules in the same application; the business layer can implement the business processing module.

[0165] It should be understood that in the embodiment of the present application, the process of the kernel for processing data packets is transferred to the user mode, and the data packets are processed through the user mode, so that the process of processing data packets can be reduced from 9 steps to 6 steps. These 6 steps can be: (1) Hardware interrupt, (2) Abandon the interrupt process, (3) User layer device mapping, (4) User layer protocol stack, (5) Logical layer, (6) Business layer. Among them, the hardware interrupt can indicate that when the network card receives a data packet, the UIO can intercept the hardware interrupt sent by the network card component to the CPU core; the abandon interrupt process can indicate that the network card component copies the data packet from the network card receive queue to the memory (or CPU cache) in the user space; the user layer device mapping can indicate that the interface corresponding to the data packet in the memory is used as a file interface, and the user space can perform operations such as parsing the data packet through the file interface; the user layer protocol stack can indicate that the application program in the application layer can parse the data packet; the logical layer and the business layer are business modules of specific applications, which can be used to verify whether the data packet has permissions and route it to which module for processing, etc.

[0166] As Figure 7The process shown bypasses the network driver module of the Linux kernel (i.e., the operating system kernel), directly reaching the user space from the hardware and the link, without the need for frequent memory copies and system calls. The UIO technology divides the device driver into two parts: the user space driver and the kernel space driver. The kernel space driver is mainly responsible for device resource allocation, UIO device registration, and a small part of the interrupt response function. Most of the work of the driver is completed under the driver program in the user space. Through the API interface (Application Programming Interface) provided by the UIO framework, the UIO driver is registered with the kernel. After the registration is completed, a mapping file containing information such as the physical address of the device is generated. When a user-state process accesses this file, the memory space address corresponding to the device is mapped to the user space, and the memory space of the device can be directly operated. The UIO technology enables the application program to directly operate the memory space of the device through the user space driver, avoiding multiple copies of data between the kernel buffer and the application buffer and improving the data processing efficiency.

[0167] Step S303, in the working thread in the user state, based on the data packets in the buffer reception queue, generate a data packet set;

[0168] It can be understood that the network card can evenly distribute the packets in the network card reception queue to the queue caches of different working threads. In this way, the working threads can poll their respective queue caches, analyze the types of the packets in their respective queue caches, obtain different packet execution types corresponding to the data packets, and then can pack the packets of different packet execution types into different packet sets.

[0169] Among them, for the specific process of the user plane function network element generating a data packet set based on the data packets in the buffer reception queue, reference can be made to the description of step S101 in the corresponding embodiment above, and details will not be repeated here. Figure 3 It should be understood that the user-state processing pipeline provided by the embodiments of the present application can be compatible with the transfer of both kernel data packets and service data packets at the same time. When the data packets belong to different packet execution types, the data packets can be transferred to different pipelines for transfer processing. Among them, the kernel data packets can execute the pipeline corresponding to step S304 below, and the service data packets can execute the pipeline corresponding to steps S305 - S310 below.

[0170] Step S304, if there are kernel data packets in the data packet set, then in the working thread, according to the access control rules, divert the kernel data packets to the kernel-state thread, and the kernel-state thread performs transfer processing on the kernel data packets;

[0171] For ease of understanding, please refer to

[0172] For ease of understanding, please refer toFigure 8a and Figure 8b , Figure 8a and Figure 8b are schematic flowcharts of a user-mode packet pipelining process provided by an embodiment of this application. As Figure 8a and Figure 8b shown, an application program may include a main thread and multiple worker threads. The multiple worker threads may be used to poll a buffered receive queue, and the main thread may be used to manage the multiple worker threads.

[0173] Among them, here, taking the number of worker threads as 3 as an example for illustration, the 3 worker threads may specifically include worker thread 50a, worker thread 50b, and worker thread 50c. For ease of understanding, an embodiment of this application takes worker thread 50a as an example to illustrate the processing flow of the user-mode packet pipeline. The processing flow of the user-mode packet pipeline in worker thread 50b and worker thread 50c may refer to the description of worker thread 50a.

[0174] As Figure 8a and Figure 8b shown, the network card receive queue and the network card transmit queue may respectively include N positions, and the N positions may be used to store N data packets. It can be understood that when the network card receive queue is full, the network card receive queue cannot receive data packets; when the network card transmit queue is empty, the network card transmit queue cannot send data packets. Among them, Figure 8a taking the packet format of the data packets in the data packet set as the IPv4 packet format as an example for illustration, Figure 8b taking the packet format of the data packets in the data packet set as the IPv6 packet format as an example for illustration. Among them, Figure 8a and Figure 8b shown nodes may be collectively referred to as packet processing nodes.

[0175] As Figure 8a shown, the Ethernet input node may be an ethernet-input node, the packet input node P0 may be an arp-input node, the packet input node P8 may be an ip6-input node, the routing matching node P6 may be an ip6-lookup node, the rewrite node P2 may be an ip6-rewrite node, the packet input node P7 may be an ip4-input node, the routing matching node P5 may be an ip4-lookup node, the rewrite node P1 may be an ip4-rewrite node, the local node P 11It can be an ip4 - local node. The first packet parsing node P3 can be a gre4 - encap node. The second packet parsing node P4 can be a vxlan4 - encap node. The first packet parsing node P9 can be a gre4 - input node. The second packet parsing node P 10 can be a vxlan4 - input node. The network splitter node can be a tap - inject node. The access control node can be an acl plugin node. The policy node can be a policer plugin node. The tunnel processing node can be an ipsecplugin node.

[0176] such as Figure 8b shown, the Ethernet input node can be an ethernet - input node. The packet input node P0 can be an arp - input node. The packet input node P8 can be an ip6 - input node. The routing match node P6 can be an ip6 - lookup node. The rewrite node P2 can be an ip6 - rewrite node. The packet input node P7 can be an ip4 - input node. The routing match node P5 can be an ip4 - lookup node. The rewrite node P1 can be an ip4 - rewrite node. The local node P 14 can be an ip6 - local node. The first packet parsing node P 12 can be a gre6 - encap node. The second packet parsing node P 13 can be a vxlan6 - encap node. The first packet parsing node P 15 can be a gre6 - input node. The second packet parsing node P 16 can be a vxlan6 - input node. The network splitter node can be a tap - inject node. The access control node can be an acl plugin node. The policy node can be a policer plugin node. The tunnel processing node can be an ipsecplugin node.

[0177] such as Figure 8a shown, in the kernel packet pipeline, after the network card receive queue receives a data packet, it can be forwarded to the IP4 node (i.e., the ip4 - input node, packet input node P7) through the Ethernet input node (i.e., the Ethernet node), and then distributed according to the ACL access control rules of the packet. If it is a legal packet, the data packet is sent to the Linux kernel through the tap port (i.e., the tap - inject node). Optionally, if it is illegal, the data packet is discarded.

[0178] such as Figure 8bAs shown in the figure, in the kernel message pipeline, after the network card receive queue receives a data message, it can be forwarded to the IP6 node (i.e., the ip6-input node, message input node P8) through the Ethernet input node (i.e., the Ethernet node), and then distributed according to the ACL access control rules of the message. If it is a legal message, the data message is sent to the Linux kernel through the tap port (i.e., the tap-inject node). Optionally, if it is illegal, the data message is discarded.

[0179] Among them, the tap port can be understood as the interface from the user space to the kernel space. After the kernel data message processes the data message, if it wants to send data, the kernel can directly send the data to the network card send queue without sending the data back to the user space through the tap port again.

[0180] Among them, for the specific process of the user plane function network element to transfer and process the kernel data message through the kernel state thread, reference can be made to the description of step S102 in the corresponding embodiment above. Figure 3 It will not be elaborated here.

[0181] Step S305, if there is a service data message in the data message set, in the working thread, the service data message is split to the routing matching node in the working thread according to the access control rules;

[0182] Step S306, the destination address carried by the service data message is routed and matched through the routing matching node to obtain the routing data message corresponding to the service data message;

[0183] Please refer to Figure 4 , Figure 4 Taking the execution path of node G3 as an example for illustration, after the data message in the data message set is loaded into the data cache at the message input node (i.e., node G3), the data message can be transmitted to the access control node (not shown in the figure), and then the data message is split to node G7 through the access control node. Further, after node G7 performs routing matching on the data message, it can transmit the routing data message to different message operation nodes to identify the message protocol type associated with the routing data message through the message operation nodes. Among them, the message operation nodes here can include Figure 4 Nodes G8 and G9 shown in the figure.

[0184] It can be understood that, as Figure 4 Nodes G8 and G9 shown in the figure represent different processing of the data message. Node G8 can represent rewrite and translation (i.e., no processing), and node G9 can represent discard and forward the data packet. Among them, translation is similar to passing a parameter in a function. The message is passed as an input parameter variable to the function so that the function knows the reference of this variable.

[0185] Among them, for the specific process of the user plane function network element performing routing matching through the routing matching node, reference can be made to the description of step S103 in the corresponding embodiment above. Figure 3 This will not be elaborated here.

[0186] Step S307: Parse the message protocol of the routing data message.

[0187] Among them, for the specific process of the user plane function network element parsing the message protocol of the routing data message, reference can be made to the description of step S103 in the corresponding embodiment above. Figure 3 This will not be elaborated here.

[0188] Step S308: Obtain the parsed data message obtained after message protocol parsing, send the parsed data message to the policy node, and perform policy control on the parsed data message through the policy node to obtain the parsed data message after policy control.

[0189] Step S309: Send the parsed data message after policy control to the tunnel processing node, and perform tunnel processing on the parsed data message after policy control through the tunnel processing node to obtain the encrypted data message.

[0190] Step S310: Send the encrypted data message to the network card sending queue corresponding to the network card component.

[0191] Specifically, the user plane function network element can add the encrypted data message to the buffer sending queue corresponding to the working thread through the tunnel processing node. Further, the user plane function network element can obtain the encrypted data message in the buffer sending queue through the network card component, and store the encrypted data message obtained by the network card component in the network card sending queue corresponding to the network card component.

[0192] For ease of understanding, please refer to Figure 8a In the service message pipeline, after the network card receiving queue receives the data message, it can be forwarded to the IP4 node (i.e., the ip4-input node, the message input node P7) through the Ethernet input node (i.e., the Ethernet node), and then distributed according to the message ACL access control rule. If it is a service data message, the service data message is transferred to the routing matching node (for example, the routing matching node P5) through the access control node (i.e., the ACL node).

[0193] Such as Figure 8aThe shown routing matching node P5 can look up the corresponding routing table, and through a packet operation node (e.g., rewrite node P1), after parsing the IP packet, it can find out whether the packet is for the GRE protocol or the Vxlan protocol, and distribute it to the corresponding service processing (e.g., the first packet parsing node P3). The processed packet is sent to the network card sending queue of the network card through the buffer sending queue, and then transmitted through the network to the remote end. Among them, the packet processed by the first packet parsing node P3 can also be sent to the policy node for policy control and the tunnel processing node for encrypted tunnel processing, and then the policy node and the tunnel processing node send the processed packet to the network card sending queue.

[0194] Optionally, the rewrite node P1 can also distribute the packet to the second packet parsing node P4 for service processing, and then through the policy node and the tunnel processing node, send the processed packet to the network card sending queue. Optionally, the routing matching node P5 can also pass the packet to the local node P 11 , so as to pass the packet through the local node P 11 to the first packet parsing node P9 or the second packet parsing node P 10 .

[0195] For easy understanding, please refer to Figure 8b again. In the service packet pipeline, after the network card receiving queue receives the data packet, it can be forwarded to the IP6 node (i.e., the ip6-input node, packet input node P8) through the Ethernet input node (i.e., the Ethernet node), and then distributed according to the ACL access control rules of the packet. If it is a service data packet, the service data packet is transferred to the routing matching node (e.g., routing matching node P6) through the access control node (i.e., the ACL node).

[0196] As Figure 8b shown, the routing matching node P6 can look up the corresponding routing table, and through a packet operation node (e.g., rewrite node P2), after parsing the IP packet, it can find out whether the packet is for the GRE protocol or the Vxlan protocol, and distribute it to the corresponding service processing (e.g., the second packet parsing node P 13 ), and the processed packet is sent to the network card sending queue of the network card through the buffer sending queue, and then transmitted through the network to the remote end. Among them, the packet processed by the second packet parsing node P 13 can also be sent to the policy node for policy control and the tunnel processing node for encrypted tunnel processing, and then the policy node and the tunnel processing node send the processed packet to the network card sending queue.

[0197] Optionally, the rewrite node P2 can also distribute the packet to the first packet parsing node P 12Perform service processing, and then send the processed message to the network card send queue through the policy node and the tunnel processing node. Optionally, the routing matching node P6 can also pass the message to the local node P 14 , so as to pass the message through the local node P 14 to pass the message to the first message parsing node P 15 or the second message parsing node P 16 .

[0198] It can be understood that the embodiments of the present application can create the protocol of the pipeline designed in this solution, and this protocol can add or delete nodes in the processing pipeline shown in Figure 8a and Figure 8b . Among them, the plugin for implementing the protocol can be developed through code, and the plugin can be added and deleted in the configuration file. It should be understood that Figure 8a and Figure 8b The nodes shown can be located in the same graph, and the nodes included in this graph will not be listed one by one here.

[0199] Please refer to Figure 4 again. The data message will pass through the corresponding flow graph nodes (i.e., graph nodes) in sequence according to the processing pipeline indicated by Figure 4 , until it is sent out by the output node. Among them, the output node here can be the network card send queue corresponding to the network card component. It can be understood that the user-mode data message processing pipeline can avoid the frequent switching between the user mode and the kernel mode, propose the optimization of steps, accelerate the message processing ability, and can provide high-performance protocol support for UDP (User Datagram Protocol), TCP (Transmission Control Protocol), and TLS (Transport Layer Security).

[0200] It should be understood that the embodiments of the present application provide a user-mode data packet processing pipeline by means of technologies such as bypassing the kernel protocol stack, non-interruptible transceiver of packets based on the polling mode, optimization of memory / buffer / queue management, and multi-queue of network cards to replace the Linux kernel protocol stack. It mainly considers two aspects of data traffic. One is the kernel data packets for the kernel, and the other is the service data packets for the service. Among them, after the network card obtains the data packets, it can evenly distribute the data packets to the queue cache in the user mode. The user-mode application can start multiple working threads to concurrently process the data packets in the queue cache in units of packet sets. Among them, each idle working thread continuously polls the packet reception queue (i.e., the buffer reception queue). Different from the Linux kernel being interrupted, polling is an active query, which can reduce the overhead of context switching. Based on this, the embodiments of the present application can improve the hit rate of the CPU cache, accelerate the packet transfer, effectively improve the throughput capacity, and achieve high-performance packet forwarding ability in the user mode; the embodiments of the present application can also reduce the latency caused by the overhead of frequent context switching.

[0201] Further, please refer to Figure 9 , Figure 9 FIG. is a schematic structural diagram of a data processing device provided by an embodiment of the present application. The data processing device 1 may include: a set generation module 11, a first processing module 12, and a second processing module 13; further, the data processing device 1 may further include: a rule matching module 14, a first matching module 15, a second matching module 16, a packet storage module 17, and an interception interruption module 18;

[0202] The set generation module 11 is used to generate a data packet set based on the data packets in the buffer reception queue in the working thread in the user mode; the data packets in the same data packet set have the same packet format;

[0203] Among them, the set generation module 11 includes: a format recognition unit 111 and a set generation unit 112;

[0204] The format recognition unit 111 is used to poll the buffer reception queue corresponding to the working thread in the working thread in the user mode and recognize the packet format of the data packets obtained by polling; the packet format includes the target packet format;

[0205] The set generation unit 112 is used to generate a data packet set corresponding to the target packet format based on the data packets with the target packet format if the number of data packets with the target packet format is greater than or equal to the number threshold.

[0206] Among them, the specific implementation manners of the format recognition unit 111 and the set generation unit 112 may refer to the above Figure 3The description of step S101 in the corresponding embodiment will not be elaborated here.

[0207] The first processing module 12 is configured to, if there is a kernel data packet in the data packet set, in a working thread, split the kernel data packet to a kernel-mode thread according to an access control rule, and perform a transfer process on the kernel data packet through the kernel-mode thread.

[0208] The second processing module 13 is configured to, if there is a service data packet in the data packet set, in a working thread, split the service data packet to one or more packet processing nodes in the working thread according to an access control rule, and perform a transfer process on the service data packet through the one or more packet processing nodes.

[0209] Wherein, the one or more packet processing nodes include a routing matching node.

[0210] The second processing module 13 includes: a packet splitting unit 131, a routing matching unit 132, and a packet parsing unit 133; Optionally, the second processing module 13 may further include: a policy control unit 134, a tunnel processing unit 135, and a packet sending unit 136.

[0211] The packet splitting unit 131 is configured to, if there is a service data packet in the data packet set, in a working thread, split the service data packet to the routing matching node in the working thread according to an access control rule.

[0212] The routing matching unit 132 is configured to perform routing matching on the destination address carried by the service data packet through the routing matching node to obtain a routing data packet corresponding to the service data packet.

[0213] The packet parsing unit 133 is configured to perform packet protocol parsing on the routing data packet.

[0214] Wherein, the one or more packet processing nodes further include a first packet parsing node and a second packet parsing node.

[0215] The packet parsing unit 133 includes: a protocol identification subunit 1331, a first parsing subunit 1332, and a second parsing subunit 1333.

[0216] The protocol identification subunit 1331 is configured to identify the packet protocol type associated with the routing data packet.

[0217] The first parsing subunit 1332 is configured to, if the packet protocol type is a generic routing encapsulation protocol type, send the routing data packet to the first packet parsing node, and perform packet protocol parsing on the routing data packet through the first packet parsing node.

[0218] The second parsing subunit 1333 is configured to, if the protocol type of the message is the virtual extensible local area network protocol type, send the routing data message to the second message parsing node, and perform message protocol parsing on the routing data message through the second message parsing node.

[0219] Among them, for the specific implementation manners of the protocol identification subunit 1331, the first parsing subunit 1332, and the second parsing subunit 1333, reference may be made to the description of step S103 in the corresponding embodiment above, which will not be elaborated here. Figure 3 The description of step S103 in the corresponding embodiment above will not be elaborated here.

[0220] Optionally, one or more message processing nodes further include a policy node and a tunnel processing node;

[0221] The policy control unit 134 is configured to obtain the parsed data message obtained through message protocol parsing, send the parsed data message to the policy node, and perform policy control on the parsed data message through the policy node to obtain the parsed data message after policy control;

[0222] The tunnel processing unit 135 is configured to send the parsed data message after policy control to the tunnel processing node, and perform tunnel processing on the parsed data message after policy control through the tunnel processing node to obtain an encrypted data message;

[0223] The message sending unit 136 is configured to send the encrypted data message to the network card sending queue corresponding to the network card component.

[0224] Among them, the message sending unit 136 is specifically configured to add the encrypted data message to the buffer sending queue corresponding to the working thread through the tunnel processing node;

[0225] The message sending unit 136 is further specifically configured to obtain the encrypted data message in the buffer sending queue through the network card component, and store the encrypted data message obtained by the network card component into the network card sending queue corresponding to the network card component.

[0226] Among them, for the specific implementation manners of the message splitting unit 131, the routing matching unit 132, the message parsing unit 133, the policy control unit 134, the tunnel processing unit 135, and the message sending unit 136, reference may be made to the description of step S103 in the corresponding embodiment above, which will not be elaborated here. Figure 3 The description of step S103 in the corresponding embodiment above will not be elaborated here.

[0227] Optionally, the access control rules include the kernel message matching rules and the service message matching rules in the access control list;

[0228] The rule matching module 14 is configured to send the data message set to the access control node in the working thread, and in the access control node, match the data messages in the data message set based on the access control list;

[0229] Among them, the rule matching module 14 includes: a message detection unit 141 and a first sending unit 142; optionally, the rule matching module 14 may further include: a second sending unit 143;

[0230] The message detection unit 141 is configured to load the data messages in the data message set into the data cache, and sequentially perform message detection on the data messages in the data message set in the data cache;

[0231] Among them, the message detection unit 141 includes: a message loading subunit 1411, a first detection subunit 1412, and a second detection subunit 1413;

[0232] The message loading subunit 1411 is configured to load the data messages in the data message set into the data cache, and obtain the data message Si of the data message set from the data cache; i ; i is a positive integer less than or equal to the number of data messages in the data message set;

[0233] The first detection subunit 1412 is configured to obtain the corresponding message processing instruction for the data message S, load the message processing instruction into the instruction cache, and perform message detection on the data message S through the message processing instruction in the instruction cache; i i i perform message detection;

[0234] The second detection subunit 1413 is configured to obtain the data message Si of the data message set from the data cache, obtain the message processing instruction from the instruction cache, and perform message detection on the data message S through the message processing instruction; i+1 i+1 i+1 perform message detection.

[0235] Among them, for the specific implementation manners of the message loading subunit 1411, the first detection subunit 1412, and the second detection subunit 1413, reference may be made to the description of step S201 in the corresponding embodiment above, and details will not be elaborated here. Figure 3 will not be elaborated here.

[0236] The first sending unit 142 is configured to, if a data message with successful verification is detected in the data message set, send the data message with successful verification to the access control node in the working thread;

[0237] Optionally, the second sending unit 143 is configured to, if a data message with failed verification is detected in the data message set, send the data message with failed verification to the failure handling node.

[0238] Among them, for the specific implementation manners of the message detection unit 141, the first sending unit 142, and the second sending unit 143, reference may be made to the aboveFigure 5 The description of step S201 in the corresponding embodiment will not be repeated here.

[0239] The first matching module 15 is configured to determine that there is a kernel data packet in the data packet set if there is a data packet in the data packet set that matches the kernel packet matching rule;

[0240] The second matching module 16 is configured to determine that there is a service data packet in the data packet set if there is a data packet in the data packet set that matches the service packet matching rule.

[0241] Optionally, the packet storage module 17 is configured to obtain data packets through the network card component and store the data packets obtained by the network card component into the network card receiving queue corresponding to the network card component;

[0242] The interception interruption module 18 is configured to perform interception interruption processing on the data packets in the network card receiving queue through the network card component, and evenly distribute the data packets after the interception interruption processing to the buffer receiving queue.

[0243] Wherein, the number of threads of the working threads is at least two, and each of the at least two working threads corresponds to a buffer receiving queue;

[0244] The interception interruption module 18 is specifically configured to perform interception interruption processing on the data packets in the network card receiving queue through the network card component, and generate a packet identifier for the data packets after the interception interruption processing;

[0245] The interception interruption module 18 is further specifically configured to evenly distribute the data packets after the interception interruption processing to the buffer receiving queues corresponding to at least two working threads according to the packet identifier.

[0246] Wherein, the specific implementation manners of the set generation module 11, the first processing module 12, the second processing module 13, the rule matching module 14, the first matching module 15, the second matching module 16, the packet storage module 17, and the interception interruption module 18 can refer to the above Figure 3 description of steps S101 - S103 in the corresponding embodiment, Figure 5 description of steps S201 - S203 in the corresponding embodiment, and Figure 6 description of steps S301 - S310 in the corresponding embodiment, which will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated either.

[0247] Furthermore, please refer to Figure 10 , Figure 10 is a schematic structural diagram of a network element device provided by an embodiment of the present application. As Figure 10As shown in the figure, the network element device 1000 may include: a processor 1001, a network interface 1004, and a memory 1005. In addition, the above-mentioned network element device 1000 may further include: at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Optionally, the network interface 1004 may include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 1005 may also be at least one storage device located far from the aforementioned processor 1001. As Figure 10 shown, in the memory 1005, which is a computer-readable storage medium, there may be included an operating system, a network communication module, and a device control application program.

[0248] In the network element device 1000 as Figure 10 shown, the network interface 1004 can provide network communication functions; and the processor 1001 can be used to call the device control application program stored in the memory 1005 to achieve:

[0249] In the working thread in the user state, based on the data packets in the buffer receiving queue, a set of data packets is generated; the data packets in the same set of data packets have the same packet format;

[0250] If there is a kernel data packet in the set of data packets, then in the working thread, according to the access control rules, the kernel data packet is split to the kernel state thread, and the kernel data packet is processed for transfer through the kernel state thread;

[0251] If there is a service data packet in the set of data packets, then in the working thread, according to the access control rules, the service data packet is split to one or more packet processing nodes in the working thread, and the service data packet is processed for transfer through one or more packet processing nodes.

[0252] It should be understood that the network element device 1000 described in the embodiments of the present application can execute the description of the data processing method in the corresponding embodiments before Figure 3 、 Figure 5 or Figure 6 corresponding, and can also execute the description of the data processing device 1 in the corresponding embodiments before Figure 9 corresponding. Details are not described herein again. In addition, the description of the beneficial effects of adopting the same method is not described again.

[0253] In addition, it should be noted here that: The embodiments of the present application also provide a computer-readable storage medium, and the computer-readable storage medium stores the computer program executed by the aforementioned data processing device 1, and the computer program includes program instructions. When the processor executes the program instructions, it can execute the description of the data processing method in the corresponding embodiments mentioned above. Therefore, the description will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the description of the method embodiments of the present application. Figure 3 , Figure 5 or Figure 6 The description of the data processing method in the corresponding embodiments will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer-readable storage medium involved in the present application, please refer to the description of the method embodiments of the present application.

[0254] The above computer-readable storage medium may be the internal storage unit of the data processing device 1 provided in the above embodiments or the above network element device, such as the hard disk or memory of the network element device. The computer-readable storage medium may also be an external storage device of the network element device, such as a plug-in hard disk equipped on the network element device, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Further, the computer-readable storage medium may also include both the internal storage unit and the external storage device of the network element device. The computer-readable storage medium is used to store the computer program and other programs and data required by the network element device. The computer-readable storage medium may also be used to temporarily store the data that has been output or will be output.

[0255] In addition, it should be noted that: The embodiments of the present application also provide a computer program product or a computer program. The computer program product or the computer program may include computer instructions, and the computer instructions may be stored in a computer-readable storage medium. The processor of the network element device reads the computer instructions from the computer-readable storage medium, and the processor may execute the computer instructions, so that the network element device executes the description of the data processing method in the corresponding embodiments mentioned above. Therefore, the description will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer program product or the computer program involved in the present application, please refer to the description of the method embodiments of the present application. Figure 3 , Figure 5 or Figure 6 The description of the data processing method in the corresponding embodiments will not be repeated here. In addition, the description of the beneficial effects of using the same method will not be repeated either. For the technical details not disclosed in the embodiments of the computer program product or the computer program involved in the present application, please refer to the description of the method embodiments of the present application.

[0256] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.

[0257] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of the rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.

Claims

1. A data processing method, characterized in that, Including: In a working thread in user mode, generate a data packet set based on the data packets in the buffer receiving queue; The data packets in the same data packet set have the same packet format, and all the data packets in the same data packet set either hit the instruction cache or do not hit the instruction cache; Obtain the packet processing instruction corresponding to the first data packet in the data packet set, load the packet processing instruction into the instruction cache, perform packet detection on the first data packet through the packet processing instruction in the instruction cache, and perform packet detection on the remaining data packets in the data packet set through the packet processing instruction in the instruction cache to obtain the data packets with successful verification in the data packet set; If there are kernel data packets among the data packets with successful verification in the data packet set, then in the working thread, divert the kernel data packets to the kernel-mode thread according to the access control rules, and perform transfer processing on the kernel data packets through the kernel-mode thread; If there are service data packets among the data packets with successful verification in the data packet set, then in the working thread, divert the service data packets to one or more packet processing nodes in the working thread according to the access control rules, and perform transfer processing on the service data packets through the one or more packet processing nodes.

2. The method according to claim 1, wherein The generating a data packet set based on the data packets in the buffer receiving queue in a working thread in user mode includes: In a working thread in user mode, poll the buffer receiving queue corresponding to the working thread, and identify the packet format of the data packets obtained by polling; the packet format includes the target packet format; If the number of data packets with the target packet format is greater than or equal to the quantity threshold, then generate a data packet set corresponding to the target packet format based on the data packets with the target packet format.

3. The method according to claim 1, wherein The access control rules include the kernel packet matching rule and the service packet matching rule belonging to the access control list; The method further includes: Send the data packets with successful verification in the data packet set to the access control node in the working thread, and in the access control node, match the data packets in the data packet set based on the access control list; If there are data packets in the data packet set that match the kernel packet matching rule, then determine that there are kernel data packets in the data packet set; If there are data packets in the data packet set that match the service packet matching rule, then determine that there are service data packets in the data packet set.

4. The method according to claim 3, wherein The sending the data packets with successful verification in the data packet set to the access control node in the working thread includes: If packet detection detects that there are data packets with successful verification in the data packet set, then send the data packets with successful verification in the data packet set to the access control node in the working thread; The method further includes: if a data packet with failed verification is detected in the data packet set, sending the data packet with failed verification in the data packet set to a failure handling node.

5. The method according to claim 1, characterized in that, One or more packet processing nodes include a routing matching node; If there is a service data packet among the data packets with successful verification in the data packet set, in the working thread, according to the access control rule, splitting the service data packet to one or more packet processing nodes in the working thread, and performing transfer processing on the service data packet through the one or more packet processing nodes, including: If there is a service data packet among the data packets with successful verification in the data packet set, in the working thread, according to the access control rule, splitting the service data packet to the routing matching node in the working thread; Performing routing matching on the destination address carried by the service data packet through the routing matching node to obtain a routing data packet corresponding to the service data packet; Performing packet protocol parsing on the routing data packet.

6. The method according to claim 5, wherein The one or more packet processing nodes further include a first packet parsing node and a second packet parsing node; The performing packet protocol parsing on the routing data packet includes: Identifying a packet protocol type associated with the routing data packet; If the packet protocol type is a generic routing encapsulation protocol type, sending the routing data packet to the first packet parsing node, and performing packet protocol parsing on the routing data packet through the first packet parsing node; If the packet protocol type is a virtual extensible local area network protocol type, sending the routing data packet to the second packet parsing node, and performing packet protocol parsing on the routing data packet through the second packet parsing node.

7. The method according to claim 5, characterized in that, The one or more packet processing nodes further include a policy node and a tunnel processing node; The method further includes: Obtaining a parsed data packet obtained through packet protocol parsing, sending the parsed data packet to the policy node, and performing policy control on the parsed data packet through the policy node to obtain a parsed data packet after policy control; Sending the parsed data packet after policy control to the tunnel processing node, and performing tunnel processing on the parsed data packet after policy control through the tunnel processing node to obtain an encrypted data packet; Sending the encrypted data packet to a network card transmission queue corresponding to the network card component.

8. The method according to claim 7, wherein The sending the encrypted data packet to a network card transmission queue corresponding to the network card component includes: Adding the encrypted data packet to a buffered transmission queue corresponding to the working thread through the tunnel processing node; Obtaining the encrypted data packet in the buffered transmission queue through the network card component, and storing the encrypted data packet obtained by the network card component to the network card transmission queue corresponding to the network card component.

9. The method according to claim 1, wherein The method further includes: Obtaining a data packet through the network card component, and storing the data packet obtained by the network card component to the network card reception queue corresponding to the network card component; The network card component intercepts and interrupts the data packets in the network card receive queue, and evenly distributes the data packets after the interception and interruption processing to the buffer receive queue.

10. The method according to claim 9, wherein The number of threads of the working threads is at least two, and each of the at least two working threads corresponds to a buffer receive queue; The network card component intercepts and interrupts the data packets in the network card receive queue, and evenly distributes the data packets after the interception and interruption processing to the buffer receive queue, including: The network card component intercepts and interrupts the data packets in the network card receive queue, and generates a packet identifier for the data packets after the interception and interruption processing; According to the packet identifier, the data packets after the interception and interruption processing are evenly distributed to the buffer receive queues corresponding to the at least two working threads respectively.

11. A data processing device, characterized in that, Including: A set generation module, configured to generate a data packet set based on the data packets in the buffer receive queue in the working threads in the user state; The data packets in the same data packet set have the same packet format, and the data packets in the same data packet set all hit the instruction cache or all do not hit the instruction cache; A rule matching module, configured to obtain the packet processing instruction corresponding to the first data packet in the data packet set, load the packet processing instruction into the instruction cache, perform packet detection on the first data packet through the packet processing instruction in the instruction cache, and perform packet detection on the remaining data packets in the data packet set through the packet processing instruction in the instruction cache, to obtain the data packets in the data packet set that pass the inspection; A first processing module, configured to, if there are kernel data packets among the data packets in the data packet set that pass the inspection, in the working thread, split the kernel data packets to the kernel state thread according to the access control rule, and perform transfer processing on the kernel data packets through the kernel state thread; A second processing module, configured to, if there are service data packets among the data packets in the data packet set that pass the inspection, in the working thread, split the service data packets to one or more packet processing nodes in the working thread according to the access control rule, and perform transfer processing on the service data packets through the one or more packet processing nodes.

12. A network element device, characterized in that, Including: A processor, a memory, and a network interface; The processor is connected to the memory and the network interface, wherein the network interface is used to provide data communication functions, the memory is used to store program codes, and the processor is used to call the program codes so that the network element device executes the method according to any one of claims 1-10.

13. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program is suitable for being loaded and executed by the processor to execute the method according to any one of claims 1-10.

14. A computer program product, characterized in that, The computer program product includes computer instructions, which are stored in a computer-readable storage medium and are adapted to be read and executed by a processor so that a network element device having the processor executes the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Transmission method and device of virtual private network data

    CN113055269A