A message processing method, device, equipment and medium

CN116389367BActive Publication Date: 2026-10-09NEW H3C SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310342245.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-30
Publication Date
2026-10-09
Estimated Expiration
2043-03-30

AI Technical Summary

Technical Problem

[0005]但是上述方案中,由于SFF结点需要配置IPv6隧道外层的基础头部(记为外层IP头)和源路由扩展头的每一种可能组合和一个VLan ID的对应关系,导致SFF结点的配置十分复杂,不利于服务链网络维护和修改配置

Benefits of technology

[0031]The message processing method, apparatus, device, and storage medium provided in this application embodiment allow a first network device to extract the header of an inner message from a received first SRv6 message; insert the header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain a second SRv6 message; and forward the second SRv6 message to a second network device. In this way, the second network device can quickly and accurately extract the information needed for security service load balancing from the second SRv6 message and perform load balancing processing. This achieves security service load balancing for the second network device, and the first network device does not need to maintain the correspondence between the VLAN ID, the outer IP header, and the source routing extension header, thus eliminating the need to expand Ethernet interfaces to maintain the aforementioned relationship, thereby significantly saving network operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389367B_ABST
    Figure CN116389367B_ABST
Patent Text Reader

Abstract

The application provides a message processing method and device, equipment and medium, and relates to the technical field of communication. When the method is applied to a first network device, the first network device extracts a message header of an inner message from a received first SRv6 message; inserts the message header into a set position between Ethernet encapsulation information included in the first SRv6 message and an outer IP header, to obtain a second SRv6 message; and forwards the second SRv6 message to a second network device. Thus, the load sharing and processing performance of a secure service are ensured, and the network operation cost is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a message processing method, apparatus, device and medium. Background Technology

[0002] In a service chain network, the Service Function (SF) node is only responsible for implementing security services, while SRv6 packet forwarding is handled by a separate Service Function Forwarder (SFF) node. This reduces the SF node's role in forwarding SRv6 (Segment Route IPv6) packets, thus reducing CPU consumption. The SFF node forwards the packet to the SF node based on the source routing extension header of the SRv6 packet. After processing the security services, the SF node then forwards the packet to the SFF node.

[0003] When processing SRv6 packets, SF nodes typically utilize both the switching chip and the multi-core CPU chip. The SF node's switching chip distributes the packets to the various CPUs within the SF node based on the IP address of the IPv4 or IPv6 packet within the tunnel. The multi-core CPU chip further distributes the packets to different single-core CPUs for load balancing based on the IP address and TCP / UDP port number of the IPv4 or IPv6 packet within the tunnel. Therefore, the SF node's switching chip and multi-core CPU chip must accurately identify the IPv4 or IPv6 packet within the tunnel to correctly implement security services. In some cases, the SF node's switching chip and multi-core CPU chip cannot accurately parse and skip the IPv6 base header and IPv6 source routing extension header of the outer tunnel layer, resulting in inaccurate parsing of the IPv4 or IPv6 packet within the tunnel layer. This prevents proper load balancing of security services and impacts the SF node's service processing performance.

[0004] To address the aforementioned issues, in existing technologies, when an SFF node forwards an SRv6 packet to an SF node, it strips the base header and source routing extension header of the IPv6 tunnel outer layer and directly encapsulates the IPv4 or IPv6 packet within the tunnel using an Ethernet link. However, this requires the SFF node to be able to restore the original base header and source routing extension header of the IPv6 tunnel outer layer upon receiving the SRv6 packet processed by the SF node, and continue forwarding based on the source routing extension header. Therefore, a mapping between each possible combination of the IPv6 tunnel outer layer base header and source routing extension header and a VLAN ID needs to be configured in the SFF node. The Ethernet encapsulation of the SRv6 packet between the SFF and SF nodes carries this VLAN ID. The switching chip and multi-core CPU chip of the SF node no longer need to parse the base header and source routing extension header of the IPv6 tunnel outer layer; they can directly parse the IPv4 or IPv6 packet within the tunnel and correctly perform security service load balancing. After receiving a message from an SF node, the SFF node recovers the basic header and source routing extension header of the IPv6 tunnel outer layer based on the VLAN ID, and then forwards it to the next SF node based on the source routing extension header.

[0005] However, in the above scheme, the SFF node requires configuring a mapping between each possible combination of the IPv6 tunnel's outer base header (denoted as the outer IP header) and source routing extension header and a VLAN ID. This makes the SFF node configuration extremely complex, hindering service chain network maintenance and configuration modifications. Furthermore, since an Ethernet interface has a limit of 4094 VLAN IDs, the current scheme also limits the number of combinations of the IPv6 tunnel's outer base header and source routing extension header, thus limiting the total number of service paths in a service chain carried by an Ethernet interface. When the number of service paths exceeds 4094, it can only be achieved by adding new Ethernet interfaces, thereby increasing network operating costs. Summary of the Invention

[0006] In view of this, this application provides a message processing method, apparatus, device and medium to ensure the processing performance of SF nodes in handling security services and to save network operating costs.

[0007] Specifically, this application is implemented through the following technical solution:

[0008] According to a first aspect of this application, a message processing method is provided, applied in a first network device, the method comprising:

[0009] Extract the header of the inner message from the first received SRv6 message;

[0010] The message header is inserted into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain the second SRv6 message;

[0011] The second SRv6 message is forwarded to the second network device.

[0012] According to a second aspect of this application, a message processing method is provided, applied in a second network device, the method comprising:

[0013] The first network device receives a second SRv6 message sent by the first network device. The second SRv6 message is obtained by the first network device after receiving the first SRv6 message by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message.

[0014] The header of the inner message is parsed from a predetermined position between the Ethernet encapsulation information of the second SRv6 message and the outer IP header.

[0015] Based on the parsed message header, the second SRv6 message is processed for service load balancing.

[0016] Delete the header at the specified position in the second SRv6 message to restore the first SRv6 message;

[0017] Forward the first SRv6 message obtained from the reconstruction.

[0018] According to a third aspect of this application, a message processing apparatus is provided, disposed in a first network device, the apparatus comprising:

[0019] The extraction module is used to extract the header of the inner message from the first received SRv6 message;

[0020] An insertion module is used to insert the packet header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 packet to obtain a second SRv6 packet;

[0021] The forwarding module is used to forward the second SRv6 message to the second network device.

[0022] According to a fourth aspect of this application, a message processing apparatus is provided, disposed in a second network device, the apparatus comprising:

[0023] The receiving module is used to receive a second SRv6 message sent by the first network device. The second SRv6 message is obtained by the first network device after receiving the first SRv6 message by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message.

[0024] The parsing module is used to parse the header of the inner packet from a predetermined position between the Ethernet encapsulation information and the outer IP header of the second SRv6 packet.

[0025] The load balancing module is used to perform service load balancing processing on the second SRv6 message based on the parsed message header;

[0026] The deletion module is used to delete the header at the set position in the second SRv6 message and restore the first SRv6 message.

[0027] The forwarding module is used to forward the first SRv6 message obtained from the reconstruction.

[0028] According to a fifth aspect of this application, an electronic device is provided, including a processor and a machine-readable storage medium storing a computer program executable by the processor, wherein the processor is prompted by the computer program to perform the method provided in the first aspect of the present application, or to perform the method provided in the second aspect of the present application.

[0029] According to a sixth aspect of this application, a machine-readable storage medium is provided, which stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method provided in the first aspect of the embodiments of this application, or to perform the method provided in the second aspect of the embodiments of this application.

[0030] The beneficial effects of the embodiments of this application are as follows:

[0031] The message processing method, apparatus, device, and storage medium provided in this application embodiment allow a first network device to extract the header of an inner message from a received first SRv6 message; insert the header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain a second SRv6 message; and forward the second SRv6 message to a second network device. In this way, the second network device can quickly and accurately extract the information needed for security service load balancing from the second SRv6 message and perform load balancing processing. This achieves security service load balancing for the second network device, and the first network device does not need to maintain the correspondence between the VLAN ID, the outer IP header, and the source routing extension header, thus eliminating the need to expand Ethernet interfaces to maintain the aforementioned relationship, thereby significantly saving network operating costs. Attached Figure Description

[0032] Figure 1 This is a flowchart illustrating a message processing method provided in an embodiment of this application;

[0033] Figure 2 This is a flowchart illustrating another message processing method provided in an embodiment of this application;

[0034] Figure 3 This is a schematic diagram of a service chain network structure provided in an embodiment of this application;

[0035] Figure 4 This is a schematic diagram of the structure of a message processing device provided in an embodiment of this application;

[0036] Figure 5 This is a schematic diagram of another message processing device provided in an embodiment of this application;

[0037] Figure 6 This is a schematic diagram of an electronic device structure for implementing a message processing method according to an embodiment of this application. Detailed Implementation

[0038] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0039] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the corresponding listed items.

[0040] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0041] Before introducing the message processing method provided in this application, let's first explain the technical terms involved:

[0042] SRv6 (IPv6 Segment Routing): A new forwarding framework, similar to source routing forwarding, where the starting node for forwarding packets can specify the forwarding path.

[0043] SFC (Service Function Chain): A framework for deploying secure service devices in a network. Each customer service packet can specify the nodes of the service devices that the packet passes through during the forwarding process, which allows customers to flexibly configure which services the packet needs to pass through and the order of these services.

[0044] SF (Service Function): A device that runs secure services within a service chain framework.

[0045] SFF (Service Function Forwarder): A device that runs SRv6 forwarding functionality. This device forwards packets to service nodes to implement security services. After processing, the service node sends the packet back to the service forwarding node, which then forwards it to the next service node. The forwarding service node acts as a proxy device for the service node.

[0046] The message processing method provided in this application is described in detail below.

[0047] See Figure 1 , Figure 1This is a flowchart of a message processing method provided in this application. This method can be applied to a first network device, which can act as an SSF node in a service chain network. When implementing this method, the first network device may include the following steps:

[0048] S101. Extract the header of the inner message from the first received SRv6 message.

[0049] In this step, after receiving the first SRv6 message sent by the preceding device, the first network device needs to perform security processing on the message to ensure network security when the message enters the intranet. Therefore, this application proposes to extract the inner packet header from the first SRv6 message before sending it to the network security device (referred to as the second network device). Specifically, referring to Table 1, the encapsulation method of the message in the SRv6 network is generally IPv4InIPv6 or IPv6InIPv6 tunnel encapsulation. That is, the inner packet needs to be encapsulated with a source routing extension header, an outer IP header, and Ethernet information to obtain the first SRv6 message. The inner packet is generally the customer's service packet, i.e., the IPv4 or IPv6 packet inside the tunnel.

[0050] Table 1

[0051] Ethernet link encapsulation Outer IP Header Source routing extension header Inner message

[0052] Therefore, based on the encapsulation format of the first SRv6 message shown in Table 1, the inner message can be parsed from the first SRv6 message, and then the message header of the inner message can be extracted from the inner message.

[0053] It should be noted that the Ethernet link encapsulation described above can be understood as using Ethernet encapsulation information to encapsulate the outer IP header, source routing extension header, and inner message. The outer IP header mentioned above is the outer IPv6 basic header, and the source routing extension header mentioned above is the source routing extension header of the IPv6 protocol.

[0054] S102. Insert the message header into the designated position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain the second SRv6 message.

[0055] In this step, to facilitate the second network device to quickly and accurately identify the header of the inner packet after receiving the SRv6 packet sent by the first network device, and thus accurately perform service load handling, this embodiment proposes that after parsing the header of the inner packet, the header is inserted into a predetermined position between the first position of the Ethernet encapsulation information constituting the first SRv6 packet and the second position of the outer IP header constituting the first SRv6 packet, thereby obtaining the processed first SRv6 packet, denoted as the aforementioned second SRv6 packet.

[0056] It should be noted that, in order to implement the above-mentioned operation of inserting the inner message header, in this embodiment, the first network device will configure the interface with the second network device to perform the message encapsulation process in step S102 before sending the received first SRv6 message to the second network device.

[0057] S103. Forward the second SRv6 message to the second network device.

[0058] In this step, after processing the first SRv6 message in step S102, it can be sent to the second network device. That is, while carrying the outer IP header and source routing extension header in the second SRv6 message, this application also encapsulates the inner message header at the beginning of the outer IP header. This not only facilitates the second network device's forwarding of the SRv6 message based on the source routing extension header after receiving it, but also allows the second network device to easily and quickly parse the inner message header when performing security service load balancing. Specifically, the second network device can quickly parse the inner message header from the designated position between the Ethernet encapsulation information and the outer IP header of the second SRv6 message, thus obtaining the information needed for load balancing. This achieves the goal of ensuring the second network device performs security service load balancing without increasing network operating costs.

[0059] By implementing the message processing method provided in this application, the first network device extracts the header of the inner message from the received first SRv6 message; inserts the header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain a second SRv6 message; and forwards the second SRv6 message to the second network device. In this way, the second network device can quickly and accurately extract the information required for security service load balancing from the second SRv6 message and perform load balancing processing. This not only realizes the security service load balancing processing of the second network device, but also eliminates the need for the first network device to maintain the correspondence between the VLAN ID, the outer IP header, and the source routing extension header. Consequently, it does not need to expand the Ethernet interface to maintain the above relationship, thereby greatly saving network operating costs.

[0060] Optionally, based on the above embodiments, in one possible embodiment, the header of the inner packet includes the IP address and port information of the inner packet; on this basis, step S102 can be performed according to the following method: inserting a new IP header and a UDP header between the Ethernet encapsulation information and the outer IP header; writing the IP address into the new IP header; writing the port information into the UDP header to obtain the second SRv6 packet.

[0061] Specifically, new IP and UDP headers are inserted between the Ethernet encapsulation information and the outer IP header to carry the IP address and port information obtained from the inner packet header, respectively. Since the format of the new IP header matches the format of the inner packet header, the IP address from the inner packet header can be directly written into the IP address field of the new IP header. Similarly, the port information is written into the port field of the UDP header, thus obtaining the second SRv6 packet. In this way, after receiving the second SRv6 packet, the second network device can extract the IP address from the new IP header according to the IP header format, and then extract the port information from the UDP header. The resulting IP address and port information are the IP address and port information of the inner packet, and thus, load balancing for security services can be performed based on this information.

[0062] Furthermore, the aforementioned IP address includes the source IP address and destination IP address of the inner packet; the port information includes the source port and destination port. Based on this, the step of writing the IP address into the new IP header can be performed according to the following procedure: fill the source IP address of the inner packet into the source IP address field of the new IP header, and fill the destination IP address of the inner packet into the destination IP address field of the new IP header.

[0063] Similarly, the port information can be written into the UDP header according to the following process: when the inner packet is a protocol packet, the source port of the inner packet is filled into the source port field of the UDP header; the destination port of the inner packet is filled into the destination port field of the UDP header; when the inner packet is a fragmented packet, the value in the packet identifier field of the fragmented packet is filled into the source port field and destination port field of the UDP header; when the inner packet is neither a protocol packet nor a fragmented packet, a set value is filled into the source port field and destination port field of the UDP header.

[0064] Specifically, the inner packet is generally an IPv4 packet or an IPv6 packet. Based on this, when the inner packet is an IPv4 packet (denoted as the inner IPv4 packet), the source IP address and destination IP address of the inner IPv4 packet are respectively the source IPv4 address and the destination IPv4 address. Therefore, the first network device adds an IPv4 header (i.e., the new IP header mentioned above) and a UDP header to the outer IP header, and then performs Ethernet encapsulation to obtain the second SRv6 packet. It should be noted that the source IPv4 address field of the newly added IPv4 header is filled with the source IPv4 address of the inner IPv4 packet, and the destination IPv4 address field of the newly added IPv4 header is filled with the destination IPv4 address of the inner IPv4 packet. Similarly, when the inner packet is not a fragmented packet, the destination port field of the newly added UDP header is filled with the TCP or UDP destination port number of the inner IPv4 packet, and the source port field of the newly added UDP header is filled with the TCP or UDP source port number of the inner IPv4 packet, as shown in Table 2 for the packet encapsulation format:

[0065] Table 2

[0066]

[0067] When the inner packet is an IPv4 fragmented packet, the value of the packet ID field in the inner IPv4 packet header is filled into the source port number field of the newly added UDP packet header, and the destination port number field of the newly added UDP packet header can be filled with the value 0. When the inner packet is neither a TCP / UDP packet nor a fragmented packet, that is, neither a TCP packet nor a UDP packet nor an IPv4 fragmented packet, in this case, both the destination port number field and the source port number field of the newly added UDP packet header can be filled with the value 0.

[0068] When the aforementioned inner packet is an IPv6 packet (denoted as the inner IPv6 packet), the source IP address and destination IP address of the inner IPv6 packet are respectively the source IPv6 address and the destination IPv6 address. Based on this, the first network device adds an IPv6 packet header and a UDP packet header to the outer IP header, and then performs Ethernet information encapsulation on this basis to obtain the aforementioned second SRv6 packet. It should be noted that the source IPv6 address field in the newly added IPv6 header should be filled with the source IPv6 address of the inner IPv6 packet, and the destination IPv6 address field in the newly added IPv6 header should be filled with the destination IPv6 address of the inner IPv6 packet. Similarly, when the inner packet is not a fragmented packet of TCP or UDP protocol, the destination port number field in the newly added UDP header should be filled with the TCP or UDP destination port number of the inner IPv6 packet, and the source port number field in the newly added UDP header should be filled with the TCP or UDP source port number of the inner IPv6 packet, as shown in Table 3.

[0069] Table 3

[0070]

[0071] In special cases, when the inner packet is an IPv6 fragmented packet, the 32-byte value of the fragment ID field in the inner IPv6 fragmented packet header is filled into the 32-byte fields of the destination port number and source port number in the newly added UDP header. However, when the inner packet is neither a TCP packet nor a UDP packet, nor an IPv6 fragmented packet, the destination port number and source port number fields in the newly added UDP header are both filled with the value 0; that is, the above setting is 0 in this case.

[0072] It should be noted that prior to this, the first network device and the second network device could negotiate the processing based on the format of the header of the inner message. For example, the first network device and the second network device could negotiate to use new IP headers and UDP headers to carry the header of the inner message. In this way, the first network device can insert the header of the inner message into the IP header and UDP header to obtain the second SRv6 message, and forward it to the second network device. When the second network device receives the second SRv6 message, it can parse the required header of the inner message from it according to the format of the IP header and UDP header, and then perform load balancing processing for security services.

[0073] Optionally, based on any of the above embodiments, in another possible embodiment, step S102 can also be performed according to the following process: inserting a network service header between the Ethernet encapsulation information and the outer IP header; filling the packet header into the network service header to obtain the second SRv6 packet.

[0074] Specifically, other methods can be used when encapsulating the header of the inner message. Therefore, this embodiment proposes that a simple, fixed-length and fixed-position format can be used to carry the header of the inner message. This simple, fixed-length and fixed-position format can, but does not need to be, a Network Service Header (NSH). Based on this, the IP address and port information from the inner message header can be filled into the NSH. It should be noted that before this, the first network device and the second network device can negotiate the format of the inner message header. For example, the first network device and the second network device can negotiate to use NSH to carry the inner message header. In this way, the first network device can insert the inner message header into the NSH to obtain the second SRv6 message and forward it to the second network device. When the second network device receives the second SRv6 message, it can parse the required inner message header from it according to the NSH format, and then perform load balancing processing for security services.

[0075] Optionally, based on any of the above embodiments, in another possible embodiment, step S102 can also be performed according to the following process: writing the IP address in the outer IP header into the setting field of the source routing extension header in the first SRv6 message; writing the IP address in the message header into the IP address field in the outer IP header to obtain the second SRv6 message.

[0076] Specifically, to facilitate the second network device's identification of the IP address and port information in the inner packet, this embodiment proposes, referring to the packet structure shown in Table 1 for the first SRv6 packet, that the first network device can extract the IP address from the outer IP header of the first SRv6 packet and record it as the outer IP address; then, it writes this outer IP address into the setting field of the source routing extension header, and replaces the IP address in the outer IP header with the IP address in the inner packet header, thereby obtaining the second SRv6 packet. That is, when the inner packet is an IPv4 packet, the IPv4 address in the inner IPv4 packet can be filled into the IPv6 field of the outer IP header; if the inner packet is an IPv6 packet, the IPv6 address in the inner IPv6 packet can be filled into the IPv6 field of the outer IP header. In this way, when the second network device receives the second SRv6 message according to this encapsulation format, it can parse the IP address of the inner message from the outer IP header after performing Ethernet decapsulation, thereby achieving a certain degree of load balancing.

[0077] By implementing the message processing method provided in any of the above embodiments, not only can the load balancing function of security services be guaranteed, but also complex configurations to restore the outer IP header and source routing extension header are not required, simplifying the maintenance of the SRv6 service chain network. At the same time, the number of outer IP headers and source routing extension headers that a single Ethernet interface of the first network device and the second network device can support is no longer limited, that is, the number of service chains of a single Ethernet interface is unlimited, saving network operating costs.

[0078] Based on the same inventive concept, this embodiment also provides a message processing method implemented on the second network device side, referencing... Figure 2 The diagram shown illustrates another message processing method. The second network device described above can serve as an SF node in a service chain network. When implementing the message processing method described above, the second network device may include the following steps:

[0079] S201. Receive the second SRv6 message sent by the first network device.

[0080] The second SRv6 message is obtained by the first network device after receiving the first SRv6 message, by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message.

[0081] In this step, after the second network device receives the second SRv6 message obtained by the first network device processing the first SRv6 message using the message processing method provided in any of the above embodiments, the second network device will perform message parsing processing.

[0082] S202. Parse the header of the inner message from the set position between the Ethernet encapsulation information and the outer IP header of the second SRv6 message.

[0083] In this step, the second network device can parse the inner packet header from the designated location in the second SRv6 packet using the packet encapsulation format negotiated with the first network device. Since the inner packet header is located between the Ethernet information and the outer IP header, the second network device does not need to decapsulate the Ethernet, outer IP header, and source routing extension header one by one. It only needs to remove the Ethernet encapsulation to accurately parse the inner packet header.

[0084] S203. Based on the parsed message header, perform service load balancing processing on the second SRv6 message.

[0085] In this step, after parsing the header from the second SRv6 message, the load balancing of security services can be performed based on the IP address and port information in the header. That is, the second SRv6 message is sent to each CPU of the second network device to distribute the load of security services.

[0086] S204. Delete the message header at the set position in the second SRv6 message to restore the first SRv6 message.

[0087] In this step, to facilitate subsequent message processing, after parsing the header of the inner message, the second network device can delete the header of the memory message at the set position, thereby restoring the first SRv6 message, i.e., the first SRv6 message shown in Table 1, for subsequent processing of the first SRv6 message.

[0088] S205, forward the first SRv6 message obtained from the reconstruction.

[0089] In this step, since the second network device is used to perform security service processing on the packets arriving on the device, after performing security service processing, the packet forwarding process will continue, that is, forwarding the restored first SRv6 packet.

[0090] In the above-mentioned message processing method on the second network device side, after receiving the second SRv6 message sent by the first network device, the second network device can parse the header of the inner message from the set position between the Ethernet encapsulation information and the outer IP header of the second SRv6 message; then, based on the parsed header, the second SRv6 message is processed for service load balancing; and the header at the set position in the second SRv6 message is deleted to restore the first SRv6 message; finally, the restored first SRv6 message is forwarded. Since the second SRv6 message is obtained by the first network device after receiving the first SRv6 message, by inserting the header of the inner message from the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message, the second network device can directly read the header of the inner message after decapsulating the Ethernet encapsulation. This eliminates the need for full encapsulation and parsing of the second SRv6 message to extract the inner message header. This avoids the inability to accurately identify the inner message header due to excessive encapsulation, thus preventing the correct processing of security services and improving security service processing performance to some extent. Simultaneously, the first network device does not need to maintain the mapping between the VLAN ID and the outer IP header and source routing extension header, saving network operating costs.

[0091] Based on any of the above embodiments, in one possible embodiment, step S202 can be performed according to the following process: parsing the IP address of the packet header from the new IP packet header inserted between the Ethernet encapsulation information and the outer IP header, and parsing the port information from the UDP packet header inserted between the Ethernet encapsulation information and the outer IP header.

[0092] Based on this, step S203 can be performed according to the following process: delete the new IP packet header and UDP packet header to restore the first SRv6 packet.

[0093] Specifically, when the IP address and port information of the inner packet header are located in the new IP header and UDP header inserted between the Ethernet encapsulation information and the outer IP header of the second SRv6 packet, respectively, the second network device can parse the IP address from the new IP header (i.e., the TCP header) and the port information of the inner packet from the UDP header, thus accurately obtaining the IP address and port information of the inner packet. After resolving the IP address and port information, to facilitate the second network device's security service load balancing and subsequent packet forwarding, the second network device can delete the TCP and UDP headers from the second SRv6 packet to restore the first SRv6 packet. In this way, the second network device's switching chip can distribute the restored first SRv6 packet to various CPUs for load balancing based on the resolved IP address. Meanwhile, the multi-core CPU chip of the second network device can distribute the first SRv6 packet to different single-core CPUs based on the parsed IP address and port information to perform security service processing. This not only achieves accurate identification of the IP address and port information of the inner packet, but also ensures the accuracy of security service load balancing, and improves the performance of security service processing to a certain extent.

[0094] It should be noted that the encapsulation format used in the inner message header can be negotiated between the first network device and the second network device. For example, if the first network device and the second network device negotiate that the inner message header is encapsulated according to the TCP or UDP header format, then when the second network device receives the aforementioned second SRv6 message, it can parse the IP address and port information of the inner message from the IP header and UDP header between the Ethernet information and the outer IP header, respectively.

[0095] Optionally, based on any of the above embodiments, in another possible embodiment, step S202 can also be performed according to the following process: parsing the packet header from the network service header inserted between the Ethernet encapsulation information and the outer IP header.

[0096] Based on this, step S203 can be performed according to the following process: delete the network service header and restore the first SRv6 packet.

[0097] Specifically, when the packet header is located in the Network Service Header (NSH) inserted between the Ethernet encapsulation information and the outer IP header, the second network device can parse the inner packet header from the NSH. Furthermore, to facilitate subsequent security service processing by the second network device, it can also delete the NSH from the second SRv6 packet, thereby restoring the first SRv6 packet. This not only allows for quick and accurate identification of the inner packet header but also facilitates load balancing of security services by the second network device based on the IP address and port information in the packet header.

[0098] Optionally, based on any of the above embodiments, in another possible embodiment, step S202 can also be performed according to the following process: parsing the IP address of the packet header from the IP address field of the outer IP header.

[0099] Based on this, step S203 can be performed according to the following process: extract the target IP address from the setting field of the source routing extension header; replace the IP address in the outer IP header with the target IP address.

[0100] Specifically, when the first network device writes the IP address of the inner packet into the outer IP header, the second network device can parse the IP address of the inner packet from the outer IP header. Simultaneously, when the second network device reconstructs the first SRv6 packet, it needs to extract and delete the destination IP address from the configuration field of the source routing extension header of the second SRv6 packet. This destination IP address is recorded as the outer IPv6 address, and then this destination IP address replaces the IP address in the outer IP header, thus reconstructing the first SRv6 packet. Therefore, not only can the IP address of the inner packet be identified quickly and accurately, but it also facilitates the second network device's load balancing of security services based on IP addresses.

[0101] To better understand any of the message processing methods described above in this application, Figure 3 The following explanation uses the service chain network as an example. Figure 3The SFF1 and SFF2 nodes can integrate the functions of the first network device, while the SF1, SF2, and SF3 nodes can integrate the functions of the second network device. Based on this, after receiving the first SRv6 message from the previous node, the SFF1 node, through configuration on the interface connecting the SF1 and SF2 nodes, parses the inner packet header from the first SRv6 message and encapsulates it at a designated location between the Ethernet information and the outer IP header of the first SRv6 message before forwarding it to the SF1 node, thus obtaining the second SRv6 message. For ease of understanding, let's take an example where the inner packet is an IPv4 packet and not a fragmented packet. The SFF1 node can then extract the header of the parsed inner packet and encapsulate it according to the format in Table 2. Specifically, it fills the source IPv4 address from the header into the source IPv4 address field of the newly added IPv4 header, and the destination IPv4 address into the destination IPv4 address field. Simultaneously, it fills the source port number from the header into the source port field of the newly added UDP header, and the destination port number into the destination port field, thus obtaining the second SRv6 packet. The SFF1 node can then forward this second SRv6 packet to the SF1 node for security service processing.

[0102] By configuring the interface between the SF1 node and the SFF1 node, the SF1 node, upon receiving the second SRv6 packet, can quickly and accurately obtain the IPv4 address and port information of the inner IPv4 packet after decrypting the Ethernet information. Subsequently, the switching chip and multi-core CPU chip in the SF1 node can load-distribute the second SRv6 packet based on the resolved IPv4 address and port information, assigning it to a single-core CPU. After performing security service processing, the SF1 node can remove the IPv4 and UDP headers to reconstruct the first SRv6 packet, and then send the first SRv6 packet back to the SFF1 node via an ingress interface reflection message.

[0103] Upon receiving the first SRv6 packet, the SFF1 node, being a standard SRv6 encapsulated packet, does not need to recover the outer IP header and source routing extension header. It simply forwards the first packet to the next SF node based on the source routing extension header within the first SRv6 packet. This not only ensures load balancing for security services but also eliminates the need for complex configuration to recover the outer IP header and source routing extension header, simplifying the maintenance of the SRv6 service chain network. Furthermore, the number of outer IP headers and source routing extension headers that a single Ethernet interface of the first and second network devices can support is no longer limited, meaning the number of service chains per Ethernet interface is unlimited, thus saving network operating costs.

[0104] Based on the same inventive concept, this application also provides a message processing apparatus corresponding to the message processing method provided by the first network device described above. Specific implementation details of this message processing apparatus can be found in the description of the message processing method in the first network device described above, and will not be elaborated upon here.

[0105] See Figure 4 , Figure 4 This application provides an exemplary embodiment of a message processing apparatus, disposed in a first network device, the apparatus comprising:

[0106] Extraction module 401 is used to extract the header of the inner message from the received first SRv6 message;

[0107] Insertion module 402 is used to insert the message header into a set position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain a second SRv6 message;

[0108] Forwarding module 403 is used to forward the second SRv6 message to the second network device.

[0109] In the message processing apparatus provided in this embodiment, the first network device extracts the header of the inner message from the received first SRv6 message; inserts the header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain a second SRv6 message; and forwards the second SRv6 message to the second network device. In this way, the second network device can quickly and accurately extract the information required for security service load balancing from the second SRv6 message and perform load balancing processing. This not only realizes the security service load balancing processing of the second network device, but also eliminates the need for the first network device to maintain the correspondence between the VLAN ID, the outer IP header, and the source routing extension header. Consequently, it does not need to expand the Ethernet interface to maintain the above relationship, thereby greatly saving network operating costs.

[0110] Optionally, the above-mentioned header includes the IP address and port information of the inner packet; based on this, in one possible embodiment, the above-mentioned insertion module 402 is specifically used to insert a new IP packet header and a UDP packet header between the Ethernet encapsulation information and the outer IP header; write the IP address into the new IP packet header; write the port information into the UDP packet header to obtain the second SRv6 packet.

[0111] Furthermore, the aforementioned IP address includes the source IP address and destination IP address of the inner packet; the port information includes the source port and destination port; based on this, the aforementioned insertion module 402 is specifically used to fill the source IP address of the inner packet into the source IP address field of the new IP header, and to fill the destination IP address of the inner packet into the destination IP address field of the new IP header;

[0112] The aforementioned insertion module 402 is further configured to: when the inner message is a protocol message, fill the source port of the inner message into the source port field of the UDP header; fill the destination port of the inner message into the destination port field of the UDP header; when the inner message is a fragmented message, fill the source port field and destination port field of the UDP header with the values ​​in the message identifier field of the fragmented message; when the inner message is neither a protocol message nor a fragmented message, fill the source port field and destination port field of the UDP header with a set value.

[0113] Alternatively, in another possible embodiment, the insertion module 402 is specifically used to insert a network service header between the Ethernet encapsulation information and the outer IP header; the packet header is filled into the network service header to obtain a second SRv6 packet.

[0114] Optionally, in another possible embodiment, the insertion module 402 is specifically used to write the IP address in the outer IP header into the setting field of the source routing extension header in the first SRv6 packet; and to write the IP address in the packet header into the IP address field in the outer IP header to obtain the second SRv6 packet.

[0115] Based on the same inventive concept, this application also provides a message processing apparatus corresponding to the message processing method provided by the second network device described above. Specific implementation details of this message processing apparatus can be found in the description of the message processing method in the second network device described above, and will not be elaborated upon here.

[0116] See Figure 5 , Figure 5This application provides an exemplary embodiment of a message processing apparatus, disposed in a second network device, the apparatus comprising:

[0117] The receiving module 501 is used to receive a second SRv6 message sent by the first network device. The second SRv6 message is obtained by the first network device after receiving the first SRv6 message by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message.

[0118] The parsing module 502 is used to parse the header of the inner packet from a set position between the Ethernet encapsulation information of the second SRv6 packet and the outer IP header;

[0119] The load balancing module 503 is used to perform service load balancing processing on the second SRv6 message based on the parsed message header;

[0120] The deletion module 504 is used to delete the message header at the set position in the second SRv6 message and restore the first SRv6 message.

[0121] Forwarding module 505 is used to forward the restored first SRv6 message.

[0122] In the message processing apparatus provided in this embodiment, after receiving the second SRv6 message sent by the first network device, the header of the inner message can be parsed from a predetermined position between the Ethernet encapsulation information and the outer IP header of the second SRv6 message; then, based on the parsed header, the second SRv6 message is processed for service load balancing; the header at the predetermined position in the second SRv6 message is deleted to restore the first SRv6 message; finally, the restored first SRv6 message is forwarded. Since the second SRv6 message is obtained by the first network device after receiving the first SRv6 message, by inserting the header of the inner message from the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message, the second network device can directly read the header of the inner message after decapsulating the Ethernet encapsulation. This eliminates the need for full encapsulation and parsing of the second SRv6 message to extract the inner message header. This avoids the inability to accurately identify the inner message header due to excessive encapsulation, thus preventing the correct processing of security services and improving security service processing performance to some extent. Simultaneously, the first network device does not need to maintain the mapping between the VLAN ID and the outer IP header and source routing extension header, saving network operating costs.

[0123] Optionally, based on the above embodiments, in one possible embodiment, the parsing module 502 is specifically used to parse the IP address of the packet header from the new IP packet header inserted between the Ethernet encapsulation information and the outer IP header, and to parse the port information from the UDP packet header inserted between the Ethernet encapsulation information and the outer IP header.

[0124] Based on this, the aforementioned deletion module 504 is specifically used to delete the new IP packet header and UDP packet header, restoring the first SRv6 packet.

[0125] Alternatively, in another possible embodiment, the parsing module 502 is specifically used to parse the packet header from the network service header inserted between the Ethernet encapsulation information and the outer IP header;

[0126] Based on this, the aforementioned deletion module 504 is specifically used to delete the network service header and restore the first SRv6 packet.

[0127] Optionally, in another possible embodiment, the parsing module 502 is specifically used to parse the IP address of the packet header from the IP address field of the outer IP header;

[0128] Based on this, the deletion module 504 is specifically used to extract the target IP address from the setting field of the source routing extension header; and replace the IP address in the outer IP header with the target IP address.

[0129] Based on the same inventive concept, embodiments of this application provide an electronic device, which may, but is not limited to, the first network device or the second network device described above. For example... Figure 6 As shown, the electronic device includes a processor 601 and a machine-readable storage medium 602. The machine-readable storage medium 602 stores a computer program executable by the processor 601. The processor 601 is prompted by the computer program to execute the message processing method provided in any embodiment of this application. Furthermore, the electronic device also includes a communication interface 603 and a communication bus 604, wherein the processor 601, the communication interface 603, and the machine-readable storage medium 602 communicate with each other via the communication bus 604.

[0130] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0131] The communication interface is used for communication between the aforementioned electronic devices and other devices.

[0132] The machine-readable storage medium 602 described above can be a memory, which may include random access memory (RAM), DDR SRAM (Double Data Rate Synchronous Dynamic Random Access Memory), or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0133] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0134] For embodiments of electronic devices and machine-readable storage media, since the methods involved are basically similar to those described in the foregoing method embodiments, the description is relatively simple, and relevant details can be found in the descriptions of the method embodiments.

[0135] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0136] The specific implementation process of the functions and roles of each unit / module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0137] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units / modules described as separate components may or may not be physically separate. The components shown as units / modules may or may not be physical units / modules, that is, they may be located in one place or distributed across multiple network units / modules. Some or all of the units / modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0138] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A message processing method, characterized in that, The method, applied in a first network device, includes: Extract the header of the inner message from the first received SRv6 message; The message header is inserted into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message to obtain the second SRv6 message; The second SRv6 message is forwarded to the second network device.

2. The method according to claim 1, characterized in that, The message header includes the IP address and port information of the inner message; The message header is inserted at a predetermined position between the Ethernet encapsulation information and the outer IP header of the first SRv6 message to obtain a second SRv6 message, which includes: A new IP header and a UDP header are inserted between the Ethernet encapsulation information and the outer IP header; Write the IP address into the new IP header; The port information is written into the UDP header to obtain the second SRv6 packet.

3. The method according to claim 2, characterized in that, The IP address includes the source IP address and destination IP address of the inner packet; the port information includes the source port and destination port; Writing the IP address into the new IP header includes: The source IP address of the inner packet is filled into the source IP address field of the new IP header, and the destination IP address of the inner packet is filled into the destination IP address field of the new IP header. Writing the port information into the UDP header includes: When the inner message is a protocol message, the source port of the inner message is filled into the source port field of the UDP header; the destination port of the inner message is filled into the destination port field of the UDP header. When the inner message is a fragmented message, the source port field and destination port field of the UDP message header are filled with the values ​​from the message identifier field of the fragmented message; When the inner message is not a protocol message or a fragmented message, the set values ​​are filled into the source port field and destination port field of the UDP message header.

4. The method according to claim 1, characterized in that, The message header is inserted at a predetermined position between the Ethernet encapsulation information and the outer IP header of the first SRv6 message to obtain a second SRv6 message, which includes: A network service header is inserted between the Ethernet encapsulation information and the outer IP header; The message header is filled into the network service header to obtain the second SRv6 message.

5. The method according to claim 1, characterized in that, The message header is inserted at a predetermined position between the Ethernet encapsulation information and the outer IP header of the first SRv6 message to obtain a second SRv6 message, which includes: Write the IP address in the outer IP header into the setting field of the source routing extension header in the first SRv6 message; The IP address in the packet header is written into the IP address field in the outer IP header to obtain the second SRv6 packet.

6. A message processing method, characterized in that, The method, applied in a second network device, includes: The first network device receives a second SRv6 message sent by the first network device. The second SRv6 message is obtained by the first network device after receiving the first SRv6 message by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message. The header of the inner message is parsed from a predetermined position between the Ethernet encapsulation information of the second SRv6 message and the outer IP header. Based on the parsed message header, the second SRv6 message is processed for service load balancing. Delete the header at the specified position in the second SRv6 message to restore the first SRv6 message; Forward the first SRv6 message obtained from the reconstruction.

7. The method according to claim 6, characterized in that, The header of the inner packet is parsed from a predetermined position between the Ethernet encapsulation information of the second SRv6 packet and the outer IP header, including: The IP address of the packet header is parsed from the new IP packet header inserted between the Ethernet encapsulation information and the outer IP header, and the port information is parsed from the UDP packet header inserted between the Ethernet encapsulation information and the outer IP header. Delete the header at the specified position in the second SRv6 message to restore the first SRv6 message, including: Delete the new IP packet header and UDP packet header to restore the first SRv6 packet.

8. The method according to claim 6, characterized in that, The header of the inner packet is parsed from a predetermined position between the Ethernet encapsulation information of the second SRv6 packet and the outer IP header, including: The packet header is parsed from the network service header inserted between the Ethernet encapsulation information and the outer IP header; Delete the header at the specified position in the second SRv6 message to restore the first SRv6 message, including: Delete the network service header to restore the first SRv6 packet.

9. The method according to claim 6, characterized in that, The header of the inner packet is parsed from a predetermined position between the Ethernet encapsulation information of the second SRv6 packet and the outer IP header, including: The IP address of the packet header is parsed from the IP address field of the outer IP header; Delete the header at the specified position in the second SRv6 message to restore the first SRv6 message, including: Extract the target IP address from the configuration field of the source routing extension header; Replace the IP address in the outer IP header with the target IP address.

10. A message processing apparatus, characterized in that, The device, configured in a first network device, includes: The extraction module is used to extract the header of the inner message from the first received SRv6 message; An insertion module is used to insert the packet header into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 packet to obtain a second SRv6 packet; The forwarding module is used to forward the second SRv6 message to the second network device.

11. A message processing apparatus, characterized in that, The device, configured in a second network device, includes: The receiving module is used to receive a second SRv6 message sent by the first network device. The second SRv6 message is obtained by the first network device after receiving the first SRv6 message by inserting the header of the inner message in the first SRv6 message into a predetermined position between the Ethernet encapsulation information and the outer IP header included in the first SRv6 message. The parsing module is used to parse the header of the inner packet from a predetermined position between the Ethernet encapsulation information and the outer IP header of the second SRv6 packet. The load balancing module is used to perform service load balancing processing on the second SRv6 message based on the parsed message header; The deletion module is used to delete the header at the set position in the second SRv6 message and restore the first SRv6 message. The forwarding module is used to forward the first SRv6 message obtained from the reconstruction.

12. An electronic device, characterized in that, The method includes a processor and a machine-readable storage medium storing a computer program executable by the processor, the processor being prompted by the computer program to perform the method according to any one of claims 1-5, or to perform the method according to any one of claims 6-9.

13. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method according to any one of claims 1-5, or the method according to any one of claims 6-9.

Citation Information

Patent Citations

  • Method and device for realizing service function processing

    CN114448861A

  • Message processing method, apparatus and system, and storage medium

    WO2022228533A1