A message-triggered session aging method

CN116455953BActive Publication Date: 2026-09-25CHINA TELECOM CLOUD TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310252420.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-12
Publication Date
2026-09-25
Estimated Expiration
2043-03-12

AI Technical Summary

Technical Problem

因为该架构下,定时器模块,及各个安全业务处理模块都处在同一个大循环下,而7层的一些安全业务有的特别耗时,这就导致定时器模块很可能虽然已经超时了,但是由于被安全业务阻塞,而无法及时的被调度到

Benefits of technology

[0024]1、本发明摒弃了定时器方式管理会话老化的方案,也就彻底摒弃了因定时器无法及时被调度而带来的老化效率不及预期的缺陷。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455953B_ABST
    Figure CN116455953B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of IP network communication, and particularly discloses a message-triggered session aging method, which comprises the following steps: S1, first searching a hash to match a session after a message arrives at a firewall, and if a first packet cannot be matched, a new session needs to be established; S2, allocating session resources for the new session; S3, when there are session resources, a session table item is allocated, the update time on the session is set as the current time, and the session is added to the tail of a corresponding aging queue link table; and S4, when there are no session resources, whether the session pointed to by a head node of the aging link table has reached an aging time is judged, and the like; the application simplifies development and debugging difficulty, and the establishment and aging of the session are bound together in a message-triggered mode, so that the dynamic balance between the establishment and the aging is naturally achieved, and a better establishment performance can be found without deliberately and repeatedly debugging as before.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of IP network communication technology, specifically a message-triggered session aging method. Background Technology

[0002] To enhance network security, client traffic accessing servers, besides passing through necessary routing and switching equipment, often needs to be filtered by firewall products before successfully reaching the destination. Since each webpage opened or server accessed by a user represents one or more new sessions from the firewall's perspective, the session establishment rate (the number of new HTTP connection requests the firewall can handle per second) has always been a crucial performance indicator for firewall products. Simply put, a higher establishment rate means more users can be served simultaneously.

[0003] When discussing new session creation, another unavoidable topic is aging (the process of tearing down connections). Every session creation involves aging, and the aging capability of a device session significantly limits its new session creation ability. Current technology primarily controls session aging through timer mechanisms. One or more aging timers are started, sessions are added to the corresponding aging queue, and when the aging timer expires, the aging list is traversed to delete expired session nodes. However, this approach has the following main shortcomings in practice:

[0004] 1. Although the aging timer has expired, it often fails to be scheduled in time, resulting in an aging rate that is less than expected. This problem is particularly prominent in new-generation firewall products that use the DPDK polling architecture. In this architecture, the timer module and various security service processing modules are all in the same large loop, and some layer 7 security services are particularly time-consuming. This means that although the timer module may have expired, it may be blocked by security services and unable to be scheduled in time.

[0005] 2. Existing aging mechanisms have poor adaptability and are difficult to scale elastically. Parameters such as the number of nodes traversed and deleted per aging timeout are debugged for specific products. The number of nodes traversed and aged per cycle cannot be too high or too low. If too few nodes are traversed and aged per cycle, the new creation rate will far exceed the aging rate, causing session capacity to be quickly filled, making it impossible to serve new users. If too many nodes are traversed and aged per cycle, it may lead to resource waste. A longer aging operation consumes more CPU time, while a relatively shorter new creation operation consumes less CPU time, resulting in a decrease in new creation performance and failing to achieve optimal new creation performance. Different products have different CPU models, numbers of CPUs, memory sizes, and other specifications. Every time a new product is launched, a set of corresponding optimal aging parameters needs to be debugged. For traditional hardware manufacturers, the workload might be manageable due to the relatively fixed products, but in today's era of diverse cloud products with constantly changing specifications, the workload is undoubtedly enormous.

[0006] Therefore, we propose a message-triggered session aging method. Summary of the Invention

[0007] The purpose of this invention is to provide a message-triggered session aging method to avoid the problem of insufficient device session aging performance caused by the inability of timers to be scheduled in a timely manner. At the same time, this solution has strong versatility and will not bring excessive additional workload due to the introduction of new products.

[0008] To achieve the above objectives, the present invention provides the following technical solution: a message-triggered session aging method, the method comprising the following steps:

[0009] Step S1: After the packet reaches the firewall, the first step is to check the hash to match the session. If the first packet cannot be matched, a new session needs to be created.

[0010] Step S2: Create a new session, allocate session resources, and determine the resource allocation details;

[0011] Step S3: When there are session resources, allocate a session table entry, assign the update time on the session to the current time, and add it to the end of the linked list of the corresponding aging queue.

[0012] In step S4, if there are no session resources, check in turn whether the session pointed to by the head node of the aging list has reached its aging time. If none of the head nodes of the list have reached their aging time, it is determined that all resources are occupied, the allocation fails, and an alarm is issued that no session resources are available. As long as one session node has reached its aging time, its resources can be released, and then return to step S2 to re-apply for session resources.

[0013] Step S5: After the packet arrives at the firewall, it is matched with an existing session. At this time, it is first determined whether the session has reached its aging time. If it has not reached its aging time, the update time of the session needs to be assigned to the current time, and then it is removed from the aging list and re-inserted into the end of the list. Subsequent sessions can be used normally.

[0014] In a preferred embodiment of the present invention, the session resource allocation in step S2 includes two cases: one is that there are still resources, and the other is that there are no session resources.

[0015] In a preferred embodiment of the present invention, if the session in step S5 reaches its aging time, it is released, and then the process returns to step S2 to re-apply for a session.

[0016] As a preferred embodiment of the present invention, the queue storage structure of the session includes: a session hash bucket, a collision linked list, and an old session queue.

[0017] As a preferred embodiment of the present invention, determining whether the session pointed to by the head node of the aging list has reached its aging time refers to comparing the session's update time plus the session's own aging time with the current time.

[0018] In a preferred embodiment of the present invention, the session is stored using a hash structure.

[0019] In a preferred embodiment of the present invention, the session structure needs to store aging node nodes to associate the aging queues corresponding to the sessions.

[0020] In a preferred embodiment of the present invention, the aging queue is first classified according to aging time.

[0021] In a preferred embodiment of the present invention, each queue of the aging queue is organized in the form of a doubly linked circular list.

[0022] In a preferred embodiment of the present invention, the aging queue is sorted according to the session update time, with the most recently updated session placed at the end of the linked list, and the head node of the linked list pointing to the session closest to the aging time.

[0023] Compared with the prior art, the beneficial effects of the present invention are:

[0024] 1. This invention abandons the timer-based management of session aging, thus completely eliminating the defect of aging efficiency being lower than expected due to the inability of timers to be scheduled in a timely manner.

[0025] 2. This invention simplifies the development and debugging process. The new session creation and aging are bound together by message triggering, which naturally achieves a dynamic balance between new session creation and aging. It eliminates the need for repeated debugging to find a better new session performance as before.

[0026] 3. This invention greatly reduces the extra workload brought about by the launch of new products. This invention is highly versatile and has no direct relationship with the specifications of the product, such as the CPU model, number, and memory size. Therefore, it will not increase the extra workload due to the launch of new products. Attached Figure Description

[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention.

[0028] Figure 1 This is a flowchart illustrating the message-triggered session aging process of a message-triggered session aging method according to the present invention.

[0029] Figure 2 This is a diagram of the session and its aging queue storage structure for a message-triggered session aging method according to the present invention. Detailed Implementation

[0030] To make the technical problems to be solved, the technical solutions, and the beneficial effects of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the present invention and are not intended to limit the present invention.

[0031] Please see Figures 1-2 To achieve the above objectives, this invention proposes a message-triggered session aging method, which includes the following steps:

[0032] Step S1: After the packet reaches the firewall, the first step is to check the hash to match the session. If the first packet cannot be matched, a new session needs to be created.

[0033] Step S2: Create a new session, allocate session resources, and determine the resource allocation details;

[0034] Step S3: When there are session resources, allocate a session table entry, assign the update time on the session to the current time, and add it to the end of the linked list of the corresponding aging queue.

[0035] In step S4, if there are no session resources, check in turn whether the session pointed to by the head node of the aging list has reached its aging time. If none of the head nodes of the list have reached their aging time, it is determined that all resources are occupied, the allocation fails, and an alarm is issued that no session resources are available. As long as one session node has reached its aging time, its resources can be released, and then return to step S2 to re-apply for session resources.

[0036] Step S5: After the packet arrives at the firewall, it is matched with an existing session. At this time, it is first determined whether the session has reached its aging time. If it has not reached its aging time, the update time of the session needs to be assigned to the current time, and then it is removed from the aging list and re-inserted into the end of the list. Subsequent sessions can be used normally.

[0037] Furthermore, the session resource allocation in step S2 includes two cases: one is that there are still resources, and the other is that there are no session resources.

[0038] Furthermore, if a session in step S5 reaches its aging time, it is released, and then the process returns to step S2 to re-apply for a session.

[0039] Furthermore, the queue storage structure for the session includes: a session hash bucket, a collision chain, and an old message queue.

[0040] Furthermore, determining whether the session pointed to by the head node of the aging list has reached its aging time refers to comparing the session's update time plus the session's own aging time with the current time.

[0041] Furthermore, the sessions are stored using a hash structure.

[0042] Furthermore, the session structure needs to store aging node nodes, which are used to associate the aging queue corresponding to the session.

[0043] Furthermore, the aging queue is first classified according to aging time.

[0044] Furthermore, each queue in the aging queue is organized in the form of a doubly linked circular list.

[0045] Furthermore, the aging queue is sorted according to the session update time, with the most recently updated session placed at the end of the linked list, and the head node of the linked list pointing to the session closest to the aging time.

[0046] Example

[0047] like Figure 2As shown, the session and its aging queue storage structure involved in this invention uses a hash structure for storage, which facilitates quick packet retrieval of related sessions. The session structure also needs to store aging nodes to associate the sessions with their corresponding aging queues. The aging queues are first simply categorized according to aging time; here, we assume there are three types: 2s, 30s, and 600s aging queues. Each queue is organized as a doubly linked circular list and needs to be sorted according to session update time. The most recently updated session is placed at the end of the list, and the head node of the list points to the session closest to its aging time.

[0048] Please see Figure 1 ,like Figure 1 The specific process for triggering session aging processing for the message shown is as follows:

[0049] Step S1: After the packet reaches the firewall, the first step is to check the hash to match the session. The first packet will definitely not be matched, so a new session needs to be created.

[0050] Step S2: Creating a new session requires allocating session resources. At this point, there are two scenarios: either there are still resources available, or there are no session resources available.

[0051] Step S3: If there are still session resources, directly allocate a session entry.

[0052] Simply assign the update time on the session to the current time and add it to the end of the linked list of the corresponding aging queue.

[0053] In step S4, if there are no session resources, it is necessary to check whether the sessions pointed to by the head nodes of the three aging lists have reached their aging time (by comparing the session's update time plus its own aging time (2s, 30s, or 600s) with the current time). If none of the head nodes of the three lists have reached their aging time, it means that all resources are indeed occupied, and the allocation will fail, issuing an alert that no session resources are available. Conversely, if any session node has reached its aging time, its resources can be released, and then step S2 can be performed to re-apply for session resources.

[0054] In step S5, after the packet arrives at the firewall, an existing session is matched. At this point, the session cannot be used directly. Instead, it is necessary to first determine whether the session has reached its aging time. If it has reached its aging time, it should be released, and then the process should return to step S2 to re-request session resources. If it has not reached its aging time, the session's update time should be set to the current time, and then it should be removed from the aging list and reinserted at the end of the list. Subsequent sessions can then be used normally.

[0055] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, system, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, system, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, system, article, or apparatus that includes that element.

[0056] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A message-triggered session aging method, characterized in that, The method includes the following steps: Step S1: After the packet reaches the firewall, the first step is to check the hash to match the session. If the first packet cannot be matched, a new session needs to be created. Step S2: Create a new session, allocate session resources, and determine the resource allocation details; Step S3: When session resources are available, allocate a session entry, assign the update time of the session to the current time, and add it to the end of the linked list of the corresponding aging queue; In step S4, if there are no session resources, check whether the sessions pointed to by the head node of the aging list have reached their aging time. If none of the head nodes of the list have reached their aging time, it is determined that all resources are occupied, the allocation fails, and an alarm is issued that no session resources are available. If any session node has reached its aging time, its resources are released, and then return to step S2 to re-apply for session resources. In step S5, after the packet arrives at the firewall, an existing session is matched. First, it is determined whether the session has reached its aging time. If it hasn't, the session's update time is set to the current time, then it is removed from the aging list and reinserted at the end of the list, allowing subsequent sessions to be used normally. In step S2, session resource allocation includes two scenarios: available resources or no session resources. In step S5, if a session reaches its aging time, it is released, and the process returns to step S2 to re-apply for a session. The session queue storage structure includes a session hash bucket, a collision list, and an old session queue. Determining whether the session pointed to by the head node of the aging list has reached its aging time involves comparing the session's update time plus its own aging time with the current time.

2. The message-triggered session aging method according to claim 1, characterized in that, The sessions are stored using a hash structure.

3. The message-triggered session aging method according to claim 2, characterized in that, The session structure needs to store aging node nodes, which are used to associate the aging queues corresponding to the sessions.

4. The message-triggered session aging method according to claim 3, characterized in that, The aging queues are first classified according to aging time.

5. The message-triggered session aging method according to claim 4, characterized in that, Each queue in the aging queue is organized as a doubly linked circular list.

6. The message-triggered session aging method according to claim 5, characterized in that, The aging queue is sorted according to session update time, with the most recently updated session placed at the end of the linked list, and the head node of the linked list pointing to the session closest to the aging time.

Citation Information

Patent Citations

  • NAT session management method based on distributed system

    CN106790556A