Tunnel message processing method and device, electronic equipment and storage medium
Patent Information
- Application Number
- CN202210190358.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-28
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-02-28
AI Technical Summary
[0004]本申请实施例的目的在于提供一种隧道报文处理方法、装置、电子设备和存储介质,用以解决隧道封装报文冲击交换设备的CPU的问题
[0004]本申请实施例的目的在于提供一种隧道报文处理方法、装置、电子设备和存储介质,用以解决隧道封装报文冲击交换设备的CPU的问题。
Smart Images

Figure CN116708316B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication, and more specifically, to a tunnel message processing method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the continuous development of networks, tunneling technology is widely used in various networks. Tunneling technology enables two independent networks to communicate. During the initial construction of a tunnel network, network configuration changes, or when the tunnel is experiencing unstable fluctuations, the states at both ends of the tunnel will switch between Down and UP. The switching devices at both ends of the tunnel each handle the UP state of the tunnel; therefore, it is possible for a switching device at one end of the tunnel to be in the UP state, while the switching device at the other end is in the Down state. In this case, the switching device in the UP state will send tunnel encapsulation packets to the switching device at the other end of the tunnel.
[0003] Normally, a switch receiving a tunnel-encapsulated packet needs to decapsulate it and then forward it based on the packet's actual destination IP address. However, because the switch receiving the tunnel-encapsulated packet is in a Down state, it cannot decapsulate the packet, and the packet is forwarded as a regular Layer 3 packet. Simultaneously, since the outer destination IP address of the tunnel-encapsulated packet is the IP address of the switch in the Down state (as defined by the tunneling protocol), according to the switch's default logic, it assumes the packet needs to be processed by the Down state switch. Therefore, the packet is sent to the switch's CPU for processing. Since the actual destination IP address is not the switch's, the CPU ultimately discards the packet. When there are a large number of tunnel-encapsulated packets, sending a large number of these packets to the CPU for processing can overload the CPU, increasing CPU utilization and affecting the normal operation of the switch. Summary of the Invention
[0004] The purpose of this application is to provide a tunnel message processing method, apparatus, electronic device, and storage medium to solve the problem of tunnel encapsulated messages impacting the CPU of switching devices.
[0005] In a first aspect, this application provides a tunnel packet processing method applied to a switching device that sets up a tunnel. The method includes: receiving a tunnel encapsulation packet sent by a peer; determining that a decapsulation table corresponding to the tunnel is not saved; querying a preset ACL entry matching condition based on the outer information of the tunnel encapsulation packet to make the outer information match the matching condition; and discarding the packet through an execution action in the ACL entry.
[0006] In this embodiment, a tunnel encapsulation packet sent by the peer is received, and the system determines whether it has a tunnel decapsulation table. If it is determined that the corresponding tunnel decapsulation table is not stored, the system queries the matching conditions of preset ACL entries based on the outer information of the tunnel encapsulation packet to ensure that the outer information matches the conditions. The packet is then discarded through the execution action in the ACL entry. By discarding tunnel encapsulation packets when the switching device does not have a tunnel decapsulation table and by discarding tunnel encapsulation packets through the execution action in the ACL entry, undecapsulated tunnel encapsulation packets are avoided from being sent to the CPU for processing, thus reducing the impact on the CPU. Furthermore, compared to solving the CPU impact problem of tunnel encapsulation packets by setting private protocols on the switching devices at both ends of the tunnel, discarding undecapsulated tunnel encapsulation packets through ACL entries, thereby reducing the CPU impact, does not require that both switching devices at both ends of the tunnel support the corresponding private protocols, and can also reduce the coupling between the switching devices at both ends of the tunnel.
[0007] In an optional implementation, the matching condition for the preset ACL entry is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
[0008] In an optional implementation, the method further includes: determining a decapsulation table that stores the corresponding tunnel; querying a preset ACL entry for matching conditions based on the inner information of the tunnel encapsulated packet, so that the inner information cannot match the matching conditions; decapsulating the tunnel encapsulated packet according to the decapsulation table; and forwarding the tunnel encapsulated packet.
[0009] In this embodiment of the application, by means of the above method, when the switching device stores the tunnel encapsulated message, the tunnel encapsulated message is decapsulated and forwarded, thereby ensuring the normal forwarding of the tunnel encapsulated message.
[0010] In an optional implementation, the tunnel is one of a VXLAN tunnel, an IP-to-IP tunnel, or a GRE tunnel.
[0011] In an optional implementation, the tunnel is a VXLAN tunnel, the tunnel identification information is the protocol number and destination port number of the tunnel message, and the tunnel IP address of the switching device is the IP address of the switching device in the VXLAN tunnel.
[0012] Secondly, this application provides a tunnel packet processing device configured in a switching device that sets up a tunnel. The device includes: a receiving module for receiving tunnel encapsulation packets sent by the peer; and a discarding module for determining that the decapsulation table for the corresponding tunnel is not saved, querying a preset ACL entry matching condition based on the outer information of the tunnel encapsulation packet, so that the outer information matches the matching condition, and discarding the packet through the execution action in the ACL entry.
[0013] In an optional implementation, the matching condition for the preset ACL entry is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
[0014] In an optional implementation, the device further includes: a forwarding module, configured to determine a decapsulation table corresponding to the tunnel, query the matching conditions of the preset ACL entries according to the inner information of the tunnel encapsulated packet so that the inner information cannot match the matching conditions, decapsulate the tunnel encapsulated packet according to the decapsulation table, and forward the tunnel encapsulated packet.
[0015] In an optional implementation, the tunnel is one of a VXLAN tunnel, an IP-to-IP tunnel, or a GRE tunnel.
[0016] In an optional implementation, the tunnel is a VXLAN tunnel, the tunnel identification information is the protocol number and destination port number of the tunnel message, and the tunnel IP address of the switching device is the IP address of the switching device in the VXLAN tunnel.
[0017] Thirdly, this application provides an electronic device, including: a processor, a memory, and a bus; the processor and the memory communicate with each other through the bus; the memory stores program instructions that can be executed by the processor, and the processor can execute the method as described in any of the foregoing embodiments by calling the program instructions.
[0018] Fourthly, this application provides a storage medium on which computer program instructions are stored, which, when read and executed by a computer, perform the method described in any of the foregoing embodiments. Attached Figure Description
[0019] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 A flowchart of a tunnel message processing method provided in this application embodiment;
[0021] Figure 2 A structural block diagram of a tunnel message processing device provided in an embodiment of this application;
[0022] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0023] Icons: 200-Tunnel message processing device; 201-Receiving module; 202-Discarding module; 300-Electronic device; 301-Processor; 302-Communication interface; 303-Memory; 304-Bus. Detailed Implementation
[0024] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0025] Please see Figure 1 , Figure 1 This is a flowchart illustrating a tunnel message processing method provided in an embodiment of this application. The tunnel message processing method provided in this embodiment is applied to a switching device that sets up a tunnel. The tunnel message processing method may include the following steps:
[0026] Step 101: Receive the tunnel encapsulation message sent by the peer.
[0027] Step 102: Determine if the decapsulation table for the corresponding tunnel is not saved. Query the matching conditions of the preset ACL entries based on the outer information of the tunnel-encapsulated packet to ensure that the outer information matches the conditions. Then, discard the packet by executing the action in the ACL entry.
[0028] The above methods will be explained in detail below.
[0029] Step 101: Receive the tunnel encapsulation message sent by the peer.
[0030] In this embodiment, a tunnel is established between two switching devices. One switching device receives a tunnel encapsulation message sent by the other end (the switching device at the other end of the tunnel). It should be noted that in this embodiment, the two switching devices do not need to be configured with a proprietary protocol to ensure that both ends of the tunnel are in the UP state.
[0031] Specifically, the tunnel between the two switching devices can be one of a VXLAN (Virtual Extensible Local Area Network) tunnel, an IP-in-IP tunnel, or a GRE tunnel. Among these, an IP-in-IP tunnel primarily refers to a tunnel based on IP address encapsulation, including IPv4-in-IPv6, IPv6-in-IPv4, IPv4-in-IPv4, and IPv6-in-IPv6. This application does not specify which tunneling protocol the two switching devices should use to establish the tunnel.
[0032] Step 102: Determine if the decapsulation table for the corresponding tunnel is not saved. Query the matching conditions of the preset ACL entries based on the outer information of the tunnel-encapsulated packet to ensure that the outer information matches the conditions. Then, discard the packet by executing the action in the ACL entry.
[0033] In this embodiment of the application, after receiving the tunnel encapsulation message sent by the peer, the switching device determines whether it has stored the tunnel decapsulation table.
[0034] The switching device has pre-defined ACL (Access Control List) entries. When the switching device does not store a tunnel encapsulation table, it uses the outer information of the tunnel encapsulated packet to query the pre-defined ACL entries for matching conditions. The action of this ACL entry is to discard packets that meet the matching conditions. When the outer information of a tunnel encapsulated packet matches the conditions, the switching device will discard the tunnel encapsulated packet according to the action of the ACL entry. In this embodiment, the tunnel encapsulated packet is discarded when the switching device does not store a tunnel decapsulation table, avoiding sending undecapsulated tunnel encapsulated packets to the CPU for processing, thereby reducing the impact on the CPU. In addition, since the ACL entries are hardware resources of the switching device, when discarding tunnel encapsulated packets according to the ACL entries, the tunnel encapsulated packet will not be sent to the CPU of the switching device. Therefore, discarding tunnel encapsulated packets through ACL entries will not put processing pressure on the CPU.
[0035] Specifically, the preset ACL entry matching condition is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
[0036] The outer layer of a tunnel encapsulation packet is a tunnel header, added by the tunneling protocol before the original packet header when forwarding packets through a tunnel. This tunnel header carries tunnel identification information to characterize the tunnel type. According to the tunneling protocol, the destination IP address in the tunnel header is the tunnel IP address of the switching device receiving the tunnel encapsulation packet. Therefore, when querying the preset ACL entries for matching conditions based on the outer layer information of the tunnel encapsulation packet, the outer layer information of the tunnel encapsulation packet will match the preset ACL entries, thus causing the tunnel encapsulation packet to be discarded according to the preset ACL entry's execution action.
[0037] Furthermore, as an optional implementation method, the tunnel message processing method provided in this application also includes:
[0038] It is determined that the decapsulation table corresponding to the tunnel is stored. Based on the inner information of the tunnel encapsulation packet, the matching conditions of the preset ACL table entries are queried. When the inner information cannot match the conditions, the tunnel encapsulation packet is decapsulated according to the decapsulation table and then forwarded.
[0039] In this embodiment, when the switching device stores a tunnel encapsulation table, the inner information of the tunnel encapsulated packet is used to query the matching conditions of a preset ACL entry. It should be noted that the inner information of the tunnel encapsulated packet is the original packet header before the tunnel packet header is encapsulated according to the tunnel protocol. The original packet header does not include tunnel identification information; the destination IP address in the header is the IP address of the network device that actually receives the packet. Therefore, when querying the matching conditions of the preset ACL entry based on the inner information of the tunnel encapsulated packet, the inner information of the tunnel encapsulated packet will not match the preset ACL entry's matching conditions, and the tunnel encapsulated packet will not be discarded according to the preset ACL entry's execution action. Since the switching device stores a tunnel decapsulation table at this time, the switching device can decapsulate the tunnel encapsulated packet according to the tunnel decapsulation table, determine the IP address of the network device that actually receives the packet from the inner information, and forward the packet based on that IP address. It should be noted that the specific implementation method for decapsulating and forwarding the tunnel-encapsulated message according to the tunnel's decapsulation table can be found in existing technologies, and will not be elaborated upon here.
[0040] The following example will be used to explain the above steps in detail.
[0041] As an optional implementation, the tunnel between the two switching devices is a VXLAN tunnel. The tunnel identification information includes the protocol number and destination port number of the tunnel packet, and the tunnel IP address of the switching device is the IP address of the switching device within the VXLAN tunnel. According to the VXLAN tunnel protocol, the VXLAN tunnel protocol number is UDP, and the destination port number is 4789. Therefore, in this embodiment, the preset ACL entry matching conditions are: 1. The protocol number of the tunnel encapsulated packet header is UDP and the destination port number is 4789; 2. The destination IP address of the tunnel encapsulated packet is the tunnel IP address of the switching device.
[0042] When the switching device is not in the UP state, it does not store the tunnel decapsulation table. When it receives a tunnel encapsulation packet from the switching device at the other end of the tunnel, it determines that the switching device does not store the tunnel decapsulation table. Therefore, it queries the preset ACL entry matching condition based on the outer information of the tunnel encapsulation packet. If the outer information of the tunnel encapsulation packet matches the preset ACL entry matching condition, the tunnel encapsulation packet is discarded.
[0043] When the switching device is in UP state, it stores a tunnel decapsulation table. When it receives a tunnel encapsulation packet from the switching device at the other end of the tunnel, it checks the stored tunnel decapsulation table and queries the preset ACL entries for matching conditions based on the inner information of the tunnel encapsulation packet. If the inner information of the tunnel encapsulation packet does not match the preset ACL entries, the switching device decapsulates the tunnel encapsulation packet according to the tunnel decapsulation table and forwards it.
[0044] It should be noted that since dozens or hundreds of tunnels may be established between two switching devices, only one preset ACL entry needs to be issued for each type of tunnel. This will ensure that if the switching device does not have a tunnel decapsulation table for that type of tunnel, the tunnel encapsulation packets corresponding to that type of tunnel will be discarded. This will prevent the tunnel encapsulation packets corresponding to that type of tunnel from overwhelming the CPU, thus solving the problem of tunnel encapsulation packets overwhelming the switching device's CPU, reducing the processing pressure on the switching device's CPU, and improving the stability and reliability of the entire network.
[0045] In summary, this application provides a tunnel packet processing device that receives tunnel encapsulation packets sent by the peer and determines whether it has stored a tunnel decapsulation table. If it determines that it does not have a corresponding tunnel decapsulation table, it queries a preset ACL entry for matching conditions based on the outer information of the tunnel encapsulation packet to ensure the outer information matches the conditions, and then discards the packet through the execution action in the ACL entry. By discarding tunnel encapsulation packets when the switching device does not have a tunnel decapsulation table and by discarding tunnel encapsulation packets through the execution action in the ACL entry, it avoids sending undecapsulated tunnel encapsulation packets to the CPU for processing, thereby reducing the impact on the CPU. Furthermore, compared to solving the CPU impact problem of tunnel encapsulation packets by setting private protocols on the switching devices at both ends of the tunnel, discarding undecapsulated tunnel encapsulation packets through ACL entries, thereby reducing the CPU impact, does not require that both switching devices at both ends of the tunnel support the corresponding private protocols, and can also reduce the coupling between the switching devices at both ends of the tunnel.
[0046] Based on the same inventive concept, this application also provides a tunnel message processing device in its embodiments. Please refer to... Figure 2 , Figure 2 This is a structural block diagram of a tunnel packet processing device provided in an embodiment of this application. The tunnel packet processing device 200 is configured in a switching device that provides a tunnel. The tunnel packet processing device 200 may include:
[0047] The receiving module 201 is used to receive tunnel encapsulation messages sent by the peer.
[0048] The discard module 202 is used to determine that the decapsulation table corresponding to the tunnel is not saved, query the preset ACL table entry matching conditions according to the outer layer information of the tunnel encapsulated packet, so that the outer layer information matches the matching conditions, and discard the packet through the execution action in the ACL table entry.
[0049] In an optional implementation, the matching condition for the preset ACL entry is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
[0050] In an optional embodiment, the device further includes: a forwarding module, configured to determine a decapsulation table corresponding to the tunnel, query a preset ACL entry for matching conditions based on the inner information of the tunnel encapsulated packet so that the inner information cannot match the matching conditions, decapsulate the tunnel encapsulated packet according to the decapsulation table, and forward the tunnel encapsulated packet.
[0051] In an optional implementation, the tunnel is one of a VXLAN tunnel, an IP-to-IP tunnel, or a GRE tunnel.
[0052] In an optional implementation, the tunnel is a VXLAN tunnel, the tunnel identification information is the protocol number and destination port number of the tunnel message, and the tunnel IP address of the switching device is the IP address of the switching device in the VXLAN tunnel.
[0053] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of an electronic device 300 according to an embodiment of this application. The electronic device 300 includes: at least one processor 301, at least one communication interface 302, at least one memory 303, and at least one bus 304. The bus 304 is used to enable direct communication between these components. The communication interface 302 is used for signaling or data communication with other node devices. The memory 303 stores machine-readable instructions executable by the processor 301. When the electronic device 300 is running, the processor 301 communicates with the memory 303 via the bus 304. When the machine-readable instructions are invoked by the processor 301, the tunnel message processing method described above is executed.
[0054] Processor 301 can be an integrated circuit chip with signal processing capabilities. The processor 301 can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.
[0055] The memory 303 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.
[0056] Understandable. Figure 3 The structure shown is for illustrative purposes only; the electronic device 300 may also include components that are more advanced than those shown. Figure 3 The more or fewer components shown, or having the same Figure 3 The different configurations shown. Figure 3 The components shown can be implemented using hardware, software, or a combination thereof. In the embodiments of this application, electronic device 300 can be, but is not limited to, physical devices such as desktop computers, laptops, smartphones, smart wearable devices, and in-vehicle devices, or virtual devices such as virtual machines. Furthermore, electronic device 300 is not necessarily a single device; it can be a combination of multiple devices, such as a server cluster, etc.
[0057] Furthermore, this application embodiment also provides a computer storage medium storing a computer program, which, when run by a computer, executes the steps of the tunnel message processing method as described in the above embodiment.
[0058] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.
[0059] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0060] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0061] It should be noted that if the function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0062] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.
[0063] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A tunnel message processing method, characterized in that, A switching device used for setting up tunnels, wherein the switching device has preset ACL entries, the matching conditions of the ACL entries are matched with the outer information of the tunnel encapsulated packets, and the execution action of the ACL entries is to discard packets that meet the matching conditions, the method includes: Receive tunnel encapsulation messages sent by the peer; If it is determined that the decapsulation table corresponding to the tunnel is not saved, the matching conditions of the ACL entry are queried according to the outer information of the tunnel-encapsulated packet so that the outer information matches the matching conditions. The packet is then discarded through the execution action in the ACL entry. The outer information of the tunnel-encapsulated packet is the tunnel header encapsulated before the header of the original packet. If it is determined that a decapsulation table corresponding to the tunnel is stored, the matching conditions of the ACL entry are queried according to the inner information of the tunnel encapsulated packet so that the inner information cannot match the matching conditions. The tunnel encapsulated packet is decapsulated according to the decapsulation table and forwarded. The inner information of the tunnel encapsulated packet is the original packet header of the packet before the tunnel packet header is encapsulated.
2. The method according to claim 1, characterized in that, The matching condition for the ACL entry is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
3. The method according to claim 1 or 2, characterized in that, The tunnel is one of VXLAN tunnel, IP in IP tunnel, or GRE tunnel.
4. The method according to claim 3, characterized in that, The tunnel is a VXLAN tunnel, the tunnel identification information is the protocol number and destination port number of the tunnel message, and the tunnel IP address of the switching device is the IP address of the switching device in the VXLAN tunnel.
5. A tunnel message processing device, characterized in that, A switching device configured to set up a tunnel, the switching device having preset ACL entries, the matching conditions of the ACL entries matching the outer layer information of the tunnel encapsulated packets, the execution action of the ACL entries being to discard packets that meet the matching conditions; the device includes: The receiving module is used to receive tunnel-encapsulated messages sent by the peer. The discard module is used to, if it is determined that the decapsulation table corresponding to the tunnel is not saved, query the matching conditions of the ACL entry according to the outer information of the tunnel-encapsulated packet, so that the outer information matches the matching conditions, and discard the packet through the execution action in the ACL entry, wherein the outer information of the tunnel-encapsulated packet is the tunnel packet header encapsulated before the packet header of the original packet; The forwarding module is used to, if it is determined that a decapsulation table corresponding to the tunnel is stored, query the matching conditions of the ACL entry according to the inner information of the tunnel encapsulated packet so that the inner information cannot match the matching conditions, decapsulate the tunnel encapsulated packet according to the decapsulation table, and forward the tunnel encapsulated packet. The inner information of the tunnel encapsulated packet is the original packet header of the packet before the tunnel packet header is encapsulated.
6. The apparatus according to claim 5, characterized in that, The matching condition for the ACL entry is that the header of the tunnel encapsulated message includes tunnel identification information and the destination IP address of the tunnel encapsulated message is the tunnel IP address of the switching device.
7. An electronic device, characterized in that, include: Processor, memory, and bus; The processor and the memory communicate with each other via the bus; The memory stores program instructions that can be executed by the processor, and the processor can execute the method as described in any one of claims 1-4 by calling the program instructions.
8. A storage medium, characterized in that, The storage medium stores computer program instructions, which, when read and executed by a computer, perform the method as described in any one of claims 1-4.