Message forwarding method and device, storage medium and electronic equipment
Patent Information
- Application Number
- CN202310781590.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-28
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2043-06-28
AI Technical Summary
[0004]本发明实施例提供了一种报文转发方法、装置、存储介质及电子设备,以至少解决相关技术中处理器对报文的转发效率不理想的技术问题
[0015] In this embodiment of the invention, a target packet is received; the number of processors included in the forwarding device is determined; based on the target packet and the number of processors, a target processor in the forwarding device is determined for processing the target packet; and the target processor is used to forward the target packet to a predetermined network. This achieves the goal of improving the utilization rate of processors in the forwarding device, realizing the technical effect of improving packet forwarding efficiency, and thus solving the technical problem of unsatisfactory packet forwarding efficiency of processors in related technologies.
Smart Images

Figure CN116708329B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and more specifically, to a message forwarding method, apparatus, storage medium, and electronic device. Background Technology
[0002] VPN (Virtual Private Network) is a technology that establishes a private network over a public network for encrypted communication. For VPN communication to occur, the initial packets sent by the sending device need to be encapsulated. The encapsulation device and the forwarding device are the two endpoints of the VPN tunnel. The encapsulation device encapsulates the incoming traffic data packets and transmits them through the VPN tunnel to the forwarding device for processing. Regardless of whether the packets originate from the same sending device, they will all undergo the same encapsulation process. This results in packets from different sending devices being forwarded by the same pre-defined processor, leading to low processor utilization and inefficient packet processing in the forwarding device.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This invention provides a message forwarding method, apparatus, storage medium, and electronic device to at least solve the technical problem of unsatisfactory message forwarding efficiency of processors in related technologies.
[0005] According to one aspect of the present invention, a message forwarding method is provided, comprising: receiving a target message; determining the number of processors included in a forwarding device; determining a target processor in the forwarding device for processing the target message based on the target message and the number of processors; and forwarding the target message to a predetermined network using the target processor.
[0006] Furthermore, determining the target processor in the forwarding device for processing the target packet based on the target packet and the quantity includes: determining a target vector based on the target packet; performing a modulo operation on the target vector using the quantity to obtain a first modulo result corresponding to the target packet; determining the identifiers corresponding to the number of processors in the forwarding device; and determining the target processor whose identifier matches the first modulo result among the number of processors.
[0007] Furthermore, before receiving the target message, the encapsulation device performs the following processing: receiving an initial message; determining the hash value and random number vector corresponding to the initial message; modifying the random number vector based on the quantity and hash value to obtain a target vector; encapsulating the initial message and the target vector to obtain a target message, and sending the target message to the forwarding device.
[0008] Furthermore, the step of modifying the random number vector based on the quantity and hash value to obtain the target vector includes: using the quantity to perform modulo processing on the hash value to obtain a second modulo result; using the quantity to perform modulo processing on the random number vector to obtain a third modulo result; and modifying the random number vector based on the second modulo result and the third modulo result to obtain the target vector.
[0009] Furthermore, determining the hash value corresponding to the initial message includes: determining the first port number of the sending device corresponding to the initial message, the first Internet Protocol address of the sending device, the second port number of the receiving device corresponding to the initial message, the second Internet Protocol address of the receiving device, and the protocol number corresponding to the initial message; and determining the hash value based on the first port number, the first Internet Protocol address, the second port number, the second Internet Protocol address, and the protocol number.
[0010] Furthermore, determining the hash value and random number vector corresponding to the initial message includes: determining whether the virtual private network tunnel between the encapsulation device and the forwarding device supports a predetermined function of generating a hash value as an identifier for the message; if the virtual private network tunnel supports the predetermined function, then determining the hash value and the random number vector.
[0011] Furthermore, the method further includes: if the virtual private network tunnel does not support the predetermined function, then encapsulating the initial message to obtain a first message, and sending the first message to the forwarding device, wherein the first message is forwarded to the predetermined network by a predetermined processor in the forwarding device.
[0012] According to another aspect of the present invention, a packet forwarding apparatus is provided, comprising: a receiving module for receiving a target packet; a determining module for determining the number of processors included in a forwarding device; an allocation module for determining a target processor in the forwarding device for processing the target packet based on the target packet and the number of processors; and a forwarding module for forwarding the target packet to a predetermined network using the target processor.
[0013] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, and the computer program is configured to execute the above-described message forwarding method at runtime.
[0014] According to another aspect of the present invention, an electronic device is provided, comprising: one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement any of the packet forwarding methods described above.
[0015] In this embodiment of the invention, a target packet is received; the number of processors included in the forwarding device is determined; based on the target packet and the number of processors, a target processor in the forwarding device is determined for processing the target packet; and the target processor is used to forward the target packet to a predetermined network. This achieves the goal of improving the utilization rate of processors in the forwarding device, realizing the technical effect of improving packet forwarding efficiency, and thus solving the technical problem of unsatisfactory packet forwarding efficiency of processors in related technologies. Attached Figure Description
[0016] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:
[0017] Figure 1 This is a schematic diagram of an optional message forwarding method provided by relevant technologies;
[0018] Figure 2 This is a flowchart of an optional message forwarding method provided according to an embodiment of the present invention;
[0019] Figure 3 This is a schematic diagram of the message structure of an optional message forwarding method provided according to an embodiment of the present invention;
[0020] Figure 4 This is an application diagram of an optional message forwarding method provided according to an embodiment of the present invention;
[0021] Figure 5 This is a schematic diagram of an optional message forwarding device provided according to an embodiment of the present invention. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] For ease of description, the following explains some of the nouns or terms used in the embodiments of this application:
[0025] VPN (Virtual Private Network) is a technology that establishes a private network over a public network for encrypted communication.
[0026] VPN tunneling technology is a technique used to implement Virtual Private Networks. VPNs require encapsulation of raw packets; traffic between two VPN endpoints is encapsulated into packets carrying VPN traffic. Generally, network devices process data forwarding by performing hash operations on source and destination addresses, source and destination port numbers, etc., and then assigning the data to the corresponding processor (CPU, Central Processing Unit) for processing.
[0027] Figure 1 This is a schematic diagram illustrating an optional message forwarding method provided by relevant technologies, in such cases... Figure 1 As shown, there is only one VPN tunnel between the two endpoints. The encapsulation device has three data streams, which are encapsulated by CPU1, CPU2, and CPU3 respectively, resulting in the same type of VPN traffic. When sent to the forwarding device, this same type of VPN traffic corresponds to a designated CPU for processing. Because the forwarding device uses the encapsulation method described in relevant technologies, the packets within the encapsulated VPN traffic have identical hash values, and are all processed accordingly. Figure 1 The CPU2 specified in the code cannot take advantage of the multiple CPUs or multiple devices included in the forwarding device, resulting in a performance bottleneck and insufficient packet processing efficiency.
[0028] A related technology (application number: 201910736381.2) discloses a method to improve packet forwarding efficiency by using a dedicated acceleration card. However, this dedicated acceleration card is very expensive and requires customized hardware support, which makes it not very versatile and limits the use of encapsulation and forwarding equipment.
[0029] Another related technology (application number: 202210843953.9) discloses a method for balancing the CPU load of IPsec VPN. It uses a round-robin distribution method to process packets transmitted from the same data stream using different CPUs. Since the processing time of different CPUs is different, a time difference is caused between packets. The load balancing method in the related technology will lead to the problem of out-of-order packets.
[0030] Another related technology (application number: 202010449924.5) discloses a method for allocating CPUs based on CPU utilization in a forwarding device. If the current CPU utilization exceeds 90% and there are CPUs with utilization below 50%, the first CPU with utilization not exceeding 50% is selected as the destination CPU, and the packet is sent to the shared queue of the destination CPU for plaintext packet encryption. This method results in uneven CPU utilization and poor decryption performance.
[0031] It should be noted that all relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this invention are information and data authorized by the user or fully authorized by all parties. For example, this system has an interface with the relevant user or organization. Before obtaining relevant information, it needs to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving consent from the aforementioned user or organization.
[0032] Example 1
[0033] According to an embodiment of the present invention, a method embodiment for message forwarding is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0034] Figure 2 This is a flowchart of an optional message forwarding method according to an embodiment of the present invention, such as... Figure 2 As shown, the executing entity is the forwarding device, and the method includes the following steps:
[0035] Step S202: Receive the target message;
[0036] It is understandable that when a forwarding device receives a target packet to be forwarded, the processor in the forwarding device will encrypt and decrypt the target packet before forwarding it to the intended network. Therefore, if the processor in the forwarding device has an uneven load, it will cause a decrease in the efficiency of packet forwarding.
[0037] Optionally, the target message is encapsulated using a predetermined format. This predetermined format ensures that the modulo result of the target vector corresponding to the message in the data stream is the same, thereby ensuring that messages in the same data stream will be processed by the same processor, thus guaranteeing the message-in-order transmission method.
[0038] Step S204: Determine the number of processors included in the forwarding device;
[0039] It is understood that the forwarding device includes processing for packet processing. In contrast to the related technologies that specify a processor to process the same type of VPN traffic, this embodiment of the invention needs to determine the number of processors and select the processor.
[0040] Step S206: Based on the target message and the quantity, determine the target processor in the forwarding device used to process the target message;
[0041] It is understandable that a forwarding device can determine the target processor for processing the target packet based on the target packet and the number of processors it includes. The selection of the target processor is calculated, not based on methods specified in related technologies or random selection. Through this process, since packets within the same data stream as the target packet need to be transmitted in order, and packets within the same data stream correspond to the same target processor as the target packet, the technical effect of preventing out-of-order packet transmission can be achieved.
[0042] In one optional embodiment, determining the target processor in the forwarding device for processing the target packet based on the target packet and the quantity includes: determining a target vector based on the target packet; performing a modulo operation on the target vector using the quantity to obtain a first modulo result corresponding to the target packet; determining the identifiers corresponding to the number of processors in the forwarding device; and determining the target processor whose identifier matches the first modulo result among the number of processors.
[0043] It is understandable that the target packet carries a target vector for identification. After obtaining the target vector, the number of processors is used to perform a modulo operation on the target vector to obtain the first modulo result corresponding to the target packet. The forwarding device has a certain number of processors, each corresponding to its own identifier. The processor corresponding to the identifier that matches the first modulo result is determined as the target processor for forwarding the target packet. Through the above processing, the selection of the target processor depends on the first modulo result, which can be considered as the remainder obtained by taking the number of processors as the modulo of the target vector. This remainder is a positive integer, enabling matching with the processor identifier. Furthermore, the fact that the modulo results of target vectors in the same data stream are the same does not mean that the target vectors in the data stream must be identical. As long as the encapsulation method used ensures that the modulo results are the same, it guarantees that data streams from the same user terminal are processed by the same processor, avoiding packet out-of-order processing.
[0044] Optionally, the target vector may carry information such as a hash value for unique identification.
[0045] Step S208: The target message is forwarded to the predetermined network using the target processor described above.
[0046] It is understandable that after the forwarding device determines the target processor for forwarding the target packet, the target packet is forwarded to the predetermined network through the target processor.
[0047] In an optional embodiment, before receiving the target message, the encapsulation device performs the following processing: receiving an initial message; determining the hash value and random number vector corresponding to the initial message; modifying the random number vector based on the quantity and hash value to obtain a target vector; encapsulating the initial message and the target vector to obtain a target message, and sending the target message to the forwarding device.
[0048] It is understandable that the execution entity is the encapsulation device. To ensure that packets within the same data stream can be assigned to the same processor at the forwarding device end, the encapsulation method must guarantee that the modulo value obtained based on the target packet is the same, thereby ensuring that the processor matching the identifier is the same. Therefore, for the encapsulation device, the packet sent from the user terminal's data stream is first used as the initial packet. The initial packet needs to be encapsulated by the encapsulation device before being transmitted to the forwarding device. After receiving the initial packet, the hash value and random number vector corresponding to the initial packet are determined. The hash value is used to identify the initial packet, and the random number vector is the initialization vector (IV vector), which is randomly generated. Based on the number of processors included in the forwarding device and the hash value generated by the encapsulation device for the initial packet, the random number vector is modified to obtain the target vector. The encapsulation device encapsulates the initial packet carrying traffic data and the target vector generated for it to form the target packet. The encapsulation device sends the target packet to the forwarding device, which uses it to determine the target processor.
[0049] Optionally, a VPN tunnel is set up between the encapsulation device and the forwarding device. The tunnel is an IPSec tunnel. When negotiating the IPSec SA (security negotiation parameters) at both ends of the IPSec tunnel (encapsulation device and forwarding device), the encapsulation device detects whether the other end supports the IV Hash function. The IV Hash function is a unique identifier for packets (Hash is a hash value). When both ends support this function, the encapsulation device obtains the number of processors of the forwarding device.
[0050] In one optional embodiment, the above-mentioned modification of the random number vector based on the quantity and hash value to obtain the target vector includes: using the quantity to perform modulo processing on the hash value to obtain a second modulo result; using the quantity to perform modulo processing on the random number vector to obtain a third modulo result; and modifying the random number vector based on the second modulo result and the third modulo result to obtain the target vector.
[0051] It can be understood that the encapsulation device obtains the number of processors in the forwarding device, and uses this number to perform modulo operations on the hash value generated from the initial packet, obtaining a second modulo result. Furthermore, the encapsulation device also uses this number to perform modulo operations on the random number vector generated from the initial packet, obtaining a third modulo result. Based on the second and third modulo results, the random number vector is corrected to obtain the target vector. The target vector obtained in this way ensures that the target vector and the hash value generated from the initial packet have the same modulo result on the forwarding device side.
[0052] Optionally, the target message mentioned above is in ESP (Encapsulating Security Payload) message format, which is a data encapsulation protocol in the IPsec architecture. Figure 3 This is a schematic diagram of the message structure of an optional message forwarding method provided according to an embodiment of the present invention, as shown below. Figure 3 As shown, the ESP message format includes the Security Parameter Index (SPI), sequence number, random number vector (i.e., initialization vector IV), payload data, pad data, pad length, next message header, and authentication data.
[0053] Optionally, the random number vector is denoted as IV, the number of processors in the forwarding device is denoted as QUEUE, and the hash value of the initial packet is denoted as HASH1. The IV is corrected in the following way to obtain the target vector, denoted as IV. NEW :
[0054] IV NEW =(HASH1%QUEUE)-(IV%QUEUE)+IV.
[0055] Wherein, “%” represents the modulo operation, HASH1%QUEUE is the second modulo result mentioned above, and IV%QUEUE is the third modulo result mentioned above.
[0056] In one optional embodiment, determining the hash value corresponding to the initial message includes: determining the first port number of the sending device corresponding to the initial message, the first Internet Protocol address of the sending device, the second port number of the receiving device corresponding to the initial message, the second Internet Protocol address of the receiving device, and the protocol number corresponding to the initial message; and determining the hash value based on the first port number, the first Internet Protocol address, the second port number, the second Internet Protocol address, and the protocol number.
[0057] It's understandable that within the same data stream, the sending and receiving devices, and the protocol number used are all the same. Therefore, the hash values generated within the same data stream will be identical because the range for calculating hash values is the same. First, it's necessary to determine the first port number and first Internet Protocol address (IP address) of the initial message sending device, and the second port number and second Internet Protocol address of the initial message receiving device, along with the corresponding protocol number for the initial message. Using the first port number, first Internet Protocol address, second port number, second Internet Protocol address, and protocol number as the range for hash calculation, the hash value of the initial message is obtained.
[0058] Optionally, the protocol used in the above initial message is IPsec.
[0059] Optionally, the first port number is denoted as srcport, the first Internet Protocol address as srcaddr, the second port number as dstport, the second Internet Protocol address as dstaddr, and the protocol number as protocol. The hash algorithm used can be one or more combinations (including concatenated or parallel algorithms), such as MD5, SHA256, etc., and is denoted as HASH(*). The hash value of the initial message is denoted as HASH1, and can be expressed mathematically as follows:
[0060] HASH1=HASH(srcaddr,srcport,dstaddr,dstport,protocol).
[0061] In an optional embodiment, determining the hash value and random number vector corresponding to the initial message includes: determining whether the virtual private network tunnel between the encapsulation device and the forwarding device supports a predetermined function of generating a hash value as an identifier for the message; if the virtual private network tunnel supports the predetermined function, then determining the hash value and the random number vector.
[0062] It is understandable that before starting to process the random number vector, it is necessary to first determine whether the virtual private network tunnel between the encapsulation device and the aforementioned forwarding device supports the pre-defined function of generating a hash value as an identifier for the packet. The aforementioned pre-defined function can be the IV Hash function. Only if the aforementioned pre-defined function is supported is it necessary to further determine the hash value and random number vector of the initial packet in order to generate the target packet.
[0063] In an optional embodiment, the method further includes: if the virtual private network tunnel does not support the predetermined function, encapsulating the initial message to obtain a first message, and sending the first message to the forwarding device, wherein the first message is forwarded to the predetermined network by a predetermined processor in the forwarding device.
[0064] It is understandable that, even without the support for pre-defined functions, the encapsulation device still needs to reassemble the initial message, but using a different encapsulation method to obtain the first message. After the first message is sent to the forwarding device, it is processed by a pre-defined processor, rather than by selecting a processor for load balancing.
[0065] Through the above steps S202 to S208, the utilization rate of the processor in the forwarding device can be improved, the technical effect of improving the packet forwarding efficiency can be achieved, and the technical problem of unsatisfactory packet forwarding efficiency of the processor in related technologies can be solved.
[0066] Based on the above embodiments and optional embodiments, the present invention proposes an optional implementation method, specifically comprising the following steps. Figure 4 This is an application diagram of an optional message forwarding method provided by an embodiment of the present invention, such as... Figure 4 As shown, this is applied to both the encapsulation device and the forwarding device. The encapsulation device and the forwarding device are connected via a VPN tunnel, specifically an IPsec tunnel. The encapsulation device receives multiple data streams from multiple user terminals. The traffic data in the data streams is carried in the initial packets and needs to be encapsulated by the encapsulation device before passing through the IPsec tunnel, where it is received and processed by the forwarding device.
[0067] Step S1: The initial message arrives at the encapsulation device.
[0068] Step S2: The encapsulation device and the forwarding device negotiate IPSec SA. If the IPsec tunnel has IV Hash functionality, proceed to steps S3 to S6. If the IPsec tunnel does not have IV Hash functionality, proceed to step S7.
[0069] Step S3: The encapsulation device calculates the hash value of the initial message. The first port number of the sending device is denoted as srcport, and the first Internet Protocol address is denoted as srcaddr. The second port number of the receiving device is denoted as dstport, and the second Internet Protocol address is denoted as dstaddr. The protocol number corresponding to the initial message is denoted as protocol. The hash algorithm used can be MD5. The hash value of the initial message (denoted as HASH1) can be obtained using the following mathematical expression:
[0070] HASH1=HASH(srcaddr,srcport,dstaddr,dstport,protocol).
[0071] Step S4: The packaging device generates a string of random numbers as a random number vector (denoted as IV, i.e., initialization vector).
[0072] Step S5: The encapsulation device corrects the random number vector to generate the target vector. The number of processors in the aforementioned forwarding device is denoted as QUEUE. The IV is corrected using the following method to obtain the target vector, denoted as IV. NEW :
[0073] IV NEW =(HASH1%QUEUE)-(IV%QUEUE)+IV.
[0074] Step S6: The encapsulation device encapsulates the initial message and the target vector to obtain the target message, and sends it to the forwarding device. Then, step S8 is executed.
[0075] In step S7, if the IPsec tunnel does not have IV Hash functionality, the initial packet is encapsulated into a first packet for processing by a pre-defined processor in the forwarding device.
[0076] In step S8, after receiving the target packet, the forwarding device can determine the target processor. Based on the target packet, the target vector can be determined. The forwarding device uses the number of processors it includes to perform a modulo operation on the target vector obtained above, and the processor identifier that matches the modulo result (i.e., the first modulo result) is taken as the target processor.
[0077] Step S9: The target processor forwards the target message to the predetermined network, so that the receiving device in the predetermined network receives the target message.
[0078] The above optional implementation methods achieve at least the following effects: An encapsulation method is provided, allowing packets from the same data stream originating from the same user terminal to be assigned to the same processor for processing, avoiding out-of-order packet transmission. For different data streams from different user terminals, this implementation method uses modulo of the corresponding target vector to assign them to different processors. Compared to related technologies that encapsulate different data streams into the same VPN traffic and then assign them to a specific processor, this method offers better packet processing efficiency. In scenarios with a small number of tunnels (the number of tunnels is far less than the number of processors), it is necessary to maximize processor utilization. Packets can be assigned to matching processors using modulo of the target packet, rather than being assigned to a single processor. This effectively reduces hardware bottlenecks and improves the utilization of processors in forwarding devices.
[0079] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.
[0080] Example 2
[0081] This embodiment also provides a message forwarding device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the terms "module" and "device" can refer to a combination of software and / or hardware that performs a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, hardware implementations, or a combination of software and hardware, are also possible and contemplated.
[0082] According to embodiments of the present invention, an apparatus embodiment for implementing a message forwarding method is also provided. Figure 5 This is a schematic diagram of a message forwarding device according to an embodiment of the present invention, such as... Figure 5 As shown, the above-mentioned message forwarding device includes a receiving module 502, a determining module 504, an allocation module 506, and a forwarding module 508. The device will be described below.
[0083] Receiver module 502 is used to receive target messages;
[0084] It is understandable that when a forwarding device receives a target packet to be forwarded, the processor in the forwarding device will encrypt and decrypt the target packet before forwarding it to the intended network. Therefore, if the processor in the forwarding device has an uneven load, it will cause a decrease in the efficiency of packet forwarding.
[0085] Optionally, the target message is encapsulated using a predetermined format. This predetermined format ensures that the modulo result of the target vector corresponding to the message in the data stream is the same, thereby ensuring that messages in the same data stream will be processed by the same processor, thus guaranteeing the message-in-order transmission method.
[0086] The determination module 504 is used to determine the number of processors included in the forwarding device;
[0087] It is understood that the forwarding device includes processing for packet processing. In contrast to the related technologies that specify a processor to process the same type of VPN traffic, this embodiment of the invention needs to determine the number of processors and select the processor.
[0088] The allocation module 506 is used to determine the target processor in the forwarding device for processing the target packet based on the target packet and the quantity.
[0089] It is understandable that a forwarding device can determine the target processor for processing the target packet based on the target packet and the number of processors it includes. The selection of the target processor is calculated, not based on methods specified in related technologies or random selection. Through this process, since packets within the same data stream as the target packet need to be transmitted in order, and packets within the same data stream correspond to the same target processor as the target packet, the technical effect of preventing out-of-order packet transmission can be achieved.
[0090] In an optional embodiment, the allocation module 506 is further configured to: determine a target vector based on the target message; perform modulo processing on the target vector using the quantity to obtain a first modulo result corresponding to the target message; determine the identifiers corresponding to the quantity of processors in the forwarding device; and determine the target processor whose identifier matches the first modulo result among the quantity of processors.
[0091] It is understandable that the target packet carries a target vector for identification. After obtaining the target vector, the number of processors is used to perform a modulo operation on the target vector to obtain the first modulo result corresponding to the target packet. The forwarding device has a certain number of processors, each corresponding to its own identifier. The processor corresponding to the identifier that matches the first modulo result is determined as the target processor for forwarding the target packet. Through the above processing, the selection of the target processor depends on the first modulo result, which can be considered as the remainder obtained by taking the number of processors as the modulo of the target vector. This remainder is a positive integer, enabling matching with the processor identifier. Furthermore, the fact that the modulo results of target vectors in the same data stream are the same does not mean that the target vectors in the data stream must be identical. As long as the encapsulation method used ensures that the modulo results are the same, it guarantees that data streams from the same user terminal are processed by the same processor, avoiding packet out-of-order processing.
[0092] Optionally, the target vector may carry information such as a hash value for unique identification.
[0093] The forwarding module 508 is used to forward the target message to the predetermined network using the target processor.
[0094] It is understandable that after the forwarding device determines the target processor for forwarding the target packet, the target packet is forwarded to the predetermined network through the target processor.
[0095] In an optional embodiment, the above-mentioned apparatus is further configured to: receive an initial message; determine the hash value and random number vector corresponding to the initial message; modify the random number vector based on the quantity and hash value to obtain a target vector; encapsulate the initial message and the target vector to obtain a target message; and send the target message to the forwarding device.
[0096] It is understandable that the execution entity is the encapsulation device. To ensure that packets within the same data stream can be assigned to the same processor at the forwarding device end, the encapsulation method must guarantee that the modulo value obtained based on the target packet is the same, thereby ensuring that the processor matching the identifier is the same. Therefore, for the encapsulation device, the packet sent from the user terminal's data stream is first used as the initial packet. The initial packet needs to be encapsulated by the encapsulation device before being transmitted to the forwarding device. After receiving the initial packet, the hash value and random number vector corresponding to the initial packet are determined. The hash value is used to identify the initial packet, and the random number vector is the initialization vector (IV vector), which is randomly generated. Based on the number of processors included in the forwarding device and the hash value generated by the encapsulation device for the initial packet, the random number vector is modified to obtain the target vector. The encapsulation device encapsulates the initial packet carrying traffic data and the target vector generated for it to form the target packet. The encapsulation device sends the target packet to the forwarding device, which uses it to determine the target processor.
[0097] Optionally, a VPN tunnel is set up between the encapsulation device and the forwarding device. The tunnel is an IPSec tunnel. When negotiating the IPSec SA (security negotiation parameters) at both ends of the IPSec tunnel (encapsulation device and forwarding device), the encapsulation device detects whether the other end supports the IV Hash function. The IV Hash function is a unique identifier for packets (Hash is a hash value). When both ends support this function, the encapsulation device obtains the number of processors of the forwarding device.
[0098] In an optional embodiment, the above-described apparatus is further configured to: perform modulo processing on the hash value using the above-described quantity to obtain a second modulo result; perform modulo processing on the random number vector using the above-described quantity to obtain a third modulo result; and modify the random number vector based on the second modulo result and the third modulo result to obtain the target vector.
[0099] It can be understood that the encapsulation device obtains the number of processors in the forwarding device, and uses this number to perform modulo operations on the hash value generated from the initial packet, obtaining a second modulo result. Furthermore, the encapsulation device also uses this number to perform modulo operations on the random number vector generated from the initial packet, obtaining a third modulo result. Based on the second and third modulo results, the random number vector is corrected to obtain the target vector. The target vector obtained in this way ensures that the target vector and the hash value generated from the initial packet have the same modulo result on the forwarding device side.
[0100] Optionally, the target message mentioned above is in ESP (Encapsulating Security Payload) format. ESP is a data encapsulation protocol in the IPsec architecture, such as... Figure 3 As shown, the ESP message format includes the Security Parameter Index (SPI), sequence number, random number vector (i.e., initialization vector IV), payload data, pad data, pad length, next message header, and authentication data.
[0101] Optionally, the random number vector is denoted as IV, the number of processors in the forwarding device is denoted as QUEUE, and the hash value of the initial packet is denoted as HASH1. The IV is corrected in the following way to obtain the target vector, denoted as IV. NEW :
[0102] IV NEW =(HASH1%QUEUE)-(IV%QUEUE)+IV.
[0103] Wherein, “%” represents the modulo operation, HASH1%QUEUE is the second modulo result mentioned above, and IV%QUEUE is the third modulo result mentioned above.
[0104] In an optional embodiment, the apparatus is further configured to: determine the first port number of the sending device corresponding to the initial message, the first Internet Protocol address of the sending device, the second port number of the receiving device corresponding to the initial message, the second Internet Protocol address of the receiving device, and the protocol number corresponding to the initial message; and determine the hash value based on the first port number, the first Internet Protocol address, the second port number, the second Internet Protocol address, and the protocol number.
[0105] It's understandable that within the same data stream, the sending and receiving devices, and the protocol number used are all the same. Therefore, the hash values generated within the same data stream will be identical because the range for calculating hash values is the same. First, it's necessary to determine the first port number and first Internet Protocol address (IP address) of the initial message sending device, and the second port number and second Internet Protocol address of the initial message receiving device, along with the corresponding protocol number for the initial message. Using the first port number, first Internet Protocol address, second port number, second Internet Protocol address, and protocol number as the range for hash calculation, the hash value of the initial message is obtained.
[0106] Optionally, the protocol used in the above initial message is IPsec.
[0107] Optionally, the first port number is denoted as srcport, the first Internet Protocol address as srcaddr, the second port number as dstport, the second Internet Protocol address as dstaddr, and the protocol number as protocol. The hash algorithm used can be one or more combinations (including concatenated or parallel algorithms), such as MD5, SHA256, etc., and is denoted as HASH(*). The hash value of the initial message is denoted as HASH1, and can be expressed mathematically as follows:
[0108] HASH1=HASH(srcaddr,srcport,dstaddr,dstport,protocol).
[0109] In an optional embodiment, the above-mentioned apparatus is further configured to: determine whether the virtual private network tunnel between the encapsulation device and the forwarding device supports a predetermined function of generating a hash value as an identifier for a packet; if the virtual private network tunnel supports the predetermined function, then determine the hash value and the random number vector.
[0110] It is understandable that before starting to process the random number vector, it is necessary to first determine whether the virtual private network tunnel between the encapsulation device and the aforementioned forwarding device supports the pre-defined function of generating a hash value as an identifier for the packet. The aforementioned pre-defined function can be the IV Hash function. Only if the aforementioned pre-defined function is supported is it necessary to further determine the hash value and random number vector of the initial packet in order to generate the target packet.
[0111] In an optional embodiment, the above-mentioned apparatus is further configured to: if the above-mentioned virtual private network tunnel does not support the above-mentioned predetermined function, encapsulate the above-mentioned initial message to obtain a first message, and send the first message to the above-mentioned forwarding device, wherein the first message is forwarded to the above-mentioned predetermined network by a predetermined processor in the above-mentioned forwarding device.
[0112] It is understandable that, even without the support for pre-defined functions, the encapsulation device still needs to reassemble the initial message, but using a different encapsulation method to obtain the first message. After the first message is sent to the forwarding device, it is processed by a pre-defined processor, rather than by selecting a processor for load balancing.
[0113] In a message forwarding device provided by this embodiment of the invention, a receiving module 502 is used to receive a target message; a determining module 504 is used to determine the number of processors included in the forwarding device; an allocation module 506 is used to determine a target processor in the forwarding device for processing the target message based on the target message and the number of processors; and a forwarding module 508 is used to forward the target message to a predetermined network using the target processor. This achieves the goal of improving the utilization rate of the processors in the forwarding device, realizing the technical effect of improving message forwarding efficiency, and thus solving the technical problem of unsatisfactory message forwarding efficiency of processors in related technologies.
[0114] It should be noted that the above modules can be implemented by software or hardware. For example, for the latter, it can be implemented in the following ways: the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0115] It should be noted that the receiving module 502, determining module 504, allocating module 506, and forwarding module 508 correspond to steps S202 to S208 in the embodiments. The instances and application scenarios implemented by these modules and their corresponding steps are the same, but they are not limited to the content disclosed in the above embodiments. It should also be noted that these modules, as part of the device, can operate in a computer transmitting device.
[0116] It should be noted that the optional or preferred implementation methods of this embodiment can be found in the relevant descriptions in the embodiments, and will not be repeated here.
[0117] The aforementioned message forwarding device may also include a processor and a memory. The receiving module 502, the determining module 504, the allocating module 506, the forwarding module 508, etc., are all stored as program units in the memory, and the processor executes the aforementioned program units stored in the memory to realize the corresponding functions.
[0118] The processor contains a core that retrieves the corresponding program unit from memory. One or more cores may be configured. Memory may include non-persistent memory in computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip.
[0119] Example 3
[0120] According to another aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer-readable storage medium, and the computer program is configured to execute the above-described message forwarding method at runtime.
[0121] Example 4
[0122] This invention provides an electronic device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: receiving a target message; determining the number of processors included in a forwarding device; determining a target processor in the forwarding device for processing the target message based on the target message and the number of processors; and forwarding the target message to a predetermined network using the target processor. The device in this document may be a server, a PC, etc.
[0123] Example 5
[0124] The present invention also provides a computer program product, which, when executed on a data processing device, is adapted to execute an initialization program having the following method steps: receiving a target message; determining the number of processors included in a forwarding device; determining a target processor in the forwarding device for processing the target message based on the target message and the number; and using the target processor to forward the target message to a predetermined network.
[0125] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0126] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0127] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0128] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0129] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0130] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0131] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0132] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0133] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0134] The above are merely embodiments of the present invention and are not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the present invention should be included within the scope of the claims of the present invention.
Claims
1. A message forwarding method, characterized in that, include: Receive the target message; Determine the number of processors included in the forwarding device; Based on the target message and the quantity, a target processor for processing the target message is determined in the forwarding device. After receiving the target message, the forwarding device determines a target vector based on the target message, performs modulo processing on the target vector based on the quantity, and takes the processor whose processor identifier matches the modulo result as the target processor. The target processor forwards the target message to the predetermined network. Before receiving the target message, the encapsulation device performs the following processes: receiving an initial message; determining the hash value and random number vector corresponding to the initial message; modifying the random number vector based on the quantity and hash value to obtain a target vector; encapsulating the initial message and the target vector to obtain a target message, and sending the target message to the forwarding device. The step of modifying the random number vector based on the quantity and hash value to obtain the target vector includes: taking the hash value modulo the quantity to obtain a second modulo result; taking the random number vector modulo the quantity to obtain a third modulo result; and modifying the random number vector based on the second modulo result and the third modulo result to obtain the target vector. Wherein, if the message sending device, receiving device, and protocol number used in the same data stream are the same, then the hash values generated in the same data stream are the same.
2. The method according to claim 1, characterized in that, The step of determining the target processor in the forwarding device for processing the target packet based on the target packet and the quantity includes: Based on the target message, determine the target vector; Using the quantity, the target vector is modulo-processed to obtain the first modulo result corresponding to the target message; Determine the identifiers corresponding to the number of processors in the forwarding device; Among the number of processors, identify the target processor whose identifier matches the first modulo result.
3. The method according to claim 1, characterized in that, Determining the hash value corresponding to the initial message includes: Determine the first port number of the sending device corresponding to the initial message, the first Internet Protocol address of the sending device, the second port number of the receiving device corresponding to the initial message, the second Internet Protocol address of the receiving device, and the protocol number corresponding to the initial message; The hash value is determined based on the first port number, the first Internet Protocol address, the second port number, the second Internet Protocol address, and the protocol number.
4. The method according to any one of claims 1 to 3, characterized in that, Determining the hash value and random number vector corresponding to the initial message includes: Determine whether the virtual private network tunnel between the encapsulation device and the forwarding device supports the predefined function of generating hash values as identifiers for packets; If the virtual private network tunnel supports the predetermined function, then the hash value and the random number vector are determined.
5. The method according to claim 4, characterized in that, The method further includes: If the virtual private network tunnel does not support the predetermined function, the initial message is encapsulated to obtain a first message, and the first message is sent to the forwarding device, wherein the first message is forwarded to the predetermined network by a predetermined processor in the forwarding device.
6. A message forwarding device, characterized in that, include: The receiving module is used to receive target messages; The determination module is used to determine the number of processors included in the forwarding device; The allocation module is used to determine the target processor in the forwarding device for processing the target packet based on the target packet and the quantity. After receiving the target packet, the forwarding device determines the target vector based on the target packet, performs modulo processing on the target vector based on the quantity, and takes the processor whose processor identifier matches the modulo result as the target processor. The forwarding module is used to forward the target packet to a predetermined network using the target processor; The device is further configured to, before receiving the target message, have the encapsulation device perform the following processing: receiving an initial message; determining the hash value and random number vector corresponding to the initial message; modifying the random number vector based on the quantity and hash value to obtain a target vector; encapsulating the initial message and the target vector to obtain a target message; and sending the target message to the forwarding device. The device is further configured to use the quantity to perform modulo processing on the hash value to obtain a second modulo result; use the quantity to perform modulo processing on the random number vector to obtain a third modulo result; and based on the second modulo result and the third modulo result, modify the random number vector to obtain the target vector. Wherein, if the message sending device, receiving device, and protocol number used in the same data stream are the same, then the hash values generated in the same data stream are the same.
7. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores a computer program, wherein the computer program is configured to execute the message forwarding method according to any one of claims 1 to 5 when it is run.
8. An electronic device, characterized in that, include: One or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the message forwarding method according to any one of claims 1 to 5.
Citation Information
Patent Citations
A method and system for accelerating IPsec network security processing
CN110535834B
A method for improving the performance of software encryption and decryption in a single IPsec VPN tunnel.
CN111669374B
High-performance IPsec VPN CPU load balancing method
CN115225430A
Dynamically changed transmission message processing method and device
CN104618253A
Message distribution method, multi-core processor and readable storage medium
CN112073332A