Method, device and medium for interaction of service traffic in multi-domain pure ipv6 network

By determining the source address type of IPv6/IPv4 packets and dynamically adjusting the uRPF detection mode, the packet loss problem caused by strict uRPF detection in multi-domain pure IPv6 networks is solved, thus improving the reliability of service traffic.

CN116846840BActive Publication Date: 2026-08-04CHINA TELECOM CORP LTD BEIJING RESEARCH INSTITUTE +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD BEIJING RESEARCH INSTITUTE
Filing Date
2023-05-16
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In multi-domain pure IPv6 networks, the strict uRPF detection mechanism causes packet loss in service traffic, especially when IPv4 packets are transmitted through the multi-domain pure IPv6 network. After the XLAT mapping of the ingress PE device generates IPv6 packets, the strict uRPF detection causes the traffic packets to be dropped.

Method used

By determining whether the source address of an IPv6 or IPv4 packet is SRH encapsulated or carries an IPv6 composite prefix or a NAT64 resource pool address, the uRPF detection mode is dynamically adjusted to strict or loose to avoid packet loss.

Benefits of technology

Without increasing hardware or changing the communication architecture, it improves the reliability of service traffic interaction in multi-domain pure IPv6 networks and solves the packet loss problem caused by uRPF detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116846840B_ABST
    Figure CN116846840B_ABST
Patent Text Reader

Abstract

This disclosure provides a method, apparatus, device, and medium for the interaction of service traffic in a multi-domain pure IPv6 network. The method includes: determining whether a data packet of service traffic in the multi-domain pure IPv6 network is an IPv6 data packet or an IPv4 data packet; if the data packet is determined to be an IPv6 data packet, determining whether the IPv6 data packet is an SRH-encapsulated message; if the IPv6 data packet is determined to be an SRH-encapsulated message, determining whether the source address of the IPv6 data packet carries an IPv6 composite prefix; if the data packet is determined to be an IPv4 data packet, determining whether the source address of the IPv4 data packet is a preset IPv4 address in the NAT64 resource pool; and setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 data packet or IPv4 data packet. Through the embodiments of this disclosure, the packet loss problem caused by uRPF detection can be solved without increasing hardware facilities or changing the communication architecture, thus improving the reliability of service traffic interaction in a multi-domain pure IPv6 network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network technology, and more specifically, to a method, apparatus, device, and medium for the interaction of service traffic in a multi-domain pure IPv6 network. Background Technology

[0002] Currently, in multi-domain pure IPv6 (Internet Protocol Version 6) networks with strict uRPF (Unicast Reverse Path Forwarding), for IPv4 (Internet Protocol version 4) packets that need to be transmitted through the multi-domain pure IPv6 network, the XLAT of the ingress PE device can generate corresponding IPv6 source and destination addresses based on global mapping rules, converting IPv4 packets into IPv6 packets, and then transmitting them within and across domains within the multi-domain pure IPv6 network. However, if the corresponding device interface executes a strict uRPF inspection mechanism after receiving the packet, it can lead to problems such as packet dropping.

[0003] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0004] The purpose of this disclosure is to provide a method, apparatus, device, and medium for the interaction of service traffic in a multi-domain pure IPv6 network, which can at least to some extent overcome the packet loss problem of service traffic in a multi-domain pure IPv6 network under the uRPF detection mechanism due to the limitations and defects of related technologies.

[0005] According to a first aspect of the present disclosure, a method for interacting service traffic in a multi-domain pure IPv6 network is provided, comprising: determining whether a data packet of the service traffic in the multi-domain pure IPv6 network is an IPv6 data packet or an IPv4 data packet; if the data packet is determined to be an IPv6 data packet, determining whether the IPv6 data packet is an SRH-encapsulated message; if the IPv6 data packet is determined to be an SRH-encapsulated message, determining whether the source address of the IPv6 data packet carries an IPv6 composite prefix; if the data packet is determined to be an IPv4 data packet, determining whether the source address of the IPv4 data packet is a preset IPv4 address in a NAT64 resource pool; and setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection according to the determination result of the IPv6 data packet or the IPv4 data packet.

[0006] In one exemplary embodiment of this disclosure, before determining whether a data packet of service traffic in the multi-domain pure IPv6 network is an IPv6 data packet or an IPv4 data packet, the method further includes: Retrieves the preset global mapping rules, the forwarding type of service traffic, and the mapping prefix of the default IPv6 composite prefix.

[0007] In one exemplary embodiment of this disclosure, if it is determined that the data packet is an IPv6 data packet, then determining whether the IPv6 data packet is an SRH-encapsulated message includes: If the data packet is determined to be an IPv6 data packet, then determine whether the IPv6nextheader field in the source address of the IPv6 data packet is a specified field, and whether the routing type in the routing extension header in the source address is a specified type; If it is determined that the IPv6 nextheader field in the source address of the IPv6 packet is the specified field, and the routing type in the routing extension header of the source address is the specified type, then the IPv6 packet is determined to be a message encapsulated by SRH.

[0008] In an exemplary embodiment of this disclosure, if it is determined that the IPv6 data packet is not a message encapsulated by the SRH, then determining whether the source address of the IPv6 data packet carries an IPv6 composite prefix includes: If it is determined that the IPv6 packet is not a message encapsulated by the SRH, then it is determined whether the IPv6 packet carries the IPv6 composite prefix based on the obtained preset global mapping rule, the forwarding type of the service traffic, and the mapping prefix of the default IPv6 composite prefix.

[0009] In one exemplary embodiment of this disclosure, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet includes: If the IPv6 packet is determined to be a message encapsulated by the SRH, or if the IPv6 packet carries the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection.

[0010] In one exemplary embodiment of this disclosure, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet further includes: If it is determined that the IPv6 packet does not carry the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

[0011] In one exemplary embodiment of this disclosure, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet further includes: If the source address of the IPv4 packet is determined to be a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the source address of the IPv4 packet is not a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

[0012] According to a second aspect of the present disclosure, an interaction device for service traffic in a multi-domain pure IPv6 network is provided, comprising: The determination module is configured to determine whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 data packets or IPv4 data packets; The judgment module is configured to determine whether the IPv6 data packet is an SRH-encapsulated message if it is determined that the data packet is an IPv6 data packet. The judgment module is configured to determine whether the source address of the IPv6 data packet carries an IPv6 composite prefix if it is determined that the IPv6 data packet is a message encapsulated by the SRH. The judgment module is configured to determine whether the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool if the determined packet is an IPv4 packet. The configuration module is configured to set the uRPF detection of the multi-domain pure IPv6 network to either strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet.

[0013] According to a third aspect of this disclosure, an electronic device is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the method as described in any of the preceding methods based on instructions stored in the memory.

[0014] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided having a program stored thereon that, when executed by a processor, implements the method for interacting service traffic in a multi-domain pure IPv6 network as described in any of the preceding claims.

[0015] In this embodiment, by determining whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 packets or IPv4 packets, if the data packet is determined to be an IPv6 packet, it is determined whether the IPv6 packet is an SRH-encapsulated message. If the IPv6 packet is determined to be an SRH-encapsulated message, it is determined whether the source address of the IPv6 packet carries an IPv6 composite prefix. If the data packet is determined to be an IPv4 packet, it is determined whether the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool. Then, based on the determination result of the IPv6 packet or the IPv4 packet, the uRPF detection of the multi-domain pure IPv6 network is set to strict uRPF detection or loose uRPF detection. Without increasing hardware facilities or changing the communication architecture, the packet loss problem caused by uRPF detection is solved, and the reliability of service traffic interaction in the multi-domain pure IPv6 network is improved.

[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0018] Figure 1 A schematic diagram of an exemplary system architecture for an interaction scheme of service traffic in a multi-domain pure IPv6 network to which embodiments of the present invention can be applied is shown. Figure 2 This is a flowchart of a method for interacting service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 3 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 4 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 5This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 6 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 7 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 8 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 9 This is a schematic diagram of an interaction scheme for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 10 This is a schematic diagram of another interaction scheme for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 11 This is a schematic diagram of another interaction scheme for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 12 This is a schematic diagram of another interaction scheme for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 13 This is a flowchart of another method for interacting service traffic in a multi-domain pure IPv6 network, as illustrated in an exemplary embodiment of this disclosure. Figure 14 This is a block diagram of an interaction device for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure; Figure 15 This is a block diagram of an electronic device according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0019] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this disclosure more comprehensive and complete, and to fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, apparatus, steps, etc., can be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0020] Furthermore, the accompanying drawings are merely illustrative of this disclosure, and the same reference numerals in the drawings denote the same or similar parts, thus repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0021] Figure 1 A schematic diagram of an exemplary system architecture for an interaction scheme of service traffic in a multi-domain pure IPv6 network to which embodiments of the present invention can be applied is shown.

[0022] like Figure 1 As shown, system architecture 100 may include one or more of terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 serves as the medium for providing communication links between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0023] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, there can be any number of terminal devices, networks, and servers. For example, server 105 could be a server cluster composed of multiple servers.

[0024] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Terminal devices 101, 102, and 103 can be various electronic devices with displays, including but not limited to smartphones, tablets, laptops, and desktop computers, etc.

[0025] In some embodiments, the method for interacting service traffic in a multi-domain pure IPv6 network provided in this invention is generally executed by server 105. Correspondingly, the device for interacting service traffic in a multi-domain pure IPv6 network is generally located in terminal device 103 (or terminal device 101 or 102). In other embodiments, some terminals may have functions similar to those of the server device to execute this method.

[0026] In related technologies, URPF testing is divided into two types: strict and loose.

[0027] Strict type: This requires not only that the router's forwarding table contains a route to the packet's source address, but also that the packet's ingress interface matches the outgress interface of the route to the source address in the forwarding table. Only packets that meet both conditions are considered valid. Strict checks may incorrectly discard packets on asymmetric paths.

[0028] Loose type: This requires that the router's forwarding table contains a route to the source address of the packet.

[0029] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0030] Figure 2 This is a flowchart of a method for interacting service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure.

[0031] refer to Figure 2 Methods for interacting service traffic in a multi-domain pure IPv6 network may include: Step S202: Determine whether the data packets of the service traffic in the multi-domain pure IPv6 network are IPv6 data packets or IPv4 data packets.

[0032] Step S204: If it is determined that the data packet is an IPv6 data packet, then determine whether the IPv6 data packet is an SRH-encapsulated message.

[0033] Step S206: If it is determined that the IPv6 data packet is a message encapsulated by the SRH, then determine whether the source address of the IPv6 data packet carries the IPv6 composite prefix.

[0034] Step S208: If the determined data packet is an IPv4 data packet, then determine whether the source address of the IPv4 data packet is a preset IPv4 address in the NAT64 resource pool.

[0035] Step S210: Based on the determination result of the IPv6 data packet or the IPv4 data packet, set the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection.

[0036] In this embodiment, by determining whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 packets or IPv4 packets, if the data packet is determined to be an IPv6 packet, it is determined whether the IPv6 packet is an SRH-encapsulated message. If the IPv6 packet is determined to be an SRH-encapsulated message, it is determined whether the source address of the IPv6 packet carries an IPv6 composite prefix. If the data packet is determined to be an IPv4 packet, it is determined whether the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool. Then, based on the determination result of the IPv6 packet or the IPv4 packet, the uRPF detection of the multi-domain pure IPv6 network is set to strict uRPF detection or loose uRPF detection. Without increasing hardware facilities or changing the communication architecture, the packet loss problem caused by uRPF detection is solved, and the reliability of service traffic interaction in the multi-domain pure IPv6 network is improved.

[0037] The following section provides a detailed explanation of each step in the interaction method for service traffic in a multi-domain pure IPv6 network.

[0038] In one exemplary embodiment of this disclosure, such as Figure 3 As shown, before determining whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 data packets or IPv4 data packets, the process further includes: Step S302: Obtain the preset global mapping rules, the forwarding type of service traffic, and the mapping prefix of the default IPv6 composite prefix.

[0039] In one exemplary embodiment of this disclosure, such as Figure 4 As shown, if the data packet is determined to be an IPv6 data packet, then determining whether the IPv6 data packet is an SRH-encapsulated message includes: Step S402: If it is determined that the data packet is the IPv6 data packet, then determine whether the IPv6 nextheader field in the source address of the IPv6 data packet is a specified field, and whether the routing type in the routing extension header in the source address is a specified type.

[0040] Step S404: If it is determined that the IPv6 nextheader field in the source address of the IPv6 packet is the specified field, and the routing type in the routing extension header in the source address is the specified type, then the IPv6 packet is determined to be the SRH-encapsulated message.

[0041] In one exemplary embodiment of this disclosure, such as Figure 5As shown, if it is determined that the IPv6 data packet is not a message encapsulated by the SRH, then determining whether the source address of the IPv6 data packet carries an IPv6 composite prefix includes: Step S502: If it is determined that the IPv6 data packet is not a message encapsulated by the SRH, then determine whether the IPv6 data packet carries the IPv6 composite prefix based on the obtained preset global mapping rule, the forwarding type of the service traffic, and the mapping prefix of the default IPv6 composite prefix.

[0042] In one exemplary embodiment of this disclosure, such as Figure 6 As shown, based on the determination result of the IPv6 packet or the IPv4 packet, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection includes: Step S602: If it is determined that the IPv6 data packet is a message encapsulated by the SRH, or if it is determined that the IPv6 data packet carries the IPv6 composite prefix, then the uRPF detection of the IPv6 data packet by the multi-domain pure IPv6 network is set to loose uRPF detection.

[0043] In one exemplary embodiment of this disclosure, such as Figure 7 As shown, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet further includes: Step S702: If it is determined that the IPv6 data packet does not carry the IPv6 composite prefix, then the uRPF detection of the IPv6 data packet by the multi-domain pure IPv6 network is set to strict uRPF detection.

[0044] In one exemplary embodiment of this disclosure, such as Figure 8 As shown, setting the uRPF detection of the multi-domain pure IPv6 network to strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet further includes: Step S802: If it is determined that the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet by the multi-domain pure IPv6 network is set to loose uRPF detection.

[0045] Step S804: If it is determined that the source address of the IPv4 packet is not a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet by the multi-domain pure IPv6 network is set to strict uRPF detection.

[0046] In one exemplary embodiment of this disclosure, such as Figure 9 As shown, in the multi-domain pure IPv6 scenario 900, the network architecture includes cloud data centers (GW (backbone communication), VPC (Virtual Privita Cloud), VM (virtual machine)), metropolitan area networks (multi-domain pure IPv6) accessing home and enterprise users, 4G / 5G core networks (multi-domain pure IPv6) accessing mobile users, IP backbone networks (multi-domain pure IPv6), and external neighbor networks (external IPv6 networks and / or external IPv4 networks), but is not limited to these.

[0047] In one exemplary embodiment of this disclosure, such as Figure 10 As shown in the related technology, in the end-to-end communication scenario 1000 of IPv4 services in a multi-domain pure IPv6 network, the source and destination addresses of the data packets are both IPv4 addresses. The ingress PE (Provider Edge, network-side edge device) looks up the corresponding Pref64 mapping prefixes for the source and destination IPv4 addresses in the local mapping rule database. Then, the XLAT instruction of this PE (XLAT is an assembly language table lookup instruction that uses DS:[BX+AL] as the address to extract a byte from memory and then put it into AL) processes the source and destination addresses of the data packets to synthesize the source and destination addresses of the IPv6 data packets through the Pref64-1 instruction of this PE, and generates new IPv6 packets through encapsulation or translation mechanisms. After the egress PE receives the IPv6 data packets from within the network, it removes the mapping prefixes for the source and destination IPv6 addresses from the IPv6 data packets, and the remaining 32 bits are the original IPv4 addresses. When the traffic at the device ingress interface is inconsistent with the routing outgress interface of the IPv4 packet source address, the strict uRPF detection fails, and the packet is dropped.

[0048] In one exemplary embodiment of this disclosure, such as Figure 11 As shown in the related technology, in the communication scenario 1100 where an IPv6 host accesses IPv4 services in a multi-domain pure IPv6 network, when an IPv6 client initiates a connection to IPv4 network resources and configures an IPv4 address pool on the NAT64 function to temporarily convert the user's IPv6 source address to a certain IPv4 address, a strict uRPF is used on a certain node in the IPv4 network to detect that the device's ingress interface is inconsistent with the routing outgress interface of the IPv4 packet source address, and the packet is dropped.

[0049] In one exemplary embodiment of this disclosure, such as Figure 12As shown in the related technology, in the communication scenario 1200 where an IPv4 host accesses IPv6 services in a multi-domain pure IPv6 network, the ingress PE searches the local mapping rule database to obtain the mapping prefix Pref64 corresponding to its source IPv4 address. Then, XLAT synthesizes the source address of the data packet into the source address of the IPv6 data packet through Pref64-1, and generates a new IPv6 packet through single translation technology. When the traffic at the ingress interface of the device is inconsistent with the routing outgress interface of the source address of the SRv6 outer IPv6 packet, the strict uRPF detection fails, and the packet is dropped.

[0050] In one exemplary embodiment of this disclosure, in related technologies, when IPv6 hosts access IPv6 services in a multi-domain pure IPv6 network, some IPv6 service instances require the use of SRv6 capabilities. In such cases, an SRH extended header is inserted, and SRv6-based routing is performed. For services that do not require SRv6 capabilities, they can be forwarded directly as IPv6 BE services. When traffic using SRv6 capabilities has an ingress interface on the device that does not match the outgress interface of the source address of the SRv6 outer IPv6 packet, strict uRPF detection fails, and the packet is discarded. BE services, or best-effort services, are services that are not sensitive to latency but require low data transmission error rates, have no guaranteed bandwidth requirements, and are prone to burstiness. Their practical applications mainly include web browsing, sending and receiving emails, and file downloads, but are not limited to these.

[0051] To address the issue of packet loss in the aforementioned related technologies, the embodiments of this disclosure solve the packet loss problem, and the specific processing procedure is shown in Figure 13: Step S1302: Obtain traffic packets in a multi-domain pure IPv6 network.

[0052] Step S1304: Determine the type of data packet corresponding to the traffic message.

[0053] In step S1306, if the packet is an IPv4 packet, determine whether the source address is an address in the NAT64 resource pool. If yes, proceed to step S1314; otherwise, proceed to step S1312.

[0054] In step S1308, if it is an IPv6 packet, check whether the source address carries an SRH header. If yes, proceed to step S1314; otherwise, proceed to step S1310.

[0055] Step S1310: Determine whether the source address carries an IPv6 composite prefix. If yes, proceed to step S1314; otherwise, proceed to step S1312.

[0056] Step S1312: Modify the strict configuration mode of uRPF to strict uRPF.

[0057] Step S1314: Modify the uRPF policy configuration mode to loose uRPF.

[0058] Step S1316: Business traffic is successfully established and forwarded.

[0059] Specifically, the packet type is first determined. If it is an IPv4 packet, and the source IPv4 is detected as an IPv4 address allocated in the NAT64 resource pool, the uRPF detection is automatically downgraded to loose uRPF detection; otherwise, it remains a strict uRPF detection. If it is an IPv6 packet, the first step checks if the packet carries an SRH header. If so, the uRPF detection is automatically downgraded to loose uRPF detection. Otherwise, the second step checks if the source address has an IPv6 composite prefix. If so, the detection is automatically downgraded to loose uRPF detection; otherwise, it remains a strict uRPF detection.

[0060] Upon receiving an IPv6 packet, after the packet is received on the strict uRPF interface, the system determines whether the source address of the IPv6 packet has an IPv6 composite prefix (mapped prefix Pref64) based on the global mapping rules, forwarding type, and the default IPv6 composite prefix mapping prefix of the default translation gateway. If so, a loose uRPF check is performed. Additionally, the system checks whether the packet is encapsulated with SRH (IPv6 nextheader=43 & Routing Extension Header with Routing Type=4).

[0061] Upon receiving an IPv4 packet, the strict uRPF interface determines whether the source IPv4 address is an IPv4 address allocated in the NAT64 resource pool. If the source IPv4 is detected as an IPv4 address allocated in the NAT64 resource pool, the uRPF detection is automatically downgraded to loose uRPF detection. Loose uRPF detection addresses packet loss issues in multi-domain pure IPv6 service traffic in related technologies. Otherwise, strict uRPF detection is maintained to ensure data security for multi-domain pure IPv6 service traffic.

[0062] Corresponding to the above method embodiments, this disclosure also provides an interaction device for service traffic in a multi-domain pure IPv6 network, which can be used to execute the above method embodiments.

[0063] Figure 14 This is a block diagram of an interaction device for service traffic in a multi-domain pure IPv6 network according to an exemplary embodiment of this disclosure.

[0064] refer to Figure 14The interaction device 1400 for service traffic in a multi-domain pure IPv6 network may include: The determination module 1402 is configured to determine whether the data packets of the service traffic in the multi-domain pure IPv6 network are IPv6 data packets or IPv4 data packets.

[0065] The judgment module 1404 is configured to determine whether the IPv6 data packet is an SRH-encapsulated message if it is determined that the data packet is an IPv6 data packet.

[0066] The judgment module 1404 is configured to determine whether the source address of the IPv6 data packet carries an IPv6 composite prefix if it is determined that the IPv6 data packet is a message encapsulated by the SRH.

[0067] The judgment module 1404 is configured to determine whether the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool if the determined packet is an IPv4 packet.

[0068] The setting module 1406 is configured to set the uRPF detection of the multi-domain pure IPv6 network to either strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 data packet or the IPv4 data packet.

[0069] In one exemplary embodiment of this disclosure, the determining module 1402 is further configured to: Before determining whether a data packet of service traffic in the multi-domain pure IPv6 network is an IPv6 data packet or an IPv4 data packet, the preset global mapping rules, the forwarding type of service traffic, and the mapping prefix of the default IPv6 composite prefix are obtained.

[0070] In one exemplary embodiment of this disclosure, the determining module 1404 is further configured to: If the data packet is determined to be an IPv6 data packet, then determine whether the IPv6nextheader field in the source address of the IPv6 data packet is a specified field, and whether the routing type in the routing extension header in the source address is a specified type; If it is determined that the IPv6 nextheader field in the source address of the IPv6 packet is the specified field, and the routing type in the routing extension header of the source address is the specified type, then the IPv6 packet is determined to be a message encapsulated by SRH.

[0071] In one exemplary embodiment of this disclosure, the determining module 1404 is further configured to: If it is determined that the IPv6 packet is not a message encapsulated by the SRH, then it is determined whether the IPv6 packet carries the IPv6 composite prefix based on the obtained preset global mapping rule, the forwarding type of the service traffic, and the mapping prefix of the default IPv6 composite prefix.

[0072] In one exemplary embodiment of this disclosure, the setting module 1406 is further configured to: If the IPv6 packet is determined to be a message encapsulated by the SRH, or if the IPv6 packet carries the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection.

[0073] In one exemplary embodiment of this disclosure, the setting module 1406 is further configured to: If it is determined that the IPv6 packet does not carry the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

[0074] In one exemplary embodiment of this disclosure, the setting module 1406 is further configured to: If the source address of the IPv4 packet is determined to be a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the source address of the IPv4 packet is not a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

[0075] Since the functions of the device 1400 have been described in detail in their respective method embodiments, they will not be repeated here.

[0076] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0077] In an exemplary embodiment of this disclosure, an electronic device capable of implementing the above-described method is also provided.

[0078] Those skilled in the art will understand that various aspects of the present invention can be implemented as systems, methods, or program products. Therefore, various aspects of the present invention can be specifically implemented in the following forms: entirely in hardware, entirely in software (including firmware, microcode, etc.), or in a combination of hardware and software, collectively referred to herein as “circuit,” “module,” or “system.”

[0079] The following reference Figure 15 To describe an electronic device 1500 according to this embodiment of the present invention. Figure 15 The electronic device 1500 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0080] like Figure 15 As shown, the electronic device 1500 is manifested in the form of a general-purpose computing device. The components of the electronic device 1500 may include, but are not limited to: at least one processing unit 1510, at least one storage unit 1520, and a bus 1530 connecting different system components (including storage unit 1520 and processing unit 1510).

[0081] The storage unit stores program code that can be executed by the processing unit 1510, causing the processing unit 1510 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of the present invention. For example, the processing unit 1510 can perform the method shown in the embodiments of this disclosure.

[0082] Storage unit 1520 may include readable media in the form of volatile storage units, such as random access memory (RAM) 15201 and / or cache memory 15202, and may further include read-only memory (ROM) 15203.

[0083] Storage unit 1520 may also include a program / utility 15204 having a set (at least one) of program modules 15205, such program modules 15205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0084] Bus 1530 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0085] Electronic device 1500 can also communicate with one or more external devices 1540 (e.g., keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1500, and / or any device that enables electronic device 1500 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1550. Furthermore, electronic device 1500 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1560. As shown, network adapter 1560 communicates with other modules of electronic device 1500 via bus 1530. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0086] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0087] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the methods described above is stored. In some possible embodiments, various aspects of the invention may also be implemented as a program product comprising program code that, when the program product is run on a terminal device, causes the terminal device to perform the steps of the various exemplary embodiments of the invention described in the "Exemplary Methods" section of this specification.

[0088] The program product for implementing the above-described method according to embodiments of the present invention may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0089] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0090] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0091] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0092] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0093] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of the present invention, and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0094] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and concept of this disclosure are indicated by the claims.

Claims

1. A method for traffic interaction in a multi-domain pure IPv6 network, characterized in that, include: The data packets of service traffic in the multi-domain pure IPv6 network are determined to be either IPv6 data packets or IPv4 data packets; If the data packet is determined to be an IPv6 data packet, then determine whether the IPv6 data packet is an SRH-encapsulated message; If the IPv6 data packet is determined to be a message encapsulated by the SRH, then determine whether the source address of the IPv6 data packet carries the IPv6 composite prefix; If the data packet is determined to be an IPv4 data packet, then determine whether the source address of the IPv4 data packet is a preset IPv4 address in the NAT64 resource pool; Based on the determination result of the IPv6 packet or the IPv4 packet, the uRPF detection of the multi-domain pure IPv6 network is set to strict uRPF detection or loose uRPF detection, including: If the IPv6 packet is determined to be a message encapsulated by the SRH, or if the IPv6 packet carries the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the IPv6 packet does not carry the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection. If the source address of the IPv4 packet is determined to be a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the source address of the IPv4 packet is not a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

2. The method of claim 1, wherein the method further comprises: Before determining whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 packets or IPv4 packets, the process also includes: Retrieves the preset global mapping rules, the forwarding type of service traffic, and the mapping prefix of the default IPv6 composite prefix.

3. The method of claim 1, wherein the method further comprises: If the data packet is determined to be an IPv6 data packet, then determining whether the IPv6 data packet is an SRH-encapsulated message includes: If the data packet is determined to be an IPv6 data packet, then determine whether the IPv6nextheader field in the source address of the IPv6 data packet is a specified field, and whether the routing type in the routing extension header in the source address is a specified type; If it is determined that the IPv6 nextheader field in the source address of the IPv6 packet is the specified field, and the routing type in the routing extension header of the source address is the specified type, then the IPv6 packet is determined to be a message encapsulated by SRH.

4. The method of claim 2, wherein the method further comprises: If it is determined that the IPv6 packet is not a message encapsulated by SRH, then determining whether the source address of the IPv6 packet carries an IPv6 composite prefix includes: If it is determined that the IPv6 packet is not a message encapsulated by the SRH, then it is determined whether the IPv6 packet carries the IPv6 composite prefix based on the obtained preset global mapping rule, the forwarding type of the service traffic, and the mapping prefix of the default IPv6 composite prefix.

5. An apparatus for interaction of traffic flows in a multi-domain pure IPv6 network, characterized in that, include: The determination module is configured to determine whether the data packets of service traffic in the multi-domain pure IPv6 network are IPv6 data packets or IPv4 data packets; The judgment module is configured to determine whether the IPv6 data packet is an SRH-encapsulated message if it is determined that the data packet is an IPv6 data packet. The judgment module is configured to determine whether the source address of the IPv6 data packet carries an IPv6 composite prefix if it is determined that the IPv6 data packet is a message encapsulated by the SRH. The judgment module is configured to determine whether the source address of the IPv4 packet is a preset IPv4 address in the NAT64 resource pool if the determined packet is an IPv4 packet. The configuration module is set to configure the uRPF detection of the multi-domain pure IPv6 network to be either strict uRPF detection or loose uRPF detection based on the determination result of the IPv6 packet or the IPv4 packet, including: If the IPv6 packet is determined to be a message encapsulated by the SRH, or if the IPv6 packet carries the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the IPv6 packet does not carry the IPv6 composite prefix, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection. If the source address of the IPv4 packet is determined to be a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to loose uRPF detection. If it is determined that the source address of the IPv4 packet is not a preset IPv4 address in the NAT64 resource pool, then the uRPF detection of the IPv6 packet in the multi-domain pure IPv6 network is set to strict uRPF detection.

6. An electronic device, comprising: include: Memory; as well as A processor coupled to the memory, the processor being configured to execute, based on instructions stored in the memory, the method for interacting with service traffic in a multi-domain pure IPv6 network as described in any one of claims 1-4.

7. A computer-readable storage medium having a program stored thereon that, when executed by a processor, implements the method for interacting service traffic in a multi-domain pure IPv6 network as described in any one of claims 1-4.