Tunnel session allocation method and allocation device for multi-core CPU

By calculating hash values and mapping values in multi-core CPU devices, the problem of uniform distribution of sessions in the tunnel is solved, and the uniform distribution of sessions in the tunnel is achieved between different CPU cores, improving the CPU processing performance.

CN117614962BActive Publication Date: 2025-07-11BEIJING QINGWANG TECH CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311575736.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-23
Publication Date
2025-07-11
Estimated Expiration
2043-11-23

AI Technical Summary

Technical Problem

In multi-core CPU devices, the problem of uniform distribution of sessions in the tunnel leads to a degradation of CPU processing performance. The prior art cannot effectively solve the problem of traffic concentration caused by the same 5-tuples in the outer layer of the tunnel, especially in encrypted tunnels, which cannot achieve uniform distribution.

Method used

By calculating the hash value and mapping value in a multi-core CPU device, determining the CPU core to be allocated corresponding to the packet, and encapsulating the mapping value during processing, ensuring that the sessions in the tunnel are evenly distributed among different CPU cores. Hash mapping technology is used to calculate the mapping value based on the number of CPU cores, ensuring uniform distribution.

Benefits of technology

It realizes even distribution of sessions in the tunnel among multi-core CPUs, improves the processing performance of the CPU, avoids overload or idleness of some CPU cores, and improves the overall processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117614962B_ABST
    Figure CN117614962B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a method and apparatus for session allocation within a tunnel of a multi-core CPU, including: the current device sends the received packet to the session management module in the current device; the session management module determines the hash value corresponding to the packet, calculates the mapping value corresponding to the hash value according to the hash value; determines the CPU core to which the packet is to be allocated according to the mapping value, and sends the packet to the CPU core to be allocated; the CPU core to be allocated processes the packet, encapsulates the mapping value into the processed packet during the processing, and transmits the processed packet to the next device at the opposite end of the tunnel; sends the received processed packet to the tunnel management module; obtains the mapping value according to the processed packet; determines the CPU core to be processed corresponding to the processed packet of the next device according to the mapping value. The embodiments of this specification can achieve uniform allocation of sessions between multi-core CPUs within a tunnel and improve the processing performance of the CPU.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the field of data transmission, and particularly to a method and device for allocating sessions within a tunnel of a multi-core CPU. Background Art

[0002] In the field of data transmission, traditional routers route based on the destination address and do not perceive sessions. With the development of the Internet, more and more network intermediate devices are beginning to perceive sessions, such as security devices, auditing devices, load balancing devices, tunnel gateways, etc. These devices require that all packets of the same session go through the same processing logic. If they do not go through the same processing, problems such as out-of-order and function failure may occur, that is, the requirement of the same source and the same destination.

[0003] Existing network devices are evolving towards multi-core devices, and the requirement of the same source and the same destination on multi-core devices is equally strict. If the packets of the same session are allocated to different CPU cores for processing, problems such as out-of-order may occur, resulting in abnormal situations. The traditional method to ensure the same source and the same destination under multiple cores is to extract feature values such as the 5-tuple of the packet, perform a Hash calculation on it, and allocate it to different CPU queues according to the Hash value. Since the 5-tuple features of the same session are the same, the resulting Hash values are the same, naturally enabling multiple packets of the same session to be processed on the same CPU core.

[0004] In application scenarios such as tunnels, a large number of sessions enter the same tunnel, and the outer-layer 5-tuple of the tunnel is the same. If the outer-layer 5-tuple of the tunnel is used to calculate the Hash, it will cause the traffic to concentrate on some CPU cores, resulting in uneven distribution. Therefore, it is required that the device can calculate the Hash of the 5-tuple of the inner-layer session in advance to ensure the even distribution of traffic on each CPU. However, this method requires perceiving the inner-layer session of the tunnel, which violates the principle of network packet encapsulation. Moreover, for encrypted tunnels, the inner-layer session has been encrypted and the original 5-tuple cannot be obtained, so the sessions cannot be evenly distributed.

[0005] To address the above problems, there is an urgent need for a method for allocating sessions within a tunnel of a multi-core CPU that can achieve an even distribution of sessions between multi-core CPUs within the tunnel and improve the processing performance of the CPU. Summary of the Invention

[0006] The purpose of the embodiments of this specification is to provide a method, device, equipment, and storage medium for allocating sessions within a tunnel of a multi-core CPU to achieve an even distribution of sessions between multi-core CPUs within the tunnel and improve the processing performance of the CPU.

[0007] To achieve the above objective, on the one hand, the embodiments of this specification provide a method for allocating sessions within a tunnel of a multi-core CPU, including:

[0008] The current device sends the received message to the session management module in the current device;

[0009] The session management module determines the hash value corresponding to the message, and calculates the mapping value corresponding to the hash value;

[0010] The session management module determines the CPU core to be allocated corresponding to the message according to the mapping value, and sends the message to the CPU core to be allocated for processing;

[0011] The CPU core to be allocated processes the message, encapsulates the mapping value into the processed message during the processing, and transmits the processed message to the next device at the opposite end of the tunnel;

[0012] The next device sends the received processed message to the tunnel management module in the next device;

[0013] The tunnel management module extracts the mapping value according to the processed message;

[0014] The tunnel management module determines the CPU core to be processed corresponding to the processed message in the next device according to the mapping value, and sends the processed message to the CPU core to be processed for processing.

[0015] Preferably, the session management module determining the hash value corresponding to the message further includes:

[0016] The session management module determines whether the hash value corresponding to the message is recorded in the session table;

[0017] If so, obtain the hash value corresponding to the message from the session table;

[0018] If not, calculate the hash value corresponding to the message according to the five-tuple of the message, and record the corresponding relationship between the five-tuple of the message and the hash value in the session table.

[0019] Preferably, the calculating the mapping value corresponding to the hash value further includes:

[0020] Determine different calculation methods of the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel;

[0021] Calculate the mapping value corresponding to the hash value according to different calculation methods.

[0022] Preferably, the determining different calculation methods of the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel further includes:

[0023] If the number of CPU cores of the current device and the next device is the same, perform hash mapping using the number of CPU cores of the current device and the hash value to obtain a mapping value;

[0024] If the number of CPU cores of the current device and the next device is different, perform hash mapping using the least common multiple of the number of CPU cores of the current device and the next device and the hash value to obtain a mapping value.

[0025] Preferably, further comprising determining the CPU core to be allocated corresponding to the packet according to the mapping value:

[0026] If the number of CPU cores of the current device and the next device is the same, use the CPU core corresponding to the mapping value as the CPU core to be allocated corresponding to the packet;

[0027] If the number of CPU cores of the current device and the next device is different, take the modulus of the mapping value with the number of CPU cores of the current device to obtain a modulus value;

[0028] Use the CPU core corresponding to the modulus value as the CPU core to be allocated corresponding to the packet.

[0029] Preferably, further comprising encapsulating the mapping value into the processed packet:

[0030] Encapsulate the mapping value into the processed packet by using it as a part of the IP header, as a part of the TCP / UDP header, as a part of the tunnel encapsulation header, or as an independent header.

[0031] Preferably, further comprising determining the CPU core to be processed corresponding to the processed packet in the next device by the tunnel management module according to the mapping value:

[0032] If the number of CPU cores of the current device and the next device is the same, use the CPU core corresponding to the mapping value as the CPU core to be processed corresponding to the processed packet;

[0033] If the number of CPU cores of the current device and the next device is different, take the modulus of the mapping value with the number of CPU cores of the next device to obtain a modulus value;

[0034] Use the CPU core corresponding to the modulus value as the CPU core to be processed corresponding to the processed packet.

[0035] Preferably, after sending the processed packet to the CPU core to be processed for processing, further comprising:

[0036] Record the correspondence between the five-tuple of the processed message and the hash value in the session table of the session management module of the next device.

[0037] On the other hand, an embodiment of the present specification provides a session allocation device in a tunnel of a multi-core CPU. The device includes:

[0038] A receiving module, configured to send the received message by the current device to the session management module in the current device;

[0039] A calculation module, configured to determine the hash value corresponding to the message by the session management module, and calculate the mapping value corresponding to the hash value;

[0040] A determination module, configured to determine the CPU core to be allocated corresponding to the message by the session management module according to the mapping value, and send the message to the CPU core to be allocated for processing;

[0041] A first processing module, configured to process the message by the CPU core to be allocated, encapsulate the mapping value into the processed message during the processing, and transmit the processed message to the next device at the opposite end of the tunnel;

[0042] A sending module, configured to send the received processed message in the next device to the tunnel management module in the next device;

[0043] An extraction module, configured to extract the mapping value from the processed message by the tunnel management module;

[0044] A second processing module, configured to determine the CPU core to be processed corresponding to the processed message in the next device by the tunnel management module according to the mapping value, and send the processed message to the CPU core to be processed for processing.

[0045] On yet another aspect, an embodiment of the present specification further provides a computer device, including a memory, a processor, and a computer program stored on the memory. When the computer program is run by the processor, it executes the instructions of the method according to any one of the above.

[0046] On yet another aspect, an embodiment of the present specification further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by the processor of a computer device, it executes the instructions of the method according to any one of the above.

[0047] As can be seen from the technical solutions provided in the embodiments of this specification above, through the method of the embodiments of this specification, a mapping value can be obtained through the calculation of a hash value, and then the CPU core to be allocated corresponding to the packet in the current device can be determined. The CPU core to be allocated encapsulates the mapping value during the process of processing the packet and transmits it to the next device at the opposite end of the tunnel. The next device then determines the corresponding CPU core to be processed according to the mapping value. In this process, the principle of packet encapsulation is not violated, and different sessions can be evenly allocated to the corresponding CPU cores through calculation, improving the processing performance of the CPU.

[0048] To make the above and other purposes, features, and advantages of this specification more obvious and understandable, the following specific preferred embodiments are given, and detailed descriptions are made in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0050] Figure 1 The flowchart showing the method for session allocation within a tunnel of a multi-core CPU provided by the embodiments of this specification;

[0051] Figure 2 The flowchart showing the session management module determining the hash value corresponding to the packet provided by the embodiments of this specification;

[0052] Figure 3 The flowchart showing the process of calculating the mapping value corresponding to the hash value according to the hash value provided by the embodiments of this specification;

[0053] Figure 4 The schematic diagram showing the packet transfer between the current device and the next device provided by the embodiments of this specification;

[0054] Figure 5 The schematic diagram of the module structure of a device for session allocation within a tunnel of a multi-core CPU provided by the embodiments of this specification;

[0055] Figure 6 The schematic diagram of the structure of a computer device provided by the embodiments of this specification.

[0056] DESCRIPTION OF THE REFERENCE NUMERALS IN THE DRAWINGS:

[0057] 100, receiving module;

[0058] 200, calculation module;

[0059] 300. Determination module;

[0060] 400. First processing module;

[0061] 500. Sending module;

[0062] 600. Extraction module;

[0063] 700. Second processing module;

[0064] 602. Computer device;

[0065] 604. Processor;

[0066] 606. Memory;

[0067] 608. Driving mechanism;

[0068] 610. Input / output module;

[0069] 612. Input device;

[0070] 614. Output device;

[0071] 616. Rendering device;

[0072] 618. Graphical user interface;

[0073] 620. Network interface;

[0074] 622. Communication link;

[0075] 624. Communication bus. Detailed implementation manners

[0076] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts shall fall within the scope of protection of the embodiments of this specification.

[0077] First of all, it should be noted that the method in the embodiments of this specification is applied to session allocation in a tunnel. The tunnel technology is a data packet encapsulation technology. It can provide a path on an incompatible or insecure network, enabling packets of different protocol types to be transmitted on this path. The tunnel protocol repackages these packets of different protocols in a new packet header and sends them. The new packet header provides routing information, so that the encapsulated payload data can be transmitted through the Internet.

[0078] The tunnel includes an inner layer and an outer layer. The inner layer is the message, and the outer layer is the new packet header encapsulated by the tunnel. When a large number of sessions enter the same tunnel, the five-tuple of the tunnel outer layer corresponding to all sessions is the same, while the five-tuple of the tunnel inner layer corresponding to each session is different. The five-tuple refers to the source IP address, source port, destination IP address, destination port, and transport layer protocol.

[0079] When the current device transfers the session to the next device, if the hash value is calculated through the five-tuple of the tunnel outer layer to allocate CPU cores, all sessions will be concentrated on some CPU cores of the next device, resulting in uneven distribution of sessions and affecting the processing performance of the CPU. To achieve uniform distribution of sessions, the method described in the embodiments of this specification is proposed.

[0080] To solve the above problems, the embodiments of this specification provide a method for allocating sessions in a tunnel of a multi-core CPU. Figure 1 It is a schematic flowchart of a method for allocating sessions in a tunnel of a multi-core CPU provided by the embodiments of this specification. This specification provides the method operation steps as described in the embodiments or flowcharts, but based on routine or non-creative labor, it may include more or fewer operation steps. The step order listed in the embodiments is only one way among the execution orders of numerous steps, and does not represent the only execution order. When the actual system or device product executes, it can be executed in the order of the method shown in the embodiments or the drawings, or executed in parallel.

[0081] It should be noted that the terms "first", "second", etc. in the specification, claims, and the above drawings of the embodiments of this specification are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of this specification described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product, or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or equipment.

[0082] Referring to Figure 1 , the embodiments of this specification provide a method for allocating sessions in a tunnel of a multi-core CPU, including:

[0083] S101: The current device sends the received message to the session management module in the current device;

[0084] S102: The session management module determines the hash value corresponding to the message, and calculates the mapping value corresponding to the hash value according to the hash value;

[0085] S103: The session management module determines the CPU core to be allocated corresponding to the message according to the mapping value, and sends the message to the CPU core to be allocated for processing;

[0086] S104: The CPU core to be allocated processes the message, encapsulates the mapping value into the processed message during the processing, and transmits the processed message to the next device at the other end of the tunnel;

[0087] S105: The next device sends the received processed message to the tunnel management module in the next device;

[0088] S106: The tunnel management module extracts the mapping value according to the processed message;

[0089] S107: The tunnel management module determines the CPU core to be processed corresponding to the processed message in the next device according to the mapping value, and sends the processed message to the CPU core to be processed for processing.

[0090] The current device includes a session management module. The session management module can refer to a module implemented by software or a hardware function embedded in hardware, such as a hardware function embedded in a network card. The session management module manages the session table, which records the correspondence between the five-tuple of the message in the session and the hash value. For multiple messages in the same session, the five-tuples of the multiple messages are the same.

[0091] After determining the hash value corresponding to the message according to the session table, the mapping value can be calculated according to the hash value, and the CPU core to be allocated corresponding to the message in the current device can be determined according to the mapping value. The CPU core to be allocated is used to process the message. The message processing process includes the entire process of packet reception, encryption, encapsulation, and packet transmission, and the hash value will be encapsulated into the processed message, and then the processed message will be transmitted to the next device at the other end of the tunnel.

[0092] After the next device receives the processed message through the tunnel, the mapping value can be extracted, and the CPU core to be processed corresponding to the processed message in the next device can be determined according to the mapping value. The CPU core to be processed is used to process the processed message.

[0093] Among them, when the mapping value is encapsulated into the processed message, it can be encapsulated into the processed message by taking the mapping value as a part of the IP header, as a part of the TCP / UDP header, as a part of the tunnel encapsulation header, or as an independent header. The IP header refers to the IP header of the outer layer of the tunnel, the TCP / UDP header refers to the TCP / UDP header of the outer layer of the tunnel, and the header refers to the header of the outer layer of the tunnel. The mapping value can be placed at any of the above positions, and the next device can extract the mapping value from the corresponding position for calculation.

[0094] Since the five-tuples of all messages in the same session are the same, the corresponding hash values are the same, the calculated mapping values are also the same, and the corresponding CPU cores to be allocated and the CPU cores to be processed are also the same. Therefore, the CPU cores to be allocated and the CPU cores to be processed corresponding to different sessions may be different, thus achieving uniform distribution of sessions.

[0095] Refer to Figure 4 According to the method of the embodiments of this specification, the mapping value can be obtained through the calculation of the hash value, and then the CPU core to be allocated corresponding to the message in the current device can be determined. The allocated CPU core encapsulates the mapping value during the process of processing the message and transmits it to the next device at the opposite end of the tunnel. The next device then determines the corresponding CPU core to be processed according to the mapping value. In this process, the principle of message encapsulation is not damaged, and different sessions can be evenly distributed to the corresponding CPU cores through calculation, preventing excessive processing pressure on some CPU cores or excessive idleness of some CPU cores, thereby improving the processing performance of the CPU.

[0096] In the embodiments of this specification, refer to Figure 2 The session management module further determining the hash value corresponding to the message includes:

[0097] S201: The session management module determines whether the hash value corresponding to the message is recorded in the session table;

[0098] S202: If so, obtain the hash value corresponding to the message from the session table;

[0099] S203: If not, calculate the hash value corresponding to the message according to the five-tuple of the message, and record the corresponding relationship between the five-tuple of the message and the hash value in the session table.

[0100] If the hash value corresponding to the message is recorded in the session table, the hash value can be directly obtained from the session table. If it is not recorded in the session table, the hash value corresponding to the message is calculated according to the five-tuple of the message, and then the corresponding relationship between the five-tuple and the hash value is recorded in the session table.

[0101] In the embodiments of this specification, refer toFigure 3 The calculating of the mapping value corresponding to the hash value further includes:

[0102] S301: Determine different calculation methods for the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel;

[0103] S302: Calculate the mapping value corresponding to the hash value according to different calculation methods.

[0104] When the number of CPU cores of the devices at both ends of the tunnel is the same or different, the corresponding calculation methods for the mapping value are also different.

[0105] Specifically, the determining of different calculation methods for the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel further includes:

[0106] Step 1: If the number of CPU cores of the current device and the next device is the same, perform hash mapping using the number of CPU cores of the current device and the hash value to obtain the mapping value;

[0107] Step 2: If the number of CPU cores of the current device and the next device is different, perform hash mapping using the least common multiple of the number of CPU cores of the current device and the next device and the hash value to obtain the mapping value.

[0108] When creating the tunnel, an interaction process can be added to allow the current device and the next device to respectively inform the peer device of the number of CPU cores of their own devices.

[0109] The purpose of hash mapping is to map a larger value to a smaller interval. In the embodiments of this specification, the hash value is mapped to the interval [0, M), where M is the number of CPU cores of the current device or the least common multiple of the number of CPU cores of the current device and the next device. The mapping value obtained by hash mapping is a value within the interval [0, M). After performing hash mapping, the relatively scattered hash values can be evenly mapped to the corresponding intervals. The specific method of hash mapping can be: taking the modulus of the hash value with the number of CPU cores of the current device or the least common multiple of the number of CPU cores of the current device and the next device to obtain the mapping value.

[0110] Hash itself performs uniform hashing. For example, the commonly used MD5 is a uniform hash that results in a 16-byte number, while the Jenkins hash algorithm produces a 4-byte number. There are also some other hash methods that can give a smaller range. These hash values may not be divisible by the number of CPU cores of the current device and the next device. That is, there will be a small amount of imbalance when sessions are distributed according to the hash values. Therefore, hash mapping is required to evenly re-hash the hash values into the range of the least common multiple of the devices at both ends of the tunnel.

[0111] The following example illustrates the imbalance situation: Suppose the devices at both ends of the tunnel have 4 cores and 6 cores respectively, and 80,000 sessions are hashed to the 8 numbers from 0 to 7. This is equivalent to 10,000 sessions corresponding to each hash value. On the 4-core CPU, each CPU core is assigned 2 hash values, that is, 20,000 sessions, which is balanced. On the 6-core CPU, the first two CPU cores are assigned 2 hash values (20,000 sessions), and the last 4 CPU cores are each assigned 1 hash value (10,000 sessions), thus causing an imbalance in the session distribution.

[0112] In the embodiments of this specification, further including determining the CPU core to be allocated corresponding to the packet according to the mapping value:

[0113] If the number of CPU cores of the current device and the next device is the same, then use the CPU core corresponding to the mapping value as the CPU core to be allocated corresponding to the packet;

[0114] If the number of CPU cores of the current device and the next device is different, then take the modulo of the mapping value with the number of CPU cores of the current device to obtain a modulo value;

[0115] Use the CPU core corresponding to the modulo value as the CPU core to be allocated corresponding to the packet.

[0116] Refer to Figure 4 , if the number of CPU cores of the current device and the next device is the same, the calculated mapping value is the value obtained by evenly distributing the hash value. Since the hash values corresponding to all packets of the same session are the same, the session can be evenly distributed among the CPU cores of the current device. Since the number of CPU cores of the current device and the next device is the same, the mapping value can evenly distribute the session among the CPU cores of the current device, and thus can also evenly distribute the session among the CPU cores of the next device. The CPU cores of the current device are numbered starting from 0, and use the CPU core corresponding to the same serial number as the mapping value as the CPU core to be allocated.

[0117] If the number of CPU cores of the current device and the next device is different, although the mapping value calculated by the method similar to Step 1 can evenly distribute the sessions among the CPU cores of the current device, it cannot evenly distribute the sessions among the CPU cores of the next device. Therefore, the method of Step 2 needs to be used to calculate the mapping value. However, the obtained mapping value cannot be directly mapped to the serial number of the CPU core. Therefore, the mapping value can be modulo-divided by the number of CPU cores of the current device to obtain a modulo value, and the CPU core corresponding to the serial number equal to the modulo value is used as the CPU core to be allocated.

[0118] In the embodiments of this specification, the tunnel management module determining the CPU core to be processed corresponding to the processed message in the next device according to the mapping value further includes:

[0119] If the number of CPU cores of the current device and the next device is the same, the CPU core corresponding to the mapping value is used as the CPU core to be processed corresponding to the processed message;

[0120] If the number of CPU cores of the current device and the next device is different, the mapping value is modulo-divided by the number of CPU cores of the next device to obtain a modulo value;

[0121] The CPU core corresponding to the modulo value is used as the CPU core to be processed corresponding to the processed message.

[0122] Similar to the calculation method of the current device, the next device can obtain the corresponding CPU core to be processed.

[0123] In addition, after the processed message is sent to the CPU core to be processed for processing, it further includes:

[0124] The correspondence between the five-tuple of the processed message and the hash value is recorded in the session table of the session management module of the next device.

[0125] For the next device, it also has a session management module. Since the situation discussed above is that the current device sends a message to the session management device, and the next device can also send a message to the current device in the reverse direction, the corresponding logic is the same as that described above. Therefore, the session management module of the next device is used when sending a message in the reverse direction.

[0126] In one embodiment, the session receives packets from the network card of the current device. Since RSS is enabled on the network card, the initial hash value is automatically calculated and attached to the packets. However, the initial hash value calculated based on the network card cannot achieve uniform distribution of sessions. Therefore, after the packets are sent to the session management module, the session management module still calculates the mapping value according to the hash value by the method of the embodiments of this specification, where the hash value is calculated by the network card RSS, and then determines the serial number of the CPU core according to the mapping value, and hands the packets to the CPU core for processing.

[0127] Based on the method for session allocation in the tunnel of a multi-core CPU described above, the embodiments of this specification also correspondingly provide a device for session allocation in the tunnel of a multi-core CPU. The device may include a system (including a distributed system), software (application), module, component, server, client, etc. that uses the method of the embodiments of this specification and combines the necessary implementation hardware. Based on the same innovative concept, the devices in one or more embodiments provided by the embodiments of this specification are as described in the following embodiments. Since the implementation solutions for the device to solve problems are similar to the method, the implementation of the specific device in the embodiments of this specification can refer to the implementation of the foregoing method, and the repeated parts will not be elaborated. As used hereinafter, the term "unit" or "module" may be a combination of software and / or hardware that can implement a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0128] Specifically, Figure 5 is a schematic diagram of the module structure of an embodiment of a device for session allocation in the tunnel of a multi-core CPU provided by the embodiments of this specification. Referring to Figure 5 as shown, a device for session allocation in the tunnel of a multi-core CPU provided by the embodiments of this specification includes: a receiving module 100, a calculating module 200, a determining module 300, a first processing module 400, a sending module 500, an extracting module 600, and a second processing module 700.

[0129] The receiving module 100 is configured to send the received packets from the current device to the session management module in the current device;

[0130] The calculating module 200 is configured to determine the hash value corresponding to the packet by the session management module and calculate the mapping value corresponding to the hash value according to the hash value;

[0131] The determining module 300 is configured to determine the CPU core to be allocated corresponding to the packet by the session management module according to the mapping value, and send the packet into the CPU core to be allocated for processing;

[0132] The first processing module 400 is used to process the packet by the CPU to be allocated, encapsulate the mapping value into the processed packet during the processing, and transmit the processed packet to the next device at the tunnel peer end;

[0133] The sending module 500 is used to send the received processed packet in the next device to the tunnel management module in the next device;

[0134] The extraction module 600 is used for the tunnel management module to extract the mapping value according to the processed packet;

[0135] The second processing module 700 is used for the tunnel management module to determine the CPU core to be processed corresponding to the processed packet in the next device according to the mapping value, and send the processed packet into the CPU core to be processed for processing.

[0136] Refer to Figure 6 As shown, based on the above-mentioned method for allocating sessions in a tunnel of a multi-core CPU, an embodiment of this specification also provides a computer device 602, where the above method runs on the computer device 602. The computer device 602 may include one or more processors 604, such as one or more central processing units (CPUs) or graphics processing units (GPUs), and each processing unit may implement one or more hardware threads. The computer device 602 may also include any memory 606 for storing any kind of information such as code, settings, data, etc. In a specific implementation, a computer program stored on the memory 606 and executable on the processor 604, when run by the processor 604, may execute instructions according to the above method. Non-limiting, for example, the memory 606 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory devices, hard disks, optical discs, etc. More generally, any memory may use any technology to store information. Further, any memory may provide volatile or non-volatile retention of information. Further, any memory may represent a fixed or removable component of the computer device 602. In one case, when the processor 604 executes the associated instructions stored in any memory or combination of memories, the computer device 602 may perform any operation of the associated instructions. The computer device 602 also includes one or more drive mechanisms 608 for interacting with any memory, such as a hard disk drive mechanism, an optical disc drive mechanism, etc.

[0137] The computer device 602 may also include an input / output module 610 (I / O) for receiving various inputs (via the input device 612) and for providing various outputs (via the output device 614). A specific output mechanism may include a presentation device 616 and an associated graphical user interface 618 (GUI). In other embodiments, the input / output module 610 (I / O), the input device 612, and the output device 614 may not be included, and it may only be a computer device in the network. The computer device 602 may also include one or more network interfaces 620 for exchanging data with other devices via one or more communication links 622. One or more communication buses 624 couple the components described above together.

[0138] The communication link 622 may be implemented in any way, for example, via a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 622 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.

[0139] Corresponding to Figures 1 - 3 In accordance with the method in [description], an embodiment of this specification also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is run by a processor, it executes the steps of the above method.

[0140] An embodiment of this specification also provides a computer-readable instruction. When the processor executes the instruction, the program therein causes the processor to execute the method as Figures 1 to 3 shown.

[0141] It should be understood that in various embodiments of this specification, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this specification.

[0142] It should also be understood that in the embodiments of this specification, the term "and / or" is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the embodiments of this specification generally represents an "or" relationship between the associated objects before and after.

[0143] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this specification can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this specification's embodiments.

[0144] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here.

[0145] In the several embodiments provided in this specification, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, or can also be electrical, mechanical, or other forms of connection.

[0146] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can also be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this specification's embodiments.

[0147] In addition, the functional units in each embodiment of this specification can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0148] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the embodiments of this specification, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of this specification. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.

[0149] Specific embodiments are used in this specification to elaborate on the principles and implementation manners of the embodiments of this specification. The description of the above embodiments is only used to help understand the methods and their core ideas of the embodiments of this specification; at the same time, for those of ordinary skill in the art, according to the ideas of the embodiments of this specification, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the embodiments of this specification.

Claims

1. A method for session allocation in a tunnel of a multi-core CPU, characterized in that, Including: The current device sends the received packet to the session management module in the current device; The session management module determines the hash value corresponding to the packet, and calculates the mapping value corresponding to the hash value according to the hash value; The session management module determines the CPU core to be allocated corresponding to the packet according to the mapping value, and sends the packet into the CPU core to be allocated for processing; The CPU core to be allocated processes the packet, encapsulates the mapping value into the processed packet during the processing, and transmits the processed packet to the next device at the opposite end of the tunnel; The next device sends the received processed packet to the tunnel management module in the next device; The tunnel management module extracts the mapping value according to the processed packet; The tunnel management module determines the CPU core to be processed corresponding to the processed packet in the next device according to the mapping value, and sends the processed packet into the CPU core to be processed for processing.

2. The method according to claim 1, wherein The session management module determining the hash value corresponding to the packet further includes: The session management module determines whether the hash value corresponding to the packet is recorded in the session table; If so, obtain the hash value corresponding to the packet from the session table; If not, calculate the hash value corresponding to the packet according to the five-tuple of the packet, and record the corresponding relationship between the five-tuple of the packet and the hash value in the session table.

3. The method according to claim 1, wherein The calculating the mapping value corresponding to the hash value according to the hash value further includes: Determine different calculation methods for the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel; Calculate the mapping value corresponding to the hash value according to different calculation methods.

4. The method according to claim 3, wherein The determining different calculation methods for the mapping value according to the relationship between the number of CPU cores of the current device and the next device at both ends of the tunnel further includes: If the number of CPU cores of the current device and the next device is the same, perform hash mapping using the number of CPU cores of the current device and the hash value to obtain the mapping value; If the number of CPU cores of the current device and the next device is different, perform hash mapping using the least common multiple of the number of CPU cores of the current device and the next device and the hash value to obtain the mapping value.

5. The method according to claim 4, wherein The determining the CPU core to be allocated corresponding to the packet according to the mapping value further includes: If the number of CPU cores of the current device and the next device is the same, use the CPU core corresponding to the mapping value as the CPU core to be allocated corresponding to the packet; If the number of CPU cores of the current device and the next device is different, take the modulo of the mapping value with the number of CPU cores of the current device to obtain the modulo value; Use the CPU core corresponding to the modulo value as the CPU core to be allocated corresponding to the packet.

6. The method according to claim 1, wherein The encapsulating the mapping value into the processed packet further includes: By encapsulating the mapping value into the processed packet as a part of the IP header, as a part of the TCP / UDP header, as a part of the tunnel encapsulation header, or as an independent header.

7. The method according to claim 1, wherein The tunnel management module further determining the CPU core to be processed corresponding to the processed packet in the next device according to the mapping value includes: If the number of CPU cores of the current device and the next device is the same, using the CPU core corresponding to the mapping value as the CPU core to be processed corresponding to the processed packet; If the number of CPU cores of the current device and the next device is different, taking the modulus of the number of CPU cores of the next device with the mapping value to obtain a modulus value; Using the CPU core corresponding to the modulus value as the CPU core to be processed corresponding to the processed packet.

8. The method according to claim 1, wherein After sending the processed packet into the CPU core to be processed for processing, it further includes: Recording the correspondence between the five-tuple of the processed packet and the hash value into the session table of the session management module of the next device.

9. A tunnel session allocation device for a multi-core CPU, characterized in that, The device includes: A receiving module, configured to send the packet received by the current device to the session management module in the current device; A calculating module, configured to determine the hash value corresponding to the packet by the session management module, and calculate the mapping value corresponding to the hash value; A determining module, configured to determine the CPU core to be allocated corresponding to the packet by the session management module according to the mapping value, and send the packet into the CPU core to be allocated for processing; A first processing module, configured to process the packet by the CPU core to be allocated, encapsulating the mapping value into the processed packet during the processing, and transmitting the processed packet to the next device at the tunnel peer; A sending module, configured to send the received processed packet in the next device to the tunnel management module in the next device; An extracting module, configured to extract the mapping value from the processed packet by the tunnel management module; A second processing module, configured to determine the CPU core to be processed corresponding to the processed packet in the next device by the tunnel management module according to the mapping value, and send the processed packet into the CPU core to be processed for processing.

10. A computer device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, When the computer program is run by the processor, it executes the instructions of the method according to any one of claims 1-8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is run by the processor of the computer device, it executes the instructions of the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Message processing method and device, message processing chip and server

    CN107659515A

  • Message forwarding method and device, storage medium and electronic equipment

    CN112965824A