Methods, apparatus, equipment and media for implementing H-VPN hierarchical management of SRV6 policy networks

By generating and associating SRV6 policies in the BGP of SPE devices, the problem of SRV6 VPN SID exchange failure was solved, enabling EVPN L2/L3 service layered management in SRV6 networks, and improving forwarding efficiency and network performance.

CN117640486BActive Publication Date: 2026-08-04CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2022-08-11
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In existing technologies, SRV6 VPN SIDs cannot be exchanged at SPE nodes, which prevents H-VPN deployment from achieving hierarchical management. Furthermore, SRV6 routing requires full network connectivity, increasing network routing volume and service pressure on SPE nodes.

Method used

By receiving service routes in the BGP of the SPE device, selecting the target SID type based on the service scenario, generating the target SRV6 policy, and associating it with the target SID type, the target service route is generated. VPN SID exchange can be directly implemented on the SPE node without deploying a VPN instance.

Benefits of technology

It enables hierarchical management of EVPN L2/L3 services in SRV6 networks, reducing network pressure and improving service forwarding efficiency. SPE nodes can directly exchange IPv6 addresses and generate SRv6 policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117640486B_ABST
    Figure CN117640486B_ABST
Patent Text Reader

Abstract

This disclosure provides a method, apparatus, device, and medium for implementing H-VPN hierarchical management of SRV6policy networks, relating to the field of communication technology. The method includes: receiving a service route sent by a first device, the service route carrying a service label and a color value; selecting a target SID type from preset SID types based on the service scenario to which the service route belongs; generating a target SRV6policy based on the color value and the service label; associating the target SID type and the target SRV6policy to generate a target service route, where the next hop of the SID corresponding to the target SID type in the target service route is the target SRV6policy; and sending the target service route to a second device, so that the second device forwards the route based on an address lookup table in the target service route. According to embodiments of this disclosure, the SPE does not need to deploy a VPN instance and can directly implement VPNSID exchange, realizing H-VPN hierarchical management of EVPN L2 / L3 services in the SRV6policy network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a method, apparatus, device and medium for implementing H-VPN hierarchical management of SRV6 policy networks. Background Technology

[0002] In an H-VPN+MPLS tunnel, after a UPE service packet arrives at the SPE, the inner service label is switched, and then the service label is superimposed on the outer tunnel and sent to the PE node. However, for an H-VPN+SRV6 tunnel, since the SPE does not have a VPN instance configured, there is currently no way to implement SRV6 service label (VPN SID) switching; therefore, there is no existing method for implementing H-VPN+SRV6 services in the industry. In related technologies, the Layer 2 services of SRV6 services all establish MP-BGP neighbors directly between the source and destination nodes, and the source and destination nodes directly advertise the VPN SID to the peer. This routing does not achieve hierarchical structure; it is an end-to-end VPN service.

[0003] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0004] The inventors discovered through research that current EVPN L3VPN / VPWS / VPLS cannot achieve MPLS label-like switching due to the inability of SRV6 VPN SIDs to implement hierarchical H-VPN deployment. Therefore, they can only use point-to-point BGP neighbor establishment to achieve service deployment, and SRV6 routing needs to be fully connected across the network. This method increases the total number of routes across the network and is not conducive to hierarchical management.

[0005] As an example, the interpretation of the terms in this application is based on the definitions of the standard protocols of the China Communications Standards Association.

[0006] According to a first aspect of this disclosure, a method for implementing hierarchical management of SRV6 policy networks H-VPN is provided, applied to BGP of SPE devices, the method comprising:

[0007] Receive the service route sent by the first device. The service route carries a service label and a color value.

[0008] Based on the business scenario to which the business route belongs, select the target SID type from the preset SID types;

[0009] Generate the target SRV6 policy based on the color value and business tag;

[0010] Associate the target SID type with the target SRV6 policy to generate a target service route. The next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy.

[0011] The target service route is sent to the second device so that the second device can look up the address in the target service route and forward it.

[0012] In one embodiment of this disclosure, a target SRV6 policy is generated based on the color value and the business tag, including:

[0013] Based on the color value, the first SRV6 policy can be retrieved.

[0014] Generate a second SRV6 policy, whose sidlist is the same as that of the first SRV6 policy;

[0015] Based on the second SRV6 policy and the business tag, the target SRV6 policy is obtained.

[0016] In one embodiment of this disclosure, the final layer of the target SRV6 policy is a service tag. In one embodiment of this disclosure, the service scenario includes at least one of the following scenarios:

[0017] IPv4 H-VPN scenario, IPv6 H-VPN scenario, EVPN VPWS H-VPN scenario, EVPN VPLS H-VPN scenario.

[0018] In one embodiment of this disclosure, when the service routing belongs to an IPv4 H-VPN scenario, the first SID type is selected;

[0019] When the service routing belongs to the IPv6 H-VPN scenario, select the second SID type;

[0020] When the service routing belongs to the EVPN VPWS H-VPN scenario, select the third SID type;

[0021] When the service routing belongs to the EVPN VPLS H-VPN scenario, select the fourth SID type.

[0022] In one embodiment of this disclosure, if the first device is an NPE device, the second device is a UPE device; if the first device is a UPE device, the second device is an NPE device.

[0023] In one embodiment of this disclosure, routing the target service to the second device includes:

[0024] The target service route is sent to the second device via an update message.

[0025] In one embodiment of this disclosure, the update message also carries at least one of the following attributes:

[0026] RT attribute, target SID type attribute, color attribute.

[0027] In one embodiment of this disclosure, the method further includes:

[0028] Obtain the network segment route corresponding to the SRv6 SID through the IGP protocol.

[0029] According to a second aspect of this disclosure, an apparatus for implementing H-VPN hierarchical management of SRV6 policy networks is provided, applied to BGP of SPE devices, the apparatus comprising:

[0030] The routing message receiving module is used to receive service routes sent by the first device. The service routes carry service labels and color values.

[0031] The judgment module is used to select the target SID type from the preset SID types based on the business scenario to which the business route belongs;

[0032] The first data processing module generates the target SRV6 policy based on the color value and business tag.

[0033] The second data processing module associates the target SID type with the target SRV6 policy to generate a target service route. The next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy.

[0034] The data sending module is used to send the target service route to the second device, so that the second device can look up the address in the target service route and forward it.

[0035] According to a third aspect of this disclosure, an electronic device is provided, comprising: a memory for storing instructions; and a processor for calling the instructions stored in the memory to implement the above-described method for implementing H-VPN hierarchical management of SRV6 policy networks.

[0036] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided that stores computer instructions thereon, which, when executed by a processor, implement the above-described method for implementing H-VPN hierarchical management of SRV6 policy networks.

[0037] According to a fifth aspect of this disclosure, a computer program product is provided, which stores instructions that, when executed by a computer, cause the computer to implement the above-described method for implementing H-VPN hierarchical management of SRV6 policy networks.

[0038] According to a sixth aspect of this disclosure, a chip is provided, including at least one processor and an interface;

[0039] An interface is used to provide program instructions or data to at least one processor;

[0040] At least one processor is used to execute program instructions to implement the above-described method for implementing H-VPN hierarchical management of SRV6 policy networks.

[0041] The method, apparatus, device, and medium for implementing H-VPN hierarchical management of SRV6 policy networks provided in this disclosure, based on the service scenario to which the service route belongs, selects a target SID type from preset SID types, generates a target SRV6 policy according to the color value and service label, then associates the target SID type and the target SRV6 policy to generate a target service route, where the next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy; and sends the target service route to a second device so that the second device can forward the route by looking up the address in the target service route. In this disclosure, the SPE does not need to deploy a VPN instance and can directly implement VPN SID exchange, thereby achieving H-VPN hierarchical management of EVPNL2 / L3 services in the SRV6 policy network.

[0042] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0043] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0044] Obviously, the accompanying drawings described below are merely some embodiments of this disclosure. Those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0045] Figure 1 This diagram illustrates the EVPN, L3VPN, and HoVPN service architecture in related technologies.

[0046] Figure 2This invention discloses a flowchart illustrating a method for implementing hierarchical management of H-VPN in an SRV6 policy network according to an embodiment of the present disclosure.

[0047] Figure 3 This diagram illustrates the mapping of END.BDT6.SID to SRV6-POLICY in an embodiment of this disclosure.

[0048] Figure 4 This diagram illustrates the generation of END.BDT6.SID in an embodiment of this disclosure.

[0049] Figure 5 This illustration shows a service forwarding diagram where the next hop for END.BDT6.SID is SRV6-POLICY, as shown in this embodiment of the present disclosure.

[0050] Figure 6 This diagram illustrates an apparatus for implementing hierarchical management of SRV6 policy network H-VPN according to an embodiment of the present disclosure;

[0051] Figure 7 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation

[0052] The exemplary implementation will now be described more fully with reference to the accompanying drawings.

[0053] It should be noted that the example implementation can be implemented in many forms and should not be construed as being limited to the examples set forth herein.

[0054] Most current network designs adopt traditional layered structures. For example, a typical metropolitan area network (MAN) has a three-layer model: core layer, aggregation layer, and access layer. BGP / MPLS IP VPN, however, is a flat model where all physical network entities (PEs) are on the same plane. To deploy VPN functionality in a layered network, BGP / MPLS IP VPN must be transformed from a flat model to a layered model. Therefore, the Hierarchy of VPN (HVPN) solution has been proposed.

[0055] HVPN solutions distribute the functionality of a PE (Pressure Equipment) across multiple PE devices. These PEs perform different roles, forming a hierarchical structure that collectively performs the functions of a single PE. Therefore, this solution is sometimes referred to as a layered PE solution.

[0056] An SRv6 segment is an IPv6 address format, often referred to as an SRv6 SID (SegmentIdentifier). As shown in the diagram, an SRv6 SID consists of two parts: a Locator and a Function. The format is Locator:Function, where the Locator occupies the high-order bits of the IPv6 address, and the Function occupies the remaining bits of the IPv6 address.

[0057] The Locator has a location function, so it must be unique within the SR domain. After a node is configured with a Locator, the system generates a Locator network segment route and distributes it within the domain via IGP. Other nodes in the network can locate this node through the Locator network segment route.

[0058] Function represents the device's instructions, which are pre-defined by the device. The Function section is used to instruct the SRv6 SID generation node to perform the corresponding functional operations.

[0059] Nodes that enable SRv6 maintain a local SID table, which contains all SRv6 SID information generated on the node. An SRv6 forwarding table (FIB) can be generated based on this table.

[0060] The Local SID table has the following uses:

[0061] 1. Define a locally generated SID, such as End.X SID.

[0062] 2. Specify the instructions to bind to these SIDs.

[0063] 3. Store forwarding information related to these instructions, such as the outgoing interface and the next hop.

[0064] In an H-VPN+MPLS tunnel, after a UPE service packet arrives at the SPE, the inner service label is switched, and then the service label is superimposed on the outer tunnel and sent to the PE node.

[0065] For H-VPN+SRV6 tunnels, since the SPE does not have a VPN instance configured, there is currently no way to implement SRV6 VPNSID exchange, and there is no existing method in the industry to implement H-VPN+SRV6 services. Currently, the Layer 2 services for SRV6 all establish MP-BGP neighbors directly between the source and destination nodes, and the source and destination nodes directly advertise the VPN SID to the peer. In this way, the routing does not achieve hierarchical structure, and it is an end-to-end VPN service.

[0066] The inventors discovered the following problems in the related technology:

[0067] Currently, EVPN L3VPN / VPWS / VPLS cannot achieve MPLS label-like switching due to the inability of IPv6 VPNSID to implement hierarchical H-VPN deployment. Therefore, it can only use point-to-point BGP neighbor establishment to achieve service deployment, and SRV6 routing needs to be connected across the entire network. This method increases the total number of routes across the network and is not conducive to hierarchical management.

[0068] For existing EVPN, L3VPN, and HoVPN services, by deploying VPN services on SPE nodes, traffic from both UPE and NPE ends up at the SPE before routing. However, after VPN deployment, the SPE nodes need to generate a large number of VPN service routes, placing significant pressure on the SPEs.

[0069] When configuring the EVPN L3VPN HoVPN model, services from both UPE and NPE nodes need to be routed to the SPE before being forwarded, resulting in low service forwarding efficiency.

[0070] like Figure 1 In the related technologies shown, the SRV6 EVPN L3VPN HOVPN service deploys VPN instances on SPE nodes. Services originating from both UPE and NPE are routed to the SPE before being checked against the routing forwarding mechanism. After deploying the VPN, the SPE node needs to maintain VPN service routes.

[0071] When configuring an EVPN, L3VPN, or HoVPN model, services from both UPE and NPE nodes need to be routed to the SPE before being forwarded, resulting in low service forwarding efficiency. After deploying the VPN, the SPE node needs to generate a large number of VPN service routes, placing significant pressure on the SPE.

[0072] In this embodiment, H-VPN hierarchical management of L2 / L3 services in SRV6 network is achieved by exchanging new service SIDs. SPE nodes directly exchange SRV6 VPN SIDs without needing to look up VPN service routes after the service is deployed. Furthermore, SPE does not need to deploy VPN instances, and services can directly exchange IPv6 addresses on SPE nodes, improving forwarding efficiency.

[0073] The following detailed description of this exemplary implementation method is provided in conjunction with the accompanying drawings and embodiments.

[0074] Figure 2 This disclosure illustrates a method for implementing hierarchical management of SRV6 policy network H-VPN, applied to the BGP of an SPE device, such as... Figure 1 As shown, the NAME method provided in this embodiment includes the following steps:

[0075] S202, Receive the service route sent by the first device. The service route carries a service label and a color value.

[0076] S204, based on the business scenario to which the service route belongs, select the target SID type from the preset SID types;

[0077] S206, Generate the target SRV6 policy based on the color value and business tag;

[0078] S208, associate the target SID type with the target SRV6 policy to generate the target service route. The next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy.

[0079] S210, the target service route is sent to the second device so that the second device can look up the table and forward it according to the address in the target service route.

[0080] In some embodiments, the service route can be the VPNv6 route corresponding to the VPNv6 service.

[0081] It should be noted that the embodiments disclosed herein can be applied to H-VPN layered deployment scenarios carrying SRV6 EVPN VPWS / VPLS / L3VPN services on the network. These embodiments can meet the layered deployment requirements of SRV6 EVPN L2 and L3 services, reducing network load.

[0082] In this embodiment of the disclosure, the first device and the second device may be an NPE device and / or a UPE device.

[0083] As an example, in the case where the first device is an NPE device, the second device is a UPE device.

[0084] As another example, if the first device is a UPE device, the second device is an NPE device.

[0085] SRv6 Policy utilizes the source routing mechanism of Segment Routing, guiding packets across the network by encapsulating an ordered list of instructions at the header node. Besides indicating forwarding paths, SRv6 can also indicate VASs, such as firewalls, application acceleration, and other network functions, or user gateways. SRv6 Policy enables end-to-end service requirements and is the primary mechanism for implementing SRv6 network programming.

[0086] In some embodiments, the SRv6 Policy includes the following elements: Key value, Candidate Path, SegmentList, and Binding SID.

[0087] As an example, an SRv6 Policy uses the following triplet as a key to globally and uniquely identify an SRv6 Policy: Headend, Color, and Endpoint.

[0088] The headend directs traffic into an SRv6 Policy. The color identifies the SRv6 Policy's ID, which can be associated with a range of service attributes, such as low latency and high bandwidth; it can be understood as a service requirement template ID, and its value can be assigned by the administrator. The endpoint identifies the destination address of the SRv6 Policy.

[0089] In some embodiments, the business scenario in S204 above may include at least one of the following scenarios:

[0090] IPv4 H-VPN scenario, IPv6 H-VPN scenario, EVPN VPWS H-VPN scenario, EVPN VPLS H-VPN scenario.

[0091] In the above S204, when the service scenario to which the service route belongs is an IPv4 H-VPN scenario, the first SID type is selected;

[0092] In the above S204, when the service scenario to which the service route belongs is an IPv6 H-VPN scenario, the second SID type is selected;

[0093] In the above S204, when the service scenario to which the service route belongs is an EVPN VPWS H-VPN scenario, the third SID type is selected;

[0094] In the above S204, when the service scenario to which the service route belongs is an EVPN VPLS H-VPN scenario, the fourth SID type is selected.

[0095] In the embodiments disclosed herein, the terms “first,” “second,” “third,” and “fourth,” etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0096] In the above example, the first SID type, the second SID type, the third SID type, and the fourth SID type are only used to represent different SID types. In specific implementations, SID types may also have other names.

[0097] As an example, the first SID type can be End.BDT4 SID, the second SID type can be End.BDT6 SID, the third SID type can be End.BDX2 SID, and the fourth SID type can be END.BDT2U SID.

[0098] End.BDT4 SID: End.BDT4 SID is used in SRV6 H-VPN (IPv4 private network) scenarios. It is used to replace a new next hop. The bottom layer of the SID LIST is the service label (VPN SID), and the outermost SID is updated to the DIP. Forwarding is then performed based on the new IPv6 address lookup table. End.BDT4 SID is used in IPv4 H-VPN scenarios.

[0099] End.BDT6 SID: End.BDT6 SID is used in SRV6 H-VPN (IPv6 private network) scenarios. It is used to replace a new next hop. The bottom layer of the SID LIST is the service label (VPN SID), and the outermost SID is updated to the DIP. Forwarding is then performed based on the new IPv6 address lookup table. End.BDT6 SID is used in IPv6 H-VPN scenarios.

[0100] End.BDX2 SID: End.BDX2 SID represents the scenario of SRV6 EVPN VPWS H-VPN service. It is used to replace a new next hop. The bottom layer of the SID LIST is the service label (VPN SID), and the outermost SID is updated to the DIP. Forwarding is then performed based on the new IPv6 address lookup table. End.BDX2 SID can be used in EVPN VPWS H-VPN scenarios.

[0101] END.BDT2U SID: End.BDT2U SID represents a scenario for SRV6 EVPN VPLS H-VPN services. It is used to replace the previous hop with a new one. The bottom layer of the SID list is the service label (VPN SID), and the outermost SID is updated to the DIP. Forwarding is then performed based on the new IPv6 address lookup table. It can be used in EVPN VPLS H-VPN scenarios.

[0102] In some embodiments, this disclosure also adds an SRV6 SID next-hop attribute.

[0103] For END.BDT6, END.BDT4, END.BDX2, and END.BDT2U, a new next-hop attribute flag is added. If the next hop is an SRV6-POLICY tunnel, the flag is set to 1; the default value is 0.

[0104] In some embodiments, the process of S206 generating the target SRV6 policy is as follows:

[0105] Based on the color value, the first SRV6 policy is retrieved; the second SRV6 policy is generated, and the sidlist of the second SRV6 policy is the sidlist of the first SRV6 policy; based on the second SRV6 policy and the business tag, the target SRV6 policy is obtained.

[0106] In one embodiment of this disclosure, the final layer of the target SRV6 policy is the service label.

[0107] The following section, using the above example, details the mapping of VPN SIDs.

[0108] For L3 VPNV6+SRV6 H-VPN services, the NPE advertises the service route to the SPE via MP-BGP, carrying VPN SID A and COLOR C. The SPE then requests a new END.BDT6 B locally via BGP.

[0109] For L3 VPNV4+SRV6 H-VPN services, the NPE advertises VPNv4 routes to the SPE via MP-BGP, carrying VPN SID A and COLOR C. The SPE then requests a new END.BDT4 B locally via BGP.

[0110] For the EVPN VPWS+SRV6 H-VPN service, the NPE advertises a Type 1 route to the SPE via MP-BGP, carrying the service SID A and COLOR C. The SPE then requests a new END.BDX2 B locally via BGP.

[0111] For EVPN VPLS+SRV6 H-VPN services, the NPE advertises Type 2 routes to the SPE via MP-BGP, carrying the service SID A and COLOR C. The SPE then locally requests a new END.BDT2U B.

[0112] For SRV6 POLICY services, the SRv6 Policy tunnel flag is set to 1, and the next-hop attribute is modified to SRV6POLICY.

[0113] Based on COLOR C, POLICY S is located. BGP dynamically requests an SRV6 POLICY A1, copies the SIDLIST of POLICY S to A1, and then copies the business VPN SID A to the last layer of the SIDLIST of A1. The next hop of END.BDT6 / END.BDT4 / END.BDX2 / END.BDT2U is set to SRV6 POLICY A1.

[0114] As an example, such as Figure 3 The SRv6 policy service on the NPE is shown, and BGP marks different VPN routes with colors.

[0115] The SPE receives the NPE service route, such as: private network route 2001::1 / 128, VPN SID A2:1:: 100, color: C.

[0116] SPE finds the corresponding policy based on the color, generates a new END.BDT6 SID A and policy A1, sets the next-hop attribute of A to SRV6-POLICY, binds SID A to policy A1, copies the sidlist of policy S to A1, and adds a VPN SID to the innermost layer of A1.

[0117] As an example, the rules for generating dynamic POLICY are as follows:

[0118] policy Name color C endpoint XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX:XXXX

[0119] Where color+endpoint is the policy key, color = system reserved starting value + policy S color, endpoint is the NPE loopback interface, which is dynamically requested and created by BGP from SRRP. At the same time, an attribute is added to this policy: BDT6 flag, which is used exclusively for END.DT6 services and other services cannot be overlaid with this policy; the policy's sidlist is a combination of policyS and VPN SID, and END.BDT6 is associated with the policy.

[0120] SPE replaces NPE's VPNSID with END.BDT6.SID A, and sends END.BDT6.SID A as the new VPN SID to UPE via an update message.

[0121] As another example, BGP dynamically generates SRV6-POLICY rules as follows:

[0122] The key values ​​for SRV6-POLICY are COLOR and ENDPOINT. Assuming the VPNSID of the BGP VPN message sent by NPE / UPE to SPE is A, and the COLOR value is C, when SPE dynamically generates SRV6-POLICY A1 for the END.BDT tag, A1's COLOR is assigned the value C, and its ENDPOINT is assigned the value 127.0.0::1. Based on the COLOR value of the NPE / UPE VPN message and the PEER IP, SPE searches for SRV6-POLICY locally. If SRV6-POLICY S is found, its SIDLIST is copied to A1, and VPN SID A is copied to the last hop of A1. Simultaneously, END.BDT6 / END.BDT4 / END.BDX2 / END.BDT2U are associated with A1, and the next hop is set to SRV6-POLICY A1.

[0123] Tag push NPE->SPE->UPE: After the SPE device's BGP receives the NPE's service tag A, it dynamically generates an END.BDT6 / END.BDT4 / END.BDX2 / END.BDT2U tag and uses this tag as the service tag to push it to the UPE device via the BGPUPDATE message; the reverse process is the same, UPE->SPE->NPE.

[0124] Figure 4 This diagram illustrates the generation of END.BDT6.SID, which is the BGP protocol label implementation process in this embodiment of the disclosure. In this example, the service route is a VPNv6 route, such as... Figure 4 As shown, the BGP protocol label implementation process includes the following steps:

[0125] S401, configure SRv6 VPN.

[0126] The PE device is configured with SRv6 and SRv6 VPN, while the intermediate node SPE device does not need to be configured with SRV6 VPN.

[0127] S402 publishes SRv6 Locator routes to other PE devices.

[0128] NPE2 distributes SRv6 Locator routes to other PE devices.

[0129] S403, publish IPv6 routes.

[0130] S404, Install VPN instance route, generate VPNv6 route.

[0131] S405, publishes VPNv6 routes, carrying VPN SID, color.

[0132] S406, SPE locally requests END.BDT6 via BGP and generates a new policy A. The innermost layer of SIDLIST in A is VPNSID, which is associated with END.BDT6. Then, VPNv6 routes are published, carrying VPN SID (END.BDT6) to UPE.

[0133] S407 receives VPNv6 routes and installs VPN instance routes carrying SRv6 VPN SIDs.

[0134] Routing information exchange from CE to PE: CE2 advertises its local IPv6 routes to NPE. After learning the VPN routing information from CE2, NPE stores it in the VPN instance routing table. Simultaneously, it translates it into VPNv6 routes.

[0135] Route advertising between PEs: The NPE advertises VPNv6 routes to the SPE via MP-BGP, carrying VPN SID A and COLOR C. The SPE locally requests a new END.BDT6 SID B using BGP, and simultaneously queries the policy based on the color, finding policy N. A new policy M is then generated, and the sidlist of policy N is copied to the sidlist of policy M, with SID A added at the end. END.BDT6 SID B is then associated with policy M, and an Update message is sent to the UPE.

[0136] In some embodiments, the update message also carries at least one of the following attributes: RT attribute, target SID type attribute, and color attribute.

[0137] As an example, the update message carries the RT attribute, the SRv6 VPN SID B attribute, and the COLOR attribute.

[0138] After receiving the VPNv4 route, the UPE sends the VPN route and simultaneously associates it with the SRv6 VPN SID B.

[0139] Figure 5 This diagram illustrates a service forwarding scenario where the next hop for END.BDT6.SID is SRV6-POLICY. In this example, the service route is a VPNv6 route. Figure 5 As shown, the service forwarding implementation process is as follows:

[0140] Configure the END SID on the NPE, and then publish it to the SPE and UPE via the IGP protocol.

[0141] UPE learns the network segment route A2:1:: / 64 corresponding to the SRv6 SID through the IGP protocol.

[0142] The NPE automatically generates the END.DT6 SID A2:1::100 for the VPN instance within the END SID range, and generates the LocalSID table.

[0143] After receiving the private IPv6 route published by CE2, NPE converts the private IPv6 route into a BGP VPNv6 route and publishes it to SPE. This route carries the SRv6 VPN SID attribute: VPNSID A2:1::100, color C.

[0144] After receiving the VPNv6 route, the SPE generates a new END.BDT6 A3:1::1, policy M, and copies the sidlist of policy N obtained through color lookup to policy M. It then adds a VPN sid: A2:1::100 to the innermost layer of M. Finally, it sends the VPNv6 route to the UPE, carrying the SRV6 VPN SID A3:1::1.

[0145] After receiving the VPNv6 route, the UPE cross-references it to the corresponding VPN instance routing table, then converts it into a regular IPv6 route and publishes it to CE1.

[0146] refer to Figure 5 The data forwarding phase process is as follows:

[0147] CE1 sends a regular IPv6 message to UPE.

[0148] After receiving a private network packet from the interface bound to the VPN instance, the UPE searches the routing table of the corresponding VPN instance, matches the destination IPv6 prefix, and finds the associated SRv6 VPN SID and next-hop information. Then, it directly encapsulates the packet into an IPv6 packet using the SRv6VPN SID A3:1::1 as the destination address.

[0149] When the SPE receives the message, it resolves the outer DIP A3:1::1 to the local END.BDT6, adds an SRH header, fills the first label of the SRH header into the DIP, and then looks up the routing table to send it to the NPE.

[0150] The NPE uses A2:1::100 to look up the Local SID table, matches the forwarding action corresponding to END.DT6 SID, removes the IPv6 header, and then matches the VPN instance based on END.DT6 SID, looks up the VPN instance routing table, and forwards the packet.

[0151] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result.

[0152] In some embodiments, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be broken down into multiple steps for execution.

[0153] This disclosure enables H-VPN hierarchical management of EVPN L2 / L3 services in SRV6 networks; SRV6 networks can deploy H-VPN services, SPE nodes can directly exchange VPN SIDs, and SPEs do not need to deploy VPN instances; by adding a new exchange type SID, EVPN L2 / L3VPN H-VPN is realized, allowing services to directly exchange IPv6 addresses and generate SRv6 policies on SPE nodes, improving forwarding efficiency.

[0154] Based on the same inventive concept, this disclosure also provides an apparatus for implementing hierarchical management of SRV6 policy network H-VPN, as described in the following embodiments. Since the principle by which this apparatus solves the problem is similar to that of the method embodiments described above, the implementation of this apparatus embodiment can refer to the implementation of the method embodiments described above, and repeated details will not be elaborated further.

[0155] Figure 6 This disclosure illustrates an apparatus for implementing H-VPN hierarchical management of an SRV6 policy network, applied to the BGP of an SPE device, such as... Figure 6 As shown, the apparatus 600 for implementing hierarchical management of SRV6 policy network H-VPN includes:

[0156] The routing message receiving module 602 is used to receive the service route sent by the first device. The service route carries a service label and a color value.

[0157] The judgment module 604 is used to select the target SID type from the preset SID types based on the business scenario to which the business route belongs.

[0158] The first data processing module 606 generates the target SRV6 policy based on the color value and business tag;

[0159] The second data processing module 608 associates the target SID type with the target SRV6 policy to generate a target service route. The next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy.

[0160] The data sending module 610 is used to send the target service route to the second device, so that the second device can forward the route by looking up the address in the target service route.

[0161] In some embodiments, the first data processing module 606 is specifically used for:

[0162] Based on the color value, the first SRV6 policy can be retrieved.

[0163] Generate a second SRV6 policy, whose sidlist is the same as that of the first SRV6 policy;

[0164] Based on the second SRV6 policy and the business tag, the target SRV6 policy is obtained.

[0165] In some embodiments, the final layer of the target SRV6 policy is a business label.

[0166] In some embodiments, the business scenario includes at least one of the following scenarios:

[0167] IPv4 H-VPN scenario, IPv6 H-VPN scenario, EVPN VPWS H-VPN scenario, EVPN VPLS H-VPN scenario.

[0168] In some embodiments, when the service scenario to which the service route belongs is an IPv4 H-VPN scenario, the determination module 604 selects the first SID type;

[0169] When the service routing belongs to the IPv6 H-VPN scenario, select the second SID type;

[0170] When the service routing belongs to the EVPN VPWS H-VPN scenario, select the third SID type;

[0171] When the service routing belongs to the EVPN VPLS H-VPN scenario, select the fourth SID type.

[0172] In some embodiments, if the first device is an NPE device, the second device is a UPE device; if the first device is a UPE device, the second device is an NPE device.

[0173] In some embodiments, the data sending module 610 sends the target service route to the second device, which may be done by sending the target service route to the second device via an update message.

[0174] In some embodiments, the update message also carries at least one of the following attributes:

[0175] RT attribute, target SID type attribute, color attribute.

[0176] In some embodiments, the apparatus 600 for implementing H-VPN hierarchical management of SRV6 networks may further include:

[0177] The acquisition module is used to obtain the network segment route corresponding to the SRv6 SID via the IGP protocol.

[0178] The concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to define the order of functions performed by these devices, modules or units or their interdependencies.

[0179] Regarding the apparatus for implementing H-VPN hierarchical management of SRV6 networks in the above embodiments, the specific manner in which each module performs its operations has been described in detail in the embodiments concerning the method for implementing H-VPN hierarchical management of SRV6 networks, and will not be elaborated upon here.

[0180] This disclosure enables H-VPN hierarchical management of EVPN L2 / L3 services in SRV6 networks; SRV6 networks can deploy H-VPN services, SPE nodes can directly exchange VPN SIDs, and SPEs do not need to deploy VPN instances; by adding a new exchange type SID, EVPN L2 / L3VPN H-VPN is realized, allowing services to directly exchange IPv6 addresses and generate SRv6 policies on SPE nodes, improving forwarding efficiency.

[0181] It should be noted that although several modules or units of the device used for action execution are mentioned in the detailed description above, this division is not mandatory.

[0182] In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0183] Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0184] The following reference Figure 7 This describes the electronic device provided in the embodiments of this disclosure. Figure 7 The electronic device 700 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0185] Figure 7 This diagram illustrates the architecture of an electronic device 700 provided in an embodiment of the present invention. Figure 7 As shown, the electronic device 700 includes, but is not limited to, at least one processor 710 and at least one memory 720.

[0186] Memory 720 is used to store instructions.

[0187] In some embodiments, memory 720 may include a readable medium in the form of volatile memory cells, such as random access memory (RAM) 7201 and / or cache memory 7202, and may further include read-only memory (ROM) 7203.

[0188] In some embodiments, the memory 720 may also include a program / utility 7204 having a set (at least one) program module 7205, such program module 7205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0189] In some embodiments, the memory 720 may store an operating system. This operating system may be a real-time operating system (RTX), such as Linux, UNIX, Windows, or OS X.

[0190] In some embodiments, the memory 720 may also store data.

[0191] As an example, processor 710 can read data stored in memory 720, which may be stored at the same memory address as the instruction, or the data may be stored at a different memory address than the instruction.

[0192] Processor 710 is configured to invoke instructions stored in memory 720 to implement the steps described in the "Exemplary Methods" section above, according to various exemplary embodiments of this disclosure. For example, processor 710 may execute the following steps of the above method embodiments:

[0193] Receive the service route sent by the first device. The service route carries a service label and a color value.

[0194] Based on the business scenario to which the business route belongs, select the target SID type from the preset SID types;

[0195] Generate the target SRV6 policy based on the color value and the business tag;

[0196] Associating the target SID type with the target SRV6 policy generates a target service route, wherein the next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy;

[0197] The target service route is sent to the second device so that the second device can look up the address in the target service route and forward it.

[0198] It should be noted that the processor 710 described above can be a general-purpose processor or a special-purpose processor. The processor 710 may include one or more processing cores, and the processor 710 executes various functional applications and data processing by running instructions.

[0199] In some embodiments, processor 710 may include a central processing unit (CPU) and / or a baseband processor.

[0200] In some embodiments, the processor 710 may determine an instruction based on the priority identifier and / or function category information carried in each control instruction.

[0201] In this disclosure, the processor 710 and the memory 720 can be configured separately or integrated together.

[0202] As an example, the processor 710 and memory 720 can be integrated on a single board or a system-on-a-chip (SOC).

[0203] like Figure 7 As shown, the electronic device 700 is embodied in the form of a general-purpose computing device. The electronic device 700 may also include a bus 730.

[0204] Bus 730 can represent one or more of several types of bus structures, including a memory bus or memory controller, peripheral bus, graphics acceleration port, processor, or a local bus using any of the various bus structures.

[0205] Electronic device 700 can also communicate with one or more external devices 740 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 700, and / or with any device that enables electronic device 700 to communicate with one or more other computing devices (e.g., router, modem, etc.). Such communication can be performed through input / output (I / O) interface 750.

[0206] Furthermore, the electronic device 700 can also communicate with one or more networks (such as local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via the network adapter 760.

[0207] like Figure 7 As shown, the network adapter 760 communicates with other modules of the electronic device 700 via the bus 730.

[0208] It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 700, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0209] It is understood that the structure illustrated in the embodiments of this disclosure does not constitute a specific limitation on the electronic device 700. In other embodiments of this disclosure, the electronic device 700 may include more than Figure 7 This may involve more or fewer components, or combining certain components, or splitting certain components, or different component arrangements. Figure 7 The components shown can be implemented in hardware, software, or a combination of both.

[0210] This disclosure also provides a computer-readable storage medium storing computer instructions thereon, which, when executed by a processor, implement the method for implementing H-VPN hierarchical management of SRV6 policy networks as described in the above method embodiments.

[0211] In this embodiment of the disclosure, the computer-readable storage medium is a computer instruction that can be sent, propagated, or transmitted for use by or in conjunction with an instruction execution system, apparatus, or device.

[0212] As an example, a computer-readable storage medium is a non-volatile storage medium.

[0213] In some embodiments, more specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, USB flash drives, portable hard drives, or any suitable combination of the foregoing.

[0214] In this embodiment of the disclosure, the computer-readable storage medium may include data signals propagated in baseband or as part of a carrier wave, wherein computer instructions (readable program code) are carried.

[0215] The transmitted data signal can take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof.

[0216] Any readable medium other than a readable storage medium

[0217] In some examples, computational instructions contained on a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0218] This disclosure also provides a computer program product that stores instructions that, when executed by a computer, cause the computer to implement the method for implementing H-VPN hierarchical management of SRV6 policy networks as described in the above method embodiments.

[0219] The aforementioned instructions can be program code. In practice, the program code can be written using any combination of one or more programming languages.

[0220] Programming languages ​​include object-oriented programming languages—such as Java and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages.

[0221] The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0222] In cases involving remote computing devices, the remote computing devices can be connected to user computing devices via any type of network, including local area networks (LANs) or wide area networks (WANs), or they can be connected to external computing devices (e.g., via the Internet using an Internet service provider).

[0223] This disclosure also provides a chip, including at least one processor and an interface;

[0224] An interface is used to provide program instructions or data to at least one processor;

[0225] At least one processor is used to execute program instructions to implement the method for implementing H-VPN hierarchical management of SRV6policy networks as described in the above method embodiments.

[0226] In some embodiments, the chip may further include a memory for storing program instructions and data, the memory being located within or outside the processor.

[0227] Those skilled in the art will understand that all or part of the steps of the above embodiments can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which can be collectively referred to as "circuit", "module" or "system".

[0228] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein.

[0229] This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.

Claims

1. A method for implementing hierarchical management of H-VPN in SRV6 policy networks, characterized in that, The method, applied to BGP for SPE devices, includes: Receive a service route sent by a first device, the service route carrying a service label and a color value, the service label including a VPN SID; Based on the business scenario to which the service route belongs, select the target SID type from the preset SID types; Generate the target SRV6 policy based on the color value and the business tag; Associating the target SID type with the target SRV6 policy generates a target service route, wherein the next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy; The target service route is sent to the second device, so that the second device forwards the service based on the address in the target service route by looking up a table. The step of generating a target SRV6 policy based on the color value and the service tag includes: querying and obtaining a first SRV6 policy based on the color value; generating a second SRV6 policy, wherein the sidlist of the second SRV6 policy is the sidlist of the first SRV6 policy; and obtaining the target SRV6 policy based on the second SRV6 policy and the service tag.

2. The method according to claim 1, characterized in that, The final layer of the target SRV6 policy is the business tag.

3. The method according to claim 1, characterized in that, Business scenarios include at least one of the following: IPv4 H-VPN scenario, IPv6 H-VPN scenario, EVPN VPWS H-VPN scenario, EVPN VPLS H-VPN scenario.

4. The method according to claim 3, characterized in that, When the service route belongs to the IPv4 H-VPN scenario, select the first SID type; When the service scenario to which the service route belongs is an IPv6 H-VPN scenario, select the second SID type; When the service route belongs to the EVPN VPWS H-VPN scenario, select the third SID type; When the service route belongs to the EVPN VPLS H-VPN scenario, select the fourth SID type.

5. The method according to claim 1, characterized in that, When the first device is an NPE device, the second device is a UPE device; when the first device is a UPE device, the second device is an NPE device.

6. The method according to claim 1, characterized in that, Sending the target service route to the second device includes: The target service route is sent to the second device via an update message.

7. The method according to claim 6, characterized in that, The update message also carries at least one of the following attributes: RT attribute, target SID type attribute, color attribute.

8. The method according to claim 1, characterized in that, The method further includes: Obtain the network segment route corresponding to the SRv6 SID through the IGP protocol.

9. An apparatus for implementing hierarchical management of H-VPN in SRV6 policy networks, characterized in that, BGP for use in SPE equipment, the device comprising: The routing message receiving module is used to receive service routes sent by the first device. The service routes carry service labels and color values. The service labels include VPN SIDs. The determination module is used to select the target SID type from the preset SID types based on the business scenario to which the business route belongs; The first data processing module is used to generate a target SRV6 policy based on the color value and the business tag. The second data processing module associates the target SID type with the target SRV6 policy to generate a target service route, wherein the next hop of the SID corresponding to the target SID type in the target service route is the target SRV6 policy; The data sending module is used to send the target service route to the second device, so that the second device can forward the route by looking up the address in the target service route. The first data processing module is configured to query and obtain a first SRV6 policy based on the color value; generate a second SRV6 policy, wherein the sidlist of the second SRV6 policy is the sidlist of the first SRV6 policy; and obtain a target SRV6 policy based on the second SRV6 policy and the business tag.

10. An electronic device, characterized in that, include: Memory, used to store instructions; A processor is configured to invoke instructions stored in the memory to implement the method for implementing H-VPN hierarchical management of SRV6 policy networks as described in any one of claims 1-8.

11. A computer-readable storage medium storing computer instructions thereon, characterized in that, When the computer instructions are executed by the processor, they implement the method for implementing H-VPN hierarchical management of SRV6 policy networks as described in any one of claims 1-8.