A method and system for quickly searching source ports based on load balancing equipment
By building a three-layer hash structure source port search method on load balancing equipment, the problems of slow source port search and insufficient port resource utilization in the existing technology are solved, and efficient and accurate source port search is achieved.
Patent Information
- Application Number
- CN202410738253.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-07
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-06-07
AI Technical Summary
In the prior art, the source port search algorithm is simple, the number of searches is large, the search times are slow, and the ports cannot be used all, especially when the number of available ports becomes smaller, it takes considerable time to traverse the port_bitmap.
Using the fast search method of source ports based on load balancing devices, we quickly lock the target hash bucket and determine the target source port from it by defining and building a three-layer hash structure of the source port search data structure.
On the basis of reducing the number of searches, the efficiency and accuracy of source port searches are improved, the consumption of service resources is reduced, and the port resources are fully utilized.
Smart Images

Figure CN118660057B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet and database technology, and more specifically, to a method and system for fast searching of source ports based on a load balancing device. Background Art
[0002] Load balancing is a basic element of application high availability. By distributing traffic to different backend servers, the service throughput of the application system can be expanded, single points of failure can be eliminated, and the availability of the application system can be improved.
[0003] After receiving the TCP handshake / UDP packet from the client, the load balancer needs to generate the TCP handshake / UDP packet sent to the real server based on the load balancing configuration rules. The client is just like communicating directly with the real server. Figure 2 As shown, the client data packet needs to be converted into a server data packet and then sent to the real server. The TCP handshake / UDP packet sent to the real server needs to determine the five-tuple data (proto, sip, sport, dip and dport). The load balancer can quickly find dip and dport through the configured DNAT rules, and can quickly find sip through the configured SNAT rules. According to the SNAT and DNAT rules, proto, dip, dport and sip are determined, and sport needs to be searched. Because the five-tuple determines a connection, the server context environment, and the new connection cannot have the same five-tuple as the existing connection, so when the four-tuple is determined and the same, the source port must be different.
[0004] There are currently several source port concurrent search algorithms:
[0005] 1. Source port random collision search algorithm:
[0006] Create a hash table with bucket_max buckets and use the zipper method to resolve hash conflicts.
[0007] a) When the four-tuple (proto, sip, dport, dip) has been determined, a random source port (ports 0-1023 are excluded), a hash value hash is calculated based on this five-tuple, and the hash bucket hashtable [hash% bucket_max] is obtained;
[0008] b) Add a write lock and traverse the elements under the hash bucket by comparing the five-tuples;
[0009] c) If the node with the same five-tuple is found, the write lock is released and the process returns to step a) to continue. The execution count is increased by 1. When the execution count is greater than N (1024), the process jumps to step e.
[0010] d) If no node with the same five-tuple is found, a five-tuple node is created and inserted, the write lock is released, and the port number is returned;
[0011] e) The loop is repeated for a maximum of N (1024) times. If no useful source port can be found, the source port allocation failure is returned.
[0012] The algorithm is simple, but it requires many comparisons, is slow to search, and cannot use up all ports.
[0013] 2. Quadruple (proto, sip, dport, dip) deterministic search algorithm:
[0014] The struct list structure is declared as follows:
[0015] name type prev struct list* next struct list*
[0016] The struct port_node structure is declared as follows:
[0017] name type node struct list lock spinlock_t hash uint32_t proto uint8_t dport uint16_t sip uint8_t
[16] dip uint8_t
[16] port_bitmap uint8_t
[8192]
[0018] Create a hash table hashtable with bucket_max buckets (struct list hashtable[bucket_max]) and use the zipper method to resolve hash conflicts. The algorithm is described as follows:
[0019] a) Generate a hash value hash according to the four-tuple (proto, sip, dport, dip) selected by the rule, and obtain the hash bucket hashtable [hash% bucket_max];
[0020] b) Add a read lock to the hash bucket, traverse the linked list under the hash bucket, and determine whether there are nodes with the same four-tuple. If the four-tuple passed in by the interface and the corresponding members of struct port_node are equal, they are the same;
[0021] c) If there is a node with the same quadruple, add a spin lock to the node, then randomly select a port number, check whether the port_bitmap bit corresponding to the port number is 1 ((port_bitmap[port / 8]>>(port%8))&0x1), if it is 1, set the position to 0 (port_bitmap[port%8]&=~(1<<(port%8))), release the spin lock, release the read lock, and return the port number; if the bit is not 1, traverse to the higher bits, find the first bit that is not 1, set it to 0, and get the subscript of the bit in port_bitmap, which is the port number, release the spin lock, release the read lock, and return the port number; if the higher bits are not found, search from the random port number to the lower bits, set the bit to 0 when it is found, release the spin lock, release the read lock, and return the port number; if none of them are found, return failure.
[0022] d) If there is no node with the same quadruple, release the read lock, add a write lock to the hash bucket, compare the quadruple and traverse the hash bucket. If there is no node with the same quadruple, create a node and initialize the quadruple, spin lock, port_bitmap (set all array bits (except 0-1023) to 1), add the node to the hash bucket, randomly select a port number (except 0-1023), set the corresponding bit to 0, return the port number, release the write lock and return the port number; if there is a node with the same quadruple, search from the random port number to the high bit, if not found, search to the low bit, find the first bit that is 1, set it to 0, then release the write lock, return the port number, if not found, release the write lock and return failure;
[0023] This algorithm is faster when the number of ports is large, but when the number of available ports decreases, the time spent traversing the port_bitmap increases significantly.
[0024] In summary, it is necessary to introduce a new method and system, which is based on a new search structure and can quickly find the required source port with fewer searches, so as to solve the technical problems existing in the prior art, such as simple algorithm, large number of search comparisons, slow search, inability to use all ports, and significant increase in the time spent on traversing port_bitmap when the number of available ports decreases, thereby improving the efficiency and accuracy of source port search and reducing the consumption of service resources. Summary of the invention
[0025] In response to the technical problems mentioned above, the present invention provides a method and system for quickly searching for source ports based on a load balancing device. The method and system are based on a new search structure, namely a three-layer hash structure among the highest layer, the middle layer and the lowest layer of the source port search data structure. The method and system can quickly lock the target hash bucket and accurately and quickly determine the target source port from the nodes in the target hash bucket to solve the technical problems existing in the prior art, such as the simple algorithm, the large number of search and comparison times, the slow search, the inability to use up all ports, and the significant increase in the time spent on traversing the port_bitmap when the number of available ports decreases. The method and system can then improve the efficiency and accuracy of the source port search on the basis of reducing the number of searches, reduce the consumption of service resources, and make full use of the port resources.
[0026] The present invention provides a method for quickly searching source ports based on a load balancing device, the method comprising:
[0027] S1, based on the load balancing device, define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create a hash bucket according to the source port search data structure, and set the number of the hash buckets; S2, the load balancing device receives the source port search task request in real time, parses the source port search task request, obtains the target quadruple data corresponding to the source port search task request, and calculates the target hash value according to the target quadruple data; S3, determines the target node node from the target hash bucket according to the target hash value and the target quadruple data, traverses the source port in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and determines the target source port according to the traversal result; wherein the hash bucket stores the source port search data in each of the nodes node in a linked list.
[0028] Preferably, the source port search data structure includes: member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and three-layer hash data structure;
[0029] in,
[0030] The lock Lock includes a read lock, a write lock and a spin lock;
[0031] The three-layer hash data structure includes the highest layer, the middle layer and the lowest layer;
[0032] The lowest layer is map2[i], the middle layer is map1[j], and the highest layer is map0[k].
[0033]
[0034] i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map2[i] is i×sizeof(uint64_t);
[0035]
[0036] j is a positive integer greater than or equal to 0, and j is less than or equal to 16, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map1[j] is j×sizeof(unit64_t);
[0037]
[0038] k is a positive integer greater than or equal to 0, and k is less than or equal to 16. The maximum length of map0[k] is 0xFFFF, and 0xFFFF is a hexadecimal value.
[0039] Preferably, in step S1, based on the load balancing device, defining and initializing the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, creating a hash bucket according to the source port search data structure, and setting the number of the hash buckets further comprises: S111, based on the load balancing device, defining the source port search data structure, including member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and a three-layer hash data structure, the three-layer hash data structure includes the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k]; S112, determining the mapping relationship between the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k], the lowest layer map2[j] has i×sizeof(uint64_t) bits, each bit value represents a source port number, and each map1[j] can store at most j×sizeof(uint64_t ) source port number corresponding to the hash value, each bit value in the middle layer map1[j] is the 64-bit integer value in the lowest layer map2[i], and each bit value in the highest layer map0[k] is the 64-bit integer value in the middle layer map1[j]; S113, based on the source port search data structure and the mapping relationship, create the hash bucket according to the set number of the hash buckets; S114, add numbers to each hash bucket according to the number of the hash buckets, and initialize the values of all source port search data in each hash bucket; In the example, sizeof(uint64_t) is the length of an element whose data type is uint64_t, i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, j is a positive integer greater than or equal to 0, and j is less than or equal to 16, k is a positive integer greater than or equal to 0, and k is less than or equal to 16; at initialization, the values of the source port search data in the hash bucket are all null values; the number of the hash buckets is Hnum, Hnum is a positive integer greater than or equal to 1; the minimum value of the hash bucket number is zero, and the maximum value is (Hnum-1).
[0040] Preferably, in step S2, the step of parsing the source port search task request, obtaining the target quadruple data corresponding to the source port search task request, and calculating the target hash value based on the target quadruple data further includes: S21, according to the parsing result of the source port search task request, obtaining the protocol proto, destination port dport, destination address dip and source address sip corresponding to the source port search task request; S22, according to the protocol proto, destination port dport, destination address dip and source address sip corresponding to the source port search task request, obtaining the target hash value secondhash of the target quadruple data; wherein the target quadruple data includes the protocol proto, the destination port dport, the destination address dip and the source address sip.
[0041] Preferably, in step S3, the step of determining the target node node from the target hash bucket according to the target hash value and the target four-tuple data, and traversing the source port in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer further includes: S31, determining the target hash bucket according to the target hash value secondhash and the number of hash buckets Hnum, if [target hash value secondhash% number of hash buckets Hnum] is equal to the number of the hash bucket, determining the hash bucket corresponding to the number as the target hash bucket; S32, Bucket adds a read lock, and traverses the node node in the target hash bucket to determine the target node node. If the hash values of all the four-tuple data in the node node are greater than or less than the target hash value secondhash, jump to step S33. If there is a four-tuple data with a hash value equal to the target hash value secondhash in the node node, and the four-tuple data is equal to the target four-tuple data, determine that the node node is the target node node, and jump to step S34; S33, repeat step S32 until all the nodes in the target hash bucket are After all node traversals are completed, if the target node node does not exist in the target hash bucket, the read lock of the target hash bucket is released and the process jumps to step S35. If the target node node exists in the target hash bucket, the process jumps to step S34. In step S34, a spin lock is added to the target node node, and according to the mapping relationship between the highest layer, the middle layer and the lowest layer, the target source port is determined from the target node node, and the execution result is returned to the source port search task request. If there is no available source port in the target node node, the process jumps to step S35. In step S35, a spin lock is added to the target node node, and according to the mapping relationship between the highest layer, the middle layer and the lowest layer, the target source port is determined from the target node node, and the execution result is returned to the source port search task request. A write lock is added to the target hash bucket, a new node node is created according to the target quadruple data, and the quadruple data and source port sport of the new node node, as well as the statistical value count and lock Lock of the source port sport are determined according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and updated to the target hash bucket, and then the new node node is set as the target node node, and the process returns to step S34; wherein the target node node is a node node whose hash value is equal to the target hash value secondhash, and whose quadruple data is equal to the quadruple data.
[0042] Preferably, the step S34 also includes the step of source port allocation processing, specifically: S33-1, verifying the highest layer map0[k] corresponding to the target node node from low to high, obtaining a first verification value, if the first verification value is zero, returning a notification of source port allocation failure, the first verification value is greater than zero, jumping to step S33-2; S33-2, verifying the middle layer map1[j] corresponding to the target node node from low to high, obtaining a second verification value, if the second verification value is zero, returning a notification of source port allocation failure. If the second check value is greater than zero, determine the lowest bit whose value is 1 from the middle layer map1[j], and jump to step S33-3; S33-3, check the lowest layer map2[i] corresponding to the target node node from low to high according to the lowest bit, obtain the third check value according to the lowest bit whose value is 1 in the lowest layer map2[i], and determine the target source port; wherein the first check value is first, the second check value is second, the third check value is three, and the target source port is port, then
[0043] port=(first×64+second)×64+three;
[0044] three=map2[first×64+second];
[0045] second=map1[first].
[0046] Preferably, the S33-3, after determining the target source port, also includes a port reset processing step, specifically: S33-31, setting the third position of the lowest layer map2[first×64+second] corresponding to the target node node to zero; if the value of the lowest layer map2[first×64+second] corresponding to the target node node after the third position is zero is zero, jump to step S33-32; otherwise, return a notification of the end of the search, and release the spin lock of the target node node; S33-32, set the second position of the intermediate layer map1[first] corresponding to the target node node to zero, return a notification of the end of the search, and release the lock Lock of the target node node; wherein the lock Lock includes a read lock, a write lock and a spin lock.
[0047] Preferably, in step S35, the step of creating a new node node according to the target quad-tuple data, determining the quad-tuple data and source port sport of the new node node, as well as the statistical value count and lock Lock of the source port sport according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and updating them to the target hash bucket further includes: S34-1, obtaining the number of the new node node and all source ports sport corresponding to the quad-tuple data in the new node node according to the quad-tuple data corresponding to the source port search task request; S34-2, based on the mapping relationship between the highest layer, the middle layer and the lowest layer, sorting the number of the new node and all source ports sport corresponding to the quad-tuple data in the new node and storing them in the target hash bucket.
[0048] Preferably, the step S34-2 further includes:
[0049] S34-21, if the value of the protocol proto of the new node node is less than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the new node node is before the storage location of the source port search data corresponding to the other node node,
[0050] If the value of the protocol proto of the new node node is greater than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0051] If the value of the protocol proto of the new node node is equal to the value of the protocol proto of another node node in the target hash bucket, jump to step S34-22;
[0052] S34-22, if the value of the destination port dport of the new node node is smaller than the value of the destination port dport of another node node, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is placed before the storage location of the source port search data corresponding to the new node node.
[0053] If the value of the destination port dport of the new node node is greater than the value of the destination port dport of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0054] If the value of the destination port dport of the new node node is equal to the value of the destination port dport of another node node in the target hash bucket, jump to step S34-23;
[0055] S34-23, if the value of the source address sip of the new node node is less than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0056] If the value of the source address sip of the new node node is greater than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0057] If the value of the source address sip of the new node node is equal to the value of the source address sip of another node node in the target hash bucket, jump to step S34-24;
[0058] S34-24, if the value of the destination address dip of the new node node is less than or equal to the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node,
[0059] If the value of the destination address dip of the new node node is greater than the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage position of the source port search data corresponding to the other node node is before the storage position of the source port search data corresponding to the new node node;
[0060] S34-25, repeat steps S34-21, S34-22, S34-23 and S34-24 until all nodes node in the target hash bucket are compared and sorted, then determine the storage position of the source port search data corresponding to the new node node in the target hash bucket, and store the target hash value secondhash, the number of the new node node, the five-tuple data corresponding to the four-tuple data, and the mapping relationship between the highest layer, the middle layer and the lowest layer in the target hash bucket according to the storage position, and update the lock Lock of the target hash bucket to a read lock, and set the statistical value count of the new node node to zero;
[0061] The five-tuple data includes the protocol proto, the destination port dport, the destination address dip, the source address sip and the source port sport.
[0062] Correspondingly, the present invention also provides a system for rapid source port search based on a load balancing device, the system comprising a search initialization module, a search request preprocessing module and a source port search determination module;
[0063] Among them, the search initialization module is used to define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create a hash bucket according to the source port search data structure, and set the number of the hash buckets; the search request preprocessing module is used for the load balancing device to receive the source port search task request in real time, parse the source port search task request, obtain the target four-tuple data corresponding to the source port search task request, and calculate the target hash value according to the target four-tuple data; the source port search determination module is used to determine the target node node from the target hash bucket according to the target hash value and the target four-tuple data, traverse the source port in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and determine the target source port according to the traversal processing result; the hash bucket stores the source port search data in each of the nodes node in a linked list.
[0064] The present invention, by applying the above technical scheme, realizes the three-layer hash structure among the highest layer, the middle layer and the lowest layer by defining and constructing the source port search data structure, and on the basis of quickly locking the target hash bucket, accurately and quickly determines the target source port from the nodes in the target hash bucket, so as to solve the technical problems existing in the prior art that the algorithm is simple, the number of search comparisons is large, the search is slow, and the ports cannot be fully used, and when the number of available ports decreases, the time consumption of traversing the port_bitmap will increase significantly, thereby improving the efficiency and accuracy of the source port search on the basis of reducing the number of searches, reducing the consumption of service resources, and making full use of the port resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0066] Figure 1 A schematic diagram of a flow chart of a method for quickly searching source ports based on a load balancing device proposed in an embodiment of the present invention is shown;
[0067] Figure 2 A schematic diagram of interaction between a client and a server of a method for rapid source port search based on a load balancing device proposed in an embodiment of the present invention is shown;
[0068] Figure 3 A schematic diagram of a source port search process of a method for rapid source port search based on a load balancing device proposed in an embodiment of the present invention is shown;
[0069] Figure 4 A schematic structural diagram of a system for rapid source port search based on a load balancing device proposed in an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0070] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0071] The present invention provides a method for quickly searching source ports based on a load balancing device, such as Figure 1 As shown, the method comprises the following steps:
[0072] S1, based on the load balancing device, define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create a hash bucket according to the source port search data structure, and set the number of the hash buckets.
[0073] The hash bucket stores the source port search data in each of the nodes in a linked list manner.
[0074] In this embodiment, the source port search data structure includes: member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and three-layer hash data structure;
[0075] in,
[0076] The lock Lock includes a read lock, a write lock and a spin lock;
[0077] The three-layer hash data structure includes the highest layer, the middle layer and the lowest layer;
[0078] The lowest layer is map2[i], the middle layer is map1[k], and the highest layer is map0[k].
[0079]
[0080] i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map2[i] is i×sizeof(uint64_t);
[0081]
[0082] j is a positive integer greater than or equal to 0, and j is less than or equal to 16, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map1[j] is j×sizeof(uint64_t);
[0083]
[0084] k is a positive integer greater than or equal to 0, and k is less than or equal to 16. The maximum length of map0[k] is 0xFFFF, and 0xFFFF is a hexadecimal value.
[0085] In this embodiment, the steps of defining and initializing a source port search data structure and a mapping relationship between the highest layer, the middle layer, and the lowest layer based on a load balancing device, creating a hash bucket according to the source port search data structure, and setting the number of the hash buckets further include:
[0086] S111, based on the load balancing device, define the source port search data structure, including member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and three-layer hash data structure, the three-layer hash data structure includes the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k];
[0087] S112, determine the mapping relationship between the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k], the lowest layer map2[i] has i×sizeof(uint64_t) bits, each bit value represents a source port number, each map1[j] can store at most j×sizeof(uint64_t) hash values corresponding to the source port numbers, the value of each bit in the middle layer map1[j] is the 64-bit integer value in the lowest layer map2[i], and the value of each bit in the highest layer map0[k] is the 64-bit integer value in the middle layer map1[j];
[0088] S113, based on the source port search data structure and the mapping relationship, create the hash bucket according to the set number of the hash buckets;
[0089] S114, adding numbers to each of the hash buckets according to the number of the hash buckets, and initializing the values of all source port search data in each of the hash buckets;
[0090] in,
[0091] sizeof(uint64_t) is the length of an element of data type uint64_t, i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, j is a positive integer greater than or equal to 0, and j is less than or equal to 16, k is a positive integer greater than or equal to 0, and k is less than or equal to 16;
[0092] During initialization, the values of the source port search data in the hash bucket are all null values;
[0093] The number of the hash buckets is Hnum, where Hnum is a positive integer greater than or equal to 1;
[0094] The minimum value of the hash bucket number is zero, and the maximum value is (Hnum-1).
[0095] S2, the load balancing device receives the source port search task request in real time, parses the source port search task request, obtains the target four-tuple data corresponding to the source port search task request, and calculates the target hash value according to the target four-tuple data;
[0096] In this embodiment, in step S2, the step of parsing the source port search task request, obtaining the target four-tuple data corresponding to the source port search task request, and calculating the target hash value according to the target four-tuple data further includes:
[0097] S21, according to the parsing result of the source port search task request, obtaining the protocol proto, destination port dport, destination address dip and source address sip corresponding to the source port search task request;
[0098] S22, obtaining a target hash value secondhash of the target four-tuple data according to the protocol proto, the destination port dport, the destination address dip and the source address sip corresponding to the source port search task request;
[0099] The target four-tuple data includes the protocol proto, the destination port dport, the destination address dip and the source address sip.
[0100] S3, determining a target node node from a target hash bucket according to the target hash value and the target quadruple data, traversing the source ports in the target node according to the mapping relationship among the highest layer, the middle layer and the lowest layer, and determining a target source port according to the traversal processing result;
[0101] In this embodiment, in step S3, the step of determining the target node node from the target hash bucket according to the target hash value and the target quadruple data, and traversing the source port in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer further includes:
[0102] S31, determining the target hash bucket according to the target hash value secondhash and the number of hash buckets Hnum, if [target hash value secondhash%number of hash buckets Hnum] is equal to the number of the hash bucket, determining the hash bucket corresponding to the number as the target hash bucket;
[0103] S32, adding a read lock to the target hash bucket, and traversing the node node in the target hash bucket to determine the target node node,
[0104] If the hash values of all the four-tuple data in the node node are greater than or less than the target hash value secondhash, jump to step S33,
[0105] If there is a quadruple data with a hash value equal to the target hash value secondhash in the node node, and the quadruple data is equal to the target quadruple data, then the node node is determined to be the target node node, and the process jumps to step S34;
[0106] S33, repeat step S32 until all nodes in the target hash bucket are traversed. If the target node does not exist in the target hash bucket, release the read lock of the target hash bucket and jump to step S35.
[0107] If the target node node exists in the target hash bucket, jump to step S34;
[0108] S34, adding a spin lock to the target node node, and determining the target source port from the target node node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and returning the execution result to the source port search task request, if there is no available source port in the target node node, jumping to step S35;
[0109] S35, add a write lock to the target hash bucket, create a new node node according to the target quadruple data, determine the quadruple data and source port sport of the new node node, and the statistical value count and lock Lock of the source port sport according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and update them to the target hash bucket, then set the new node node as the target node node, and return to step S34;
[0110] The target node node is a node node whose hash value is equal to the target hash value secondhash and whose four-tuple data is equal to the four-tuple data.
[0111] In this embodiment, the step S34 also includes a source port allocation processing step, specifically:
[0112] S33-1, verify the highest layer map0[k] corresponding to the target node node from low to high, and obtain a first verification value. If the first verification value is zero, return a notification of source port allocation failure. If the first verification value is greater than zero, jump to step S33-2;
[0113] S33-2, verify the middle layer map1[j] corresponding to the target node node from low to high, and obtain a second verification value. If the second verification value is zero, return a notification of source port allocation failure. If the second verification value is greater than zero, determine the lowest bit whose value is 1 from the middle layer map1[j], and jump to step S33-3;
[0114] S33-3, verify the lowest level map2[i] corresponding to the target node node from low to high according to the lowest bit, obtain a third verification value according to the lowest bit with a value of 1 in the lowest level map2[i], and determine the target source port;
[0115] in,
[0116] The first check value is first, the second check value is second, the third check value is three, and the target source port is port, then
[0117] port=(first×64+second)×64+three;
[0118] three=map2[first×64+second];
[0119] second=map1[first].
[0120] In this embodiment, the S33-3, after determining the target source port, further includes a port reset processing step, specifically:
[0121] S33-31, set the third position of the lowest level map2[first×64+second] corresponding to the target node node to zero. If the value of the lowest level map2[first×64+second] corresponding to the target node node after the third position is zero is zero, jump to step S33-32. Otherwise, return a notification of the end of the search and release the spin lock of the target node node.
[0122] S33-32, set the second position of the intermediate layer map1[first] corresponding to the target node node to zero, return a notification of the end of the search, and release the lock Lock of the target node node;
[0123] The lock Lock includes a read lock, a write lock and a spin lock.
[0124] In this embodiment, in step S35, the step of creating a new node node according to the target quad-tuple data, determining the quad-tuple data and source port sport of the new node node, and the statistical value count and lock Lock of the source port sport according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and updating them to the target hash bucket further includes:
[0125] S34-1, acquiring the number of the new node node and all source ports sport corresponding to the four-tuple data in the new node node according to the four-tuple data corresponding to the source port search task request;
[0126] S34-2, based on the mapping relationship between the highest layer, the middle layer and the lowest layer, sort the number of the new node and all source ports sport corresponding to the four-tuple data in the new node and store them in the target hash bucket.
[0127] In this embodiment, the step S34-2 further includes:
[0128] S34-21, if the value of the protocol proto of the new node node is less than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the new node node is before the storage location of the source port search data corresponding to the other node node,
[0129] If the value of the protocol proto of the new node node is greater than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0130] If the value of the protocol proto of the new node node is equal to the value of the protocol proto of another node node in the target hash bucket, jump to step S34-22;
[0131] S34-22, if the value of the destination port dport of the new node node is smaller than the value of the destination port dport of another node node, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is placed before the storage location of the source port search data corresponding to the new node node.
[0132] If the value of the destination port dport of the new node node is greater than the value of the destination port dport of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0133] If the value of the destination port dport of the new node node is equal to the value of the destination port dport of another node node in the target hash bucket, jump to step S34-23;
[0134] S34-23, if the value of the source address sip of the new node node is less than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0135] If the value of the source address sip of the new node node is greater than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node.
[0136] If the value of the source address sip of the new node node is equal to the value of the source address sip of another node node in the target hash bucket, jump to step S34-24;
[0137] S34-24, if the value of the destination address dip of the new node node is less than or equal to the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node,
[0138] If the value of the destination address dip of the new node node is greater than the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage position of the source port search data corresponding to the other node node is before the storage position of the source port search data corresponding to the new node node;
[0139] S34-25, repeat steps S34-21, S34-22, S34-23 and S34-24 until all nodes node in the target hash bucket are compared and sorted, then determine the storage position of the source port search data corresponding to the new node node in the target hash bucket, and store the target hash value secondhash, the number of the new node node, the five-tuple data corresponding to the four-tuple data, and the mapping relationship between the highest layer, the middle layer and the lowest layer in the target hash bucket according to the storage position, and update the lock Lock of the target hash bucket to a read lock, and set the statistical value count of the new node node to zero;
[0140] The five-tuple data includes the protocol proto, the destination port dport, the destination address dip, the source address sip and the source port sport.
[0141] In order to enable those skilled in the art to better understand the above technical solution provided by the present invention, the technical solution of the rapid search of the source port based on the load balancing device provided by the present invention is further supplemented by an example. Figure 2 and Figure 3 shown.
[0142] Define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, and create a hash table based on the source port search data structure. The hash table includes a hash bucket and a linked list. The structlist structure is declared as follows:
[0143] Member Name type prev struct list* next struct list*
[0144] The struct port_node structure is declared as follows:
[0145] Member Name type node struct list hash uint32_t proto protocol uint16_t dport destination port uint16_t dip destination address uint8_t
[16] sip source address uint8_t
[16] Lock spinlock_t Count Statistics uint32_t map0 top uint32_t map1 middle layer uint64_t
[16] map2 lowest level uint64_t
[1024]
[0146] Search data structure based on the source port and mapping relationship between the highest layer, middle layer and lowest layer:
[0147] a) Generate a hash value hash according to the four-tuple (proto, sip, dip, dport) selected by the rule, and obtain the hash bucket hashtable [hash% bucket_max] according to the hash value hash;
[0148] b) Add a read lock to the hash bucket and traverse the linked list under the hash bucket. If the hash value of the four-tuple selected by the rule is greater than the hash value of the four-tuple in the linked list node struct port_node, continue to compare the subsequent nodes. If they are equal, jump to c. If the hash value of the four-tuple selected by the rule is less than the hash value of the four-tuple in the node struct port_node or there is no untraversed node in the linked list, release the read lock and jump to d.
[0149] c) Use the node's internal struct port_node member variable lock to add a spin lock, use first = __builtin_ffsll((map0), if first is equal to 0, the direct port allocation fails and the process ends. If it is any other value, first = first-1; continue to search map1, second = __builtin_ffsll(map1[first]), find the lowest non-0 bit, second = second-1, and finally search map2, three = __builtin_ffsll(map2[first*64+second]), three = three-1, and you can get the port number port = (first*64+second)*64+three. To avoid this port number being searched again before it is released, you need to set the corresponding bits in the map0, map1, and map2 array elements to 0.
[0150] 1. Set the third bit of map2[first*64+second] to 0. If the value of map2[first*64+second] is not equal to 0, directly return the port number and end the search process. If the value is equal to 0;
[0151] 2. Set the second bit of map1[first] to 0. After setting, if the value of map1[first] is not equal to 0, directly return the port number and end the search process. If the value is equal to 0;
[0152] 3. Set the first bit of map0 to 0, end the search process and return the port number. The end process will release the lock spin lock. If the hash bucket was previously added with a read lock, the read lock will be released. If the hash bucket was previously added with a write lock, the write lock will be released and the process ends.
[0153] d) Add a write lock to the hash bucket and traverse the nodes under the hash bucket using the selected quadruple.
[0154] If there is a node with the same quadruple, jump to c.
[0155] If it does not exist, create a node and initialize the node struct port_node. During initialization (ports 0-1023 are reserved for the system): the value of map0 is 0xFFFF; map1[0] = 0xFFFFFFFFFFFF0000, the elements in other map1 arrays are initialized to 0xFFFFFFFFFFFFFFFF, the first 16 uint64_t integers of map2 are all 0, and the uint64_t integers of other map2 are assigned to 0xFFFFFFFFFFFFFFFF, initialize lock, initialize proto, dport, dip, and sip with the selected four-tuple, the number of ports count is (65536-1024), and the four-element hash value is initialized to hash. After initialization, add the node to the linked list and then jump to c.
[0156] When the port is released after use, the port number needs to be put into the search structure (struct port_node). The release algorithm (port is the port number) is: 1. Set the port%64th bit of map2[port / 64] to 1; 2. Set the port / 64%64th bit of map1[port / 64 / 64] to 1; 3. Set the port / 64 / 64th bit of map0 to 1.
[0157] When port acquisition needs to maintain a certain degree of randomness, count (the current number of available ports) can be used. The initial value is (65536-1024). After hitting the port search node, if count is greater than or equal to 10000, a random value v (rand% (1024-16) + 16) is first generated, and then the number num of the lowest bit (1) is obtained through __builtin_ffsll (map2[v]). num needs to be reduced by 1 (num=num-1), then the available port number is 64*v+num, and the number of available ports becomes count-1. The corresponding bits of the elements in the map2, map1, and map0 arrays are set to 0. If map2[v] is 0 or count is less than 10000, it is queried and obtained by searching map0, map1, and map2 (the method described above).
[0158] By applying the above technical scheme, a three-layer hash structure among the highest layer, middle layer and lowest layer of the source port search data structure is defined and constructed. On the basis of quickly locking the target hash bucket, the target source port is accurately and quickly determined from the nodes in the target hash bucket, so as to solve the technical problems existing in the prior art, such as simple algorithm, large number of search and comparison times, slow search, inability to use up all ports, and significant increase in the time consumption of traversing port_bitmap when the number of available ports decreases. Then, on the basis of reducing the number of searches, the efficiency and accuracy of the source port search are improved, the consumption of service resources is reduced, and the port resources are fully utilized.
[0159] Corresponding to the method for rapid search of source ports based on a load balancing device in one embodiment of the present invention, the present invention also discloses a system for rapid search of source ports based on a load balancing device, such as Figure 4 As shown, the system includes a search initialization module, a search request preprocessing module and a source port search determination module;
[0160] in,
[0161] The search initialization module is used to define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create hash buckets according to the source port search data structure, and set the number of hash buckets;
[0162] The search request preprocessing module is used for the load balancing device to receive the source port search task request in real time, parse the source port search task request, obtain the target four-tuple data corresponding to the source port search task request, and calculate the target hash value according to the target four-tuple data;
[0163] The source port search and determination module is used to determine the target node node from the target hash bucket according to the target hash value and the target four-tuple data, traverse the source ports in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and determine the target source port according to the traversal processing result;
[0164] The hash bucket stores the source port search data in each of the nodes in a linked list manner.
[0165] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0166] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.
Claims
1. A method for quickly searching source ports based on a load balancing device, characterized in that: The method comprises: S1, based on the load balancing device, define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create a hash bucket according to the source port search data structure, and set the number of the hash buckets; S2, the load balancing device receives the source port search task request in real time, parses the source port search task request, obtains the target four-tuple data corresponding to the source port search task request, and calculates the target hash value according to the target four-tuple data; S3, determining a target node node from a target hash bucket according to the target hash value and the target quadruple data, traversing the source ports in the target node according to the mapping relationship among the highest layer, the middle layer and the lowest layer, and determining a target source port according to the traversal processing result; The hash bucket stores the source port search data in each node in a linked list manner; The source port search data structure includes: member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and three-layer hash data structure; in, The lock Lock includes a read lock, a write lock and a spin lock; The three-layer hash data structure includes the highest layer, the middle layer and the lowest layer; The lowest layer is map2[i], the middle layer is map1[j], and the highest layer is map0[k]. i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map2[i] is i×sizeof(uint64_t); j is a positive integer greater than or equal to 0, and j is less than or equal to 16, sizeof(uint64_t) is the length of an element of the uint64_t data type, and the maximum length of map1[j] is j×sizeof(uint64_t); k is a positive integer greater than or equal to 0, and k is less than or equal to 16. The maximum length of map0[k] is 0xFFFF, and 0xFFFF is a hexadecimal value. In step S1, based on the load balancing device, defining and initializing the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, creating a hash bucket according to the source port search data structure, and setting the number of the hash buckets further includes: S111, based on the load balancing device, define the source port search data structure, including member name, member type, node node, hash value hash, protocol proto, destination port dport, destination address dip, source address sip, source port sport, lock Lock, statistical value count and three-layer hash data structure, the three-layer hash data structure includes the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k]; S112, determine the mapping relationship between the lowest layer map2[i], the middle layer map1[j] and the highest layer map0[k], the lowest layer map2[i] has i×sizeof(uint64_t) bits, each bit value represents a source port number, each map1[j] can store at most j×sizeof(uint64_t) hash values corresponding to the source port numbers, the value of each bit in the middle layer map1[j] is the 64-bit integer value in the lowest layer map2[i], and the value of each bit in the highest layer map0[k] is the 64-bit integer value in the middle layer map1[j]; S113, based on the source port search data structure and the mapping relationship, create the hash bucket according to the set number of the hash buckets; S114, adding numbers to each of the hash buckets according to the number of the hash buckets, and initializing the values of all source port search data in each of the hash buckets; in, sizeof(uint64_t) is the length of an element of data type uint64_t, i is a positive integer greater than or equal to 0, and i is less than or equal to 1024, j is a positive integer greater than or equal to 0, and j is less than or equal to 16, k is a positive integer greater than or equal to 0, and k is less than or equal to 16; During initialization, the values of the source port search data in the hash bucket are all null values; The number of the hash buckets is Hnum, where Hnum is a positive integer greater than or equal to 1; The minimum value of the hash bucket number is zero, and the maximum value is (Hnum-1); In step S3, the step of determining the target node node from the target hash bucket according to the target hash value and the target quadruple data, and traversing the source ports in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer further includes: S31, determining the target hash bucket according to the target hash value secondhash and the number of hash buckets Hnum, if [target hash value secondhash%number of hash buckets Hnum] is equal to the number of the hash bucket, determining the hash bucket corresponding to the number as the target hash bucket; S32, adding a read lock to the target hash bucket, and traversing the node node in the target hash bucket to determine the target node node, If the hash values of all the four-tuple data in the node node are greater than or less than the target hash value secondhash, jump to step S33, If there is a quadruple data with a hash value equal to the target hash value secondhash in the node node, and the quadruple data is equal to the target quadruple data, then the node node is determined to be the target node node, and the process jumps to step S34; S33, repeat step S32 until all nodes in the target hash bucket are traversed. If the target node does not exist in the target hash bucket, release the read lock of the target hash bucket and jump to step S35. If the target node node exists in the target hash bucket, jump to step S34; S34, adding a spin lock to the target node node, and determining the target source port from the target node node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and returning the execution result to the source port search task request, if there is no available source port in the target node node, jumping to step S35; S35, add a write lock to the target hash bucket, create a new node node according to the target quadruple data, determine the quadruple data and source port sport of the new node node, and the statistical value count and lock Lock of the source port sport according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and update them to the target hash bucket, then set the new node node as the target node node, and return to step S34; The target node node is a node node whose hash value is equal to the target hash value secondhash and whose four-tuple data is equal to the four-tuple data.
2. The method according to claim 1, characterized in that In step S2, the step of parsing the source port search task request, obtaining the target four-tuple data corresponding to the source port search task request, and calculating the target hash value according to the target four-tuple data further includes: S21, according to the parsing result of the source port search task request, obtaining the protocol proto, destination port dport, destination address dip and source address sip corresponding to the source port search task request; S22, obtaining a target hash value secondhash of the target four-tuple data according to the protocol proto, the destination port dport, the destination address dip and the source address sip corresponding to the source port search task request; The target four-tuple data includes the protocol proto, the destination port dport, the destination address dip and the source address sip.
3. The method according to claim 1, characterized in that The step of S34 also includes the step of source port allocation processing, specifically: S33-1, verify the highest layer map0[k] corresponding to the target node node from low to high, and obtain a first verification value. If the first verification value is zero, return a notification of source port allocation failure. If the first verification value is greater than zero, jump to step S33-2; S33-2, verify the middle layer map1[j] corresponding to the target node node from low to high, and obtain a second verification value. If the second verification value is zero, return a notification of source port allocation failure. If the second verification value is greater than zero, determine the lowest bit whose value is 1 from the middle layer map1[j], and jump to step S33-3; S33-3, verify the lowest level map2[i] corresponding to the target node node from low to high according to the lowest bit, obtain a third verification value according to the lowest bit with a value of 1 in the lowest level map2[i], and determine the target source port; in, The first check value is first, the second check value is second, the third check value is three, and the target source port is port, then port=(first×64+second)×64+three; three=map2[first×64+second]; second = map1[first].
4. The method according to claim 3, characterized in that The S33-3, after determining the target source port, also includes a port resetting process step, specifically: S33-31, set the third position of the lowest level map2[first×64+second] corresponding to the target node node to zero. If the value of the lowest level map2[first×64+second] corresponding to the target node node after the third position is zero is zero, jump to step S33-32. Otherwise, return a notification of the end of the search and release the spin lock of the target node node. S33-32, set the second position of the intermediate layer map1[first] corresponding to the target node node to zero, return a notification of the end of the search, and release the lock Lock of the target node node; The lock Lock includes a read lock, a write lock and a spin lock.
5. The method according to claim 1, characterized in that In step S35, the step of creating a new node node according to the target quad-tuple data, determining the quad-tuple data and source port sport of the new node node, and the statistical value count and lock Lock of the source port sport according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and updating them to the target hash bucket further includes: S34-1, acquiring the number of the new node node and all source ports sport corresponding to the four-tuple data in the new node node according to the four-tuple data corresponding to the source port search task request; S34-2, based on the mapping relationship between the highest layer, the middle layer and the lowest layer, sort the number of the new node and all source ports sport corresponding to the four-tuple data in the new node and store them in the target hash bucket.
6. The method according to claim 5, characterized in that The step of S34-2 further includes: S34-21, if the value of the protocol proto of the new node node is less than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the new node node is before the storage location of the source port search data corresponding to the other node node, If the value of the protocol proto of the new node node is greater than the value of the protocol proto of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node. If the value of the protocol proto of the new node node is equal to the value of the protocol proto of another node node in the target hash bucket, jump to step S34-22; S34-22, if the value of the destination port dport of the new node node is smaller than the value of the destination port dport of another node node, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is placed before the storage location of the source port search data corresponding to the new node node. If the value of the destination port dport of the new node node is greater than the value of the destination port dport of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node. If the value of the destination port dport of the new node node is equal to the value of the destination port dport of another node node in the target hash bucket, jump to step S34-23; S34-23, if the value of the source address sip of the new node node is less than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node. If the value of the source address sip of the new node node is greater than the value of the source address sip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node. If the value of the source address sip of the new node node is equal to the value of the source address sip of another node node in the target hash bucket, jump to step S34-24; S34-24, if the value of the destination address dip of the new node node is less than or equal to the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage location of the source port search data corresponding to the other node node is before the storage location of the source port search data corresponding to the new node node, If the value of the destination address dip of the new node node is greater than the value of the destination address dip of another node node in the target hash bucket, then in the target hash bucket, the storage position of the source port search data corresponding to the other node node is before the storage position of the source port search data corresponding to the new node node; S34-25, repeat steps S34-21, S34-22, S34-23 and S34-24 until all nodes node in the target hash bucket are compared and sorted, then determine the storage position of the source port search data corresponding to the new node node in the target hash bucket, and store the target hash value secondhash, the number of the new node node, the five-tuple data corresponding to the four-tuple data, and the mapping relationship between the highest layer, the middle layer and the lowest layer in the target hash bucket according to the storage position, and update the lock Lock of the target hash bucket to a read lock, and set the statistical value count of the new node node to zero; The five-tuple data includes the protocol proto, the destination port dport, the destination address dip, the source address sip and the source port sport.
7. A system for implementing the method for fast searching source ports based on a load balancing device according to claim 1, characterized in that: The system includes a search initialization module, a search request preprocessing module and a source port search determination module; in, The search initialization module is used to define and initialize the source port search data structure and the mapping relationship between the highest layer, the middle layer and the lowest layer, create hash buckets according to the source port search data structure, and set the number of hash buckets; The search request preprocessing module is used for the load balancing device to receive the source port search task request in real time, parse the source port search task request, obtain the target four-tuple data corresponding to the source port search task request, and calculate the target hash value according to the target four-tuple data; The source port search and determination module is used to determine the target node node from the target hash bucket according to the target hash value and the target four-tuple data, traverse the source ports in the target node according to the mapping relationship between the highest layer, the middle layer and the lowest layer, and determine the target source port according to the traversal processing result; The hash bucket stores the source port search data in each of the nodes in a linked list manner.
Citation Information
Patent Citations
Efficient and scalable IP packet classification method
CN109218224A
Preventing Duplicate Sources from Clients Served by a Network Address Port Translator
US20060227807A1