Method, device, electronic device, and storage medium for determining SRv6 message processing instances
By embedding a preset operation in the SRv6 message to obtain the target VPN SID value, the problem that the SRv6 message cannot identify the virtual private network information is solved, and accurate processing instance determination and SRv6 message processing without message overhead are achieved.
Patent Information
- Application Number
- CN202310907649.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-21
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2043-07-21
AI Technical Summary
In SRv6 message forwarding scenarios, the service function node cannot identify the virtual private network information of the message, resulting in the inability to associate the message with a specific processing instance for processing, which increases the message overhead.
By embedding preset operations in the segment identifiers published by the service function node for tenants, the target virtual private network segment identifier value in the SRv6 message is obtained, and the preset mapping table is searched based on the value to determine the processing instance. Three service chain operations are supported: END.LS, END.LD, and END.LM, which use the source VPN SID, destination VPN SID, or their combination as indexes for search.
Accurately determine the processing instance of SRv6 messages, eliminating the need for tenants to modify messages, avoiding increased message overhead, and achieving precise processing of SRv6 messages.
Smart Images

Figure CN118827826B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data transmission technology, and in particular to a method, device, electronic device, and storage medium for determining an SRv6 message processing instance. Background Art
[0002] In the Segment Routing over Internet Protocol Version 6 (SRv6) message forwarding scenario, although the application service (SF) node can identify and process SRv6 messages, the SF cannot identify the virtual private network (VPN) information of the message. Taking the firewall service as an example, the firewall is composed of many instances (virtual firewalls) that provide services. After receiving the tenant message, the firewall needs to associate the tenant message with the instance and provide the corresponding service to the tenant. In the related technology, the firewall only publishes a segment identifier (SID) to the outside world. The tenant who accesses the firewall service will compile the SID into the path list, and the message is forwarded according to the path list. When the firewall receives the message, it cannot identify which tenant the message comes from, nor can it associate the message with a specific instance for processing. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a method, apparatus, electronic device, and storage medium for determining an SRv6 message processing instance, which can accurately identify an SRv6 message processing instance.
[0004] The technical solution of the embodiment of the present invention is achieved as follows:
[0005] In a first aspect, an embodiment of the present invention provides a method for determining an SRv6 message processing instance, which is applied to an application service SF node. The method includes:
[0006] Receive SRv6 packets sent by tenants through electronic devices;
[0007] Obtaining a segment identifier SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents an acquisition location of a segment identifier VPN SID value of a target virtual private network in the SRv6 message;
[0008] Obtaining, according to a preset operation in the SID, a target VPN SID value at a corresponding position in the SRv6 message;
[0009] A preset mapping table is queried according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; the preset mapping table represents a mapping relationship between multiple VPN SID values and a processing instance corresponding to each VPN SID value, and the multiple VPN SID values include the target VPN SID value.
[0010] In the above solution, obtaining the SID issued by the SF node for the tenant in the SRv6 message includes:
[0011] Acquire, according to the destination address field in the SRv6 message, the SID published by the SF node for the tenant.
[0012] In the above solution, the preset operation includes a first service chain operation, a second service chain operation, and a third service chain operation;
[0013] The acquiring, according to the preset operation in the SID, a target VPN SID value at a corresponding position in the SRv6 message includes:
[0014] If the preset operation is the first service chain operation, determining the value of the source VPN SID in the source address field in the SRv6 message as the target VPN SID value;
[0015] If the preset operation is the second service chain operation, determining the first destination VPN SID in the segment identifier list of the SRv6 message as the target VPN SID value;
[0016] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are determined as the target VPN SID value.
[0017] In the above solution, the step of querying a preset mapping table according to the target VPN SID value to determine the target processing instance corresponding to the SRv6 message includes:
[0018] If the preset operation is the first service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the source VPN SID as an index;
[0019] If the preset operation is the second service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the destination VPN SID as an index;
[0020] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are used as indexes to query the target processing instance corresponding to the SRv6 message in the preset mapping table.
[0021] In the above solution, the method further includes:
[0022] Forward the SRv6 message to the target processing instance.
[0023] In the above solution, the method further includes:
[0024] Upon receiving a service purchase request from the tenant, determining a preset operation in the SID published to the tenant according to the service purchase request;
[0025] According to the preset operation, a SID is generated and issued to the tenant.
[0026] In the above solution, the method further includes:
[0027] The mapping relationship between the target VPN SID value and the target processing instance corresponding to the preset operation is stored in the preset mapping table.
[0028] In a second aspect, an embodiment of the present invention provides a device for determining an SRv6 message processing instance, the device including:
[0029] A receiving module, configured to receive SRv6 packets sent by tenants via electronic devices;
[0030] A first acquisition module is configured to acquire the SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents the acquisition position of the target VPN SID value in the SRv6 message;
[0031] A second acquisition module is configured to acquire a target VPN SID value at a corresponding position in the SRv6 message according to a preset operation in the SID;
[0032] A query module is configured to query a preset mapping table according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; the preset mapping table represents a mapping relationship between multiple VPN SID values and a processing instance corresponding to each VPN SID value, and the multiple VPN SID values include the target VPN SID value.
[0033] In a third aspect, an embodiment of the present invention provides an electronic device, comprising a processor and a memory, the processor and the memory being connected to each other, wherein the memory is used to store a computer program, the computer program comprising program instructions, and the processor is configured to call the program instructions to execute the steps of the method for determining an SRv6 message processing instance provided in the first aspect of the embodiment of the present invention.
[0034] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, including: the computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the steps of the method for determining an SRv6 message processing instance as provided in the first aspect of the embodiment of the present invention.
[0035] In the embodiment of the present application, after receiving an SRv6 message sent by a tenant via an electronic device, the SF node obtains the SID published by the SF node for the tenant in the SRv6 message. Then, based on the preset operation in the SID, it obtains the target VPN SID value at the corresponding position in the SRv6 message. Finally, based on the target VPN SID value, it queries a preset mapping table to determine the target processing instance corresponding to the SRv6 message. The preset operation in the SID represents the location from which the target VPN SID value in the SRv6 message is obtained. The preset mapping table represents the mapping relationship between multiple VPN SID values and the processing instance corresponding to each VPN SID value, where the multiple VPN SID values include the target VPN SID value. By embedding a preset operation in the SID published for the tenant, the SF node can obtain the target VPN SID value from the SRv6 message based on the preset operation carried in the SID. Then, based on the target VPN SID value, it queries the preset mapping table to obtain the target processing instance for the SRv6 message. The embodiment of the present application can accurately determine the processing instance of the SRv6 message without requiring the tenant to modify the message, thereby increasing the tenant's message overhead. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 This is a schematic diagram of an SRv6 message format provided by an embodiment of the present invention;
[0037] Figure 2 This is a schematic diagram of an SRv6-based service function chain (SFC) provided by an embodiment of the present invention;
[0038] Figure 3 This is a schematic diagram of the structure of an SRv6 Segment provided by an embodiment of the present invention;
[0039] Figure 4 is a schematic diagram of a firewall service provided by an embodiment of the present invention;
[0040] Figure 5 This is a schematic diagram of an implementation flow of a method for determining an SRv6 message processing instance provided by an embodiment of the present invention;
[0041] Figure 6 This is a schematic diagram of a process for a CPE to use a network service according to an embodiment of the present invention;
[0042] Figure 7 1 is a schematic diagram of a device for determining an SRv6 message processing instance provided by an embodiment of the present invention;
[0043] Figure 8 is a schematic diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0045] With the development of SRv6 technology, the application of SRv6 in actual networks is just around the corner. The SRv6 protocol extends the header of the IPv6 data packet. The format of the SRv6 message is as follows: Figure 1 As shown. The SRv6 extended header follows the IPv6 header. The Segment List (Segment Identification List) in the extended header records the address of each SRv6 node in the path. The list arranges the addresses in the path in reverse order, that is, the first Segment List [0] (the first SID) in the list is the last hop on the path, and the last Segment List [n] in the list is the first hop on the path. The Segment Left field identifies the position of the next hop address in the Segment List (SL). Every time it passes through an SRv6 node, the SL = SL-1 operation is performed, and the address at that position in the list is updated to the Destination Address (destination address) field in the IPv6 packet header, and then the data packet is forwarded.
[0046] Figure 2 This is a diagram of the SRv6-based Service Function Chain (SFC). SRv6 SFC is a technology that adds SRv6 path information to the original message to guide the message to pass through the application layer service device in sequence along the specified path.
[0047] The Service Classifier (SC), located at the edge of the SRv6 SFC service chain network, is the source node of the service chain path. The SC can use different traffic diversion methods to direct service data into the SRv6-TE Policy tunnel for forwarding.
[0048] SFs are nodes that provide specific application services for business traffic. SF nodes that cannot identify SRv6 packets are called SRv6-unaware SFs, while SF nodes that can identify SRv6 packets are called SRv6-aware SFs.
[0049] The Service Function Forwarder (SFF), acting as a service chain agent for the SF, forwards received packets to several SFs associated with the SFF based on SRv6 encapsulation information. After processing the packet, the SF returns it to the SFF, which then decides whether to continue forwarding the packet.
[0050] The SRv6 Segment is formally a 128-bit IPv6 address, such as Figure 3 As shown in the figure, Segment consists of Locator and Function. Function can also contain Arguments. Locator is used for IPv6 routing, and Function is used to specify various SRv6 operations that nodes need to apply to data packets to achieve network programmability.
[0051] In related technologies, the SRv6 service chain operates as follows:
[0052] END.AD This operation will remove the outer IPv6 packet header and then send the packet to SF.
[0053] END.AM This operation updates the IPv6 destination address to the segment when SL=0, that is, the final IPv6 destination address, and then forwards it to the service.
[0054] In SRv6-based service chaining scenarios, path information is orchestrated using a SID list. Therefore, the service chain nodes that a packet must pass through can be included in the generated SRv6 packet. Application service nodes (SFs) are classified into two types: SRv6-aware and SRv6-unaware. SRv6-aware SFs can identify and process received SRv6 packets. In this case, service chaining can be implemented by simply incorporating the SF's SID into the service chain path. SRv6-unaware SFs do not recognize SRv6 packets. In this scenario, service chaining requires configuring an SF proxy.
[0055] In an SRv6-aware scenario, although SF can identify and process SRv6 packets, it cannot identify the VPN information in the packets. Figure 4 As shown, taking the firewall service as an example, the firewall consists of many instances that provide services (virtual firewalls, Figure 4 The firewall consists of instances 1-6). After receiving a tenant message, the firewall needs to associate the tenant message with the instance to provide the corresponding service. Currently, the firewall only publishes a single SID value. Tenants accessing firewall services will compile this SID value into a path list, and messages are forwarded according to the path list. When the firewall receives a message, it cannot identify the tenant from which the message comes, nor can it associate the message with a specific instance for processing, which is not conducive to tenant use.
[0056] Related technologies assign a SID to each virtual firewall and publish it to tenants. When composing messages, tenants add the SID to the SID List in the message. Tenants need to add all the services they use to the message, which greatly increases the message overhead.
[0057] To address the shortcomings of the aforementioned related technologies, embodiments of the present invention provide a method for determining an SRv6 message processing instance, capable of identifying VPN information in an SRv6 message and accurately determining the SRv6 message processing instance. To illustrate the technical solution of the present invention, a specific embodiment is provided below.
[0058] Figure 5 This figure is a schematic diagram illustrating the implementation flow of a method for determining an SRv6 message processing instance, provided in an embodiment of the present invention. This method is performed by a SF node, which provides specific application services for traffic. SF nodes that cannot recognize SRv6 messages are called SRv6-unaware SF nodes, while SF nodes that can recognize SRv6 messages are called SRv6-aware SF nodes. This embodiment is applicable to both SRv6-aware and SRv6-unaware SF nodes.
[0059] In its specific implementation, SF can be a virtual element or a function embedded in a specific network device. SF nodes include Deep Packet Inspection (DPI), Load Balance (LB), Firewall (FW), Intrusion Prevention System (IPS), and Web Application Firewall (WAF).
[0060] refer to Figure 5 The method for determining the SRv6 message processing instance includes:
[0061] S501: Receive an SRv6 message sent by a tenant through an electronic device.
[0062] Users who purchase application services provided by SF nodes are called tenants. Tenants can be businesses, schools, institutions, businesses, or individuals. When tenants need to use application services, they send SRv6 packets to SF nodes through their electronic devices. SF nodes then receive the SRv6 packets sent by tenants.
[0063] This embodiment can be applied in a wide area network (WAN). The WAN network adopts end-to-end SRv6 forwarding and can provide tenants with a variety of value-added services, such as firewall, load balancing, application firewall, etc.
[0064] S502: Acquire a SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents an acquisition position of a target VPN SID value in the SRv6 message.
[0065] When a tenant purchases a service, the SF node will issue a SID to the tenant, and the tenant will compile the SID into a path list. The tenant's SRv6 message is forwarded according to the path list. When the SF node receives the SRv6 message, it obtains the SID issued by the SF node in the SRv6 message.
[0066] Unlike the prior art, the preset operation carried in the SID published by the SF node in this embodiment of the present application indicates the location from which the target VPN SID value is obtained. When the SF node publishes the SID, the correspondence between the location from which the target VPN SID value is obtained and the preset operation is pre-stored. This allows the SF node to determine the location from which the target VPN SID in the SRv6 message is obtained based on the preset operation carried in the SID.
[0067] S503: Obtain a target VPNSID value at a corresponding position in the SRv6 message according to a preset operation in the SID.
[0068] Different preset operations represent obtaining VPN SID values at different positions in the SRv6 message. This application does not limit the number of VPN SIDs included in the target VPN SID, and the target VPN SID may include multiple VPN SIDs in the SRv6 message.
[0069] For example, if the preset operation is the first service chain operation, the value of the source VPN SID in the source address field in the SRv6 message is determined as the target VPN SID value;
[0070] If the preset operation is the second service chain operation, the first destination VPN SID (the value of Segment List[0]) in the segment identifier list of the SRv6 message is determined as the target VPN SID value;
[0071] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are determined as the target VPN SID value.
[0072] S504: Query a preset mapping table according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; the preset mapping table represents a mapping relationship between multiple VPN SID values and a processing instance corresponding to each VPN SID value, and the multiple VPN SID values include the target VPN SID value.
[0073] When a tenant purchases a service, the SF node in this embodiment pre-stores the mapping between the tenant's target VPN SID value and the target processing instance based on the purchased service details in a preset mapping table, establishing a mapping relationship between the tenant and the processing instance providing the service. After obtaining the preset operation carried in the SID, the SF node determines where to obtain the target VPN SID value based on the preset operation and queries the target processing instance for the SRv6 message based on the target VPN SID value.
[0074] For example, compared with the prior art, this embodiment adds the following preset operations:
[0075] The END.LS operation is added. This operation indicates that when the SF node receives a packet, it uses the source VPN SID as an index to find the target processing instance corresponding to the packet. The source VPN SID value is located in the source address field of the SRv6 packet.
[0076] A new END.LD operation has been added. This operation indicates that when the SF node receives a message, it uses the destination VPN SID value as an index to search for the target processing instance corresponding to the message. The value of Segment List[0] in the SRv6 message is the destination VPN SID value.
[0077] The END.LM operation is added. This operation indicates that when the SF node receives a message, it uses the mixed source VPN SID value and the destination VPN SID value as an index to find the target processing instance corresponding to the message.
[0078] In the embodiment of the present application, after receiving an SRv6 message sent by a tenant via an electronic device, the SF node obtains the SID published by the SF node for the tenant in the SRv6 message. Then, based on the preset operation in the SID, it obtains the target VPN SID value at the corresponding position in the SRv6 message. Finally, based on the target VPN SID value, it queries a preset mapping table to determine the target processing instance corresponding to the SRv6 message. The preset operation in the SID represents the location from which the target VPN SID value in the SRv6 message is obtained, and the preset mapping table represents the mapping relationship between multiple VPN SID values and the processing instance corresponding to each VPN SID value, where the multiple VPN SID values include the target VPN SID value. By embedding a preset operation in the SID published for the tenant, the SF node can obtain the target VPN SID value from the SRv6 message based on the preset operation carried in the SID. Then, based on the target VPN SID value, it queries the preset mapping table to obtain the target processing instance for the SRv6 message. Compared to related technologies, the embodiment of the present application can accurately determine the processing instance of an SRv6 message, and the tenant does not need to modify the message, thereby increasing message overhead.
[0079] In one embodiment, obtaining the SID issued by the SF node for the tenant in the SRv6 message includes:
[0080] Acquire, according to the destination address field in the SRv6 message, the SID published by the SF node for the tenant.
[0081] like Figure 1 As shown, every time an SRv6 message passes through an SRv6 node, an SL=SL-1 operation is performed, and the address at that position in the list is updated to the Destination Address field in the IPv6 packet header.
[0082] Therefore, the SID published by the SF node for the tenant can be obtained from the Destination Address field in the SRv6 message. The value of the Destination Address field is the SID published by the SF node for the tenant. When arranging the message, the tenant adds the SID published by the SF node for the tenant to the SID List in the message. Every time the SRv6 message passes through an SRv6 node, the value of the Destination Address field in the IPv6 packet header is updated. When the SRv6 message reaches the SF node, the value of the Destination Address field is exactly the SID published by the SF node for the tenant. Therefore, the SF node can easily obtain the SID previously published for the tenant from the Destination Address field in the SRv6 message. Moreover, the SF node's acquisition of the SID does not increase performance loss, and the tenant does not need to increase message overhead.
[0083] In one embodiment, the preset operation includes a first service chain operation, a second service chain operation, and a third service chain operation;
[0084] The acquiring, according to the preset operation in the SID, a target VPN SID value at a corresponding position in the SRv6 message includes:
[0085] If the preset operation is the first service chain operation, determining the value of the source VPN SID in the source address field in the SRv6 message as the target VPN SID value;
[0086] If the preset operation is the second service chain operation, determining the first destination VPN SID in the segment identifier list of the SRv6 message as the target VPN SID value;
[0087] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are determined as the target VPN SID value.
[0088] Among them, the segment identifier list is Figure 1 In the Segment List in the extended header shown in the figure, the first destination VPNSID is the value of Segment List[0] in the Segment List.
[0089] In existing technologies, SF nodes only publish a single SID value when providing services to tenants. Therefore, for all incoming messages from tenants, SF nodes cannot distinguish whether a message should be looked up using the source VPN SID, the destination VPN SID, or a combination of the source and destination VPN SIDs. Each SID value carries one operation, and source VPN SID lookup, destination VPN SID lookup, and a combination of source and destination VPN SID lookup correspond to three corresponding operations on SF nodes.
[0090] Therefore, this embodiment proposes the following three SRv6 service chain operations:
[0091] 1. END.LS operation: This operation indicates that when the SF node receives a message, it should use the source VPN SID as an index to find the target processing instance corresponding to the message. The source VPN SID value is located in the source address field in the SRv6 message.
[0092] 2. END.LD operation: This operation indicates that when the SF node receives the message, it should use the destination VPN SID as the index to find the target processing instance corresponding to the message. The value of Segment List[0] in the SRv6 message is the destination VPN SID value.
[0093] 3. END.LM operation: This operation indicates that when the SF node receives a message, it should use the mixed source and destination VPN SIDs as an index to find the target processing instance corresponding to the message.
[0094] By adding three new operations, SF can use the source VPN SID, destination VPN SID, or a combination of the source VPN SID and destination VPN SID as the tenant VPN information identifier to establish a corresponding relationship with the target processing instance, so that the SF node can accurately obtain the target VPN SID according to the type of preset operation, facilitating table lookup to obtain the target processing instance.
[0095] Among them, the first business chain operation corresponds to the END.LS operation, the second business chain operation corresponds to the END.LD operation, and the third business chain operation corresponds to the END.LM operation.
[0096] In one embodiment, the querying of a preset mapping table according to the target VPN SID value to determine the target processing instance corresponding to the SRv6 message includes:
[0097] If the preset operation is the first service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the source VPN SID as an index;
[0098] If the preset operation is the second service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the destination VPN SID as an index;
[0099] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are used as indexes to query the target processing instance corresponding to the SRv6 message in the preset mapping table.
[0100] For example, the source VPN SID can be used as the tenant VPN information identifier. The SF node uses the source VPN SID to establish a mapping relationship between the tenant information and the processing instance that processes the tenant's message. For example, a VPN information mapping table or forwarding table can be established, and the SID corresponding to the END.LS operation is published to the tenant. After receiving the SRv6 message, the SF node obtains the value of the source VPN SID through the source address field based on the END.LS operation in the SID value. It then uses the source VPN SID to perform a table lookup to obtain the corresponding target processing instance.
[0101] For example, the destination VPN SID can also be used as the tenant VPN information identifier. As previously mentioned, when SRv6 forwards a message, each time it passes through an SRv6 node, it updates the address of the next-hop node in the Segment List to the Destination Address field in the IPv6 packet header. Therefore, the Destination Address field is not fixed. When the SF node receives the SRv6 message, the Destination Address field is not the value of the destination VPN SID. Therefore, when the SF node needs to obtain the destination VPN SID, it needs to read the first segment in the Segment List in the SRH, that is, the segment value when SL = 0. Because the Segment List is sorted in reverse order, SL = 0 is the last hop of the path, that is, the destination node. Therefore, the value of Segment List [0] is the destination VPN SID value.
[0102] The SF node uses the destination VPN SID to establish a mapping between user information and the instance that processes the tenant's message. For example, it can establish a VPN information mapping table or forwarding table, and publish the SID corresponding to the END.LD to the tenant. After receiving the SRv6 message, the SF node obtains the value of the destination VPN SID based on the END.LD operation carried in the SID, and uses the destination VPN SID to perform a table lookup to obtain the corresponding target processing instance.
[0103] For example, a combination of the source VPN SID and the destination VPN SID can also be used as a tenant information identifier. In addition to using the source VPN SID and the destination VPN SID individually as tenant information identifiers, some services require the use of both the source VPN SID and the destination VPN SID for verification. For example, when a tenant accesses certain cloud applications, it is necessary to verify both the legality of the tenant (source VPN SID) and the accessibility of the accessed application (destination VPN SID). First, the SF node uses the source VPN SID and the destination VPN SID to establish a mapping relationship between tenant information and the instance that processes the tenant's message. For example, a VPN information mapping table or forwarding table can be established, and the SID corresponding to END.LM is issued to the tenant. After receiving the SRv6 message, the SF node obtains the source VPN SID value and the destination VPN SID value based on the END.LM carried in the SID, and uses the combination of the source VPN SID value and the destination VPN SID value to perform a table lookup to obtain the corresponding target processing instance.
[0104] By adding three new service chain operations corresponding to three search methods, the SF node can accurately obtain the target VPN SID in the SRv6 message according to the preset operation type, and then perform a table lookup based on the target VPN SID to obtain the target processing instance of the SRv6 message.
[0105] In actual application scenarios, the SRv6-based Software-Defined WAN (SD-WAN) adopts end-to-end SRv6 forwarding and can provide tenants with a variety of value-added services. These value-added services can be provided at the point-of-presence (PoP) in the form of SFC. These value-added services are SF. Figure 6 As shown, Figure 6 The LB, FW, and WAF in the figure are SFs. In a WAN network, SRv6 packets from multiple tenants are aggregated at the PoP, forwarded by the PoP to the SF, processed by the SF, and then forwarded by the PoP.
[0106] Taking traffic filtering as an example, a tenant purchases a traffic filtering service. When the customer premises equipment (CPE) sends an SRv6 message, it will include the SID published by the traffic filtering service in the path, which will be forwarded by the PoP to the corresponding SF. The SF can publish different SID values to the tenant based on the service details purchased by the tenant. The tenant will include the SID value in the path list, and the PoP will forward the message to the corresponding SF. The SF will obtain the source VPN SID and / or destination VPN SID in the message based on the different operations represented by the SID value, search the corresponding table entry based on the source VPN SID and / or destination VPN SID, and forward the message to the corresponding target processing instance for processing (pass or reject according to the conditions). After the message is processed, the SF will forward it to the PoP, which will continue to forward it.
[0107] In one embodiment, the method further comprises:
[0108] Forward the SRv6 message to the target processing instance.
[0109] For example, in Figure 4 In the example, if it is determined that the processing instance corresponding to the VPN SID is instance 1, the SRv6 packet is forwarded to instance 1, so that the tenant's business can proceed smoothly.
[0110] In one embodiment, upon receiving a service purchase request from the tenant, determining a preset operation in the SID issued to the tenant according to the service purchase request;
[0111] According to the preset operation, a SID is generated and issued to the tenant.
[0112] In one embodiment, the preset mapping table stores a mapping relationship between the target VPN SID value corresponding to the preset operation and the target processing instance.
[0113] For example, in the above embodiment, when the source VPN SID is used as the target VPN SID value, the SF uses the source VPN SID to establish a mapping relationship between the tenant information and the target processing instance that processes the tenant's message, and publishes the SID corresponding to the END.LS operation to the tenant.
[0114] For example, when the destination VPN SID is used as the target VPN SID value, the SF uses the destination VPN SID to establish a mapping relationship between the tenant information and the target processing instance that processes the tenant's message, and publishes the SID corresponding to the END.LD operation to the tenant.
[0115] When the combination of the source VPN SID and the destination VPN SID is used as the target VPN SID value, the SF uses the source VPN SID and the destination VPN SID to establish a mapping relationship between the tenant information and the target processing instance that processes the tenant's packets, and publishes the SID corresponding to the END.LM operation to the tenant.
[0116] This embodiment of the present application can obtain the target VPN SID value's acquisition location based on the preset operation embedded in the SID published by the SF node for the tenant in the SRv6 message, and then query the preset mapping table based on the target VPN SID value to obtain the target processing instance for the SRv6 message. The tenant does not need to modify the message, so there is no additional message overhead for the tenant.
[0117] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0118] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0119] It should be noted that the technical solutions described in the embodiments of the present invention can be arbitrarily combined without conflict.
[0120] In addition, in the embodiments of the present invention, “first”, “second”, etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0121] refer to Figure 7 , Figure 7 is a schematic diagram of a device for determining an SRv6 message processing instance provided by an embodiment of the present invention, such as Figure 7 As shown, the device includes:
[0122] A receiving module, configured to receive SRv6 packets sent by tenants via electronic devices;
[0123] A first acquisition module is configured to acquire the SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents the acquisition position of the target VPN SID value in the SRv6 message;
[0124] A second acquisition module is configured to acquire a target VPN SID value at a corresponding position in the SRv6 message according to a preset operation in the SID;
[0125] A query module is configured to query a preset mapping table according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; the preset mapping table represents a mapping relationship between multiple VPN SID values and a processing instance corresponding to each VPN SID value, and the multiple VPN SID values include the target VPN SID value.
[0126] In one embodiment, the first acquisition module is specifically configured to:
[0127] Acquire, according to the destination address field in the SRv6 message, the SID published by the SF node for the tenant.
[0128] In one embodiment, the preset operation includes a first service chain operation, a second service chain operation, and a third service chain operation;
[0129] The second acquisition module is specifically used for:
[0130] If the preset operation is the first service chain operation, determining the value of the source VPN SID in the source address field in the SRv6 message as the target VPN SID value;
[0131] If the preset operation is the second service chain operation, determining the first destination VPN SID in the segment identifier list of the SRv6 message as the target VPN SID value;
[0132] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are determined as the target VPN SID value.
[0133] In one embodiment, the query module is specifically configured to:
[0134] If the preset operation is the first service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the source VPN SID as an index;
[0135] If the preset operation is the second service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the destination VPN SID as an index;
[0136] If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are used as indexes to query the target processing instance corresponding to the SRv6 message in the preset mapping table.
[0137] In one embodiment, the apparatus further comprises:
[0138] A forwarding module is used to forward the SRv6 message to the target processing instance.
[0139] In one embodiment, the apparatus further comprises:
[0140] a publishing module, configured to, upon receiving a service purchase request from the tenant, determine a preset operation in the SID to be published to the tenant according to the service purchase request;
[0141] A generating module is used to generate a SID issued to the tenant according to the preset operation.
[0142] In one embodiment, the apparatus further comprises:
[0143] The storage module is configured to store a mapping relationship between the target VPN SID value corresponding to the preset operation and the target processing instance in the preset mapping table.
[0144] In actual application, the receiving module, the first acquisition module, the second acquisition module and the query module can be implemented by a processor in an electronic device, such as a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU) or a programmable gate array (FPGA).
[0145] It should be noted that the apparatus for determining an SRv6 message processing instance provided in the above embodiment only uses the division of the above modules as an example to illustrate the determination of an SRv6 message processing instance. In actual applications, the above processing can be assigned to different modules as needed, that is, the internal structure of the apparatus can be divided into different modules to complete all or part of the above-described processing. In addition, the apparatus for determining an SRv6 message processing instance provided in the above embodiment and the embodiment of the method for determining an SRv6 message processing instance are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0146] The aforementioned SRv6 message processing instance determination device may be in the form of an image file. After execution, the image file may be run as a container or virtual machine to implement the SRv6 message processing instance determination method described herein. Of course, this is not limited to image files; any software form capable of implementing the SRv6 message processing instance determination method described herein is within the scope of protection of this application.
[0147] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiment of the present application, the embodiment of the present application also provides an electronic device. Figure 8 This is a schematic diagram of the hardware structure of the electronic device according to the embodiment of the present application. Figure 8 As shown, the electronic equipment includes:
[0148] Communication interface, capable of exchanging information with other devices such as network equipment;
[0149] The processor is connected to the communication interface to implement information exchange with other devices and is used to execute the methods provided by one or more technical solutions on the electronic device side when running a computer program. The computer program is stored in the memory.
[0150] Of course, in actual applications, the various components in the electronic device are coupled together through a bus system. It is understood that the bus system is used to achieve connection and communication between these components. In addition to the data bus, the bus system also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 8 In the text, various buses are labeled as bus systems.
[0151] The memory in the embodiments of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.
[0152] It is understood that the memory can be volatile memory or non-volatile memory, or can include both volatile and non-volatile memory. Among them, non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disk, or compact disc read-only memory (CD-ROM); magnetic surface memory can be magnetic disk memory or tape memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.
[0153] The methods disclosed in the above embodiments of the present application can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above methods can be completed by hardware integrated logic circuits in the processor or instructions in software form. The above processor may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in a memory. The processor reads the program in the memory and completes the steps of the above methods in combination with its hardware.
[0154] Optionally, when the processor executes the program, it implements the corresponding processes implemented by the electronic device in each method of the embodiments of the present application, which will not be described here for the sake of brevity.
[0155] In an exemplary embodiment, the present application also provides a storage medium, namely, a computer storage medium, specifically a computer-readable storage medium, including, for example, a first memory storing a computer program, wherein the computer program can be executed by a processor of an electronic device to perform the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0156] In the several embodiments provided in this application, it should be understood that the disclosed devices, electronic devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0157] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0158] In addition, all functional units in the embodiments of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the above-mentioned integrated units can be implemented in the form of hardware or in the form of hardware plus software functional units.
[0159] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: mobile storage devices, ROM, RAM, disks or optical disks, etc. Various media that can store program codes.
[0160] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application can be essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0161] It should be noted that the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0162] In addition, in the examples of this application, "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0163] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A method for determining an SRv6 message processing instance, applied to an application service SF node, characterized in that: The method comprises: Receive SRv6 packets sent by tenants through electronic devices; Obtaining a segment identifier SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents an acquisition location of a segment identifier VPN SID value of a target virtual private network in the SRv6 message; Obtaining a target VPN SID value at a corresponding position in the SRv6 message according to a preset operation in the SID; the preset operation includes a first service chain operation, a second service chain operation, and a third service chain operation; If the preset operation is the first service chain operation, determining the value of the source VPN SID in the source address field in the SRv6 message as the target VPN SID value; If the preset operation is the second service chain operation, determining the first destination VPN SID in the segment identifier list of the SRv6 message as the target VPN SID value; If the preset operation is the third service chain operation, determining the value of the source VPN SID and the value of the destination VPN SID as the target VPN SID value; A preset mapping table is queried according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; the preset mapping table represents a mapping relationship between multiple VPN SID values and a processing instance corresponding to each VPN SID value, and the multiple VPN SID values include the target VPN SID value.
2. The method according to claim 1, characterized in that The obtaining the SID issued by the SF node for the tenant in the SRv6 message includes: Acquire, according to the destination address field in the SRv6 message, the SID published by the SF node for the tenant.
3. The method according to claim 1, characterized in that The querying of a preset mapping table according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message includes: If the preset operation is the first service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the source VPN SID as an index; If the preset operation is the second service chain operation, querying the target processing instance corresponding to the SRv6 message in the preset mapping table using the value of the destination VPN SID as an index; If the preset operation is the third service chain operation, the value of the source VPN SID and the value of the destination VPN SID are used as indexes to query the target processing instance corresponding to the SRv6 message in the preset mapping table.
4. The method according to claim 1, wherein The method further comprises: Forward the SRv6 message to the target processing instance.
5. The method according to claim 1, wherein The method further comprises: Upon receiving a service purchase request from the tenant, determining a preset operation in the SID published to the tenant according to the service purchase request; According to the preset operation, a SID is generated and issued to the tenant.
6. The method according to claim 5, characterized in that The method further comprises: The mapping relationship between the target VPN SID value and the target processing instance corresponding to the preset operation is stored in the preset mapping table.
7. A device for determining an SRv6 message processing instance, characterized in that: include: A receiving module, configured to receive SRv6 packets sent by tenants via electronic devices; A first acquisition module is configured to acquire a SID issued by the SF node for the tenant in the SRv6 message; the preset operation in the SID represents an acquisition position of a target VPN SID value in the SRv6 message; a second acquisition module, configured to acquire, according to a preset operation in the SID, a target VPN SID value at a corresponding position in the SRv6 message; the preset operation includes a first service chain operation, a second service chain operation, and a third service chain operation; if the preset operation is the first service chain operation, determining the value of the source VPN SID in the source address field in the SRv6 message as the target VPN SID value; If the preset operation is the second service chain operation, determining the first destination VPN SID in the segment identifier list of the SRv6 message as the target VPN SID value; If the preset operation is the third service chain operation, determining the value of the source VPN SID and the value of the destination VPN SID as the target VPN SID value; A query module, configured to query a preset mapping table according to the target VPN SID value to determine a target processing instance corresponding to the SRv6 message; The preset mapping table represents a mapping relationship between a plurality of VPN SID values and a processing instance corresponding to each VPN SID value, wherein the plurality of VPN SID values include the target VPN SID value.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method for determining the SRv6 message processing instance according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the method for determining an SRv6 message processing instance according to any one of claims 1 to 6.
Citation Information
Patent Citations
Message indication method and device, equipment and storage medium
CN112511418A
Message processing method, device and system and storage medium
CN113472650A