Packet detection method and electronic device
By introducing a blockchain verification mechanism in message transmission and using the segment routing header and performance detection field to generate a hash value, the problem of tampering of network measurement information along the route is solved, the security and transparency of network measurement are improved, and the risk of network attacks is reduced.
Patent Information
- Application Number
- CN202411164274.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-22
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-08-22
AI Technical Summary
In-path network measurement requests are easily tampered with, which increases the possibility of network attacks, affects the uniformity of network resource allocation, and may cause network congestion or equipment paralysis.
By combining message transmission with blockchain, the reference hash value is generated using the segment routing header and performance detection field to perform message detection, ensure information transparency and immutability, and use the blockchain verification and feedback mechanism to achieve message detection and performance feedback.
It avoids the tampering of the on-line network measurement information, reduces the possibility of network attacks, improves the security and transparency of the on-line network measurement, and ensures the rational allocation and optimization of network resources.
Smart Images

Figure CN118869339B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network communications, and in particular to a message detection method and electronic equipment. Background Art
[0002] In the field of network telemetry, path-associated network measurement is a key method. By carrying specific detection fields in packets, network nodes are triggered to perform packet detection, data collection, and statistical reporting, thereby enabling on-site service quality assessment in business scenarios. Because SRv6 (Segment Routing over IPv6) packets can carry detection fields, they can simultaneously implement network programming and measure key metrics such as packet loss rate, latency, and jitter along the transmission path.
[0003] While route-associated network measurements can provide visibility into network status, they can also pose significant security risks. For example, measurement requests initiated by tampering with or forging route-associated network measurement information can lead network managers to make erroneous resource allocation decisions. This can affect the uniformity of network resource allocation and potentially cause actual network congestion or device failure. It can also lead to the leakage of sensitive information such as network status and topology, exposing the locations of key network nodes and traffic distribution, potentially opening the door to subsequent network attacks.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] The embodiments of the present invention provide a message detection method and electronic device to at least solve the technical problem in the related art that an associated network measurement request is easily tampered with, thereby increasing the possibility of network attacks.
[0006] According to one aspect of an embodiment of the present invention, a message detection method is provided, including: a first network device determines target data to be transmitted, a first segment routing header, and a performance detection field, wherein the target data is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used for the transmission network device to perform message detection; the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device belongs to the transmission network device, the first reference hash value is used to generate a first task whose recipient address is the address of a third network device, the first task includes the first reference hash value, and is used to be passed to a blockchain, so that the third network device obtains the first task through interaction with the blockchain, the third network device is used to generate a first detection task including the first reference hash value based on the first task, the third network device is used to send the first detection task to the second network device, and Notify the second network device to perform message detection; the first network device generates a first message based on the target data, the first segment routing header, and the performance detection field; the first network device sends the first message, wherein the first message is used to be transmitted on a predetermined forwarding path, the predetermined forwarding path includes a transmission network device, the second network device is used to receive the first message to be detected on the predetermined forwarding path, the first message to be detected is used by the second network device to generate a first hash value to be detected, the second network device is used to match the first hash value to be detected and the first reference hash value to obtain a matching result, when the matching result indicates that the first hash value to be detected and the first reference hash value match, the second network device is used to detect the first message to be detected according to the first detection task sent by the third network device, and determine the first detection result, the second network device is used to send the first detection result to the third network device, the third network device is used to generate a performance feedback task based on the first detection result, and the third network device is used to upload the performance feedback task to the blockchain.
[0007] According to one aspect of an embodiment of the present invention, another message detection method is provided, including: a second network device obtains a first detection task including a first reference hash value, wherein the second network device belongs to a transmission network device included in a predetermined forwarding path, the first detection task is generated by a third network device based on the first task, and is used to notify the second network device to perform message detection, the first task includes a first reference hash value, and is used to be transmitted to a blockchain, so that the third network device obtains the first task through interaction with the blockchain, the recipient address of the first task is the address of the third network device, the first reference hash value is generated by the first network device based on the indication information corresponding to the second network device indicated by the first segment routing header, and the performance detection field, the target data starts from the first network device, and the transmission network device determined according to the indication information of the first segment routing header. The method comprises the following steps: performing orderly transmission, wherein the performance detection field is used to transmit a network device to perform message detection; the second network device receives a first message to be detected, wherein the first message to be detected is any message received by the second network device on a predetermined forwarding path; the second network device generates a first hash value to be detected based on the first message to be detected; the second network device matches the first hash value to be detected and the first reference hash value to obtain a matching result; when the matching result indicates that the first hash value to be detected matches the first reference hash value, the second network device detects the first message to be detected according to the first detection task and determines the first detection result; the second network device sends the first detection result to the third network device, so that the third network device generates a performance feedback task based on the first detection result, wherein the third network device uploads the performance feedback task to the blockchain.
[0008] According to one aspect of an embodiment of the present invention, another message detection method is provided, including: a first network device determines target data to be transmitted, a first segment routing header, and a performance detection field, wherein the target data is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used for the transmission network device to perform message detection; the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device belongs to the transmission network device, the first reference hash value is used to generate a first task whose receiving address is the address of the third network device, the first task includes the first reference hash value and is used to be transmitted to the blockchain; the third network device obtains the first task by interacting with the blockchain; the third network device generates a first detection task including the first reference hash value based on the first task; the third network device sends the first detection task to the second network device and notifies The second network device performs message detection; the first network device generates a first message based on the target data, the first segment routing header, and the performance detection field; the first network device sends the first message, wherein the first message is used to be transmitted on a predetermined forwarding path, and the predetermined forwarding path includes a transmission network device; the second network device receives the first message to be detected on the predetermined forwarding path, wherein the first message to be detected is used by the second network device to generate a first hash value to be detected; the second network device matches the first hash value to be detected and the first reference hash value to obtain a matching result; when the matching result indicates that the first hash value to be detected matches the first reference hash value, the second network device is used to detect the first message to be detected according to the first detection task sent by the third network device to determine the first detection result; the second network device sends the first detection result to the third network device; the third network device generates a performance feedback task based on the first detection result; the third network device uploads the performance feedback task to the blockchain.
[0009] According to another aspect of an embodiment of the present invention, an electronic device is provided, comprising: one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors implement any one of the message detection methods.
[0010] In an embodiment of the present invention, a method of combining message transmission with blockchain is adopted, and the target data to be transmitted, the first segment routing header, and the performance detection field are determined by the first network device, wherein the target data is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used for the transmission network device to perform message detection; the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device belongs to the transmission network device, the first reference hash value is used to generate a first task whose recipient address is the address of the third network device, the first task includes the first reference hash value, and is used to be transmitted to the blockchain, so that the third network device obtains the first task through interaction with the blockchain, the third network device is used to generate a first detection task including the first reference hash value based on the first task, the third network device is used to send the first detection task to the second network device, and Notify the second network device to perform message detection; the first network device generates a first message based on the target data, the first segment routing header, and the performance detection field; the first network device sends the first message, wherein the first message is used to be transmitted on a predetermined forwarding path, the predetermined forwarding path includes a transmission network device, the second network device is used to receive the first message to be detected on the predetermined forwarding path, the first message to be detected is used by the second network device to generate a first hash value to be detected, the second network device is used to match the first hash value to be detected and the first reference hash value to obtain a matching result, when the matching result indicates that the first hash value to be detected and the first reference hash value match, the second network device is used to detect the first message to be detected according to the first detection task sent by the third network device, and determine the first detection result, the second network device is used to send the first detection result to the third network device, the third network device is used to generate a performance feedback task based on the first detection result, and the third network device is used to upload the performance feedback task to the blockchain. The purpose of preventing the on-line network measurement information from being tampered with and reducing the possibility of triggering network attacks is achieved, and the technical effect of improving the security of on-line network measurement is achieved, thereby solving the technical problem in related technologies that on-line network measurement requests are easily tampered with, thereby increasing the possibility of network attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0012] Figure 1 is a first flow chart of an optional message detection method according to an embodiment of the present invention;
[0013] Figure 2 is a first interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0014] Figure 3 is a second interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0015] Figure 4 is a third interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0016] Figure 5 is a fourth interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0017] Figure 6 is a fifth interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0018] Figure 7 is a first format diagram of an optional packet detection method according to an embodiment of the present application;
[0019] Figure 8 is a second format diagram of an optional packet detection method according to an embodiment of the present application;
[0020] Figure 9 is a third format diagram of an optional packet detection method according to an embodiment of the present application;
[0021] Figure 10 is a fourth format diagram of an optional packet detection method according to an embodiment of the present application;
[0022] Figure 11 is a fifth format diagram of an optional packet detection method according to an embodiment of the present application;
[0023] Figure 12 is a packet diagram of an optional packet detection method according to an embodiment of the present application;
[0024] Figure 13 is an extension header diagram of an optional packet detection method according to an embodiment of the present application;
[0025] Figure 14 is a second flow diagram of an optional packet detection method according to an embodiment of the present application;
[0026] Figure 15 is a sixth interaction diagram of an optional packet detection method according to an embodiment of the present application;
[0027] Figure 16is a seventh interactive schematic diagram of an optional message detection method provided according to an embodiment of the present invention;
[0028] Figure 17 This is an eighth interactive diagram of an optional message detection method provided according to an embodiment of the present invention;
[0029] Figure 18 is a third flow chart of an optional message detection method provided according to an embodiment of the present invention;
[0030] Figure 19 is a schematic flow chart of an optional message detection method provided according to an embodiment of the present invention;
[0031] Figure 20 is a 5G schematic diagram of an optional message detection method provided according to an embodiment of the present invention;
[0032] Figure 21 This is a schematic diagram of an application of an optional message detection method provided according to an embodiment of the present invention. DETAILED DESCRIPTION
[0033] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0034] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0035] According to an embodiment of the present application, a method for processing a packet is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0036] Figure 1 is a first flowchart of an optional packet detection method according to an embodiment of the present application, as shown in Figure 1 the method comprises the following steps:
[0037] In step S102, the first network device determines target data to be transmitted, a first segment routing header, and a performance detection field, wherein the target data is sequentially transmitted according to the indication information of the first segment routing header, and the performance detection field is used for packet detection by the transmission network device.
[0038] It can be understood that the first network device needs to determine the target data to be transmitted, the first segment routing header, and the performance detection field. Among them, the first segment routing header is responsible for providing the indication information corresponding to all transmission network devices in the predetermined forwarding path, ensuring that the target data can be forwarded through a specific transmission network device according to a predetermined order, and the performance detection field is used for packet detection by the subsequent transmission network device. Through the above processing, the setting of the first segment routing header realizes the ordered transmission of data, and the introduction of the performance detection field provides a processing basis for the detection of subsequent transmission performance, which is helpful for the in-situ network measurement processing.
[0039] Optionally, the above-mentioned first segment routing header (SRH, Segment Routing Header) is a forwarding mechanism based on IPv6 (Internet Protocol version 6), which inserts a segment list (Segment List) with an order in the data packet header to guide the forwarding path of the data packet in the network. In the segment routing, key information about how the data packet is processed and forwarded is included, and the first segment routing header includes a series of segment identifiers (SIDs, Segment Identifiers) corresponding to the transmission network devices in the predetermined forwarding path. Through the first segment routing header SRH, the first packet can be forwarded in the network according to the predetermined path.
[0040] Step S104: The first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device is a transmission network device, and the first reference hash value is used to generate a first task whose recipient address is the address of the third network device. The first task includes the first reference hash value and is transmitted to the blockchain, so that the third network device obtains the first task through interaction with the blockchain. The third network device is used to generate a first detection task including the first reference hash value based on the first task. The third network device is used to send the first detection task to the second network device and notify the second network device to perform message detection.
[0041] It can be understood that the first network device can generate a first reference hash value based on the information of the second network device indicated in the first segment routing header and the performance detection field. The first reference hash value provides a reliable verification basis for subsequent message detection, which helps prevent the message from being tampered with during transmission. The first reference hash value can be used to create a first task, the recipient of which is a third network device, and is delivered through the blockchain. The delivery of the first task through the blockchain enhances the transparency and immutability of the on-path network measurement and improves the security of network detection. After the third network device obtains the first task from the blockchain, it generates a first detection task based on the first reference hash value therein, which is used to send to the second network device and notify it to perform message detection.
[0042] Optionally, the first network device may generate a first reference field corresponding to the second network device based on the indication information corresponding to the second network device and the performance detection field, and then generate a first reference hash value from the first reference field.
[0043] In an optional embodiment, the method also includes: when the first network device is set to directly interact with the blockchain, the first network device generates a first task based on the first reference hash value; the first network device uploads the first task to the blockchain; the first network device queries the blockchain to determine a performance feedback task whose recipient address is the address of the first network device, wherein the performance feedback task includes a processing result of the first task uploaded by the first network device.
[0044] I understand. Figure 2 : is a first interactive schematic diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 2In the optional embodiment, the first network device is configured to interact with the blockchain directly without the need of other intermediate devices or networks. The first network device creates the first task based on the first reference hash value generated previously. The first network device then uploads the first task directly to the blockchain, and the distributed and tamper-proof nature of the blockchain ensures the security and traceability of the first task. After completing the uploading of the first task, the first network device can periodically or on demand query the blockchain to find the performance feedback task with the receiver address being the address of the first network device. The performance feedback task is generated by the third network device after completing the performance detection and processing specified by the first task, and uploaded to the blockchain. The performance feedback task contains the processing result of the first task.
[0045] Optionally, after receiving the performance feedback task, the first network device parses the processing result in the performance feedback task and makes further processing or decision as needed. For example, if the performance feedback task shows that there is a problem in data transmission, i.e., when a network performance bottleneck is found, the first network device can select the optimal transmission path or adjust the data transmission strategy according to the performance feedback task.
[0046] It should be noted that the query processing of the blockchain to obtain the performance feedback task can also be performed by other network devices, and it can be optionally set whether the first network device needs to obtain the performance feedback task or send the performance feedback task to a predetermined performance adjustment device for overall processing.
[0047] In an optional embodiment, the method further includes: in the case where the first network device is set to indirectly interact with the blockchain, the first network device sends the first reference hash value to a fourth network device, so that the fourth network device generates the first task based on the first reference hash value and uploads the first task to the blockchain, wherein the fourth network device has the ability to interact with the first network device and the blockchain respectively; the first network device obtains the performance feedback task through the fourth network device, and the fourth network device is used to query the blockchain and determine the performance feedback task with the address of the fourth network device as the receiver address, and the performance feedback task includes the processing result of the first task uploaded by the fourth network device.
[0048] It can be understood that, Figure 3 is a second interaction diagram of an optional message detection method according to an embodiment of the present application, as shown in Figure 3The first network device shown is configured not to interact directly with the blockchain, but to rely on an intermediate device, namely the fourth network device, to perform such interaction. The fourth network device is configured to have the ability to interact with the first network device and the blockchain respectively, and can transfer information and tasks between the two. The first network device sends the first reference hash value to the fourth network device. The fourth network device generates a first task based on the first reference hash value and uploads the first task to the blockchain. Since the first network device interacts indirectly with the blockchain, the first network device does not directly perform the processing of querying the blockchain, and the first network device can obtain performance feedback tasks through the fourth network device. The fourth network device can query the blockchain regularly or on demand, determine the performance feedback task whose recipient address is its own address (the address of the fourth network device) and forward it to the first network device.
[0049] In an optional embodiment, the fourth network device interacts with the blockchain through the first proxy device, wherein the first proxy device is used to perform interaction processing between the fourth network device and the blockchain.
[0050] I understand. Figure 4 is a third interactive schematic diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 4 The first proxy device shown is used to handle the interaction between the fourth network device and the blockchain, so that each fourth network device can focus on sending the first task and querying the performance feedback task, transferring the complexity of the blockchain interaction to the dedicated proxy device, which helps to reduce the coupling between the network device and the blockchain and improve the maintainability and scalability of the system.
[0051] Optionally, the first proxy device may be a router, a switch or other network device.
[0052] In an optional embodiment, the first network device interacts with the fourth network device through at least one first intermediate device.
[0053] I understand. Figure 5 is a fourth interactive schematic diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 5 As shown, the interaction between the first network device and the fourth network device is further implemented through at least one first intermediate device, increasing the flexibility of the system architecture. The first intermediate device acts as a bridge between the first and fourth network devices, responsible for receiving data or tasks from the first network device and forwarding them to the fourth network device. Simultaneously, it can also receive data or tasks from the fourth network device and forward them to the first network device.
[0054] Optionally, the first intermediate device can be a router, switch or other network device, etc., which plays a role of forwarding data in the network. In this way, even if the first network device and the fourth network device are not in the same local area network, or are limited by network isolation, they can still communicate information and tasks.
[0055] In an optional embodiment, the first network device interacts with the fourth network device through the second proxy device, and the fourth network device interacts with the blockchain through the second proxy device, wherein the second proxy device is configured to perform interaction processing between the fourth network device and the blockchain, and perform interaction processing between the first network device and the fourth network device.
[0056] It can be understood that, Figure 6 is a fifth interaction schematic diagram of an optional message detection method according to an embodiment of the present application, as Figure 6 The second proxy device acts as a bidirectional proxy, which is a medium for interaction between the first network device and the fourth network device, and a medium for interaction between the fourth network device and the blockchain. That is, the second proxy device is responsible for processing interaction between the first network device and the fourth network device, and interaction between the fourth network device and the blockchain. Through the above setting, the flexibility of the system architecture can be increased, the interaction efficiency can be improved, the communication between multiple network nodes (such as transmission network devices) can be centrally managed and controlled, and the complexity and maintenance cost of the network system can be reduced.
[0057] Through the introduction of the proxy device, the burden of the network device is reduced, which is conducive to improving the overall performance and scalability. Through centralized management and control of communication between multiple network devices, the overall efficiency and reliability of the work of each network device can be better coordinated.
[0058] In an optional embodiment, the sender address of the first task is used to indicate an address for performing the first task upload processing through the blockchain. The first network device generates the first task based on the first reference hash value, including: in the case that the first network device is configured to directly interact with the blockchain, the first network device determines the sender address of the first task as the address of the first network device; the first network device generates the first task based on the sender address of the first task and the first reference hash value; in the case that the first network device is configured to indirectly interact with the blockchain, the first network device sends the first reference hash value to the fourth network device, so that the fourth network device generates the first task based on the sender address of the first task and the first reference hash value, wherein the sender address of the first task is the address of the fourth network device.
[0059] It is understandable that the determination of the sender address of the first task and the generation process of the first task vary depending on the different ways in which the first network device is set to interact with the blockchain (directly or indirectly). When the first network device is set to interact directly with the blockchain, it is responsible for generating and uploading the first task to the blockchain. The first network device is the entity that directly interacts with the blockchain, and the first network device will use its own address as the sender address of the first task. The first network device performs the process of generating the first task based on the sender address of the first task (the address of the first network device) and the first reference hash value.
[0060] Similarly, when the first network device is set to interact indirectly with the blockchain, the first network device will send the first reference hash value to the fourth network device, which will be responsible for generating the first task and executing the upload task. The fourth network device is the entity that actually interacts with the blockchain, so the sender address of the first task will be set to the address of the fourth network device. The fourth network device will generate the first task based on the sender address of the first task (that is, the address of the fourth network device) and the first reference hash value. Through the above processing, the sender address and generation process of the first task are determined according to the interaction method between the first network device and the blockchain, which provides flexibility and scalability and helps to ensure the processing efficiency of the network system.
[0061] In an optional embodiment, the first task is determined based on a message detection request and a first reference hash value, wherein the message detection request is used to carry message detection information.
[0062] It is understood that the message inspection request is used to carry message inspection information during the first task generation process, and is used to instruct the execution of message inspection processing. Message inspection is an important means of ensuring the integrity and security of data packets in network communications. It verifies whether the data packet has been tampered with or forged by inspecting each part of the data packet.
[0063] Optionally, the first task is generated by combining the sender address and receiver address of the first task, as well as the message detection request and the first reference hash value. In the first task, the first reference hash value is used to identify the uniqueness of the task, or as part of the task verification, to ensure that the task (or message) has not been tampered with during transmission. It should be noted that according to the interaction mode (direct interaction or indirect interaction) of the first network device to the blockchain, there will be differences in the execution subject of the first task. The execution subject of direct interaction is the first network device, and the execution subject of indirect interaction is the fourth network device. Once the execution subject generates the first task, it will generate and upload the first task to the blockchain. Since the first task contains the sender address, the receiver address and the message detection request, as well as the first reference hash value for verifying the authenticity of the task, it can ensure the accurate execution of the first task in the blockchain network and the reliable delivery of the first message in the predetermined forwarding path.
[0064] Optionally, the message detection request may come from a user, other system components, or an external trigger event.
[0065] In an optional embodiment, the message detection request includes a transmission quality feedback request for the first message, the transmission quality feedback request is used to request the third network device to generate a performance feedback task, the performance feedback task is used to feedback the transmission quality corresponding to the first message, and the content of the transmission quality feedback request includes delay data, jitter data, packet loss rate data, number of outgoing / incoming messages, and at least any one of outgoing / incoming timestamps.
[0066] It can be understood that the message detection request not only provides message detection instructions, but also includes a feedback request for the transmission quality of the first message. The above-mentioned transmission quality feedback request allows the third network device to generate a performance feedback task after detecting the first message, thereby feeding back the transmission quality of the message to the requesting party. The content of the transmission quality feedback request can include multiple data fields, such as delay data, jitter data, packet loss rate data, number of outgoing / incoming messages, and outgoing / incoming timestamps, etc., which together constitute a comprehensive evaluation of the transmission quality of the first message. The above-mentioned delay data, jitter data, packet loss rate data, number of outgoing / incoming messages, and outgoing / incoming timestamps can be regarded as a kind of fine-grained indicator. Delay data, jitter data, and packet loss rate data are used to evaluate network transmission quality, which is of great significance for optimizing network performance. The number of outgoing / incoming messages and the outgoing / incoming timestamps reflect the transmission process of the first message. By recording the number of ingoing and outgoing messages and the timestamps of the first message, it is helpful to understand the transmission process of the message and provide more refined data support for network management and optimization.
[0067] Through the above processing, the transparency of network transmission quality is improved, and the transmission quality data of the first message can be obtained, so as to have a clearer understanding of the actual performance of the network, and facilitate accurate evaluation of network resource utilization based on transmission quality feedback data, thereby making more reasonable resource allocation decisions and improving network resource utilization.
[0068] Optionally, the content of the transmission quality feedback request also includes at least: a detection completion flag, a requirement satisfaction flag. The above-mentioned detection completion flag and requirement satisfaction flag are used as a coarse-grained indicator. The detection completion flag is used to indicate the detection completion status of the first message, and the requirement satisfaction flag is used to indicate whether the transmission performance of the first message meets the predetermined transmission requirements. The predetermined transmission requirements are carried by at least any one of the message detection request, the performance detection field, and the destination option extension header included in the first segment routing header.
[0069] In an optional embodiment, the message detection request includes at least any one of a message security detection flag, a message performance detection flag, a first message quantity, and a first flow identifier, wherein the message security detection flag is used to indicate whether the first reference hash value is in a valid state or an invalid state, and the message performance detection flag is used to indicate whether to perform performance detection on the first message.
[0070] It can be understood that the message detection request includes at least one of a message security detection flag, a message performance detection flag, a first message quantity, and a first flow identifier. The message security detection flag is used to indicate whether a security detection is required for the first message. The message performance detection flag is used to indicate whether a performance detection is required for the first message. By setting the message security detection flag and the message performance detection flag in different ways (valid or invalid), it is possible to flexibly select whether to perform security detection and performance detection on the first message, thereby adjusting the network optimization strategy according to actual needs. The first message quantity field is used to notify the third network device and the second network device of the message quantity of the first message sent by the first network device, so as to facilitate subsequent performance detection to perceive whether packet loss occurs. The first flow identifier is used to mark a business flow. A business flow can be composed of multiple messages, and multiple messages have the same destination, transmission protocol or service quality requirements. By marking the message flow that requires special processing, the network can provide more efficient processing, thereby meeting the needs of different services and improving the overall performance and reliability of the network.
[0071] In an optional embodiment, the packet performance detection flag includes at least any one of a packet loss detection enable, a time delay detection enable, and a performance tracking enable. The packet loss detection enable is used to indicate whether a packet loss detection bit included in the packet performance detection flag is valid. The time delay detection enable is used to indicate whether a time delay detection bit included in the packet performance detection flag is valid. The performance tracking enable is used to indicate whether a performance tracking flag is valid.
[0072] It can be understood that the packet performance detection flag is used to flexibly and configurable detect the packet transmission performance. The packet performance detection flag allows to selectively enable or disable a specific performance detection function, i.e. control enable, according to the needs, so as to achieve fine control of the packet transmission performance. The packet performance detection flag includes at least any one of a packet loss detection enable, a time delay detection enable, and a performance tracking enable. The packet loss detection enable is used to control whether to perform packet loss detection on the packet. If in the enable state, the transmission network device on the predetermined forwarding path will detect and record the packet loss when the first packet is transmitted in the network. The time delay detection enable is used to control whether to perform time delay detection on the packet. If in the enable state, the transmission network device will perform time delay detection based on the timestamp of the packet. The performance tracking enable is used to control whether to perform performance tracking on the transmission process of the packet.
[0073] By configuring the enable state, the specific performance detection function can be flexibly turned on or off according to the actual needs, so as to achieve targeted control of the transmission performance of the specific packet, improve the flexibility and efficiency of network communication, and help to quickly locate and solve network performance problems.
[0074] Optionally, the packet detection request can include a detection mode, a detection period, etc. The detection period is used to indicate the period of packet statistics performed by the second network device. The detection mode is a hop-by-hop detection mode or an end-to-end detection mode. The packet detection request allows the user to customize the detection request, including selecting the detection mode (hop-by-hop detection mode or end-to-end detection mode), setting the detection period, and enabling or disabling specific detection functions such as packet loss detection, time delay detection, and performance tracking. Through periodic or on-demand packet statistics and detection, more comprehensive network performance data can be obtained, which provides strong support for network optimization and troubleshooting.
[0075] In hop-by-hop detection mode, each transmission network device (such as a router or switch) on the message transmission path will detect the message data packets and report their status (such as packet loss, latency, etc.), which helps to determine the specific location of the problem. In end-to-end detection mode, detection can be performed at the starting and ending points of message transmission, reporting the transmission performance of the entire predetermined forwarding path. The detection period specifies the period at which the second network device performs message statistics, such as every second, every minute, or every hour. The detection period can be flexibly set according to the network environment and needs.
[0076] In an optional embodiment, the performance detection field includes at least any one of the following: a delay detection field, a packet loss detection field, and a performance tracking indication field, wherein the delay detection field is used to characterize the message transmission delay, the packet loss detection field is used to characterize the message transmission packet loss rate, and the performance tracking indication field is used to indicate the type of data that needs to be collected for message performance detection.
[0077] It is understood that the performance monitoring field includes at least one of the following: the delay detection field, the packet loss detection field, and the performance tracking indication field. This comprehensively evaluates the transmission performance of packets in the network and facilitates obtaining key information such as packet transmission delay, packet loss rate, and the data type required for performance tracking. The introduction of the delay detection field, the packet loss detection field, and the performance tracking indication field provides guidance for packet performance monitoring, helping to improve the efficiency of associated performance monitoring.
[0078] Optionally, the above-mentioned message transmission delay can be of multiple types, such as: link delay, and / or processing delay. Link delay is the transmission delay from one network device to the next network device, and processing delay is the time required for a message to be processed or forwarded in a network device.
[0079] Optionally, the performance tracking indication fields can be multiple, and the data collection scope of the performance detection can be customized as needed to more accurately analyze network performance issues. For example, data types such as bandwidth utilization, queue depth, and traffic distribution can be collected.
[0080] In an optional embodiment, the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: when the first network device includes a performance tracking indication field in the performance detection field, the first network device generates the first reference hash value based on the indication information corresponding to the second network device and the performance tracking indication field; when the first network device includes a delay detection field in the performance detection field, the first network device generates multiple first reference hash values based on the alternating mark state of the delay detection field and the indication information corresponding to the second network device; or when the first network device includes a packet loss detection field in the performance detection field, the first network device generates multiple first reference hash values based on the alternating mark state of the packet loss detection field and the indication information corresponding to the second network device.
[0081] It can be understood that when the first network device generates the first reference hash value related to the second network device, it will adopt different strategies according to different fields in the performance detection field. The hash value is a kind of summary information, which is usually used to quickly determine whether the data is equal, or for purposes such as data verification. In the message transmission scenario, the first reference hash value is used to identify or verify the security of the message data packet received by the second network device. When the performance detection field contains a performance tracking indication field, for example, the performance tracking indication field is an IOAM (In-situ Operations, Administration, and Maintenance) tracking type, which is a non-alternatingly marked field, a first reference hash value can be generated accordingly.
[0082] If the performance detection field includes a delay detection field, and the delay detection field has an alternating flag state (e.g., set to 0 or 1), the first network device generates multiple first reference hash values based on the alternating flag state of the delay detection field and the corresponding indication information of the second network device. In this way, the matching of the first reference hash values is not affected by the alternating flag states of different delay detection fields.
[0083] Similarly, if the performance detection field includes a packet loss detection field, and the packet loss detection field also has an alternating flag state, the first network device will generate multiple first reference hash values based on the alternating flag state of the packet loss detection field and the corresponding indication information of the second network device. In this way, the matching of the first reference hash values is not affected by the alternating flag states of different packet loss detection fields.
[0084] In an optional embodiment, when the first network device includes a delay detection field, a packet loss detection field, and also includes a performance tracking indication field in the performance detection field, the first network device generates multiple first reference hash values based on the alternating marking state of the delay detection field, the alternating marking state of the packet loss detection field, the indication information corresponding to the second network device, and the performance tracking indication field.
[0085] It can be understood that if the performance detection field includes both the delay detection field and the packet loss detection field, these two fields have alternating marking states. The alternating marking states corresponding to the delay detection field and the packet loss detection field can be arranged and combined, and combined with the performance tracking indication field and the indication information corresponding to the second network device to generate multiple first reference hash values.
[0086] It should be noted that the above-mentioned alternating marking state can change the field assignment of the delay detection field and the packet loss detection field. The first network device, as the starting network device that initiates the first message, generates multiple first reference hash values for all possible assignments in order to provide data support and reference standards for the transmission network devices on the predetermined forwarding path.
[0087] A field assignment can be a single value, such as setting the alternating flag state of the packet loss detection field assignment to 0 or 1. A field assignment can also be a combination of multiple values, each representing a performance check processing flag. The combination of multiple values collectively determines the combined processing methods for multiple performance checks.
[0088] Once the field assignment of the performance detection field is determined, the first network device can generate a first reference hash value based on the field assignment. The field assignment (whether it is a single value or a combination of multiple values) is converted into a fixed-length hash value, i.e., the first reference hash value. If the field assignment is a combination of multiple values, then each combination will generate a unique corresponding hash value, meaning that the number of combinations of the field assignment matches the number of generated first reference hash values. The number of combinations is determined based on the number of single values or combinations of multiple values in the field assignment, and different combinations of values will generate different hash values. Since the hash value is generated based on the field assignment of the specific performance detection field, it can accurately indicate that the second network device needs to perform performance detection on the packet, which is conducive to accurately sensing the actual performance of the corresponding network device, thereby making more reasonable network configuration. Moreover, since the generation of the hash value is directly related to the field assignment of the performance detection field, different field assignments represent different alternating mark states, and different hash values generated can be used for different performance evaluation scenarios. As long as the field assignment of the performance detection field is configured into the first reference field, the corresponding hash value can be generated to enable the second network device on the predetermined forwarding path to perform performance evaluation. The above-mentioned method of generating the first reference hash value based on the alternating mark state is conducive to improving scalability and flexibility.
[0089] It should be noted that the performance tracking indication field in the performance detection field is not an alternating mark state, i.e., the field assignment is a single value, and then only one first reference hash value will be generated.
[0090] Optionally, Figure 7 is a first format diagram of an optional packet detection method according to an embodiment of the present application, according to Figure 7As shown, the Performance Testing Field (PTF) is added to the Segment Identifier (SID) 1 corresponding to the second network device in the first Segment Routing Header (SRH-1). The Segment Identifier can include the Locator, Function, and Arguments. In SRv6, the Locator, Function, and Arguments are the three components that make up the Segment Identifier (SID). The Locator is an identifier assigned to a network node (network device) in the network. It is a segment of an IPv6 prefix used for routing and forwarding packets. The Function is an ID value assigned by the device to local forwarding instructions, which expresses the forwarding action to be performed by the device. In SRv6 network programming, different forwarding behaviors are represented by different Function IDs, which instruct the network device what action to perform upon receiving a packet. Arguments are used to convey additional information or parameters to the destination node. Arguments allow specific instructions or data to be embedded in the SID, enabling more complex operations or decisions during packet forwarding. The parameters (Arguments) include an optional field, a delay detection field (denoted as D) and a packet loss detection field (denoted as L).
[0091] Optionally, Figure 8 is a schematic diagram of a second format of an optional message detection method provided according to an embodiment of the present invention, according to Figure 8 As shown, the performance detection field PTF may also include: a flow instruction identifier denoted as FII, a flow instruction header denoted as FIH, and a flow instruction extended header denoted as FIEH. The flow instruction identifier FII is used to determine the starting position and length of the performance detection field, and the flow instruction header FIH includes a delay detection field denoted as D and a packet loss detection field denoted as L. The flow instruction header FIH is used to identify the service flow and carries the alternating marking state, which can be used to distinguish different data flows and set specific marking states for these data flows, such as alternating marking rules. The flow instruction extended header FIEH is used to define extended functions to support more complex performance detection requirements or specific network operations.
[0092] Optionally, Figure 9 is a schematic diagram of a third format of an optional message detection method provided according to an embodiment of the present invention, according to Figure 9As shown, the performance detection field is recorded as PTF, and the adding position can be located in the segment identifier SID1 corresponding to the second network device of the first segment routing header SRH-1. The parameter field of the segment identifier includes a performance tracking indication field, such as an IOAM tracking type. The IOAM tracking type is used to describe the collected data. Each bit in the IOAM tracking type represents a type of data that needs to be collected. When a network device (such as a router or switch) encounters a message with a performance detection field, it will collect corresponding performance data according to the data type defined in the IOAM tracking type for network performance analysis, troubleshooting, etc. The performance tracking indication field (IOAM tracking type) can be expanded as needed to support more data types and more complex performance monitoring requirements.
[0093] Optionally, Figure 10 is a schematic diagram of a fourth format of an optional message detection method provided according to an embodiment of the present invention, according to Figure 10 As shown, the performance monitoring field, denoted as PTF, may also include, for example, a namespace, a tag, and an IOAM trace type (performance trace indication field). The namespace is used to distinguish IOAM data collection types defined by different vendors. The IOAM trace type is used to describe the collected data, with each bit representing a type of data to be collected.
[0094] Optionally, Figure 11 is a fifth format diagram of an optional message detection method provided according to an embodiment of the present invention, according to Figure 11 As shown, the performance detection field PTF includes, for example, an IOAM tracking type, a delay detection field D and a packet loss detection field L.
[0095] Optionally, the packet loss detection field L can be used to perform packet loss detection based on an alternating marking state, and the delay detection field D can be used to perform delay detection based on an alternating marking state. In network communications, alternating marking technology can be used for purposes such as message marking, packet loss detection, and delay detection. By alternating the field values of a field in a message (such as the packet loss detection field L and the delay detection field D), network devices can count the number of lost or delayed messages and analyze network performance. For example, the performance detection field sets the packet loss detection field L and the delay detection field D to 0 or 1, respectively, to implement message marking.
[0096] If there are a second network device and a fifth network device on the predetermined forwarding path, the two devices respectively count the values of 0 or 1 in the packet loss detection field L and the delay detection field D in the received message, generating a first detection result for the second network device and a second detection result for the fifth detection device. Based on the first detection result and the second detection result, the third network device can analyze the packet loss rate and delay of the message. For example, within a predetermined detection period, the counter of the second network device counts the number of messages with the packet loss detection field L set to 1 as a first number and reports it to the third network device. The counter of the fifth network device counts the number of messages with the packet loss detection field L set to 1 as a second number and reports it to the third network device. The third network device determines the packet loss rate of the path from the second network device to the fifth network device based on the first detection result reported by the second network device and the second detection result reported by the fifth network device.
[0097] When the first network device initiates delay detection and packet loss detection, assuming that there are multiple domains in the predetermined forwarding path, the performance detection field PTF includes a packet loss detection field L and a delay detection field D. There are four combinations of field values for the packet loss detection field L and the delay detection field D, namely (L=1, D=1), (L=1, D=0), (L=0, D=1), and (L=0, D=0). The corresponding performance detection fields PTF are recorded as PTF(11), PTF(10), PTF(01), and PTF(00). If there are other fields that also have multiple values, such as multiple heterogeneous segment routing headers, the corresponding performance detection fields PTF may be more than four.
[0098] According to the four situations in which the performance detection field PTF exists, the first network device uses a predetermined hash algorithm to obtain four first reference hash values corresponding to the second network device, which are recorded as H2 (H2-1; H2-2; H2-3; H2-4). Similarly, for the fifth network device, four second reference hash values corresponding to the fifth network device can also be obtained (the above first and second reference hash values are only for reference purposes), which are recorded as H5 (H5-1; H5-2; H5-3; H5-4). In the case where there are multiple reference hash values, they can be recorded in a list format.
[0099] It should be noted that the first network device, as the starting sender of the first message, will pre-configure the performance detection field in the message, and the transmission network device (including the second network device) in the predetermined transmission path can only perform statistical processing on the message, without changing or setting the field value in the performance detection field, thereby saving the processing time of the transmission network device on the predetermined transmission path and improving transmission efficiency. The first network device will be set according to the possible alternating mark state (field assignment) of the performance detection field. In the case where there are multiple value combinations of the field assignment, the corresponding generated first reference hash value will also be multiple.
[0100] Alternatively, if the Figure 9 and Figure 10 The performance detection field PTF shown has only one type of performance detection field. If the performance detection field PTF only includes the performance tracking indication field (non-alternating flag state), the first network device uses a predetermined hash algorithm to obtain a first reference hash value H2 corresponding to the second network device based on the indication information corresponding to the second network device and the performance detection field PTF. Similarly, the first network device also performs a hash calculation on the indication information corresponding to the fifth network device and the performance detection field PTF, and also obtains only a second reference hash value H5 corresponding to the fifth network device.
[0101] In an optional embodiment, the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: the first network device determines the first reference protocol header corresponding to the second network device, wherein the first reference protocol header is generated by the first network device based on the first protocol header and the detection segment pointer pointing to the segment identifier corresponding to the second network device, the first protocol header includes a source address and a destination address, the source address of the first protocol header is the address of the first network device, the destination address of the first protocol header is the address corresponding to the first segment identifier in the segment list pointed to by the detection segment pointer of the first segment routing header, the first segment routing header includes a segment list, the segment list includes a group of ordered segment identifiers, and the segment list includes the segment identifier corresponding to the transmitting network device; the first network device generates the first reference hash value based on the first reference protocol header, at least any one of the target data, and the indication information corresponding to the second network device indicated by the first segment routing header, and the performance detection field.
[0102] It can be understood that the first network device determines the first reference protocol header corresponding to the second network device. The first reference protocol header is dynamically generated by the first network device based on the existing first protocol header and a specific detection segment pointer (pointing to the segment identifier corresponding to the second network device). The detection segment pointer can also be called a segment remainder or a segment pointer. The above-mentioned first protocol header is associated with the second network device, and contains a source address, that is, the address of the first network device, and a destination address, that is, determined according to the first segment identifier in the segment list pointed to by the detection segment pointer. If the second network device is the first network device after the first network device, then the detection segment pointer points to the segment identifier corresponding to the second network device. The segment list in the first segment routing header contains a set of ordered segment identifiers used to identify the transmission path of the data packet in the network. The first network device generates a first reference hash value based on the first reference protocol header, target data, and performance detection field. Through the above processing, by dynamically generating the first reference protocol header, it can be ensured that the generation of the first reference hash value is based on specific information directly related to the second network device, thereby improving the pertinence and accuracy of the first reference hash value, providing a verification mechanism for data transmission, improving the flexibility and scalability of the network system, and also improving the efficiency of the second network device in performing message security detection.
[0103] Optionally, the first protocol header may be an IPv6 basic header. Figure 12 Schematic diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 12 As shown, the Version, Traffic Class, Flow Label, Payload Length, Next Header, Hop Limit, Source Address, and Destination Address are shown. The Version indicates the version of the IP protocol, the Traffic Class indicates the class or priority of the IPv6 datagram, and the Flow Label distinguishes real-time traffic. Different flow labels combined with the source address can uniquely identify a data flow. The Payload Length indicates the total length of the target data following the IPv6 header, the Next Header indicates the type of extended header immediately following the IPv6 basic header, and the Hop Limit indicates the maximum number of transmission network devices that a data packet can pass through during forwarding.
[0104] The first segment routing header is denoted as SRH-1, and the first segment routing header includes a segment list. In the case where the predetermined forwarding path includes the second network device and the fifth network device, the segment identifier corresponding to the second network device is SID1, and the segment identifier corresponding to the fifth network device is SID0. Therefore, the segment list is denoted as (SID1, SID0), and the detection segment pointer (which can also be referred to as a segment remaining) is denoted as SL. In the case where the second network device is pointed to, SL = 1, and in the case where the fifth network device is pointed to, SL = 0. The segment list (SID1, SID0) is a kind of instruction execution in a simple sequence.
[0105] In step S106, the first network device generates a first message based on the target data, the first segment routing header, and the performance detection field.
[0106] It can be understood that the first network device generates the first message based on the target data, that is, the necessary transmission information, and the first segment routing header and the performance detection field, which provide information support for subsequent transmission and detection processes. The generation and sending of the first message ensure that the target data is transmitted according to the predetermined path.
[0107] In an optional embodiment, the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: the first network device determines a plurality of domains included in the predetermined network system, wherein the plurality of domains respectively include at least one transmission network device; the first network device respectively generates a corresponding performance detection field for the plurality of domains; and the first network device generates the first reference hash value based on the indication information corresponding to the second network device and the performance detection field respectively generated for the plurality of domains.
[0108] It can be understood that the processing of the performance detection field of the plurality of domains in the entire predetermined network system is introduced. The network system can be divided into different domains, and each domain can include one or more transmission network devices. The above different domains can have different routing strategies, security settings, or management permissions. When the predetermined forwarding path involves multiple domains, it is considered that the target data needs to be transmitted between multiple domains. The first network device generates the first reference field for the second network device based on the indication information corresponding to the second network device and the performance detection field. For each domain, the first network device generates a corresponding performance detection field. The performance detection fields corresponding to different domains can be the same or different. For example, there are 3 domains in the predetermined forwarding path, and each domain corresponds to a performance detection field for indicating the detection method in the domain; or 3 domains can use the same performance detection field.
[0109] In an optional embodiment, the indication information includes a segment identifier, and the performance detection field is carried in at least any one of the following locations, including: a segment identifier corresponding to the transmission network device included in the first segment routing header, an optional type length value TLV (Type Length Value) field, a label field, a tag field, and a first segment identifier, a hop-by-hop option extension header, and a destination option extension header, wherein the first segment identifier is the first segment identifier in the segment list included in the first segment routing header, and the segment list includes a group of ordered segment identifiers corresponding to the transmission network devices.
[0110] It can be understood that the first network device first needs to determine the location where the performance detection field is added. The location where the performance detection field is added can be one of multiple options, including but not limited to the segment identifier corresponding to the transmission network device in the first segment routing header, the optional type length value TLV field, the label field, the tag field, the first segment identifier (the first segment identifier in the segment list), and the hop-by-hop option extension header or the destination option extension header. The choice of the location where the performance detection field is added depends on the specific network environment and requirements. For example, the performance detection field can be added to each segment identifier, and the performance detection field can also be added to the corresponding extension header. Once the location where the performance detection field is added is determined, the first network device will add the performance detection field to the first message according to the location where the performance detection field is added, so as to measure the performance parameters of the first message during the transmission process. By selecting different locations where the performance detection field is added, the first network device can flexibly configure the performance detection field according to actual needs, so that network management is more in line with actual application scenarios and the efficiency of network management is improved.
[0111] Alternatively, Figure 12 As shown, the first segment routing header includes the next header (Next Header), the extended header length (Hdr Ext Len), the routing header type (Routing Type), the segments left (Segments Left), the last entry (Last Entry), the flag (Flags), the tag (Tag), the segment list (Segment List), where n represents the sequence number of the segment identifier, the optional TLV (i.e., the optional type length value TLV field), and the payload (Payload); wherein the segment left is the segment pointer, abbreviated as SL, and the pointer value of the segment left parameter is updated according to the transmission process to obtain the detection segment pointer SL = 0, 1, and so on.
[0112] Optionally, Figure 13 FIG. 1 is a schematic diagram of an extended header of an optional message detection method provided according to an embodiment of the present invention, such as Figure 13As shown, the next header in the IPv6 basic header (IPv6 Header) can indicate different extended headers, including: Hop-by-Hop Options Header, Destination Options Header, Routing Header, Fragment Header, and Other Headers. The Hop-by-Hop Options Header is used to carry optional information that is inspected and processed along the packet's transmission path. The Destination Options Header is used to contain information related to the destination address, such as QoS (Quality of Service) information, security-related parameters, or additional information for specific applications. The Routing Header is used to transmit routing information between routers, such as designated paths and source routes. The Fragment Header is used to handle the reassembly of fragmented data packets and contains fragment information and a reassembly flag. Other Headers represent other extended headers that may exist in IPv6. IPv6 provides a wealth of features and customization options for network communications. Other extended headers allow the network to be configured according to actual needs to meet the performance, security, and routing requirements in different scenarios.
[0113] Among them, the next header can indicate the next header or protocol type after the first segment routing header (SRH-1), the extended header length is determined based on the specific implementation of the first segment routing header (SRH-1) and the number of fields contained therein, and the segment remainder indicates the number of segments that the data packet needs to pass through before reaching the destination. The segment remainder value is reduced by 1 for each network device passed through. The last entry refers to the last entry in the segment list, the tag is used to indicate certain characteristics or behaviors of the first segment routing header (SRH-1), the label is a label or identifier associated with the segment routing policy, the optional TLV is used to add optional, variable-length fields in the protocol header, and the payload can be target data.
[0114] In step S108, the first network device sends a first packet, wherein the first packet is used for transmission on a predetermined forwarding path, the predetermined forwarding path includes a transmission network device, the second network device is used for receiving the first to-be-detected packet on the predetermined forwarding path, the first to-be-detected packet is used for the second network device to generate a first to-be-detected hash value, the second network device is used for matching based on the first to-be-detected hash value and the first reference hash value to obtain a matching result, in a case where the matching result indicates that the first to-be-detected hash value and the first reference hash value match, the second network device is used for detecting the first to-be-detected packet according to the first detection task sent by the third network device to determine a first detection result, the second network device is used for sending the first detection result to the third network device, and the third network device is used for generating a performance feedback task based on the first detection result and uploading the performance feedback task to a block chain.
[0115] It can be understood that the first network device sends the first packet to the predetermined forwarding path, and the predetermined forwarding path includes a plurality of transmission network devices, wherein the second network device is one of the network devices. It should be noted that the first network device and the second network device can be directly connected or indirectly connected, and there can be other network devices between the first network device and the second network device. After receiving the first packet, the second network device generates a first to-be-detected hash value and matches it with the first reference hash value received before. If the matching is successful, the packet is detected according to the first detection task sent by the third network device to generate a first detection result, and the result is sent back to the third network device. The third network device generates a performance feedback task based on the first detection result and uploads it to the block chain for storage and recording, providing reliable data support for subsequent network performance analysis and optimization. Through the matching of the hash value and the execution of the detection task, the security of the packet in the transmission process is ensured, the network measurement information along the way is avoided from being tampered with, the possibility of network attacks is reduced, and the security of the network measurement along the way is improved. The technical problem that the network measurement request along the way is easily tampered with in the related art, and the possibility of network attacks is increased is solved. Through the combination of the block chain, the hash value matching, and the packet detection, a safe and reliable environment is provided for packet data transmission and performance detection.
[0116] In an optional embodiment, the indication information includes a detection segment pointer, the first network device generates the first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, and the method includes the following steps: the first network device updates the first segment routing header based on the detection segment pointer of the second network device to obtain a first reference routing header corresponding to the second network device; and the first network device determines the first reference hash value based on the first reference routing header and the performance detection field.
[0117] It is understood that the indication information includes a detection segment pointer (also referred to as a segment pointer). The first network device determines the detection segment pointer of the second network device. The detection segment pointer points to the segment identifier (SID) included in the first segment routing header. The first network device updates the first segment routing header based on the detection segment pointer, generating a first reference routing header associated with the second network device. After obtaining the first reference routing header, a first reference hash value is generated by combining the performance detection field.
[0118] A performance detection method is provided for a segment routing mechanism in a network, wherein the indication information provided may include a detection segment pointer. The detection segment pointer is used to point to a segment identifier corresponding to a network device in a predetermined forwarding path, which changes as the message forwarding process changes and is used to generate a first reference hash value. The first segment routing header may provide indication information about the network devices included in the predetermined forwarding path. Based on the detection segment pointer corresponding to the second network device, the first network device updates the first segment routing header according to the detection segment pointer to obtain a first reference routing header. After obtaining the first reference routing header, the first reference hash value is generated by combining the performance detection field.
[0119] Through the above processing, combined with the first reference routing header and performance detection field corresponding to the second network device, a first reference hash value is generated to serve the subsequent security detection and performance detection process, ensuring that the message can obtain accurate performance evaluation when it is transmitted to the second network device. By introducing the detection segment pointer and performance detection field, it is possible to perform security detection and performance detection on a specific network device (the second network device) in the network. At the same time, because it is implemented based on a segmented routing mechanism, it is easy to integrate into the existing network architecture, which improves the flexibility of message detection. And because the first reference routing header is dynamically generated for the specific network device (i.e., the second network device) to be detected, it can adapt to different network environments and transmission requirements, providing a more flexible and efficient network performance detection solution.
[0120] Optionally, based on the inclusion of the second network device and the fifth network device in the predetermined forwarding path, the first network device generates a first reference segment routing header (RSRH-2) corresponding to the second network device based on the first segment routing header (SRH-1). The first reference segment routing header (RSRH-2) may include a segment list and a detection segment pointer. The detection segment pointer points to the segment identifier (SID1) corresponding to the second network device, i.e., the detection segment pointer (SL) = 1. Based on the first reference segment routing header (RSRH-2) and the performance detection field (PTF), a corresponding first reference hash value is generated.
[0121] The first network device generates a second reference segment routing header RSRH-5 corresponding to the fifth network device based on the first segment routing header SRH-1. The second reference segment routing header RSRH-5 includes a segment list and a detection segment pointer. The detection segment pointer points to the segment identifier SID0 corresponding to the fifth network device, that is, the detection segment pointer SL = 0. The first network device determines that the fifth network device includes the second reference segment routing header RSRH-5 and the performance detection field PTF, and generates a corresponding second reference hash value.
[0122] Through the above steps S102 to S108, the purpose of preventing the on-link network measurement information from being tampered with and reducing the possibility of triggering a network attack can be achieved, and the technical effect of improving the security of the on-link network measurement is achieved, thereby solving the technical problem in the related art that the on-link network measurement request is easily tampered with, thereby increasing the possibility of a network attack.
[0123] Figure 14 is a second flow chart of an optional message detection method provided according to an embodiment of the present invention, such as Figure 14 As shown, the method includes the following steps:
[0124] Step S1402: The second network device obtains a first detection task including a first reference hash value, wherein the second network device belongs to a transmission network device included in a predetermined forwarding path, the first detection task is generated by the third network device based on the first task, and is used to notify the second network device to perform message detection, the first task includes a first reference hash value, and is used to be transmitted to the blockchain, so that the third network device obtains the first task through interaction with the blockchain, the recipient address of the first task is the address of the third network device, the first reference hash value is generated by the first network device based on the indication information corresponding to the second network device indicated by the first segment routing header, and the performance detection field, the target data starts from the first network device and is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used for the transmission network device to perform message detection;
[0125] It is understood that the second network device, as a transmission network device in the predetermined forwarding path, will receive the first detection task from the third network device. The first detection task is generated based on the first task obtained by the third network device from the blockchain, and is intended to detect the message transmission performance of the transmission network device or the predetermined forwarding path. The first task includes a first reference hash value generated by the first network device based on the first reference field corresponding to the second network device. Since the first reference hash value is generated for the second network device, the first detection task is also generated for the second network device and can be used specifically on the second network device to provide data support for subsequent message detection.
[0126] In an optional embodiment, the second network device is configured to interact indirectly with the third network device, and the second network device interacts with the third network device through at least one second intermediate device.
[0127] I understand. Figure 15 is a sixth interactive schematic diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 15 As shown, the second network device is configured to indirectly interact with the third network device through at least one second intermediate device. In this interactive architecture, the second network device does not communicate directly with the third network device, but rather communicates through at least one second intermediate device (such as a router, switch, server, or other network device). This can increase network flexibility, scalability, or security because the second intermediate device can provide additional functions such as load balancing, traffic control, and security filtering.
[0128] In an optional embodiment, the second network device is configured to interact directly with the third network device, and the third network device interacts with the blockchain through a third proxy device.
[0129] I understand. Figure 16 is a seventh interactive diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 16 As shown, the third network device interacts with the blockchain through a third proxy device. The third proxy device is deployed between the third network device and the blockchain and is responsible for executing the interaction processing between the third network device and the blockchain. This allows the third network device to communicate with the blockchain in a unified and standardized manner without having to worry about the details and complexity of the underlying blockchain technology.
[0130] Optionally, a third agent device may perform tasks such as identity authentication, data format conversion, error handling, logging, etc. to ensure smooth interaction.
[0131] In an optional embodiment, the second network device interacts with the third network device through a fourth proxy device, and the third network device interacts with the blockchain through the fourth proxy device, wherein the fourth proxy device is used to perform interaction processing between the third network device and the blockchain, and to perform interaction processing between the second network device and the third network device.
[0132] I understand. Figure 17 8 is an eighth interactive diagram of an optional message detection method provided according to an embodiment of the present invention, such as Figure 17As shown, the second network device interacts with the third network device through the fourth proxy device, and the third network device interacts with the blockchain through the fourth proxy device. Under this interaction architecture, the fourth proxy device performs bidirectional proxy, not only responsible for performing interaction processing between the third network device and the blockchain, but also responsible for performing interaction processing between the second network device and the third network device, which can further simplify the network architecture, reduce the number of second intermediate devices, and reduce the complexity of management and maintenance, increase the flexibility and scalability of the network.
[0133] It should be noted that the selection of the above interaction mode depends on the specific application scenario, network architecture and security requirements. In actual deployment, the interaction mode between the third network device, the second network device and the blockchain can be selected according to the actual situation, and the corresponding second intermediate device or third and fourth proxy devices can be configured to ensure the smooth progress of the interaction.
[0134] Step S1404, the second network device receives a first to-be-detected packet, wherein the first to-be-detected packet is any one packet received by the second network device on the predetermined forwarding path;
[0135] It can be understood that in the normal network transmission process, the second network device will receive packets from the upstream or downstream devices on the predetermined forwarding path, and the first to-be-detected packet can be regarded as any one of these packets without detection.
[0136] Step S1406, the second network device generates a first to-be-detected hash value based on the first to-be-detected packet;
[0137] It can be understood that when the second network device receives the first to-be-detected packet, and generates the first to-be-detected hash value based on the first to-be-detected packet, the first to-be-detected hash value is used to match the first reference hash value to detect whether the first to-be-detected packet is an abnormal packet.
[0138] Optionally, the second network device can generate the first to-be-detected hash value based on the first to-be-detected field included in the first to-be-detected packet.
[0139] In an optional embodiment, the second network device generates the first to-be-detected hash value based on the first to-be-detected packet, including: the second network device determines the generation mode of the first reference hash value, wherein the generation mode is the mode in which the first network device generates the first reference hash value; and in the case where the hash algorithm adopted by the second network device is the same as that of the first network device, the second network device generates the first to-be-detected hash value based on the first to-be-detected field using the hash algorithm.
[0140] It can be understood that the second network device first needs to know how the first network device generates the first reference hash value, and uses the hash algorithm and specific hash generation rules used by the first network device for processing. If it is determined that the generation method is to use a predetermined hash algorithm, then the second network device will use the same hash algorithm to generate the first hash value to be detected. Using the above-determined hash algorithm, the second network device will calculate the hash value based on the first message to be detected. Follow the same rules and standards as the first network device to ensure that the generated hash value is comparable. Once the first hash value to be detected is generated, the second network device can compare it with the first reference hash value to verify the integrity or consistency of the data.
[0141] Optionally, if there is no first reference hash value available for comparison, the second network device may store the first hash value to be detected for subsequent matching and use.
[0142] Optionally, the second network device may obtain information about the hash algorithm used by the first network device through preconfigured information, communication with the first network device, or other means.
[0143] Optionally, the second network device generates a first hash value UH2 to be detected based on a first field to be detected of the first message to be detected, where the first field to be detected includes a first segment routing header USRH-2 to be detected and a performance detection field. The second network device matches the first hash value UH2 to be detected with a locally stored first reference hash value H2 (H2-1; H2-2; H2-3; H2-4), and determines that the received first message to be detected is the first message if UH2 matches one of the first reference hash values H2 (H2-1; H2-2; H2-3; H2-4).
[0144] Step S1408: The second network device performs matching based on the first hash value to be detected and the first reference hash value to obtain a matching result;
[0145] It can be understood that the second network device can compare the first hash value to be detected with the first reference hash value to obtain a matching result, thereby quickly determining whether the first message to be detected requires further performance testing.
[0146] In an optional embodiment, the first detection task includes multiple first reference hash values, and the second network device matches the first hash value to be detected and the first reference hash value to obtain a matching result, including: the second network device matches the first hash value to be detected with multiple first reference hash values respectively based on the first hash value to be detected to determine the matching result; the method also includes: when the matching result indicates that the first hash value to be detected matches any one of the multiple first reference hash values, according to the first detection task, the first message to be detected is detected to determine the first detection result.
[0147] It can be understood that the first detection task includes multiple first reference hash values, and the multiple first reference hash values can correspond to the field assignments corresponding to all possible alternating mark states, and are used to match the first hash value of the first message to be detected received by the second network device. When the second network device receives the first message to be detected, it will calculate a hash value based on the first field to be detected of the message (the first field to be detected includes the first segment routing header to be detected and the performance detection field), that is, the first hash value to be detected. The second network device will match the calculated first hash value to be detected with the multiple first reference hash values one by one. When the matching result indicates that the first hash value to be detected matches any one of the multiple first reference hash values, if the first hash value to be detected successfully matches any one of the first reference hash values, then it is considered that the first message to be detected is not an abnormal message, and performance detection processing can be performed. According to the first detection task, the first message to be detected is detected to determine the first detection result.
[0148] Step S1410: When the matching result indicates that the first hash value to be detected matches the first reference hash value, the second network device detects the first message to be detected according to the first detection task and determines a first detection result.
[0149] It can be understood that if the match is successful, that is, the first hash value to be detected is consistent with the first reference hash value, then the second network device will perform a performance test on the first message to be detected according to the detection method specified in the first detection task. The detection content can be in accordance with the message detection request indicated in the first detection task. The indicated detection content can include the message delay data, jitter data, packet loss rate data, number of outgoing / incoming messages, and at least any one of the outgoing / incoming timestamps. By performing a detailed performance test on the first message to be detected, the second network device can comprehensively evaluate the quality of network transmission and provide performance data support, which is of great significance for optimizing network configuration and improving network performance. It should be noted that even if the match is successful, the first message to be detected is not necessarily the first message, but can be a message indicating a transmission on a predetermined forwarding path, that is, a message after the first message has been forwarded and processed.
[0150] In an optional embodiment, the second network device, in a case where the matching result indicates that the first to-be-detected hash value matches the first reference hash value, performs detection on the first to-be-detected packet according to the first detection task to determine a first detection result, including: the second network device performs packet statistics according to the performance detection field of the first to-be-detected packet to obtain statistical information corresponding to the first to-be-detected packet, where the statistical information includes the number of the first to-be-detected packet, and / or the timestamp of the first to-be-detected packet, and the first to-be-detected hash value corresponding to the first to-be-detected packet, the timestamp of the first to-be-detected packet being generated when the second network device receives the first to-be-detected packet; and the second network device obtains the first detection result based on the statistical information corresponding to the first to-be-detected packet.
[0151] It can be understood that the second network device checks whether the first to-be-detected hash value matches the first reference hash value, and if the matching is successful, the subsequent packet detection task can be continued to be performed on the first to-be-detected packet, and the first to-be-detected packet is regarded as not being an abnormal packet. The second network device performs packet statistics according to the performance detection field of the first to-be-detected packet to obtain the first detection result corresponding to the first to-be-detected packet, and the second network device sends the first detection result to the third network device, which is used to calculate the packet performance and generate a performance feedback task to help evaluate the performance and efficiency of the entire network system.
[0152] Optionally, the second network device performs forwarding or unpacking processing on the first to-be-detected packet according to the packet processing strategy corresponding to the first to-be-detected packet, as a normal transmission operation, and the performance detection processing is only for evaluating the performance in the transmission process. The packet processing strategy can include forwarding, unpacking, or a predetermined abnormal packet processing mode. For the packet that needs to be forwarded or unpacked, it means that the packet is a matching successful packet and is associated with the first task, and needs to be subjected to performance detection. For the predetermined abnormal packet processing mode, it can include packet discarding processing, which means that the packet is not associated with the first task and can be a tampered packet that does not need to be subjected to performance detection.
[0153] If the second network device is the last network device on the predetermined forwarding path, the unpacking processing of the first to-be-detected packet is performed, and if the second network device is not the last network device on the predetermined forwarding path, the forwarding processing of the first to-be-detected packet is performed. In this way, the entire network system can be adjusted and optimized according to the actual running situation, thereby improving the performance and efficiency.
[0154] In an optional embodiment, the method further includes: in a case where the matching result indicates that the first to-be-detected hash value does not match the first reference hash value, the second network device processes the first to-be-detected packet by using a predetermined abnormal packet processing mode.
[0155] It is understood that the second network device will compare the hash value calculated for the first message to be detected (i.e., the first hash value to be detected) with the first reference hash value. If the two hash values do not match, it means that the first message to be detected may have been tampered with, damaged, or otherwise abnormal during transmission, or it may be another unknown message. The unknown other message can be understood as a message that has not been confirmed by the blockchain. When the hash values do not match, the second network device will trigger a predetermined abnormal message processing process, which may include a series of preset response measures for handling different types of abnormal messages.
[0156] Optionally, there are multiple ways to handle predetermined abnormal messages, such as recording detailed information of the first message to be detected, hash value comparison results, and processing time, etc., for subsequent analysis and auditing. Or the first message to be detected can be directly discarded to avoid delivering potentially unsafe or invalid messages to the target device. Or an alarm can be sent to the security system to notify that a hash value mismatch has occurred so that further measures can be taken in a timely manner. The first message to be detected can also be forwarded to an isolation area for more in-depth analysis and processing to determine whether it is an abnormal message. If the message is discarded, no subsequent processing will be performed. If the message is forwarded to an isolation area, further analysis and detection can be performed in that area and processed according to specific application scenarios and needs.
[0157] In an optional embodiment, the statistical information further includes at least any one of the following: the number of first messages to be detected, and the timestamp of the first message to be detected, wherein the timestamp of the first message to be detected is generated when the second network device receives the first message to be detected.
[0158] It can be understood that when the second network device indicates in the matching result that the first hash value to be detected matches the first reference hash value, in addition to recording the first hash value to be detected as statistical information, the statistical information will also include, but not limited to at least any one of the following: the number of first messages to be detected, the timestamp of the first message to be detected. The second network device will record the number of first messages to be detected that are successfully matched during the processing process. The number of first messages to be detected can help evaluate the network traffic, load and possible abnormal activities, such as whether the first message to be detected has packet loss. The timestamp records when the first message to be detected is received by a certain network device (such as the second network device). The timestamp plays a data support role in network performance analysis and troubleshooting. It can calculate the transmission delay or the delay of message processing in the network device. When the timestamp is generated by the second network device when receiving the first message to be detected, it can accurately reflect the arrival time of the message, providing a reliable time basis for subsequent statistics and analysis of message delay and other performance.
[0159] Step S1412, the second network device sends the first detection result to the third network device, so that the third network device generates a performance feedback task based on the first detection result, wherein the third network device uploads the performance feedback task to the block chain.
[0160] It can be understood that by performing performance detection on the first to-be-detected packet, the second network device will generate a first detection result corresponding to itself and send it to the third network device. After receiving the first detection result, the third network device will further process the information and can upload it to the block chain for storage or sharing. The distributed storage feature of the block chain also makes the data more secure and easy to access.
[0161] Through the above steps S1402 to S1412, the purpose of avoiding tampering of on-path network measurement information and reducing the possibility of network attack can be achieved, and the technical effect of improving the security of on-path network measurement is achieved, thereby solving the technical problem that the on-path network measurement request is easy to be tampered in the related art, and the possibility of network attack is increased.
[0162] Figure 18 According to an embodiment of the present application, an optional packet detection method is provided, as shown in Figure 18 The method comprises the following steps:
[0163] Step S1802, the first network device determines the target data to be transmitted, the first segment routing header, and the performance detection field, wherein the target data is sequentially transmitted according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used for packet detection by the transmission network device;
[0164] Step S1804, the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device belongs to the transmission network device, and the first reference hash value is used to generate a first task with the address of the third network device as the receiver address, and the first task includes the first reference hash value and is used for transmission to the block chain;
[0165] Step S1806, the third network device acquires the first task through interaction with the block chain;
[0166] Step S1808, the third network device generates a first detection task including the first reference hash value based on the first task;
[0167] Step S1810, the third network device sends the first detection task to the second network device and notifies the second network device to perform packet detection;
[0168] Step S1812, the first network device generates a first message based on the target data, the first segment routing header, and the performance detection field;
[0169] Step S1814, the first network device sends the first message, wherein the first message is used for transmission on the predetermined forwarding path, and the predetermined forwarding path includes the transmission network device;
[0170] Step S1816, the second network device receives the first to-be-detected message on the predetermined forwarding path, wherein the first to-be-detected message is used for the second network device to generate a first to-be-detected hash value;
[0171] Step S1818, the second network device matches the first to-be-detected hash value and the first reference hash value based on the first to-be-detected hash value and the first reference hash value to obtain a matching result;
[0172] Step S1820, in a case where the matching result indicates that the first to-be-detected hash value and the first reference hash value match, the second network device is configured to detect the first to-be-detected message according to the first detection task sent by the third network device to determine a first detection result;
[0173] Step S1822, the second network device sends the first detection result to the third network device;
[0174] Step S1824, the third network device generates a performance feedback task based on the first detection result;
[0175] Step S1826, the third network device uploads the performance feedback task to a block chain.
[0176] It can be understood that when the first network device needs to transmit target data, the first segment routing header and the performance detection field will be determined based on the target data. The first segment routing header provides indication information of each transmission network device (such as the second network device) included in the predetermined forwarding path, ensuring that the data can be transmitted in the network according to the predetermined order and path. The performance detection field is to support message detection and help evaluate the performance in the transmission process. Based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, the first network device will generate a first reference hash value related to the second network device, which is used to create a first task, and the target recipient of the first task is the third network device, which is responsible for collecting and feeding back the message transmission performance of the entire transmission network device. The third network device obtains the first task by interacting with the blockchain, and generates a corresponding first detection task based on the first reference hash value included in the first task. The third network device will send the first detection task to the second network device to inform it to perform the corresponding message detection. The first network device will generate the first message based on the target data, the first segment routing header and the performance detection field, and send it out through the predetermined forwarding path after the first detection task is issued. The first message will be transmitted according to the predetermined forwarding path, ensuring that the data can accurately reach the destination.
[0177] When the second network device receives the first to-be-detected message, the second network device will check the first to-be-detected message and generate a first to-be-detected hash value based on the first to-be-detected message, which is used for the second network device to match the first to-be-detected hash value with the first reference hash value received through the first detection task before. If the matching is successful, it means that the first to-be-detected message is a message related to the first task (not necessarily the first message, it may be a message obtained based on the forwarding process of the first message), and the second network device will perform performance detection on the first to-be-detected message according to the first detection task received before. After the performance detection is completed, the second network device will send the first detection result to the third network device. The third network device will generate a performance feedback task based on the received first detection result. The performance feedback task contains performance information of the transmission network device in the message transmission process. In order to ensure the reliability and traceability of the performance feedback task, the third network device will upload the performance feedback task to the blockchain for other related parties to query and reference (such as the first network device or the fourth network device).
[0178] In an optional embodiment, the third network device generates a first detection task including a first reference hash value based on the first task, including: the third network device determines a message detection request based on the first task; the third network device generates a first detection indication based on the message detection request, wherein the first detection indication is used to notify the second network device to perform message detection processing; the third network device generates the first detection task according to the first detection indication and the first reference hash value included in the first task.
[0179] It will be understood that when the third network device receives or identifies the first task, it can obtain the message detection request included in the first task. After receiving the message detection request, the third network device generates a first detection instruction. The first detection instruction is used to notify the second network device to perform message detection processing. While generating the first detection instruction, the third network device also needs to generate a first detection task based on the first reference hash value included in the first task. The first reference hash value is generated by the first network device and transmitted to the third network device as part of the first task. The third network device will use the first reference hash value as part of the first detection task for matching and use in subsequent message detection processes. Since the first reference hash value is associated with the second network device, the first detection task including the first reference hash value also corresponds to the second network device. Through the above processing, the third network device and the second network device, two different network devices, work together to perform the message detection task. Through clear instructions and task allocation, it can ensure that all parts of the network system can collaborate effectively and in a targeted manner, thereby improving the overall performance of the system.
[0180] Optionally, the third network device sends the first detection task to the second network device, for example, through various interactive modes, including network protocols, message queues, shared memory or other communication mechanisms.
[0181] Through the above steps S1802 to S1826, the purpose of preventing the on-link network measurement information from being tampered with and reducing the possibility of triggering a network attack can be achieved, and the technical effect of improving the security of the on-link network measurement is achieved, thereby solving the technical problem in the related art that the on-link network measurement request is easily tampered with, thereby increasing the possibility of a network attack.
[0182] Based on the above embodiments and optional embodiments, the present invention proposes an optional implementation mode: Figure 19 This is a schematic flow chart of an optional message detection method provided according to an embodiment of the present invention. The predetermined forwarding path includes a second network device and a fifth network device. The first network device interacts with the blockchain through the fourth network device. The following steps are performed to detect the message: Figure 19 To explain in detail:
[0183] In step S1901, the first network device determines the target data to be transmitted and determines a first segment routing header (SRH-1). The first segment routing header (SRH-1) includes a segment list (SID1, SID0) and a detection segment pointer (SL=1) pointing to SID1 in the segment list. The segment identifier corresponding to the second network device is SID1, and the segment identifier corresponding to the fifth network device is SID0.
[0184] The first network device determines a performance detection field PTF, where the performance detection field includes a field for instructing the second network device and the fifth network device to perform performance detection.
[0185] The first network device generates a first reference segment routing header (RSRH-2) corresponding to the second network device based on the first segment routing header (SRH-1). The first reference segment routing header (RSRH-2) includes a segment list and a detection segment pointer. The detection segment pointer points to the segment identifier (SID1) corresponding to the second network device, that is, the detection segment pointer (SL) = 1. The first network device determines a first reference field corresponding to the second network device. The first reference field includes the first reference segment routing header (RSRH-2) and a performance test field (PTF).
[0186] The first network device generates a second reference segment routing header RSRH-5 corresponding to the fifth network device based on the first segment routing header SRH-1. The second reference segment routing header RSRH-5 includes a segment list and a detection segment pointer. The detection segment pointer points to the segment identifier SID0 corresponding to the fifth network device, that is, the detection segment pointer SL=0. The first network device determines a second reference field corresponding to the fifth network device. The second reference field includes the second reference segment routing header RSRH-5 and the performance detection field PTF.
[0187] In step S1902, the first network device generates a first reference hash value H2 corresponding to the second network device based on the first reference field corresponding to the second network device. The first network device generates a second reference hash value H5 corresponding to the fifth network device based on the second reference field corresponding to the fifth network device. When the aforementioned performance detection field PTF is added to the first message, it is necessary to determine the field assignment (e.g., setting to 1 or 0) of the alternating flag state of the delay detection field and / or the packet loss detection field in the performance detection field.
[0188] The performance detection field includes a packet loss detection field L and a delay detection field D. The packet loss detection field L and the delay detection field D are set to 0 or 1 to realize packet marking processing. The packet loss detection field L can be used for packet loss detection based on alternate marking, and the delay detection field D can be used for delay detection based on alternate marking. Assuming that there are multiple domains in the predetermined forwarding path, the packet loss detection field L and the delay detection field D have four combinations, (L = 1, D = 1), (L = 1, D = 0), (L = 0, D = 1), and (L = 0, D = 0). The corresponding performance detection field PTF is denoted as PTF(11), PTF(10), PTF(01), and PTF(00), respectively. If there are other fields with multiple assignments, such as multiple foreign segment routing headers, the number of corresponding performance detection fields PTF can be more than four.
[0189] According to the four cases of the performance detection field PTF, the first network device uses a predetermined hash algorithm to perform hash calculation on the first reference field corresponding to the second network device. Then, four first reference hash values corresponding to the second network device are obtained, denoted as H2(H2-1; H2-2; H2-3; H2-4). Similarly, for the fifth network device, four second reference hash values corresponding to the fifth network device are obtained, denoted as H5(H5-1; H5-2; H5-3; H5-4). In the case of multiple first reference hash values (or second reference hash values), a list can be used for recording.
[0190] Regardless of how the first network device sets the field assignment according to the alternate marking state and generates the first reference hash value (or the second reference hash value) corresponding to each assignment, the second network device (or the fifth network device) can find a reference hash value that matches in the four first reference hash values corresponding to the four first reference fields (or in the four second reference hash values corresponding to the four second reference fields).
[0191] In step S1903, the first network device is set to indirectly interact with the blockchain, and sends a task request to the fourth network device. The task request includes the first reference hash value H2(H2-1; H2-2; H2-3; H2-4) corresponding to the second network device, and the second reference hash value H5(H5-1; H5-2; H5-3; H5-4) corresponding to the fifth network device. The task request can also include a packet detection request, which carries the packet detection requirement information of the first network device.
[0192] The above-mentioned message detection request may include at least any one of a message security detection flag, a message performance detection flag, the number of first messages, and a first flow identifier, or include a transmission quality feedback request for the first message, the transmission quality feedback request is used to request the third network device to generate a performance feedback task, the performance feedback task is used to feedback the transmission quality corresponding to the first message, the content of the transmission quality feedback request includes at least any one of a detection completion flag, a requirement satisfaction flag, delay data, jitter data, packet loss rate data, the number of outgoing / incoming messages, and outgoing / incoming timestamps, or includes a detection mode and a detection period. The above-mentioned message performance detection flag includes at least any one of packet loss detection enable, delay detection enable, and performance tracking enable.
[0193] In step S1904, the fourth network device generates a first task. The fourth network device generates the first task for the third network device to query based on the sender address of the first task being the address of the fourth network device, the receiver address of the first task being the address of the third network device, the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4), and the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4).
[0194] Step S1905: The fourth network device submits the first task to the blockchain.
[0195] In step S1906, the accounting node of the blockchain verifies the first task and determines whether the first task is stored in the blockchain.
[0196] Step S1907: The fourth network device submits a request to query the first task to the blockchain.
[0197] In step S1908, the fourth network device confirms the record status of the first task in the blockchain to ensure that the third network device can query it normally.
[0198] In step S1909, the third network device submits a query request to the blockchain. It should be noted that if the third network device is a bookkeeping node, it is deemed to automatically obtain the corresponding first task, and step S1909 can be omitted, with step S1908 directly executing step S1910.
[0199] Step S1910: The third network device obtains the first task from the blockchain.
[0200] Step S1911, the third network device generates a first detection task corresponding to the second network device according to the first task, and generates a second detection task corresponding to the fifth network device. The first detection task includes the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4) and a first detection indication, and the first detection indication is used to inform the second network device to perform packet detection according to the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4). The second detection task includes the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4) and a second detection indication, and the second detection indication is used to inform the fifth network device to perform packet detection according to the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4).
[0201] Step S1912, the third network device sends the first detection task to the second network device.
[0202] Step S1913, the third network device sends the second detection task to the fifth network device.
[0203] Step S1914, the second network device acquires the first detection task, acquires the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4) and the first detection indication, and can store the plurality of first reference hash values locally.
[0204] Step S1915, the fifth network device acquires the second detection task, acquires the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4) and the second detection indication, and can store the plurality of second reference hash values locally.
[0205] Step S1916, after determining that the steps S1914 and S1915 are completed, the first network device sends the first packet.
[0206] In step S1917, the second network device receives the first message to be detected including the first message. The second network device generates a first hash value to be detected UH2 based on the first field to be detected of the first message to be detected, and the above-mentioned first field to be detected includes the first segment routing header to be detected USRH-2 and the performance detection field. The second network device matches the above-mentioned first hash value to be detected UH2 with the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4) stored locally, and when UH2 matches one of the hash values of the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4), it determines that the received first message to be detected is the first message. The second network device detects the field assignment corresponding to the alternating mark state included in the performance detection field PTF in the above-mentioned first message, performs performance statistics, and generates a corresponding timestamp to finally obtain the first detection result.
[0207] Step S1918: The second network device generates a second message based on the first message and sends it to the fifth network device.
[0208] Step S1919: The second network device sends a second message.
[0209] In step S1920, the fifth network device receives a second message to be detected including the second message. The fifth network device generates a second hash value to be detected UH5 based on the second field to be detected of the second message to be detected, and the second field to be detected includes the second segment routing header to be detected USRH-5 and the performance detection field PTF. The fifth network device matches the second hash value to be detected UH5 with the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4) stored locally, and when UH5 matches one of the hash values of the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4), it determines that the received second message to be detected is the second message. The fifth network device detects the field value corresponding to the alternating mark state included in the performance detection field PTF in the second message, performs performance statistics, and generates a corresponding timestamp to finally obtain the second detection result.
[0210] In step S1921, if the fifth network device is not the last network device in the predetermined forwarding path, the fifth network device generates a third message based on the second message and continues to transmit the message along the predetermined forwarding path. If the fifth network device is the last network device in the predetermined forwarding path, the fifth network device decompresses and processes the second message.
[0211] In step S1922, the second network device sends a first detection result obtained based on detecting the first message to the third network device.
[0212] In step S1923 , the fifth network device sends a second detection result obtained based on detecting the second message to the third network device.
[0213] In step S1924, the third network device calculates the message transmission performance based on the first detection result of the first message sent by the second network device and the second detection result of the second message sent by the fifth network device, and generates a performance feedback task.
[0214] The third network device generates a performance feedback task for query by the fourth network device based on the sender address of the performance feedback task being the address of the third network device, the receiver address of the performance feedback task being the address of the fourth network device, the first reference hash value H2 (H2-1; H2-2; H2-3; H2-4) and the second reference hash value H5 (H5-1; H5-2; H5-3; H5-4), and the message transmission performance.
[0215] In step S1925, the third network device submits the performance feedback task to the blockchain.
[0216] In step S1926, the accounting node of the blockchain verifies the performance feedback task and determines whether the performance feedback task is stored in the blockchain.
[0217] In step S1927, the fourth network device submits a query request to the blockchain. It should be noted that if the fourth network device is a bookkeeping node, it is deemed to automatically obtain the corresponding performance feedback task, and step S1927 can be omitted, with step S1926 directly executing step S1928.
[0218] In step S1928, the fourth network device obtains a performance feedback task from the blockchain and obtains the execution result of the first task.
[0219] Step S1929: The fourth network device sends the execution result of the first task to the first network device.
[0220] Through the above processing, the purpose of message forwarding path detection and transmission performance detection can be achieved, the in-path network measurement information can be prevented from being tampered with, the possibility of triggering network attacks can be reduced, and the technical effect of improving the security of in-path network measurement can be achieved, thereby solving the technical problem in related technologies that in-path network measurement requests are easily tampered with, thereby increasing the possibility of network attacks.
[0221] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0222] This application also provides an optional implementation method, in which the application scenario of the network system is a 5G network, including a local network, a remote network and a blockchain system, and the local network and the remote network implement an interaction mechanism through the blockchain system. Figure 20 This is a 5G schematic diagram of an optional message detection method provided according to an embodiment of the present invention. The local network includes a user equipment (UE), a radio access network (RAN), an access and mobility management function (AMF), a local session management function (H-SMF, Home Session Management Function), a local user plane function (H-UPF, Home User Plane Function), a protocol data unit session anchor point of the local user plane function (H-UPF PSA1, Home User Plane Function Protocol Data Unit Session Anchor 1), a local policy control function (H-PCF, Home Policy Control Function), a local data network (H-DN1, Home Data Network1) and a local blockchain agent (H-BA, Home Blockchain Agent).
[0223] The remote network includes the remote user plane function (R-UPF), the remote user plane function uplink classifier (R-UPF ULCL), the remote user plane function protocol data unit session anchor (R-UPF PSA2), the remote user plane function protocol data unit session anchor 2 (R-UPF PSA2), the remote session management function (R-SMF), the remote policy control function (R-PCF), the remote data network (R-DN2), and the remote blockchain agent (R-BA).
[0224] Among them, H-UPF PSA1 is the first network device, H-SMF is the fourth network device, H-BA is the first proxy device, which is the local network blockchain proxy and proxies the interaction between H-SMF and the blockchain system. R-SMF is the third network device, R-BA is the remote network blockchain proxy and proxies the interaction between R-SMF and the blockchain system. The second network device is R-UPF ULCL, and the fifth network device is R-UPF PSA2.
[0225] The local network includes a local data network (H-DN1), which provides services such as artificial intelligence, computing, and storage for UEs. UEs access the local network through the RAN and access H-DN1, located at the network edge. If H-DN1 cannot meet the UE's service needs, but R-DN2 can, the UE initiates a request to connect to the remote data network (R-DN2) through the local network. The local network can be a campus network or an industry-specific network.
[0226] The local H-SMF delegates the local blockchain agent (H-BA) to access the remote network and confirm that the remote network's R-DN2 can meet the UE's service requirements. The local H-SMF delegates the blockchain agent H-BA to upload a first task to the blockchain system and send it to the R-BA. The first task includes the first and second reference hash values (which can be one or more) calculated by the local network's H-UPF PSA1. The remote R-SMF (a third network device) obtains the first task through the R-BA, then obtains the first reference hash value and generates a first detection task corresponding to the second network device. It also obtains the second reference hash value and generates a second detection task corresponding to the fifth network device. The first detection task is sent to the second network device R-UPF ULCL and the second detection task is sent to the fifth network device R-UPF PSA2. The fourth network device H-SMF and the third network device R-SMF establish a message forwarding path between the local network and the remote network based on the first task. Optionally, the local network blockchain agent H-BA and the remote blockchain agent R-BA interact with the blockchain system in the form of smart contracts to complete the confirmation of the first task.
[0227] The UE sends a service message, which is then encapsulated in SRv6 by the first network device H-UPF PSA1 and then sent to the remote network. The second network device R-UPF ULCL and the fifth network device R-UPF PSA2 in the remote network test the message based on the first and second reference hash values, confirming that the forwarding path of the first message complies with the agreement for the first task. The second network device R-UPF ULCL tests the performance detection field in the first message to be tested and reports the test results to the third network device R-SMF. The fifth network device R-UPF PSA2 tests the performance detection field in the second message to be tested and reports the test results to the third network device R-SMF. The third network device R-SMF collects the message detection results and calculates the real-time performance of the message transmission path. The remote network can optimize the network based on real-time performance to ensure that the agreed quality of service is met. After completing the first task, the third network device R-SMF reports the transmission status to the fourth network device H-SMF via the blockchain system.
[0228] The interaction of the first task is completed through the blockchain system, and a trusted connection is established between the local network and the remote network. Further, the security detection and performance detection of the first message can be completed to determine the transmission security and transmission quality of the UE service message in the remote network.
[0229] Optionally, the third network device R-SMF has all the functions of R-BA and can complete the interaction with the blockchain system.
[0230] Optionally, the fourth network device H-SMF has all the functions of H-BA and can complete the interaction with the blockchain system.
[0231] In an optional embodiment, in a 5G network, N1, N2, N3, N4, N6, N7, N9 and N11 are defined reference points, respectively representing communication interfaces between different network functions.
[0232] Based on the above embodiments and optional embodiments, the present invention proposes an optional implementation manner. Figure 21 FIG. 1 is a schematic diagram of an application of an optional message detection method provided according to an embodiment of the present invention. Figure 21 The specific implementation steps are as follows:
[0233] In step S2101, the UE completes local network registration, establishes a session with the local network, and accesses local data network H-DN1. The UE can access the local network and use local data network H-DN1 normally. The UE accesses H-DN1 via path 1: UE → RAN → H-UPF → H-DN1. The H-UPF serves as the UE's PDU session anchor and is responsible for data packet routing and forwarding.
[0234] In step S2102, the UE needs to access the data network R-DN2 located in the remote network. The UE triggers an access request to R-DN2 according to service requirements.
[0235] In step S2103, the H-UPF notifies the session management function (H-SMF) of the UE's new requirements. The H-UPF detects that the UE needs to access services in R-DN2 and reports the UE's request to access R-DN2 to the H-SMF. Optionally, the H-UPF sends the request to the H-SMF via an N4 message.
[0236] Step S2104: The H-SMF (ie, the fourth network device) initiates a policy update request to the H-PCF; optionally, the policy update request is sent via an N7 message.
[0237] Step S2105 , the H-PCF replies to the H-SMF with a policy update response; optionally, the policy update response is sent via an N7 message.
[0238] In step S2106, the H-SMF (i.e., the fourth network device) determines that the data network R-DN2 that the UE needs to access is not within the connection range of the local network and identifies that the target network the UE is accessing is a remote network. For example, the Data Network Access Identifier (DNAI) corresponding to R-DN2 cannot be found.
[0239] In step S2107, H-SMF (i.e., the fourth network device) sends a query request to the local blockchain agent H-BA (i.e., the first agent device). H-BA queries the blockchain system for information such as the affiliation, service type, and service quality of R-DN2, confirms that the remote network to which R-DN2 belongs and the service type and service quality provided by R-DN2 can meet the UE requirements, and confirms the detailed information of R-DN2 through the blockchain system.
[0240] Step S2108: establish a new forwarding path for the UE's data flow, and the H-SMF inserts a new user plane function anchor H-UPF PSA1 in the data transmission path; the H-SMF configures the network and establishes an N9 tunnel from the H-UPF to the H-UPF PSA1.
[0241] In step S2109, the H-SMF (i.e., the fourth network device) notifies the H-UPF to modify the PDU session. The H-UPF configures itself as the uplink classifier ULCL, forwards qualified data packets to the H-UPF PSA1, updates the PDU session to use the new forwarding path, and establishes path 2: UE→RAN→H-UPF→H-UPF PSA1.
[0242] Step S2110, the H-UPF PSA1 (i.e., the first network device) calculates the first and second reference hash values (which can be one or more, and in the multiple case, a list form can be used).
[0243] The H-UPF PSA1 determines a first packet, wherein the source address of the IPv6 basic header is the address of the H-UPF PSA1, the destination address is the address of the R-UPF ULCL (i.e., the second network device), the addresses of the R-UPF ULCL, the R-UPF PSA2 (i.e., the fifth network device) and the R-DN2 are sequentially included in the first segment routing header (denoted as SRH-1), the optional TLV field of the SRH-1 includes the performance detection field, and the data payload includes the UE service packet (i.e., the target data). For performance detection, the H-UPF PSA1 alternately marks the delay detection field and the packet loss detection field included in the performance detection field of the first packet.
[0244] Optionally, the performance detection field is located at the segment identifiers corresponding to the R-UPF ULCL (i.e., the second network device) and the R-UPF PSA2 (i.e., the fifth network device), and the performance detection field includes the delay detection field and the packet loss detection field.
[0245] The H-UPF PSA1 (i.e., the first network device) obtains the first reference segment routing header RSRH-2 corresponding to the R-UPF ULCL (i.e., the second network device) according to the SRH-1 of the first packet, and performs hash calculation on the RSRH-2 to obtain the first reference hash value, which is assumed to be four, denoted as H2 (H2-1, H2-2, H2-3, H2-4), wherein the SL in the RSRH-2 corresponds to the segment identifier of the R-UPF ULCL (i.e., the second network device), and in this example, SL = 1.
[0246] The H-UPF PSA1 (i.e., the first network device) obtains the second reference segment routing header RSRH-5 corresponding to the R-UPF PSA2 (i.e., the fifth network device) according to the SRH-1 of the first packet, and performs hash calculation on the RSRH-5 to obtain the second reference hash value, which is assumed to be four, denoted as H5 (H5-1, H5-2, H5-3, H5-4); wherein the SL in the RSRH-5 corresponds to the segment identifier of the R-UPF PSA2 (i.e., the fifth network device), and in this example, SL = 0.
[0247] Step S2111, the H-UPF PSA1 (i.e., the first network device) sends the first reference hash value H2 and the second reference hash value H5 to the H-SMF, and optionally, the H-UPF PSA1 sends the first reference hash value to the H-SMF (i.e., the fourth network device) through the N4 message.
[0248] Step S2112, the H-SMF (i.e., the fourth network device) checks the first reference hash value H2 and the second reference hash value H5, confirms the legality of the first reference hash value, and generates a first task. Optionally, the H-SMF can also not check the first reference hash value H2 and the second reference hash value H5.
[0249] Step S2113, the H-SMF (i.e., the fourth network device) sends the first task to the H-BA (i.e., the first proxy device), and the first task includes the first reference hash value H2 and the second reference hash value H5.
[0250] Step S2114, the H-BA (i.e., the first proxy device) uploads the first task.
[0251] Step S2115, the blockchain system writes the first task.
[0252] Step S2116, the R-BA (i.e., the third proxy device) queries and obtains the first task.
[0253] Step S2117, the R-BA (i.e., the third proxy device) sends the first task to the R-SMF (i.e., the third network device).
[0254] Step S2118, the R-SMF (i.e., the third network device) obtains the first task, and further obtains the first reference hash value H2 and the second reference hash value H5.
[0255] Step S2119, the R-SMF (i.e., the third network device) inserts the R-UPF PSA2 (i.e., the fifth network device), establishes an N9 tunnel from the R-UPF ULCL (i.e., the second network device) to the R-UPF PSA2 (i.e., the fifth network device), and establishes a path 3: R-UPF ULCL→R-UPF PSA2→R-DN2.
[0256] Step S2120, the local network and the remote network establish a path 4: UE→RAN→H-UPF→H-UPF PSA1→R-UPF ULCL→R-UPF PSA2→R-DN2 through the first task, which is a connection path 2 (local network) and a path 3 (remote network).
[0257] Step S2121, the R-SMF (i.e., the third network device) sends a first detection task to the R-UPF ULCL (i.e., the second network device), including the first reference hash value H2; and the R-SMF (i.e., the third network device) sends a second detection task to the R-UPF PSA2 (i.e., the fifth network device), including the second reference hash value H5.
[0258] Optionally, the R-SMF (ie, the third network device) sends the first detection task to the R-UPF ULCL (ie, the second network device) through an N4 message.
[0259] Optionally, the R-SMF (ie, the third network device) sends the second detection task to the R-UPF PSA2 (ie, the fifth network device) through the N4 message.
[0260] Step S2122: The UE sends a service message.
[0261] In step S2123, H-UPF PSA1 (i.e., the first network device) performs GTP-U decapsulation on the message received by the N9 interface to obtain the UE service message. H-UPF PSA1 performs SRv6 encapsulation on the UE service message as described in step S2210 to obtain the first message.
[0262] Step S2124: H-UPF PSA1 (ie, the first network device) sends a first message.
[0263] In step S2125, the R-UPF ULCL (ie, the second network device) detects and processes the first message to be detected, where the first message to be detected includes the first message. If the first message to be detected can be determined to be the first message, a second message may be generated.
[0264] The R-UPF ULCL (i.e., the second network device) receives a first message to be detected including a first message. The R-UPF ULCL calculates the hash value of the first segment routing header to be detected of the first message to be detected, and obtains the first hash value to be detected UH2. The R-UPF ULCL matches the above-mentioned first hash value to be detected UH2 with the local first reference hash value (which can be one or more). When UH2 matches one of the first reference hash values H2 (H2-1, H2-2, H2-3, H2-4), it is determined that the received first message to be detected is the first message, and it can be determined that the message path complies with the agreement of the first task. After performing hash value detection on the first message, the R-UPF ULCL allows the first message that passes the detection to enter the remote network.
[0265] The R-UPF ULCL detects the performance detection field in the first message, performs message performance statistics based on the delay detection field and the packet loss detection field, and generates a second message based on the first message.
[0266] Step S2126: The R-UPF ULCL (ie, the second network device) performs GTP-U tunnel encapsulation on the second message and sends it to the R-UPF PSA2 (ie, the fifth network device) through the N9 interface.
[0267] In step S2127, R-UPF PSA2 detects and processes the second message to be detected, where the second message to be detected includes the second message. If the second message to be detected can be determined to be the second message, a third message can be generated or the forwarding process can be ended.
[0268] R-UPF PSA2 (i.e., the fifth network device) receives the message through the N9 interface, decapsulates it through the GTP-U tunnel, and obtains a second message to be detected that includes the second message. R-UPF PSA2 calculates the hash value of the second reference segment routing header of the second message to be detected to obtain a second hash value to be detected, UH5. R-UPF PSA2 matches the above second hash value to be detected, UH5, with the local second reference hash value. When UH5 matches one of the second reference hash values H5 (H5-1, H5-2, H5-3, H5-4), it determines that the received second message to be detected is the second message, and at the same time, it can be determined that the message path complies with the agreement of the first task. After R-UPF PSA2 (i.e., the fifth network device) detects the second hash value to be detected of the second message, it allows the second message that passes the detection to be further forwarded to R-DN2.
[0269] R-UPF PSA2 (i.e., the fifth network device) detects the performance detection field in the second message, performs message performance statistics based on the delay detection field and the packet loss detection field, and performs SRv6 decapsulation on the second message to generate a third message.
[0270] In step S2128, R-UPF PSA2 (ie, the fifth network device) sends the third message to R-DN2.
[0271] Step S2129: The R-UPF ULCL (ie, the second network device) sends the performance statistics information of the first message to the R-SMF (ie, the third network device). Optionally, the R-UPF ULCL sends the first detection result to the R-SMF via an N4 message.
[0272] Step S2130: R-UPF PSA2 (ie, the fifth network device) sends the performance statistics information of the second message to R-SMF (ie, the third network device). Optionally, R-UPF PSA2 sends the second detection result to R-SMF via an N4 message.
[0273] In step S2131, the R-SMF (ie, the third network device) calculates the message transmission performance according to the first detection result and the second detection result, and generates a performance feedback task.
[0274] In step S2132, the R-SMF (ie, the third network device) sends the performance feedback task to the R-BA (ie, the third agent device).
[0275] In step S2133, R-BA (i.e., the third agent device) uploads the performance feedback task to the blockchain.
[0276] Step S2134: The blockchain system writes a performance feedback task.
[0277] In step S2135 , the H-BA (ie, the first proxy device) queries and obtains the performance feedback task.
[0278] In step S2136, the H-BA transfers the performance feedback task to the H-SMF.
[0279] In step S2137, the H-SMF obtains the completion status of the first task from the performance feedback task and sends it to the H-UPF PSA1. Optionally, the H-SMF sends the completion status of the first task to the H-UPF PSA1 via an N4 message.
[0280] It should be noted that the above modules can be implemented by software or hardware. For example, for the latter, it can be implemented in the following ways: the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0281] It should be noted that the optional or preferred implementation of this embodiment can be found in the relevant description in the embodiment, which will not be repeated here.
[0282] An embodiment of the present invention provides a non-volatile storage medium on which a program is stored. When the program is executed by a processor, a message detection method is implemented.
[0283] An embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a program stored in the memory and runnable on the processor. When the processor executes the program, it implements the message detection method provided by any embodiment. The device in this article can be a server, a PC, etc.
[0284] The present invention also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program for initializing the message detection method provided by any embodiment.
[0285] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0286] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0287] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0288] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more flow or blocks Figure 1 means for functionally implementing the steps listed in the flowchart block or blocks.
[0289] In one typical configuration, the computing device includes one or more processors (CPU's), input / output interfaces, network interfaces, and memory.
[0290] The memory can include non-persistent memory and / or persistent memory, such as flash memory, read-only memory (ROM), and / or volatile or non-volatile random access memory (RAM), among others. The memory is an example of computer readable media.
[0291] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0292] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of other identical elements in the process, method, commodity, or apparatus comprising the element.
[0293] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0294] The above are merely embodiments of the present invention and are not intended to limit the present invention. It will be apparent to those skilled in the art that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are intended to be included within the scope of the claims of the present invention.
Claims
1. A message detection method, characterized in that: include: The first network device determines target data to be transmitted, a first segment routing header, and a performance detection field, wherein the target data is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used by the transmission network device to perform message detection; The first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, wherein the second network device belongs to the transmission network device, and the first reference hash value is used to generate a first task whose recipient address is the address of the third network device. The first task includes the first reference hash value and is transmitted to the blockchain, so that the third network device obtains the first task through interaction with the blockchain. The third network device is used to generate a first detection task including the first reference hash value based on the first task. The third network device is used to send the first detection task to the second network device and notify the second network device to perform message detection; The first network device generates a first message based on the target data, the first segment routing header, and the performance detection field; The first network device sends the first message, wherein the first message is used to be transmitted on a predetermined forwarding path, and the predetermined forwarding path includes the transmission network device. The second network device is used to receive a first message to be detected on the predetermined forwarding path. The first message to be detected is used by the second network device to generate a first hash value to be detected. The second network device is used to match the first hash value to be detected and the first reference hash value to obtain a matching result. When the matching result indicates that the first hash value to be detected matches the first reference hash value, the second network device is used to detect the first message to be detected according to the first detection task sent by the third network device to determine a first detection result. The second network device is used to send the first detection result to the third network device. The third network device is used to generate a performance feedback task based on the first detection result. The third network device is used to upload the performance feedback task to the blockchain.
2. The method according to claim 1, characterized in that The method further comprises: In a case where the first network device is configured to directly interact with the blockchain, the first network device generates the first task based on the first reference hash value; The first network device uploads the first task to the blockchain; The first network device queries the blockchain to determine the performance feedback task whose recipient address is the address of the first network device, wherein the performance feedback task includes a processing result of the first task uploaded by the first network device.
3. The method according to claim 1, characterized in that The method further comprises: In a case where the first network device is configured to indirectly interact with the blockchain, the first network device sends the first reference hash value to a fourth network device, so that the fourth network device generates the first task based on the first reference hash value and uploads the generated task to the blockchain, wherein the fourth network device has the ability to interact with the first network device and the blockchain respectively; The first network device obtains the performance feedback task through the fourth network device. The fourth network device is used to query the blockchain and determine the performance feedback task whose recipient address is the address of the fourth network device. The performance feedback task includes the processing result of the first task uploaded by the fourth network device.
4. The method according to claim 1, wherein The sender address of the first task is used to indicate the address for performing upload processing of the first task through the blockchain. The first network device generates the first task based on the first reference hash value, including: In a case where the first network device is configured to directly interact with the blockchain, the first network device determines that the sender address of the first task is the address of the first network device; the first network device generates the first task based on the sender address of the first task and the first reference hash value; In a case where the first network device is configured to interact indirectly with the blockchain, the first network device sends the first reference hash value to a fourth network device, so that the fourth network device generates the first task based on the sender address of the first task and the first reference hash value, wherein the sender address of the first task is the address of the fourth network device.
5. The method according to claim 2 or 3, characterized in that The first task is determined based on a message detection request and the first reference hash value, wherein the message detection request is used to carry message detection information.
6. The method according to claim 5, characterized in that The message detection request includes a transmission quality feedback request for the first message, and the transmission quality feedback request is used to request the third network device to generate the performance feedback task, and the performance feedback task is used to feedback the transmission quality corresponding to the first message. The content of the transmission quality feedback request includes at least any one of delay data, jitter data, packet loss rate data, number of outgoing / incoming messages, and outgoing / incoming timestamps.
7. The method according to claim 5, characterized in that The message detection request includes at least any one of a message security detection flag, a message performance detection flag, a first message quantity, and a first flow identifier, wherein the message security detection flag is used to indicate whether the first reference hash value is valid or invalid, and the message performance detection flag is used to indicate whether to perform performance detection on the first message.
8. The method according to claim 7, characterized in that The message performance detection flag includes at least any one of packet loss detection enable, delay detection enable and performance tracking enable. The packet loss detection enable is used to indicate whether the packet loss detection bit included in the message performance detection flag is valid. The delay detection enable is used to indicate whether the delay detection bit included in the message performance detection flag is valid. The performance tracking enable is used to indicate whether the message performance tracking flag is valid.
9. The method according to claim 1, characterized in that The performance detection field includes at least any one of the following: a delay detection field, a packet loss detection field, and a performance tracking indication field, wherein the delay detection field is used to characterize the message transmission delay, the packet loss detection field is used to characterize the message transmission packet loss rate, and the performance tracking indication field is used to indicate the type of data that needs to be collected for message performance detection.
10. The method according to claim 9, characterized in that The first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: When the performance detection field includes the performance tracking indication field, the first network device generates the first reference hash value based on the indication information corresponding to the second network device and the performance tracking indication field; When the first network device includes the delay detection field in the performance detection field, the first network device generates a plurality of first reference hash values based on an alternating mark state of the delay detection field and indication information corresponding to the second network device; or When the first network device includes the packet loss detection field in the performance detection field, the first network device generates multiple first reference hash values based on the alternating mark state of the packet loss detection field and the indication information corresponding to the second network device.
11. The method according to claim 1, wherein The indication information includes a segment identifier, The performance detection field is carried in at least any one of the following locations, including: a segment identifier corresponding to the transmission network device included in the first segment routing header, an optional type-length-value TLV field, a label field, a tag field, and a first segment identifier, a hop-by-hop option extension header, and a destination option extension header, wherein the first segment identifier is the first segment identifier in the segment list included in the first segment routing header, and the segment list includes a group of segment identifiers corresponding to the transmission network device that are arranged in order.
12. The method according to claim 1, characterized in that The indication information includes a detection segment pointer, and the first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: The first network device updates the first segment routing header based on the detection segment pointer of the second network device to obtain a first reference routing header corresponding to the second network device; The first network device determines the first reference hash value based on the first reference routing header and the performance detection field.
13. The method according to claim 1, wherein The first network device generates a first reference hash value corresponding to the second network device based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, including: The first network device determines a plurality of domains included in a predetermined network system, wherein the plurality of domains respectively include at least one transmission network device; The first network device generates corresponding performance detection fields for the multiple domains respectively; The first network device generates the first reference hash value based on the indication information corresponding to the second network device and the corresponding performance detection fields generated by the multiple domains.
14. A message detection method, characterized in that: include: The second network device obtains a first detection task including a first reference hash value, wherein the second network device belongs to a transmission network device included in a predetermined forwarding path, the first detection task is generated by the third network device based on the first task, and is used to notify the second network device to perform message detection, the first task includes the first reference hash value and is used to be transmitted to the blockchain, so that the third network device obtains the first task through interaction with the blockchain, the recipient address of the first task is the address of the third network device, the first reference hash value is generated by the first network device based on the indication information corresponding to the second network device indicated by the first segment routing header, and the performance detection field, the target data starts from the first network device and is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used by the transmission network device to perform message detection; The second network device receives a first message to be detected, wherein the first message to be detected is any message received by the second network device on a predetermined forwarding path; The second network device generates a first hash value to be detected based on the first message to be detected; The second network device performs matching based on the first to-be-detected hash value and the first reference hash value to obtain a matching result; When the matching result indicates that the first to-be-detected hash value matches the first reference hash value, the second network device detects the first to-be-detected message according to the first detection task and determines a first detection result; The second network device sends the first detection result to the third network device, so that the third network device generates a performance feedback task based on the first detection result, wherein the third network device uploads the performance feedback task to the blockchain.
15. The method according to claim 14, characterized in that The first detection task includes a plurality of first reference hash values, and the second network device performs matching based on the first hash value to be detected and the first reference hash value to obtain a matching result, including: The second network device matches the first hash value to be detected with a plurality of first reference hash values respectively to determine the matching result; The method further includes: when the matching result indicates that the first to-be-detected hash value matches any one of the multiple first reference hash values, detecting the first to-be-detected message according to the first detection task to determine the first detection result.
16. The method according to claim 14, characterized in that When the matching result indicates that the first to-be-detected hash value matches the first reference hash value, the second network device detects the first to-be-detected message according to the first detection task to determine a first detection result, including: The second network device performs message statistics according to the performance detection field of the first message to be detected to obtain statistical information corresponding to the first message to be detected, wherein the statistical information includes the number of first messages to be detected and / or the timestamp of the first message to be detected, and the first hash value to be detected corresponding to the first message to be detected, where the timestamp of the first message to be detected is generated when the second network device receives the first message to be detected; The first detection result is obtained based on the statistical information corresponding to the first message to be detected.
17. The method according to claim 16, characterized in that The method further comprises: When the matching result indicates that the first hash value to be detected does not match the first reference hash value, the second network device processes the first message to be detected using a predetermined abnormal message processing method.
18. A message detection method, characterized in that: include: The first network device determines target data to be transmitted, a first segment routing header, and a performance detection field, wherein the target data is transmitted in an orderly manner according to the transmission network device determined by the indication information of the first segment routing header, and the performance detection field is used by the transmission network device to perform message detection; The first network device generates, based on the indication information corresponding to the second network device indicated by the first segment routing header and the performance detection field, a first reference hash value corresponding to the second network device, wherein the second network device belongs to the transmission network device, and the first reference hash value is used to generate a first task whose recipient address is the address of the third network device, and the first task includes the first reference hash value and is used to be transmitted to the blockchain; The third network device obtains the first task by interacting with the blockchain; The third network device generates a first detection task including the first reference hash value based on the first task; The third network device sends the first detection task to the second network device, and notifies the second network device to perform message detection; The first network device generates a first message based on the target data, the first segment routing header, and the performance detection field; The first network device sends the first message, wherein the first message is used to be transmitted on a predetermined forwarding path, and the predetermined forwarding path includes the transmission network device; The second network device receives a first message to be detected on the predetermined forwarding path, wherein the first message to be detected is used by the second network device to generate a first hash value to be detected; The second network device performs matching based on the first to-be-detected hash value and the first reference hash value to obtain a matching result; When the matching result indicates that the first to-be-detected hash value matches the first reference hash value, the second network device is configured to detect the first to-be-detected message according to the first detection task sent by the third network device, and determine a first detection result; The second network device sends the first detection result to the third network device; The third network device generates a performance feedback task based on the first detection result; The third network device uploads the performance feedback task to the blockchain.
19. The method according to claim 18, characterized in that The third network device generates, based on the first task, a first detection task including the first reference hash value, including: The third network device determines a message detection request based on the first task; The third network device generates a first detection instruction based on the message detection request, wherein the first detection instruction is used to notify the second network device to perform message detection processing; The third network device generates the first detection task according to the first detection instruction and the first reference hash value included in the first task.
20. An electronic device, characterized in that: include: One or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the message detection method described in any one of claims 1 to 19.
Citation Information
Patent Citations
Performance measurement method, device and system
CN114531369A
Message processing method and system
CN116800867A