A service chain protection method, device, node, and storage medium

By publishing attribute information through business function forwarding nodes and orchestrating detection paths through head nodes, the flexibility problem of reliability protection in SRv6 SFC is solved, and node migration adaptability without manual configuration and reliability protection with reduced alternative conflicts are achieved.

CN119030918BActive Publication Date: 2025-10-24BEIJING XINWANG RUIJIE NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310590251.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-23
Publication Date
2025-10-24
Estimated Expiration
2043-05-23

AI Technical Summary

Technical Problem

Existing technologies cannot flexibly implement reliability protection in SRv6 SFC. In particular, a large amount of configuration information needs to be manually modified during node migration, and conflicts between alternative service function forwarding nodes and primary service function forwarding nodes are prone to occur.

Method used

By publishing notifications of attribute information through the business function forwarding node, the head node orchestrates the target detection path and sends detection messages to the main business function forwarding node to mark the alternative business function forwarding node, reducing alternative conflicts and achieving flexible reliability protection.

Benefits of technology

It enables flexible adjustment of the backup relationship between business function forwarding nodes without manual modification of configuration information after node migration, reduces alternative conflicts, and improves the reliability and protection efficiency of the business chain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119030918B_ABST
    Figure CN119030918B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a service chain protection method and device, a node and a storage medium. The method is applied to a head node in an SFC domain, and comprises the following steps: after receiving notification information published by a plurality of service function forwarding nodes, attribute information corresponding to the plurality of service function forwarding nodes is determined; based on the attribute information, a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes is arranged; the target detection path comprises the main service function forwarding node and corresponding non-main service function forwarding nodes; a detection packet is sent to the main service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding standby service function forwarding node from the non-main service function forwarding nodes based on the detection packet after receiving the detection packet, and marks the corresponding standby service function forwarding node in the detection packet, and the marked detection packet is sent to the corresponding standby service function forwarding node.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a service chain protection method and device, a node and a storage medium. BACKGROUND

[0002] Due to the requirements for safety, quality and the like in data transmission, some service packets need to be additionally routed through the services of a third party for processing. In a service function chain (SFC), when a head node diverts, a service sequence that needs to be routed is filled in the network service header (NSH) information of the packet, so that the service packet can pass through specific equipment for specific service function processing.

[0003] Segment Routing IPv6 (SRv6) SFC technology is a source routing technology using SRv6, which logically connects the devices and services on the network at the head node to form an ordered service combination, thereby realizing the service chain function.

[0004] In the related art, in order to realize the reliability protection of SRv6 SFC, a backup node is added and manually configured to realize the protection of the fault in the service chain.

[0005] However, the above method is strongly related to the network topology, and when the node changes (such as service function node migration), a large amount of configuration information needs to be manually modified. SUMMARY

[0006] The embodiments of the present application provide a service chain protection method, device, node and storage medium, which are used to flexibly realize the reliability protection of SRv6 SFC.

[0007] In a first aspect, the embodiments of the present application provide a first service chain protection method applied to a head node in an SFC domain, which includes:

[0008] After receiving the announcement information published by a plurality of service function forwarding nodes in the SFC domain, attribute information corresponding to the plurality of service function forwarding nodes is determined, wherein the attribute information represents the service type of the service function node agented by the service function forwarding node;

[0009] determine a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes; wherein the target detection path comprises the master service function forwarding node and non-master service function forwarding nodes corresponding to the master service function forwarding node in the plurality of service function forwarding nodes;

[0010] sending a detection packet to the master service function forwarding node, so that any service function forwarding node in the target detection path, after receiving the detection packet, determines a corresponding candidate service function forwarding node from the non-master service function forwarding nodes based on the detection packet, marks the corresponding candidate service function forwarding node in the detection packet, and sends the marked detection packet to the corresponding candidate service function forwarding node; wherein the detection packet contains node information of the non-master service function forwarding node, and any service function forwarding node in the target detection path is the master service function forwarding node or the non-master service function forwarding node.

[0011] The above scheme, the service function forwarding node will publish the announcement information carrying the attribute of the agent service function node, the head node receives the announcement information of the service function forwarding node in the SFC domain, and the attribute information can determine the non-master service function forwarding node which can be used as the backup of the master service function forwarding node. These service function forwarding nodes can provide reliability protection (the candidate service function forwarding node provides protection for the corresponding master service function forwarding node or non-master service function forwarding node). The head node sends a detection packet to the master service function forwarding node, and sequentially learns the backup service function forwarding node from the unmarked service function forwarding node starting from the master service function forwarding node, so as to flexibly perform reliability protection. Even if the node migrates, the head node can also timely perceive through the announcement information, so as to flexibly adjust the backup relationship between the service function forwarding nodes. In addition, each service function forwarding node marks the backup service function forwarding node, reduces the occurrence of backup conflict, and makes the reliability protection of the service chain more orderly.

[0012] In some optional embodiments, based on the attribute information corresponding to the plurality of service function forwarding nodes, the target detection path corresponding to the master service function forwarding node in the plurality of service function forwarding nodes is arranged, comprising:

[0013] the service function forwarding nodes corresponding to the attribute information same as the master service function forwarding node in the plurality of service function forwarding nodes are taken as the non-master service function forwarding nodes;

[0014] If there are multiple non-main service function forwarding nodes, the target detection path is arranged based on the distance between the main service function forwarding node and each non-main service function forwarding node, and the distance between different non-main service function forwarding nodes.

[0015] If there is one non-main service function forwarding node, the main service function forwarding node is determined as the first hop in the target detection path, and the non-main service function forwarding node is determined as the second hop in the target detection path.

[0016] The above scheme accurately realizes reliable protection by determining non-main service function forwarding nodes with the same attribute information as the main service function forwarding node, reducing the occurrence of situations where non-main service function forwarding nodes with different attributes cannot provide protection for the main service function forwarding node. If there are multiple non-main service function forwarding nodes, the target detection path is reasonably arranged based on the distance between the main service function forwarding node and each non-main service function forwarding node, and the distance between different non-main service function forwarding nodes, efficiently performing reliable protection. If there is only one non-main service function forwarding node, it can only provide protection for the main service function forwarding node by being used as the next hop of the main service function forwarding node. Thus, the target detection path is reasonably arranged for different scenarios.

[0017] In some optional embodiments, the target detection path is arranged based on the distance between the main service function forwarding node and each non-main service function forwarding node, and the distance between different non-main service function forwarding nodes, including:

[0018] The main service function forwarding node is determined as the first hop in the target detection path.

[0019] The remaining non-main service function forwarding node closest to the (n-1)th hop in the target detection path is determined as the nth hop in the target detection path; where 2≤n≤N, N is the total number of the main service function forwarding node and the non-main service function forwarding node in the target detection path; the remaining non-main service function forwarding node is the non-main service function forwarding node in the target detection path without a determined hop number.

[0020] The above scheme selects the non-main service function forwarding node closest to each hop service function forwarding node in the target detection path as the next hop (i.e., its alternative service function forwarding node) from the non-main service function forwarding nodes without a determined hop number, so that the distance between the alternative service function forwarding node and the service function forwarding node it protects is as close as possible, efficiently performing reliable protection.

[0021] In some optional embodiments, the notification information is published by the plurality of service function forwarding nodes at a preset time interval.

[0022] In the above scheme, the service function forwarding nodes re-flood the attribute information of the service function nodes at a certain time interval, so that the head node can timely perceive the change of the nodes, re-arrange a new path, and adjust the backup relationship between the service function forwarding nodes without modifying a large amount of configuration information.

[0023] In a second aspect, the embodiments of the present application provide a second service chain protection method, applied to a target service function forwarding node, the target service function forwarding node being any service function forwarding node in an SFC domain, and the method comprising:

[0024] publishing the notification information carrying the attribute information, so that, after receiving the notification information of the plurality of service function forwarding nodes, the head node in the SFC domain arranges a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on the attribute information corresponding to the plurality of service function forwarding nodes, and sends a detection packet to the master service function forwarding node; wherein the plurality of service function forwarding nodes include the any service function forwarding node, and the attribute information represents the service type of the service function node proxied by the service function forwarding node; the target detection path includes the master service function forwarding node and a non-master service function forwarding node in the plurality of service function forwarding nodes corresponding to the master service function forwarding node;

[0025] after receiving the target detection packet, determining a corresponding candidate service function forwarding node from the non-master service function forwarding node based on the target detection packet; wherein the target detection packet contains node information of the non-master service function forwarding node; if the target service function forwarding node is the master service function forwarding node, the target detection packet is a detection packet sent by the head node; if the target service function forwarding node is a target non-master service function forwarding node, the detection packet is a marked detection packet sent by a previous-hop service function forwarding node in the target detection path;

[0026] marking the corresponding candidate service function forwarding node in the target detection packet, and sending the marked detection packet to the corresponding candidate service function forwarding node.

[0027] The above scheme, the service function forwarding node will issue the announcement information carrying the attribute of the agent service function node, the head node can determine the non-main service function forwarding node which can be used as the backup of the main service function forwarding node based on the attribute information after receiving the announcement information of the service function forwarding node in the SFC domain, and the service function forwarding nodes can provide reliability protection (the backup service function forwarding node provides protection for the corresponding main service function forwarding node or non-main service function forwarding node); the head node sends a detection packet to the main service function forwarding node, and the main service function forwarding node starts to learn its backup service function forwarding node from the unmarked service function forwarding node in turn, so as to flexibly perform reliability protection. Even after the node migration, the head node can timely perceive through the announcement information, so as to flexibly adjust the backup relationship between the service function forwarding nodes; in addition, each service function forwarding node marks its backup service function forwarding node, reduces the occurrence of backup conflict, and makes the reliability protection of the service chain more orderly.

[0028] In some optional embodiments, if the target service function forwarding node is the main service function forwarding node, the corresponding backup service function forwarding node is determined from the non-main service function forwarding node based on the target detection packet, including:

[0029] The next hop non-main service function forwarding node in the target detection path is determined as the corresponding backup service function forwarding node.

[0030] In the above scheme, the main service function forwarding node is the first hop service function forwarding node in the target detection path, that is, the first service function forwarding node receiving the detection packet in the target detection path. The detection packet has not been marked by other service function forwarding nodes, and there is a backup service function forwarding node of the main service function forwarding node. Therefore, the main service function forwarding node directly determines the next hop non-main service function forwarding node as the corresponding backup service function forwarding node.

[0031] In some optional embodiments, if the target service function forwarding node is the non-main service function forwarding node, the corresponding backup service function forwarding node is determined from the non-main service function forwarding node based on the target detection packet, including:

[0032] If there is an unmarked non-main service function forwarding node in the target detection packet, the next hop unmarked non-main service function forwarding node in the target detection packet is determined as the corresponding backup service function forwarding node.

[0033] In the above scheme, since the non-service function forwarding node is not the first-hop service function forwarding node in the target detection path, the received detection packet has been marked by other service function forwarding nodes as an alternative service function forwarding node, and the non-main service function forwarding node may not have an alternative service function forwarding node of the non-main service function forwarding node. Therefore, the non-main service function forwarding node needs to determine from the target detection packet whether there is an unmarked other non-main service function forwarding node, and if there is, the unmarked non-main service function forwarding node in the next hop of the target detection packet is determined as the corresponding alternative service function forwarding node.

[0034] In some optional embodiments, the marking of the corresponding alternative service function forwarding node in the target detection packet comprises:

[0035] The node information of the corresponding alternative service function forwarding node is marked as occupied in the target detection packet.

[0036] In the above scheme, after the service function forwarding node determines the alternative service function forwarding node thereof, the alternative service function forwarding node is marked and sent to the next service function forwarding node (alternative service function forwarding node), so as to avoid backup conflicts.

[0037] In some optional embodiments, the method further comprises:

[0038] After receiving the service packet, if a link fault occurs between the target service function forwarding node and the corresponding service function node, the service packet is re-encapsulated, and the re-encapsulated service packet is sent to the corresponding alternative service function forwarding node.

[0039] In the above scheme, after the service function forwarding node learns the protection command, if a main path fault is found, the backup path is taken, that is, the service packet is sent to the corresponding alternative service function forwarding node, the packet is sent by the alternative service function forwarding node to the service function node for processing, and fast re-routing is implemented.

[0040] In some optional embodiments, the notification information is published by the plurality of service function forwarding nodes every preset time length.

[0041] In the above scheme, the service function forwarding node re-floods the attribute information of the service function node every certain time length, so that the head node can timely perceive the change of the node, rearrange a new path, and adjust the backup relationship between the service function forwarding nodes without modifying a large amount of configuration information.

[0042] In a third aspect, a first service chain protection device is provided, which is applied to a head node in an SFC domain, and the device comprises:

[0043] The attribute determining module is configured to determine attribute information corresponding to the plurality of service function forwarding nodes after receiving the announcement information published by the plurality of service function forwarding nodes in the SFC domain, wherein the attribute information represents a service type of a service function node that the service function forwarding node proxies.

[0044] The arrangement module is configured to arrange a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on the attribute information corresponding to the plurality of service function forwarding nodes, wherein the target detection path includes the master service function forwarding node and non-master service function forwarding nodes in the plurality of service function forwarding nodes corresponding to the master service function forwarding node.

[0045] The detection module is configured to send a detection packet to the master service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding standby service function forwarding node from the non-master service function forwarding nodes based on the detection packet after receiving the detection packet, and sends a marked detection packet to the corresponding standby service function forwarding node, wherein the detection packet contains node information of the non-master service function forwarding node, and any service function forwarding node in the target detection path is the master service function forwarding node or the non-master service function forwarding node.

[0046] In a fourth aspect, a second service chain protection device is provided, which is applied to a target service function forwarding node, and the target service function forwarding node is any service function forwarding node in an SFC domain. The device includes:

[0047] The publishing module is configured to publish announcement information carrying attribute information, so that a head node in the SFC domain arranges a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes after receiving the announcement information published by the plurality of service function forwarding nodes, and sends a detection packet to the master service function forwarding node, wherein the plurality of service function forwarding nodes include the any service function forwarding node, the attribute information represents a service type of a service function node that the service function forwarding node proxies, and the target detection path includes the master service function forwarding node and non-master service function forwarding nodes in the plurality of service function forwarding nodes corresponding to the master service function forwarding node.

[0048] determining, based on the target detection packet, a corresponding candidate service function forwarding node from the non-primary service function forwarding node, wherein the target detection packet contains node information of the non-primary service function forwarding node; if the target service function forwarding node is the primary service function forwarding node, the target detection packet is a detection packet sent by the head node; if the target service function forwarding node is a target non-primary service function forwarding node, the detection packet is a marked detection packet sent by a previous hop service function forwarding node in the target detection path;

[0049] marking the corresponding candidate service function forwarding node in the target detection packet, and sending the marked detection packet to the corresponding candidate service function forwarding node.

[0050] In a fifth aspect, an embodiment of the present application provides a head node, including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the service chain protection method in any of the first aspect.

[0051] In a sixth aspect, an embodiment of the present application provides a service function forwarding node, including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the service chain protection method in any of the second aspect.

[0052] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program executable by a processor, and when the program is run on the processor, the processor executes the service chain protection method in any of the first aspect or the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort based on these drawings.

[0054] Figure 1 The first application scenario provided by the embodiment of the present application is shown in the following figure;

[0055] Figure 2 The second application scenario provided by the embodiment of the present application is shown in the following figure;

[0056] Figure 3A third application scenario diagram provided by the embodiment of the present application is shown in FIG. 6.

[0057] Figure 4 An interaction flow diagram of a service chain protection method provided by the embodiment of the present application is shown in FIG. 7.

[0058] Figure 5 A message header field diagram provided by the embodiment of the present application is shown in FIG. 8.

[0059] Figure 6 A fourth application scenario diagram provided by the embodiment of the present application is shown in FIG. 9.

[0060] Figure 7 A flow diagram of a first service chain protection method provided by the embodiment of the present application is shown in FIG. 10.

[0061] Figure 8 A flow diagram of a second service chain protection method provided by the embodiment of the present application is shown in FIG. 11.

[0062] Figure 9 A structure diagram of a first service chain protection device provided by the embodiment of the present application is shown in FIG. 12.

[0063] Figure 10 A structure diagram of a second service chain protection device provided by the embodiment of the present application is shown in FIG. 13.

[0064] Figure 11 A structure diagram of a head node provided by the embodiment of the present application is shown in FIG. 14. DETAILED DESCRIPTION

[0065] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0066] The terms "first", "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0067] In the description of the present application, it should be noted that unless otherwise explicitly specified and limited, the term ''connection'' should be understood broadly, for example, it can be direct connection or indirect connection through an intermediate medium, and it can be internal connection of two devices. For those skilled in the art, the specific meaning of the above-mentioned term in the present application can be understood according to the specific circumstances.

[0068] In the embodiment, a service function forwarding node (Service function Forwarder, SFF) is configured to forward a message received from a network to a service function node (service function, SF) associated with the SFF according to service chain path information carried in the message.

[0069] The SF is configured to receive the message from the SFF, perform service function processing on the message, and return the processed message to the same SFF.

[0070] SFC is a technology for providing ordered services to the application layer; an area containing SFC devices can be referred to as an SFC domain.

[0071] Due to the requirements for security, quality, etc. in data transmission, some service messages need to be additionally routed through third-party services for processing. For example, a firewall, a traffic cleaning server, or a traffic acceleration server, etc.

[0072] In the SFC domain, when the head node (the first node in the linked list) diverts, the service sequence that needs to be routed is filled in the NSH information of the message, so that the service message can pass through specific devices for specific service function processing.

[0073] SRv6 technology is that source routing specifies the traffic forwarding path by arranging a list of segment identifiers (Segment ID, SID) at the head node; and the SID of SRv6 supports flexible forwarding programmability. SRv6 technology itself can meet the needs of SFC, so SRv6 SFC is proposed.

[0074] SRv6 SFC technology is to use the source routing technology of SRv6 to logically chain the devices and services on the network at the head node to form an ordered service combination, thereby realizing service chain function.

[0075] Referring to Figure 1 As shown in the figure, the scenario is provided with a service classifier (Service Classifier, SC), SF1, SFF1 proxying SF1, SF2, SFF2 proxying SF2;

[0076] In this scenario, the SC as the head node encapsulates the received initial packet to obtain service packet 1, and the segment list in the Segment Routing Header (SRH) of service packet 1 is the forwarding path of the packet in the service chain; the segment list is Tail End.DT4 SID, Tail End SID, SF2 Proxy SID, and SF1 Proxy SID.

[0077] The SC sends service packet 1 to SFF1, SFF1 strips the SRH from the packet and sends the packet without the SRH to SF1.

[0078] SF1 performs service processing on the initial packet to obtain a processed packet and sends the processed packet to SFF1.

[0079] SFF1 completes SR encapsulation of the packet based on the SRH to obtain service packet 2 and sends service packet 2 to SFF2.

[0080] Similarly, SFF2 strips the SRH of service packet 2 and sends the packet to SF2 for processing, SFF2 encapsulates to obtain service packet 3 and sends service packet 3 to the IPv6 node for IPv6 routing forwarding.

[0081] The above example takes an ipv4 packet as an example of a packet that needs to be processed, and other types of packets can also be used in implementation.

[0082] However, the above method cannot achieve reliability protection, for example, when a link between the service function node 1 and the service function forwarding node 1 fails, the service of the service function node 1 cannot be used; when a link between the service function node 2 and the service function forwarding node 2 fails, the service of the service function node 2 cannot be used.

[0083] In related technologies, in order to achieve reliability protection of SRv6 SFC, a backup node is added, and static configuration (configuration of how to go to an alternative path, etc. Logical information) is manually performed to achieve protection against faults in the service chain.

[0084] 1. By connecting the service function node to multiple service function forwarding nodes, when a link on one side fails, the service function node can be bypassed through a backup service function forwarding node to complete the service chain function.

[0085] Referring to Figure 2As shown, SF1 dual-homed access SFF1 and SFF2. SFF1 acts as the proxy of SF1, configures END.AS type primary SID (END.AS) and backup SID (ENA.AS backup), and needs to configure cache SRH packet information (including SIDList, IPv6 source IP address, TTL, etc.) for the primary SID; SFF2 also needs to configure the above information as another proxy of SF dual-homed access.

[0086] After the SC receives the initial packet, the initial packet is introduced into the SRv6 TE Policy according to the matching steering strategy; the SC performs SRv6 packet encapsulation according to the SRv6 TE Policy, and the SID sequence of the SRv6 TE Policy is (Tail END.DT4, Tail END, SFF1 END.AS).

[0087] SFF1 receives the packet, identifies that the current SID is the local END.AS type primary SID, and determines that the link between SFF1 and SF1 is faulty, and SFF1 needs to forward the packet through the backup path;

[0088] SFF1 peels off the original SRH header and re-encapsulates the SID sequence of the backup path (SFF1 END.AS backup, SFF2 END) to generate a new SRH packet header;

[0089] SFF2 receives the backup path packet, identifies that SFF2 END is a local END type SID, and processes according to the END standard behavior; identifies the next SID: SFF1 END.AS backup is a local backup SID, and peels off the SRH header according to the behavior of the backup SID to forward the inner packet to SF1;

[0090] After SFF2 receives the inner packet returned by SF1, it re-encapsulates the SRH header according to the cache SRH packet information configured by END.AS to send the packet;

[0091] SFF3 receives the packet and forwards it through IPv6 routing;

[0092] Tail End identifies that it is a local END type SID and processes according to the END standard behavior; identifies that the next SID is a local END.DT4 type and uses the inner packet destination IP address to find private network routing and forwarding.

[0093] Figure 2 In the scenario shown, the normal forwarding process is shown by the dashed line, and the protection process is shown by the solid line.

[0094] 2. The primary service function node is protected by the alternative service function node, and the service chain function can be completed by the alternative service function node when the primary service function node fails. In this example, the attribute information of the primary service function node SF1 and the alternative service function node SF2 is the same, that is, the functions are the same, SFF2 is the alternative of SFF1, and SFF3 is the alternative of SFF2.

[0095] SFF1 is the proxy of SF, and END.AS type main SID (END.AS) and backup SID (ENA.AS backup) are configured, and the cache SRH packet information (including SID List, IPv6 source IP address, TTL, etc.) needs to be configured for the main SID; SFF2 is another proxy of SF dual-homing access, and also needs to be configured with the above information;

[0096] SFF2 is configured at the same time, and SFF3 END.AS SID protects SFF2 and SF1 link failure;

[0097] After the SC receives the initial packet, the initial packet is introduced into the SRv6 TE Policy according to the matching diversion strategy; the SC encapsulates the SRv6 packet according to the SRv6 TE Policy, and the SID sequence of the SRv6 TE Policy is (Tail END.DT4, Tail END, SFF1 END.AS).

[0098] SFF1 receives the packet, identifies that the current SID is the local END.AS type main SID, and identifies the link failure between SFF1 and SF1; SFF1 needs to forward the packet through the backup path;

[0099] SFF1 peels off the original SRH header and encapsulates the backup path SID sequence (SFF1 END.AS backup, SFF2 END) again to generate a new SRH packet header.

[0100] SFF2 receives the backup path packet, identifies that SFF2 END is a local END type SID, and processes according to the END standard behavior; the next SID is identified: SFF1 END.AS backup is a local backup SID, and it is identified that there is a link failure between SFF2 and SF1; SFF2 needs to forward the packet through the bypass path;

[0101] SFF2 peels off the original SRH header, reuses SFF2 END.AS SID as the destination address, encapsulates an IPv6 header, and forwards through routing;

[0102] SFF3 receives the packet, identifies that the destination address is a local END.AS SID, peels off the SRH header, and forwards the packet to SF2;

[0103] SFF3 receives the inner-layer message returned by SF2, re-encapsulates the SRH header according to the cached SRH message information configured by END.AS, and sends the message;

[0104] Tail End identification is a local END type SID, and is processed according to the END standard behavior; the next SID is identified as a local END.DT4 type, and the inner-layer message destination IP address is used to search for a private network route for forwarding.

[0105] Figure 3 In the scenario shown, the normal forwarding process is shown by the dashed line, and the protection process is shown by the solid line.

[0106] However, the above two reliability protection methods need to manually configure a large amount of information (such as protection commands), which is strongly related to the network topology. When a node changes (such as a service function node migration), a large amount of configuration information needs to be manually modified. In addition, the standby service function forwarding node and the main service function forwarding node need to be configured with the same SID information (Proxy SID and BackupProxy SID). In planning, the same locator needs to be used for the node, which may cause conflicts.

[0107] In view of this, the embodiments of the present application propose a service chain protection method, device, node and storage medium. The method is applied to a head node in an SFC domain. After receiving notification information published by a plurality of service function forwarding nodes in the SFC domain, attribute information corresponding to the plurality of service function forwarding nodes is determined, wherein the attribute information represents the service type of a service function node proxied by the service function forwarding node. Based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes is arranged. The target detection path includes the main service function forwarding node and non-main service function forwarding nodes in the plurality of service function forwarding nodes corresponding to the main service function forwarding node. A detection message is sent to the main service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding standby service function forwarding node from the non-main service function forwarding nodes based on the detection message after receiving the detection message, marks the corresponding standby service function forwarding node in the detection message, and sends the marked detection message to the corresponding standby service function forwarding node. The detection message contains node information of the non-main service function forwarding node, and any service function forwarding node in the target detection path is the main service function forwarding node or the non-main service function forwarding node.

[0108] The above scheme, the service function forwarding node publishes the announcement information carrying the attribute of the agent service function node, and the head node can determine the standby non-main service function forwarding node which can be used as the backup of the main service function forwarding node based on the attribute information after receiving the announcement information of the service function forwarding node in the SFC domain. The service function forwarding nodes can provide reliability protection (the standby service function forwarding node provides protection for the corresponding main service function forwarding node or non-main service function forwarding node). The head node sends a detection packet to the main service function forwarding node, and the main service function forwarding node obtains the standby service function forwarding node from the unmarked service function forwarding node in turn, so as to flexibly provide reliability protection. Even if the node migrates, the head node can timely perceive through the announcement information, so as to flexibly adjust the standby relationship between the service function forwarding nodes. In addition, the service function forwarding nodes mark the standby service function forwarding nodes, reduce the occurrence of standby conflict, and make the reliability protection of the service chain more orderly.

[0109] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below in combination with the drawings and specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described in detail in some embodiments.

[0110] Figure 4 The first service chain protection method provided by the embodiment of the present application has the interaction flowchart as shown in Figure 4 The method comprises the following steps:

[0111] Step S401: The target service function forwarding node publishes the announcement information carrying the attribute information.

[0112] The target service function forwarding node is any service function forwarding node in the SFC domain, and the attribute information represents the service type of the service function node agent by the service function forwarding node.

[0113] For example, any service function forwarding node in the SFC domain floods and publishes the announcement information based on the Intermediate System-to-Intermediate System (ISIS) protocol, which is a link state protocol and belongs to the internal gateway routing protocol. The head node collects the announcement information of each service function forwarding node.

[0114] Referring to Figure 5As shown, the attribute information can be represented by a Service Type field in the message header, such as 0 representing a firewall, 1 representing a traffic acceleration server, 2 representing a traffic cleaning server, and the like; a Traffic Type representing a type of traffic, a Proxy Type representing a type of proxy; in addition, a TLV field is a field that can be used, and information such as resource capability can be placed in an AttributeSub-TLV field.

[0115] In this embodiment, the SID of each service function forwarding node is independent and does not need to be configured to be the same, and the same locator does not need to be used.

[0116] In addition, the embodiment adds a SID of a dynamic protection type (Dynamic Protectproxy, END.ADP) on the basis of the existing SFC SID, to avoid conflict with the standard type.

[0117] Step S402: After receiving the announcement information published by the plurality of service function forwarding nodes in the SFC domain, the head node determines attribute information corresponding to the plurality of service function forwarding nodes.

[0118] In this embodiment, since the protection command is not manually configured, even if there is a node that can be used, the service function forwarding node cannot directly execute the protection command; based on this, after collecting the announcement information of the plurality of service function forwarding nodes in the SFC domain, the head node can determine attribute information corresponding to the service function forwarding nodes, and between the service function forwarding nodes corresponding to the service function nodes of the same service type, reliable protection can be provided.

[0119] In the implementation, a private network route is introduced between the head node and the tail node through a Border Gateway Protocol (BGP), and tenant attributes and tenant service requirement information are extended to support.

[0120] Step S403: The head node arranges a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes based on the attribute information corresponding to the plurality of service function forwarding nodes.

[0121] The target detection path includes the main service function forwarding node and a non-main service function forwarding node corresponding to the main service function forwarding node in the plurality of service function forwarding nodes.

[0122] As described above, the service function nodes of the same service type can provide reliability protection between the service function forwarding nodes corresponding to the service function nodes; based on this, after determining the attribute information of each service function forwarding node, the target detection path including multiple service function forwarding nodes can be arranged based on the attribute information, and through subsequent detection messages, the service function forwarding nodes on the target detection path can learn the information of the master and backup protection.

[0123] Step S404: The head node sends a detection message to the master service function forwarding node.

[0124] In implementation, the head node sends a detection message to the master service function forwarding node in the target detection path, and the detection message includes the protection information of the target detection path, that is, the node information of the non-master service function forwarding node (which non-master service function forwarding nodes are in the target detection path).

[0125] For example, the SRH is encapsulated in the detection message, the protection information of the target detection path is carried by the newly added TLV of the SRH, and the arranged protection information is notified to the service function forwarding node and the protection node, so that the protection information of the master and backup is learned by the service function forwarding node through one-time notification, and the subsequent service flow does not need to carry the protection information, thereby achieving flexible reliability protection.

[0126] Step S405: After receiving the target detection message, the target service function forwarding node determines the corresponding alternative service function forwarding node from the non-master service function forwarding node based on the target detection message.

[0127] The target detection message includes the node information of the non-master service function forwarding node; if the target service function forwarding node is the master service function forwarding node, the target detection message is the detection message sent by the head node; if the target service function forwarding node is a target non-master service function forwarding node, the detection message is a marked detection message sent by the previous hop service function forwarding node in the target detection path.

[0128] Step S406: The target service function forwarding node marks the corresponding alternative service function forwarding node in the target detection message, and sends the marked detection message to the corresponding alternative service function forwarding node.

[0129] For example, after receiving the detection message, the target service function forwarding node can learn the alternative service function forwarding node, mark the alternative service function forwarding node, reduce the occurrence of alternative conflict, and make the reliability protection of the service chain more orderly.

[0130] The above scheme, the service function forwarding node will publish the attribute information of the service function node to be agent, the head node can determine the non-main service function forwarding node which can be used as backup for the main service function forwarding node based on the attribute information after receiving the attribute information of the service function forwarding node in the SFC domain, and the service function forwarding nodes can provide reliability protection (the backup service function forwarding node provides protection for the corresponding main service function forwarding node or non-main service function forwarding node). Specifically, the head node sends a detection packet to the main service function forwarding node, and the main service function forwarding node obtains its backup service function forwarding node from the unmarked service function forwarding node in turn; the main service function forwarding node further sends a detection packet to its backup service function forwarding node, so that the backup service function forwarding node continues to obtain the corresponding backup service function forwarding node from the unmarked service function forwarding node (if any); the detection is forwarded level by level until all service function forwarding nodes in the SFC domain are polled. Through the above method, the reliability protection between the service function forwarding nodes can be flexibly performed, and even after the node migration, the head node can timely perceive through the attribute information, so as to flexibly adjust the backup relationship between the service function forwarding nodes; in addition, each service function forwarding node marks the backup service function forwarding node, reduces the occurrence of backup conflict, and makes the reliability protection of the service chain more orderly.

[0131] In some optional embodiments, the attribute information is published by the plurality of service function forwarding nodes every preset time interval.

[0132] For example, in order to timely perceive the migration of the node, the service function forwarding node re-floods the attribute information of the service function node every certain time interval, so that the head node can timely perceive the change of the node, rearrange a new path, and adjust the backup relationship between the service function forwarding nodes without modifying a large amount of configuration information.

[0133] In some optional embodiments, the step S403 can be implemented by but not limited to the following methods:

[0134] The service function forwarding node with the same attribute information as the main service function forwarding node in the plurality of service function forwarding nodes is used as the non-main service function forwarding node.

[0135] If there are a plurality of non-main service function forwarding nodes, the target detection path is arranged based on the distance between the main service function forwarding node and each non-main service function forwarding node and the distance between different non-main service function forwarding nodes; or

[0136] If there is one non-main service function forwarding node, the main service function forwarding node is determined as the first hop in the target detection path, and the non-main service function forwarding node is determined as the second hop in the target detection path.

[0137] For example, if the main service function forwarding node is service function forwarding node A, the corresponding attribute information is attribute 1, there are three service function forwarding nodes B, C, and D in the SFC domain, and the corresponding attribute information of the three service function forwarding nodes is attribute 1, and other service function forwarding nodes in the SFC domain correspond to other attribute information; the service function forwarding nodes B, C, and D are determined as non-main service function forwarding nodes; the service function forwarding node A is the first hop in the target detection path, and the hop numbers of the service function forwarding nodes B, C, and D need to refer to the distances between the service function forwarding node A and the service function forwarding nodes B, C, and D, respectively, and the distances between the service function forwarding nodes B, C, and D. If the main service function forwarding node is service function forwarding node E, the corresponding attribute information is attribute 2, and there is only service function forwarding node F in the SFC domain, and the corresponding attribute information of the service function forwarding node F is attribute 1; the service function forwarding node F is determined as a non-main service function forwarding node; the service function forwarding node A is the first hop in the target detection path, and the service function forwarding node F is the second hop in the target detection path.

[0138] The above examples are only for more clearly illustrating the process of arranging the target detection path in different cases, and the embodiment does not specifically limit the corresponding attribute information of the main service function forwarding node and the number of non-main service function forwarding nodes.

[0139] The above scheme accurately realizes reliability protection by determining the non-main service function forwarding nodes corresponding to the attribute information of the main service function forwarding node, reduces the situation that the non-main service function forwarding nodes cannot provide protection for the main service function forwarding node due to different attributes; if there are multiple non-main service function forwarding nodes, the target detection path is reasonably arranged based on the distances between the main service function forwarding node and each non-main service function forwarding node, and the distances between different non-main service function forwarding nodes, and the reliability protection is efficiently performed; if there is only one non-main service function forwarding node, the main service function forwarding node can only be protected by the non-main service function forwarding node, and the non-main service function forwarding node can be used as the next hop of the main service function forwarding node. Thus, the target detection path is reasonably arranged for different scenarios.

[0140] In some optional embodiments, the above arrangement of the target detection path based on the distances between the main service function forwarding node and each non-main service function forwarding node, and the distances between different non-main service function forwarding nodes, can be realized by but not limited to the following ways:

[0141] determining the main service function forwarding node as the first hop in the target detection path;

[0142] determining the remaining non-main service function forwarding node closest to the (n-1)th hop in the target detection path as the nth hop in the target detection path; wherein 2≤n≤N, N is the total number of the main service function forwarding node and the non-main service function forwarding node in the target detection path; the remaining non-main service function forwarding node is the non-main service function forwarding node in the target detection path without a determined hop number.

[0143] For example, if the main service function forwarding node is service function forwarding node A, the corresponding attribute information is attribute 1, there are three service function forwarding nodes B, C and D in the SFC domain, the corresponding attribute information of which is attribute 1, and other service function forwarding nodes in the SFC domain correspond to other attribute information; service function forwarding nodes B, C and D are determined as non-main service function forwarding nodes;

[0144] Service function forwarding node A is the first hop in the target detection path, among service function forwarding nodes B, C and D, service function forwarding node C is closest to service function forwarding node A, and service function forwarding node C is determined as the second hop in the target detection path;

[0145] Among service function forwarding nodes B and D, service function forwarding node B is closest to service function forwarding node A, and service function forwarding node B is determined as the third hop in the target detection path; finally, service function forwarding node D is determined as the third hop in the target detection path.

[0146] The above example is only for more clearly illustrating the process of compiling the target detection path when there are multiple non-main service function forwarding nodes, and the corresponding attribute information of the main service function forwarding node and the number of non-main service function forwarding nodes are not specifically limited in this embodiment.

[0147] The above scheme selects the non-main service function forwarding node closest to each hop service function forwarding node in the target detection path as the next hop (that is, its alternative service function forwarding node) among the non-main service function forwarding nodes without a determined hop number, so that the alternative service function forwarding node is as close as possible to the service function forwarding node it protects, and the reliability protection is efficiently performed.

[0148] In some optional embodiments, the above step S405 can be implemented by but not limited to the following manners:

[0149] If the target service function forwarding node is the main service function forwarding node, the next hop non-main service function forwarding node in the target detection path is determined as the corresponding alternative service function forwarding node.

[0150] If the target service function forwarding node is the non-primary service function forwarding node, and there is a non-primary service function forwarding node in the target detection packet that is not marked, the non-primary service function forwarding node that is not marked in the next hop of the target detection packet is determined as the corresponding backup service function forwarding node.

[0151] Since the primary service function forwarding node is the first hop service function forwarding node in the target detection path, that is, the first service function forwarding node that receives the detection packet in the target detection path, the detection packet has not been marked by other service function forwarding nodes with backup service function forwarding nodes, and there is a backup service function forwarding node of the primary service function forwarding node. Therefore, the primary service function forwarding node directly determines the non-primary service function forwarding node in the next hop as the corresponding backup service function forwarding node.

[0152] Since the non-primary service function forwarding node is not the first hop service function forwarding node in the target detection path, the received detection packet has been marked by other service function forwarding nodes with backup service function forwarding nodes, and there is not necessarily a backup service function forwarding node of the non-primary service function forwarding node. Therefore, the non-primary service function forwarding node needs to determine from the target detection packet whether there is an unmarked other non-primary service function forwarding node, and if there is, the non-primary service function forwarding node that is not marked in the next hop of the target detection packet is determined as the corresponding backup service function forwarding node. Of course, if there is no unmarked other non-primary service function forwarding node, it is determined that it has no corresponding backup service function forwarding node.

[0153] In some optional embodiments, the above step S406 can be implemented by but not limited to the following manner:

[0154] In the target detection packet, the node information of the corresponding backup service function forwarding node is marked as occupied.

[0155] In the above scheme, after determining the backup service function forwarding node, the service function forwarding node marks the backup service function forwarding node and sends it to the next service function forwarding node (backup service function forwarding node), so as to avoid backup conflicts.

[0156] In the implementation, the head node optimizes the primary service function forwarding node, the backup service function forwarding node (the backup service function forwarding node of the primary service function forwarding node), and the bypass service function forwarding node (the backup service function forwarding node of the backup service function forwarding node) in the service function node service topology in the domain, and performs path arrangement. Of course, more levels of backup relationship can also be set, which will not be described here.

[0157] Referring to Figure 6As shown, the head node calculates and identifies that the primary service function forwarding node is SFF1 Proxy SID (1st hop in the target detection path), the backup service function forwarding node is SFF2 Porxy SID (alternative service function forwarding node of the primary service function forwarding node, 2nd hop in the target detection path), and the bypass service function forwarding node is SFF3Proxy SID (alternative service function forwarding node of the alternative service function forwarding node SFF2, 3rd hop in the target detection path).

[0158] After path arrangement, all service function forwarding nodes on the path need to be notified, such as using an extended SRv6 ping (a network command) detection message process as a control plane of protection information to publish the protection information to related service function forwarding nodes. The ping detection message carries O-FLAG identification on the SRH and carries a private extended TLV.

[0159] After each device in the path receives the ping detection message, the protection information carried by the extended new TLV of the SRH in the detection message is identified, and a protection path of the SF is locally generated.

[0160] In this embodiment, the TLV field contains multi-level information, the first-level information is reserved information, the second-level information is a protection position (representing a function to be protected, such as a protection SL position = 2 for a firewall), and the third-level information is information indicating whether to use as a backup node. After receiving the detection message, the service function forwarding node identifies whether there is an unmarked service function forwarding node, and if so, marks the first unmarked service function forwarding node (such as Figure 6 As shown, replace "false" with "true"), and when sending the detection message to the next service function forwarding node, the next service function forwarding node will not use the same service function forwarding node as a backup or as a backup for each other.

[0161] The above detection message is only an exemplary description, and as long as a message carrying the protection information of the target detection path can be used to implement the notification, the message can be used as the detection message in this embodiment. In implementation, other protocol form messages can be used, such as Operation Administration and Maintenance (OAM) messages; or, the message header carries the above information, such as using the SRH extended TLV to complete the pre-notification of the protection information.

[0162] The head node sends a detection packet to the primary service function forwarding node, identifies the candidate service function forwarding node from the unmarked service function forwarding node, and obtains the protection information from the primary service function forwarding node; the service function forwarding node marks the candidate service function forwarding node and sends it to the next service function forwarding node to avoid backup conflicts.

[0163] In some optional embodiments, on the basis of any of the above embodiments, the service function forwarding node further performs the following steps:

[0164] After receiving the service packet, if the link between the target service function forwarding node and the corresponding service function node fails, the service packet is re-encapsulated and sent to the corresponding candidate service function forwarding node.

[0165] For example, the service function forwarding node can use a bidirectional forwarding detection (BFD) mechanism to detect the primary path (link between the service function node) in the received service packet, and switch to the backup path (link between the candidate service function forwarding node) within 50 ms of the primary path failure.

[0166] In the above scheme, after the service function forwarding node obtains the protection command, if the primary path fails, the backup path is taken, that is, the service packet is sent to the corresponding candidate service function forwarding node, and the packet is sent to the service function node for processing through the candidate service function forwarding node, to realize fast reroute (FRR).

[0167] In the service chain protection method performed by the head node in the embodiments of the present application, as shown in Figure 7 The method comprises the following steps:

[0168] Step S701: After receiving the notification information published by a plurality of service function forwarding nodes in the SFC domain, attribute information corresponding to the plurality of service function forwarding nodes is determined, wherein the attribute information represents the service type of the service function node agent by the service function forwarding node;

[0169] Step S702: Based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a primary service function forwarding node in the plurality of service function forwarding nodes is arranged; wherein the target detection path comprises the primary service function forwarding node and a non-primary service function forwarding node corresponding to the primary service function forwarding node in the plurality of service function forwarding nodes;

[0170] Step S703: sending a detection packet to the master service function forwarding node, so that any service function forwarding node in the target detection path, after receiving the detection packet, determines a corresponding alternative service function forwarding node from the non-master service function forwarding node based on the detection packet, marks the corresponding alternative service function forwarding node in the detection packet, and sends the marked detection packet to the corresponding alternative service function forwarding node; wherein the detection packet contains node information of the non-master service function forwarding node, and any service function forwarding node in the target detection path is the master service function forwarding node or the non-master service function forwarding node.

[0171] In some optional embodiments, based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes is arranged, comprising:

[0172] The service function forwarding node in the plurality of service function forwarding nodes with the same attribute information as the master service function forwarding node is determined as the non-master service function forwarding node.

[0173] If there are a plurality of non-master service function forwarding nodes, the target detection path is arranged based on the distance between the master service function forwarding node and each non-master service function forwarding node, and the distance between different non-master service function forwarding nodes; or

[0174] If there is one non-master service function forwarding node, the master service function forwarding node is determined as the first hop in the target detection path, and the non-master service function forwarding node is determined as the second hop in the target detection path.

[0175] In some optional embodiments, the target detection path is arranged based on the distance between the master service function forwarding node and each non-master service function forwarding node, and the distance between different non-master service function forwarding nodes, comprising:

[0176] The master service function forwarding node is determined as the first hop in the target detection path.

[0177] The remaining non-master service function forwarding node closest to the (n-1)th hop in the target detection path is determined as the nth hop in the target detection path; wherein 2≤n≤N, N is the total number of the master service function forwarding node and the non-master service function forwarding node in the target detection path; the remaining non-master service function forwarding node is the non-master service function forwarding node in the target detection path without a determined hop number.

[0178] In some optional embodiments, the notification information is published by the plurality of service function forwarding nodes at a preset time interval.

[0179] In the embodiments of the present application, the service chain protection method performed by the target service function forwarding node includes the following steps as shown in the figure: Figure 8

[0180] Step S801: Publish the notification information carrying attribute information, so that the head node in the SFC domain arranges a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes after receiving the notification information of the plurality of service function forwarding nodes, and sends a detection packet to the master service function forwarding node; wherein the plurality of service function forwarding nodes include the any service function forwarding node, and the attribute information represents a service type of a service function node proxied by the service function forwarding node; the target detection path includes the master service function forwarding node and a non-master service function forwarding node in the plurality of service function forwarding nodes corresponding to the master service function forwarding node;

[0181] Step S802: After receiving the target detection packet, determine a corresponding alternative service function forwarding node from the non-master service function forwarding node based on the target detection packet; wherein the target detection packet contains node information of the non-master service function forwarding node; if the target service function forwarding node is the master service function forwarding node, the target detection packet is a detection packet sent by the head node; if the target service function forwarding node is a target non-master service function forwarding node, the detection packet is a marked detection packet sent by a previous hop service function forwarding node in the target detection path;

[0182] Step S803: Mark the corresponding alternative service function forwarding node in the target detection packet, and send the marked detection packet to the corresponding alternative service function forwarding node.

[0183] In some optional embodiments, if the target service function forwarding node is the master service function forwarding node, determining the corresponding alternative service function forwarding node from the non-master service function forwarding node based on the target detection packet includes:

[0184] determining the next hop non-master service function forwarding node in the target detection path as the corresponding alternative service function forwarding node.

[0185] ​In some optional embodiments, if the target service function forwarding node is the non-primary service function forwarding node, the corresponding alternative service function forwarding node is determined from the non-primary service function forwarding node based on the target detection packet, including:

[0186] If the non-primary service function forwarding node is not marked in the target detection packet, the non-primary service function forwarding node whose next hop is not marked in the target detection packet is determined as the corresponding alternative service function forwarding node.

[0187] In some optional embodiments, the corresponding alternative service function forwarding node is marked in the target detection packet, including:

[0188] The node information of the corresponding alternative service function forwarding node is marked as occupied in the target detection packet.

[0189] In some optional embodiments, the method further includes:

[0190] After receiving a service packet, if a link between the target service function forwarding node and the corresponding service function node fails, the service packet is re-encapsulated, and the re-encapsulated service packet is sent to the corresponding alternative service function forwarding node.

[0191] In some optional embodiments, the announcement information is published by the plurality of service function forwarding nodes at a preset time interval.

[0192] Figure 7-8 The specific implementation of the embodiments can refer to the implementation of the above-mentioned interaction method, and the repeated parts will not be described again.

[0193] As shown in Figure 9 , based on the same inventive concept as the service chain protection method shown in Figure 7 , the first service chain protection device 900 is provided in the embodiments of the present application, which is applied to a head node in an SFC domain, and the device includes:

[0194] An attribute determining module 901 is configured to determine attribute information corresponding to a plurality of service function forwarding nodes in the SFC domain after receiving announcement information published by the plurality of service function forwarding nodes, wherein the attribute information represents a service type of a service function node which is proxied by the service function forwarding node.

[0195] The arrangement module 902 is configured to arrange a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes. The target detection path includes the master service function forwarding node and non-master service function forwarding nodes corresponding to the master service function forwarding node in the plurality of service function forwarding nodes.

[0196] The detection module 903 is configured to send a detection packet to the master service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding candidate service function forwarding node from the non-master service function forwarding nodes based on the detection packet after receiving the detection packet, and sends a marked detection packet to the corresponding candidate service function forwarding node. The detection packet contains node information of the non-master service function forwarding node, and any service function forwarding node in the target detection path is the master service function forwarding node or the non-master service function forwarding node.

[0197] In some optional embodiments, the arrangement module 902 is specifically configured to:

[0198] The service function forwarding nodes corresponding to the attribute information of the master service function forwarding node in the plurality of service function forwarding nodes are determined as the non-master service function forwarding nodes.

[0199] If there are a plurality of non-master service function forwarding nodes, the target detection path is arranged based on distances between the master service function forwarding node and each non-master service function forwarding node and distances between different non-master service function forwarding nodes; or

[0200] If there is one non-master service function forwarding node, the master service function forwarding node is determined as a first hop in the target detection path, and the non-master service function forwarding node is determined as a second hop in the target detection path.

[0201] In some optional embodiments, the arrangement module 902 is specifically configured to:

[0202] The master service function forwarding node is determined as a first hop in the target detection path.

[0203] The remaining non-main service function forwarding node closest to the n-1th hop distance in the target detection path is determined as the nth hop in the target detection path, where 2≤n≤N, N is the total number of the main service function forwarding node and the non-main service function forwarding node in the target detection path, and the remaining non-main service function forwarding node is the non-main service function forwarding node in the target detection path without a determined hop number.

[0204] In some optional embodiments, the announcement information is published by the plurality of service function forwarding nodes at a preset time interval.

[0205] As shown in Figure 10 Based on the same inventive concept as the service chain protection method shown in Figure 8 Based on the same inventive concept as the service chain protection method shown in

[0206] The publishing module 1001 is configured to publish announcement information carrying attribute information, so that the head node in the SFC domain arranges a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes after receiving the announcement information of the plurality of service function forwarding nodes, and sends a detection packet to the main service function forwarding node. The plurality of service function forwarding nodes include the any service function forwarding node, and the attribute information represents the service type of the service function node proxied by the service function forwarding node. The target detection path includes the main service function forwarding node and a non-main service function forwarding node corresponding to the main service function forwarding node in the plurality of service function forwarding nodes.

[0207] The alternative determining module 1002 is configured to determine a corresponding alternative service function forwarding node from the non-main service function forwarding node based on a target detection packet after receiving the target detection packet. The target detection packet contains node information of the non-main service function forwarding node. If the target service function forwarding node is the main service function forwarding node, the target detection packet is a detection packet sent by the head node. If the target service function forwarding node is a target non-main service function forwarding node, the detection packet is a marked detection packet sent by a previous hop service function forwarding node in the target detection path.

[0208] The alternative marking module 1003 is configured to mark the corresponding alternative service function forwarding node in the target detection packet, and send the marked detection packet to the corresponding alternative service function forwarding node.

[0209] In some optional implementations, if the target service function forwarding node is the primary service function forwarding node, the alternative determination module 1002 is specifically configured to:

[0210] The non-primary service function forwarding node at the next hop in the target detection path is determined as the corresponding candidate service function forwarding node.

[0211] In some optional implementations, if the target service function forwarding node is the non-primary service function forwarding node, the alternative determination module 1002 is specifically configured to:

[0212] If there is an unmarked non-primary service function forwarding node in the target detection message, the unmarked non-primary service function forwarding node at the next hop in the target detection message is determined as the corresponding candidate service function forwarding node.

[0213] In some optional implementations, the candidate marking module 1003 is specifically configured to:

[0214] The node information of the corresponding candidate service function forwarding node is marked as occupied in the target detection message.

[0215] Some optional implementations further include a protection module 1004, configured to:

[0216] After receiving the service message, if a link between the target service function forwarding node and the corresponding service function node fails, the service message is re-encapsulated and sent to the corresponding alternative service function forwarding node.

[0217] In some optional implementations, the notification information is published by the multiple service function forwarding nodes at preset time intervals.

[0218] Figure 9-10 The specific implementation of the embodiment can refer to the implementation of the above-mentioned interaction method, and the repeated parts will be omitted.

[0219] Based on the same technical concept, the embodiment of the present application also provides a head node 1100, such as Figure 11 As shown, it includes at least one processor 1101 and a memory 1102 connected to the at least one processor. The specific connection medium between the processor 1101 and the memory 1102 is not limited in the embodiment of the present application. Figure 11 For example, the processor 1101 and the memory 1102 are connected via a bus 1103. The bus can be divided into a path bus, a data bus, a control bus, etc. For ease of representation, Figure 11 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0220] The processor 1101 is a control center of the head node, can connect various parts of the head node by using various interfaces and lines, and realizes data processing by running or executing instructions stored in the memory 1102 and calling data stored in the memory 1102. Optionally, the processor 1101 can include one or more processing units, and the processor 1101 can integrate an application processor and a modem processor, where the application processor mainly processes an operating system, a user interface, and an application program, and the modem processor mainly processes an issued instruction. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 1101. In some embodiments, the processor 1101 and the memory 1102 can be implemented on the same chip, and in some embodiments, they can also be respectively implemented on independent chips.

[0221] The processor 1101 can be a general-purpose processor, for example, a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in combination with the service chain protection method embodiment can be directly embodied as hardware processor execution or executed by a combination of hardware and software modules in the processor.

[0222] The memory 1102, as a non-volatile computer readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 1102 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. The memory 1102 is any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this. The memory 1102 in the embodiment of the present application can also be a circuit or other any device capable of realizing the storage function, used to store program instructions and / or data.

[0223] In the embodiment of the present application, the memory 1102 stores a computer program, when the program is executed by the processor 1101, the processor 1101 executes:

[0224] After receiving the announcement information published by the plurality of service function forwarding nodes in the SFC domain, attribute information corresponding to the plurality of service function forwarding nodes is determined, wherein the attribute information represents the service type of the service function node agent by the service function forwarding node;

[0225] Based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes is arranged; wherein the target detection path includes the main service function forwarding node and a non-main service function forwarding node in the plurality of service function forwarding nodes corresponding to the main service function forwarding node;

[0226] sending a detection packet to the primary service function forwarding node, so that any service function forwarding node in the target detection path, upon receiving the detection packet, determines a corresponding alternative service function forwarding node from the non-primary service function forwarding nodes based on the detection packet, and marks the corresponding alternative service function forwarding node in the detection packet, and sends the marked detection packet to the corresponding alternative service function forwarding node; wherein the detection packet contains node information of the non-primary service function forwarding node, and any service function forwarding node in the target detection path is the primary service function forwarding node or the non-primary service function forwarding node.

[0227] In some optional embodiments, the processor 1101 specifically performs:

[0228] determining, as the non-primary service function forwarding node, a service function forwarding node in the plurality of service function forwarding nodes that has the same attribute information as the primary service function forwarding node;

[0229] if there are multiple non-primary service function forwarding nodes, arranging the target detection path based on distances between the primary service function forwarding node and each of the non-primary service function forwarding nodes, and distances between different non-primary service function forwarding nodes; or

[0230] if there is one non-primary service function forwarding node, determining the primary service function forwarding node as the first hop in the target detection path, and determining the non-primary service function forwarding node as the second hop in the target detection path.

[0231] In some optional embodiments, the processor 1101 specifically performs:

[0232] determining the primary service function forwarding node as the first hop in the target detection path;

[0233] determining, as the nth hop in the target detection path, a remaining non-primary service function forwarding node that is closest to the (n-1)th hop in the target detection path, wherein 2≤n≤N, N is the total number of the primary service function forwarding node and the non-primary service function forwarding nodes in the target detection path, and the remaining non-primary service function forwarding node is a non-primary service function forwarding node in the target detection path that does not have a determined hop number.

[0234] In some optional embodiments, the announcement information is published by each of the plurality of service function forwarding nodes at a preset time interval.

[0235] Based on the same technical concept, the application further provides a service function forwarding node, comprising at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor executes the following steps:

[0236] publishing the announcement information carrying the attribute information, so that the head node in the SFC domain arranges a target detection path corresponding to a master service function forwarding node in the multiple service function forwarding nodes based on attribute information corresponding to the multiple service function forwarding nodes after receiving the announcement information of the multiple service function forwarding nodes, and sends a detection packet to the master service function forwarding node; wherein the multiple service function forwarding nodes comprise the any service function forwarding node, and the attribute information represents a service type of a service function node represented by the service function forwarding node; the target detection path comprises the master service function forwarding node and a non-master service function forwarding node in the multiple service function forwarding nodes corresponding to the master service function forwarding node;

[0237] after receiving the target detection packet, determining a corresponding alternative service function forwarding node from the non-master service function forwarding node based on the target detection packet; wherein the target detection packet contains node information of the non-master service function forwarding node; if the target service function forwarding node is the master service function forwarding node, the target detection packet is a detection packet sent by the head node; if the target service function forwarding node is a target non-master service function forwarding node, the detection packet is a marked detection packet sent by a previous hop service function forwarding node in the target detection path;

[0238] marking the corresponding alternative service function forwarding node in the target detection packet, and sending the marked detection packet to the corresponding alternative service function forwarding node.

[0239] In some optional embodiments, if the target service function forwarding node is the master service function forwarding node, the processor specifically executes:

[0240] determining a next hop non-master service function forwarding node in the target detection path as the corresponding alternative service function forwarding node.

[0241] In some optional embodiments, if the target service function forwarding node is the non-master service function forwarding node, the processor specifically executes:

[0242] if there is an unmarked non-master service function forwarding node in the target detection packet, determining a next hop unmarked non-master service function forwarding node in the target detection packet as the corresponding alternative service function forwarding node.

[0243] In some optional embodiments, the processor specifically performs:

[0244] In the target detection packet, the node information of the corresponding alternative service function forwarding node is marked as occupied.

[0245] In some optional embodiments, the processor further performs:

[0246] After receiving the service packet, if a link between the target service function forwarding node and the corresponding service function node fails, the service packet is re-encapsulated, and the re-encapsulated service packet is sent to the corresponding alternative service function forwarding node.

[0247] In some optional embodiments, the announcement information is published by the plurality of service function forwarding nodes at a preset time interval.

[0248] Based on the same technical concept, the embodiments of the present application further provide a computer readable storage medium, which stores a computer program executable by a processor, and when the program runs on the processor, the processor executes the steps of the service chain protection method.

[0249] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0250] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one flow or multiple flows and / or blocks Figure 1 The device that implements the functions specified in one flow or multiple flows and / or blocks.

[0251] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0252] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that are executed on the computer or other programmable apparatus provide steps for implementing the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0253] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the preferred embodiments by those of skill in the art once they have the benefit of the present disclosure. Therefore, the appended claims are intended to encompass within their scope all possible variations and modifications of the preferred embodiments.

[0254] It is apparent that a person skilled in the art can make various changes and modifications to the application without departing from the spirit and scope thereof. Thus, if these modifications and variations of the application fall within the scope of the claims and their equivalents, it is intended to include them within the scope of the application.

Claims

1. A service chain protection method applied to a head node in a service chain SFC domain, characterized in that, The method comprises: After receiving the announcement information published by the plurality of service function forwarding nodes in the SFC domain, attribute information corresponding to the plurality of service function forwarding nodes is determined, wherein the attribute information represents the service type of the service function node served by the service function forwarding node; Based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes is arranged; wherein the target detection path comprises the main service function forwarding node and non-main service function forwarding nodes corresponding to the main service function forwarding node in the plurality of service function forwarding nodes; A detection packet is sent to the main service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding standby service function forwarding node from the non-main service function forwarding node based on the detection packet after receiving the detection packet, and marks the corresponding standby service function forwarding node in the detection packet, and sends the marked detection packet to the corresponding standby service function forwarding node; wherein the detection packet contains node information of the non-main service function forwarding node, and any service function forwarding node in the target detection path is the main service function forwarding node or the non-main service function forwarding node.

2. The method of claim 1, wherein, Based on the attribute information corresponding to the plurality of service function forwarding nodes, a target detection path corresponding to a main service function forwarding node in the plurality of service function forwarding nodes is arranged, comprising: The service function forwarding nodes with the same attribute information as the main service function forwarding node in the plurality of service function forwarding nodes are used as the non-main service function forwarding nodes; If there are a plurality of non-main service function forwarding nodes, the target detection path is arranged based on the distance between the main service function forwarding node and each non-main service function forwarding node, and the distance between different non-main service function forwarding nodes; or If there is one non-main service function forwarding node, the main service function forwarding node is determined as the first hop in the target detection path, and the non-main service function forwarding node is determined as the second hop in the target detection path.

3. The method of claim 2, wherein, Based on the distance between the main service function forwarding node and each non-main service function forwarding node, and the distance between different non-main service function forwarding nodes, the target detection path is arranged, comprising: The main service function forwarding node is determined as the first hop in the target detection path; The remaining non-main service function forwarding node closest to the (n-1)th hop in the target detection path is determined as the nth hop in the target detection path; wherein 2≤n≤N, N is the total number of the main service function forwarding node and the non-main service function forwarding node in the target detection path; the remaining non-main service function forwarding node is the non-main service function forwarding node in the target detection path without a determined hop number.

4. The method according to any one of claims 1 to 3, characterized in that The announcement information is published by the plurality of service function forwarding nodes every preset time length.

5. A service chain protection method, applied to a target service function forwarding node, wherein the target service function forwarding node is any service function forwarding node in a service chain SFC domain, characterized in that: The method comprises: The announcement information carrying attribute information is published, so that the head node in the SFC domain arranges a target detection path corresponding to a main service function forwarding node in the multiple service function forwarding nodes based on attribute information corresponding to the multiple service function forwarding nodes after receiving the announcement information of the multiple service function forwarding nodes, and sends a detection packet to the main service function forwarding node; wherein the multiple service function forwarding nodes include the any service function forwarding node, and the attribute information represents the service type of the service function node agent by the service function forwarding node; the target detection path includes the main service function forwarding node and a non-main service function forwarding node in the multiple service function forwarding nodes corresponding to the main service function forwarding node; After receiving the target detection packet, the corresponding alternative service function forwarding node is determined from the non-main service function forwarding node based on the target detection packet; wherein the target detection packet contains node information of the non-main service function forwarding node; if the target service function forwarding node is the main service function forwarding node, the target detection packet is the detection packet sent by the head node; if the target service function forwarding node is the non-main service function forwarding node, the detection packet is the marked detection packet sent by the previous hop service function forwarding node in the target detection path; The corresponding alternative service function forwarding node is marked in the target detection packet, and the marked detection packet is sent to the corresponding alternative service function forwarding node.

6. The method of claim 5, wherein, If the target service function forwarding node is the main service function forwarding node, the corresponding alternative service function forwarding node is determined from the non-main service function forwarding node based on the target detection packet, including: The next hop non-main service function forwarding node in the target detection path is determined as the corresponding alternative service function forwarding node.

7. The method of claim 5, wherein, If the target service function forwarding node is the non-main service function forwarding node, the corresponding alternative service function forwarding node is determined from the non-main service function forwarding node based on the target detection packet, including: If there is an unmarked non-main service function forwarding node in the target detection packet, the next hop unmarked non-main service function forwarding node in the target detection packet is determined as the corresponding alternative service function forwarding node.

8. The method of claim 5, wherein, Marking the corresponding alternative service function forwarding node in the target detection packet includes: Marking the node information of the corresponding alternative service function forwarding node as occupied in the target detection packet.

9. The method of claim 5, wherein, Further comprising: After receiving the service packet, if the link between the target service function forwarding node and the corresponding service function node fails, the service packet is re-encapsulated, and the re-encapsulated service packet is sent to the corresponding alternative service function forwarding node.

10. The method of any one of claims 5 to 9, wherein, The announcement information is published by the multiple service function forwarding nodes every preset time interval.

11. A service chain protection device, applied to a head node in a service chain SFC domain, characterized in that, The device comprises: The attribute determining module is configured to determine attribute information corresponding to a plurality of service function forwarding nodes in the SFC domain after receiving announcement information published by the plurality of service function forwarding nodes, wherein the attribute information represents a service type of a service function node that the service function forwarding node proxies; The arrangement module is configured to arrange a target detection path corresponding to a master service function forwarding node in the plurality of service function forwarding nodes based on the attribute information corresponding to the plurality of service function forwarding nodes, wherein the target detection path includes the master service function forwarding node and non-master service function forwarding nodes corresponding to the master service function forwarding node in the plurality of service function forwarding nodes; The detection module is configured to send a detection packet to the master service function forwarding node, so that any service function forwarding node in the target detection path determines a corresponding candidate service function forwarding node from the non-master service function forwarding nodes based on the detection packet after receiving the detection packet, and marks the corresponding candidate service function forwarding node in the detection packet and sends the marked detection packet to the corresponding candidate service function forwarding node, wherein the detection packet contains node information of the non-master service function forwarding node, and the any service function forwarding node in the target detection path is the master service function forwarding node or the non-master service function forwarding node.

12. A service chain protection device, applied to a target service function forwarding node, wherein the target service function forwarding node is any service function forwarding node in a service chain SFC domain, characterized in that: The device comprises: The publishing module is configured to publish announcement information carrying attribute information, so that a head node in the SFC domain arranges a target detection path corresponding to a master service function forwarding node in a plurality of service function forwarding nodes based on attribute information corresponding to the plurality of service function forwarding nodes after receiving announcement information of the plurality of service function forwarding nodes, and sends a detection packet to the master service function forwarding node, wherein the plurality of service function forwarding nodes include the any service function forwarding node, the attribute information represents a service type of a service function node that the service function forwarding node proxies, and the target detection path includes the master service function forwarding node and non-master service function forwarding nodes corresponding to the master service function forwarding node in the plurality of service function forwarding nodes; The candidate determining module is configured to determine a corresponding candidate service function forwarding node from the non-master service function forwarding nodes based on a target detection packet after receiving the target detection packet, wherein the target detection packet contains node information of the non-master service function forwarding node, the target detection packet is a detection packet sent by the head node if the target service function forwarding node is the master service function forwarding node, and the detection packet is a marked detection packet sent by a previous hop service function forwarding node in the target detection path if the target service function forwarding node is a target non-master service function forwarding node; The candidate marking module is configured to mark the corresponding candidate service function forwarding node in the target detection packet and send the marked detection packet to the corresponding candidate service function forwarding node.

13. A head node, characterized by A computer program product comprising at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions executable by a computer to cause the computer to perform the method of any one of claims 1-4.

14. A service function forwarding node, characterized by, A computer program product comprising at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions executable by a computer to cause the computer to perform the method of any one of claims 5-10.

15. A computer-readable storage medium, characterized in that A computer program product comprising at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions executable by a computer to cause the computer to perform the method of any one of claims 1-4, or any one of claims 5-10.

Citation Information

Patent Citations

  • Method of selecting network function for data forwarding and service function forward (SFF)

    CN106209419A

  • Segment routing service processing method and device, routing equipment and storage medium

    CN112511427A