Flow Table Offloading System, Device, and Cluster

By extracting the common information of tunnel message headers and mirror message headers as pressed information in the cloud computing network, the problem of limited storage specifications of tunnel image messages is solved, and more efficient information storage and multiplexing is achieved.

CN119316350BActive Publication Date: 2025-06-20ZHUHAI XINGYUN ZHILIAN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411851306.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-06-20
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

The storage specifications of tunnel mirrored messages in cloud computing networks are limited, which leads to waiting for the original header information to be released before continuing to store after the pressed messages in the mirrored message header is used up, resulting in wasting time.

Method used

By extracting the common information of the tunnel message header and the mirror message header as the pressed information, only one pressed information is stored in the tunnel mirror space, thereby multiplexing it when needed and reducing the stored pressed information.

Benefits of technology

It effectively improves the specifications of the tunnel mirror space, reduces the time and resource waste of storing and managing pressed information, and improves the reuse rate of information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316350B_ABST
    Figure CN119316350B_ABST
Patent Text Reader

Abstract

The present application provides a flow table offloading system, device, and cluster. The system includes: a host, configured to offload a first flow table entry to the flow table space of the offloading hardware and offload first pushing information to the tunnel mirroring space of the offloading hardware, where the first flow table entry includes a first matching item and a first action item, the first action item includes a first index, the first index is associated with the first pushing information, and the first pushing information includes common information of a first tunnel packet header and a first mirror packet header; the offloading hardware is further configured to receive a first original packet, and when the packet header information of the first original packet matches the first matching item in the flow table space, obtain the first pushing information from the tunnel mirroring space according to the first index of the first action item, and add the first tunnel packet header and the first mirror packet header to the first original packet based on the first pushing information to obtain a first tunnel mirror packet.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and in particular, to a flow table offloading system, device, and cluster. Background Art

[0002] With the development of cloud computing networks, their extensive business requirements have led to the rapid growth of data centers, a sharp increase in data traffic, and the limitations of data forwarding through the virtual switches of hosts have become increasingly prominent, and it has become increasingly unable to meet the growing business requirements. To meet the high-performance service forwarding requirements, dedicated offloading hardware is required to carry the data forwarding service. There are many tunnel packets in cloud computing networks. Therefore, there are more and more push-in information of tunnel mirror packets for troubleshooting network faults. However, the storage specification of the push-in information of tunnel mirror packets is limited. Once it exceeds the 64 specifications of the push-in information of the original tunnel mirror packet header, it can only wait for the release of the push-in information of the original tunnel mirror packet header before continuing to store the push-in information of the mirror packet header, which greatly wastes time. Summary of the Invention

[0003] This application provides a flow table offloading system, device, and cluster, which can effectively improve the specification of the tunnel mirror space.

[0004] In a first aspect, a flow table offloading system is provided, including:

[0005] A host for offloading a first flow table entry to the flow table space of the offloading hardware and offloading first push-in information to the tunnel mirror space of the offloading hardware, where the first flow table entry includes a first matching item and a first action item, the first action item includes a first index, the first index is associated with the first push-in information, and the first push-in information includes the common information of a first tunnel packet header and a first mirror packet header;

[0006] The offloading hardware is further configured to receive a first original packet, and when the packet header information of the first original packet matches the first matching item in the flow table space, obtain the first push-in information from the tunnel mirror space according to the first index of the first action item, and add the first tunnel packet header and the first mirror packet header to the first original packet based on the first push-in information to obtain a first tunnel mirror packet.

[0007] In the above solution, since the tunnel header and the mirror header are basically the same, common information can be extracted from the first tunnel header and the first mirror header as the pushed-in information. This enables the offloading hardware to only fill in one copy of the pushed-in information in the tunnel mirror space and restore the tunnel header and the mirror header based on this pushed-in information, thereby reducing the number of pushed-in information that needs to be stored in the tunnel mirror space. For example, the specification of the compressed information of the tunnel header can be 8,000, and the specification of the compressed information of the mirror header can be 64. If the pushed-in information of the tunnel header and the pushed-in information of the mirror header are managed separately, once the 64 specifications of the pushed-in information of the mirror header are used up, it can only wait until the pushed-in information of the mirror header is released before continuing to store the pushed-in information of the mirror header, which greatly wastes time. Additionally, if the pushed-in information of the tunnel header and the pushed-in information of the mirror header are stored separately, when the tunnel header and the mirror header are the same, the host needs to send the pushed-in information to the offloading hardware twice. When there are many flow tables and a large traffic volume, the power consumption is greatly increased.

[0008] In some possible designs, the host is further configured to offload a second flow entry to the flow table space, where the second flow entry includes a second matching item and a second action item, and the second action item includes the first index.

[0009] The offloading hardware is further configured to receive a second original packet. When the packet header information of the second original packet matches the second matching item in the flow table space, the first pushed-in information is obtained from the tunnel mirror space according to the first index of the second action item, and the first tunnel header is added to the second original packet based on the first pushed-in information to obtain a first tunnel packet.

[0010] In the above solution, the pushed-in information in the tunnel mirror space can be provided not only for tunnel mirror packets but also for tunnel packets, which can further improve the reuse rate of the pushed-in information and further reduce the number of pushed-in information that needs to be stored in the tunnel mirror space.

[0011] In some possible designs, the host is further configured to offload a third flow entry to the flow table space and offload second pushed-in information to the tunnel mirror space, where the third flow entry includes a third matching item and a third action item, the third action item includes a second index, the second index is associated with the second pushed-in information, the second pushed-in information includes information of a second tunnel header, and the first pushed-in information and the second pushed-in information share the specification of the tunnel mirror space.

[0012] The unloading hardware is further configured to receive a third original packet. When the header information of the third original packet matches a third matching entry in the flow table space, the second pushing information is obtained from the tunnel mirror space according to the second index of the third action entry, and the second tunnel packet header is added to the third original packet based on the second pushing information to obtain a second tunnel packet.

[0013] In some possible designs, the host is further configured to unload a fourth flow table entry to the flow table space, where the fourth flow table entry includes a fourth matching entry and a fourth action entry, and the fourth action entry includes the first index;

[0014] The unloading hardware is further configured to receive a fourth original packet. When the header information of the fourth original packet matches a fourth matching entry in the flow table space, the first pushing information is obtained from the tunnel mirror space according to the first index of the fourth action entry, and the first mirror packet header is added to the fourth original packet based on the first pushing information to obtain a first mirror packet.

[0015] In the above solution, the pushing information in the tunnel mirror space can be provided not only for tunnel mirror packets but also for mirror packets, which can further improve the reuse rate of the pushing information and further reduce the amount of pushing information that needs to be stored in the tunnel mirror space.

[0016] In some possible designs, the host is further configured to unload a fifth flow table entry to the flow table space and unload third pushing information to the tunnel mirror space, where the fifth flow table entry includes a fifth matching entry and a fifth action entry, the fifth action entry includes a third index, the third index is associated with the third pushing information, the third pushing information includes information of a second mirror packet header, and the first pushing information and the third pushing information share the specification of the tunnel mirror space;

[0017] The unloading hardware is further configured to receive a fifth original packet. When the header information of the fifth original packet matches a fifth matching entry in the flow table space, the third pushing information is obtained from the tunnel mirror space according to the third index of the fifth action entry, and the second mirror packet header is added to the fifth original packet based on the third pushing information to obtain a second mirror packet.

[0018] In some possible designs, the first action entry further includes one or more modification actions;

[0019] The offloading hardware is further configured to, when the port identifier is an output port identifier, add the first tunnel packet header to the first original packet, perform the modification action on the first tunnel packet header to obtain a third tunnel packet header, copy the third tunnel packet header to obtain a third mirror packet header, and add the third mirror packet header to obtain an output port mirror packet.

[0020] In the above solution, editing actions need to be performed on the tunnel packet and the mirror packet respectively during output port mirroring. Therefore, when there are multiple modification actions in the action items of the flow table entries for generating the tunnel packet and the mirror packet from the original packet, the check value needs to be recalculated every time after modification. Especially when there are a large number of actions (up to 16), it is quite time-consuming and the efficiency is not high.

[0021] In some possible designs, the offloading hardware is further configured to, when the port identifier is an input port identifier, add the first tunnel packet header to the first original packet, copy the first tunnel packet header to obtain the first mirror packet header, and add the first mirror packet header to obtain an input port mirror packet.

[0022] In some possible designs, the first tunnel packet header and the first mirror packet header are the same except that the virtual network interface identifiers are different.

[0023] In a second aspect, a computing device is provided, including a flow table offloading system and a storage unit. Communication can be carried out between the flow table offloading system and the storage unit, and the flow table offloading system is the system according to any one of the first aspect.

[0024] In a third aspect, a computing device cluster is provided, including a plurality of computing devices. At least one computing device includes a flow table offloading system and a storage unit. Communication can be carried out between the flow table offloading system and the storage unit, and the flow table offloading system is the system according to any one of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the background art, the drawings required to be used in the embodiments of the present invention or the background art will be described below.

[0026] Figure 1 is a schematic structural diagram of a software-defined network (SDN) provided by the present application;

[0027] Figure 2 is a schematic structural diagram of a flow table offloading system provided by the present application;

[0028] Figure 3 is a schematic structural diagram of another flow table offloading system provided by the present application;

[0029] Figure 4 It is a schematic structural diagram of a tunnel mirror provided by this application;

[0030] Figure 5 It is a schematic structural diagram of a computing device provided by this application. Specific embodiments

[0031] The embodiments of the present invention will be described below with reference to the accompanying drawings in the embodiments of the present invention. The terms used in the embodiments part of the present invention are only used to explain the specific embodiments of the present invention, rather than aiming to limit the present invention.

[0032] See Figure 1 , Figure 1 It is a schematic structural diagram of an SDN provided by this application. As Figure 1 shown, the software-defined network of this application includes: an SDN controller 110 and an open virtual switch (OVS) 120.

[0033] The SDN controller 110 is a core component in the SDN architecture and is responsible for implementing centralized management and control of the entire network. The SDN controller separates the control plane and the data plane of the network, thus providing a more flexible, programmable, and scalable network management method. The main functions of the SDN controller include: managing the control plane of the entire network, including topology discovery, routing calculation, flow table distribution, etc. Specifically, the SDN controller 110 communicates with the OVS 120 to collect network topology information, calculates routes according to application requirements, and then distributes the flow tables to the OVS 120. Secondly, the SDN controller 110 can dynamically adjust the network routing selection and traffic distribution according to the characteristics and requirements of traffic, so as to achieve traffic load balancing, congestion control, and service quality guarantee; it can implement security measures such as access control, traffic filtering, and intrusion detection, and respond to network security events in a timely manner to protect the network from malicious attacks and data leakage threats, etc. The SDN controller 110 can be a physical device or a virtual device. When the number of SDN controllers 110 is multiple, it can also be a mixed use of physical devices and virtual devices. The SDN controller 110 can run on physical servers, virtual machines, containers, cloud platforms, and bare-metal servers.

[0034] OVS120 is an open-source virtual switch software that implements a flexible, programmable, and scalable switch platform for communicating with an SDN controller via the open-source OpenFlow protocol, receiving flow tables issued by the SDN controller 110, and forwarding and routing traffic according to the flow tables. OVS120 supports packet switching and routing in layer 2 and layer 3 networks. Therefore, OVS120 supports the processing of Ethernet data frames and packets, etc. OVS120 can run on physical servers, virtual machines, containers, cloud platforms, and bare-metal servers. OVS120 can also be used in combination with physical switches, etc.

[0035] Both the SDN controller 110 and OVS120 can be set in a container. In this case, the SDN controller 110 and OVS120 can be concentrated in the same container or distributed in different containers. Both the SDN controller 110 and OVS120 can be set in a virtual machine. In this case, the SDN controller 110 and OVS120 can be concentrated in the same virtual machine or distributed in different virtual machines. Both the SDN controller 110 and OVS120 can be set in a server. In this case, the SDN controller 110 and OVS120 can be concentrated in the same server or distributed in different servers. Both the SDN controller 110 and OVS120 can be set in a bare-metal server. In this case, the SDN controller 110 and OVS120 can be concentrated in the same bare-metal server or distributed in different bare-metal servers. Or, the SDN controller 110 is set in a container and OVS120 is set in any one of a virtual machine, a server, and a bare-metal server. The SDN controller 110 is set in a virtual machine and OVS120 is set in any one of a container, a server, and a bare-metal server. The SDN controller 110 is set in a server and OVS120 is set in any one of a container, a virtual machine, and a bare-metal server. The SDN controller 110 is set in a bare-metal server and OVS120 is set in any one of a container, a virtual machine, and a server.

[0036] The following will describe the process of transmitting a data packet from a source IP address to a destination IP address in combination with specific embodiments. First, the user can perform routing calculations on the SDN controller 110 based on the source IP address, destination IP address, and the network topology of the SDN to obtain a suitable forwarding path, and generate a flow table entry according to the forwarding path. Then, the SDN controller issues the flow table entry to the relevant OVS120. When the data packet arrives at the OVS120, the OVS120 will check its header information and match it with the matching items in the flow table entry. If the header information of the data packet can match the matching items, the OVS120 will forward the data packet according to the forwarding items in the flow table entry.

[0037] The above OVS120 is usually virtualized using the computing resources (e.g., processors), storage resources, and network resources (e.g., network cards) of a computing device. Moreover, to improve the forwarding performance of OVS120, it is often necessary to set up offloading hardware for acceleration. Therefore, a flow table offloading system can be composed of a processor, offloading hardware, and a network card. Refer to Figure 2 , Figure 2 which is a schematic structural diagram of a flow table offloading system provided by this application. As Figure 2 shown, the flow table offloading system of this application includes a processor 230, offloading hardware 220, and a network card 240.

[0038] The processor 230 is the operation core and control core, capable of handling complex situations. The processor 230 can be a very large scale integrated circuit. An operating system and other software programs are installed in the processor, so that the processor 230 can access the memory and various PCIE devices. The processor 230 can quickly access the memory through an on-chip bus. The processor can include one or more processor cores. In one implementation, the processor 230 can be a multi-core chip, that is, a chip containing multiple processing cores. In another implementation, the processor can include one or more processor cores. It can be a chip with one processing core. The OVS and the Data Plane Development Kit (DPDK) can run in the processor 230. For the introduction of OVS, refer to Figure 1 the relevant descriptions in. The efficiency of OVS in reading the memory is not high either. The lightweight library functions of DPDK adopt a very effective memory processing mechanism, that is, using a circular buffer to transfer data packets back and forth between the physical network card and the virtual switch using DPDK, thereby improving the overall performance of the system. OVS lacks optimization in processing high-speed data packets. Therefore, many steps in the process of data packet processing need to use the processor 230. Since the processor needs to handle multiple tasks, its availability (especially in the case of overload) will have a performance bottleneck problem. To reduce the number of processor interrupts required for data packet reading, DPDK adopts a periodic polling mechanism to regularly poll for new data packets. If the data packet rate drops to a very low value, then it can be switched to the interrupt mode instead of the periodic polling mode. Through effective cache management, optimized minimum CPU interrupt number, and other enhanced functions, DPDK can enable the virtual switch to achieve near-native performance.

[0039] The offloading hardware 220 is usually used to store flow tables and the like. The offloading hardware 220 can be a ternary content addressable memory (TCAM), a dynamic random access memory (DRAM), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a data processing unit (DPU), and so on. The offloading hardware 220 can also be other random access memories, such as a static random access memory (SRAM), etc. The number and type of the offloading hardware are not limited in this embodiment. In addition, the offloading hardware can be configured to have a power preservation function. The power preservation function means that when the system loses power and then powers on again, the data stored in the memory will not be lost.

[0040] The network card 240 is used to receive or send data packets. Since it has a media access control (MAC) address, it belongs to the layer between layer 1 and layer 2 of the open system interconnection (OSI) model. It enables users to connect to each other via cables or wirelessly. Each network card has a unique 48-bit serial number called the MAC address, which is written in a ROM on the card. Here, the network card can be a field programmable gate array (FPGA) network card, an application specific integrated circuit (ASIC) network card, and so on. The network card can interact with the virtual switch, that is, the network card can receive data packets from the virtual switch and can also send data packets to the virtual switch.

[0041] See Figure 3 , Figure 3 is a schematic structural diagram of another flow table offloading system provided by this application. As Figure 3 shown, the flow table offloading system of this application includes:

[0042] The first host 210 is used to offload the first flow table entry to the flow table space of the offloading hardware and offload the first pushing information to the tunnel mirroring space of the offloading hardware.

[0043] The first flow entry includes a first matching entry and a first action entry. The first action entry includes a first index. Optionally, the first index further includes one or more modification actions, such as modifying a Virtual Network Identifier (VIN), replacing a destination port (dport), Network Address Translation (NAT), Virtual Local Area Network (VLAN), destination MAC address, destination source IP address, etc. The first index is associated with first push-in information, and the first push-in information includes common information of a first tunnel header and a first mirror header. In a specific embodiment, the first push-in information includes a head size, layer 2 information, layer 3 information, port information, etc., where the layer 2 information includes a destination (Media Access Control Address, MAC) address, a source MAC address, a network type (dltype), etc. The layer 3 information includes a source Internet Protocol (IP) address, a destination IP address, an IP address type (proto), a Type of Service (ToS), a Time To Live (ttl), etc. The port information includes a source port number (sport), a destination port number (dport), etc. The first push-in information is derived from the common information of the first tunnel header and the first mirror header. In a specific embodiment, as Figure 4 shown, after the virtual machine 3.3.3.10 in the first host 210 sends a first tunnel packet to the physical function through an open switch, the first tunnel packet between the physical function and the second host 3.3.3.16 is encapsulated and forwarded through a tunnel with a source IP address of 7.7.7.7, a destination IP address of 7.7.7.9, and a virtual network identifier of 0xc8. When a link failure occurs between the virtual machine 3.3.3.10 in the first host 210 and the second host 3.3.3.16, it is necessary to copy a first tunnel packet between the virtual machine 3.3.3.10 and the second host to obtain a first tunnel mirror packet, and forward it to the mirror host 3.3.3.16 through mirror encapsulation with a source IP address of 7.7.7.7, a destination IP address of 7.7.7.9, and a virtual network identifier of 0x64. Then,

[0044] The information of the first tunnel header can be seen as follows:

[0045] clone(tnl_push(tnl_port(vxlan_sys_4789),header(size=50,type=4,eth(dst=B0:7B:25:18:7f:56,src=5a:2a:b7:8e:32:48,dl_type=0x0800),ipv4(src=7.7.7.7,dst=7.7.7.9,proto=17,tos=0,ttl=64,frag=0x4000),udp(src=0,dst=4789,csum=0x0),vxlan(flags=0x8000000,vni=0xc8)),out_port(br-ip)),dpdk-pf0).

[0046] The information of the first mirror packet header can be seen in the following text:

[0047] clone(tnl_push(tnl_port(vxlan_sys_4789),header(size=50,type=4,eth(dst=04:3f:72:9b:e3:9f,src=5a:2a:b7:8e:32:48,dl_type=0x0800),ipv4(src=7.7.7.7,dst=7.7.7.9,proto=17,tos=0,ttl=64,frag=0x4000),udp(src=0,dst=4789,csum=0x0),vxlan(flags=0x8000000,vni=0x64)),out_port(br-ip)),dpdk-pf0).

[0048] It is not difficult to see that the difference between the information of the first tunnel packet header and the first mirror packet header lies in the different virtual network identifiers (vnis).

[0049] In a possible embodiment, the first push-in information can be represented using a structure:

[0050] Struct tnl_mir_buf

[0051] {

[0052] Char date

[40] ;

[0053] int count;

[0054] }

[0055] Among them, the structure includes a character variable (date) of the character type (char). Since the length of the character variable is 8 bits, the total length of 40 character variables is 320. Among them, one bit is used to store the port identifier. When the port identifier is the first value, the port identifier is the output port identifier. When the port identifier is the second value, the port identifier is the input port identifier. The remaining 319 bits are used to store the first push-in information. The structure also includes an integer variable (count) of the integer type (int). The integer variable is used to store the number of times the first push-in information is referenced. The initial value of the integer variable is zero. Whenever the first push-in information is referenced, the count of the integer variable will be incremented by 1. Whenever the first push-in information is dereferenced, the count of the integer variable will be decremented by 1.

[0056] If the push-in information of the tunnel packet header and the push-in information of the mirror packet header are stored in different spaces and use different specifications respectively. For example, the push-in information of the tunnel packet header uses the specification of 8,000 push-in information, and the mirror packet header uses the specification of 64 push-in information. Then, once the 64 specifications of the push-in information of the mirror packet header are used up, it can only wait until the push-in information of the mirror packet header is released before continuing to store the push-in information of the mirror packet header, which greatly wastes time. However, in this application, the push-in information of the tunnel packet header and the mirror packet header share the same specification. Among them, sharing the same specification means that the corresponding storage space can be used by the push-in information of the tunnel packet header and also by the push-in information of the mirror packet header. When there is more push-in information of the tunnel packet header, it can occupy the storage space of the push-in information of the mirror packet header. When there is more push-in information of the mirror packet header, it can occupy the storage space of the push-in information of the tunnel packet header. That is to say, the shared specification is the common space for the push-in information of the tunnel packet header and the mirror packet header. For example, the push-in information of the tunnel packet header and the mirror packet header share the specification of 8,000 + 64. Then, when the push-in information of the mirror packet header even exceeds 64, it can still use the specification of 8,000, which will greatly reduce the wasted time. Moreover, there will also be no situation of resource waste caused by excessive pre-allocation. If 512 push-in information of the mirror packet header are pre-allocated, but the push-in information of the mirror packet header does not use so many and only uses 80, then there will be a waste of 432 push-in information of the mirror packet header.

[0057] Upon unloading, if the value of the integer variable in the structure is zero, then the tunnel mirror space has not stored the first push-in information, and the first push-in information can be unloaded into the tunnel mirror space. If the value of the integer variable in the structure is not zero, then the first push-in information has already been stored in the tunnel mirror space, and the value of the integer variable in the structure can be incremented by 1. Upon deletion, if the value of the integer variable in the structure is zero, then there is no longer a reference to the first push-in information in the tunnel mirror space, and the first push-in information in the tunnel mirror space can be deleted. If the value of the integer variable in the structure is not zero, then there is still a reference to the first push-in information in the tunnel mirror space, and the value of the integer variable in the structure can be decremented by 1.

[0058] Since the first tunnel packet header and the first mirror packet header data are basically the same, only one copy of the first push-in information needs to be downloaded in this solution. Therefore, the first host only needs to send it to the unloading hardware once, and for the other time, only increment the integer variable by 1. If the push-in information in the first tunnel packet header and the push-in information in the first mirror packet header are stored in different spaces respectively, it can effectively reduce the waste of space.

[0059] Since the first tunnel packet header and the first mirror packet header data are basically the same, the first push-in information only needs to be downloaded once. As long as the process of "if the value of the integer variable in the structure is zero, then the tunnel mirror space has not stored the first push-in information, and the first push-in information can be unloaded into the tunnel mirror space. If the value of the integer variable in the structure is not zero, then the first push-in information has already been stored in the tunnel mirror space, and the value of the integer variable in the structure can be incremented by 1" is executed once. Compared with the case where the push-in information in the first tunnel packet header and the push-in information in the first mirror packet header are stored in different spaces and two unloading processes need to be executed, it reduces the interaction between software and hardware registers by one time, reduces power consumption, and the effect is very significant when the number of flow table entries is relatively large.

[0060] Since the first tunnel packet header and the first mirror packet header data are basically the same, the first push-in information only needs to be deleted once. As long as the process of "if the value of the integer variable in the structure is zero, then there is no longer a reference to the first push-in information in the tunnel mirror space, and the first push-in information in the tunnel mirror space can be deleted. If the value of the integer variable in the structure is not zero, then there is still a reference to the first push-in information in the tunnel mirror space, and the value of the integer variable in the structure can be decremented by 1" is executed once. Compared with the case where the push-in information in the first tunnel packet header and the push-in information in the first mirror packet header are stored in different spaces and two deletion processes need to be executed, it reduces the interaction between software and hardware registers by one time, reduces power consumption, and the effect is very significant when the number of flow table entries is relatively large.

[0061] The offloading hardware 220 is also used to receive a first original packet. When the packet header information of the first original packet matches a first matching entry in the flow table space, the first pushing information is obtained from the tunnel mirror space according to the first index of the first action entry, and a first tunnel packet header and a first mirror packet header are added to the first original packet based on the first pushing information to obtain a first tunnel mirror packet.

[0062] Optionally, the first host 210 is also used to offload a second flow table entry to the flow table space. The second flow table entry includes a second matching entry and a second action entry, and the second action entry includes a first index. The offloading hardware 220 is also used to receive a second original packet. When the packet header information of the second original packet matches the second matching entry in the flow table space, the first pushing information is obtained from the tunnel mirror space according to the first index of the second action entry, and a first tunnel packet header is added to the second original packet based on the first pushing information to obtain a first tunnel packet. Here, in addition to being provided for use by the tunnel mirror packet, the first pushing information can also be provided for use by the tunnel packet, further improving the reuse rate of the first pushing information.

[0063] Optionally, the first host 210 is also used to offload a third flow table entry to the flow table space and offload second pushing information to the tunnel mirror space. The third flow table entry includes a third matching entry and a third action entry, the third action entry includes a second index, the second index is associated with the second pushing information, the second pushing information includes information of a second tunnel packet header, and the first pushing information and the second pushing information share the specifications of the tunnel mirror space. The offloading hardware 220 is also used to receive a third original packet. When the packet header information of the third original packet matches the third matching entry in the flow table space, the second pushing information is obtained from the tunnel mirror space according to the second index of the third action entry, and a second tunnel packet header is added to the third original packet based on the second pushing information to obtain a second tunnel packet. Here, the tunnel packet and the tunnel mirror packet also share the tunnel mirror space, which can more effectively improve the utilization rate of the pushing information in the shared tunnel mirror space.

[0064] Optionally, the first host 210 is also used to offload a fourth flow table entry to the flow table space. The fourth flow table entry includes a fourth matching entry and a fourth action entry, and the fourth action entry includes a first index. The offloading hardware 220 is also used to receive a fourth original packet. When the packet header information of the fourth original packet matches the fourth matching entry in the flow table space, the first pushing information is obtained from the tunnel mirror space according to the first index of the fourth action entry, and a first mirror packet header is added to the fourth original packet based on the first pushing information to obtain a first mirror packet. Here, in addition to being provided for use by the tunnel mirror packet, the first pushing information can also be provided for use by the mirror packet, further improving the reuse rate of the first pushing information.

[0065] Optionally, the first host 210 is further configured to unload a fifth flow table entry to the flow table space and unload third push-in information to the tunnel mirroring space, where the fifth flow table entry includes a fifth match item and a fifth action item, the fifth action item includes a third index, the third index is associated with the third push-in information, the third push-in information includes information of a second mirror packet header, and the first push-in information and the third push-in information share the specification of the tunnel mirroring space; the unloading hardware 220 is further configured to receive a fifth original packet, and when the packet header information of the fifth original packet matches the fifth match item in the flow table space, obtain the third push-in information from the tunnel mirroring space according to the third index of the fifth action item, and add a second mirror packet header to the fifth original packet based on the third push-in information to obtain a second mirror packet. Here, the mirror packet and the tunnel mirror packet also share the tunnel mirroring space, which can more effectively improve the utilization rate of the push-in information in the shared tunnel mirroring space.

[0066] Optionally, the offloading hardware 220 is further configured to, when the port identifier is an out-port identifier, add a first tunnel packet header to the first original packet, perform a modification action on the first tunnel packet header to obtain a third tunnel packet header, copy the third tunnel packet header to obtain a third mirror packet header, and add the third mirror packet header to obtain an out-port mirror packet. When the port identifier is an in-port identifier, add a first tunnel packet header to the first original packet, copy the first tunnel packet header to obtain a first mirror packet header, and add the first mirror packet header to obtain an in-port mirror packet. In the prior art solution, assuming that the modification actions include modifying the virtual network identifier, modifying the destination MAC address, modifying the virtual local area network, and modifying the destination IP address, then, add a first tunnel packet header to the first original packet, modify the virtual network identifier in the first tunnel packet header, recalculate the check value, modify the destination MAC address in the first tunnel packet header, recalculate the check value, modify the virtual local area network in the first tunnel packet header, recalculate the check value, modify the destination IP address in the first tunnel packet header, recalculate the check value. Add a first mirror packet header to the first tunnel packet header to obtain a first tunnel mirror packet, modify the virtual network identifier in the first mirror packet, recalculate the check value, modify the destination MAC address in the first mirror packet header, recalculate the check value, modify the virtual local area network in the first mirror packet header, recalculate the check value, modify the destination IP address in the first mirror packet header, recalculate the check value. It can be seen that the process of the prior art is very cumbersome, especially if there are many modification actions, the process is very performance-consuming. In this application, add a first tunnel packet header to the first original packet, modify the virtual network identifier in the first tunnel packet header, recalculate the check value, modify the destination MAC address in the first tunnel packet header, recalculate the check value, modify the virtual local area network in the first tunnel packet header, recalculate the check value, modify the destination IP address in the first tunnel packet header, recalculate the check value. Subsequently, directly check whether the out-port identifier on the first push-in information is an out-port identifier. If it is an out-port identifier, it means it is an out-port mirror. The packet header after editing the first mirror packet header should be the same as the packet header after editing the first tunnel packet header. Therefore, directly copy the currently edited first tunnel packet and add it to the first tunnel packet, and recalculate the check value.

[0067] See Figure 5 , Figure 5 FIG. is a schematic structural diagram of a computing device provided by this application. The computing device 400 includes: one or more processing units 410, a communication interface 420, and a storage unit 430.

[0068] The processing unit 410, the communication interface 420, and the storage unit 430 are interconnected via a bus 440. Optionally, the computing device 400 may further include an input / output interface 450, which is connected to input / output devices for receiving parameters set by the user, etc. The computing device 400 can be used to implement some or all of the functions of the device embodiments or system embodiments in the embodiments of the present application described above; the processing unit 410 can also be used to implement some or all of the operation steps of the method embodiments in the embodiments of the present application described above. For example, the specific implementation of the computing device 400 performing various operations can refer to the specific details in the above embodiments. For example, the processing unit 410 is used to execute some or all of the steps or some or all of the operations in the above method embodiments. Another example is that in the embodiments of the present application, the computing device 400 can be used to implement some or all of the functions of one or more components in the above device embodiments. In addition, the communication interface 420 can specifically be used for communication functions necessary to implement the functions of these devices and components, etc., and the processing unit 410 can specifically be used for processing functions necessary to implement the functions of these devices and components, etc.

[0069] Figure 5 The computing device 400 may include one or more processing units 410, and the multiple processing units 410 may cooperate to provide processing capabilities in a parallel connection mode, a serial connection mode, a serial-parallel connection mode, or any connection mode. Or the multiple processing units 410 may form a processor sequence or a processor array, or the multiple processing units 410 may be divided into a main processor and an auxiliary processor, or the multiple processing units 410 may have different architectures, such as using a heterogeneous computing architecture. Additionally, Figure 5 For the computing device 400 shown, the related structural descriptions and functional descriptions are exemplary and non-limiting. In some exemplary embodiments, the computing device 400 may include more or fewer components than Figure 5 shown, or combine certain components, or split certain components, or have a different component arrangement.

[0070] The processing unit 410 may have various specific implementation forms. For example, the processing unit 410 may include one or a combination of a central processing unit (CPU), a graphic processing unit (GPU), a neural-network processing unit (NPU), a tensor processing unit (TPU), or a data processing unit (DPU), etc., and the embodiments of the present application do not make specific limitations. The processing unit 410 may also be a single-core processor or a multi-core processor. The processing unit 410 may be a combination of a CPU and a hardware chip. The above hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processing unit 410 may also be implemented by a logic device with built-in processing logic alone, such as an FPGA or a digital signal processor (DSP), etc. The communication interface 420 may be a wired interface or a wireless interface for communicating with other modules or devices. The wired interface may be an Ethernet interface, a local interconnect network (LIN), etc., and the wireless interface may be a cellular network interface or a wireless local area network interface, etc.

[0071] The storage unit 430 may be a non-volatile memory, for example, a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The storage unit 430 may also be a volatile memory, and the volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). The storage unit 430 can also be used to store program code and data, so that the processing unit 410 can call the program code stored in the storage unit 430 to execute some or all of the operation steps in the above method embodiments, or execute the corresponding functions in the above device embodiments. In addition, the computing device 400 may include more or fewer components than Figure 5 shown, or have a different component configuration.

[0072] The bus 440 may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a Unified bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), etc. The bus 440 can be divided into an address bus, a data bus, a control bus, etc. In addition to including a data bus, the bus 440 may also include a power bus, a control bus, and a status signal bus, etc. However, for the sake of clarity,Figure 5 It is represented only by a thick line in the figure, but it does not mean that there is only one bus or one type of bus.

[0073] The embodiment of the present application further provides a system, which includes a plurality of computing devices. The structure of each computing device can refer to the structure of the computing device described above. The functions or operations that the system can implement can refer to the specific implementation steps in the above method embodiment and / or the specific functions described in the above device embodiment, which will not be elaborated here.

[0074] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one network site, computer, server, or data center to another network site, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line) or a wireless manner (such as infrared, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape, etc.), an optical medium (such as a DVD, etc.), or a semiconductor medium (such as a solid-state drive), etc. In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

Claims

1. A flow table unloading system, characterized in that: include: A host, configured to unload a first flow table entry to a flow table space of unloading hardware, and unload first push information to a tunnel mirror space of the unloading hardware, wherein the first flow table entry includes a first matching item and a first action item, the first action item includes a first index, the first index is associated with the first push information, the first push information includes common information of a first tunnel message header and a first mirror message header, the first push information and a first virtual network interface identifier constitute the first tunnel message header, and the first push information and a second virtual network interface constitute the first mirror message header; The uninstall hardware is also used to receive a first original message, and when the message header information of the first original message matches the first matching item in the flow table space, obtain the first push information from the tunnel mirror space according to the first index of the first action item, add the first tunnel message header to the first original message based on the first push information and the first virtual network interface identifier, and add the first mirror message header based on the first push information and the second virtual network interface to obtain a first tunnel mirror message; The first action item also includes one or more modification actions; The offloading hardware is further used for, when the port identifier is an egress port identifier, adding the first tunnel message header to the first original message, performing the modification action on the first tunnel message header to obtain a third tunnel message header, copying the third tunnel message header to obtain a third mirror message header, and adding the third mirror message header to obtain an egress port mirror message; The offloading hardware is further used for, when the port identifier is an inbound port identifier, adding the first tunnel message header to the first original message, copying the first tunnel message header to obtain the first mirror message header, and adding the first mirror message header to obtain an inbound port mirror message; The host is further configured to unload a second flow table entry to the flow table space, wherein the second flow table entry includes a second matching item and a second action item, and the second action item includes the first index; The offloading hardware is also used to receive a second original message. When the message header information of the second original message matches the second matching item in the flow table space, the first push information is obtained from the tunnel mirror space according to the first index of the second action item, and the first tunnel message header is added to the second original message based on the first push information and the first virtual network interface identifier to obtain a first tunnel message.

2. The system according to claim 1, characterized in that The host is further used to unload a third flow table entry to the flow table space, and unload the second push information to the tunnel mirror space, wherein the third flow table entry includes a third matching item and a third action item, the third action item includes a second index, the second index is associated with the second push information, the second push information includes information of a second tunnel message header, and the first push information and the second push information share the specification of the tunnel mirror space; The offloading hardware is also used to receive a third original message. When the message header information of the third original message matches the third matching item in the flow table space, the second push information is obtained from the tunnel mirror space according to the second index of the third action item, and the second tunnel message header is added to the third original message based on the second push information to obtain a second tunnel message.

3. The system according to claim 1, characterized in that The host is further configured to unload a fourth flow table entry to the flow table space, wherein the fourth flow table entry includes a fourth matching item and a fourth action item, and the fourth action item includes the first index; The offloading hardware is also used to receive a fourth original message. When the message header information of the fourth original message matches the fourth matching item in the flow table space, the first push information is obtained from the tunnel mirror space according to the first index of the fourth action item, and the first mirror message header is added to the fourth original message based on the first push information and the second virtual network interface identifier to obtain a first mirror message.

4. The system according to claim 3, characterized in that The host is further used to unload the fifth flow table entry to the flow table space, and unload the third push information to the tunnel mirror space, wherein the fifth flow table entry includes a fifth matching item and a fifth action item, the fifth action item includes a third index, the third index is associated with the third push information, the third push information includes information of the second mirror message header, and the first push information and the third push information share the specification of the tunnel mirror space; The offloading hardware is also used to receive a fifth original message, and when the message header information of the fifth original message matches the fifth matching item in the flow table space, the third push information is obtained from the tunnel mirror space according to the third index of the fifth action item, and the second mirror message header is added to the fifth original message based on the third push information to obtain a second mirror message.

5. A computing device, characterized in that: It comprises a flow table unloading system and a storage unit, the flow table unloading system and the storage unit can communicate with each other, and the flow table unloading system is a system as described in any one of claims 1-4.

6. A computing device cluster, characterized in that: It includes multiple computing devices, at least one computing device includes a flow table unloading system and a storage unit, the flow table unloading system and the storage unit can communicate with each other, and the flow table unloading system is a system as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Tunnel encapsulation table resource management method, DPU and related equipment

    CN116996478A