A message processing apparatus and method

By using a hardware-offloaded VLAN tag identification, filtering, and insertion module, the problems of low efficiency in software-driven systems and hardware insertion errors are solved, achieving efficient and secure VLAN tag management and improving the performance and security of the network system.

CN119420528BActive Publication Date: 2025-11-14WUXI STARS MICRO SYSTEM TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411533730.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-11-14
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

In existing technologies, software-driven insertion of VLAN tags is inefficient, while hardware-driven insertion of VLAN tags is prone to errors and is susceptible to VLAN attacks.

Method used

By employing a hardware offloading approach, through a VLAN tag identification module, a VLAN tag filtering module, and a VLAN tag insertion module, the hardware can automatically identify VLAN tag types, insertion locations, and filter tags that do not meet expectations, thereby improving insertion efficiency and security.

Benefits of technology

It improves the efficiency and accuracy of VLAN tag insertion, enhances the security and robustness of the network system, reduces software resource consumption, and supports the management of different types and levels of VLAN tags.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420528B_ABST
    Figure CN119420528B_ABST
Patent Text Reader

Abstract

This application provides a packet processing apparatus and method. The apparatus includes a VLAN tag identification module, a VLAN tag filtering module, and a VLAN tag insertion module. The VLAN tag identification module identifies the original packet and outputs identification information. The identification information includes VLAN tag carrying information in the original packet, VLAN tag insertion location information in the original packet, and the original inner and outer attributes of the carried VLAN tag. The VLAN tag filtering module filters the original packet according to pre-configured VLAN filtering configuration information and the identification information. The filtering process includes discarding, modifying and allowing, or directly allowing. The VLAN tag insertion module inserts a new VLAN tag into the original packet according to pre-configured VLAN insertion configuration information and the identification information. This application improves the efficiency of VLAN insertion into packets through hardware offloading.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network chip technology, and specifically relates to a message processing device and method. Background Technology

[0002] VLAN (Virtual Local Area Network) is a technology that logically divides a physical local area network (LAN) into multiple independent broadcast domains. It allows network administrators to divide a physical LAN into multiple logical LANs, each VLAN being an independent broadcast domain. VLAN technology can divide a large network into multiple smaller LANs, effectively controlling broadcast traffic, improving network security and performance, and enhancing network performance and flexibility. Summary of the Invention

[0003] The purpose of this application is to provide a message processing device and method to solve technical problems such as low efficiency of software-driven VLAN tag insertion, easy errors in hardware-driven VLAN tag insertion, and VLAN attacks.

[0004] According to a first aspect of this application, a message processing apparatus is provided, comprising: a VLAN tag identification module, a VLAN tag filtering module, and a VLAN tag insertion module; wherein,

[0005] The VLAN tag identification module is used to identify the original packet and output identification information; the identification information includes the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag;

[0006] The VLAN tag filtering module is used to filter the original packets according to the pre-configured VLAN filtering configuration information and identification information; the filtering process includes discarding, modifying and allowing, or allowing directly;

[0007] The VLAN tag insertion module inserts a new VLAN tag into the original message based on the pre-configured VLAN insertion configuration information and the identification information.

[0008] In an optional implementation,

[0009] If the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message.

[0010] If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted.

[0011] If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted.

[0012] If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered.

[0013] If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

[0014] In an optional implementation, the VLAN filtering configuration information includes the filtering mode corresponding to the VLAN filtering level; the VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs.

[0015] If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0016] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode and then allowing it to pass.

[0017] If the filtering mode corresponding to the original packet is replacement mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0018] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0019] If the filtering mode corresponding to the original packet is the desired mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet.

[0020] If the filtering mode corresponding to the original packet is the discard mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet.

[0021] If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0022] In an optional implementation, if the VLAN tag insertion position information in the identification information is at the Layer 2 packet location, the VLAN tag insertion module will offset the set insertion position corresponding to the new VLAN tag by the set length corresponding to the Layer 2 packet.

[0023] If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second.

[0024] If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

[0025] In an optional implementation, if the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then if the original inner and outer layer attributes are inner layer and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0026] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet.

[0027] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet.

[0028] If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0029] In an optional implementation, if the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not not carried, then if the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet; and if the original inner and outer layer attributes are double-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support double-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet.

[0030] According to a second aspect of this application, a message processing method is provided, comprising:

[0031] The VLAN tag identification module identifies the original packet and outputs identification information; the identification information includes the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag;

[0032] The VLAN tag filtering module filters the original packets based on pre-configured VLAN filtering information and the identification information; the filtering process includes discarding, modifying and allowing, or allowing directly.

[0033] The VLAN tag insertion module inserts a new VLAN tag into the original packet based on the pre-configured VLAN insertion configuration information and the identification information.

[0034] In an optional implementation, the VLAN tag identification module identifies the original packet and outputs identification information, including:

[0035] If the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message.

[0036] If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted.

[0037] If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted.

[0038] If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered.

[0039] If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

[0040] In an optional implementation, the VLAN filtering configuration information includes filtering modes corresponding to VLAN filtering levels; the VLAN tag filtering module filters the original packets according to the pre-configured VLAN filtering configuration information and the identification information, including:

[0041] The VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs.

[0042] If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module will directly allow the original packet to pass.

[0043] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs filtering processing on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode, and then allowing it to pass.

[0044] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carries no information, then the VLAN tag filtering module will directly allow the original packet to pass.

[0045] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module will directly allow the original packet to pass.

[0046] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is not carried, then the VLAN tag filtering module will discard the original packet.

[0047] If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs a drop filtering process on the original packet.

[0048] If the filtering mode corresponding to the original packet is the drop mode and the VLAN tag information is not carried, then the VLAN tag filtering module will directly allow the original packet to pass.

[0049] In an optional implementation, the VLAN tag insertion module inserts a new VLAN tag into the original packet based on pre-configured VLAN insertion configuration information and the identification information, including:

[0050] If the VLAN tag insertion position information in the identification information is at the Layer 2 packet, then the VLAN tag insertion module will offset the set insertion position corresponding to the new VLAN tag by the set length corresponding to the Layer 2 packet.

[0051] If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second.

[0052] If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

[0053] In an optional implementation, the VLAN tag insertion module inserts the new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, including:

[0054] If the original inner and outer layer attributes are inner layer, and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0055] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet.

[0056] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet.

[0057] If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0058] In an optional implementation, the VLAN tag insertion module inserts the new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, and further includes:

[0059] If the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet. If the original inner and outer layer attributes are two-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support two-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet.

[0060] Compared with related technologies, the technical solution of this application has the following advantages:

[0061] 1. Compared to software-based VLAN tag insertion, this application effectively improves the efficiency of VLAN tag insertion through hardware offloading. When the system has multiple queues, hardware-based VLAN tag insertion offers even greater efficiency improvements, freeing up resources previously allocated to software calculation and management of VLAN tags. In related technologies, hardware directly inserts VLAN tags after the MAC source address in the L2 header. This method disregards the outer and inner attributes of the VLAN tag, potentially leading to incorrect tag placement order in the L2 header. This application ensures correct VLAN insertion by accurately identifying the VLAN tag type and insertion position.

[0062] 2. By automatically identifying VLAN tag types through hardware, the hardware can filter out untrusted VLAN tags or directly discard packets. This approach can solve the problems of virtual machine VLAN attacks and VLAN priority traffic preemption, improving the overall system security and robustness.

[0063] 3. Hardware filtering offers high flexibility in VLAN hierarchy, allowing for selection of different granular filtering configurations through software configuration; hardware VLAN filtering modes are flexibly configurable, enabling the selection of different VLAN filtering methods based on different service types, increasing the software's control over hardware, and reducing the software's resource consumption for VLAN tag management.

[0064] 4. Flexible hardware insertion of VLAN tags, supporting insertion of different types of VLAN tags, dual-layer / multi-layer VLAN tag insertion, and management of insertion of VLAN tags at different levels.

[0065] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures and processes shown in the description and the accompanying drawings. Attached Figure Description

[0066] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0067] Figure 1 This is a schematic diagram of an Ethernet frame format carrying a VLAN tag, based on relevant technologies.

[0068] Figure 2 This is a schematic diagram of the structure of a message processing apparatus according to an exemplary embodiment of this application.

[0069] Figure 3 This is a schematic diagram of software configuration information according to an exemplary embodiment of this application.

[0070] Figure 4 This is a schematic diagram of the identification process of a VLAN tag identification module according to an exemplary embodiment of this application.

[0071] Figure 5 This is a schematic diagram of the filtering process of a VLAN tag filtering module according to an exemplary embodiment of this application.

[0072] Figure 6 This is a schematic diagram of the insertion process of a VLAN tag insertion module according to an exemplary embodiment of this application.

[0073] Figure 7 This is a schematic flowchart of a message processing method according to an exemplary embodiment of this application. Detailed Implementation

[0074] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0075] VLANs work by implementing logical segmentation at the data link layer, distinguishing data packets from different VLANs by adding VLAN tags (as defined in the IEEE 802.1Q standard) to Ethernet frames. The VLAN frame format is as follows: Figure 1 As shown, the first fields are the MAC destination address and the MAC source address, followed by the VLAN tag. Figure 1 The image shows a VLAN tag of type 802.1QTag.

[0076] With the development of VLAN technology, in order to divide more local area networks (LANs), Ethernet in related technologies supports network frame formats with two or even multiple VLAN layers. Simultaneously, with the development of network hardware, network cards can now support multiple queues (such as 2K, 4K, 8K, and 16K) of packet transmission and simultaneous insertion of VLAN tags. The implementation methods of VLAN technology in related technologies include two types: 1. Upper-layer software directly inserts VLAN tags into packets; 2. Software drivers control hardware to insert VLAN tags into packets (this method can be called hardware offloading). The inventors of this application, through research and understanding, found that older graphics cards generally only support software-inserted VLAN tags, while only newer or mid-to-high-performance network cards support hardware-inserted VLAN tags.

[0077] Furthermore, since existing network interface cards (NICs) can support multiple queues (such as 2K, 4K, 8K, and 16K) for packet transmission, different queues are typically opened to upper-layer software or virtual machines (VMs) for packet transmission. Because upper-layer software or VMs may send unreliable data, VLAN attacks and other problems exist during system operation. Therefore, the host needs to identify and filter packets carrying problematic VLAN tags, a process usually implemented in software. However, most NIC hardware does not support VLAN identification and filtering.

[0078] In summary, the relevant technologies have the following problems:

[0079] 1. Software-based VLAN tag insertion is inefficient. As the types of VLAN tags to be inserted increase and the number of queues supported by the network card grows, the software needs to consume a lot of resources to insert and manage VLAN tags in the original packets.

[0080] 2. Low accuracy of hardware-based VLAN tag insertion. Most network cards supporting hardware VLAN tag insertion lack the ability to accurately identify and correctly insert VLAN tags. Typically, network cards directly insert VLAN tags after the MAC source address in the link layer (L2) header. This method disregards the outer and inner attributes of the VLAN tag, leading to incorrect tag placement order in the header. Furthermore, the hardware doesn't recognize the type of VLAN tag carried in the original packet, directly inserting VLAN tags through software control, resulting in multiple VLAN tags of the same type in a single packet.

[0081] 3. The network card lacks VLAN filtering functionality. Existing network cards can support multiple queues for packet transmission, which makes VLAN attack prevention in both hardware and software more difficult.

[0082] Based on the above analysis, this application proposes a hardware-offload-based VLAN tag insertion and filtering scheme. After the hardware operating mode is configured in the software, the scheme utilizes hardware identification of the VLAN tag type carried in the packet and determination of the VLAN tag insertion location to achieve automatic VLAN tag insertion and filtering of unexpected VLAN tags. This solves the technical problems of low efficiency in software-driven VLAN tag insertion and susceptibility to errors and VLAN attacks in hardware-driven VLAN tag insertion. This application can enhance the efficiency of VLAN tag insertion for network cards and improve the security of network cards.

[0083] See Figure 2 As shown, this application exemplarily proposes a message processing apparatus, including: a VLAN tag identification module, a VLAN tag filtering module, and a VLAN tag insertion module; wherein,

[0084] The VLAN tag identification module is used to identify the original packet and output identification information; the identification information includes the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag;

[0085] The VLAN tag filtering module is used to filter the original packets according to the pre-configured VLAN filtering configuration information and identification information; the filtering process includes discarding, modifying and allowing, or allowing directly;

[0086] The VLAN tag insertion module inserts a new VLAN tag into the original message based on the pre-configured VLAN insertion configuration information and the identification information.

[0087] For example, in this application, the storage content of the corresponding VLAN tag insertion register can be pre-configured by software. There are multiple types of VLAN tags, and each type of VLAN tag can correspond to an insertion register. The storage content of the insertion register includes the content of the VLAN tag of that type, such as VLAN tag type, identifier, inner and outer layer attributes, etc. In this way, the granularity of VLAN tag insertion can be flexibly selected, including TC (Traffic Category), Queue, and VSI (Virtual Switching Interface). This granularity can be understood as the layer to which the original packet belongs.

[0088] For example, this application identifies VLAN tags in the original packets using hardware. This includes identifying whether the original packets contain VLAN tags, the types of VLAN tags, the number of VLAN tags, and the inner and outer attributes of the VLAN tags. Since VLAN tags may have been pre-inserted into the original packets by software, this step requires hardware to first identify the VLAN tags that the original packets may carry and output the identification information. For example, this identification process can be implemented by a VLAN tag identification module in the packet processing device, and the identified information can be used as identification information by the VLAN tag filtering module and VLAN tag insertion module of the packet processing device.

[0089] For example, this application configures VLAN filtering information through software, so that the hardware can choose to discard, allow, or modify the original packet based on the VLAN filtering configuration information configured in the software and the identification information output by the VLAN tag identification module. This process implements VLAN anti-attack functionality and can improve system security. For example, this filtering process can be implemented by the VLAN tag filtering module in the packet processing device.

[0090] For example, this application determines the number and insertion position of new VLAN tags based on the original inner and outer layer attributes of the VLAN tags carried in the original packets identified by the hardware, as well as whether the software configuration supports dual / multi-layer VLANs and the new inner and outer layer attributes of the new VLAN tags. This process ensures the accuracy of VLAN tag insertion. For example, this filtering process can be implemented by a VLAN tag insertion module in a packet processing device.

[0091] The following is through Figure 3 Examples of software configuration information are provided.

[0092] For example, the software configuration information may include VLAN insertion configuration information, which may include the following parts:

[0093] VLAN insertion level: This determines the hardware's processing level for raw packets. For example, if TC-level insertion is configured, the hardware uses the same insertion configuration for raw packets belonging to the same TC (Traffic Category). VLAN insertion levels can include, but are not limited to, TC (Traffic Category), TX Queue (Transmission Queue), and VSI (Virtual Switch Interface).

[0094] VLAN Insertion Type: This determines the type of VLAN tag that the software controls the hardware to insert. This can include, but is not limited to, 0x88A8 (STAG), 0x8100 (802.1Q TAG), 0x9100 (outer tag of 802.1QinQ), and other custom tags.

[0095] VLAN insertion layer number: This determines the maximum number of VLAN layers that the hardware can insert. VLAN insertion layers can include single-layer, two-layer, and multi-layer (i.e., more than two layers) VLAN tags.

[0096] VLAN Insertion Location: This section allows configuration of optional insertion locations. First, hardware automatic identification means the software does not interfere with the actual insertion location of the VLAN. The hardware automatically identifies the new VLAN tag's insertion location within the original packet based on the original inner / outer layer attributes of the VLAN tag carried in the original packet, and selects the designated insertion location from the software-configured VLAN insertion locations. For example, if the hardware determines to insert the new VLAN tag into the innermost layer, it will always insert the new VLAN tag into the designated insertion location corresponding to the innermost layer. In this case, the designated insertion location can be the position farthest from the MAC source address. Alternatively, if the hardware determines to insert the new VLAN tag into the outermost layer, it will always insert the new VLAN tag into the designated insertion location corresponding to the outermost layer. In this case, the designated insertion location can be the position closest to the MAC source address.

[0097] For example, the software configuration information may also include VLAN filtering configuration information, which may include the following parts:

[0098] VLAN filtering level: This determines the level at which the hardware filters raw packets. For example, configuring VSI-level filtering means that the VLAN filtering mode will be applied at the same VSI level. VLAN filtering levels can include, but are not limited to, TC (Traffic Category), TX Queue, and VSI (Virtual Switch Interface).

[0099] VLAN filtering mode: This is a configurable filtering method. VLAN filtering modes include the following:

[0100] Accept mode: If the corresponding VLAN filtering level is configured to accept mode, the hardware accepts the content of all original packets belonging to that filtering level. That is, regardless of whether the original packet carries a VLAN tag, the hardware will not modify the original packet or mark it as discarded, but will allow it to pass directly.

[0101] Replacement Mode: If replacement mode is configured for the corresponding VLAN filtering level, the hardware replaces the VLAN tag content carried by the original packets belonging to that filtering level. The replacement content includes the PFI, CFI, and VLAN ID fields in the VLAN tag. The content of these fields is configured by the software. If the original packet does not carry a VLAN tag, the hardware does not make any modifications to the original packet. In replacement mode, the original packet will not be marked for discard, meaning the original packet will not be discarded.

[0102] Expected Mode: If the expected mode is configured for the corresponding VLAN filtering level, the VLAN tag type corresponding to the expected mode also needs to be set. If the VLAN tag of this type is detected in the original packet belonging to this filtering level, the expectation is considered successful and the hardware will send the original packet normally. If the original packet does not carry the VLAN tag of this type, the expectation is considered to have failed and the hardware will discard the original packet.

[0103] Drop mode: If the corresponding VLAN filtering level is configured with drop mode, the VLAN tag type corresponding to the drop mode also needs to be set. If the VLAN tag of this type is detected in the original packet belonging to this filtering level, the hardware will drop the original packet. If the original packet does not carry the VLAN tag of this type, the hardware will send the original packet normally.

[0104] In some optional implementations, if the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message.

[0105] If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted.

[0106] If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted.

[0107] If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered.

[0108] If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

[0109] The following is combined Figure 4 The hardware identification process is illustrated by example.

[0110] See Figure 4 As shown, for example, the VLAN tag identification module identifies the original packet according to the following process and outputs identification information. This identification information may include, but is not limited to, the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag:

[0111] Step 1: Detect the ETYPE field following the MAC source address (DA / SA) of the original packet, which identifies the Ethernet frame protocol type. Check if the content of the ETYPE field is a combination of BVLAN (0x88a8) and ITAG (0x88E7), i.e., check if the ETYPE field is a MAC-in-MAC tag. If it is a MAC-in-MAC tag, it indicates that the original packet contains a nested Layer 2 packet. If it is not a MAC-in-MAC tag, determine if the ETYPE field after the source address of the original packet contains a VLAN tag, and then proceed to Step 2. If it is a MAC-in-MAC tag, then proceed to Step 6.

[0112] Step 2: If no VLAN tag exists, end the detection process and record the VLAN tag information carried in the original packet as "not carried," and the VLAN tag insertion location information as "unrestricted." If a VLAN tag exists, proceed to Step 3.

[0113] Step 3: Check if the VLAN tag is equal to the first set tag type, such as an NHoe tag (the tag for the destination MAC address in a MAC packet) or an MPLS tag (Multiprotocol Label Switching). If it is equal to an NHoe tag or an MPLS tag, record the VLAN tag insertion location information as unrestricted. If it is not equal to an NHoe tag or an MPLS tag, continue to step 4;

[0114] Step 4: Check if the VLAN tag is equal to the second set type of tag, such as whether it is a tag of type 0x8100, 0x9100, or 0x88a8. If it is not equal to the second set type, end the detection and record the VLAN tag insertion location information as unrestricted and / or the VLAN tag carrying information as not carried. If it is equal to the second set type, it means that there may be inner VLAN tags, in which case proceed to step 5.

[0115] Step 5: Check if an inner VLAN tag exists. For example, check if the ETYPE after the second specified type tag in a Layer 2 packet is equal to the 0x8100 tag. If it does not exist, end the detection and record the original inner / outer layer attribute as outer layer, meaning the original packet only carries the outer VLAN tag. If it exists, end the detection and record the original inner / outer layer attribute as double layer, meaning the original packet carries double VLAN tags.

[0116] Step Six: Check the ETYPE field after the MAC source address (DA / SA) of the Layer 2 packet to determine if a VLAN tag exists, and then proceed to Step Two. This step can also refresh the insertion position of the new VLAN tag, that is, offset the software-configured insertion position from the set length of the Layer 2 packet. Alternatively, you can simply identify the original packet nested with a Layer 2 packet, and temporarily not refresh the insertion position of the new VLAN tag; instead, the VLAN tag insertion module will refresh the insertion position.

[0117] In some optional implementations, the VLAN filtering configuration information includes the filtering mode corresponding to the VLAN filtering level; the VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs.

[0118] If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0119] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode and then allowing it to pass.

[0120] If the filtering mode corresponding to the original packet is replacement mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0121] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0122] If the filtering mode corresponding to the original packet is the desired mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet.

[0123] If the filtering mode corresponding to the original packet is the discard mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet.

[0124] If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

[0125] The following is combined Figure 5 This example illustrates the filtering process for the raw message.

[0126] See Figure 5 As shown, for example, the VLAN tag filtering module filters the original packets according to the following process:

[0127] Step 1: The hardware determines the packet processing level based on the VLAN filtering configuration information in the software configuration and the VLAN filtering mode configured for that filtering level. The filtering levels include Traffic Category (TC), Virtual Switch Interface (VSI), and Transmission Queue (TX Queue).

[0128] Step 2: Determine if the filtering level is the same as the level of the original packet, and if the corresponding filtering mode is accept mode. If it is accept mode, the hardware will not modify the original packet and will end the VLAN filtering process. If it is not accept mode, proceed to Step 3.

[0129] Step 3: Determine if the filtering level is the same as the level of the original packet, and whether the corresponding filtering mode is replacement mode. If it is replacement mode, the hardware replaces the VLAN tag carried in the original packet. The replacement content includes the PRI, CFI, and VLAN ID field segment in the VLAN tag. If the original packet does not carry a VLAN tag, the hardware does not make any modifications to the original packet and ends the hardware filtering process. If it is not replacement mode, proceed to Step 4.

[0130] Step 4: Determine if the filtering level is the same as the level of the original packet, and if the corresponding filtering mode is the expected mode. If it is equal to the expected mode, and the hardware does not detect that the original packet carries the VLAN tag type corresponding to the expected mode, then the expectation is considered to have failed, and the original packet is discarded. If the original packet is detected to carry the VLAN tag type corresponding to the expected mode, then the expectation is considered to have succeeded, and the hardware sends the packet normally. If it is not equal to the expected mode, proceed to Step 5.

[0131] Step 5: Determine if the filtering level is the same as the level of the original packet, and whether the corresponding filtering mode is drop mode. If it is equal to drop mode, and the hardware detects that the original packet carries a VLAN tag type corresponding to drop mode, the packet will be dropped. If the hardware does not detect the VLAN tag type, the packet will be sent normally, and the hardware filtering process will end. If it is not equal to the expected mode, the hardware filtering process will end.

[0132] It should be noted that in the above process, in some cases, the VLAN tag carrying information can be set to not carry, but the VLAN tag insertion location information is empty; in this case, the VLAN tag insertion module can determine that the VLAN tag insertion location information is actually unrestricted based on the fact that the VLAN tag carrying information is not carried.

[0133] In some optional implementations, if the VLAN tag insertion position information in the identification information is at the Layer 2 packet location, then the VLAN tag insertion module will offset the set insertion position corresponding to the new VLAN tag by the set length corresponding to the Layer 2 packet.

[0134] If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second.

[0135] If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

[0136] For example, if the original packet does not carry a VLAN tag, the VLAN tag identification module will set the VLAN tag insertion position information to unlimited and / or set the VLAN tag carrying information to not carry. In this case, the VLAN tag insertion module can insert the new VLAN tag into the corresponding information of the original packet according to the relevant information configured in the software. According to the relevant protocol, for single-layer VLAN tags, the VLAN tag usually follows the DA (destination address) / SA (source address) of the original packet. For double-layer or multi-layer (more than two layers) VLANs, the outermost VLAN tag is inserted after the DA (destination address) / SA (source address). Inner VLAN tags can continue to be inserted after the outermost VLAN tag. That is to say, the position after the DA (destination address) / SA (source address) is the set insertion position. Starting from the DA (destination address) / SA (source address), new VLAN tags are inserted in the order of outermost to innermost. The number of new VLAN tags and the order of inner and outer layers in the case of multiple new VLAN tags are pre-configured by the software in the new inner and outer layer attributes.

[0137] It's important to note that when there are no Layer 2 packets, the insertion position is set after the DA (destination address) / SA (source address) of the original packet. However, when there are Layer 2 packets, if the VLAN tag identification module sets the VLAN tag insertion position information to the Layer 2 packet, then the insertion position is set after the DA (destination address) / SA (source address) of the Layer 2 packet. Therefore, if the default insertion position is set after the DA (destination address) / SA (source address) of the original packet, the insertion position needs to be offset by the corresponding set length of the Layer 2 packet. The set length can be understood as the length from the position after the DA (destination address) / SA (source address) of the original packet to the DA (destination address) / SA (source address) of the Layer 2 packet.

[0138] For example, if the VLAN tag identification module identifies that the original packet carries a VLAN tag, and the VLAN tag insertion location information is not unlimited and the VLAN tag carrying information is not non-carrying, the VLAN tag insertion module needs to further insert the new VLAN tag into an appropriate position according to the identification information and VLAN insertion configuration information, or if there is no appropriate position, the new VLAN tag will not be inserted.

[0139] In some optional implementations, if the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not not carried, then if the original inner and outer layer attributes are inner layer and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0140] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet.

[0141] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet.

[0142] If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0143] In some alternative implementations, if the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not not carried, then if the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module does not insert the new VLAN tag into the original packet; and if the original inner and outer layer attributes are dual-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support dual-layer VLANs, then the VLAN tag insertion module does not insert the new VLAN tag into the original packet.

[0144] The following is combined Figure 6 The detailed process of several optional implementations involved in the above VLAN tag insertion process is illustrated by example.

[0145] See Figure 6 As shown, for example, the VLAN tag insertion module inserts a new VLAN tag as follows:

[0146] Step 1: The hardware determines the packet processing level based on the insertion level configured in the software, namely Traffic Category (TC), Virtual Switch Interface (VSI), and Transmit Queue (TX Queue); it determines the VLAN tag to be inserted into the original packet based on the insertion type configured in the software; and it determines the number of VLAN layers to be inserted based on the number of insertion layers configured in the software.

[0147] Step 2: Confirm the packet VLAN insertion location according to the hardware VLAN identification process;

[0148] Step 3: If there are no restrictions on the insertion location of the original packet, the hardware inserts the VLAN in order according to the inner and outer attributes of the VLAN tag;

[0149] Step 4: If the original packet carries an inner VLAN tag (such as a VLAN tag of type 0x8100). In this case, if the software is configured to support only a single VLAN layer, the hardware will not insert a new VLAN tag; if the software is configured to support more than one VLAN layer, the hardware will insert a new VLAN tag on the outer layer.

[0150] Step 5: If the original packet carries an outer VLAN tag. In this case, if the software is configured to support only a single-layer VLAN tag, the hardware will not insert a new VLAN tag; if the software is configured to support two-layer VLAN tags, a new VLAN tag can be inserted in the inner layer; if the software is configured to support multiple-layer VLAN tags, a new VLAN tag can be inserted in both the inner and outer layers.

[0151] Step Six: If the original packet carries a dual-layer VLAN. If the software is configured to support only single-layer or dual-layer VLAN tags, the hardware will not insert a new VLAN tag; if the software is configured to support multi-layer VLANs, the hardware can insert a VLAN tag at the outer layer.

[0152] The above is the message processing apparatus proposed in this application, which has the following advantages:

[0153] 1. Compared to software-based VLAN tag insertion, this application effectively improves the efficiency of VLAN tag insertion through hardware offloading. When the system has multiple queues, hardware-based VLAN tag insertion offers even greater efficiency improvements, freeing up resources previously allocated to software calculation and management of VLAN tags. In related technologies, hardware directly inserts VLAN tags after the MAC source address in the L2 header. This method disregards the outer and inner attributes of the VLAN tag, potentially leading to incorrect tag placement order in the L2 header. This application ensures correct VLAN insertion by accurately identifying the VLAN tag type and insertion position.

[0154] 2. By automatically identifying VLAN tag types through hardware, the hardware can filter out untrusted VLAN tags or directly discard packets. This approach can solve the problems of virtual machine VLAN attacks and VLAN priority traffic preemption, improving the overall system security and robustness.

[0155] 3. Hardware filtering offers high flexibility in VLAN hierarchy, allowing for selection of different granular filtering configurations through software configuration; hardware VLAN filtering modes are flexibly configurable, enabling the selection of different VLAN filtering methods based on different service types, increasing the software's control over hardware, and reducing the software's resource consumption for VLAN tag management.

[0156] 4. Flexible hardware insertion of VLAN tags, supporting insertion of different types of VLAN tags, dual-layer / multi-layer VLAN tag insertion, and management of insertion of VLAN tags at different levels.

[0157] Accordingly, see Figure 7 As shown, this application also provides an exemplary message processing method, including:

[0158] In step S701, the VLAN tag identification module identifies the original packet and outputs identification information; the identification information includes the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag;

[0159] In step S702, the VLAN tag filtering module filters the original packet according to the pre-configured VLAN filtering configuration information and the identification information; the filtering process includes discarding, modifying and allowing, or allowing directly.

[0160] In step S703, the VLAN tag insertion module inserts a new VLAN tag into the original packet according to the pre-configured VLAN insertion configuration information and the identification information.

[0161] In some optional implementations, the VLAN tag identification module identifies the original packet and outputs identification information, including:

[0162] If the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message.

[0163] If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted.

[0164] If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted.

[0165] If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered.

[0166] If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

[0167] In some optional implementations, the VLAN filtering configuration information includes the filtering mode corresponding to the VLAN filtering level; the VLAN tag filtering module filters the original packet according to the pre-configured VLAN filtering configuration information and the identification information, including:

[0168] The VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs.

[0169] If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module will directly allow the original packet to pass.

[0170] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs filtering processing on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode, and then allowing it to pass.

[0171] If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carries no information, then the VLAN tag filtering module will directly allow the original packet to pass.

[0172] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module will directly allow the original packet to pass.

[0173] If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is not carried, then the VLAN tag filtering module will discard the original packet.

[0174] If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs a drop filtering process on the original packet.

[0175] If the filtering mode corresponding to the original packet is the drop mode and the VLAN tag information is not carried, then the VLAN tag filtering module will directly allow the original packet to pass.

[0176] In some optional implementations, the VLAN tag insertion module inserts a new VLAN tag into the original packet based on pre-configured VLAN insertion configuration information and the identification information, including:

[0177] If the VLAN tag insertion position information in the identification information is at the Layer 2 packet, then the VLAN tag insertion module will offset the set insertion position corresponding to the new VLAN tag by the set length corresponding to the Layer 2 packet.

[0178] If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second.

[0179] If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

[0180] In some optional implementations, the VLAN tag insertion module inserts the new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, including:

[0181] If the original inner and outer layer attributes are inner layer, and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0182] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet.

[0183] If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet.

[0184] If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

[0185] In some optional implementations, the VLAN tag insertion module inserts the new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, and further includes:

[0186] If the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet. If the original inner and outer layer attributes are two-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support two-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet.

[0187] The above method can be implemented by the message processing device provided in the above embodiments. For specific implementation details, please refer to the description of the message processing device in the above embodiments, which will not be repeated here.

[0188] It is understood that the circuit structures, names, and parameters described in the above embodiments are merely examples. Those skilled in the art can also make readily conceived combinations and adjustments to the structural features of the above embodiments according to their needs, and the concept of this application should not be limited to the specific details of the above examples.

[0189] Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A message processing apparatus, characterized in that, include: The module includes a VLAN tag identification module, a VLAN tag filtering module, and a VLAN tag insertion module; among which, The VLAN tag identification module is used to identify the original packet and output identification information; the identification information includes the VLAN tag carrying information in the original packet, the VLAN tag insertion position information in the original packet, and the original inner and outer attributes of the carried VLAN tag; The VLAN tag filtering module is used to filter the original packets according to the pre-configured VLAN filtering configuration information and identification information; the filtering process includes discarding, modifying and allowing, or allowing directly; The VLAN tag insertion module inserts a new VLAN tag into the original packet according to the pre-configured VLAN insertion configuration information and the identification information; If the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message. If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted. If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted. If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered. If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

2. The message processing apparatus according to claim 1, characterized in that, The VLAN filtering configuration information includes the filtering mode corresponding to the VLAN filtering level; the VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs. If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass. If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode and then allowing it to pass. If the filtering mode corresponding to the original packet is replacement mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass. If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass. If the filtering mode corresponding to the original packet is the desired mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet. If the filtering mode corresponding to the original packet is the discard mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs the filtering process of discarding the original packet. If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is not carried, then the VLAN tag filtering module performs the filtering process of the original packet by directly allowing it to pass.

3. The message processing apparatus according to any one of claims 1-2, characterized in that, If the original message is nested into a Layer 2 message, the VLAN tag insertion module will offset the set insertion position of the new VLAN tag from the set length corresponding to the Layer 2 message. If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second. If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

4. The message processing apparatus according to claim 3, characterized in that, If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then if the original inner and outer layer attributes are inner layer and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet. If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet. If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet. If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

5. The message processing apparatus according to claim 3, characterized in that, If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then if the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet. If the original inner and outer layer attributes are two-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support two-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet.

6. A message processing method, characterized in that, include: The VLAN tag identification module identifies the original packets and outputs identification information; The identification information includes VLAN tag carrying information in the original message, VLAN tag insertion location information in the original message, and the original inner and outer attributes of the carried VLAN tag; The VLAN tag filtering module filters the original packets based on pre-configured VLAN filtering information and the identification information; the filtering process includes discarding, modifying and allowing, or allowing directly. The VLAN tag insertion module inserts a new VLAN tag into the original packet based on the pre-configured VLAN insertion configuration information and the identification information. The VLAN tag recognition module identifies the original packet and outputs recognition information, including: If the original message contains nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the Layer 2 messages; if the original message does not contain nested Layer 2 messages, the VLAN tag identification module identifies the VLAN tag after the source address of the original message. If no VLAN tag is identified, the VLAN tag identification module determines that the VLAN tag carries no information and that the VLAN tag insertion location information is unrestricted. If a VLAN tag is identified, and the VLAN tag it carries is of the first set type, then the VLAN tag identification module determines that the VLAN tag insertion location information is unrestricted. If a VLAN tag is identified and the VLAN tag it carries is of the second set type, then the VLAN tag identification module determines whether the inner layer of the VLAN tag of the second set type carries an inner layer VLAN tag. If it carries an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are double-layered. If it does not carry an inner layer VLAN tag, then the VLAN tag identification module determines that the original inner and outer layer attributes are outer-layered. If a VLAN tag is identified, and the VLAN tag it carries is neither the first set type nor the second set type, then the VLAN tag identification module determines that the VLAN tag carries no information.

7. The message processing method according to claim 6, characterized in that, The VLAN filtering configuration information includes the filtering mode corresponding to the VLAN filtering level; the VLAN tag filtering module performs filtering processing on the original packet according to the pre-configured VLAN filtering configuration information and the identification information, including: The VLAN tag filtering module identifies the VLAN filtering level to which the original packet belongs, and determines the filtering mode corresponding to the original packet based on the VLAN filtering configuration information and the VLAN filtering level to which the original packet belongs. If the filtering mode corresponding to the original packet is the accept mode, then the VLAN tag filtering module will directly allow the original packet to pass. If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs filtering processing on the original packet by first replacing the set field in the VLAN tag carried by the original packet with the configuration content corresponding to the replacement mode, and then allowing it to pass. If the filtering mode corresponding to the original packet is the replacement mode, and the VLAN tag carries no information, then the VLAN tag filtering module will directly allow the original packet to pass. If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is carried, then the VLAN tag filtering module will directly allow the original packet to pass. If the filtering mode corresponding to the original packet is the desired mode and the VLAN tag carrying information is not carried, then the VLAN tag filtering module will discard the original packet. If the filtering mode corresponding to the original packet is the drop mode, and the VLAN tag carrying information is carried, then the VLAN tag filtering module performs a drop filtering process on the original packet. If the filtering mode corresponding to the original packet is the drop mode and the VLAN tag information is not carried, then the VLAN tag filtering module will directly allow the original packet to pass.

8. The message processing method according to any one of claims 6-7, characterized in that, The VLAN tag insertion module inserts a new VLAN tag into the original packet based on pre-configured VLAN insertion configuration information and the identification information, including: If the VLAN tag insertion position information in the identification information is at the Layer 2 packet, then the VLAN tag insertion module will offset the set insertion position corresponding to the new VLAN tag by the set length corresponding to the Layer 2 packet. If the VLAN tag insertion location information in the identification information is unlimited or the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag at the set insertion location in the order of outer layer first and inner layer second. If the VLAN tag insertion location information in the identification information is not unlimited and the VLAN tag carrying information is not carried, then the VLAN tag insertion module inserts the new VLAN tag into the original packet according to the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information.

9. The message processing method according to claim 8, characterized in that, The VLAN tag insertion module inserts a new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, including: If the original inner and outer layer attributes are inner layer, and the new inner and outer layer attributes are not only supporting single-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet. If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support VLANs at layer two or above, then the VLAN tag insertion module inserts the new VLAN tag into the inner or outer layer of the original packet. If the original inner and outer layer attributes are outer layer, and the new inner and outer layer attributes support dual-layer VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the inner layer of the original packet. If the original inner and outer layer attributes are two-layered, and the new inner and outer layer attributes are not only supporting single-layered VLANs or only supporting two-layered VLANs, then the VLAN tag insertion module inserts the new VLAN tag into the outer layer of the original packet.

10. The message processing method according to claim 8, characterized in that, The VLAN tag insertion module inserts the new VLAN tag into the original packet based on the original inner and outer layer attributes in the identification information and the new inner and outer layer attributes in the VLAN insertion configuration information, and further includes: If the original inner and outer layer attributes are inner or outer, and the new inner and outer layer attributes only support single-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet. If the original inner and outer layer attributes are two-layer, and the new inner and outer layer attributes only support single-layer VLANs or only support two-layer VLANs, then the VLAN tag insertion module will not insert the new VLAN tag into the original packet.

Citation Information

Patent Citations

  • Ethernet data frame VLAN double-layer label processing device and method based on flow classification

    CN101567854A

  • Message processing method and device, electronic equipment and computer readable storage medium

    CN114389844A