A TCP mirroring stream processing device based on FPGA
Through the TCP mirror stream processing device based on FPGA, parallel processing and out-of-order rearrangement are realized, which solves the problems of low throughput and high latency in the prior art, improves processing efficiency and throughput, and adapts to complex network environments.
Patent Information
- Application Number
- CN202510356327.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-03-25
AI Technical Summary
In the prior art, TCP mirror stream processing mainly relies on software parsing, resulting in low throughput and high latency, which is not suitable for parallel processing, and cannot effectively support out-of-order reordering and long-term operation.
The TCP mirror stream processing device based on FPGA is adopted, including a network reception module, a verification module, a connection management module, a load extraction module and a data transmission module, to realize parallel processing and out-of-order re-transmission message filtering, and to adapt to complex network environments.
It improves data processing efficiency, reduces latency, supports parallel processing of multiple TCP connections, improves the resolution throughput of mirror streams, adapts to complex network environments, and supports long-term running and selective resolution of mirror streams.
Smart Images

Figure CN119892962B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technologies, and particularly to a TCP mirror stream processing device based on FPGA. Background Art
[0002] Currently, the processing of TCP (Transmission Control Protocol) mirror streams is basically carried out by software parsing. When using a processor (CPU), network packets need to be copied from a network interface device to the host memory, which will generate a relatively large transmission delay, and the processing delay will be affected by the system load.
[0003] Existing CPUs are suitable for processing serial and complex instruction operations, but not suitable for a large number of parallel fixed-mode calculations. Therefore, traditional TCP / IP based on software parsing has problems such as low throughput and high latency. FPGA (Field Programmable Gate Array) is a programmable integrated circuit with high flexibility and powerful parallel processing capabilities. An FPGA can define its internal logic functions according to requirements. It contains a large number of logic units that can work in parallel, can process multiple tasks simultaneously, and the hardware architecture of the FPGA enables it to achieve low-latency data processing. Therefore, it is very suitable for processing TCP mirror streams.
[0004] It should be noted that the above introduction to the technical background is only for the convenience of clearly and completely explaining the technical solutions of this application and facilitating the understanding of those skilled in the art. It cannot be considered that the above technical solutions are well-known to those skilled in the art just because these solutions are described in the background art part of this application. Summary of the Invention
[0005] The purpose of the present invention is to provide a TCP mirror stream processing device based on FPGA. This device supports out-of-order rearrangement, pseudo-retransmission packet filtering, supports parallel processing of multiple mirror streams, de-encapsulates packets while receiving network packets to reduce processing delay, solves the packet sequence number wrap-around problem to support long-term operation, and can be used in many scenarios such as TCP connection dual-active hot backup, network fault detection, and network security.
[0006] To solve the above problems, a TCP mirror stream processing device based on FPGA is provided below. It is composed of a network receiving module, an FPGA module, and a service module. The FPGA module includes a verification module, a connection management module, a load extraction module, and a data transmission module;
[0007] The network receiving module is used to receive network data and encapsulate it into network data packets, and output them to the verification module, connection management module, and payload extraction module respectively for parallel processing;
[0008] The verification module is used to determine whether the network data packet is a target data packet and whether it is complete, and feedback the verification result to the connection management module;
[0009] The connection management module is used to determine whether the network data packet should be received, and match the connection to which the network data packet to be received belongs;
[0010] The payload extraction module is used to extract the TCP payload in the network data packet;
[0011] Based on the parallel processing results of the verification module, connection management module, and payload extraction module, the data transmission module transmits the TCP payload to the service module.
[0012] The TCP mirror stream processing device provided by the present invention can realize parallel processing of TCP data verification, connection matching, and payload extraction, and finally merge the results, which can effectively improve the data processing efficiency, improve the throughput rate of mirror stream parsing, and reduce latency.
[0013] The verification module determines whether the network data packet is a target data packet by sequentially determining whether the network data packet is an IP data packet and whether the payload of the IP data packet is a TCP segment; the verification module performs IP header verification and TCP segment verification on the target data packet to confirm whether the target data packet is complete. The verification module performs verification work and outputs the verification result. By screening and verifying the network data packet, the target data packet is screened out and the data packet is ensured to be complete.
[0014] The connection management module includes at least one group of connection registers; the connection registers are used to store the quadruple information of different TCP mirror streams, and the quadruple information is the source IP address, source port, destination IP address, and destination port; the multiple groups of connection registers are numbered to obtain a connection index, and the connection index is also correspondingly associated with pointer information; the connection management module extracts the quadruple information of the network data packet and matches it with the connection registers; after successful matching, the connection management module obtains the payload length and sequence number of the TCP segment of the network data packet, and outputs them to the data transmission module together with the matched connection index and pointer information; the data transmission module transmits the TCP payload to the service module based on the payload length, sequence number, matched connection index, and pointer information of the TCP segment.
[0015] The connection management module further includes at least one set of configuration registers; the configuration registers are used to store the source IP address, source port, destination IP address, destination port, and aging time; the connection management module matches the quadruple information that does not match the connection register with the configuration register; after successful matching, the quadruple information is stored in the unoccupied connection register; if the matching fails, the current network data packet is discarded. The automatic formation of the connection register is realized based on the configuration register, so as to realize the monitoring of each TCP mirror stream.
[0016] The data transmission module includes a payload write module, a payload read module, and a storage module; the payload write module is used to write the TCP payload into the storage module, and the written address range is determined based on the payload length of the received TCP segment, the sequence number, and the pointer information; the payload read module is used to read the continuously received TCP payload from the storage module, perform byte alignment, and then transmit it to the service module, and the read address range is confirmed based on the sequence number, the connection index, and the pointer information. By using the payload length, sequence number, required connection index, and corresponding pointer information of each TCP segment, a mapping relationship with the storage address of each TCP payload is established, so as to realize the orderliness and integrity of the reception and transmission of all TCP payloads.
[0017] The connection management module further includes at least one set of blacklist registers, and the blacklist registers are used to store quadruple information; the connection management module extracts the quadruple information of the network data packet and first matches it with the blacklist register; after successful matching, the current network data packet is discarded; if the matching fails, it continues to match with the connection register. By setting the blacklist to filter some TCP mirror streams that are not expected to be parsed, the effective utilization rate of resources is improved.
[0018] It further includes a payload analysis module connected to the payload extraction module; the payload analysis module analyzes the TCP payload based on a preset rule and stores the obtained quadruple information in the blacklist register; the quadruple information stored in the blacklist register will be deleted after a predetermined aging time. Supporting the preset TCP mirror stream payload data rule can selectively parse the mirror stream with target characteristics and also improve the effective utilization rate of resources.
[0019] The pointer information includes a continuously received data pointer and a selectively received data pointer group.
[0020] It further includes an out-of-order rearrangement module, and the out-of-order rearrangement module realizes out-of-order reception and reordering of the TCP payload based on the SACK mechanism. Applying the sack working principle to realize out-of-order reception and reordering can adapt to a more complex network environment.
[0021] The out-of-order rearrangement module supports the sequence number wrap-around function; the sequence number wrap-around function is verified by the sequence number, the continuously received data pointer, and the highest two bits of the selective reception data pointer group. Special processing is performed when comparing the sequence number and the pointer to solve the sequence number wrap-around problem, and it can run for a long time.
[0022] Compared with the prior art, the beneficial effects of the present invention mainly include the following: 1) Support for simultaneously processing multiple TCP connection mirror streams; 2) Using FPGA logic to implement operations such as verification, connection management, load extraction, and address alignment simultaneously, and finally merging the results, with high parallel processing logic and low latency; 3) By setting up a blacklist and load analysis capabilities, it can selectively parse mirror streams with target characteristics and filter some TCP mirror streams that are not expected to be parsed, improving the effective utilization rate of resources; 4) It can run for a long time, solve the sequence number wrap-around problem, support connection aging to avoid long-term resource occupation by half-open connections; 5) Support out-of-order reordering to adapt to a more complex network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the specific embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0024] Figure 1 It is a schematic structural diagram of a TCP mirror stream processing device based on FPGA provided by the present invention.
[0025] Figure 2 It is a schematic structural diagram of another TCP mirror stream processing device based on FPGA provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] Regarding the foregoing and other technical contents, features, and effects of the present invention, they will be clearly presented in the following detailed description of a preferred embodiment in conjunction with the reference drawings. The directional terms mentioned in the following embodiments, such as: up, down, left, right, front, or back, etc., are only with reference to the directions of the attached drawings. Therefore, the directional terms used are for illustration and not for limiting the present invention.
[0027] The following will elaborate on the embodiments of the present application in conjunction with the drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present application, many technical details are proposed for the convenience of readers to understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented.
[0028] TCP is a connection-oriented, reliable, byte-stream-based transport layer communication protocol. TCP mirroring stream is a process based on the TCP protocol, which generally refers to the process of copying TCP traffic on one or more source ports to one or more target ports or services in a network environment. Without interfering with normal network traffic, it can copy and forward TCP traffic on specific ports to the specified target ports or services, and can be applied to scenarios such as TCP connection dual-active hot backup, network fault detection, and network security.
[0029] The steps in the following embodiments do not correspond one by one to the content of the invention.
[0030] Embodiment 1 is as Figure 1 shown in the structural schematic diagram of a TCP mirroring stream processing device based on FPGA provided by the present invention.
[0031] Referring to Figure 1 , the present invention provides a TCP mirroring stream processing device based on FPGA, which is composed of a network receiving module, an FPGA module, and a service module; wherein, the FPGA module includes a verification module, a connection management module, a load extraction module, a load analysis module, an out-of-order rearrangement module, and a data transmission module; the data transmission module includes a load write module, a load read module, and a storage module.
[0032] The network receiving module is used to receive network data and encapsulate it into network data packets, and output them to the verification module, the connection management module, and the load extraction module respectively for parallel processing; the verification module is used to judge whether the network data packet is a target data packet and whether it is complete, and feedback the verification result to the connection management module; the connection management module is used to judge whether the network data packet should be received, and match the connection to which the received network data packet belongs; the load extraction module is used to extract the TCP load in the network data packet; the data transmission module transmits the TCP load to the service module based on the parallel processing results of the verification module, the connection management module, and the load extraction module.
[0033] The network receiving module is used to receive network data from an external device, and encapsulate the received bit stream into network data packets, and then output them to the verification module, the connection management module, and the load extraction module respectively for parallel processing. It can be understood that the present application does not limit the source of the data received by the network receiving module (i.e., the external device). After receiving the data, it generally performs error detection on the received Ethernet frame (such as FCS, Frame Check Sequence), marks the correctness, and hands it over to the subsequent verification module to integrate the results to ensure the integrity and accuracy of the received data.
[0034] Reference Figure 1 As shown, the network receiving module outputs the obtained network data packets to the verification module, the connection management module, and the payload extraction module respectively and simultaneously. After receiving the data packets, the above three modules will process them respectively. The three modules process in parallel with each other and will merge the results of the parallel processing in the subsequent process.
[0035] It can be understood that the network data packet is the basic unit of information transmission in the network transmission process and is a data unit composed of information such as the source physical address, the destination physical address, and the frame type. Usually, the data packet includes a header and a payload. The header generally contains instructions related to the data in the data packet, such as the source address, the destination address, the protocol, and the sequence number, etc. The source address is used to indicate the source of the information packet, the destination address points to the receiving IP address, and the sequence number is used to identify the order and position of the data packet; while the payload is usually called data and is the actual data information carried by the data packet to the destination. Usually, the data packets can be classified, such as IP data packets (Internet Protocol Packet), ARP data packets (Address Resolution Protocol Packet), and RARP data packets (Reverse Address Resolution Protocol Packet), etc.
[0036] For the verification module, when the verification module receives a network data packet, it will verify the data packet to determine whether it is the target data packet and whether the received data packet is complete, and feedback the verification result to the connection management module.
[0037] It can be understood that TCP mirror data is usually encapsulated in an IP data packet for transmission, that is, the IP data packet is composed of an IP data packet header and an IP data packet payload, where the IP data packet payload is the TCP data segment; and the TCP data segment also contains two parts, namely the TCP header and the TCP payload.
[0038] Specifically, the processing object of the device provided in this application is TCP mirror data. Therefore, network packets with TCP segments (i.e., target packets) need to be screened out first. To ensure the smooth implementation of subsequent processing procedures, the integrity and accuracy of the received data also need to be confirmed. Therefore, the verification module first detects whether the received network packet is an IP packet. If not, the network packet is discarded (i.e., the verification result is no). If it is an IP packet, it further determines whether the payload of the IP packet is a TCP segment and performs an IP header verification. If not, the network packet is discarded (i.e., the verification result is no). If the payload is a TCP segment, the packet is subjected to a TCP segment verification to ensure data integrity. If it passes, it means the verification result is yes; otherwise, the network packet is discarded (i.e., the verification result is no). Finally, the verification module combines the results obtained from the above process with the received FCS verification result and then feeds back the final verification result to the connection management module. It can be understood that the judgment methods involved in the above steps, such as whether the network packet is an IP packet and whether the payload of the IP packet is a TCP segment, can be based on the identification data at specific positions in the network packet. The verification result is used to indicate whether it passes, represented by yes and no. For example, 0 represents no and 1 represents yes.
[0039] For the connection management module, it is parallel to the verification module. The connection management module is used to determine whether the received packet is legal, whether the payload of the TCP segment should be received, and match the connection to which the TCP segment belongs.
[0040] Specifically, three types of registers can be set in the connection management module, including configuration registers, connection registers, and blacklist registers. Each single register can be set with one or more groups according to actual needs.
[0041] For the configuration registers, each group of configuration registers can store information such as source IP address, source port, destination IP address, destination port, and aging time. Specifically, the number of information stored in each group of configuration registers can be confirmed according to the actual situation (including at least one quadruple information). For example, all quadruple information can be stored, or only the source IP address and source port can be configured, or only the destination IP address and destination port can be configured, etc. The configuration of the aging time is also optional. The multiple groups of configuration registers in the connection management module are numbered with non-negative integers, called configuration indexes.
[0042] For connection registers, they are respectively used to store the quadruple (i.e., source IP address, source port, destination IP address, and destination port) information of different TCP mirroring streams; the register group is numbered and distinguished by non - negative integers, which is called the connection index. The connection index not only includes the quadruple information of a TCP mirroring stream, but also corresponds to some other information, such as pointer information, usually including the continuously received data pointer (recv_ptr) and / or the selective reception data pointer group (sack_ptr[]). It can be understood that for configuration registers, since it is not necessary to completely specify the quadruple information, for each group of configuration registers, there may be multiple links, that is, multiple groups of connection registers need to be used correspondingly. In other embodiments, the configuration registers may not be set either, for example, when giving up supporting multiple mirroring streams or when one configuration detects multiple connections and other features.
[0043] For the blacklist register, it is used to store the quadruple information that is not of interest. It can be understood that in other embodiments, this blacklist register may not be set; if the blacklist register is set, the quadruple information stored therein can be set according to actual needs.
[0044] After receiving a network packet, the connection management module extracts the quadruple information of the network packet according to the protocol and compares it with the values of the configuration register, connection register, and blacklist register. First, it matches with the values in the blacklist register. If it matches successfully with a certain group of blacklist registers (i.e., the quadruple values are equal), the current network packet should be discarded; if it does not match with any blacklist register, it then matches with the connection register. If it matches successfully with a certain group of connection registers, it reads the other information corresponding to the connection index, including the continuously received data pointer (recv_ptr) or the selective reception data pointer group (sack_ptr[]); if it does not match with any connection register either, it matches with the configuration register. If it matches successfully with a certain group of configuration registers, it stores the extracted quadruple into the unoccupied connection register group; if it finally cannot match, the current network packet is discarded. It can be understood that when the connection management module extracts the quadruple information of a network packet, if the network packet is a TCP / IP packet, the quadruple information can be normally extracted and used for subsequent processes; if the type of the network packet is incorrect, the information extracted is not quadruple information, and it will also fail to match and be discarded in the subsequent process. It can be understood that in other embodiments, if the configuration register and / or the blacklist register are not set, the corresponding comparison process will be skipped.
[0045] After successfully matching a certain group of connection registers, fields such as the total length of the IP packet, the length of the IP packet header, and the length of the TCP header are extracted, and the payload length (tcp_pload_len) of the TCP segment is calculated: the payload length (tcp_pload_len) of the TCP segment is equal to the total length of the IP packet minus the length of the IP packet header minus the length of the TCP header; the sequence number (seq) of the TCP segment is extracted. The connection management module will output the obtained payload length and sequence number of the TCP segment, the matching connection index, and the corresponding pointer information to the data transmission module together; the data transmission module will transmit the TCP payload to the service module based on the received payload length, sequence number, matching connection index, and pointer information of the TCP segment. Specifically, if the payload length is not 0, the connection management module will output seq, tcp_pload_len, and pointer information (recv_ptr and / or sack_ptr[]) to the out-of-order rearrangement module, and output seq, tcp_pload_len, recv_ptr and / or sack_ptr[], and the matching connection index to the payload write module.
[0046] If the RST or FIN field of the received TCP segment is set, the corresponding connection register group will be marked as unoccupied and the corresponding connection resources will be released. The FIN (Finish) and RST (Reset) fields are flag bits in the TCP header, which are used to control the termination and exception handling of the connection. When the RST or FIN field of the TCP segment is set, it usually indicates that the connection has an exception or can end.
[0047] In this embodiment, the aging time can be configured in the configuration register of the connection management module. When the aging time is set, the connection management module will record the current system timestamp when receiving a packet, and will release the corresponding connection resources if no packet is received after the automatic aging time.
[0048] The connection management module will also receive the processing result of the payload analysis module (the obtaining process of this processing result will be described below) and add certain specific quadruple information to the blacklist register based on this processing result. That is, the mirror flow information that matches the quadruple but is not expected to be processed will be stored in the blacklist register, and will be deleted from the blacklist after a predetermined aging time (this aging time refers to the retention time of the quadruple information in the blacklist register, which can be confirmed according to the time service or process).
[0049] It should be noted that the inspection module, the connection management module, and the load extraction module process in parallel with each other, and the results of their parallel processing will be merged. Therefore, the connection management module will receive the inspection results of the verification module, and the verification results must pass. Otherwise, the processing results of the connection management module will also be discarded. For example, the connection matching process of the connection management module will work simultaneously with the verification logic of the inspection module. However, updates to the occupied status of a connection index, updates to the recv_ptr pointer, etc. also require the verification to pass, otherwise the processing results will be discarded.
[0050] For the load extraction module, after receiving network data packets sent by the network receiving module simultaneously with the verification module and the connection management module, the three process in parallel. The load extraction module is used to extract the effective payload of the TCP data segment, perform address alignment processing on the load data stream, and transmit the processed data stream to the load writing module.
[0051] In this embodiment, a load analysis module is also provided. The load analysis module is connected to the load extraction module and can analyze the TCP load obtained by the load extraction module and feedback the analysis results to the connection management module. Specifically, for example, some rules can be preset in the load analysis module according to the characteristics of service data to detect whether the TCP load meets these rules, and thus write the four-tuple information of uninteresting data packets into the blacklist register. By presetting the TCP mirror stream load data rules in the load analysis module, mirror streams with target characteristics can be selectively parsed, and some TCP mirror streams that are not expected to be parsed can be filtered, greatly improving the processing efficiency. Of course, in other embodiments, the load analysis module may not be provided.
[0052] A disordered rearrangement module is also provided in this device. The disordered rearrangement module can implement disordered reception and reordering of TCP loads based on the SACK mechanism. As described above, the disordered rearrangement module will receive the processing results from the connection management module (including the seq, tcp_pload_len, recv_ptr, and sack_ptr[] of the TCP data segment). In the disordered rearrangement module, disordered reception and reordering of data packets are performed through the seq, tcp_pload_len of the current TCP data segment, and the current recv_ptr and sack_ptr[] information.
[0053] When the seq of the currently received data packet is not equal to the current recv_ptr, it indicates that the network data packets may be out of order during transmission, or TCP retransmission has occurred, etc. First, seq + tcp_pload_len can be recorded as seq_nxt. sack_ptr[] is an array of three pairs of pointers (s0_ptr_l, s0_ptr_r; s1_ptr_l, s1_ptr_r; s2_ptr_l, s2_ptr_r). Among them, s*_ptr_l in each pair of pointers is the seq of a received TCP segment, and the pointer value s*_ptr_r is the seq + tcp_pload_len of a TCP segment. When equal values appear in several pairs of pointers, the pairs of pointers need to be merged. For example, if the current seq is equal to s0_ptr_r and seq_nxt is equal to s1_ptr_l, then the pairs of pointers s0 and s1 are merged. If seq is not equal to recv_ptr, recv_ptr remains unchanged. If seq is equal to recv_ptr, seq_nxt is equal to s0_ptr_l, recv_ptr will be updated to s0_ptr_r; if seq_nxt is not equal to s0_ptr_l, recv_ptr is updated to s0_ptr_r. The updated recv_ptr will be fed back to the payload read module, and the updated recv_ptr and sack_ptr[] are synchronized to the connection management module. It can be understood that since the verification module, the connection management module, and the payload extraction module are parallel, this update process can only be performed after the verification of the verification module passes. That is, after the verification passes, the connection management module will update recv_ptr and sack_ptr[], and only then will the updated recv_ptr be fed back to the payload read module.
[0054] To support the scenario of packet sequence number wrap-around, the highest two bits of the sequence number, the pointer to the continuously received data, and the selective receive data pointer group are used for verification. This is because the size of the receive window is limited, and using 30-bit sequence numbers, pointers to continuously received data, and selective receive data pointer groups can meet the requirements. Since the fields in the sequence number, pointer to continuously received data, and selective receive data pointer group are all 32 bits, the highest 2 bits can be used for verification. Specifically, when the highest two bits of recv_ptr are both 1 and the highest two bits of seq are both 0, the highest bit of recv_ptr is regarded as 0, the highest bit of seq is regarded as 1 for comparison, and the same processing is done for the sack_ptr[] pointer group.
[0055] It can be understood that for each link we monitor, if the mirrored link itself does not support selective acknowledgment, then the out-of-order rearrangement module does not need to work or does not work; when the mirrored link supports selective acknowledgment, in order to ensure the complete processing of the mirrored link, the out-of-order rearrangement module is necessary.
[0056] The payload write module is responsible for writing the legal TCP payload into the corresponding address in the memory. Determine the data that can be written into the memory according to seq, tcp_pload_len, and sack_ptr[], and determine the write address according to seq and the connection index to which it belongs. A legal TCP payload means that the TCP payload is a data segment that has not been received before and does not exceed the receive window.
[0057] The payload read module reads the data that has been continuously received from the memory. Determine the address range of the data through seq, recv_ptr, and the connection index, read the data from the memory and perform byte alignment, and transfer the aligned data to the service module.
[0058] The service module configures the configuration register in the connection management module, receives the payload and performs corresponding operations according to the actual service scenario.
[0059] Embodiment 2
[0060] As Figure 2 shown is a schematic structural diagram of another TCP mirroring stream processing device based on FPGA provided by the present invention.
[0061] This device is basically the same as Embodiment 1, the difference being that the out-of-order rearrangement module is omitted. It can be understood that when the mirrored link itself does not support selective acknowledgment, the out-of-order rearrangement module is not needed.
[0062] Specifically, in this embodiment, after the connection management module receives a network data packet, it extracts the four-tuple information of the network data packet according to the protocol and compares it with the values of the configuration register, connection register, and blacklist register. When it matches successfully with a group of connection registers, it reads other information corresponding to the connection index. At this time, the pointer information associated with the connection index only includes the pointer to the continuously received data (recv_ptr), and there is no group of pointers to selectively received data (sack_ptr[]). After successfully matching with a group of connection registers, extract fields such as the total length of the IP data packet, the length of the IP data packet header, and the length of the TCP header, and calculate the payload length (tcp_pload_len) of the TCP data segment:
[0063] The connection management module outputs the payload length and sequence number of the obtained TCP segment, the matching connection index, and the corresponding pointer information to the data transmission module together; the data transmission module transmits the TCP payload to the service module based on the payload length, sequence number, matching connection index, and pointer information of the received TCP segment. Specifically, if the payload length is not 0, the connection management module outputs seq, tcp_pload_len, and the pointer information recv_ptr to the payload read module, and outputs seq, tcp_pload_len, recv_ptr, and the matching connection index to the payload write module.
[0064] In this embodiment, the connection management module checks whether seq is equal to recv_ptr, and if so, updates recv_ptr. Similarly, after the verification passes, the connection management module will update recv_ptr and feedback the updated recv_ptr to the payload read module.
[0065] Some common English nouns or letters used in the present invention for the convenience of clear description are only for exemplary reference rather than limiting interpretation or specific usage, and the protection scope of the present invention should not be limited by their possible Chinese translations or specific letters.
[0066] It should also be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.
Claims
1. A TCP mirroring stream processing device based on FPGA, characterized in that, It is composed of a network receiving module, an FPGA module, and a service module. The FPGA module includes a verification module, a connection management module, a load extraction module, and a data transmission module; The network receiving module is used to receive network data and encapsulate it into network data packets, and output them to the verification module, the connection management module, and the load extraction module respectively for parallel processing; The verification module is used to determine whether the network data packet is a target data packet and whether it is complete, and feedback the verification result to the connection management module; The connection management module is used to determine whether the network data packet should be received, and match the connection to which the network data packet to be received belongs; The load extraction module is used to extract the TCP load in the network data packet; Based on the parallel processing results of the verification module, the connection management module, and the load extraction module, the data transmission module transmits the TCP load to the service module; The verification module determines whether the network data packet is a target data packet by sequentially determining whether the network data packet is an IP data packet and whether the load of the IP data packet is a TCP segment; The verification module performs an IP header check and a TCP segment check on the target data packet to confirm whether the target data packet is complete; The connection management module includes at least one group of connection registers; The connection register is used to store the quadruple information of different TCP mirror streams. The quadruple information is the source IP address, source port, destination IP address, and destination port. The multiple groups of connection registers are numbered to obtain a connection index, and the connection index is also associated with pointer information; The connection management module extracts the quadruple information of the network data packet and matches it with the connection register; After successful matching, the connection management module obtains the load length and sequence number of the TCP segment of the network data packet, and outputs them to the data transmission module together with the matched connection index and the pointer information; The data transmission module transmits the TCP load to the service module based on the load length of the TCP segment, the sequence number, the matched connection index, and the pointer information; 2. The TCP mirroring stream processing device based on FPGA according to claim 1, characterized in that, The connection management module also includes at least one group of configuration registers; The configuration register is used to store the source IP address, source port, destination IP address, destination port, and aging time; The connection management module matches the quadruple information that does not match the connection register with the configuration register; After successful matching, the quadruple information is stored in the unoccupied connection register; If the matching fails, the current network data packet is discarded; 3. The TCP mirroring stream processing device based on FPGA according to claim 1, wherein The data transmission module includes a load write module, a load read module, and a storage module; The load write module is used to write the TCP load into the storage module, and the written address range is determined based on the load length of the received TCP segment, the sequence number, and the pointer information; The load reading module is used to read the continuously received TCP load from the storage module, perform byte alignment, and then transmit it to the service module. The read address range is confirmed based on the sequence number, the connection index, and the pointer information.
4. The TCP mirroring stream processing device based on FPGA according to claim 2, wherein The connection management module further includes at least one set of blacklist registers, which are used to store quadruple information; The connection management module extracts the quadruple information of the network data packet and first matches it with the blacklist register; If the match is successful, the current network data packet is discarded; If the match fails, it continues to match with the connection register.
5. The TCP mirroring stream processing device based on FPGA according to claim 4, characterized in that It further includes a load analysis module connected to the load extraction module; The load analysis module analyzes the TCP load based on preset rules and stores the obtained quadruple information into the blacklist register; The quadruple information stored in the blacklist register will be deleted after a predetermined aging time.
6. The TCP mirroring stream processing device based on FPGA according to claim 1, characterized in that, The pointer information includes a continuously received data pointer and a selective reception data pointer group.
7. The TCP mirroring stream processing device based on FPGA according to claim 6, wherein It further includes an out-of-order rearrangement module, which realizes out-of-order reception and reordering of the TCP load based on the SACK mechanism.
8. The TCP mirroring stream processing device based on FPGA according to claim 7, characterized in that The out-of-order rearrangement module supports the sequence number wrap-around function; The sequence number wrap-around function is verified through the sequence number, the continuously received data pointer, and the highest two bits of the selective reception data pointer group.
Citation Information
Patent Citations
Integrated hardware implementing method for multi-layer amalgamation and parallel processing network access equipment
CN101321163A
TCP stream state integrity detection method based on FPGA
CN109951425A