Network layer data plane reliable transmission method and device based on hop-by-hop acknowledgement
By combining ASIC and FPGA chips in the data plane, the cache and security verification of data packets is performed using the hop-by-hop confirmation method, the high delay and high energy consumption problems caused by limited hardware resources in the prior art are solved, and the reliable transmission effect of low delay and high throughput in ultra-high-speed networks is achieved.
Patent Information
- Application Number
- CN202411853842.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-16
AI Technical Summary
The hardware resources of existing programmable switching chips are limited, making it difficult to achieve high-reliability network traffic transmission on the data plane. Especially in scenarios such as industrial Internet and satellite Internet, traditional methods require external devices to cache and process, resulting in large delays and high energy consumption.
A reliable transmission method of network layer data plane based on hop-by-hop confirmation is adopted, and data packet cache and high-intensity security verification are realized by combining two chips ASIC and FPGA. ASIC is used for initial processing and CRC verification, and FPGA is used for high-throughput cache and encryption verification, and ACK confirmation is performed on each hop to ensure the reliability and efficiency of data transmission.
It realizes low-latency, high-throughput network traffic processing and reliable transmission in ultra-high-speed networks. It is suitable for industrial Internet and satellite Internet scenarios with complex traffic processing requirements, reducing the latency of network resources utilization and improving network performance.
Smart Images

Figure CN119945959A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent programmable data plane, and in particular to a reliable transmission method and device for a network layer data plane based on hop-by-hop confirmation. Background Art
[0002] The diversified development of Internet application types has put forward higher requirements for network communication technology. With the rapid development of technologies such as industrial Internet and satellite Internet, more and more application scenarios require high-speed, reliable and low-latency data transmission and processing capabilities. Traditional network architecture and data plane technology have encountered a series of challenges such as high latency, low throughput and low reliability when facing these new application types. In recent years, programmable data plane, as a new technology, allows flexible configuration and programming of data plane functions in network devices, so that the network can quickly adapt to different application scenarios and needs. In addition, programmable data plane technology realizes high-speed processing and forwarding of data packets by introducing high-speed switching chips and programmable chips in network devices, providing network devices with higher performance and throughput. However, due to the limited hardware resources of current programmable switching chips, it is very difficult to achieve high-reliability transmission of network traffic on the data plane by relying solely on programmable switches, such as caching and retransmission of data packets. On the one hand, the static random access memory resources and register resources of current programmable switches are limited in number and cannot store a large number of data packets; on the other hand, the types of operations supported by current programmable switches are limited, making it difficult to perform high-precision calculations. Therefore, if you want to transmit network traffic on demand at high speed and high reliability on the data plane, you need to combine external devices, such as caching data packets through servers, so as to meet different application scenarios and needs. This method has three defects: it is difficult to achieve end-to-end high-speed transmission. After the transmission fails during the packet transmission process, the packet needs to be resent from the source end, and the adaptability to scenarios such as the industrial Internet is poor; the processing delay is large, and the external device has a large processing delay for data packets, which is difficult to meet the data transmission with high real-time requirements such as the industrial Internet; the energy consumption is large, such as caching through external servers, which consumes more energy. For example, when the satellite Internet edge computing is performed, the on-board equipment needs to cache some packets, and the use of external devices increases energy consumption. In fact, different network traffic has different requirements for the processing of data packets, some of which require high security, some require high reliability, and some require high bandwidth. Therefore, it is necessary to be able to intelligently process different traffic on the data plane.
[0003] Considering that the use of intelligent network traffic processing methods on the data plane can achieve efficient and reliable data transmission, thereby optimizing the utilization of network resources, this patent proposes a reliable transmission method and device for the network layer data plane based on hop-by-hop confirmation. In order to solve the resource limitation problem brought about by the current programmable switching chips, we used field programmable gate array chips (FPGA) to deploy for data packet caching and processing. Field programmable gate array chips can provide highly parallel computing power, with low latency and high throughput characteristics, and because of the programmable logic unit, they can be deployed to meet different processing needs only through program writing without replacing hardware devices. Specifically, in ASIC, data packets are classified according to the data packet header, and CRC-based security verification is performed on data packets that need high-reliability transmission, and then sent to FPGA. FPGA has stronger computing and caching capabilities, and performs high-intensity security verification on data packets to ensure that data packets come from trusted devices, and caches the packets, forwarding the processed data packets to ASIC, and ASIC forwards the data packets to the next hop; after a certain timeout wait (the delay is much lower than the current Internet end-to-end delay), if ASIC receives an ACK reply from the next hop, it notifies FPGA to delete the data packet, otherwise it takes out the data packet from FPGA and resends it to the next hop until the next hop ACK is received. After a certain number of retransmissions, if the next hop ACK is still not received, ASIC sends the packet to the backup next hop. Through this method and device, the packet can be transmitted to the next hop with the lowest delay at each hop until it reaches the destination. Better meet the high throughput and low latency requirements of the traffic processing process in ultra-high-speed networks. In general, this method and device has the advantages of low transmission latency, fast processing speed, and strong scalability in network traffic processing, verification, and reliable transmission in ultra-high-speed network scenarios, and can adapt to different traffic processing tasks. It is very suitable for providing reliable end-to-end communication in ultra-high-speed network scenarios with complex traffic processing requirements. Summary of the invention
[0004] The present invention aims to solve one of the technical problems in the related art at least to a certain extent.
[0005] To this end, the present invention proposes a reliable transmission method for the network layer data plane based on hop-by-hop confirmation. Under the premise of satisfying the normal exchange of data packets in the ultra-high-speed network, the network traffic is transmitted hop-by-hop by combining a network element device with a large-capacity cache and processing function, and the processed traffic is allowed to be securely verified according to the current traffic processing requirements in the ultra-high-speed network. This technology can effectively reduce the traffic transmission delay in the ultra-high-speed network and improve network performance to meet the needs of different application scenarios.
[0006] Another object of the present invention is to provide a network layer data plane reliable transmission device based on hop-by-hop confirmation.
[0007] To achieve the above object, the present invention proposes a reliable transmission method for network layer data plane based on hop-by-hop confirmation, comprising:
[0008] Divide the transmission path of the data packet into multiple transmission segments according to the routing information in the IP packet header; each transmission segment includes a start node and an end node of two adjacent hops that support high-reliability transmission;
[0009] Send a Send packet at the starting node of each transmission segment, and transparently forward the Send packet to the ending node through the common routing node along the transmission path;
[0010] The ACK packet corresponding to the Send packet replied by the terminating node is received. The terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried in the data packet, until the data packet reaches the terminating node of the last transmission segment to achieve hop-by-hop confirmation;
[0011] The data packet legitimacy verification is performed to ensure the performance and resources of hop-by-hop confirmation; wherein the data packet legitimacy verification includes: identity key generation mechanism, update verification code and verification of verification code.
[0012] The network layer data plane reliable transmission method based on hop-by-hop confirmation in the embodiment of the present invention may also have the following additional technical features:
[0013] In one embodiment of the present invention, the IP packet header, including RT_LIST[0-N], is a sequence of routing nodes supporting transmission, hopID represents the ID of the routing node, S represents an indicator of whether it is the last routing node, RT_MAN is an identifier for implementing security verification, flag is used to indicate the status of the packet, nextHdr indicates the protocol type of the next packet header, seq is the sequence number of the data packet, ack is the sequence number of the ACK, authcode1 is the CRC check code of the ASIC, authcode2 is the encryption verification code of the FPGA, and IP_ORIG is the original destination address of the data packet.
[0014] In one embodiment of the present invention, the Send packet is processed in the first hop start node, including:
[0015] ASIC processes the Send packet: The first-hop starting node on the entire transmission path receives a common IP data packet or a segment routing data packet. After the first-hop starting node identifies the packet as a packet that requires high-reliability transmission, it updates the RT_LIST[0-N] used between nodes, copies the destination address to IP_ORIG, updates seq in RT_MAN to the sequence number of the packet, obtains the Send packet, modifies the destination address to the end node of this transmission segment, and sends the data packet to the FPGA;
[0016] FPGA processes the Send packet: After receiving the Send packet, the FPGA caches the data packet. After completing the cache, it sets the timeout limit T and forwards the data packet to the termination node of this segment according to the normal IP.
[0017] In one embodiment of the present invention, the common high-reliability node includes a common termination node, which completes the generation of the data packet ACK packet and then converts to a common start node to complete data forwarding.
[0018] In one embodiment of the present invention, the common high-reliability node processes the Send packet, including:
[0019] ASIC: After receiving the Send packet, it updates the destination address to the next routing node that supports high-reliability transmission and sends the Send packet to the FPGA;
[0020] FPGA: After receiving the Send packet, it sends an ACK packet to the previous high-reliability node, carrying the sequence number of the Send packet and the sequence number of the ACK packet; at the same time, the Send packet is cached in the FPGA and forwarded to the next high-reliability node. At this time, it becomes a normal starting node for the next transmission segment.
[0021] In one embodiment of the present invention, the common high-reliability node processes the ACK packet, including:
[0022] ASIC: After receiving the ACK packet, ASIC forwards it to FPGA;
[0023] FPGA: After receiving the packet, the FPGA deletes the cache data of the corresponding sequence number, and the transmission of the transmission segment is completed; if no ACK data is received after the timeout limit T, the Send data packet is resent to the next hop high reliability node until ACK is received.
[0024] In one embodiment of the present invention, the last hop high reliability node processes the data packet, including:
[0025] ASIC: restores the IP destination address to the original destination address and sends it to FPGA;
[0026] FPGA: Reply ACK packet to the previous high-reliability node, then remove the newly added packet header content, the IP data packet becomes the IP packet sent by the source end, forwarded to the next-hop routing node or destination terminal, and restored to normal IP packet transmission.
[0027] In one embodiment of the present invention, the identity key generation mechanism includes:
[0028] Adjacent high-reliability nodes i and j share a pair of long-term valid keys LK i,j The key is used as the root key to calculate the identity key that changes dynamically with time slices. TS represents time slices. The control plane of the high-reliability network node periodically interacts with neighboring nodes to generate the identity key of each node and stores it in the data plane:
[0029]
[0030] In formula (1), MAC represents an encryption method, and when F is 0, it is the key keyA(i, j) between ASICs.
[0031] In one embodiment of the present invention, updating and verifying the verification code includes:
[0032] The output of the verification code algorithm uses formula (2), where key(i, j) is the key between adjacent nodes, nexthopID is the ID of the next hop, seq is the sequence number, and the output is the verification code authcode(i, j) of the data packet. The verification code is encapsulated by the sending node into the authcode1 or authcode2 field of the data packet:
[0033] authcode(i,j)=MAC key(i,j) (nexthopID||seq) (2)
[0034] First hop high reliable node: only update the verification code:
[0035] ASIC uses formula (2), where the MAC generation method can be a lightweight method such as CRC, the key is set to keyA(i,j), the verification code is generated according to the next hop and the sequence number seq, and the verification code is updated in authcode1;
[0036] FPGA uses formula (2), where the MAC generation method is a high-strength encryption method such as AES, and the key is set to keyF(i,j). On the transmission path, the verification code is generated according to the next hop and the sequence number seq, and the verification code is updated in authcode2;
[0037] Ordinary high-reliability node: Verify and update the verification code:
[0038] When ASIC receives a Send packet or an ACK packet, it first verifies whether authcode1 is correct based on keyA(i,j) and formula (2). If it is correct, it continues to use formula (2) to update the authcode1 of the Send packet for the next hop. If it is incorrect, it is discarded.
[0039] When receiving a Send packet or an ACK packet, the FPGA first verifies whether authcode2 is correct based on keyF(i,j) and formula (2). If it is incorrect, it is discarded. If it is correct, it continues to use formula (2) to update the authcode2 of the Send packet for the next hop.
[0040] Last hop high reliability node: Verification of verification code only:
[0041] For ASIC, upon receiving a Send packet or an ACK packet, it first verifies whether authcode1 is correct, and discards it if it is incorrect;
[0042] For FPGA, when receiving the Send packet, it first verifies whether authcode2 is correct. If it is incorrect, it will be discarded; the last hop node will not receive the ACK packet.
[0043] To achieve the above object, the present invention further provides a network layer data plane reliable transmission device based on hop-by-hop confirmation, comprising:
[0044] A hop-by-hop transmission module is used to divide the transmission path of the data packet into multiple transmission segments according to the routing information in the IP packet header; each transmission segment includes a starting node and a terminating node that support high-reliability transmission in two adjacent hops; a Send packet is sent at the starting node of each transmission segment, and the Send packet is transparently forwarded to the terminating node through a common routing node along the transmission path; an ACK packet corresponding to the Send packet replied by the terminating node is received, and the terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried by the data packet, until the data packet arrives at the terminating node of the last transmission segment for hop-by-hop confirmation;
[0045] The security verification module is used to verify the legitimacy of data packets to ensure the performance and resources of hop-by-hop confirmation; wherein the legitimacy verification of data packets includes: identity key generation mechanism, update verification code and verification of verification code.
[0046] The network layer data plane reliable transmission method and device based on hop-by-hop confirmation in the embodiments of the present invention can realize reliable data packet transmission at the network layer of an ultra-high-speed network, thereby realizing scenarios requiring high-speed and high-reliability transmission for industrial Internet, satellite Internet, etc. on the data plane.
[0047] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0049] Figure 1 It is a logic diagram of a network layer data plane reliable transmission method based on hop-by-hop confirmation according to an embodiment of the present invention;
[0050] Figure 2 is a schematic diagram of transmission segmentation according to an embodiment of the present invention;
[0051] Figure 3 is a schematic diagram of a data packet header format according to an embodiment of the present invention;
[0052] Figure 4 It is a structural diagram of a network layer data plane reliable transmission device based on hop-by-hop confirmation according to an embodiment of the present invention. DETAILED DESCRIPTION
[0053] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0054] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0055] The following describes a method and apparatus for reliable transmission of network layer data plane based on hop-by-hop confirmation according to an embodiment of the present invention with reference to the accompanying drawings.
[0056] Figure 1 is a flow chart of a network layer data plane reliable transmission method based on hop-by-hop confirmation according to an embodiment of the present invention. Figure 1 As shown, the method includes:
[0057] S1, dividing the transmission path of the data packet into multiple transmission segments according to the routing information in the IP packet header; wherein each transmission segment includes a starting node and an ending node of two adjacent hops supporting high-reliability transmission;
[0058] S2, sends a Send packet at the starting node of each transmission segment, and transparently forwards the Send packet to the end node through the common routing node along the transmission path;
[0059] S3, receiving the ACK packet corresponding to the Send packet replied by the terminating node, the terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried by the data packet, until the data packet reaches the terminating node of the last transmission segment to achieve hop-by-hop confirmation;
[0060] S4, verifying the legitimacy of data packets to ensure the performance and resources of hop-by-hop confirmation; wherein the legitimacy verification of data packets includes: identity key generation mechanism, updating verification code and verification of verification code.
[0061] It can be understood that the present invention is mainly used in scenarios such as industrial Internet and satellite Internet. By combining different intelligent data plane devices with high-reliability transmission capabilities, the device integrates two modules: a dedicated chip (ASIC) for data packet header processing and an FPGA for data packet caching and processing. Among them, the data packet header intelligent processing module parses, forwards and performs simple verification processing on the data packet according to the data packet header. The data packet cache processing verifies and caches the entire packet, and waits for the next hop node to return the ACK packet information of the packet. After receiving the corresponding ACK, the node deletes the cached packet; if the corresponding ACK is not received within a certain period of time, a certain number of timeout retransmissions are performed after the timeout, so as to realize the reception confirmation mechanism and timeout retransmission mechanism of the data packet at the network layer. This method and device can realize reliable data packet transmission at the network layer of ultra-high-speed networks, thereby realizing scenarios such as industrial Internet and satellite Internet that require high-speed and high-reliability transmission at the data plane.
[0062] In one embodiment of the present invention, a hop-by-hop transmission mechanism is used. The high-speed and highly reliable transmission mechanism of the present invention is based on the IP network layer and implements hop-by-hop transmission and confirmation of data packets in the data plane. Specifically, Figure 2As shown, the data packet transmission path is divided into multiple transmission segments, and each transmission segment includes two adjacent high-reliability nodes that support the high-reliability transmission of the present invention, namely the starting node and the terminating node (the routing node between the starting and terminating nodes is an ordinary routing node that does not support the hop-by-hop confirmation of the present invention, and only transparently forwards the data packet). The starting node of each transmission segment sends a Send packet (the patent refers to the data packet that needs high-reliability transmission as a Send packet), and the terminating node receives the Send packet and replies to the starting node with the ACK packet corresponding to the Send packet. Then, the terminating node re-initiates a new transmission segment as a new starting node based on the transmission path information carried by the data packet, and repeats this until the data packet arrives at the destination node (the terminating node of the last transmission segment). The hop-by-hop transmission mechanism is compatible with the end-to-end transmission mode of the IP network, fully utilizes the interconnection infrastructure provided by the IP network, is compatible with the traditional network, and ordinary routing nodes that do not support hop-by-hop confirmation can be forwarded according to the IP packet header, and have the ability to be incrementally deployed. First, a data packet parsing mechanism is established, and then the packets are processed and forwarded differently at each high-reliability node to complete reliable transmission.
[0063] Among them, the data packet parsing mechanism. The present invention completes the parsing of different data packets by defining a new IP packet header. Figure 3 As shown, the new IP packet header includes RT_LIST[0-N], which is a sequence of routing nodes supporting the transmission of the present invention, wherein hopID represents the ID of the routing node (generally an IP address or an IP prefix), and S represents an indicator of whether it is the last routing node (0 means there is a new termination node behind, and 1 means that the hop is the last termination node). RT_MAN is an identifier for implementing security verification, wherein flag is used to indicate the status of the packet, nextHdr indicates the protocol type of the next packet header, seq is the sequence number of the data packet, ack is the sequence number of the ACK, authcode1 is the CRC check code of the ASIC, and authcode2 is the encryption verification code of the FPGA. The IP header is a standard IP protocol (IPv4 or IPv6) header, and the protocol field in the IP header (tentatively designated as 157 in the present invention) indicates that the data packet is a packet that needs to be confirmed hop by hop. For this type of packet, each transmission segment performs hop by hop transmission. IP_ORIG is the original destination address of the data packet. The ASIC of this patent is a dedicated chip for processing ultra-high-speed network data packets on the current data plane, and the FPGA is a chip that can cache, process and forward, and can perform different operations on the data packets based on the data packet analysis results.
[0064] The Send packet is processed in the first hop starting node.
[0065] (1) ASIC processes the Send packet: The first-hop starting node on the entire transmission path receives a common IP (v4 or v6) data packet, or a segment routing (SRv6) data packet. After the first-hop starting node identifies the packet as a packet that requires high-reliability transmission (the IP header protocol field is 157), it updates the RT_LIST[0-N] used between nodes, copies the destination address to IP_ORIG, updates seq in RT_MAN to the sequence number of the packet, and adds the verification code field authcode1 in step 2 (if the security function is not required, it can be omitted). At this point, it becomes a data Send packet that requires high-reliability transmission, called a Send packet. Then, the destination address is modified to the end node of this transmission segment, and the data packet is sent to the FPGA.
[0066] (2) FPGA processes the Send packet: After receiving the Send packet, the FPGA caches the data packet. After completing the cache, it sets the timeout limit T and forwards the data packet to the termination node of this segment according to the normal IP. If there is a security requirement, a verification code can be added in authcode2.
[0067] Among them, ordinary high-reliability nodes process Send packets: ordinary high-reliability nodes include ordinary termination nodes, complete data packet ACK packet generation, and then convert to ordinary start nodes to complete data forwarding.
[0068] (1) ASIC: After receiving the Send packet, it updates the destination address to the next routing node that supports high-reliability transmission and sends the Send packet to the FPGA.
[0069] (2) FPGA: After receiving the Send packet, it sends an ACK packet to the previous high-reliability node, carrying the sequence number of the Send packet and the sequence number of the ACK packet. At the same time, the Send packet is cached in the FPGA and forwarded to the next high-reliability node. At this time, it becomes a normal starting node for the next transmission segment.
[0070] Among them, ordinary high-reliability nodes process ACK packets.
[0071] (1) ASIC: After receiving the ACK packet, ASIC forwards it to FPGA.
[0072] (2) FPGA: After receiving the packet, the FPGA deletes the cache data corresponding to the sequence number, and the transmission of the transmission segment is completed. If the ACK data is not received after a certain timeout T, the Send data packet is resent to the next hop high reliability node until the ACK is received, or if it is still not received after a certain number of timeouts (such as 3 times), other processing is performed. Other processing includes discarding the data packet and reporting it, reselecting an alternative route and continuing to transmit, which is not required by this patent.
[0073] Among them, the last hop high reliability node processes the data packet.
[0074] (1) ASIC: Because the subsequent nodes can no longer process the newly added packet header, the IP destination address is restored to the original destination address (i.e., the address in IP_ORIG in the new packet header) and sent to the FPGA.
[0075] (2) The FPGA replies with an ACK packet to the upstream high-reliability node, then removes the newly added packet header content. The IP data packet becomes the IP packet sent by the source (only the MAC address, TTL, and other fields change according to normal forwarding). It is then forwarded to the downstream routing node or destination terminal, and restored to normal IP packet transmission.
[0076] In one embodiment of the present invention, security verification. Based on the above scheme, hop-by-hop confirmation can be achieved. However, in order to improve security, if an attacker consumes a large amount of computing and storage resources of network element devices through denial of service attacks, data packet legitimacy verification can be performed to ensure performance and resources of hop-by-hop confirmation. The data packet legitimacy verification function mainly includes three parts: identity key generation mechanism, update verification code, and verification code verification.
[0077] Among them, the identity key generation mechanism.
[0078] Adjacent high-reliability nodes i and j share a pair of long-term valid keys LK i,j (valid for one day or longer), this key is used as the root key to calculate the identity key that changes dynamically with time slices. This key generation method can effectively reduce the overhead required for negotiation between nodes to generate identity keys. It represents the identity information of high-reliability network nodes (such as using the node IP address as identity information), and TS represents time slices. The control plane of the high-reliability network node periodically interacts with neighboring nodes to negotiate and generate the identity keys of each node, which are then stored in the data plane.
[0079]
[0080] In formula (1), MAC represents an encryption method. This patent can use AES. When F is 0, it is the key keyA(i, j) between ASICs. When F is 1, it is the key keyF(i, j) between FPGAs. Because CRC verification is used between ASICs, it is easy to be cracked, while AES and other high-strength verification code generation methods are used between FPGAs, so the keys are different. When ASICs also use high-strength encryption methods, they can also be combined into one key.
[0081] Among them, verification code update and verification:
[0082] The output of the verification code algorithm uses formula (2), where key(i,j) is the key between adjacent nodes, nexthopID is the ID of the next hop, seq is the sequence number (for ACK packets, the sequence number is the ack in the field), and the output is the verification code authcode(i,j) of the data packet, which is encapsulated by the sending node into the authcode1 or authcode2 field of the data packet.
[0083] authcode(i,j)=MAC key(i,j) (nexthopID||seq) (2)
[0084] First hop high reliable node: only update the verification code:
[0085] ASIC adopts formula (2), where the MAC generation method can be a lightweight method such as CRC, the key is set to keyA(i,j), the verification code is generated according to the next hop and sequence number seq, and the verification code is updated in authcode1.
[0086] FPGA uses formula (2), where the MAC generation method is a high-strength encryption method such as AES, the key is set to keyF(i,j), and on the transmission path, a verification code is generated based on the next hop and sequence number seq, and the verification code is updated in authcode2.
[0087] Ordinary high-reliability node: Verify and update the verification code:
[0088] For ASIC, upon receiving a Send packet or an ACK packet, first verify whether authcode1 is correct according to keyA(i,j) and formula (2). If it is correct, continue to use formula (2) to update the authcode1 of the Send packet for the next hop. If it is incorrect, discard it (all discarding behaviors are not mandatory requirements of this patent and can be configured to be marked with special identifiers and reported to the management center, etc. according to user needs);
[0089] When the FPGA receives a Send packet or an ACK packet, it first verifies whether authcode2 is correct based on keyF(i,j) and formula (2). If it is incorrect, it is discarded. If it is correct, it continues to use formula (2) to update the authcode2 of the Send packet for the next hop.
[0090] Last hop high reliability node: Verification of verification code only:
[0091] For ASIC, upon receiving a Send packet or an ACK packet, it first verifies whether authcode1 is correct, and discards it if it is incorrect;
[0092] For FPGA, when receiving the Send packet, it first verifies whether authcode2 is correct, and discards it if it is incorrect. The last hop node will not receive the ACK packet.
[0093] According to the network layer data plane reliable transmission method based on hop-by-hop confirmation in an embodiment of the present invention, reliable data packet transmission at the network layer of an ultra-high-speed network can be achieved, thereby realizing scenarios requiring high-speed and high-reliability transmission such as the industrial Internet and satellite Internet on the data plane, and can effectively reduce the traffic transmission delay within the ultra-high-speed network and improve network performance to meet the needs of different application scenarios.
[0094] In order to implement the above embodiment, Figure 4 As shown, this embodiment also provides a network layer data plane reliable transmission device 10 based on hop-by-hop confirmation, including:
[0095] The hop-by-hop transmission module 100 is used to divide the transmission path of the data packet into multiple transmission segments according to the routing information in the IP packet header; wherein each transmission segment includes a starting node and a terminating node of two adjacent hops supporting high-reliability transmission; a Send packet is sent at the starting node of each transmission segment, and the Send packet is transparently forwarded to the terminating node through a common routing node along the transmission path; an ACK packet corresponding to the Send packet replied by the terminating node is received, and the terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried by the data packet, until the data packet arrives at the terminating node of the last transmission segment to achieve hop-by-hop confirmation;
[0096] The security verification module 200 is used to verify the legitimacy of data packets to ensure the performance and resources of hop-by-hop confirmation; wherein the legitimacy verification of data packets includes: identity key generation mechanism, update verification code and verification of verification code.
[0097] According to the network layer data plane reliable transmission device based on hop-by-hop confirmation in the embodiment of the present invention, reliable data packet transmission at the network layer of an ultra-high-speed network can be realized, thereby realizing scenarios requiring high-speed and high-reliability transmission such as the industrial Internet and satellite Internet on the data plane, and can effectively reduce the traffic transmission delay within the ultra-high-speed network and improve network performance to meet the needs of different application scenarios.
[0098] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0099] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
Claims
1. A reliable transmission method for network layer data plane based on hop-by-hop confirmation, characterized in that: include: The transmission path of the data packet is divided into multiple transmission segments according to the routing information in the IP packet header; wherein each transmission segment includes a starting node and an ending node of two adjacent hops supporting high-reliability transmission; Send a Send packet at the starting node of each transmission segment, and transparently forward the Send packet to the ending node through the common routing node along the transmission path; The ACK packet corresponding to the Send packet replied by the terminating node is received. The terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried in the data packet, until the data packet reaches the terminating node of the last transmission segment to achieve hop-by-hop confirmation; The data packet legitimacy verification is performed to ensure the performance and resources of hop-by-hop confirmation; wherein the data packet legitimacy verification includes: identity key generation mechanism, update verification code and verification of verification code.
2. The method according to claim 1, characterized in that The IP packet header includes RT_LIST[0-N], which is a sequence of routing nodes supporting transmission, hopID represents the ID of the routing node, S represents an indicator of whether it is the last routing node, RT_MAN is an identifier for implementing security verification, flag is used to indicate the status of the packet, nextHdr indicates the protocol type of the next packet header, seq is the sequence number of the data packet, ack is the sequence number of the ACK, authcode1 is the CRC check code of the ASIC, authcode2 is the encryption verification code of the FPGA, and IP_ORIG is the original destination address of the data packet.
3. The method according to claim 1, characterized in that The Send packet is processed in the first hop starting node, including: ASIC processes the Send packet: The first-hop starting node on the entire transmission path receives a common IP data packet or a segment routing data packet. After the first-hop starting node identifies the packet as a packet that requires high-reliability transmission, it updates the RT_LIST[0-N] used between nodes, copies the destination address to IP_ORIG, updates seq in RT_MAN to the sequence number of the packet, obtains the Send packet, modifies the destination address to the end node of this transmission segment, and sends the data packet to the FPGA; FPGA processes the Send packet: After receiving the Send packet, the FPGA caches the data packet. After completing the cache, it sets the timeout limit T and forwards the data packet to the termination node of this segment according to the normal IP.
4. The method according to claim 1, characterized in that: Ordinary high-reliability nodes include ordinary termination nodes, which complete the generation of data packet ACK packets and then convert into ordinary start nodes to complete data forwarding.
5. The method according to claim 4, characterized in that Ordinary high-reliability nodes process Send packets, including: ASIC: After receiving the Send packet, it updates the destination address to the next routing node that supports high-reliability transmission and sends the Send packet to the FPGA; FPGA: After receiving the Send packet, it sends an ACK packet to the previous high-reliability node, carrying the sequence number of the Send packet and the sequence number of the ACK packet; at the same time, the Send packet is cached in the FPGA and forwarded to the next high-reliability node. At this time, it becomes a normal starting node for the next transmission segment.
6. The method according to claim 5, characterized in that Ordinary high-reliability nodes process ACK packets, including: ASIC: After receiving the ACK packet, ASIC forwards it to FPGA; FPGA: After receiving the packet, the FPGA deletes the cache data of the corresponding sequence number, and the transmission of the transmission segment is completed; if no ACK data is received after the timeout limit T, the Send data packet is resent to the next hop high reliability node until ACK is received.
7. The method according to claim 6, characterized in that The last hop high reliability node processes the data packet, including: ASIC: restores the IP destination address to the original destination address and sends it to FPGA; FPGA: Reply ACK packet to the previous high-reliability node, then remove the newly added packet header content, the IP data packet becomes the IP packet sent by the source end, forwarded to the next-hop routing node or destination terminal, and restored to normal IP packet transmission.
8. The method according to claim 1, characterized in that The identity key generation mechanism includes: Adjacent high-reliability nodes i and j share a pair of long-term valid keys LK i,j The key is used as the root key to calculate the identity key that changes dynamically with time slices. TS represents time slices. The control plane of the high-reliability network node periodically interacts with neighboring nodes to generate the identity key of each node and stores it in the data plane: In formula (1), MAC represents an encryption method, and when F is 0, it is the key keyA(i, j) between ASICs.
9. The method according to claim 1, characterized in that: Verification code update and verification, including: The output of the verification code algorithm uses formula (2), where key(i, j) is the key between adjacent nodes, nexthopID is the ID of the next hop, seq is the sequence number, and the output is the verification code authcode(i, j) of the data packet. The verification code is encapsulated by the sending node into the authcode1 or authcode2 field of the data packet: authcode(i,j)=MAC key(i,j) (nexthopID||seq) (2) First hop high reliable node: only update the verification code: ASIC uses formula (2), where the MAC generation method can be a lightweight method such as CRC, the key is set to keyA(i,j), and the verification code is generated according to the next hop and sequence number seq, and the verification code is updated in authcode1; FPGA uses formula (2), where the MAC generation method is a high-strength encryption method such as AES, and the key is set to keyF(i,j). On the transmission path, the verification code is generated according to the next hop and the sequence number seq, and the verification code is updated in authcode2; Ordinary high-reliability node: verify and update the verification code: When ASIC receives a Send packet or an ACK packet, it first verifies whether authcode1 is correct based on keyA(i,j) and formula (2). If it is correct, it continues to use formula (2) to update the authcode1 of the Send packet for the next hop. If it is incorrect, it is discarded. When receiving a Send packet or an ACK packet, the FPGA first verifies whether authcode2 is correct based on keyF(i,j) and formula (2). If it is incorrect, it is discarded. If it is correct, it continues to use formula (2) to update the authcode2 of the Send packet for the next hop. Last hop high reliability node: Verification of verification code only: For ASIC, upon receiving a Send packet or an ACK packet, it first verifies whether authcode1 is correct, and discards it if it is incorrect; For FPGA, when receiving the Send packet, it first verifies whether authcode2 is correct. If it is incorrect, it will be discarded; the last hop node will not receive the ACK packet.
10. A reliable transmission device for network layer data plane based on hop-by-hop confirmation, characterized in that: include: A hop-by-hop transmission module is used to divide the transmission path of the data packet into multiple transmission segments according to the routing information in the IP packet header; each transmission segment includes a starting node and a terminating node that support high-reliability transmission in two adjacent hops; a Send packet is sent at the starting node of each transmission segment, and the Send packet is transparently forwarded to the terminating node through a common routing node along the transmission path; an ACK packet corresponding to the Send packet replied by the terminating node is received, and the terminating node re-initiates a new transmission segment as a new starting node according to the transmission path information carried by the data packet, until the data packet arrives at the terminating node of the last transmission segment for hop-by-hop confirmation; The security verification module is used to verify the legitimacy of data packets to ensure the performance and resources of hop-by-hop confirmation; wherein the legitimacy verification of data packets includes: identity key generation mechanism, update verification code and verification of verification code.
Citation Information
Patent Citations
Encryption method for secure packet transmission
CN101455025A
Network resource naming method and generating device
CN103873602A
Reverse path validation for source routed networks
CN106664244A
A wireless routing method with hop-by-hop acknowledgement mechanism
CN109041156A
Network path verification method and system based on SRv6
CN111585890A