Method for detecting IFIT along with stream and node equipment

By constructing IFIT instance information and generating MQC strategies, the problem of limited fixed traffic characteristics of the five-tuple mode detection method in the existing flow-around detection technology is solved, and more flexible and accurate flow-around detection is achieved, which is suitable for device-level applications.

CN119996249APending Publication Date: 2025-05-13NEW H3C TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510218030.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the existing flow-on detection technology, the traffic characteristics of the five-tuple mode detection method are relatively fixed and limited, making it difficult to flexibly match complex service traffic.

Method used

The QOS process obtains the detection attribute information of the IFIT process on the target flow, constructs IFIT instance information and generates MQC policies, and issues it to the network processor NP to generate ACL result table entries to achieve more flexible and rich traffic detection.

Benefits of technology

It realizes more flexible and accurate flow-on-stream detection, can be extended to the device level, reduce instance configuration, and saves hardware table entry resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996249A_ABST
    Figure CN119996249A_ABST
Patent Text Reader

Abstract

The invention provides a method for detecting IFIT along with stream and node equipment, and the method comprises the steps: obtaining the detection attribute information of an IFIT process for a target stream through a QOS process, constructing IFIT instance information through the QOS process according to the detection attribute information corresponding to the target stream and the message detection feature of the target stream, generating an MQC strategy according to the IFIT instance information, and sending the MQC strategy to the node equipment; and the MQC strategy is issued to a network processor NP, so that the NP generates an ACL result table item according to the MQC strategy, and IFIT detection is carried out according to the ACL result table item. Through the method, the IFIT stream following detection of the equipment level can be expanded and realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present specification relates to the field of communication technology, and in particular to a method and node device for detecting IFIT along the flow. Background Art

[0002] IFIT (In-situ Flow Information Telemetry): flow detection;

[0003] QOS (Quality of Service): Quality of service;

[0004] MQC (Modular QoS Configuration): Modular QoS configuration;

[0005] IFIT (In-situ Flow Information Telemetry) is a flow OAM (Operations, Administration and Maintenance) detection technology. Flow detection is based on normal service messages. After the head node identifies the service message to be detected according to pre-defined features, it inserts the DOH flow detection message header into the service message for subsequent forwarding node identification and processing. The flow detection header contains: DeviceID device information, FLOWID target flow identifier, detection cycle and detection mode, among which: DeviceID is used to uniquely identify a device participating in iFIT measurement, and DeviceID and FlowID uniquely identify an iFIT target flow; FlowID is automatically generated by the ingress node and will be encapsulated in the iFIT message header and passed to the intermediate node and the egress node, and is used to uniquely identify a target flow together with the DeviceID in the iFIT measurement network; the detection cycle refers to the device performing iFIT measurement in a periodic manner. The time interval from the start of a measurement to the collection and reporting of the measurement data is called a measurement cycle; the detection mode indicates whether this measurement is end-to-end measurement or point-by-point measurement.

[0006] Currently, the traffic characteristics that can be matched through the five-tuple mode detection method are relatively fixed and limited. Summary of the invention

[0007] In order to overcome the problems existing in the related art, this specification provides a method and node device for in-flow detection of IFIT.

[0008] According to a first aspect of an embodiment of this specification, a method for detecting IFIT along with flow is provided, the method comprising:

[0009] The detection attribute information of the target flow by the IFIT process is obtained through the QOS process;

[0010] The QOS process constructs IFIT instance information according to the detection attribute information corresponding to the target flow and the packet detection characteristics of the target flow, and generates an MQC policy according to the IFIT instance information;

[0011] Sending the MQC policy to the network processor NP so that the NP generates an ACL result table entry according to the MQC policy;

[0012] An IFIT detection is performed according to the ACL result table entry.

[0013] The detection attribute information includes:

[0014] Detection mode, Flow ID, part or all of the detection period.

[0015] Wherein, the method further comprises:

[0016] Preset the packet detection features of the target flow in the flow classifier of the MQC policy;

[0017] Add the ifit enable action in the MQC policy flow action behavior and apply the MQC policy to the interface.

[0018] The sending of the MQC policy to the network processor NP so that the NP generates an ACLresult table entry according to the MQC policy includes:

[0019] The QOS process sends the MQC policy with the IFIT instance information to the NP;

[0020] NP parses the ACL rules configured by the classifier in the MQC policy to generate ACL KEY entries;

[0021] The IFIT enable action of behavior in the MQC policy and the IFIT instance information are parsed to generate the ACL result entry.

[0022] The performing IFIT detection according to the ACL result table item includes:

[0023] Detect traffic through IFIT ACL hardware entries;

[0024] Encapsulate the target flow matching the ACL entry with the flow detection header DOH.

[0025] It can be seen from the above embodiments that by specifying more flexible, rich and accurate service traffic for follow-up detection through MQC, device-level IFIT follow-up detection can be extended to be implemented.

[0026] According to a second aspect of an embodiment of this specification, a node device is provided, the node device comprising:

[0027] An acquisition module is used to acquire the detection attribute information of the target flow by the IFIT process through the QOS process;

[0028] A processing module, used for the QOS process to construct IFIT instance information according to the detection attribute information corresponding to the target flow and the message detection characteristics of the target flow, and to generate an MQC policy according to the IFIT instance information;

[0029] A sending module, used for sending the MQC policy to the network processor NP, so that the NP generates an ACLresult table item according to the MQC policy;

[0030] The detection module is used to perform IFIT detection according to the ACL result table item.

[0031] The detection attribute information includes:

[0032] Detection mode, Flow ID, part or all of the detection period.

[0033] Wherein, the node device also includes:

[0034] The configuration module is used to preset the packet detection features of the target flow in the flow classifier of the MQC policy, add the ifit enable action in the flow action behavior of the MQC policy, and apply the MQC policy to the interface.

[0035] The sending module is specifically used to send the MQC policy with IFIT instance information to the NP through the QOS process, and the NP parses the ACL rules configured by the classifier in the MQC policy to generate the ACL KEY table item, and parses the IFIT enable action of the behavior in the MQC policy and the IFIT instance information to generate the ACL result table item.

[0036] The detection module is specifically used to detect the flow through the IFIT ACL hardware table entry, and encapsulate the target flow matching the ACL table entry with the flow detection header DOH.

[0037] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.

[0039] Figure 1 This is an interactive schematic diagram of IFIT flow detection according to an exemplary embodiment of this specification.

[0040] Figure 2 It is a flowchart of a method for in-flow detection of IFIT according to an exemplary embodiment of the present specification. DETAILED DESCRIPTION

[0041] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this specification. Instead, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0042] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "the" and "the" used in this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0043] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0044] like Figure 1As shown, in the end-to-end path, when the message enters the IFIT head node Ingres device, according to the predetermined message features, the message that meets the feature matching is encapsulated with a DOH flow detection header. The head node obtains the timestamp information of the message, counts the message within the period and combines the traffic features, and reports the above information to the analyzer. The message encapsulated with the DOH header will continue to be forwarded in the IFIT link. The egress node identifies the flow detection message based on the DOH header, and also reports the traffic features, message counts and time information to the analyzer, and continues to forward according to the route after stripping the DOH header.

[0045] The current flow detection methods have the following detection methods according to the different detection granularity:

[0046] At the detection granularity based on five-tuples, the relevant field information in the IP packet header can be uniquely determined. The field information can be the source MAC, destination MAC, VLAN, VLAN Pri, VSI Xconnect, or the five-tuple of source IP address, destination IP address, protocol number, source port number, destination port number, and DSCP of the packet to generate a static detection flow. This method is suitable for performance detection of specific flows.

[0047] Under PeerLocator-based detection, a static detection flow is generated by specifying the VPN and the peer IPv4 / IPv6 address. This method is suitable for performance detection of the overall end-to-end traffic.

[0048] In the policy tunnel-based detection, statistics are collected through packets entering the specified tunnel path, which is suitable for performance detection of the end-to-end path of the policy tunnel;

[0049] At the APN-based detection granularity, the static detection flow can be uniquely determined by specifying the APN6 instance to match the APN6 corresponding domain field in the message after the target flows into the tunnel. This method is suitable for performance detection of specific flows.

[0050] It can be seen from the above detection methods that the granularity of feature matching for traffic is relatively coarse.

[0051] Currently, among the supported flow detection methods, there are more rules belonging to the five-tuple detection method, which can specify the source IP, destination IP, protocol number, source port, destination port, DSCP and source MAC, destination MAC, VLAN, and VLAN priority.

[0052] The detection of IFIT five-tuple is implemented using ACL: at the head node, the driver receives the FLOW flow rules sent by the platform IFIT and parses them, sends the different characteristic field values ​​of the FLOW rules to the KEY of the ACL hardware table item, generates the ACLKEY table, and fills the IFIT instance information DEVICE ID, FLOW ID, detection cycle, etc. sent by the platform to the driver into the result of the ACL table item. The microcode (network processor NP) will first generate ACLKEY according to the actual traffic characteristics for the traffic to be forwarded by the interface, and then match it with the IFIT ACL KEY table item sent by the driver. The traffic microcode that matches the IFIT ACL table item will encapsulate the DOH flow detection header. The head node will query the IFITMAPPING dynamic flow table according to the interface and FLOW instance information for the message encapsulated with the DOH flow detection header. If the microcode does not hit, it will actively trigger the first packet sending event and notify the driver to generate the dynamic flow IFIT MAPPING table item. For packets matched by the IFIT MAPPING table entry, the microcode can obtain the packet count from the statistical offset in the IFIT MAPPING table, and report the timestamp, period, and packet information carried by the packet within the period. At the same time, the packet encapsulated with the DOH flow detection will continue to be forwarded in the network device. At the tail node, the packet is identified with the flow detection header, and the packet encapsulated with the DOH detection header is also counted and reported in the same way. After the DOH flow detection header of the packet is stripped off, it is terminated or continued to be forwarded. For the packets reported to the analyzer, by extracting features, the message delay and count of a certain flow at the head node and the tail node are compared to obtain the message delay and packet loss rate on the forwarding link.

[0053] In order to solve the above technical problems, the present disclosure provides a method for detecting IFIT along with the flow, such as Figure 2 As shown, the method includes:

[0054] S201 obtains the detection attribute information of the target flow by the IFIT process through the QOS process;

[0055] The S202QOS process constructs IFIT instance information according to the detection attribute information corresponding to the target flow and the packet detection characteristics of the target flow, and generates an MQC policy according to the IFIT instance information;

[0056] S203: sending the MQC policy to the network processor NP, so that the NP generates an ACL result table entry according to the MQC policy;

[0057] S204 performs IFIT detection according to the ACL result table entry.

[0058] In this application, more flexible and rich traffic detection is formulated by configuring MQC policies. Specifically, in the MQC flow classifier, almost all features of the message can be specified, with more powerful rule matching capabilities. In addition to the rules contained in the above five-tuple detection, MPLS, IP message priority and ACL group rules can also be specified, including detailed features such as message length packet-length, time-range of receiving messages, message fragmentation information fragment, ack, syn and urg of TCP protocol, etc. In addition to choosing to match specific values, rules such as packet-length and ttl can also choose to match range values ​​or not match certain values. Compared with the fixed five-tuple matching method, it is more flexible.

[0059] Before executing step S201, the packet features of the target flow that needs to be detected in-flight can be preset in the flow classifier of the MQC, the ifit enable action can be added in the MQC flow action behavior, and then the policy can be applied to the interface.

[0060] In step S201, the IFIT process synchronizes the detection attribute information of the target flow to the QOS process by issuing configuration, wherein the detection attribute information may include: detection mode, Flow ID, part or all of the detection period.

[0061] In step S202, after the QOS process obtains the detection attribute information of the target flow, it constructs the IFIT instance information in combination with the packet detection characteristics, wherein the packet detection characteristics may include the packet's own attribute characteristics. For example, the packet detection characteristics may include: in addition to the rules contained in the above-mentioned five-tuple detection, it can also specify MPLS, IP packet priority and ACL group rules, including detailed characteristics such as packet length packet-length, time-range for receiving the packet, packet fragmentation information fragment, tcp protocol ack, syn and urg, etc. In addition to being able to choose to match specific values, rules such as packet-length and ttl can also choose to match range values ​​or not match certain values.

[0062] In this embodiment, the QOS process sends the MQC policy with the IFIT instance information to the driver (NP), and the driver parses and generates an ACL KEY table item according to the ACL rule configured by the classifier in the MQC. The ifitenable action of the behavior in the MQC and the instance information of ifit are parsed to generate an ACL result table item. The IFIT ACL hardware table item is used for traffic matching of the flow detection. The message that can match the ACL table item is encapsulated with the flow detection header DOH. The processing of the detection message statistics and delay after the DOH header is encapsulated remains the same as the original processing flow.

[0063] In this embodiment, if the detection period or matching rule of the IFIT instance changes, the QOS process notifies the driver of the latest IFIT instance information, and the driver performs MQC re-parsing to modify the ACL hardware entry.

[0064] It can be seen from the above embodiments that the MQC-granularity on-the-fly detection method can drive the use of the same software and hardware resources as the five-tuple detection method to achieve more flexible and accurate on-the-fly detection. If the MQC detection method is applied globally, it can be extended to implement device-level IFIT on-the-fly detection. Device-level IFIT means that multiple interfaces use the same IFIT instance, which can reduce instance configuration and save hardware table resources.

[0065] Based on the above method embodiments, the present disclosure further provides a node device, the node device comprising:

[0066] An acquisition module is used to acquire the detection attribute information of the target flow by the IFIT process through the QOS process;

[0067] A processing module, used for the QOS process to construct IFIT instance information according to the detection attribute information corresponding to the target flow and the message detection characteristics of the target flow, and to generate an MQC policy according to the IFIT instance information;

[0068] A sending module, used for sending the MQC policy to the network processor NP, so that the NP generates an ACLresult table item according to the MQC policy;

[0069] The detection module is used to perform IFIT detection according to the ACL result table item.

[0070] The detection attribute information includes:

[0071] Detection mode, Flow ID, part or all of the detection period.

[0072] Wherein, the node device also includes:

[0073] The configuration module is used to preset the packet detection features of the target flow in the flow classifier of the MQC policy, add the ifit enable action in the flow action behavior of the MQC policy, and apply the MQC policy to the interface.

[0074] The sending module is specifically used to send the MQC policy with IFIT instance information to the NP through the QOS process, and the NP parses the ACL rules configured by the classifier in the MQC policy to generate the ACL KEY table item, and parses the IFIT enable action of the behavior in the MQC policy and the IFIT instance information to generate the ACL result table item.

[0075] The detection module is specifically used to detect the flow through the IFIT ACL hardware table entry, and encapsulate the target flow matching the ACL table entry with the flow detection header DOH.

[0076] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. A person of ordinary skill in the art can understand and implement it without paying creative labor.

[0077] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0078] Those skilled in the art will readily appreciate other embodiments of the specification after considering the specification and practicing the invention claimed herein. The specification is intended to cover any variations, uses or adaptations of the specification that follow the general principles of the specification and include common knowledge or customary techniques in the art that are not claimed in the specification. The specification and examples are to be considered exemplary only, and the true scope and spirit of the specification are indicated by the following claims.

[0079] It should be understood that the present description is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present description is limited only by the appended claims.

[0080] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.

Claims

1. A method for detecting IFIT in-flow, characterized in that: The method comprises: The detection attribute information of the target flow by the IFIT process is obtained through the QOS process; The QOS process constructs IFIT instance information according to the detection attribute information corresponding to the target flow and the packet detection characteristics of the target flow, and generates an MQC policy according to the IFIT instance information; Sending the MQC policy to the network processor NP so that the NP generates an ACL result table entry according to the MQC policy; An IFIT detection is performed according to the ACL result table entry.

2. The method according to claim 1, characterized in that The detection attribute information includes: Detection mode, Flow ID, part or all of the detection period.

3. The method according to claim 1, characterized in that The method further comprises: Preset the packet detection features of the target flow in the flow classifier of the MQC policy; Add the ifit enable action in the MQC policy flow action behavior and apply the MQC policy to the interface.

4. The method according to claim 1, characterized in that: The sending of the MQC policy to the network processor NP so that the NP generates an ACL result table item according to the MQC policy includes: The QOS process sends the MQC policy with the IFIT instance information to the NP; NP parses the ACL rules configured by the classifier in the MQC policy to generate ACL KEY entries; The IFIT enable action of behavior in the MQC policy and the IFIT instance information are parsed to generate the ACL result entry.

5. The method according to claim 1, characterized in that The performing IFIT detection according to the ACL result table item includes: Detect traffic through IFIT ACL hardware entries; Encapsulate the target flow matching the ACL entry with the flow detection header DOH.

6. A node device, characterized in that: The node device comprises: An acquisition module is used to acquire the detection attribute information of the target flow by the IFIT process through the QOS process; A processing module, used for the QOS process to construct IFIT instance information according to the detection attribute information corresponding to the target flow and the message detection characteristics of the target flow, and to generate an MQC policy according to the IFIT instance information; A sending module, used for sending the MQC policy to the network processor NP, so that the NP generates an ACLresult table item according to the MQC policy; The detection module is used to perform IFIT detection according to the ACL result table item.

7. The node device according to claim 6, characterized in that: The detection attribute information includes: Detection mode, Flow ID, part or all of the detection period.

8. The node device according to claim 6, characterized in that: The node device also includes: The configuration module is used to preset the packet detection features of the target flow in the flow classifier of the MQC policy, add the ifit enable action in the flow action behavior of the MQC policy, and apply the MQC policy to the interface.

9. The node device according to claim 6, characterized in that: The sending module is specifically used to send the MQC policy with IFIT instance information to the NP through the QOS process, and the NP parses the ACL rules configured by the classifier in the MQC policy to generate the ACL KEY table item, and parses the IFIT enable action of the behavior in the MQC policy and the IFIT instance information to generate the ACL result table item.

10. The node device according to claim 6, characterized in that: The detection module is specifically used to detect the flow through the IFIT ACL hardware table items, and encapsulate the target flow matching the ACL table items with the flow detection header DOH.

Citation Information

Cited By

  • Stream following detection method based on dynamic strategy tuning and intelligent shunting

    CN122420196A