Method and equipment for realizing strict mode of source address encapsulation slice instance
By setting slice instances and strict pattern recognition table entries in the incoming direction access control table, matching the fields of IPv6 data packets, and cacheing and marking data packets, the problem that existing switching chips cannot recognize strict pattern flag bits is solved, and the forwarding support for strict pattern of source address slices is realized.
Patent Information
- Application Number
- CN202510238037.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-28
AI Technical Summary
The existing switching chips cannot recognize the strict mode flag bits in IPv6 packets and cannot support the forwarding mechanism of strict mode of source address slicing.
By setting slice instance identification table entries and strict pattern identification table entries in the incoming direction access control table, matching the slice instance fields and strict pattern fields of IPv6 data packets, cache data packets, and set slice instance identification and strict pattern flag bits in the message descriptor.
Implementation of whether IPv6 packets carry Strict-flag fields on switching chips that do not support identification of strict mode, thus supporting the forwarding mechanism of strict mode of source address slicing.
Smart Images

Figure CN119996282A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to communication technology, specifically a method and device for implementing a strict mode of source address encapsulation slice instance Background Art
[0002] SRv6 network slicing divides an SRv6 network into multiple virtual networks. Different virtual networks are independent of each other. Administrators can allocate resources on demand for different services based on the business characteristics of tenants and provide differentiated queue scheduling capabilities to meet the different needs of various services without affecting the existing network.
[0003] Slice ID-based network slicing is a network slicing technology solution applied in SRv6 networking scenarios. Slice ID is introduced in the data plane to distinguish different network slices. It uses the globally unique Slice ID to identify and divide the slice network.
[0004] The Slice ID encapsulation methods of the SRv6 network include: IPv6 Hop-by-Hop Extension Header (HBH) encapsulation, IPv6 source address encapsulation, and IPv6 flow label encapsulation.
[0005] The first of the lower 32 bits of the source IP address of an IPv6 packet that uses IPv6 source address encapsulation is the strict mode (Strict-Flag) flag; the remaining 31 bits carry the slice instance identifier. When the device forwards the IPv6 data packet, it first queries the FIB (Forward Information Base) table to find the outbound interface; when the outbound interface is bound to the channel of the slice instance, the IPv6 packet with the strict mode field as 1 is forwarded through the slice channel. When the outbound interface is not bound to the slice instance channel, the IPv6 packet with the strict mode field as 1 is discarded; if the strict mode field in the IPv6 data packet is 0, it is forwarded in SRv6 non-slicing mode.
[0006] Because the switching chips of the existing switch devices in the network were introduced earlier and are not flexibly programmable, they cannot recognize the strict mode flag of the IPv6 source address and cannot support the strict mode forwarding mechanism. Summary of the invention
[0007] The purpose of this application is to provide a method and device for implementing a strict mode of source address encapsulation slicing instance, and to identify whether an IPv6 message carries a Strict-flag field on a switching chip that does not support strict mode recognition, thereby supporting a forwarding mechanism for source address slicing strict mode.
[0008] To achieve the above-mentioned purpose, the present application provides a method for implementing a strict mode of source address encapsulation slice instance, the method comprising: setting a first slice instance identification table entry in an inbound access control table; wherein the matching item is the first slice instance identification field; the action item is to set the corresponding first slice instance identification in a message descriptor; setting a second slice instance identification table entry in the inbound access control table; wherein the matching item is the second slice instance identification field; the action item is to set the corresponding second slice instance identification in the message descriptor; setting a strict mode identification table entry in the inbound access control table; wherein the matching item strict mode field is equal to 1; the action item is to set a strict mode flag in the message descriptor; matching the slice instance identification table entry and the strict mode identification table entry with the slice instance field of the source IP address of the first IPv6 data message received through the first port, caching the first IPv6 data message and setting the slice instance identification and the strict mode flag in the message descriptor of the first IPv6 data message.
[0009] To achieve the above-mentioned purpose, the present application provides a device for implementing a slice strict mode based on source address encapsulation, the device comprising: a setting module, used to set a first slice instance identification table item, a first slice instance identification table item, and a strict mode identification table item in an inbound access control table; wherein the matching item of the first slice instance identification table item is the first slice instance identification field, and the action item is to set the corresponding first slice instance identification in the message descriptor; the matching item of the second slice instance identification table item is the second slice instance identification field, and the action item is to set the corresponding second slice instance identification in the message descriptor; the matching item strict mode field of the strict mode identification table item is equal to 1, and the action item is to set the strict mode flag of the message descriptor; a forwarding module, used to match the slice instance identification table item and the strict mode identification table item based on the slice instance field of the source IP address of the first IPv6 data message received at the first port, cache the first IPv6 data message and set the slice instance identification and the strict mode flag in the message descriptor of the first IPv6 data message.
[0010] The beneficial effect of the present application is that it is possible to identify whether an IPv6 message carries a Strict-flag field on a switching chip that does not support strict mode identification, thereby supporting a forwarding mechanism for source address slicing strict mode. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 A flowchart of an embodiment of a method for implementing a slicing strict mode based on source address encapsulation provided by the present application;
[0012] Figure 2 A schematic diagram of the slicing strict mode based on source address encapsulation of the network device provided by this application;
[0013] Figure 3 A flowchart of a device embodiment for implementing a slicing strict mode based on source address encapsulation provided in the present application. DETAILED DESCRIPTION
[0014] The present invention will be described in detail with multiple examples shown in multiple figures. In the following detailed description, multiple specific details are used to provide a comprehensive understanding of the present application. Known methods, steps, components and circuits are not described in detail in the examples to avoid making these examples difficult to understand.
[0015] Among the terms used, the term "include" means including but not limited to; the term "contain" means including but not limited to; the terms "above", "within" and "below" are inclusive of the number; the terms "greater than" and "less than" are exclusive of the number. The term "based on" means based on at least a part thereof.
[0016] Figure 1 A flowchart of an embodiment of a method for implementing a slicing strict mode based on source address encapsulation provided by the present application, the method comprising:
[0017] Step 101, in the inbound access control table, a first slice instance identification table entry is set; wherein the matching item is the first slice instance identification field; and the action item is setting the corresponding first slice instance identification in the message descriptor;
[0018] Step 102, in the inbound access control table, set a second slice instance identification table entry; wherein the matching item is the second slice instance identification field; and the action item is setting the corresponding second slice instance identification in the message descriptor;
[0019] Step 103, in the inbound access control table, set a strict mode identification table entry; wherein the matching item strict mode field is equal to 1; the action item is to set the strict mode flag bit in the message descriptor;
[0020] Step 104, the slice instance field of the source IP address of the IPv6 data packet received through the port matches the slice instance identification table entry and the strict mode identification table entry, caches the IPv6 data packet and sets the slice instance identifier and the strict mode flag in the message descriptor of the IPv6 data packet.
[0021] The beneficial effect of the present application is that it is possible to identify whether an IPv6 message carries a Strict-flag field on a switching chip that does not support strict mode identification, thereby supporting a forwarding mechanism for source address slicing strict mode.
[0022] Figure 2 A schematic diagram of the slicing strict mode based on source address encapsulation of the network device provided by this application;
[0023] Ports C and Port D of the network device are bound to slice instance 1, and port Port E is bound to slice instance 2.
[0024] The network device sets the identification ACL entry Entry 211 of slice instance 1, the identification ACL entry Entry 212 of slice instance 2, and the strict mode identification ACL entry Entry 213 in the inbound access control table 21 of the switching chip 20.
[0025] In ACL table entry 211: the matching item is the binary of slice instance 1 identifier, and the action item is to set the corresponding slice instance 1 identifier in the message descriptor.
[0026] In ACL table entry 212: the matching item is the binary of slice instance 2 identifier, and the action item is to set the corresponding slice instance 2 identifier in the message descriptor.
[0027] In the strict mode identification ACL table entry Entry 213: the matching item strict mode field is equal to 1, and the action item is to set the strict mode flag bit of the message descriptor.
[0028] The network device sets the slice instance 1 forwarding ACL table entry Entry 231 of port Port C, the slice instance 1 forwarding ACL table entry Entry 232 of port Port D, the switching instance 2 forwarding ACL table entry Entry 233 of port Port E, and the global strict mode prohibited forwarding table entry Entry 234 in the outbound access control table 23 of the switching chip 20; among which, the priority of the global strict mode prohibited forwarding table entry Entry 234 is lower than the slice instance forwarding ACL table entry of each port, that is, the priority of the forwarding ACL table entries Entry 231, Entry 232, and Entry 233.
[0029] In the forwarding ACL table entry Entry231: the matching item includes the identifier of slice instance 1, Port C and the strict mode flag; the action item is to send through the channel of slice instance 1 associated with Port C.
[0030] In the forwarding ACL table entry Entry231: the matching item includes the identifier of slice instance 1, Port D and the strict mode flag; the action item is to send through the channel of slice instance 1 associated with Port D.
[0031] In the forwarding ACL table entry Entry233: the matching item includes the identifier of slice instance 2, Port E and the strict mode flag; the action item is to send through the channel of slice instance 2 associated with Port E.
[0032] In the global strict mode prohibited forwarding table entry 234: the matching item contains the strict mode flag bit, and the action item is discard.
[0033] IPv6 data packets 201, 202, and 203 arrive at port A of the network device; and IPv6 data packet 204 arrives at port B of the network device.
[0034] The forwarding module 24 finds the ACL entry Entry 211 in the inbound access control table 21 based on the lower 31 bits of the slice ID field of the source IP address of the IPv6 data packet 201; and finds the strict mode identification ACL entry Entry 213 in the inbound access control table 21 based on the first bit of the slice ID field of the source IP address of the IPv6 data packet 202 being 1. The forwarding module 24 caches the IPv6 data packet 201, and sets the slice instance identifier Slice1 and the strict mode flag in the message descriptor of the IPv6 data packet 201.
[0035] The forwarding module 24 finds the matching ACL entry Entry 212 in the inbound access control table 21 based on the lower 31 bits of the Slice ID field of the source IP address of the IPv6 data packet 202. The forwarding module 24 finds the strict mode identification ACL entry Entry 213 in the inbound access control table 21 based on the first bit of the slice identification field of the source IP address of the IPv6 data packet 202 being 1. The forwarding module 24 caches the IPv6 data packet 202, and sets the slice instance identifier Slice2 and the strict mode flag in the message descriptor of the IPv6 data packet 202.
[0036] The forwarding module 24 searches for the matching ACL entry Entry 211 in the inbound access control table 21 based on the lower 31 bits of the Slice ID field of the source IP address of the IPv6 data packet 203. The forwarding module 24 does not match the strict mode identification ACL entry Entry 213 in the inbound access control table 21 based on the fact that the first bit of the slice identification field of the source IP address of the IPv6 data packet 202 is 0. The forwarding module 24 caches the IPv6 data packet 202 and sets the slice instance identifier Slice1 in the message descriptor of the IPv6 data packet 202.
[0037] The forwarding module 24 finds the matching ACL entry Entry 212 in the inbound access control table 21 based on the lower 31 bits of the slice ID field of the source IP address of the IPv6 data packet 204. The forwarding module 24 finds the matching strict mode identification ACL entry Entry 213 in the inbound access control table 21 based on the first bit of the slice ID field of the source IP address of the IPv6 data packet 202 being 1. The forwarding unit 24 caches the IPv6 data packet 202, and sets the slice instance identifier Slice2 and the strict mode flag in the message descriptor of the IPv6 data packet 202.
[0038] Forwarding unit 24 finds out that the outgoing interface is Port C in the FIB table based on the destination IP addresses of IPv6 data packets 201, 202, and 203 respectively; forwarding unit 24 finds out that the outgoing interface is Port D in the FIB table based on the destination IP address of IPv6 data packet 204.
[0039] The forwarding unit 24 matches the forwarding ACL table entry Entry231 based on the slice instance identifier Slice 1, the strict mode flag, and the port Port C of the IPv6 data packet 201 in the outgoing access control table 23, and forwards the IPv6 data packet 201 through the channel scheduling of the slice instance 1 associated with Port C.
[0040] The forwarding unit 24 discards the IPv6 data packet 202 in the outbound access control table 23 based on the strict mode flag bit of the IPv6 data packet 202 matching the global strict mode prohibited forwarding entry 234 .
[0041] The forwarding module 24, in the outgoing access control table 23, does not match the forwarding ACL table entry matched by the IPv6 data packet 203, and does not match the global strict mode prohibited forwarding table entry Entry 234, and then sends the IPv6 data packet 203 through Port C.
[0042] The forwarding module 24 discards the IPv6 data packet 202 based on the strict mode flag bit of the IPv6 data packet 204 matching the global strict mode prohibited forwarding entry 234 in the outbound access control table 23 .
[0043] Figure 2 In the illustrated embodiment, the network device implements identification of whether an IPv6 packet carries a Strict-flag field on a switching chip that does not support identification of strict mode through the slice instance identification entry and the strict mode identification entry set in the inbound access control table.
[0044] In addition, the network device sends IPv6 data packets belonging to the same slice instance and with the Strict-flag field set to 1 through the slice instance channel bound to the port through the slice instance forwarding table entry set in the outbound direction access control table.
[0045] In addition, the network device prohibits forwarding entry 234 through the global strict mode. All ports are prohibited from forwarding IPv6 data packets belonging to unbound slice instances and with the Strict-flag field being 1, saving table entry resources in the outbound access control table.
[0046] Figure 3 A schematic diagram of a device for implementing a slicing strict mode based on source address encapsulation provided in this application. The device 30 includes a processor 31, a machine-readable storage medium 32, a switching chip 33, and a network interface 34. The processor 31 executes a setting module 321 by executing machine-executable instructions recorded in the machine-readable storage medium 32. The switching chip 33 includes a forwarding module 331.
[0047] The setting module 321 is used to set the first slice instance identification table item, the second slice instance identification table item, and the strict mode identification table item in the inbound access control table 332; wherein the matching item of the first slice instance identification table item is the first slice instance identification field, and the action item is to set the corresponding first slice instance identification in the message descriptor; the matching item of the second slice instance identification table item is the second slice instance identification field, and the action item is to set the corresponding second slice instance identification in the message descriptor; the matching item strict mode field of the strict mode identification table item is equal to 1, and the action item is to set the strict mode flag of the message descriptor;
[0048] The forwarding module 331 is used to match the slice instance identification entry and the strict mode identification entry in the inbound access control table 332 based on the slice instance field of the source IP address of the first IPv6 data packet received at the first port, cache the first IPv6 data packet and set the slice instance identifier and the strict mode flag in the message descriptor of the first IPv6 data packet.
[0049] The forwarding module 331 is also used to match the second slice instance identification entry and the strict mode identification entry in the inbound access control table 332 based on the slice instance field of the source IP address of the second IPv6 data packet received on the first port, cache the second IPv6 data packet and set the second slice instance identifier and the strict mode flag in the message descriptor of the second IPv6 data packet.
[0050] The forwarding module 331 is also used to match the first slice instance identification entry in the inbound access control table 332 and not match the strict mode identification entry based on the slice instance field of the source IP address of the third IPv6 data packet received through the first port, cache the third IPv6 data packet and set the first slice instance identifier in the message descriptor of the third IPv6 data packet.
[0051] The setting unit 321 is further used to access the control table 333 in the outgoing direction, set the first slice instance forwarding table item for the second port, and set a global strict mode prohibited forwarding table item with a lower priority than the first slice instance forwarding table item; wherein the matching item of the first slice instance forwarding table item includes the first slice instance identifier, the second port and the strict mode flag; the action item is to send through the channel of the first slice instance associated with the second port; the matching item of the global strict mode prohibited forwarding table item includes the strict mode flag, and the action item is to discard;
[0052] The forwarding module 331 finds in the forwarding information base 334 that the outgoing interface is the second port based on the destination IP address of the first IPv6 data packet and the destination IP address of the third IPv6 data packet respectively; finds in the outgoing access control table 333 that the first slice instance identifier, the strict mode flag, and the second port of the first IPv6 data packet match the first slice instance forwarding table entry, and forwards the first IPv6 data packet through the first slice instance channel scheduling associated with the second port; in the outgoing access control table, does not find a matching outgoing access control table entry for the third IPv6 data packet, and sends the third IPv6 data packet through the second port.
[0053] The forwarding module 331 is also used to find out in the forwarding information base 334 that the outgoing interface is the second port based on the destination IP address of the second IPv6 data packet; in the outgoing access control table 333, find out that the strict mode flag of the second IPv6 data packet matches the global strict mode prohibition forwarding table entry, and discard the second IPv6 data packet.
[0054] In the present disclosure, a machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device for storing or containing information (such as executable instructions, data, etc.). For example, any machine-readable storage medium herein may be any type of random access memory (RAM), volatile memory, non-volatile memory, flash memory, storage drive (such as a hard drive), solid-state drive, any type of storage optical disk (such as a CD, DVD, etc.), and similar devices, or a combination thereof. In addition, any machine-readable storage medium herein may be a non-temporary machine-readable storage medium.
[0055] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A method for implementing a strict mode of a source address encapsulation slice instance, characterized in that: The method comprises, In the inbound access control table, a first slice instance identification table entry is set; wherein the matching item is the first slice instance identification field; and the action item is setting the corresponding first slice instance identification in the message descriptor; In the inbound access control table, a second slice instance identification table entry is set; wherein the matching item is the second slice instance identification field; and the action item is setting the corresponding second slice instance identification in the message descriptor; In the inbound access control table, a strict mode identification entry is set; The matching item strict mode field is equal to 1; the action item is to set the strict mode flag in the message descriptor; The slice instance field of the source IP address of the first IPv6 data packet received through the first port matches the slice instance identification table entry and the strict mode identification table entry, caches the first IPv6 data packet and sets the slice instance identifier and the strict mode flag in the message descriptor of the first IPv6 data packet.
2. The method according to claim 1, characterized in that The method further comprises: The slice instance field of the source IP address of the second IPv6 data packet received through the first port matches the second slice instance identification table entry and the strict mode identification table entry, caches the second IPv6 data packet and sets the second slice instance identifier and the strict mode flag in the message descriptor of the second IPv6 data packet.
3. The method according to claim 1, characterized in that The method further comprises: The slice instance field of the source IP address of the third IPv6 data packet received through the first port matches the first slice instance identification table entry and does not match the strict mode identification table entry, caches the third IPv6 data packet and sets the first slice instance identifier in the message descriptor of the third IPv6 data packet.
4. The method according to claim 3, characterized in that The method further comprises: In the outbound access control table, a first slice instance forwarding table entry is set for the second port; wherein the matching item is the first slice instance identifier, the second port and the strict mode flag; and the action item is sent through the channel of the first slice instance associated with the second port; In the outbound access control table, a global strict mode prohibited forwarding table entry having a lower priority than the first slice instance forwarding table entry is set; wherein the matching item is the strict mode flag bit; and the action item is discard; Finding that the outgoing interface is the second port based on the destination IP address of the first IPv6 data message and the destination IP address of the third IPv6 data message respectively; In the outbound access control table, find that the first slice instance identifier, the strict mode flag, and the second port of the first IPv6 data packet match the first slice instance forwarding table entry, and forward the first IPv6 data packet through the first slice instance channel associated with the second port; In the outbound access control table, no outbound access control table entry matching the third IPv6 data packet is found, and the third IPv6 data packet is sent through the second port.
5. The method according to claim 4, characterized in that The method further comprises: Finding that the outgoing interface is the second port based on the destination IP address of the second IPv6 data packet; In the outbound access control table, find that the strict mode flag of the second IPv6 data message matches the global strict mode prohibited forwarding table entry, and discard the second IPv6 data message.
6. A device for implementing a strict mode of source address encapsulation slice instance, characterized in that: The device comprises, A setting module is used to set a first slice instance identification table item, a second slice instance identification table item, and a strict mode identification table item in the inbound access control table; wherein the matching item of the first slice instance identification table item is the first slice instance identification field, and the action item is to set the corresponding first slice instance identification in the message descriptor; the matching item of the second slice instance identification table item is the second slice instance identification field, and the action item is to set the corresponding second slice instance identification in the message descriptor; the matching item strict mode field of the strict mode identification table item is equal to 1, and the action item is to set the strict mode flag of the message descriptor; A forwarding module is used to match the slice instance identification table entry and the strict mode identification table entry based on the slice instance field of the source IP address of the first IPv6 data packet received at the first port, cache the first IPv6 data packet and set the slice instance identifier and the strict mode flag in the message descriptor of the first IPv6 data packet.
7. The device according to claim 6, characterized in that The forwarding module is also used to match the second slice instance identification table entry and the strict mode identification table entry based on the slice instance field of the source IP address of the second IPv6 data packet received by the first port, cache the second IPv6 data packet and set the second slice instance identifier and the strict mode flag in the message descriptor of the second IPv6 data packet.
8. The device according to claim 6, characterized in that The forwarding module is also used to cache the third IPv6 data packet and set the first slice instance identifier in the message descriptor of the third IPv6 data packet based on the slice instance field of the source IP address of the third IPv6 data packet received through the first port matching the first slice instance identification entry and not matching the strict mode identification entry.
9. The device according to claim 8, characterized in that The setting unit is further used to access the control table in the outgoing direction, set the first slice instance forwarding table item for the second port, and set a global strict mode prohibited forwarding table item with a lower priority than the first slice instance forwarding table item; wherein the matching item of the first slice instance forwarding table item includes the first slice instance identifier, the second port and the strict mode flag; the action item is to send through the channel of the first slice instance associated with the second port; the matching item of the global strict mode prohibited forwarding table item includes the strict mode flag, and the action item is to discard; The forwarding module finds that the output interface is the second port based on the destination IP address of the first IPv6 data packet and the destination IP address of the third IPv6 data packet respectively; finds in the outbound access control table that the first slice instance identifier, the strict mode flag, and the second port of the first IPv6 data packet match the first slice instance forwarding table entry, and forwards the first IPv6 data packet through the first slice instance channel scheduling associated with the second port; does not find in the outbound access control table an outbound access control table entry matching the third IPv6 data packet, and sends the third IPv6 data packet through the second port.
10. The device according to claim 9, characterized in that The forwarding module is also used to find that the outgoing interface is the second port based on the destination IP address of the second IPv6 data packet; in the outgoing access control table, find that the strict mode flag of the second IPv6 data packet matches the global strict mode prohibit forwarding table entry, and discard the second IPv6 data packet.
Citation Information
Patent Citations
IPv6 address configuration method and routing equipment
CN114928590A
Message forwarding processing and sending method and device of network slice, equipment and medium
CN116527559A
Message processing method and device, electronic equipment and storage medium
CN117714559A
BIERV6 slice management method, device and equipment and readable storage medium
CN118433102A
SRv6 message forwarding method and device and computer readable storage medium
CN119094494A