Methods and devices for implementing strict mode for source address encapsulation slice instances

By setting slice instance and strict mode recognition entries in the inbound access control table, the problem that the switching chip cannot recognize the strict mode of the IPv6 source address is solved. This enables the forwarding of IPv6 packet slice instances on switching chips that do not support strict mode recognition, supports the forwarding mechanism of SRv6 network slices, and saves table entry resources.

CN119996282BActive Publication Date: 2025-12-02NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510238037.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-12-02
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

Existing network switch chips cannot recognize the strict mode flag of IPv6 source addresses and therefore cannot support the strict mode forwarding mechanism of SRv6 network slicing.

Method used

In the inbound access control table, a first slice instance identification entry, a second slice instance identification entry, and a strict mode identification entry are set. By matching the slice instance field and strict mode field of the IPv6 data packet, the slice instance identifier and strict mode flag in the packet descriptor are cached and set to achieve the identification and forwarding of IPv6 packets.

Benefits of technology

Slice instance identification and strict mode forwarding of IPv6 packets were implemented on switching chips that do not support strict mode recognition. The forwarding mechanism of SRv6 network slices is supported, saving the table entry resources of the outbound access control table.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996282B_ABST
    Figure CN119996282B_ABST
Patent Text Reader

Abstract

This application provides a method and apparatus for implementing source address encapsulation of slice instances in strict mode. The method includes setting first and second slice instance identification entries and a strict mode identification entry in the inbound access control table. The first slice instance identification entry has a matching field of a first slice instance identifier field and an action item of setting the corresponding first slice instance identifier in the packet descriptor. The second slice instance identification entry has a matching field of a second slice instance identifier field and an action item of setting the corresponding second slice instance identifier in the packet descriptor. The strict mode identification entry has a matching field of a strict mode field equal to 1 and an action item of setting a strict mode flag in the packet descriptor. The source IP address of an IPv6 data packet received through the port is matched against the slice instance identification entry and the strict mode identification entry, the IPv6 data packet is buffered, and the slice instance identifier and the strict mode flag are set in the packet descriptor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to communication technology, specifically a method and device for implementing strict mode for source address encapsulation slice instances. Background Technology

[0002] SRv6 network slicing divides an SRv6 network into multiple virtual networks. These virtual networks are independent of each other. Administrators can allocate resources and provide differentiated queue scheduling capabilities for different services based on the tenant's business characteristics, meeting the different needs of various services without affecting the existing network.

[0003] Slice ID-based network slicing is a network slicing technology solution applied in SRv6 networking scenarios. It introduces Slice IDs into the data plane to distinguish different network slices. It uses globally unique Slice IDs to identify and divide sliced ​​networks.

[0004] The Slice ID encapsulation methods for SRv6 networks include: IPv6 Hop-by-Hop Extension Header (HBH) encapsulation, IPv6 source address encapsulation, and IPv6 flow label encapsulation.

[0005] In IPv6 packets using IPv6 source address encapsulation, the first bit of the lower 32 bits of the source IP address is the Strict-Flag; the remaining 31 bits carry the slice instance identifier. When forwarding this IPv6 data packet, the device first queries the FIB (Forward Information Base) table to find the outgoing interface. If the outgoing interface is bound to a slice instance channel, the IPv6 packet with a Strict-Flag field of 1 is forwarded through the slice channel. If the outgoing interface is not bound to a slice instance channel, the IPv6 packet with a Strict-Flag field of 1 is discarded; if the Strict-Flag field in the IPv6 data packet is 0, it is forwarded using the SRv6 non-slice method.

[0006] Because the existing switch devices in the network have older switching chips that are not flexibly programmable, they cannot recognize the strict mode flag of the IPv6 source address and therefore cannot support the strict mode forwarding mechanism. Summary of the Invention

[0007] The purpose of this application is to provide a method and device for implementing strict mode for source address encapsulation slice instances, enabling the identification of whether IPv6 packets carry the Strict-flag field on switching chips that do not support strict mode recognition, thereby supporting the forwarding mechanism of strict mode for source address slices.

[0008] To achieve the above objectives, this application provides a method for implementing strict mode for source address encapsulation of slice instances. The method includes: setting a first slice instance identification entry in the inbound access control table; wherein the matching item is a first slice instance identifier field; the action item is setting the corresponding first slice instance identifier in the packet descriptor; setting a second slice instance identification entry in the inbound access control table; wherein the matching item is a second slice instance identifier field; the action item is setting the corresponding second slice instance identifier in the packet descriptor; setting a strict mode identification entry in the inbound access control table; wherein the strict mode field of the matching item is equal to 1; the action item is setting a strict mode flag in the packet descriptor; matching the slice instance field of the source IP address of a first IPv6 data packet received through a first port with the slice instance identification entry and the strict mode identification entry, buffering the first IPv6 data packet, and setting the slice instance identifier and the strict mode flag in the packet descriptor of the first IPv6 data packet.

[0009] To achieve the above objectives, this application provides a device for implementing a strict mode for slices based on source address encapsulation. The device includes: a setting module, configured to set a first slice instance identification entry, a first slice instance identifier entry, and a strict mode identification entry in an inbound access control table; wherein the matching item of the first slice instance identification entry is a first slice instance identifier field, and the action item is setting the corresponding first slice instance identifier in the packet descriptor; the matching item of the second slice instance identification entry is a second slice instance identifier field, and the action item is setting the corresponding second slice instance identifier in the packet descriptor; the matching item of the strict mode identification entry has a strict mode field equal to 1, and the action item is setting the strict mode flag bit of the packet descriptor; and a forwarding module, configured to match the slice instance identification entry and the strict mode identification entry based on the slice instance field of the source IP address of a first IPv6 data packet received on a first port, buffer the first IPv6 data packet, and set the slice instance identifier and the strict mode flag bit in the packet descriptor of the first IPv6 data packet.

[0010] The beneficial effect of this application is that it enables the identification of whether IPv6 packets carry the Strict-flag field on switching chips that do not support strict mode recognition, thereby supporting the forwarding mechanism of strict mode for source address slicing. Attached Figure Description

[0011] Figure 1 A flowchart illustrating an embodiment of a method for implementing strict mode of slice based on source address encapsulation provided in this application;

[0012] Figure 2 A schematic diagram of the network device provided in this application based on source address encapsulation in strict slice mode;

[0013] Figure 3 A flowchart illustrating a device embodiment of the source address-based slice strict mode provided in this application. Detailed Implementation

[0014] The following detailed description will be provided with reference to several examples illustrated in the accompanying figures. In this detailed description, numerous specific details are used to provide a comprehensive understanding of the present application. Known methods, steps, components, and circuits are not described in detail in the examples to avoid obscuring their meaning.

[0015] In the terminology used, the term "including" means including but not limited to; the term "containing" means including but not limited to; the terms "above," "within," and "below" include the number itself; the terms "greater than" and "less than" mean not including the number itself. The term "based on" means based on at least a portion of them.

[0016] Figure 1 A flowchart illustrating an embodiment of a method for implementing a source address-based slice strict mode provided in this application, the method comprising:

[0017] Step 101: In the inbound access control table, set the first slice instance identification table entry; where the matching item is the first slice instance identifier field; and the action item is to set the corresponding first slice instance identifier in the packet descriptor.

[0018] Step 102: In the inbound access control table, set the second slice instance identification table entry; where the matching item is the second slice instance identifier field; and the action item is to set the corresponding second slice instance identifier in the packet descriptor.

[0019] Step 103: In the inbound access control table, set a strict mode identification entry; where the strict mode field of the matching item is equal to 1; the action item is to set the strict mode flag in the message descriptor.

[0020] Step 104: Match the slice instance field of the source IP address of the IPv6 data packet received through the port with the slice instance identification table entry and the strict mode identification table entry, cache the IPv6 data packet, and set the slice instance identifier and strict mode flag in the packet descriptor of the IPv6 data packet.

[0021] The beneficial effect of this application is that it enables the identification of whether IPv6 packets carry the Strict-flag field on switching chips that do not support strict mode recognition, thereby supporting the forwarding mechanism of strict mode for source address slicing.

[0022] Figure 2 A schematic diagram of the network device provided in this application based on source address encapsulation in strict slice mode;

[0023] The network device's port C and port D are bound to slice instance 1, and port E is bound to slice instance 2.

[0024] In the inbound access control table 21 of the switching chip 20, the network device sets the identification ACL entry Entry 211 for slice instance 1, the identification ACL entry Entry 212 for slice instance 2, and the strict mode identification ACL entry Entry 213.

[0025] In ACL entry Entry 211: the matching item is the binary identifier of slice instance 1, and the action item is to set the corresponding slice instance 1 identifier in the packet descriptor.

[0026] In ACL entry Entry 212: the matching item is the binary identifier of slice instance 2, and the action item is to set the corresponding slice instance 2 identifier in the packet descriptor.

[0027] In the strict mode recognition ACL entry Entry213: the strict mode field of the matching item is equal to 1, and the action item is to set the strict mode flag of the message descriptor.

[0028] In the outbound access control table 23 of the switching chip 20, the network device sets the forwarding ACL entry Entry 231 for slice instance 1 of port C, the forwarding ACL entry Entry 232 for slice instance 1 of port D, the forwarding ACL entry Entry 233 for switch instance 2 of port E, and the global strict mode prohibit forwarding entry Entry 234 in the table. Among them, the priority of the global strict mode prohibit forwarding entry Entry 234 is lower than that of the slice instance forwarding ACL entries of each port, that is, the priority of forwarding ACL entries Entry 231, Entry 232, and Entry 233.

[0029] In the forwarding ACL entry Entry231: the matching item contains the identifier of slice instance 1, Port C, and the strict mode flag; the action item is to send through the channel of slice instance 1 associated with Port C.

[0030] In the forwarding ACL entry Entry231: the matching item contains the identifier of slice instance 1, Port D, and the strict mode flag; the action item is to send through the channel of slice instance 1 associated with Port D.

[0031] In the forwarding ACL entry Entry233: the matching item contains the identifier of slice instance 2, Port E, and the strict mode flag; the action item is to send through the channel of slice instance 2 associated with Port E.

[0032] In global strict mode, the forwarding entry Entry 234 is disabled: the matching item contains the strict mode flag, and the action item is discard.

[0033] IPv6 datagrams 201, 202, and 203 arrive at port A of the network device; IPv6 datagram 204 arrives at port B of the network device.

[0034] Forwarding module 24, based on the lower 31 bits of the Slice ID field of the source IP address of IPv6 datagram 201, searches for ACL entry Entry 211 in the inbound access control table 21; based on the first bit of the Slice ID field of the source IP address of IPv6 datagram 202 being 1, it searches for strict mode recognition ACL entry Entry 213 in the inbound access control table 21. Forwarding module 24 buffers IPv6 datagram 201 and sets the slice instance identifier Slice1 and the strict mode flag in the packet descriptor of IPv6 datagram 201.

[0035] Forwarding module 24, based on the lower 31 bits of the Slice ID field of the source IP address of IPv6 datagram 202, searches for a matching ACL entry Entry 212 in the inbound access control table 21. Forwarding module 24, based on the first bit of the slice identifier field of the source IP address of IPv6 datagram 202 being 1, searches for a strict mode recognition ACL entry Entry 213 in the inbound access control table 21. Forwarding module 24 buffers IPv6 datagram 202 and sets the slice instance identifier Slice2 and the strict mode flag in the packet descriptor of IPv6 datagram 202.

[0036] Forwarding module 24, based on the lower 31 bits of the Slice ID field of the source IP address of IPv6 datagram 203, searches for a matching ACL entry Entry 211 in the inbound access control table 21. Forwarding module 24, based on the fact that the first bit of the slice identifier field of the source IP address of IPv6 datagram 202 is 0, does not find a matching strict pattern recognition ACL entry Entry 213 in the inbound access control table 21. Forwarding module 24 then buffers IPv6 datagram 202 and sets the slice instance identifier Slice1 in the packet descriptor of IPv6 datagram 202.

[0037] Forwarding module 24, based on the lower 31 bits of the Slice ID field of the source IP address of IPv6 datagram 204, searches for a matching ACL entry Entry 212 in the inbound access control table 21. Forwarding module 24, based on the first bit of the Slice ID field of the source IP address of IPv6 datagram 202 being 1, searches for a matching strict mode recognition ACL entry Entry 213 in the inbound access control table 21. Forwarding unit 24 buffers IPv6 datagram 202 and sets the Slice instance identifier Slice2 and the strict mode flag in the packet descriptor of IPv6 datagram 202.

[0038] Forwarding unit 24, based on the destination IP addresses of IPv6 data packets 201, 202, and 203, finds the outgoing interface as port C in the FIB table; forwarding unit 24, based on the destination IP address of IPv6 data packet 204, finds the outgoing interface as port D in the FIB table.

[0039] Forwarding unit 24, in outgoing access control table 23, matches the slice instance identifier Slice 1, strict mode flag, and port Port C of IPv6 data packet 201 to the forwarding ACL table entry Entry 231, and forwards IPv6 data packet 201 through the channel scheduling of slice instance 1 associated with Port C.

[0040] Forwarding unit 24, in outgoing access control table 23, based on the strict mode flag bit of IPv6 data packet 202 matching the global strict mode prohibit forwarding table entry Entry 234, discards IPv6 data packet 202.

[0041] If the forwarding module 24 does not find a matching forwarding ACL entry for IPv6 data packet 203 in the outgoing access control table 23, and does not find a matching global strict mode prohibit forwarding entry Entry 234, then it will send IPv6 data packet 203 through Port C.

[0042] The forwarding module 24, in the outgoing access control table 23, based on the strict mode flag bit of IPv6 data packet 204 matching the global strict mode prohibit forwarding table entry Entry 234, discards IPv6 data packet 202.

[0043] Figure 2 In the illustrated embodiment, the network device identifies whether an IPv6 packet carries the Strict-flag field by using the slice instance identification entry and strict mode identification entry set in the inbound access control table, even on a switching chip that does not support strict mode identification.

[0044] In addition, network devices can send IPv6 data packets belonging to the same slice instance and with the Strict-flag field set to 1 through the slice instance forwarding table entry set in the outgoing access control table, via the slice instance channel bound to the port.

[0045] In addition, network devices prohibit the forwarding of entry Entry 234 through global strict mode, and all ports are prohibited from forwarding IPv6 data packets that belong to unbound slice instances and whose Strict-flag field is 1, thus saving table entry resources in the outbound access control table.

[0046] Figure 3 This is a schematic diagram of a device implementing a source address-based slice strict mode provided in this application. The device 30 includes a processor 31, a machine-readable storage medium 32, a switching chip 33, and a network interface 34. The processor 31 executes machine-executable instructions recorded in the machine-readable storage medium 32 to execute a setup module 321. The switching chip 33 includes a forwarding module 331.

[0047] The setting module 321 is used to set a first slice instance identification entry, a second slice instance identification entry, and a strict mode identification entry in the inbound access control table 332. The first slice instance identification entry's matching field is the first slice instance identifier field, and its action is to set the corresponding first slice instance identifier in the message descriptor. The second slice instance identification entry's matching field is the second slice instance identifier field, and its action is to set the corresponding second slice instance identifier in the message descriptor. The strict mode identification entry's matching field is equal to 1, and its action is to set the strict mode flag bit of the message descriptor.

[0048] The forwarding module 331 is used to match the slice instance identification entry and the strict mode identification entry in the inbound access control table 332 based on the slice instance field of the source IP address of the first IPv6 data packet received on the first port, cache the first IPv6 data packet, and set the slice instance identifier and the strict mode flag in the packet descriptor of the first IPv6 data packet.

[0049] The forwarding module 331 is also used to match the second slice instance identification entry and the strict mode identification entry in the inbound access control table 332 based on the slice instance field of the source IP address of the second IPv6 data packet received on the first port, cache the second IPv6 data packet, and set the second slice instance identifier and the strict mode flag in the packet descriptor of the second IPv6 data packet.

[0050] The forwarding module 331 is also used to, based on the slice instance field of the source IP address of the third IPv6 data packet received through the first port, match the first slice instance identification entry in the inbound access control table 332 and not match the strict mode identification entry, cache the third IPv6 data packet and set the first slice instance identifier in the packet descriptor of the third IPv6 data packet.

[0051] The setting unit 321 is also used to access the control table 333 in the outgoing direction, set a first slice instance forwarding table entry for the second port, and set a global strict mode prohibit forwarding table entry with a priority lower than the first slice instance forwarding table entry; wherein, the matching item of the first slice instance forwarding table entry includes the first slice instance identifier, the second port, and the strict mode flag bit; the action item is to send through the channel of the first slice instance associated with the second port; the matching item of the global strict mode prohibit forwarding table entry includes the strict mode flag bit, and the action item is to discard;

[0052] The forwarding module 331, based on the destination IP address of the first IPv6 data packet and the destination IP address of the third IPv6 data packet, respectively, searches the forwarding information database 334 to find that the outgoing interface is the second port; in the outgoing access control table 333, it finds that the first slice instance identifier, strict mode flag, and second port of the first IPv6 data packet match the first slice instance forwarding table entry, and schedules the forwarding of the first IPv6 data packet through the first slice instance channel associated with the second port; if no matching outgoing access control table entry for the third IPv6 data packet is found in the outgoing access control table, the third IPv6 data packet is sent through the second port.

[0053] The forwarding module 331 is also used to find out that the outgoing interface is the second port in the forwarding information database 334 based on the destination IP address of the second IPv6 data packet; and to find that the strict mode flag of the second IPv6 data packet matches the global strict mode prohibit forwarding table entry in the outgoing access control table 333, and then discard the second IPv6 data packet.

[0054] In this disclosure, a machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device used to store or contain information (such as executable instructions, data, etc.). For example, any machine-readable storage medium herein can be any type of random access memory (RAM), volatile memory, non-volatile memory, flash memory, storage drive (such as a hard disk drive), solid-state drive, any type of optical disc (such as an optical disc, DVD, etc.), and similar devices, or combinations thereof. Furthermore, any machine-readable storage medium herein can be a non-transitory machine-readable storage medium.

[0055] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for implementing strict mode for source address encapsulated slice instances, characterized in that, The method includes, In the inbound access control table, set the first slice instance identification entry; where the matching item is the first slice instance identifier field; and the action item is to set the corresponding first slice instance identifier in the packet descriptor. In the inbound access control table, set the second slice instance identification table entry; where the matching item is the second slice instance identifier field; the action item is to set the corresponding second slice instance identifier in the packet descriptor; In the incoming access control table, a strict mode recognition entry is set; The matching item's strict mode field is equal to 1; the action item is to set the strict mode flag in the message descriptor. The slice instance field of the source IP address of the first IPv6 data packet received through the first port is matched with the slice instance identification entry and the strict mode identification entry. The first IPv6 data packet is cached, and the slice instance identifier and the strict mode flag are set in the packet descriptor of the first IPv6 data packet.

2. The method according to claim 1, characterized in that, The method further includes: The slice instance field of the source IP address of the second IPv6 data packet received through the first port is matched with the second slice instance identification entry and the strict mode identification entry. The second IPv6 data packet is cached, and the second slice instance identifier and the strict mode flag are set in the packet descriptor of the second IPv6 data packet.

3. The method according to claim 2, characterized in that, The method further includes: If the slice instance field of the source IP address of the third IPv6 data packet received through the first port matches the first slice instance identification entry and does not match the strict mode identification entry, the third IPv6 data packet is cached and the first slice instance identifier is set in the packet descriptor of the third IPv6 data packet.

4. The method according to claim 3, characterized in that, The method further includes: In the outbound access control table, set a forwarding table entry for the first slice instance for the second port; where the matching item is the identifier of the first slice instance, the second port, and the strict mode flag; the action item is to send through the channel of the first slice instance associated with the second port; In the outgoing access control table, a global strict mode prohibit forwarding entry with a priority lower than the forwarding entry of the first slice instance is set; wherein the matching item is the strict mode flag bit; and the action item is discard. The outgoing interface is found to be the second port based on the destination IP address of the first IPv6 data packet and the destination IP address of the third IPv6 data packet, respectively. In the outgoing access control table, the first slice instance identifier, the strict mode flag, and the second port of the first IPv6 data packet are found to match the first slice instance forwarding table entry. The first IPv6 data packet is then forwarded through the first slice instance channel associated with the second port. If no matching entry for the third IPv6 data packet is found in the outbound access control table, the third IPv6 data packet is sent through the second port.

5. The method according to claim 4, characterized in that, The method further includes: Based on the destination IP address of the second IPv6 data packet, the outgoing interface is found to be the second port; In the outbound access control table, if the strict mode flag of the second IPv6 data packet matches the global strict mode prohibit forwarding entry, the second IPv6 data packet is discarded.

6. A device for implementing strict mode for source address encapsulation slice instances, characterized in that, The device includes, The configuration module is used to configure a first slice instance identification entry, a second slice instance identification entry, and a strict mode identification entry in the inbound access control table. Specifically, the first slice instance identification entry's matching field is the first slice instance identifier field, and its action is to set the corresponding first slice instance identifier in the packet descriptor. The second slice instance identification entry's matching field is the second slice instance identifier field, and its action is to set the corresponding second slice instance identifier in the packet descriptor. The strict mode identification entry's matching field is equal to 1, and its action is to set the strict mode flag bit of the packet descriptor. The forwarding module is used to match the slice instance identification entry and the strict mode identification entry based on the slice instance field of the source IP address of the first IPv6 data packet received on the first port, cache the first IPv6 data packet, and set the slice instance identifier and the strict mode flag in the packet descriptor of the first IPv6 data packet.

7. The device according to claim 6, characterized in that, The forwarding module is further configured to match the slice instance identification entry of the second slice instance and the strict mode identification entry of the source IP address of the second IPv6 data packet received on the first port, cache the second IPv6 data packet, and set the second slice instance identifier and the strict mode flag in the packet descriptor of the second IPv6 data packet.

8. The device according to claim 7, characterized in that, The forwarding module is further configured to cache the third IPv6 data packet and set the first slice instance identifier in the packet descriptor of the third IPv6 data packet based on the slice instance field of the source IP address of the third IPv6 data packet received through the first port matching the first slice instance identification table entry and not matching the strict mode identification table entry.

9. The device according to claim 8, characterized in that, The setting module is further configured to access the control table in the outgoing direction, set a first slice instance forwarding table entry for the second port, and set a global strict mode prohibit forwarding table entry with a priority lower than the first slice instance forwarding table entry; wherein, the matching item of the first slice instance forwarding table entry includes the first slice instance identifier, the second port, and the strict mode flag; the action item is to send through the channel of the first slice instance associated with the second port; the matching item of the global strict mode prohibit forwarding table entry includes the strict mode flag, and the action item is to discard; The forwarding module finds the outgoing interface as the second port based on the destination IP address of the first IPv6 data packet and the destination IP address of the third IPv6 data packet, respectively. In the outgoing access control table, it finds that the first slice instance identifier, the strict mode flag, and the second port of the first IPv6 data packet match the first slice instance forwarding table entry, and schedules the forwarding of the first IPv6 data packet through the first slice instance channel associated with the second port. If no matching outgoing access control table entry for the third IPv6 data packet is found in the outgoing access control table, the third IPv6 data packet is sent through the second port.

10. The device according to claim 9, characterized in that, The forwarding module is further configured to locate the outgoing interface as the second port based on the destination IP address of the second IPv6 data packet; and in the outgoing access control table, locate the strict mode flag of the second IPv6 data packet that matches the global strict mode prohibit forwarding entry, and discard the second IPv6 data packet.

Citation Information

Patent Citations

  • IPv6 address configuration method and routing equipment

    CN114928590A

  • Message forwarding processing and sending method and device of network slice, equipment and medium

    CN116527559A