Flow table configuration processing method and device, server and readable storage medium

By generating and merging flow table configurations and reducing the data based on the hierarchical storage, the performance problems caused by a large number of flow table configurations are solved, and the performance of storing and issuing flow table configurations is significantly improved.

CN120074846APending Publication Date: 2025-05-30RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311621263.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When there are too many hosts bound under a security group, the number of flow table configurations generated is too large, resulting in poor performance in storing and posting flow table configurations.

Method used

When receiving the northbound request of the first security group, N flow table configurations related to the security group are generated, and the flow table configurations with the same target field are merged to obtain M flow table configurations. Then, based on the flow table data after the hierarchical storage operation, M flow table configurations are reduced, and the flow table configuration after the reduction is issued.

Benefits of technology

By merging and reducing flow table configurations, the number of flow table configurations that need to be stored and issued is greatly reduced, thereby improving the performance of stored and issued flow table configurations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074846A_ABST
    Figure CN120074846A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a flow table configuration processing method and device, a server and a readable storage medium, relates to the technical field of communication, and solves the problem that the performance of storing and issuing flow table configuration in an existing scheme is poor. According to the specific scheme, under the condition that a northbound request corresponding to a first security group is received, N flow table configurations related to the first security group are generated, and N is a positive integer; the flow table configurations with the same target field in the N flow table configurations are combined to obtain M flow table configurations, the target field comprises the IP address of the host bound under the first security group and a remote security group rule, and M is a positive integer smaller than N; and performing reduction processing on the M flow table configurations based on the flow table data obtained after the hierarchical storage operation is performed on the M flow table configurations, and issuing the M flow table configurations after the reduction processing. The embodiments of the present application are used in scenes of storage and transmission of flow table configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to a method, apparatus, server, and readable storage medium for processing flow table configurations. Background Art

[0002] Generally, when there is another security group associated with a remote security group rule under a security group, in order to control the communication traffic between virtual machines in the two security groups, the server in the data center needs to convert the remote security group rule into a flow table configuration for storage and distribution.

[0003] Currently, the above server can combine a set of data corresponding to each host bound under the above one security group with the Internet Protocol (IP) addresses of each host bound under the above another security group to generate the above flow table configuration.

[0004] However, according to the above method, when the number of hosts bound under the above one security group and the above another security group is too large, the above combination method will result in too many generated flow table configurations, thus leading to poor performance in storing and distributing the flow table configurations. Summary of the Invention

[0005] Embodiments of the present application provide a method, apparatus, server, and readable storage medium for processing flow table configurations to solve the problem of poor performance in storing and distributing flow table configurations.

[0006] To achieve the above object, the embodiments of the present application adopt the following technical solutions:

[0007] In a first aspect of the embodiments of the present application, a method for processing flow table configurations is provided, and the method includes:

[0008] Generating N flow table configurations related to the first security group when receiving a northbound request corresponding to the first security group, where N is a positive integer;

[0009] Performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations, where the target fields include the IP addresses of the hosts bound under the first security group and the remote security group rules, and M is a positive integer less than N;

[0010] Based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, performing a reduction process on the M flow table configurations, and distributing the M flow table configurations after the reduction process.

[0011] The flow table configuration processing method provided by the embodiments of the present application can merge the flow table configurations with the same target fields among the generated N flow table configurations to obtain M flow table configurations, so as to reduce the number of generated flow table configurations. And based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, the M flow table configurations can be further reduced. Therefore, the number of flow table configurations to be stored and issued is greatly reduced, thereby improving the performance of storing and issuing flow table configurations.

[0012] Combined with the first aspect, in a possible implementation manner, the merging process of the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations includes:

[0013] Using the first merging method, merge the flow table configurations with the same target fields among the N flow table configurations to obtain the M flow table configurations;

[0014] Wherein, the first merging method includes:

[0015] Add a first field to each of the N flow table configurations, where the first field is used to indicate the list of IP addresses of the hosts bound under the second security group; or,

[0016] Concatenate the list of IP addresses of the hosts bound under the second security group into a first string;

[0017] Wherein, the second security group is the remote security group in the security group rules under the first security group.

[0018] In the embodiments of the present application, since the server can use the above first merging method to perform the above merging process to obtain the above M flow table configurations, the flow table configurations can be merged based on the above list of IP addresses, thereby greatly reducing the number of flow table configurations and improving the performance of the device.

[0019] Combined with the first aspect and the above possible implementation manner, in another possible implementation manner, the first field is a list type field, and the list type field is used to fill in the list of IP addresses.

[0020] In the embodiments of the present application, since the above first field can be a list type field, and the list type field can be used to fill in the above list of IP addresses, the list of IP addresses can be accurately indicated by adding the first field to each of the above flow table configurations.

[0021] Combined with the first aspect and the above possible implementation manner, in another possible implementation manner, the merging process of the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations includes:

[0022] Merge the flow table configurations with the same target field among the N flow table configurations into one flow table configuration to obtain the M flow table configurations.

[0023] In the embodiments of the present application, since the server can merge the flow table configurations with the same target field among the above N flow table configurations into one flow table configuration to obtain the above M flow table configurations, the number of generated flow table configurations can be reduced, and the performance of the device can be further improved.

[0024] Combined with the first aspect and the above possible implementation manners, in another possible implementation manner, the merging process of the flow table configurations with the same target field among the N flow table configurations to obtain M flow table configurations includes:

[0025] Through a Software Defined Network (SDN) controller in the server, merge the flow table configurations with the same target field among the N flow table configurations to obtain the M flow table configurations.

[0026] In the embodiments of the present application, since the above merging process can be executed by the above SDN controller to obtain the above M flow table configurations, and the SDN controller can implement centralized and automated network management, the resource utilization rate of the server can be improved and the cost can be saved.

[0027] Combined with the first aspect and the above possible implementation manners, in another possible implementation manner, the hierarchical storage operation includes:

[0028] Store the list of IP addresses of the hosts bound under the second security group, and generate a target index for indicating the list of IP addresses, where the second security group is the remote security group in the security group rules under the first security group;

[0029] Store the M flow table configurations, and the IP addresses of the hosts bound under the second security group included in each of the M flow table configurations can be indicated by the target index.

[0030] In the embodiments of the present application, since the above hierarchical storage operation may include first storing the above IP address list and generating a target index for it, and then storing the above M flow table configurations, and the IP addresses of the hosts bound under the above first security group in each stored flow table configuration can be referenced using the target index, on the one hand, it is possible to avoid directly storing the above N flow table configurations, thereby reducing the power consumption of storing the flow table configurations. On the other hand, based on the target index, the M flow table configurations are reduced, and each flow table configuration obtained after the reduction processing can still indicate the accurate IP addresses of the hosts bound under the above first security group through the target index, thereby improving the accuracy of the flow table configurations obtained after the reduction processing.

[0031] Combined with the first aspect and the above possible implementation manners, in another possible implementation manner, the reduction processing of the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations includes:

[0032] Replacing the second field included in each of the M flow table configurations with the target index to obtain the M flow table configurations after the reduction processing;

[0033] Wherein, the second field is the IP address of the host bound under the second security group.

[0034] In the embodiments of the present application, since the server can replace the second field included in each of the M flow table configurations with the target index to reference the host IP address bound to the second security group through the target index, the number of flow table configurations stored and distributed can be greatly reduced, and the processing power consumption can be improved.

[0035] In the second aspect of the embodiments of the present application, a flow table configuration processing device is provided, and the device includes a generation unit, a merging unit, and a processing unit;

[0036] The generation unit is configured to generate N flow table configurations related to the first security group when receiving a northbound request corresponding to the first security group, where N is a positive integer;

[0037] The merging unit is configured to perform a merging process on the flow table configurations with the same target field among the N flow table configurations to obtain M flow table configurations, where the target field includes the IP address of the host bound under the first security group and the remote security group rule, and M is a positive integer less than N;

[0038] The processing unit is configured to perform a reduction process on the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, and distribute the M flow table configurations after the reduction process.

[0039] In combination with the second aspect, in a possible implementation manner, the merging unit is specifically configured to use a first merging method to perform a merging process on the flow table configurations with the same target field in the N flow table configurations, so as to obtain the M flow table configurations;

[0040] Wherein, the first merging method includes:

[0041] Adding a first field to each flow table configuration in the N flow table configurations, where the first field is used to indicate a list of IP addresses of hosts bound under the second security group; or,

[0042] Concatenating the list of IP addresses of hosts bound under the second security group into a first string;

[0043] Wherein, the second security group is the remote security group in the security group rules under the first security group.

[0044] In combination with the second aspect and the above possible implementation manner, in another possible implementation manner, the first field is a list type field, and the list type field is used to fill in the list of IP addresses.

[0045] In combination with the second aspect and the above possible implementation manner, in another possible implementation manner, the merging unit is specifically configured to merge the flow table configurations with the same target field in the N flow table configurations into one flow table configuration, so as to obtain the M flow table configurations.

[0046] In combination with the second aspect and the above possible implementation manner, in another possible implementation manner, the merging unit is specifically configured to perform a merging process on the flow table configurations with the same target field in the N flow table configurations through an SDN controller in a server, so as to obtain the M flow table configurations.

[0047] In combination with the second aspect and the above possible implementation manner, in another possible implementation manner, the hierarchical storage operation includes:

[0048] Storing a list of IP addresses of hosts bound under the second security group, and generating a target index for indicating the list of IP addresses, where the second security group is the remote security group in the security group rules under the first security group;

[0049] Storing the M flow table configurations, and the IP addresses of hosts bound under the second security group included in each of the M flow table configurations can be indicated by the target index.

[0050] Combined with the second aspect and the above possible implementation manners, in another possible implementation manner, the processing unit is specifically configured to replace a second field included in each of the M flow table configurations with the target index, so as to obtain the M flow table configurations after reduction processing;

[0051] Wherein, the second field is the IP address of the host bound under the second security group.

[0052] A third aspect of the embodiments of the present application provides a server, including a processor and a memory, where the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, the steps of the flow table configuration processing method as described in the first aspect and the possible implementation manners of the first aspect are implemented.

[0053] A fourth aspect of the embodiments of the present application provides a readable storage medium, where a program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the steps of the flow table configuration processing method as described in the first aspect and the possible implementation manners of the first aspect are implemented. Description of the Drawings

[0054] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0055] Figure 1 It is a schematic diagram of the remote security group rule association relationship between two security groups in the related art;

[0056] Figure 2 It is a schematic diagram of a flow table configuration generation method provided by the related art;

[0057] Figure 3 It is one of the flowcharts of a flow table configuration processing method provided by the embodiments of the present application;

[0058] Figure 4 It is a second flowchart of a flow table configuration processing method provided by the embodiments of the present application;

[0059] Figure 5 It is a third flowchart of a flow table configuration processing method provided by the embodiments of the present application;

[0060] Figure 6 It is a fourth flowchart of a flow table configuration processing method provided by the embodiments of the present application;

[0061] Figure 7Schematic diagram of a flow table configuration stored and distributed in a flow table configuration processing method provided by an embodiment of the present application;

[0062] Figure 8 Schematic diagram of the composition of a flow table configuration processing device provided by an embodiment of the present application;

[0063] Figure 9 Schematic diagram of the composition of another flow table configuration processing device provided by an embodiment of the present application. Detailed implementation manners

[0064] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0065] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same type, and the number of objects is not limited. For example, the first object can be one or more.

[0066] In addition, the term "and / or" in this article is only a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0067] The terms "at least one (item)", "at least one of" and the like in the specification and claims of the present application refer to any one, any two or more combinations of the objects they contain. For example, at least one (item) of a, b, and c can represent: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" means two or more, and its meaning is similar to that of "at least one (item)".

[0068] Next, some nouns or terms involved in the specification and claims of the present application will be explained first.

[0069] Security Group: A security group can be regarded as a set of rules used to manage and control the network traffic of virtual machine instances in a cloud computing platform. A security group rule is a rule defined in a security group. Each security group rule contains a set of conditions, such as source IP address, destination IP address, protocol, and port, etc., and an action (allow or deny) rule for handling the matched traffic. A remote security group is a security group configuration that enables a security group to perform access control based on the membership of other security groups.

[0070] Flow Table: Also known as flow table configuration, it is an important data structure in network switching devices for implementing traffic forwarding and processing. By matching the characteristics of data packets and performing corresponding operations, it realizes functions such as routing, forwarding, filtering, and load balancing of data packets. The basic components of a flow table include the following elements: match fields (i.e., Match Fields), action set (i.e., Action Set), priority (i.e., Priority), counters (i.e., Counters), and timeout mechanism (i.e., TimeoutMechanism).

[0071] DataStore: That is, data storage. In the OpenDaylight (i.e., Open Daylight) controller, DataStore is one of the core components for storing and managing network configuration, status, and topology information. It is based on in-memory storage and uses a tree structure to organize data.

[0072] OpenFlow: It is a network communication protocol used to implement communication and interaction between network switches and controllers. Its goal is to provide a flexible and programmable way to manage and control network traffic. Using the OpenFlow protocol, a network switch can obtain forwarding rules through communication with an external controller and process data packets according to these rules.

[0073] The following will describe in detail the implementation manners of the embodiments of the present application in conjunction with the accompanying drawings.

[0074] Exemplarily, as Figure 1 shown, Security Group (SG) 1 and SG2 are two SGs with an associated relationship of remote security group rules. Among them, SG1 is the SG on Server 1 and is associated with Virtual Machine (VM) 1 and VM2. SG2 is the SG on Server 2 and is associated with VM3 and VM4. In the current flow table configuration forwarding, after the controller in Server 1 receives a northbound request from Server 2, it needs to convert the remote security group rules of SG2 into a flow table configuration for storage and distribution to VM1 and VM2 to implement the function of packet filtering by the network switching device.

[0075] Specifically, as Figure 2 shown, the SDN controller deployed in the server can use the MAC address, security rule protocol, and port of the above VM1, as well as the MAC address, security rule protocol, and port of the above VM2 as matching (i.e., Match) item 1; and use the IP address of the above VM3 and the IP address of the above VM4 as matching item 2; then arrange and combine matching item 1 and matching item 2 to generate a complete flow table configuration. Then store the data of the generated flow table configuration in the DataStore, and send the flow table configuration to VM1 and VM2 through the OpenFlow protocol to control the communication traffic between the VMs associated with the above SG1 and the above SG2.

[0076] However, according to the above method, the flow table configuration generated by the controller uses the above matching item 1 + the above matching item 2 as the complete matching item of the flow table configuration. When there are P hosts (for example, P VMs) associated with the same security group and Q (for example, Q VMs) hosts associated with the same remote security group, the number of generated host remote security rule flow table configurations is P * Q, where both P and Q are positive integers; assuming that a single security group can be associated with 1000 hosts, that is, both P and Q are 1000, then the number of generated flow table configurations is 1000 * 1000 = 1M, which will involve storing a large amount of flow table configuration data. Specifically, the following problems will exist:

[0077] 1. Large memory space occupation

[0078] DataStore is an in-memory database, and the data capacity is limited by memory. Excessive data volume is likely to cause memory shortage. Generating millions of data for a single security group will require a large amount of memory to support data storage, resulting in an increase in controller costs;

[0079] 2. Large amount of database operation data under addition, deletion, and modification operations

[0080] The amount of flow table data generated by a single security group rule is huge. When the security group rule changes, it will involve atomic operations on millions of data. And to ensure data consistency among different nodes in the cluster, data synchronization is required between nodes. The large amount of data to be operated will result in low synchronization efficiency, and ultimately cause the database to be busy and affect the normal use of the controller;

[0081] 3. Large amount of data interaction between components

[0082] The controller communicates with the underlying devices through the OpenFlow channel, which involves network communication. If there are frequent large-scale calls or the amount of data transmitted is large, it will cause pressure on performance. The current large amount of flow table configurations being sent through the OpenFlow channel will affect the performance of the controller and the devices.

[0083] To solve the above technical problems, embodiments of the present application provide a flow table configuration processing method, apparatus, server, and readable storage medium. In the flow table configuration processing method provided by the embodiments of the present application, the execution entity may be a flow table configuration processing apparatus, an electronic device, or a functional module in an electronic device, etc. In the embodiments of the present application, taking a server in a data center executing the flow table configuration processing method as an example, the flow table configuration processing method provided by the embodiments of the present application is described.

[0084] Figure 3 The flowchart of a flow table configuration processing method provided by an embodiment of the present application is shown. As Figure 3 shown, the flow table configuration processing method provided by the embodiments of the present application may include the following steps 301 to step 303.

[0085] Step 301: When receiving a northbound request corresponding to a first security group, the server generates N flow table configurations related to the first security group.

[0086] Where N is a positive integer.

[0087] In the embodiments of the present application, the above northbound request corresponding to the first security group may be sent by the server corresponding to the first security group.

[0088] Optionally, in the embodiments of the present application, the above first security group may be: a security group with a remote rule bound to the associated host (such as a VM).

[0089] Optionally, in the embodiments of the present application, the above northbound request is a communication request of a northbound interface. The northbound interface is an interface for accessing and managing a network, that is, an interface for a lower-level device to connect to a higher-level interface.

[0090] Optionally, in the embodiments of the present application, after receiving the above northbound request, the server may obtain flow table information through the above northbound interface to generate the above N flow table configurations.

[0091] Optionally, in the embodiments of the present application, the server may receive the above northbound request through an SDN controller in the server and generate the above N flow table configurations through the SDN controller.

[0092] It should be noted that the above SDN controller belongs to the control layer of the network. The northbound interface of the SDN controller is connected to the server located in the network application layer, and is connected to the network element located in the network infrastructure layer through the southbound interface of the SDN controller. When configuring parameters for the network element, the SDN controller can receive a northbound request from the server, decompose and orchestrate the northbound request to determine one or more network elements for which parameter configuration is required, and then generate corresponding southbound messages for these network elements and send them down. The network element updates its corresponding configuration data according to the received southbound message.

[0093] Optionally, in the embodiment of the present application, after receiving the above northbound request, the server can, through the above SDN controller, generate the above N flow table configurations according to the hosts bound to the first security group. Only the host IP addresses bound to the remote security group in the security group rules under the first security group are different in the N flow table configurations.

[0094] For the specific method of generating the above N flow table configurations, reference can be made to the flow table configuration generation method in the above related technology. To avoid repetition, it will not be elaborated here.

[0095] Step 302: The server merges the flow table configurations with the same target fields in the N flow table configurations to obtain M flow table configurations.

[0096] Among them, the above target fields include the IP addresses of the hosts bound under the first security group and the remote security group rules, and M is a positive integer less than N.

[0097] Optionally, in the embodiment of the present application, the server can use a service component to merge the flow table configurations with the same target fields in the N flow table configurations to obtain the above M flow table configurations. The service component is used to merge the flow table configurations.

[0098] In the embodiment of the present application, the above target fields are fields in the matching fields in the flow table configuration.

[0099] Optionally, in the embodiment of the present application, the above matching fields may include: host port or host MAC address, security rule protocol, port for transmitting the flow table configuration, and host IP address bound under the remote security group.

[0100] For example, assuming that the above target fields include the host MAC address, then the server can merge the flow table configurations with the same host MAC address in the N flow table configurations to obtain the above M flow table configurations.

[0101] For another example, assume that the above target fields include the host IP addresses bound under the remote security group and the security rule protocol. Then, the server can merge the flow table configurations in the above N flow table configurations that have the same host IP addresses bound under the same remote security group and the same security rule protocol to obtain the above M flow table configurations.

[0102] Optionally, in the embodiments of the present application, the above N flow table configurations may include multiple groups of flow table configurations with the same target fields. The server can separately merge each group of flow table configurations with the same target fields to obtain the above M flow table configurations.

[0103] Optionally, in the embodiments of the present application, in combination with Figure 3 , as Figure 4 shown, the above step 302 can be specifically implemented by the following step 302a.

[0104] Step 302a: The server uses the first merging method to merge the flow table configurations in the N flow table configurations that have the same target fields to obtain M flow table configurations.

[0105] Among them, the above first merging method includes:

[0106] Adding a first field to each flow table configuration in the above N flow table configurations, where the first field is used to indicate the list of IP addresses of the hosts bound under the second security group; or,

[0107] Concatenating the list of IP addresses of the hosts bound under the second security group into a first string;

[0108] Among them, the above second security group is the remote security group in the security group rules under the above first security group.

[0109] Optionally, in the embodiments of the present application, the above first field may be a list type field, and the list type field is used to fill in the above list of IP addresses.

[0110] Optionally, in the embodiments of the present application, other matching fields in each of the above flow table configurations except the above first field may be fields of a basic type, and the basic type may include a string type, an integer type, a floating point type, or a boolean type, etc., which can be specifically determined according to actual usage requirements and are not limited in the embodiments of the present application.

[0111] For the specific description of the above fields of the basic type, reference may be made to the relevant descriptions in the related art. To avoid repetition, it will not be elaborated here.

[0112] In the embodiments of the present application, since the above first field can be a list type field, and this list type field can be used to fill in the above IP address list, the IP address list can be accurately indicated by adding this first field to each of the above flow table configurations.

[0113] Optionally, in the embodiments of the present application, the server may use the above first merging method to merge the flow table configurations with the same target field in the above N flow table configurations into one flow table configuration, so as to obtain the above M flow table configurations.

[0114] For example, taking the above first merging method as adding the above first field to each of the above N flow table configurations as an example, assuming that the N flow table configurations include flow table configuration 1, flow table configuration 2, and flow table configuration 3; then the server may first add the list type field A (i.e., the first field) for filling in the above IP address list to flow table configuration 1, flow table configuration 2, and flow table configuration 3 respectively, and then merge the flow table configurations corresponding to the same host and the same remote security rules in flow table configuration 1, flow table configuration 2, and flow table configuration 3, so as to obtain the above M flow table configurations. It can be understood that each of the above M flow table configurations includes the list type field A.

[0115] Optionally, in the embodiments of the present application, the server may also request to create a flow table configuration according to the data structure corresponding to the above first merging method; the example of the Remote Procedure Call (RPC) request structure used to request to create a flow table configuration is as follows:

[0116] {"mac":"00:1A:2B:3C:4D:5E","protocol":"tcp","port":80,"remote-ips":"172.0.0.1,172.0.0.2","action":"drop","priority":11000}.

[0117] In the embodiments of the present application, since the server may use the above first merging method to perform the above merging process to obtain the above M flow table configurations, the flow table configurations can be merged based on the above IP address list, so that the number of flow table configurations can be greatly reduced, and the performance of the device can be improved.

[0118] Optionally, in the embodiments of the present application, in combination with Figure 3 , as Figure 5 shown, the above step 302 may be specifically implemented by the following step 302b.

[0119] Step 302b: The server merges the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations.

[0120] Optionally, in the embodiments of the present application, the server may merge a group of flow table configurations with the same target fields (i.e., having the same IP addresses of the hosts bound under the first security group and the remote security group rules) among the above N flow table configurations into one flow table configuration to obtain the above M flow table configurations.

[0121] For example, assume that the above N flow table configurations include flow table configuration 1, flow table configuration 2, flow table configuration 3, flow table configuration 4, and flow table configuration 5, where flow table configuration 1 and flow table configuration 3 have the same target fields, and flow table configuration 2 and flow table configuration 4 have the same target fields; then the server may merge flow table configuration 1 and flow table configuration 3 into one flow table configuration, and merge flow table configuration 2 and flow table configuration 4 into one flow table configuration; in this way, the original 5 flow table configurations can be reduced to 3 flow table configurations.

[0122] In the embodiments of the present application, since the server can merge the flow table configurations with the same target fields among the above N flow table configurations into one flow table configuration to obtain the above M flow table configurations, the number of generated flow table configurations can be reduced, further improving the performance of the device.

[0123] Optionally, in the embodiments of the present application, the above step 302 may be specifically implemented by the following step 302c.

[0124] Step 302c: The server performs a merging process on the flow table configurations with the same target fields among the N flow table configurations through the SDN controller in the server to obtain M flow table configurations.

[0125] For the specific description of the above SDN controller, reference may be made to the relevant descriptions in the above embodiments and related technologies. To avoid repetition, it will not be elaborated here.

[0126] In the embodiments of the present application, since the above merging process can be performed through the SDN controller to obtain the above M flow table configurations, and the SDN controller can implement centralized and automated network management, the resource utilization rate of the server can be improved and costs can be saved.

[0127] Step 303: The server performs a reduction process on the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, and distributes the M flow table configurations after the reduction process.

[0128] Optionally, in the embodiments of the present application, before the server performs the reduction process on the above-mentioned M flow table configurations based on the above-mentioned flow table data, it may first perform the above-mentioned hierarchical storage operation on the above-mentioned M flow table configurations.

[0129] Optionally, in the embodiments of the present application, the server may perform the above-mentioned hierarchical storage operation on the above-mentioned M flow table configurations through a flow table management component, which is used for the management of flow table configurations.

[0130] Optionally, in the embodiments of the present application, the server may send the reduced above-mentioned M flow table configurations to the device through an OpenFlow channel. An example of the flow table configuration sending request structure is as follows:

[0131] {"mac":"00:1A:2B:3C:4D:5E","protocol":"tcp","port":80,"remote-ips":"172.0.0.1,172.0.0.2","action":"drop","priority":11000}.

[0132] Optionally, in the embodiments of the present application, the above-mentioned hierarchical storage operation may include:

[0133] Store the IP address list of the hosts bound under the above-mentioned second security group, and generate a target index for indicating the IP address list;

[0134] Store the above-mentioned M flow table configurations. The IP addresses of the hosts bound under the above-mentioned second security group included in each of the above-mentioned M flow table configurations can be indicated by the above-mentioned target index.

[0135] Optionally, in the embodiments of the present application, an example of the data structure after the above-mentioned hierarchical storage operation is as follows:

[0136] "sgr-1001":["172.0.0.1","172.0.0.2"]

[0137] {"mac":"00:1A:2B:3C:4D:5E","protocol":"tcp","port":80,"remote-ips":

[0138] "sgr-1001","action":"drop","priority":11000}.

[0139] In the embodiment of the present application, since the above hierarchical storage operation may include first storing the above IP address list and generating a target index for it, and then storing the above M flow table configurations, and the IP addresses of the hosts bound under the above first security group in each stored flow table configuration can be referenced using the target index, on the one hand, it is not necessary to directly store the above N flow table configurations, thereby reducing the power consumption of storing the flow table configurations. On the other hand, based on the target index, the M flow table configurations are processed for reduction, so that each flow table configuration obtained after the reduction processing can still indicate the accurate IP addresses of the hosts bound under the above first security group through the target index, thereby improving the accuracy of the flow table configurations obtained after the reduction processing.

[0140] Optionally, in the embodiment of the present application, in combination with Figure 3 , as Figure 6 shown, the above step 303 can be specifically implemented by the following step 303a.

[0141] Step 303a: The server replaces the second field included in each of the M flow table configurations with the target index based on the flow table data obtained after performing the hierarchical storage operation on the M flow table configurations, obtains the M flow table configurations after the reduction processing, and distributes the M flow table configurations after the reduction processing.

[0142] Wherein, the above second field is the IP address of the host bound under the above second security group.

[0143] Optionally, in the embodiment of the present application, after performing the above hierarchical storage operation, the IP addresses of the hosts bound under the above second security group included in each of the above M flow table configurations can all be referenced through the above target index, so as to replace the second field included in each such flow table configuration with the target index, so that among the M flow table configurations, the flow table configurations corresponding to the same host's IP address bound under the above first security group and different host's IP addresses bound under the above second security group are reduced to 1 flow table configuration, thereby reducing the M flow table configurations to W flow table configurations, where W is a positive integer less than M.

[0144] For example, assume that the above M flow table configurations are configured as flow table configuration a, flow table configuration b, flow table configuration c, and flow table configuration d. Among them, flow table configuration a includes the IP address of host 1 bound under the above first security group and the IP address of host 3 bound under the above second security group. Flow table configuration b includes the IP address of this host 1 and the IP address of host 4 bound under this second security group. Flow table configuration c includes the IP address of host 2 bound under this first security group and the IP address of this host 3. Flow table configuration d includes the IP address of this host 2 and the IP address of this host 4. Then the server can replace the IP addresses of both this host 3 and this host 4 with the above target index, so as to obtain flow table configuration 1 including the IP address of this host 1 and the above target index, and flow table configuration 2 including the IP address of this host 2 and the above target index (i.e., the above W flow table configurations). In this way, the reduction processing of the above M flow table configurations can be realized.

[0145] Exemplarily, Figure 7 shows the format of the above W flow table configurations stored and issued by the server, as Figure 7 shown. The above second field in each flow table configuration is replaced with an IP address list key (i.e., the above target index), so that the number of flow table configurations finally stored and issued can be greatly reduced. Assume that the initially generated N flow table configurations are A*B flow table configurations, where A is the number of hosts bound by the above first security group and B is the number of hosts bound by the above second security group. Then, through the flow table configuration processing method provided by the embodiments of the present application, the number of flow table configurations finally stored and issued can be reduced to A. In this way, the number of flow table configurations can be greatly reduced, and the memory occupation of the database and the number of interaction times and interaction data volumes for issuing flow table configurations can be reduced.

[0146] In the embodiments of the present application, since the server can replace the second field included in each of the above M flow table configurations with a target index to reference the host IP addresses bound by the above second security group through the target index, the number of flow table configurations stored and issued can be greatly reduced, and the processing power consumption can be improved.

[0147] In the flow table configuration processing method provided by the embodiments of the present application, since the flow table configurations with the same target field in the generated N flow table configurations can be merged to obtain the M flow table configurations, so as to reduce the number of generated flow table configurations, and the M flow table configurations can be further reduced based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, the number of flow table configurations that need to be stored and issued is greatly reduced, thereby improving the performance of storing and issuing flow table configurations.

[0148] The various solutions in the above embodiments of the present application can be combined without conflict.

[0149] In the embodiments of the present application, the flow table configuration processing device may be divided into functional modules according to the above method examples. For example, each functional module may be corresponding to each function, or two or more functions may be integrated into one processing module. The above integrated module may be implemented in the form of hardware or in the form of a software functional module. It should be noted that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0150] In the case of dividing each functional module corresponding to each function, Figure 8 FIG. shows a schematic structural diagram of a flow table configuration processing device 80. The flow table configuration processing device 80 may be a server in a data center or a chip applied to the server, and the flow table configuration processing device 80 may be used to execute the functions of the server involved in the above embodiments. Figure 8 The shown flow table configuration processing device 80 may include: a generating unit 81, a merging unit 82, and a processing unit 83.

[0151] Among them, the generating unit 81 may be used to generate N flow table configurations related to the first security group when receiving a northbound request corresponding to the first security group, where N is a positive integer.

[0152] The merging unit 82 may be used to perform a merging process on the flow table configurations with the same target field among the above N flow table configurations to obtain M flow table configurations. The target field includes the IP address of the host bound under the first security group and the remote security group rule, and M is a positive integer less than N.

[0153] The processing unit 83 may be used to perform a reduction process on the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, and issue the M flow table configurations after the reduction process.

[0154] In the embodiments of the present application, the merging unit 82 may specifically be used to perform a merging process on the flow table configurations with the same target field among the above N flow table configurations using a first merging method to obtain the above M flow table configurations;

[0155] Among them, the above first merging method includes:

[0156] Adding a first field to each of the above N flow table configurations, where the first field is used to indicate a list of IP addresses of hosts bound under the second security group; or,

[0157] Concatenating the list of IP addresses of hosts bound under the second security group into a first string;

[0158] Among them, the second security group is the remote security group in the security group rules under the first security group.

[0159] In the embodiment of the present application, the first field may be a list type field, and this list type field is used to fill in the above IP address list.

[0160] In the embodiment of the present application, the merging unit 82 may specifically be used to merge the flow table configurations with the same target field in the above N flow table configurations into one flow table configuration, so as to obtain the above M flow table configurations.

[0161] In the embodiment of the present application, the merging unit 82 may specifically be used to perform a merging process on the flow table configurations with the same target field in the above N flow table configurations through the SDN controller in the server, so as to obtain the above M flow table configurations.

[0162] In the embodiment of the present application, the above hierarchical storage operation may include:

[0163] Storing the IP address list of the host bound under the second security group, and generating a target index for indicating this IP address list, where the second security group is the remote security group in the security group rules under the first security group;

[0164] Storing the above M flow table configurations, and the IP address of the host bound under the second security group included in each of the above M flow table configurations can be indicated by the above target index.

[0165] In the embodiment of the present application, the processing unit 83 may specifically be used to replace the second field included in each of the above M flow table configurations with the above target index, so as to obtain the above M flow table configurations after reduction processing;

[0166] Among them, the second field is the IP address of the host bound under the second security group.

[0167] It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be elaborated here.

[0168] It should be noted that the specific working process of each functional module in the flow table configuration processing device provided in the embodiment of the present application can refer to the specific description of the corresponding process in the method embodiment, and will not be elaborated in detail here in the embodiment of the present application. The flow table configuration processing device provided in the embodiment of the present application is used to execute the above flow table configuration processing method, so it can achieve the same effect as the above flow table configuration processing method.

[0169] From the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above function modules is used as an example. In actual applications, the above functions can be allocated to different function modules as needed, that is, the internal structure of the device can be divided into different function modules to complete all or part of the functions described above.

[0170] In several embodiments provided in the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.

[0171] The units described as separate components may or may not be physically separated. The components displayed as units can be one physical unit or multiple physical units, that is, they can be located in one place or distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0172] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0173] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks, and other media that can store program codes.

[0174] Such asFigure 9 As shown in Figure 9 , the embodiment of the present application further provides a flow table configuration processing device 90, including a processor 91 and a memory 92. A program or instruction that can run on the processor 91 is stored on the memory 92. When the program or instruction is executed by the processor 91, it implements each step of the flow table configuration processing method embodiment as described above, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0175] It should be noted that the flow table configuration processing device provided by the embodiment of the present application may be a server.

[0176] The embodiment of the present application further provides a readable storage medium. A program or instruction is stored on the readable storage medium. When the program or instruction is executed by a processor, it implements each process of the flow table configuration processing method embodiment as described above, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0177] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for processing flow table configuration, characterized in that, the method includes: When receiving a northbound request corresponding to a first security group, generating N flow table configurations related to the first security group, where N is a positive integer; Performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations, where the target fields include the Internet Protocol (IP) addresses of the hosts bound under the first security group and the remote security group rules, and M is a positive integer less than N; Based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, performing a reduction process on the M flow table configurations, and issuing the reduced M flow table configurations.

2. The method according to claim 1, characterized in that, the performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations includes: Using a first merging method to perform a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain the M flow table configurations; wherein, the first merging method includes: Adding a first field to each of the N flow table configurations, where the first field is used to indicate the list of IP addresses of the hosts bound under a second security group; or, Concatenating the list of IP addresses of the hosts bound under the second security group into a first string; wherein, the second security group is the remote security group in the security group rules under the first security group.

3. The method according to claim 2, characterized in that, the first field is a list type field, and the list type field is used to fill in the list of IP addresses.

4. The method according to claim 1, characterized in that, the performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations includes: Merging the flow table configurations with the same target fields among the N flow table configurations into one flow table configuration to obtain the M flow table configurations.

5. The method according to any one of claims 1 to 4, characterized in that, the performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain M flow table configurations includes: Through a software-defined network (SDN) controller in the server, performing a merging process on the flow table configurations with the same target fields among the N flow table configurations to obtain the M flow table configurations.

6. The method according to claim 1, characterized in that, the hierarchical storage operation includes: Storing the list of IP addresses of the hosts bound under a second security group, and generating a target index for indicating the list of IP addresses, where the second security group is the remote security group in the security group rules under the first security group; Storing the M flow table configurations, and the IP addresses of the hosts bound under the second security group included in each of the M flow table configurations can be indicated by the target index.

7. The method according to claim 6, characterized in that, Performing a reduction process on the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, includes: Replacing a second field included in each of the M flow table configurations with the target index to obtain the M flow table configurations after the reduction process; Wherein, the second field is the IP address of the host bound under the second security group.

8. A flow table configuration processing apparatus, Characterized in that, The apparatus includes a generation unit, a merging unit and a processing unit; The generation unit is configured to generate N flow table configurations related to the first security group when receiving a northbound request corresponding to the first security group, where N is a positive integer; The merging unit is configured to perform a merging process on the flow table configurations having the same target field among the N flow table configurations to obtain M flow table configurations, the target field includes the IP address of the host bound under the first security group and the remote security group rule, and M is a positive integer less than N; The processing unit is configured to perform a reduction process on the M flow table configurations based on the flow table data obtained after performing a hierarchical storage operation on the M flow table configurations, and issue the M flow table configurations after the reduction process.

9. A server, Characterized in that, It includes a processor and a memory, the memory stores a program or instruction that can run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the flow table configuration processing method according to any one of claims 1 to 7.

10. A readable storage medium, Characterized in that, The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, it implements the steps of the flow table configuration processing method according to any one of claims 1 to 7.