Data processing method and related equipment
By implementing the analysis, table lookup and modification of data packets between the programmable switching chip and the programmable logic module, the problem of limited storage resources of the programmable switching chip is solved, which improves data processing performance and reduces forwarding delay.
Patent Information
- Application Number
- CN202311637444.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-05-30
AI Technical Summary
The programmable switching chip has limited storage resources and cannot uninstall tens of millions of session tables and routing tables. It does not support updating the state and content of the flow table on the data plane, which limits its application in stateless gateways and stateful complex scenarios.
By receiving raw data packets from outside the server, parsing and encapsulating table lookup key values, perform table lookup operations on the flow table and routing table, modify data packets, and implement data forwarding and processing between the programmable logic module and the central processor module.
It significantly improves data processing indicators, reduces forwarding delay, supports hardware offloading of massive flow tables and routing tables, solves the problem of limited storage resources, and is suitable for complex stateful gateway scenarios.
Smart Images

Figure CN120075326A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and in particular, to a data processing method and related devices. Background Art
[0002] In recent years, with the emergence of programmable protocol-independent packet processing languages, the scope of network applications using their programming capabilities in the field of high-performance networks has become wider and wider, and the entire data forwarding plane can be offloaded to the hardware layer to obtain better forwarding performance and faster forwarding speed.
[0003] However, programmable switching chips still have many limitations up to now. The storage resources of programmable switching chips are limited, they cannot offload tens of millions of session tables and routing tables, and do not support updating flow table status and content on the data plane. These problems not only limit the application of programmable technologies in some stateless gateway scenarios, but also make it difficult to be actually put into online applications in stateful complex scenarios such as load balancing. Summary of the Invention
[0004] Embodiments of this application provide a data processing method and related devices, which can greatly improve data processing metrics and significantly reduce forwarding delay.
[0005] Embodiments of this application provide a data processing method, including:
[0006] Receiving original data packets from outside the server;
[0007] Parsing the original data packets to obtain parsed information;
[0008] Encapsulating a lookup key value based on the parsed information;
[0009] Performing a lookup operation on the flow table and routing table based on the lookup key value to obtain a lookup result;
[0010] Modifying the original data packets based on the lookup result to obtain modified data packets.
[0011] Correspondingly, embodiments of this application provide a data processing device, including:
[0012] A receiving unit, configured to receive original data packets from outside the server;
[0013] A parsing unit, configured to parse the original data packets to obtain parsed information;
[0014] An encapsulating unit, configured to encapsulate a lookup key value based on the parsed information;
[0015] A lookup unit, configured to perform a lookup operation on the flow table and routing table based on the lookup key value to obtain a lookup result;
[0016] A modification unit, configured to modify the original data packet based on the table lookup result to obtain a modified data packet.
[0017] Optionally, in some embodiments of the present application, the data processing device may further include a sending unit and a central processor modification unit, as follows:
[0018] The sending unit is configured to, if it is determined that the table lookup result meets a preset condition for sending to the central processor, send the original data packet to the central processor, so that the central processor modifies the original data packet based on the table lookup result to obtain a modified data packet.
[0019] Optionally, in some embodiments of the present application, the parsing unit may specifically be configured to parse the protocol header part in the original data packet to obtain the first parsed information; parse the communication tunnel of the original data packet to obtain the second parsed information.
[0020] Optionally, in some embodiments of the present application, the modification unit may specifically be configured to modify the original data packet based on the session information carried in the table lookup result to obtain an initial modified data packet; encapsulate the initial modified data packet based on the routing information carried in the table lookup result to obtain a modified data packet.
[0021] Optionally, in some embodiments of the present application, the central processor modification unit may specifically be configured to search for a full flow table based on the original data packet to obtain a full flow table search result; if it is determined that the session information is hit based on the full flow table search result, modify the original data packet based on the session information to obtain the modified data packet.
[0022] Optionally, in some embodiments of the present application, the central processor modification unit may further specifically be configured to search for a full flow table based on the original data packet to obtain a full flow table search result; if it is determined that the session information is not hit based on the full flow table search result, establish a new session connection; modify the original data packet based on the new session connection to obtain a modified data packet.
[0023] Optionally, in some embodiments of the present application, the table lookup unit may further specifically be configured to determine whether the original data packet is a fragmented packet based on the information carried in the table lookup key; if it is determined that the original data packet is not a fragmented packet, perform a table lookup operation on the flow table and the routing table based on the table lookup key to obtain a table lookup result.
[0024] Optionally, in some embodiments of the present application, the look-up table unit may specifically be further configured to determine whether the original data packet is a fragmented packet based on the information carried in the look-up table key value; if it is determined that the original data packet is a fragmented packet, look up the fragmentation information table based on the look-up table key value; find the missing information corresponding to the original data packet in the fragmentation information table; perform a look-up table operation on the flow table and the routing table based on the look-up table key value and the missing information, and obtain a look-up table result.
[0025] An electronic device provided by an embodiment of the present application includes a processor and a memory. The memory stores multiple instructions, and the processor loads the instructions to execute the steps in the data processing method provided by the embodiment of the present application.
[0026] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the data processing method provided by the embodiment of the present application are implemented.
[0027] In addition, an embodiment of the present application further provides a computer program product, including a computer program or instruction. When the computer program or instruction is executed by a processor, the steps in the data processing method provided by the embodiment of the present application are implemented.
[0028] The present application provides a data processing method and related devices. Among them, an original data packet is received from outside the server; the original data packet is parsed to obtain parsed information; a look-up table key value is encapsulated based on the parsed information; a look-up table operation is performed on the flow table and the routing table based on the look-up table key value to obtain a look-up table result; the original data packet is modified based on the look-up table result to obtain a modified data packet. The technical solution of the present application can greatly improve the data processing index and significantly reduce the forwarding delay. Description of the Drawings
[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0030] Figure 1 It is a schematic diagram of a hyper-converged server provided by an embodiment of the present application;
[0031] Figure 2 It is the first flowchart of the data service method provided by an embodiment of the present application;
[0032] Figure 3 It is the second flowchart of the data service method provided by an embodiment of the present application;
[0033] Figure 4 It is the third flowchart of the data service method provided by the embodiment of the present application;
[0034] Figure 5 It is the fourth flowchart of the data service method provided by the embodiment of the present application;
[0035] Figure 6 It is the flowchart of the slow forwarding path provided by the embodiment of the present application;
[0036] Figure 7 It is the flowchart of the fast forwarding path provided by the embodiment of the present application;
[0037] Figure 8 It is the flowchart of the central processing unit module provided by the embodiment of the present application;
[0038] Figure 9 It is the flowchart of the programmable switching module provided by the embodiment of the present application;
[0039] Figure 10 It is the flowchart of the programmable logic module provided by the embodiment of the present application;
[0040] Figure 11 It is the schematic diagram of load balancing provided by the embodiment of the present application;
[0041] Figure 12 It is the schematic diagram provided by the embodiment of the present application;
[0042] Figure 13 It is the schematic diagram of the electronic device provided by the embodiment of the present application. Detailed implementation manners
[0043] The technical solution provided by the embodiment of the present application can be applied to various scenarios that require data communication, and the embodiment of the present application does not limit this.
[0044] Next, the technical solution in the embodiment of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiment of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0045] The embodiment of the present application provides a data processing method and related devices. The related devices may include a data processing device, an electronic device, a computer-readable storage medium, and a computer program product. The data processing device may be specifically integrated in the electronic device, and the electronic device may be a device such as a terminal or a server.
[0046] Please refer to Figure 1 , Figure 1Schematic diagram of the data processing system 100 provided by the embodiments of the present application. The data processing system 100 includes a programmable switching module 110, a programmable logic module 120, and a central processing unit module 130. Among them, the programmable switching module 110 is connected to the central processing unit module 130 and the programmable logic module 120 through Ethernet ports, and is used to receive raw data packets from outside the server; parse the raw data packets to obtain parsed information; modify the raw data packets based on the lookup table result to obtain modified data packets; the programmable logic module 120 is used to encapsulate a lookup table key value based on the parsed information; perform a lookup operation on the flow table and the routing table based on the lookup table key value to obtain a lookup table result.
[0047] It should be noted that in the embodiments of the present application, there is no specific limitation on the entity display form of the data processing system. The entity display form of the data processing system can be a mobile electronic device such as a smart phone, a tablet computer, a handheld computer, a notebook computer, etc., or a fixed electronic device such as a desktop computer, a television, etc.
[0048] The following will be described in detail respectively. It should be noted that the description order of the following embodiments does not limit the preferred order of the embodiments. This embodiment will be described from the perspective of the data processing device, and the data processing device can be specifically integrated in the data processing system. This embodiment can be applied to various scenarios such as cloud technology, artificial intelligence, intelligent transportation, and assisted driving.
[0049] In one embodiment, the data processing system provided by the present application at least includes a programmable switching module 110, a programmable logic module 120, and a central processing unit module 130. For example, as Figure 1 shown, the programmable switching module 110 includes a programmable switching chip, the programmable logic module 120 includes at least one FPGA chip (Field Programmable Gate Array), and the central processing unit module 130 includes a central processing unit and a network card. That is, the embodiments of the present application disclose an all-in-one super server formed by the integration of a central processing unit, a network card, an FPGA chip, and a programmable switching chip.
[0050] Among them, the programmable switching chip allows new network protocols or new network functions to be added to the network chip without redesigning a new chip. The programmable switching chip mainly consists of two parts: a pipeline composed of a protocol parser and a processing module. The parser is used to extract various data of the network data packet, and the pipeline operates according to these data and updates the state on the chip memory.
[0051] Among them, the FPGA chip (Field Programmable Gate Array) is a hardware device with programmable logic. The FPGA is a semi-custom circuit developed on the basis of traditional logic circuits such as PAL (Programmable Array Logic), GAL (Generic Array Logic), and CPLD (Complex Programmable Logic Device) and gate arrays. It is mainly applied to the field of application-specific integrated circuits, which not only solves the deficiencies of semi-custom circuits but also overcomes the drawback of limited gate circuits in the original programmable devices.
[0052] As Figure 1 shown, the super server in the embodiment of the present application uses a programmable switching chip as the central hub, providing internal Ethernet ports for connecting internal central processor modules and programmable logic modules, and providing external Ethernet ports for connecting external network devices, and is responsible for forwarding data packets between the external ports and the internal central processor and the FPGA chip.
[0053] Among them, Ethernet is the most widely used local area network communication method and also a protocol. And the Ethernet port is the port for network data connection.
[0054] In one embodiment, the programmable switching module 110 includes a programmable switching chip. The ports in the programmable switching chip are divided into two categories: external ports and internal ports. Among them, the external ports are used to provide the external connection ability of the server. For example, the external switch can be connected through the external ports; as Figure 1 shown, the internal ports are used to connect the programmable logic module 120 and the network cards in the central processor module 130 respectively through Ethernet port interconnections. This part of the Ethernet port interconnection can be used to receive data packets from the outside, send data packets, or transfer data packets between the programmable switching module 110, the programmable logic module 120, and the central processor module 130.
[0055] The programmable switching module 110 utilizes the flexible programmable ability of the programmable switching chip to implement the network function logic processing of the fast forwarding path layer and to connect the central processor module and the programmable logic module as an intermediate hub.
[0056] In addition to the Ethernet port interconnection, there is also a PCIE channel in the embodiment of the present application. As Figure 1 shown, this PCIE channel is used to connect the central processor module 130 with the programmable switching module 110 and the programmable logic module 120. This connection can be used as a control channel to ensure that the central processor maintains and manages the status information and configuration information on the programmable switching module 110 and the programmable logic module 120.
[0057] Among them, PCIE is a high-speed serial computer expansion bus standard used to connect the computer motherboard and various peripheral devices, such as network cards, hard disks, etc. It belongs to high-speed serial point-to-point dual-channel high-bandwidth transmission. The connected devices are allocated exclusive channel bandwidth and do not share the bus bandwidth. It mainly supports functions such as active power management, error reporting, end-to-end reliable transmission, hot plugging, and quality of service. For example, in the technical solution of this application, the central processing unit connects to the programmable switch chip and the FPGA chip through the PCIE channel, which can be used to implement functions such as the management and configuration distribution of the programmable switch chip and the FPGA chip by the central processing unit respectively.
[0058] In addition, as Figure 1 shown, the programmable switch chip in the embodiment of this application can be connected to multiple FPGA chips. Each FPGA chip has a connection to double data rate synchronous dynamic random access memory storage resources, which can be used to store a large amount of flow table configuration information, routing table configuration information, etc., and implement hardware offloading of a large number of flow tables to expand the storage resources in the programmable switch chip. And the programmable switch chip completes the modification actions for the original data packet in the fast forwarding path and obtains the modified data packet: according to the lookup results of the flow table and the routing table, modify the packet protocol header, encapsulate and decapsulate the tunnel, etc. Based on the programmability of the P4 language, it can be flexibly and quickly adapted to any gateway application. Through this data processing system, the technical solution of this application can support production-level complex traffic scenarios and forwarding models.
[0059] Among them, DDR (Double Data Rate, double data rate synchronous dynamic random access memory) refers to a type of dynamic random access computer memory, which is characterized by low cost and large capacity. For example, in the embodiment of this application, the FPGA chip carrying double data rate synchronous dynamic random access memory storage resources can be used to store configurations such as flow tables and routing tables unloaded from the central processing unit to the hardware layer.
[0060] The programmable logic module mainly uses the FPGA chip with double data rate synchronous dynamic random access memory storage to expand the storage resources of the programmable switch module, and realizes the storage of a large number of flow tables and routing tables in the fast forwarding path hardware layer. As Figure 1 shown, the programmable logic module mainly realizes the common flow table lookup and routing table lookup functions in most virtual private cloud gateways. It does not need to independently parse the protocol header content, but only looks up the flow table and the routing table according to the lookup key value, and finally sends the lookup result together with the original data packet. The programmable logic module can implement many common functions in network applications, such as flow table lookup and routing table lookup, and can cover any gateway application scenario.
[0061] The central processing unit module 130 includes a central processing unit and a corresponding network card. The central processing unit module 130 mainly refers to a gateway module implemented by pure software. In addition to performing specific network function logic operations of the gateway, it is also responsible for functions such as establishing session connections, maintaining session states, offloading or updating flow tables and routing tables to hardware. The flexibility of the central processing unit platform solves the problem that programmable switching chips cannot complete session establishment and session release in data plane programming.
[0062] As Figure 2 shown, the specific process of this data processing method can be as follows:
[0063] S201. Receive the original data packet from outside the server.
[0064] For example, as Figure 7 shown, the programmable switching chip receives the original data packet from the upstream switch outside the server in step 1 in Figure 7 .
[0065] S202. Analyze the original data packet to obtain the analyzed information.
[0066] For example, as Figure 7 shown, after the programmable switching chip analyzes the content of the original data packet protocol header to obtain the analyzed information, it sends the original data packet to the FPGA chip for data processing in step 2 in Figure 7 .
[0067] Optionally, in one embodiment, the step of "analyzing the original data packet to obtain the analyzed information" may include:
[0068] Analyze the protocol header part in the original data packet to obtain the first analyzed information;
[0069] Analyze the communication tunnel of the original data packet to obtain the second analyzed information.
[0070] Wherein, the analyzed information includes the first analyzed information and the second analyzed information.
[0071] For example, as Figure 9 shown, Figure 9 in step 1, the programmable switching chip can receive the original data packet from outside the server. After receiving the packet, in Figure 9 step 2, it analyzes the protocol header part in the original data packet to obtain the first analyzed information, and then in Figure 9 step 3, it analyzes the communication tunnel of the original data packet to obtain the second analyzed information. The first analyzed information and the second analyzed information constitute the analyzed information.
[0072] S203. Encapsulate the lookup key value based on the analyzed information.
[0073] Among them, the look-up table key value can be a set containing multiple field information, and its application in different gateways can be different, specifically determined by the service logic of the specific gateway. For example, common fields can be: source address of the data packet, destination address, virtual private cloud identifier, source port, destination port, etc.
[0074] For example, as Figure 9 shown, in Figure 9 step 4, according to the parsed information, encapsulate the look-up table key value used to look up the flow table and routing table in the FPGA chip. Then, in Figure 9 step 5 and 6, send the original data packet together with the look-up table key value to the FPGA chip through the internal port of the programmable switch chip.
[0075] S204. Perform a look-up table operation on the flow table and routing table based on the look-up table key value to obtain a look-up table result.
[0076] Among them, the flow table refers to the network connection session information table, and the flow table records information such as the forward and reverse five-tuples (source address, destination address, virtual private cloud identifier, source port, destination port) of the network connection at the gateway node.
[0077] For example, as Figure 7 shown, in Figure 7 step 2, after the FPGA chip receives the original data packet and the look-up table key value from the programmable switch chip, it can perform a look-up table operation to find the flow table and the routing table according to the look-up table key value to obtain a look-up table result. Then, in Figure 7 step 3, send the look-up table result together with the original data packet to the programmable switch chip.
[0078] Optionally, in an embodiment, the step of "performing a look-up table operation on the flow table and routing table based on the look-up table key value to obtain a look-up table result" may include:
[0079] Judge whether the original data packet is a fragmented packet based on the information carried in the look-up table key value;
[0080] If it is determined that the original data packet is not a fragmented packet, perform a look-up table operation on the flow table and routing table based on the look-up table key value to obtain a look-up table result.
[0081] For example, as Figure 10 shown, the FPGA chip can be used to receive the original data packet and the look-up table key value from the programmable switch chip. After receiving the packet, the FPGA chip can judge whether the original data packet is a fragmented packet according to the information in the look-up table key value. If the original data packet is not a fragmented packet, directly continue to look up the flow table and routing table according to the look-up table key value to obtain a look-up table result.
[0082] Optionally, in one embodiment, after the step of "judging whether the original data packet is a fragmented packet based on the information carried in the look-up table key value", the following steps may further be included:
[0083] If it is determined that the original data packet is a fragmented packet, look up the fragmentation information table based on the look-up table key value;
[0084] Look up the missing information corresponding to the original data packet in the fragmentation information table;
[0085] Perform a look-up table operation on the flow table and the routing table based on the look-up table key value and the missing information to obtain a look-up table result.
[0086] Wherein, the look-up table result includes session information and routing information.
[0087] For example, as Figure 10 shown, the FPGA chip can be used to receive the original data packet and the look-up table key value from the programmable switching chip. After receiving the packet, the FPGA chip can judge whether the original data packet is a fragmented packet according to the information in the look-up table key value. If the original data packet is a fragmented packet, the FPGA chip can look up the fragmentation information table according to the information in the look-up table key value and find the transport layer port information corresponding to the original data packet, that is, the missing information, such as the source port and destination port of the TCP protocol, or the source port and destination port of the UDP protocol, and so on. Then continue to look up the flow table according to the look-up table key value to obtain session information, and look up the virtual private cloud routing table according to the look-up table key value to obtain routing information. Finally, send the session information and routing information in the look-up table result together with the original data packet to the programmable switching chip.
[0088] S205. Modify the original data packet based on the look-up table result to obtain a modified data packet.
[0089] For example, as Figure 7 shown, the programmable switching chip can modify the original data packet based on the look-up table result to obtain a modified data packet, and then the programmable switching chip executes Figure 7 step 4 in to directly send out the modified data packet, and finally reach the backend server.
[0090] Optionally, in one embodiment, the step of "modifying the original data packet based on the look-up table result to obtain a modified data packet" may include:
[0091] Modify the original data packet based on the session information carried in the look-up table result to obtain an initial modified data packet;
[0092] Encapsulate the initial modified data packet based on the routing information carried in the look-up table result to obtain a modified data packet.
[0093] For example, as Figure 9 shown, after the programmable switching chip receives the original data packet from the FPGA chip, if the lookup result contains session information and routing information, it can be determined that the session information and routing information are found, and then it can be as Figure 9 in step 9 of FIG. 9, first, according to the five-tuple (source address, destination address, virtual network identifier, source port, destination port) and behavior information in the session information, perform specific network function logic operations to complete the modification of the original data packet, and obtain the initial modified data packet. Among them, the network function logic operations may include network address translation (NAT), access control list (ACL), TCP option (transmission control protocol selection) processing, etc. And as Figure 9 in step 10 of FIG. 10, encapsulate a communication tunnel (such as the GRE protocol) for the initially modified data packet according to the routing information to complete the modification of the entire packet and obtain the modified data packet.
[0094] In one embodiment, the overall system framework protected by the present application can be divided into a slow forwarding path (slowpath) forwarded by the central processing unit module 130, and a fast forwarding path (fastpath) forwarded by the programmable switching module 110 and the programmable logic module 120, so as to support the separation of the fast and slow paths through integrated hardware. The above is the description of the fast forwarding path. Among them, the programmable switching module in the fast forwarding path is responsible for completing logic such as data packet protocol header parsing, communication tunnel decapsulation, encapsulation lookup key value, network function logic processing, and encapsulation tunnel. That is, in the fast forwarding path, DDR storage is externally connected to the FPGA chip, thus solving the problem that the storage resources in the programmable switching chip are limited and cannot store a large number of flow tables and routing tables. And the fast forwarding path can implement functions such as flow table storage and lookup, flow table timeout timer update, routing table storage and lookup, and fragmentation information table maintenance and lookup in the FPGA chip; implement various network function processing logics common to gateways in the programmable switching chip, such as: data packet protocol header parsing, communication tunnel decapsulation, encapsulation lookup key value, network function logic processing, encapsulation tunnel, etc. Effectively solve the difficult problems such as large flow table configuration scale, difficult state maintenance, complex service logic, and poor scalability encountered in hardware offloading of various gateway applications in large-scale cloud providers. The corresponding description of the slow forwarding path will be given below.
[0095] The technical solution of the present application uses the programmable switching module and the programmable logic module as the gateway to forward the fast forwarding path, which is responsible for the lookup, modification, and forwarding of data packets at the hardware layer.
[0096] For example, as Figure 6 shown, in Figure 6In step 1, the programmable switch chip receives the original data packet from the uplink switch outside the server. After parsing the content of the original data packet protocol header, Figure 6 In step 2, the original data packet is sent to the FPGA chip for data processing.
[0097] Specifically, as Figure 9 shown, Figure 9 In step 1, the programmable switch chip receives the original data packet from outside the server. After receiving the packet, Figure 9 In step 2, the protocol header part in the original data packet is parsed. Then, Figure 9 In step 3, the communication tunnel in the original data packet is parsed to obtain the parsed information. Then, Figure 9 In step 4, according to the parsed information parsed in the above steps, a look-up key value for looking up the flow table and routing table in the FPGA chip is encapsulated. Finally, Figure 9 In steps 5 and 6, the original data packet together with the look-up key value is sent to the FPGA chip through the internal port of the programmable switch chip.
[0098] For example, as Figure 6 shown, in Figure 6 In step 2, after the FPGA chip receives the original data packet and the look-up key value from the programmable switch chip, it can perform look-up operations on the flow table and routing table according to the look-up key value to obtain the look-up result. Then, Figure 6 In step 3, the look-up result together with the original data packet is sent to the programmable switch chip.
[0099] Specifically, as Figure 10 shown, the FPGA chip can be used to receive the original data packet and the look-up key value from the programmable switch chip. After receiving the packet, the FPGA chip can judge whether the original data packet is a fragmented packet according to the information in the look-up key value. If the original data packet is not a fragmented packet, it directly continues to look up the flow table and routing table according to the look-up key value to obtain the look-up result.
[0100] Specifically, as Figure 10As shown, the FPGA chip can be used to receive the original data packets and the look-up table key values from the programmable switching chip. After receiving the packets, the FPGA chip can determine whether the original data packet is a fragmented packet according to the information in the look-up table key value. If the original data packet is a fragmented packet, the FPGA chip can search the fragmentation information table according to the information in the look-up table key value and find the transport layer port information corresponding to the original data packet, that is, the missing information, such as the source port and destination port of the TCP protocol, or the source port and destination port of the UDP protocol, and so on. Then, continue to search the flow table according to the look-up table key value to obtain the session information, and search the virtual private cloud routing table according to the look-up table key value to obtain the routing information. Finally, send the session information and routing information in the look-up table result together with the original data packet to the programmable switching chip.
[0101] Among them, the programmable logic module is responsible for maintaining and searching the fragmentation information table, searching the flow table, updating the timeout timer, searching the routing table according to the look-up table key value, and sending the look-up table result in the original data packet to the programmable switching module.
[0102] Optionally, in an embodiment, before the step of "modifying the original data packet based on the look-up table result to obtain the modified data packet", it may further include:
[0103] If it is determined that the look-up table result meets the preset condition for sending to the central processing unit, send the original data packet to the central processing unit so that the central processing unit can modify the original data packet based on the look-up table result to obtain the modified data packet.
[0104] For example, as Figure 6 shown, after receiving the original data packet and the look-up table result from the FPGA chip, the programmable switching chip can determine whether to send the original data packet to the central processing unit module according to whether the look-up table result carries the session information. If the look-up table result does not carry the session information, it can directly send the original data packet to the central processing unit for processing as in step 4 of Figure 6 . Then, in Figure 6 step 4, after the central processing unit receives the original data packet from the programmable switching chip, it can execute the complete NF logic, establish a session connection, add the full flow table and unload it to the FPGA hardware, and finally send the modified packet back to the programmable switching chip in step 5 of Figure 6 .
[0105] Among them, NF (Network Function) refers to mainly processing various network functions.
[0106] Specifically, as Figure 9As shown, if the original data packet hits the flow table and routing table in the FPGA chip, the session information and routing information in the table lookup result will be sent to the programmable switch chip together. Then in Figure 9 Steps 7 and 8 in it receive the original data packet and the table lookup result from the FPGA chip through the internal port of the programmable switch chip. At this time, it can be judged by the programmable switch chip whether it is necessary to send the original data packet to the central processor to take the slow forwarding path. Among them, the judgment conditions can be adjusted according to the actual situation, and the judgment conditions set for different gateway applications are also different. For example, the conditions for not finding the FPGA session information or the found FPGA session information being expired can be set as the conditions for sending to the central processor. If as Figure 9 It is determined in step 9' that it is necessary to send the original data packet to the central processor to take the slow forwarding path, then the programmable switch chip can Figure 9 In step 10' send the original data packet to the central processor. Then, the central processor can receive the original data packet from the programmable switch module, and then modify the original data packet to obtain the modified data packet. Update the flow table and routing table to the hardware, and finally as Figure 9 In steps 11' and 12' send the modified data packet to the programmable switch module.
[0107] Optionally, in an embodiment, the step of "modifying the original data packet based on the table lookup result to obtain the modified data packet" may include:
[0108] Search for the full flow table based on the original data packet to obtain the full flow table lookup result;
[0109] If it is determined that the session information is hit based on the full flow table lookup result, modify the original data packet based on the session information to obtain the modified data packet.
[0110] For example, as Figure 9 shown, the central processor can receive the original data packet from the programmable switch module, search for the full flow table after receiving the packet to obtain the full flow table lookup result. If it is determined that the session is hit according to the full flow table lookup result, it will directly go to execute the network function logic process. During the execution of the network function logic process, all modification operations on the original data packet in the specific gateway application can be completed to obtain the modified data packet. Then unload or update the flow table and routing table to the hardware layer, and finally send the modified data packet out through the central processor network card.
[0111] Optionally, in an embodiment, after the step of "searching for the full flow table based on the original data packet to obtain the full flow table lookup result", it may further include:
[0112] If it is determined that the session information is not hit based on the full flow table lookup result, a new session connection is established;
[0113] Based on the new session connection, the original data packet is modified to obtain a modified data packet.
[0114] For example, as Figure 9 shown, the central processing unit can receive the original data packet from the programmable switching module, look up the full flow table after receiving the packet, and obtain the full flow table lookup result. If it is determined that the session is not hit according to the full flow table lookup result, a new session connection needs to be established first, and then the execution of the network function logic process is transferred. During the execution of the network function logic process, all modification operations on the original data packet in the specific gateway application can be completed to obtain a modified data packet. Then, the flow table and routing table are unloaded or updated to the hardware layer, and finally the modified data packet is sent out through the central processing unit network card. The technical solution of this application uses the central processing unit as the slow forwarding path of the gateway, which is responsible for functions such as session connection establishment, session state maintenance, session unloading, and routing unloading. Then, the programmable switching module can receive the modified data packet from the central processing unit module and send the modified data packet in Figure 6 step 6 to the backend server.
[0115] The technical solution of this application uses the central processing unit as the slow forwarding path of the gateway and uses the programmable switching chip plus the FPGA chip as the fast forwarding path, realizing the hardware unloading of the connection session table and routing table at the level of millions of entries, supporting the flexible programmability of the hardware data plane, greatly improving the gateway forwarding performance, and reducing the forwarding delay. More specifically, the slow forwarding path can realize functions such as session connection establishment, session state maintenance, session unloading, and routing unloading.
[0116] The typical application scenario of the technical solution of this application is the cloud network virtual private cloud product, which can carry specific product functions such as subnet routing, private connection, access control list, security group, and load balancing. Compared with the pure software solution in the prior art, the technical solution of this application can greatly improve key performance indicators such as forwarding bit rate, transmission rate, and single-sale cost, and significantly reduce the forwarding delay. In addition, the hardware and system provided by the technical solution of this application can also be applied to other products or devices such as forward and reverse network address conversion, load balancing, unified access, traffic analysis, and application gateway.
[0117] The programmable gateway system and the corresponding hyper-converged server proposed by the technical solution of this application, as Figure 11 shown, have been actually applied. It realizes the complete unloading of the packet forwarding logic originally processed only by software to the hardware layer, and has achieved remarkable results in terms of packet processing speed, forwarding delay, and single-machine forwarding performance. AsFigure 11 As shown, it demonstrates the application of the technical solution of this application in the virtual private cloud GW gateway, and its specific benefits brought by the technical solution of this application are reflected in the following several aspects:
[0118] First of all, the network function processing logic of the virtual private cloud gateway is completely implemented at the hardware layer based on a programmable switching chip + FPGA chip: performing FULL NAT operations on the source address, destination address, source port, and destination port, modifying TCP option, adding new TCP option, access control list, etc., truly realizing the offloading of complex stateful gateways to programmable hardware in large-scale cloud providers.
[0119] Secondly, it has successfully offloaded the flow table and routing table, each reaching the 100-megabyte level, to the hardware layer, showing a significant increase compared to the maximum offloadable flow table numbers of 1 megabyte and 10 megabytes supported in the prior art.
[0120] Thirdly, due to the generality of the programmable logic module design, when the system in the technical solution of this application adapts to the virtual private cloud gateway, only business adaptation needs to be done based on the programmability of the programmable switching chip, and the programmable logic module does not need to perform repetitive development work. Compared with the hardware offloading completely based on FPGA chips in the prior art, its flexibility and programmability are better.
[0121] Thirdly, based on the all-in-one server form of the superfusion of a central processing unit + programmable switching chip + FPGA chip, compared with the prior art composed of a combination of multiple independent devices, it has more advantages in terms of stability, forwarding delay, and device cost.
[0122] Finally, compared with the virtual private cloud gateway with pure software forwarding in the previous generation of the prior art, its benefits are more obvious. The forwarding performance of a single machine has been improved from 100G of the previous generation gateway to 800G, an 8-fold increase; the forwarding delay has been shortened from 25us of the previous generation gateway to 5us, a reduction of 80%.
[0123] As can be seen from the above, this embodiment can receive raw data packets from outside the server; parse the raw data packets to obtain parsed information; encapsulate a lookup key value based on the parsed information; perform a lookup operation on the flow table and routing table based on the lookup key value to obtain a lookup result; modify the raw data packets based on the lookup result to obtain modified data packets. The technical solution of this application can greatly improve data processing metrics and significantly reduce forwarding delay.
[0124] According to the method described in the previous embodiment, the programmable switching module in this data processing system will be further described in detail by way of example below. The programmable switching module of the embodiment of this application provides a data processing method, as Figure 3 shown, the specific process of this data processing method can be as follows:
[0125] S301. The programmable switching module receives the original data packet from outside the server.
[0126] S302. The programmable switching module parses the protocol header part and the communication tunnel in the original data packet.
[0127] For example, as Figure 9 shown in steps 2 and 3, the programmable switching chip can parse the protocol header part and the communication tunnel in the original data packet.
[0128] S303. The programmable switching module encapsulates the lookup table key value.
[0129] For example, according to Figure 9 the information parsed in steps 2 and 3, the lookup table key value for looking up the flow table and routing table in the programmable logic module can be encapsulated. Here, the lookup table key value can be a set containing multiple field information, and it can be different in different gateway applications, which is determined by the business logic of the specific gateway. For example, the common field information can be: source address of the packet, destination address, virtual private cloud identifier, source port, destination port, etc.
[0130] S304. The programmable switching module sends the original data packet and the lookup table key value to the programmable logic module, and receives the original data packet after lookup and the lookup table key value.
[0131] For example, as Figure 9 shown in steps 5 and 6, the programmable switching chip sends the original data packet together with the lookup table key value to the programmable logic module through the internal port of the programmable switching chip. Then, as Figure 9 shown in steps 7 and 8, the programmable switching chip can receive the original data packet after lookup and the lookup table key value from the programmable logic module through the internal port of the programmable logic module. If the original data packet hits the flow table and routing table in the programmable logic module, the session information and routing information in the lookup result will be sent to the programmable switching module together.
[0132] At this time, the programmable switching module judges whether it is necessary to send the original data packet to the central processor to process it through the fast forwarding path. The judgment conditions can vary according to different gateway applications. For example, the conditions for sending to the central processor can be set as: no session information is found, the found session information has expired, etc.
[0133] S305. If the programmable switching module determines that it is not necessary to send to the central processor, it modifies the original data packet and sends the modified data packet.
[0134] For example, as Figure 9As shown in step 9, the programmable switching chip can perform network function logic processing based on the found session information, such as outbound five-tuple information (source address, destination address, virtual private cloud identifier, source port, destination port), action field, etc., to complete the modification of the original data packet and obtain the modified data packet. Similarly, different gateway applications perform different network function logic actions. Common actions include replacing the source address, destination address, source port, and destination port, modifying the field values in the TCP / UDP protocol header, modifying / adding / deleting transmission control protocol options, etc.
[0135] Then, as Figure 9 shown in step 10, according to the found routing information, encapsulate a communication tunnel for the modified data packet, such as a generic routing encapsulation tunnel, etc. Then, as Figure 9 shown in step 11, send the modified data packet.
[0136] S306. If the programmable switching module determines that it needs to send data to the central processing unit, send the original data packet to the central processing unit, and after receiving the modified data packet, send the modified data packet.
[0137] For example, if the programmable switching chip determines that it needs to send data to the central processing unit, it can, as Figure 9 shown in steps 9' and 10', send the original data packet to the central processing unit through the slow forwarding path. Then, as Figure 9 shown in step 11', receive the modified data packet that has completed the slow forwarding path modification from the central processing unit through the internal port of the programmable switching module. Finally, as Figure 9 shown in step 12', send the modified data packet.
[0138] As can be seen from the above, in this embodiment, the programmable switching module can receive the original data packet from outside the server; parse the protocol header part and the communication tunnel in the original data packet; encapsulate the lookup table key value; send the original data packet and the lookup table key value to the programmable logic module, and receive the original data packet after lookup and the lookup table key value; if the programmable switching module determines that there is no need to send data to the central processing unit, modify the original data packet and send the modified data packet; if the programmable switching module determines that it needs to send data to the central processing unit, send the original data packet to the central processing unit, and after receiving the modified data packet, send the modified data packet. The programmable switching module mainly utilizes the flexible programmable ability of the programmable switching chip to implement network function logic processing at the fast forwarding path layer and act as an intermediate hub to connect the programmable logic module and the central processing unit module.
[0139] According to the method described in the previous embodiments, the central processing unit module in this data processing system will be taken as an example for further detailed description below. An embodiment of the present application provides a data processing method for the central processing unit module. As Figure 4 shown, the specific process of this data processing method can be as follows:
[0140] S401. The central processing unit module receives the original data packet from the programmable switching chip.
[0141] S402. After receiving the packet, the central processing unit module searches the full flow table. If the session is not hit, a new session connection needs to be established first, and then it goes to execute the network function logic process.
[0142] S403. If the central processing unit module determines that the session is hit, it directly goes to the network function logic process to obtain the modified data packet.
[0143] For example, as Figure 8 shown, when the central processing unit executes the network function logic process, it can complete the modification operation on the original data packet in the specific gateway application to obtain the modified data packet.
[0144] S404. The central processing unit module sends the modified data packet to the programmable switching module.
[0145] For example, as Figure 8 shown, the central processing unit can unload or update the flow table and routing table to the hardware layer, and finally send the modified data packet through the network card corresponding to the central processing unit.
[0146] As can be seen from the above, in this embodiment, the central processing unit module can receive the original data packet from the programmable switching chip; after receiving the packet, search the full flow table. If the session is not hit, a new session connection needs to be established first, and then it goes to execute the network function logic process; if the central processing unit module determines that the session is hit, it directly goes to the network function logic process to obtain the modified data packet; send the modified data packet to the programmable switching module. The central processing unit mainly refers to the gateway module implemented by pure software. In addition to executing the specific network function logic operations of the gateway, it is also responsible for functions such as establishing session connections, maintaining session states, unloading or updating the flow table and routing table to the hardware, etc.
[0147] According to the method described in the previous embodiments, the programmable logic module in this data processing system will be taken as an example for further detailed description below. An embodiment of the present application provides a data processing method for the programmable logic module. As Figure 5 shown, the specific process of this data processing method can be as follows:
[0148] S501. The programmable logic module receives the original data packet and the lookup table key value, and determines whether the original data packet is a fragmented packet.
[0149] For example, as Figure 10 shown in step 1, the programmable logic module receives the original data packet and the lookup table key value from the programmable switch chip, and determines whether the original data packet is a fragmented packet according to the information in the lookup table key value after receiving the packet.
[0150] S502. If the programmable logic module determines that the original data packet is not a fragmented packet, it directly continues to search for the flow table according to the lookup table key value.
[0151] For example, as Figure 10 shown in step 2, if the programmable logic module determines that the original data packet is not a fragmented packet, it directly continues to search for the flow table according to the lookup table key value.
[0152] S503. If the programmable logic module determines that the original data packet is a fragmented packet, it searches for the fragmentation information table, session information, and routing information.
[0153] For example, as Figure 10 shown in step 2', if the programmable logic module determines that the original data packet is a fragmented packet, it can search for the fragmentation information table according to the information in the lookup table key value, and find the transport layer port information corresponding to the original data packet, such as the source port and destination port of the TCP protocol or UDP protocol. Then, as Figure 10 shown in step 3', it continues to search for the flow table according to the lookup table key value to obtain the session information, and then as Figure 10 shown in step 4, it searches for the virtual private cloud routing table according to the lookup table key value to obtain the routing information.
[0154] S504. The programmable logic module sends the session information, routing information in the lookup result, together with the original data packet, to the programmable switch chip.
[0155] As can be seen from the above, in this embodiment, the programmable logic module can receive the original data packet and the look-up table key value, and determine whether the original data packet is a fragmented packet. If the programmable logic module determines that the original data packet is not a fragmented packet, it directly continues to look up the flow table according to the look-up table key value. If the programmable logic module determines that the original data packet is a fragmented packet, it looks up the fragmentation information table, session information, and routing information. The session information and routing information in the look-up result, together with the original data packet, are then sent out to the programmable switch chip. The programmable logic module mainly uses an FPGA chip with DDR storage to expand the storage resources of the programmable switch chip, and realizes the storage of a large number of flow tables and routing tables at the hardware layer of the fast forwarding path. The programmable logic module mainly realizes the common flow table look-up and routing table look-up functions in most virtual private cloud gateways. It does not need to independently parse the protocol header content, but only looks up the flow table and routing table according to the look-up table key value, and finally sends the look-up result together with the original data packet.
[0156] To better implement the above method, an embodiment of the present application further provides a data processing device, as Figure 12 shown. The data processing device may include a receiving unit 1201, a parsing unit 1202, a packaging unit 1203, a look-up table unit 1204, and a modification unit 1205, as follows:
[0157] The receiving unit 1201 is configured to receive an original data packet from outside the server;
[0158] The parsing unit 1202 is configured to parse the original data packet to obtain parsed information;
[0159] The packaging unit 1203 is configured to package a look-up table key value based on the parsed information;
[0160] The look-up table unit 1204 is configured to perform a look-up table operation on the flow table and routing table based on the look-up table key value to obtain a look-up result;
[0161] The modification unit 1205 is configured to modify the original data packet based on the look-up result to obtain a modified data packet.
[0162] Optionally, in some embodiments of the present application, the data processing device may further include a sending unit and a central processor modification unit, as follows:
[0163] The sending unit is configured to send the original data packet to the central processor module if it is determined that the look-up result meets a preset condition for uploading to the central processor module;
[0164] The central processor modification unit is configured to modify the original data packet based on the look-up result to obtain a modified data packet.
[0165] Optionally, in some embodiments of the present application, the parsing unit may specifically be configured to parse the protocol header part in the original data packet to obtain the first parsed information; and parse the communication tunnel of the original data packet to obtain the second parsed information.
[0166] Optionally, in some embodiments of the present application, the modifying unit may specifically be configured to modify the original data packet based on the session information carried in the table lookup result to obtain an initial modified data packet; and encapsulate the initial modified data packet based on the routing information carried in the table lookup result to obtain a modified data packet.
[0167] Optionally, in some embodiments of the present application, the central processing unit modifying unit may specifically be configured to look up a full flow table based on the original data packet to obtain a full flow table lookup result; if it is determined that the session information is hit based on the full flow table lookup result, modify the original data packet based on the session information to obtain the modified data packet.
[0168] Optionally, in some embodiments of the present application, the central processing unit modifying unit may further specifically be configured to look up a full flow table based on the original data packet to obtain a full flow table lookup result; if it is determined that the session information is not hit based on the full flow table lookup result, establish a new session connection; and modify the original data packet based on the new session connection to obtain a modified data packet.
[0169] Optionally, in some embodiments of the present application, the table lookup unit may further specifically be configured to determine whether the original data packet is a fragmented packet based on the information carried in the table lookup key value; if it is determined that the original data packet is not a fragmented packet, perform a table lookup operation on the flow table and the routing table based on the table lookup key value to obtain a table lookup result.
[0170] Optionally, in some embodiments of the present application, the table lookup unit may further specifically be configured to determine whether the original data packet is a fragmented packet based on the information carried in the table lookup key value; if it is determined that the original data packet is a fragmented packet, look up a fragmentation information table based on the table lookup key value; look up the missing information corresponding to the original data packet in the fragmentation information table; and perform a table lookup operation on the flow table and the routing table based on the table lookup key value and the missing information to obtain a table lookup result.
[0171] As can be seen from the above, in this embodiment, the programmable switching module can receive the original data packet from outside the server; parse the original data packet to obtain the parsed information; encapsulate the look-up key value based on the parsed information through the programmable logic module; perform a look-up operation on the flow table and the routing table based on the look-up key value to obtain the look-up result; and modify the original data packet based on the look-up result to obtain the modified data packet. The technical solution of this application can greatly improve the data processing index and significantly reduce the forwarding delay.
[0172] The embodiment of this application also provides an electronic device, as Figure 13 shown, which shows the structural schematic diagram of the electronic device involved in the embodiment of this application. This electronic device can be a terminal or a server, etc. Specifically:
[0173] This electronic device may include components such as a processor 1301 with one or more processing cores, a memory 1302 with one or more computer-readable storage media, a power supply 1303, and an input unit 1304. Those skilled in the art can understand that Figure 13 the structure of the electronic device shown in
[0174] does not constitute a limitation on the electronic device, and it may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements. Among them:
[0175] The memory 1302 can be used to store software programs and modules. The processor 1301 executes various functional applications and data processing by running the software programs and modules stored in the memory 1302. The memory 1302 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the electronic device. In addition, the memory 1302 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory 1302 can also include a memory controller to provide the processor 1301 with access to the memory 1302.
[0176] The electronic device further includes a power supply 1303 for powering each component. Preferably, the power supply 1303 can be logically connected to the processor 1301 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The power supply 1303 can also include any components such as one or more DC or AC power supplies, a recharge system, a power failure detection circuit, a power converter or inverter, and a power status indicator.
[0177] The electronic device may further include an input unit 1304, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function controls.
[0178] Although not shown, the electronic device may further include a display unit, etc., which will not be elaborated here. Specifically, in this embodiment, the processor 1301 in the electronic device will load the executable files corresponding to the processes of one or more application programs into the memory 1302 according to the following instructions, and the processor 1301 will run the application programs stored in the memory 1302 to implement various functions as follows:
[0179] Receive a raw data packet from outside the server; parse the raw data packet to obtain parsed information; encapsulate a look-up table key value based on the parsed information; perform a look-up table operation on the flow table and the routing table based on the look-up table key value to obtain a look-up table result; modify the raw data packet based on the look-up table result to obtain a modified data packet.
[0180] For the specific implementation of each of the above operations, reference can be made to the previous embodiments, which will not be elaborated here.
[0181] As can be seen from the above, in this embodiment, the programmable switching module can receive the original data packet from outside the server; parse the original data packet to obtain the parsed information; encapsulate the lookup table key value based on the parsed information; perform a lookup operation on the flow table and the routing table based on the lookup table key value to obtain the lookup result; and modify the original data packet based on the lookup result to obtain the modified data packet. The technical solution of this application can greatly improve the data processing index and significantly reduce the forwarding delay.
[0182] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions or by controlling related hardware through instructions. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0183] Therefore, an embodiment of this application provides a computer-readable storage medium, which stores multiple instructions that can be loaded by a processor to execute the steps in any of the data processing methods provided by the embodiments of this application. For example, the instructions can perform the following steps:
[0184] Receive the original data packet from outside the server; parse the original data packet to obtain the parsed information; encapsulate the lookup table key value based on the parsed information; perform a lookup operation on the flow table and the routing table based on the lookup table key value to obtain the lookup result; and modify the original data packet based on the lookup result to obtain the modified data packet.
[0185] For the specific implementation of each of the above operations, reference can be made to the previous embodiments and will not be elaborated here.
[0186] Among them, the computer-readable storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.
[0187] Since the instructions stored in the computer-readable storage medium can execute the steps in any of the data processing methods provided by the embodiments of this application, the beneficial effects that can be achieved by any of the data processing methods provided by the embodiments of this application can be realized. For details, reference can be made to the previous embodiments and will not be elaborated here.
[0188] According to one aspect of this application, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in the various optional implementation manners of the above data processing aspect.
[0189] The above has introduced in detail a data processing method and related devices provided by embodiments of the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A data processing method, characterized in that, it includes: Receiving an original data packet from outside the server; Parsing the original data packet to obtain parsed information; Encapsulating a lookup key value based on the parsed information; Performing a lookup operation on the flow table and the routing table based on the lookup key value to obtain a lookup result; Modifying the original data packet based on the lookup result to obtain a modified data packet.
2. The data processing method according to claim 1, characterized in that, before modifying the original data packet based on the lookup result to obtain a modified data packet, it further includes: If it is determined that the lookup result meets a preset condition for sending to the central processing unit, sending the original data packet to the central processing unit so that the central processing unit modifies the original data packet based on the lookup result to obtain a modified data packet; If it is determined that the lookup result does not meet the preset condition for sending to the central processing unit, modifying the original data packet based on the lookup result to obtain a modified data packet.
3. The data processing method according to claim 1, characterized in that, the parsed information includes first parsed information and second parsed information, and parsing the original data packet to obtain parsed information includes: Parsing the protocol header part in the original data packet to obtain the first parsed information; Parsing the communication tunnel of the original data packet to obtain the second parsed information.
4. The data processing method according to claim 1, characterized in that, modifying the original data packet based on the lookup result to obtain a modified data packet includes: Modifying the original data packet based on the session information carried in the lookup result to obtain an initial modified data packet; Encapsulating the initial modified data packet based on the routing information carried in the lookup result to obtain a modified data packet.
5. The data processing method according to claim 2, characterized in that, modifying the original data packet based on the lookup result to obtain a modified data packet includes: Searching for a full - scale flow table based on the original data packet to obtain a full - scale flow table search result; If it is determined that the session information is hit based on the full - scale flow table search result, modifying the original data packet based on the session information to obtain the modified data packet.
6. The data processing method according to claim 5, characterized in that, after searching for a full - scale flow table based on the original data packet to obtain a full - scale flow table search result, it further includes: If it is determined that the session information is not hit based on the full - scale flow table search result, establishing a new session connection; Modifying the original data packet based on the new session connection to obtain a modified data packet.
7. The data processing method according to claim 1, characterized in that, performing a lookup operation on the flow table and the routing table based on the lookup key value to obtain a lookup result includes: Judging whether the original data packet is a fragmented packet based on the information carried in the lookup key value; If it is determined that the original data packet is a non-fragmented packet, perform a table lookup operation on the flow table and the routing table based on the table lookup key value to obtain a table lookup result.
8. The data processing method according to claim 7, wherein, after determining whether the original data packet is a fragmented packet based on the information carried in the table lookup key value, it further includes: if it is determined that the original data packet is a fragmented packet, look up the fragmentation information table based on the table lookup key value; look up the missing information corresponding to the original data packet in the fragmentation information table; perform a table lookup operation on the flow table and the routing table based on the table lookup key value and the missing information to obtain a table lookup result.
9. A data processing device, wherein, it includes: a receiving unit, configured to receive an original data packet from outside the server; a parsing unit, configured to parse the original data packet to obtain parsed information; a packaging unit, configured to package a table lookup key value based on the parsed information; a table lookup unit, configured to perform a table lookup operation on the flow table and the routing table based on the table lookup key value to obtain a table lookup result; a modification unit, configured to modify the original data packet based on the table lookup result to obtain a modified data packet.
10. An electronic device, wherein, it includes a memory and a processor; the memory stores an application program, and the processor is configured to run the application program in the memory to execute the operations in the data processing method according to any one of claims 1 to 8.
11. A computer-readable storage medium, wherein, the computer-readable storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the data processing method according to any one of claims 1 to 8.
12. A computer program product, including a computer program or instruction, wherein, when the computer program or instruction is executed by a processor, it implements the steps in the data processing method according to any one of claims 1 to 8.