Message processing device and method
By introducing software-configured message analysis unit, field extraction unit, keyword organization unit and action data acquisition unit in the message processing device, the problem of lack of flexibility and programmability of message analysis in the prior art is solved, and flexible analysis and forwarding of custom and unknown network protocols is realized, and the flexibility of data flow forwarding is enhanced.
Patent Information
- Application Number
- CN202510223631.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-02-27
AI Technical Summary
In the prior art, message analysis lacks flexibility and programmability, making it difficult to analyze user-defined or unknown network protocols.
It provides a message processing device, including a message analysis unit, a field extraction unit, a keyword organization unit and an action data acquisition unit. Through software configuration, it realizes the analysis of message protocol header information, the extraction of key field domains and the organization of target keywords, and supports the analysis and forwarding of user-defined protocols.
It realizes flexible parsing and forwarding of custom and unknown network protocols, saves stream table cache space, enhances the flexibility of data flow forwarding, and can meet the complex and diverse network message editing and forwarding needs.
Smart Images

Figure CN120091060A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of computer networks, and particularly relates to a packet processing apparatus and method. Background Art
[0002] See Figure 1 As shown, in a network device, the processing flow of a packet can be basically divided into: packet protocol header parsing, table entry matching, and action execution. That is, after a network packet (Ethernet packet) is parsed by a parser, the obtained metadata is matched with a lookup table, and the result of the match hit is then matched with an action table, and finally the action data to be executed on the network packet is obtained. Summary of the Invention
[0003] The purpose of this application is to provide a packet processing apparatus and method, aiming to solve the problem of lack of flexibility and programmability in packet parsing in related technologies.
[0004] According to the first aspect of this application, a packet processing apparatus is provided, including:
[0005] A packet parsing unit, configured to parse protocol header information from a packet to be processed based on first configuration information configured by software;
[0006] A field extraction unit, configured to extract a keyword field domain from the packet to be processed based on second configuration information configured by software and the protocol header information;
[0007] A keyword organization unit, configured to organize a target keyword from the keyword domain based on third configuration information configured by software;
[0008] An action data acquisition unit, configured to acquire action data corresponding to the target keyword based on fourth configuration information pre-written into a flow table cache by software.
[0009] This apparatus is easy to implement, can be compatible with traditional fixed tuple flow table engines, supports flow forwarding behaviors defined by protocols such as open flow and OVS, and at the same time supports the parsing and forwarding of user-defined protocols by parsing the protocol header information of packets through first configuration information configured by software; it adopts a software-configurable parser, and the parsing process is controlled by software configuration, which can meet the parsing requirements for custom and unknown network protocols; it adopts a software-configurable flow table cache, which can save the cache space of the flow table, gives more flexibility to the forwarding of data streams, and can meet the editing and forwarding requirements of complex and diverse network packets.
[0010] In an alternative embodiment, the first configuration information includes protocol identifiers of different protocols, protocol recognition keywords, and a mapping relationship between a message type and a protocol identifier; the message type is divided based on a combination of one or more of the protocol identifiers.
[0011] The message parsing unit matches the protocol recognition keyword with the message to be processed, determines the protocol header offset and the corresponding hit protocol identifier in the message to be processed based on the protocol recognition keyword that hits the match, and determines the message type of the message to be processed according to the hit protocol identifier and the mapping relationship.
[0012] Since the protocol identifier, protocol recognition keyword, and the mapping relationship between the message type and the protocol identifier of the protocol are configured by software, the parsing and forwarding of user-defined protocols are supported.
[0013] In an alternative embodiment, the software is configured with one or more groups of second configuration information including: a configured protocol identifier and a configured offset corresponding to the configured protocol identifier.
[0014] The field extraction unit obtains the second configuration information corresponding to the message type of the message to be processed, matches the hit protocol identifier with the configured protocol identifier in the obtained second configuration information, and extracts the keyword field domain from the message to be processed based on the configured offset corresponding to the configured protocol identifier that hits the match and the protocol header offset.
[0015] Since the extraction information of the corresponding keyword field domain can be configured by software for different protocols, the parsing and forwarding of user-defined protocols can be better supported.
[0016] In an alternative embodiment, the software is configured with one or more groups of third configuration information including: keyword length, keyword index, and keyword mask table.
[0017] The keyword organization unit obtains the third configuration information corresponding to the message type of the message to be processed, extracts candidate keywords of the keyword length from the keyword field domain based on the keyword index in the obtained third configuration information, and obtains the target keyword after masking the candidate keywords with the mask table.
[0018] Since the keyword length and mask can be dynamically configured, the flow table cache only stores the necessary keyword field domain, significantly saving storage space.
[0019] In an alternative embodiment, the fourth configuration information includes a keyword and action data corresponding to the keyword.
[0020] The action data acquisition unit matches the target keyword with the keywords in the fourth configuration information and acquires the action data with a matching hit.
[0021] Since the keyword key and the action data are configured by software, the scalability is good and the software controllability is strong. In an alternative embodiment, the apparatus further includes:
[0022] An action execution unit, configured to execute the action indicated by the action data on the to-be-processed packet.
[0023] Since the action data corresponding to different keyword fields is configured by software, after the configured action data is matched according to the keyword field, the hardware logic can automatically execute the corresponding action.
[0024] According to a second aspect of the present application, there is provided a packet processing method, including:
[0025] Parsing protocol header information from a to-be-processed packet based on first configuration information configured by software;
[0026] Extracting a keyword field domain from the to-be-processed packet based on second configuration information configured by software and the protocol header information;
[0027] Organizing a target keyword from the keyword domain based on third configuration information configured by software;
[0028] Acquiring action data corresponding to the target keyword based on fourth configuration information pre-written into a flow table cache by software.
[0029] In an alternative embodiment, the first configuration information includes protocol identifiers of different protocols, protocol recognition keywords, and a mapping relationship between a packet type and a protocol identifier; the packet type is divided based on a combination of one or more of the protocol identifiers; the parsing of the protocol header information from the to-be-processed packet based on the first configuration information configured by software includes:
[0030] Matching the protocol recognition keyword with the to-be-processed packet;
[0031] Determining a protocol header offset and a corresponding hit protocol identifier in the to-be-processed packet based on the protocol recognition keyword with a matching hit;
[0032] Determining the packet type of the to-be-processed packet according to the hit protocol identifier and the mapping relationship.
[0033] In an alternative embodiment, the software configures one or more groups of second configuration information including the following: a configured protocol identifier and a configured offset corresponding to the configured protocol identifier; the extracting of the keyword field domain from the to-be-processed packet based on the second configuration information configured by software and the protocol header information includes:
[0034] Obtain the second configuration information corresponding to the message type of the message to be processed;
[0035] Match the hit protocol identifier with the configured protocol identifier in the obtained second configuration information;
[0036] Based on the configuration offset corresponding to the configured protocol identifier that is matched and hit and the protocol header offset, extract the keyword field from the message to be processed.
[0037] In an optional implementation manner, the software is configured with one or more groups of third configuration information including the following: keyword length, keyword index, and keyword mask table; based on the third configuration information configured in the software, organizing the target keyword from the keyword field includes:
[0038] Obtain the third configuration information corresponding to the message type of the message to be processed;
[0039] Extract candidate keywords of the keyword length from the keyword field based on the keyword index in the obtained third configuration information;
[0040] After masking the candidate keywords by using the mask table, obtain the target keyword.
[0041] In an optional implementation manner, the fourth configuration information includes keywords and action data corresponding to the keywords; based on the fourth configuration information pre-written into the flow table cache by the software, obtaining the action data corresponding to the target keyword includes:
[0042] Match the target keyword with the keywords in the fourth configuration information, and obtain the action data that is matched and hit.
[0043] In an optional implementation manner, the method further includes:
[0044] Execute the action indicated by the action data on the message to be processed.
[0045] Other features and advantages of the present application will be described in the subsequent description, and will be partially obvious from the description, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures and processes pointed out in the description and the drawings. Description of the Drawings
[0046] To more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are certain embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0047] Figure 1 It is a schematic diagram of the message processing flow according to related technologies.
[0048] Figure 2 It is a schematic diagram of the structure of the message processing device according to an exemplary embodiment of the present application.
[0049] Figure 3 It is a schematic diagram of the processing flow of the message parsing unit according to an exemplary embodiment of the present application.
[0050] Figure 4 It is a schematic diagram of the processing flow of the field extraction unit according to an exemplary embodiment of the present application.
[0051] Figure 5 It is a schematic diagram of the processing flow of the keyword organization unit according to an exemplary embodiment of the present application.
[0052] Figure 6 It is a schematic diagram of the processing flow of the action data acquisition unit according to an exemplary embodiment of the present application.
[0053] Figure 7 It is a schematic diagram of the flow table structure according to an exemplary embodiment of the present application.
[0054] Figure 8 It is a schematic diagram of the flow of the message processing method according to an exemplary embodiment of the present application. Detailed implementation manners
[0055] In order to make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0056] With the development of network protocols or technologies such as OpenFlow, virtualization, and Overlay (overlay network, such as VXLAN), the number of entries to be processed may be extremely large. The matching forms can be diverse (exact matching, fuzzy matching, etc.), and the matching fields can also be any fields of the L2-L4 layer protocol headers inside and outside the tunnel or any metadata data (meta-data). The actions to be executed can also be in various forms. Therefore, in order to meet or balance different application requirements, it is necessary to propose a flow table engine that can be flexibly programmed to process packets.
[0057] The design of the flow table engine in the prior art has at least the following problems:
[0058] 1. The parsing of packets lacks flexibility and / or programmability and cannot parse user-defined or unknown protocols.
[0059] 2. The lookup table usually only includes fixed fields of the packets to be processed, lacks programmability, cannot extract any fields of the packets, and cannot customize the matching rules.
[0060] 3. The action table only includes a limited number of action data, lacks flexibility and programmability, and is difficult to meet the packet editing and forwarding requirements of diverse services.
[0061] See Figure 2 As shown, the present application exemplarily provides a packet processing device, including:
[0062] A packet parsing unit 201, configured to parse protocol header information from a packet to be processed based on first configuration information configured by software;
[0063] A field extraction unit 202, configured to extract a keyword field from a packet to be processed based on second configuration information configured by software and the protocol header information;
[0064] A keyword organization unit 203, configured to organize a target keyword from the keyword field based on third configuration information configured by software;
[0065] An action data acquisition unit 204, configured to acquire action data corresponding to the target keyword based on fourth configuration information pre-written into a flow table cache by software.
[0066] Exemplarily, each unit included in the packet processing device is implemented by a hardware logic unit, and these hardware logic units can acquire the first configuration information - fourth configuration information pre-configured by the user through software. Among them, the first configuration information - fourth configuration information can be configured in the form of a template, and the user can configure it based on the processing requirements for the packet to be processed.
[0067] Exemplarily, after receiving the message to be processed, the message parsing unit obtains the first configuration information and parses the protocol header information from the message to be processed based on the first configuration information. It can be understood that the message to be processed may include protocol header information of one or more protocols, and the protocols may include, but are not limited to, mac, vlan, IPv4, IPv6, GRE, TCP, UDP, SCTP, VXLAN, etc. In order to identify the protocol header information carried in the message to be processed, the user can configure the protocol recognition keywords of different protocols to be recognized in the first configuration information through software.
[0068] In some embodiments, the protocol header information is the information related to the protocol parsed from the message to be processed, and may include, but is not limited to, the protocol header offset, the hit protocol identifier, and the message type in the message to be processed. The protocol header offset is the offset position where the matched protocol recognition keyword appears in the message to be processed, the hit protocol identifier is the protocol identifier corresponding to the protocol identifier keyword matched in the message to be processed, both the protocol identifier keyword and the corresponding protocol identifier are configured by software in the first configuration information, and the message type is determined by the protocol identifier corresponding to the protocol identifier keyword matched in the message to be processed. One or more protocol identifier keywords can be matched in the message to be processed, and the message type of the message to be processed can be determined through the combination of the one or more protocol identifier keywords. Among them, the combination of one or more protocol identifier keywords corresponding to each message type is also configured in the first configuration information.
[0069] Exemplarily, the field extraction unit extracts relevant keyword fields from the message to be processed based on the protocol header information parsed by the message parsing unit from the message to be processed and the second configuration information pre-configured by the user through software. It can be understood that the message parsing unit can parse the protocol header information corresponding to multiple protocols from the message to be processed, and each protocol header may include multiple keyword field segments, while the user may actually only need to extract a part of the keyword field segments in the protocol headers of some of the protocols. Therefore, the user can configure the protocol identifier of the protocol to be extracted from the message to be processed, as well as the configuration offset of the keyword field segments to be extracted in the protocol header, etc. in the second configuration information through software.
[0070] Exemplarily, the keyword field segment extracted by the field extraction unit from the message to be processed may include multiple keywords, and the keywords actually required by the user may be a part of them. Therefore, the keyword organization unit can match and organize the final target keyword from the keyword field segment based on the third configuration information pre-configured by the user through software. Among them, the third configuration information may include the keyword length, keyword index, and keyword mask table for identifying the target keyword in the keyword field segment, etc. The keyword length is used to control the total length of the organized keyword, the keyword index is used to match the keyword required by the user from the keyword field segment, and the keyword mask table is used to further extract the target keyword from the candidate keywords matched by the keyword index. For example, if the keyword field segment includes the destination address and source address of the MAC protocol, and the destination address is matched through the keyword index, and if the user actually needs some bits of the destination address, the keyword mask table can be used to match and obtain the required bits from the destination address.
[0071] Exemplarily, the user can pre-write the fourth configuration information into the flow table cache through software. The fourth configuration information may include keywords and the action data corresponding to the keywords. The action data may be the action to be performed on the message to be processed after matching the corresponding keyword. For example, write the virtual machine ID that the message to be processed is going to into the message to be processed.
[0072] The device is easy to implement, can be compatible with the traditional fixed tuple flow table engine, supports the flow forwarding behaviors defined by protocols such as open flow and OVS, and at the same time supports the parsing and forwarding of user-defined protocols by parsing the protocol header information of the message through the first configuration information configured by software; it adopts a software-configurable parser, and the parsing process is controlled by software configuration, which can meet the parsing requirements for custom and unknown network protocols; it adopts a software-configurable flow table cache, which can save the cache space of the flow table, gives more flexibility to the forwarding of data streams, and can meet the editing and forwarding requirements of complex and diverse network messages.
[0073] In some optional embodiments, the first configuration information includes the protocol identifiers of different protocols, protocol recognition keywords, and the mapping relationship between the message type and the protocol identifier; the message type is divided based on a combination of one or more protocol identifiers;
[0074] The message parsing unit matches the protocol recognition keyword with the message to be processed, determines the protocol header offset and the corresponding hit protocol identifier in the message to be processed based on the protocol recognition keyword that hits the match, and determines the message type of the message to be processed according to the hit protocol identifier and the mapping relationship.
[0075] Exemplarily, the user can configure the protocol identifiers (prot id) of protocols such as MAC, VLAN, IPv4, IPv6, GRE, TCP, UDP, SCTP, VXLAN, etc. through software, set the protocol recognition keywords for each protocol, and at the same time configure the message type pty. The message type divides the message types according to the combination of prot id.
[0076] By configuring the protocol identifier, protocol recognition keyword, and the mapping relationship between the message type and the protocol identifier through software, it supports the user to customize the parsing and forwarding of protocols.
[0077] See Figure 3 As shown, exemplarily, the message parsing unit parser performs a sliding window match on the packet to be processed to identify the protocol recognition keyword therein. If the protocol recognition keyword is matched, the corresponding protocol header offset (prot off), the protocol identifier prot id corresponding to the protocol recognition keyword, and the message type pty are obtained. If multiple protocol recognition keywords are matched in the packet to be processed, there are also multiple prot id and prot off.
[0078] In some alternative implementation manners, the software is configured with one or more groups of second configuration information including the following: configuring the protocol identifier and the corresponding configuration offset of the configured protocol identifier;
[0079] The field extraction unit obtains the second configuration information corresponding to the message type of the packet to be processed, matches the hit protocol identifier with the configured protocol identifier in the obtained second configuration information, and extracts the keyword field domain from the packet to be processed based on the configuration offset and keyword offset corresponding to the configured protocol identifier that is matched and hit.
[0080] Exemplarily, the user configures the second configuration information through software. Each message type can be configured with a corresponding group of second configuration information (for example, it can be configured in the message type table pty table). The second configuration information configures the configured protocol identifier (cfg id) to be extracted and the configuration offset (cfg off) within the protocol header (for example, cfg id and cfg off can be configured in the cfg id+cfgoff table). See Figure 4As shown, exemplarily, the field extraction unit determines the template identifier (pattern id) of the second configuration information to be used currently through the message type pty of the message to be processed, and then obtains the cfg id and cfg off in the second configuration information corresponding to the template identifier. The field extraction unit matches the protocol identifier prot id in the protocol header information recognized by the message parsing unit with the cfg id in the second configuration information. If the match is successful, the protocol header offset prot off in the protocol header information is added with the configuration offset cfg off to obtain the keyword offset offset for extracting the keyword field segment, and the corresponding keyword field segment key field is extracted from the message to be processed with this keyword offset offset.
[0081] Since the extraction information of the corresponding keyword field segments can be software-configured for different protocols, it can better support the parsing and forwarding of user-defined protocols.
[0082] In some optional implementation manners, the software is configured with one or more groups of third configuration information including the following: keyword length, keyword index, and keyword mask table;
[0083] The keyword organization unit obtains the third configuration information corresponding to the message type of the message to be processed, and extracts candidate keywords of the keyword length from the keyword field segment based on the keyword index in the obtained third configuration information, and obtains the target keyword after masking the candidate keywords with the mask table.
[0084] Exemplarily, the user configures the third configuration information through software, and a group of corresponding third configuration information is configured for each message type. The keyword length key length (for example, it can be configured in the Key 1engthtable), the keyword index key index of the group key (for example, it can be configured in the Key index table), and the mask index (for example, it can be configured in the mask index table) can be configured in the third configuration information. See Figure 5As shown, exemplarily, the keyword organization unit determines the template identifier (pattern id) of the third configuration information to be used currently through the message type pty of the message to be processed. This template identifier can be the same as the template identifier of the second configuration information to be used currently determined by the field extraction unit. That is, each message type can use the same template identifier. Thus, the key length, key index, and maskindex in the third configuration information to be used currently can be directly obtained using the template identifier determined by the field extraction unit. After extracting the key field corresponding to the key index from the message to be processed, key reordering (i.e., sorting the extracted key fields according to the key index) can be performed, and the reordered key fields are masked with the maskindex to obtain the final target keyword key.
[0085] In the above embodiment, the key length and mask are configurable. Considering that the metadata to be extracted for widely different services varies greatly and the key length naturally has significant differences, it can meet the requirements of flow lookup and forwarding for different services. Additionally, since the keyword length and mask can be dynamically configured, the flow table cache only stores the necessary keyword field domains, significantly saving storage space.
[0086] In some alternative embodiments, the fourth configuration information includes keywords and the action data corresponding to the keywords;
[0087] The action data acquisition unit matches the target keyword with the keywords in the fourth configuration information and acquires the action data that hits the match.
[0088] Exemplarily, when the software generates the flow table, the user can fill the keyword key and the action data (AD data) into the flow table cache through the software. Since the keyword key and the action data are configured by the software, it has good scalability and strong software controllability.
[0089] See Figure 6 As shown, exemplarily, the action data acquisition unit then uses the double hash algorithm to precisely match the target keyword obtained by the keyword organization unit with the keyword key in the flow table cache, thereby obtaining the action data corresponding to the target keyword. This action data can control the action execution unit to perform corresponding actions on the message to be processed.
[0090] In some alternative embodiments, the device further includes:
[0091] An action execution unit, configured to perform the actions indicated by the action data on the message to be processed.
[0092] Exemplarily, if the above keyword organizing unit can hit the target keyword, the action data acquisition unit can acquire the corresponding action data (AD data), and the action execution unit can perform corresponding message processing behaviors according to the action data.
[0093] Since the software configures the action data corresponding to different key fields, after the configured action data is matched according to the key fields, the hardware logic can automatically execute the corresponding actions.
[0094] Due to the diversity of services, the processing behaviors of the messages to be processed are also very different. The AD data may include: packet loss, adding or stripping tunnel headers, calculating or verifying IP, TCP, UDP checksums, etc., adding or stripping L2 Tags (L2 labels) such as VLANs, TCP message aggregation (TSO), specifying the virtual machine id to which the message goes, specifying the queue id to the virtual machine, etc.
[0095] A feasible flow table structure is shown in Figure 7 Exemplarily, the software can define a tab id (entry identifier) for the supported actions, define different processing actions with the tab id, or define a combination of different actions as one tab id.
[0096] Since the hardware logic unit in this application does not perceive the specific key and AD data, and the content and length of the key and AD data are also defined by the software, it gives more flexibility to the processing of the flow engine.
[0097] Correspondingly, as shown in Figure 8 This application also exemplarily provides a message processing method, including:
[0098] Step 801: Parse protocol header information from the message to be processed based on the first configuration information configured by the software;
[0099] Step 802: Extract a keyword field domain from the message to be processed based on the second configuration information configured by the software and the protocol header information;
[0100] Step 803: Organize the target keyword from the keyword domain segment based on the third configuration information configured by the software;
[0101] Step 804: Acquire the action data corresponding to the target keyword based on the fourth configuration information pre-written into the flow table cache by the software.
[0102] In some optional embodiments, the first configuration information includes protocol identifiers of different protocols, protocol recognition keywords, and the mapping relationship between the message type and the protocol identifier; the message type is divided based on a combination of one or more protocol identifiers; parsing the protocol header information from the message to be processed based on the first configuration information configured by the software includes:
[0103] Match the protocol identification keywords with the message to be processed;
[0104] Based on the protocol identification keywords that match and hit, determine the protocol header offset and the corresponding hit protocol identifier in the message to be processed;
[0105] Determine the message type of the message to be processed according to the hit protocol identifier and the mapping relationship.
[0106] In some alternative embodiments, the software is configured with one or more groups of second configuration information including the following: configuration protocol identifier and the configuration offset corresponding to the configuration protocol identifier; based on the second configuration information configured in the software and the protocol header information, extract a keyword field domain from the message to be processed, including:
[0107] Obtain the second configuration information corresponding to the message type of the message to be processed;
[0108] Match the hit protocol identifier with the configuration protocol identifier in the obtained second configuration information;
[0109] Based on the configuration offset corresponding to the configuration protocol identifier that matches and hits and the protocol header offset, extract a keyword field domain from the message to be processed.
[0110] In some alternative embodiments, the software is configured with one or more groups of third configuration information including the following: keyword length, keyword index, and keyword mask table; the method of organizing the keyword field domain based on the third configuration information configured in the software to obtain a target keyword includes:
[0111] Obtain the third configuration information corresponding to the message type of the message to be processed;
[0112] Extract candidate keywords with the keyword length from the keyword field domain based on the keyword index in the obtained third configuration information;
[0113] Perform mask processing on the candidate keywords using the mask table to obtain the target keyword.
[0114] In some alternative embodiments, the fourth configuration information includes keywords and the action data corresponding to the keywords; the method of obtaining the action data corresponding to the target keyword based on the fourth configuration information pre-written in the flow table cache by the software includes:
[0115] Match the target keyword with the keywords in the fourth configuration information, and obtain the action data that matches and hits.
[0116] In some alternative embodiments, the method further includes:
[0117] Execute the action indicated by the action data for the message to be processed.
[0118] The above method can be implemented by the message processing device provided in the above embodiments. For the specific implementation method, reference can be made to the description of the message processing device in the above embodiments, which will not be elaborated here.
[0119] It can be understood that the circuit structures, names, and parameters described in the above embodiments are only examples. Those skilled in the art can also easily combine and adjust the structural features of the above multiple embodiments according to actual needs, and should not limit the concept of this application to the specific details of the above examples.
[0120] Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A message processing device, characterized in that: include: A message parsing unit, configured to parse protocol header information from a message to be processed based on first configuration information configured by the software; A field extraction unit, configured to extract a key field domain from the message to be processed based on the second configuration information configured by the software and the protocol header information; A keyword organizing unit, configured to organize and obtain a target keyword from the keyword domain segment based on the third configuration information of the software configuration; The action data acquisition unit is used to acquire the action data corresponding to the target keyword based on the fourth configuration information pre-written into the flow table cache by software.
2. The message processing device according to claim 1, characterized in that: The first configuration information includes protocol identifiers of different protocols, protocol identification keywords, and mapping relationships between message types and protocol identifiers; the message types are divided based on one or more combinations of the protocol identifiers; The message parsing unit matches the protocol identification keyword with the message to be processed, and determines the protocol header offset and the corresponding hit protocol identifier in the message to be processed based on the matched protocol identification keyword, and determines the message type of the message to be processed according to the hit protocol identifier and the mapping relationship.
3. The message processing device according to claim 2, characterized in that: The software is configured with one or more sets of second configuration information including the following contents: a configuration protocol identifier and a configuration offset corresponding to the configuration protocol identifier; The field extraction unit obtains the second configuration information corresponding to the message type of the message to be processed, matches the hit protocol identifier with the configuration protocol identifier in the obtained second configuration information, and extracts the key field domain from the message to be processed based on the configuration offset corresponding to the matching configuration protocol identifier and the protocol header offset.
4. The message processing device according to claim 1, characterized in that: The software is configured with one or more sets of third configuration information including the following: keyword length, keyword index, and keyword mask table; The keyword organization unit obtains the third configuration information corresponding to the message type of the message to be processed, and extracts candidate keywords of keyword length from the key field domain based on the keyword index in the obtained third configuration information, and obtains the target keyword after masking the candidate keywords using the mask table.
5. The message processing device according to claim 1, characterized in that: The fourth configuration information includes a keyword and action data corresponding to the keyword; The action data acquisition unit matches the target keyword with the keyword in the fourth configuration information, and acquires the action data of the matching hit.
6. The message processing device according to any one of claims 1 to 5, characterized in that: The device also includes: An action execution unit is used to execute the action indicated by the action data on the message to be processed.
7. A message processing method, characterized in that: include: Parsing protocol header information from the message to be processed based on first configuration information configured by the software; Extracting a key field domain from the message to be processed based on the second configuration information of the software configuration and the protocol header information; Based on the third configuration information of the software configuration, a target keyword is obtained from the keyword domain segment organization; Based on the fourth configuration information pre-written into the flow table cache by software, the action data corresponding to the target keyword is obtained.
8. The message processing method according to claim 7, characterized in that: The first configuration information includes protocol identifiers of different protocols, protocol identification keywords, and mapping relationships between message types and protocol identifiers; the message types are divided based on one or more combinations of the protocol identifiers; The first configuration information based on software configuration parses protocol header information from the message to be processed, including: Matching the protocol identification keyword with the message to be processed; Determine the protocol header offset and the corresponding hit protocol identifier in the message to be processed based on the matched protocol identification keyword; The message type of the message to be processed is determined according to the hit protocol identifier and the mapping relationship.
9. The message processing method according to claim 8, characterized in that: The software is configured with one or more sets of second configuration information including the following contents: a configuration protocol identifier and a configuration offset corresponding to the configuration protocol identifier; The second configuration information based on the software configuration and the protocol header information, extracting a key field domain from the message to be processed, comprises: Obtaining the second configuration information corresponding to the message type of the message to be processed; Matching the hit protocol identifier with the configuration protocol identifier in the acquired second configuration information; Based on the configuration offset corresponding to the configuration protocol identifier that matches and the protocol header offset, the key field domain is extracted from the message to be processed.
10. The message processing method according to claim 7, characterized in that: The software is configured with one or more sets of third configuration information including the following: keyword length, keyword index, and keyword mask table; The third configuration information based on software configuration obtains the target keyword from the keyword domain segment, including: Obtain the third configuration information corresponding to the message type of the message to be processed; Extracting candidate keywords of keyword length from the key field domain based on the keyword index in the acquired third configuration information; The target keyword is obtained by performing mask processing on the candidate keyword using the mask table.
11. The message processing method according to claim 7, characterized in that: The fourth configuration information includes a keyword and action data corresponding to the keyword; the fourth configuration information pre-written into the flow table cache based on software, obtaining the action data corresponding to the target keyword, includes: The target keyword is matched with the keyword in the fourth configuration information, and the action data of the matching hit is obtained.
12. The message processing method according to any one of claims 7 to 11, characterized in that: The method further comprises: Execute the action indicated by the action data on the message to be processed.
Citation Information
Patent Citations
Access control method and apparatus
CN101409677A
System for flexible and extensible flow processing in software-defined networks
CN103999431A
Controller for flexible and extensible flow processing in software-defined networks
CN104012063A
System and method for customizing forwarding protocol security network on basis of software configuration
CN109688148A
Message processing method, programmable network card device, physical server and storage medium
CN115766620A
Cited By
Packet processing apparatus and method
WO2026179746A1