Topology virtual mapping method and device for cross-domain access control, equipment and medium
By remapping the configuration space of the target switching chip in the PCIe protocol and mapping the endpoint devices to a virtual topology with fixed series, the problem of hardware difficulty in solidifying and judgment caused by dynamic changes in the PCIe protocol is solved, and more efficient message transmission and system performance are achieved.
Patent Information
- Application Number
- CN202510449573.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-10
AI Technical Summary
The PCIe protocol does not limit the number of stages of cascade switches, which may cause a large number of stage-by-step mapping and judgment in applications, which cannot limit user behavior, and when the stages are dynamic values, the hardware is difficult to solidify judgment, affecting message delay and system performance.
By remapping the configuration space of the target device of the target switching chip based on the topological results of each host domain, the device configuration information corresponding to each host domain is generated, and it is used to generate the access control service configuration table. For each host domain, endpoint devices are mapped to the lowest layer of virtual topology with fixed series according to depth priority rules, generating independent topology for each host domain. Based on the access control service configuration table and independent topology structure, the routing transmission path of the target message is determined.
Through the judgment of cured series, the hardware can be designed according to a fixed virtual topology structure, avoiding the consideration of dynamic changes in series, and solving the problem that hardware is difficult to solidify and judge. At the same time, it reduces the delay during message transmission and improves system performance.
Smart Images

Figure CN120128484A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly relates to a topological virtual mapping method, device, equipment and medium for cross-domain access control. Background Art
[0002] In a switch chip, a management CPU (Central Processing Unit) is responsible for chip initialization, device enumeration, and address allocation. After the chip is powered on, the management CPU enumerates and allocates addresses for devices connected to downstream ports (DSP, Downstream Port). When a host initiates enumeration and address allocation by configuring read / write messages, these messages are routed to the management CPU. The management CPU feeds back the topology structure required by the host to the host. After enumeration is completed, the mapping relationship between the host domain address and the management CPU domain address is configured to an address conversion module to achieve address isolation, as Figure 1 shown.
[0003] In the PCIe (Peripheral Component Interconnect Express) protocol, an endpoint device (EP) can include multiple functions. For example, device 1 has function 0 and function 1, as Figure 2 shown. Under a multi-domain multi-function shared port (Function Pooling port), the specific method for implementing function centralized redirection of PCIe cross-domain multi-host multi-function cascaded EP device access control services (ACS, Access Control Services) is as follows: Set the ACS configuration of all downstream ports (DSP, Downstream Port) under the multi-domain multi-function shared port to "upward redirection"; Route ACS configuration messages related to the multi-domain multi-function shared port to CPU management; The CPU stores relevant configuration information through an ACS configuration table; Messages sent from the multi-domain multi-function shared port are judged level by level according to the ACS configuration table configured by the management CPU; According to the theoretical cascaded level from the device to the multi-domain multi-function shared port, compare the ACS configuration level by level to determine the routing direction of the message; According to the final ACS result, send a message from the multi-domain multi-function shared port and send the redirection result to the destination device.
[0004] However, since the PCIe protocol does not limit the number of cascaded switches (Switch), in applications, there may be a situation where the number of levels of hierarchical mapping judgment is large, and user behavior cannot be restricted. At the same time, if the number of levels is a dynamic value, it is difficult for hardware to solidify the judgment, and a large number of levels will also affect message delay and system performance. Summary of the Invention
[0005] In view of this, the object of the present invention is to provide a topological virtual mapping method, device, equipment and medium for cross-domain access control, which can solve the problem that it is difficult to solidify the judgment of hardware and improve the system performance. The specific scheme is as follows:
[0006] In the first aspect, the present application discloses a topological virtual mapping method for cross-domain access control, including:
[0007] Remap the configuration space of the target device of the target switching chip according to the topological result of each host domain to generate device configuration information corresponding to each host domain; wherein, the target device includes the downstream bridge device inside the target switching chip and the connected endpoint devices;
[0008] Generate an access control service configuration table based on the device configuration information, and store the access control service configuration table in the multi-functional shared port inside the target switching chip;
[0009] For each host domain, map the endpoint devices to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule to generate an independent topology structure for each host domain;
[0010] Determine the routing transmission path of the target packet based on the access control service configuration table and the independent topology structure; wherein, the target packet comes from the multi-functional shared port.
[0011] Optionally, generating an access control service configuration table based on the device configuration information includes:
[0012] Extract the access control service configuration information of the downstream bridge device based on the device configuration information;
[0013] Set the access control service configuration item of the downstream port connected to the multi-functional shared port to upstream remapping, and generate an access control service configuration table according to the access control service configuration information.
[0014] Optionally, after mapping the endpoint devices to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule for each host domain, it further includes:
[0015] Traverse all endpoint devices, and for the endpoint devices whose all functions belong to the same host domain, set the status of the endpoint devices to the offline status in other host domains.
[0016] Optionally, mapping the endpoint devices to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule to generate an independent topology structure for each host domain includes:
[0017] Virtualize the multi-functional shared port into a cascaded structure of multi-level switching devices, and determine the cascaded structure of multi-level switching devices as a virtual topology structure with a fixed number of levels;
[0018] In the virtual topology structure with a fixed number of levels, limit the number of endpoint devices mapped to the bottom layer of the virtual topology structure with a fixed number of levels according to the protocol requirements of the high-speed serial computer extension bus standard; wherein, the protocol requirements include address space addressing characteristic requirements, system resource allocation characteristic requirements, link load capacity limit requirements, and protocol compatibility specification requirements. The address space addressing characteristic requirements ensure the continuity and uniqueness of the address space of the endpoint devices. The system resource allocation characteristic requirements ensure the rationality of the bandwidth allocation of each host domain. The link load capacity limit requirements ensure that the transmission rate and transmission bandwidth of the link meet the target requirements. The protocol compatibility specification requirements ensure the compatibility of endpoint devices from different manufacturers;
[0019] Map the corresponding number of endpoint devices to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule to generate an independent topology structure for each host domain.
[0020] Optionally, after generating the access control service configuration table based on the device configuration information, it further includes:
[0021] Process the target packet from the multi-functional shared port according to the target processing method; the target processing method includes uplink redirection processing, violation processing, and point-to-point transmission processing.
[0022] Optionally, processing the target packet from the multi-functional shared port according to the target processing method includes:
[0023] If the target packet needs to interact with the host domain, direct the target packet to the direction of the host domain;
[0024] If the target packet does not conform to the preset access control rule, intercept the target packet;
[0025] If the receiving device of the target packet is the specified endpoint device and there is no need to pass through routing and transit, directly transmit the target packet to the specified endpoint device.
[0026] Optionally, after directly transmitting the target packet to the specified endpoint device, it further includes:
[0027] Judge whether the transmission result of the target packet is within the preset routing range according to the packet type of the target packet. If so, determine that the transmission path of the target packet is valid.
[0028] In a second aspect, the present application discloses a topological virtual mapping device for cross-domain access control, including:
[0029] A configuration information generation module, configured to remap the configuration space of a target device of a target switching chip according to the topology result of each host domain, so as to generate device configuration information corresponding to each host domain; wherein, the target device includes a downstream bridge device inside the target switching chip and the connected endpoint devices;
[0030] A configuration table generation module, configured to generate an access control service configuration table based on the device configuration information, and store the access control service configuration table into a multifunctional shared port inside the target switching chip;
[0031] A device mapping module, configured to, for each host domain, map the endpoint devices to the bottom layer of a virtual topology structure with a fixed number of levels according to the depth-first rule, so as to generate an independent topology structure for each host domain;
[0032] A message path determination module, configured to determine the routing transmission path of a target message based on the access control service configuration table and the independent topology structure; wherein, the target message originates from the multifunctional shared port.
[0033] In a third aspect, the present application discloses an electronic device, including:
[0034] A memory, configured to store a computer program;
[0035] A processor, configured to execute the computer program to implement the foregoing disclosed topology virtual mapping method for cross-domain access control.
[0036] In a fourth aspect, the present application discloses a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the foregoing disclosed topology virtual mapping method for cross-domain access control is implemented.
[0037] It can be seen that the present application proposes a topological virtual mapping method for cross-domain access control, including: remapping the configuration space of the target device of the target switching chip according to the topological results of each host domain to generate device configuration information corresponding to each host domain; the target device includes a downstream bridge device inside the target switching chip and the connected endpoint devices; generating an access control service configuration table based on the device configuration information, and storing the access control service configuration table in the multi-functional shared port inside the target switching chip; for each host domain, mapping the endpoint devices to the bottom layer of a virtual topological structure with a fixed number of levels according to the depth-first rule to generate an independent topological structure for each host domain; determining the routing transmission path of the target message based on the access control service configuration table and the independent topological structure; the target message originates from the multi-functional shared port. It can be seen that for each host domain, the present application maps the endpoint devices to the bottom layer of a virtual topological structure with a fixed number of levels to generate an independent topological structure for each host domain. In this way, by mapping the endpoint devices to a virtual topological structure with a fixed number of levels, the hardware that was originally difficult to solidify and judge due to the dynamically changing number of levels can now be judged based on the fixed number of levels. Furthermore, the hardware can be specifically designed based on this fixed virtual topological structure without considering the dynamically changing number of levels, thus solving the problem that the hardware is difficult to solidify and judge. At the same time, the present application remaps the configuration space of the target device to generate device configuration information, and then obtains the access control service configuration table, and determines the routing transmission path in combination with the independent topological structure. In this way, when a message is transmitted, there is no need to perform a large number of complex step-by-step mapping judgments, and the routing can be quickly and accurately determined based on the configuration table and the topological structure, greatly reducing the delay during the message transmission process and improving the system performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0039] Figure 1 It is a schematic diagram of the device management and address isolation process of a switch chip device;
[0040] Figure 2 It is a schematic diagram of the multi-functional distribution of PCIe endpoint devices;
[0041] Figure 3 It is a flowchart of a topological virtual mapping method for cross-domain access control disclosed in the present application;
[0042] Figure 4A cross - domain access fixed - level virtual topology architecture diagram disclosed in this application;
[0043] Figure 5 A topology and signal transmission hierarchy diagram on the host domain side disclosed in this application;
[0044] Figure 6 An example diagram of packet transmission routing judgment disclosed in this application;
[0045] Figure 7 A schematic structural diagram of a topology virtual mapping device for cross - domain access control disclosed in this application;
[0046] Figure 8 A structural diagram of an electronic device disclosed in this application. Detailed implementation manners
[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0048] Since the PCIe protocol does not limit the number of levels of cascaded switches, in applications, there may be a situation where the number of levels of hierarchical mapping judgment is large, and user behavior cannot be restricted. At the same time, if the number of levels is a dynamic value, it is difficult for the hardware to solidify the judgment, and a large number of levels will also affect packet delay and system performance.
[0049] Therefore, the embodiments of this application propose a topology virtual mapping scheme for cross - domain access control, which can solve the problem that it is difficult for the hardware to solidify the judgment and improve system performance.
[0050] The embodiments of this application disclose a topology virtual mapping method for cross - domain access control. Refer to Figure 1 As shown, this method includes:
[0051] Step S11: According to the topology results of each host domain, remap the configuration space of the target device of the target switching chip to generate device configuration information corresponding to each host domain; where the target device includes the downstream bridge device inside the target switching chip and the connected endpoint devices.
[0052] In this embodiment, according to the topology results of each host domain, the configuration space of the target device of the target switching chip is remapped to generate device configuration information corresponding to each host domain; wherein, the target device includes the downstream bridge device inside the target switching chip and the connected endpoint devices. It should be noted that the target interaction chip is a dedicated interaction chip, and the downstream bridge device inside it and the connected endpoint devices are both managed by the CPU inside the chip, that is, the configuration space of the downstream bridge device inside the dedicated switching chip and the connected endpoint devices is remapped by the CPU according to the topology results of the host. In this way, by remapping the configuration space of the target device in the target switching chip according to the host domain topology results to generate device configuration information, the target switching chip can better adapt to the requirements of different host domains. This remapping is managed by the CPU inside the chip based on the host topology, ensuring that the data transmission path between the downstream bridge device and the endpoint device and the host is more reasonable, and improving the efficiency and accuracy of data transmission.
[0053] Step S12: Generate an access control service configuration table based on the device configuration information, and store the access control service configuration table in the multi-functional shared port inside the target switching chip.
[0054] In this embodiment, based on the device configuration information, the access control service configuration information of the downstream bridge device is extracted, and the access control service configuration item of the downstream port connected to the multi-functional shared port is set to upstream remapping. Then, an access control service configuration table is generated according to the access control service configuration information, and further, the access control service configuration table is stored in the multi-functional shared port inside the target switching chip. In this way, by processing the device configuration information to generate the access control service configuration table and storing it in the multi-functional shared port of the target switching chip, the port access control is standardized and a clear basis for data transmission is provided.
[0055] Further, after generating the access control service configuration table based on the device configuration information, this embodiment further includes: processing the target packet sourced from the Function Pooling port according to the target processing method, where the target processing method includes uplink redirection processing, violation processing, and point-to-point transmission processing. Specifically, if the target packet needs to interact with the host domain, the target packet is directed to the direction of the host domain to implement uplink redirection processing; if the target packet does not conform to the preset access control rules, the target packet is intercepted to implement violation processing; if the receiving device of the target packet is the specified endpoint device and there is no need for routing transit, the target packet is directly transmitted to the specified endpoint device to implement point-to-point transmission processing. In this way, the uplink redirection processing can quickly and accurately direct the target packet that needs to interact with the host domain to the host domain direction, avoid the blind transmission of packets in the network, reduce the transmission delay, and improve the data transmission efficiency; the violation processing intercepts the target packet that does not conform to the preset access control rules to prevent illegal access and malicious data from invading the system; the point-to-point transmission processing directly transmits the target packet with a clear receiving device and no need for routing transit to the specified endpoint device, reducing the overhead of the packet in the routing process and avoiding unnecessary routing path selection.
[0056] After directly transmitting the target packet to the specified endpoint device, it further includes: judging whether the transmission result of the target packet is within the preset routing range according to the packet type of the target packet. If so, it is determined that the transmission path of the target packet is valid. It can be understood that by verifying whether the transmission result is within the preset routing range, it can ensure that the data is accurately delivered to the expected endpoint device and guarantee the accuracy of data transmission.
[0057] Step S13: For each host domain, map the endpoint devices to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule to generate an independent topology structure for each host domain.
[0058] In this embodiment, the multi-functional shared port is virtualized into a cascaded structure of multi-level switching devices, and the cascaded structure of multi-level switching devices is determined as a virtual topology structure with a fixed number of levels. Then, in the virtual topology structure with a fixed number of levels, the number of endpoint devices mapped to the bottom layer of the virtual topology structure with a fixed number of levels is restricted according to the protocol requirements of the high-speed serial computer extension bus standard; wherein, the protocol requirements include address space addressing characteristic requirements, system resource allocation characteristic requirements, link load capacity limitation requirements, and protocol compatibility specification requirements. The address space addressing characteristic requirements ensure the continuity and uniqueness of the address space of the endpoint devices. The system resource allocation characteristic requirements ensure the rationality of the bandwidth allocation for each host domain. The link load capacity limitation requirements ensure that the transmission rate and transmission bandwidth of the link meet the target requirements. The protocol compatibility specification requirements ensure that endpoint devices from different manufacturers can be compatible. Finally, the corresponding number of endpoint devices is mapped to the bottom layer of the virtual topology structure with a fixed number of levels according to the depth-first rule to generate an independent topology structure for each host domain.
[0059] Suppose in a server cluster scenario of a data center, multiple servers are connected to a target switch chip via the PCIe bus, and various expansion cards (such as network cards, graphics cards, etc.) in the servers act as endpoint devices. First, according to the addressing characteristics requirements of the address space, each network card and graphics card is assigned a continuous and unique address space. For example, the address space of network card A ranges from 0x1000 to 0x1FFF, and the address space of graphics card B ranges from 0x2000 to 0x2FFF, etc. This ensures that the addresses of different endpoint devices do not conflict during data transmission. Second, according to the system resource allocation characteristics requirements, reasonable bandwidth allocation is carried out for different host domains. If there are two host domains in the data center, one is mainly used for processing video rendering tasks and has a high bandwidth requirement; the other is used for daily office applications and has a relatively low bandwidth requirement. The system will allocate a higher bandwidth, such as 70% of the total bandwidth, to the video rendering host domain, and 30% to the office host domain. This ensures that each host domain can obtain resources that meet its own needs and avoids performance bottlenecks caused by unreasonable resource allocation. Third, the link load capacity limit requirements play an important role. If the theoretical transmission rate of the PCIe link is 16 Gbps, considering the overhead and concurrent transmission requirements in actual applications, by limiting the number of endpoint devices, it is ensured that the link will not have its transmission rate decreased due to connecting too many devices. For example, originally the link can stably carry the concurrent transmission of up to 8 endpoint devices. If the number exceeds this amount, the link is overloaded, and the transmission rate and bandwidth cannot meet the requirements. Through reasonable limitation, the stable and high-speed transmission of data on the link is guaranteed. Fourth, network cards and graphics cards produced by different manufacturers may be used in the data center. The protocol compatibility specifications ensure that these endpoint devices from different manufacturers can work properly in the system. For example, for a network card produced by manufacturer A and a graphics card produced by manufacturer B, as long as they both follow the protocol of the Peripheral Component Interconnect Express (PCIe) standard, they can achieve interconnection and interoperability with other devices, reducing the limitations of device selection.
[0060] In this embodiment, all endpoint devices are traversed. For endpoint devices whose all functions belong to the same host domain, in other host domains, the status of the endpoint devices is set to the offline status. For example, in a large data center, there are multiple server groups serving as different host domains. If a network card device only serves one of the host domains, in other host domains, this network card will be displayed as offline. At the same time, the endpoint devices in each host domain can only see the functions belonging to this host domain, and the functions that do not belong to this host domain will not be displayed. Suppose there is a multi-functional expansion card on the server, which includes two function modules: network communication and data encryption, serving different host domains respectively. Then in the host domain responsible for network communication, only the network communication function of this expansion card can be seen and used, and the data encryption function will not be presented in this host domain. In this way, the independence of each host domain in function usage and access is ensured.
[0061] Step S14: Determine the routing transmission path of the target message based on the access control service configuration table and the independent topology; wherein, the target message originates from the multi-functional shared port.
[0062] Determine the routing transmission path of the target message based on the access control service configuration table and the independent topology to achieve precise transmission of the target message; wherein, the target message originates from the multi-functional shared port.
[0063] In the PCIe cross-domain communication scenario involved in this embodiment, from the perspective of the host, the bridge devices inside the dedicated switch chip and the endpoint devices connected thereto are in a state independently managed by the root complexes (RCs) of each domain host. However, the actual situation is that the central processing unit (CPU) inside the dedicated switch chip stores the access control service configurations of each downstream port in the form of a configuration table in the multi-domain multi-functional shared port inside the switch chip. From Figure 4 the overall topology can be seen. Host 0 and Host 1 are respectively connected to the root ports (RPs) through the root complexes. Inside the dedicated switch chip, the management CPU is connected to the upstream ports (USPs) 0 and USP1, and is also associated with the address translation and bus number conversion module, the downstream ports (DSPs) 0, DSP1, and DSP2. Below the dedicated switch chip is the virtual switch chip layer. Each virtual switch chip contains an internal upstream port (iUSP) and an internal downstream port (iDSP), and finally connects to devices such as Device 0, Device 1, and Device 3. Each device has the functions of the corresponding host domain. From the perspective of the host, regardless of the actual number of levels of the topology cascaded under the multi-domain multi-functional shared port of the dedicated switch chip, under the independent multi-domain multi-functional shared ports presented by each host domain, it is a topology with a fixed number of levels. Map the endpoint devices (EPs) one by one to the downstream ports of the PCIe switch devices at the bottom level of the fixed-level virtual topology. According to the bearing limit of two-level cascading, the number of connected EP devices does not exceed 512. Therefore, the virtual scheme of this fixed-level topology can fully meet the requirements of the PCIe protocol and the actual needs of users. In Figure 4Among them, the presentation rules for each host domain are as follows: The topological structure presented by each host domain is a PCIe topological structure with a fixed number of levels, and they are independent of each other; According to the depth-first rule, the EP devices are mapped one-to-one to the bottom layer of the topological structure with a fixed number of levels; The devices in each independent host domain can only see the functions belonging to this host domain in the EP devices, and the functions that do not belong to this host domain will not be presented; The EP devices whose all functions belong to the same host domain are displayed as offline in other host domains.
[0064] When observing the EP devices cascaded by multi-level PCIe switching devices under the multi-domain multi-function shared port on the side of a certain host domain, the topological structure presented by the functional devices of the corresponding host domain on the host side is as Figure 5 shown. Figure 5 It shows the connection relationship from the root complex to the cascaded level of the dedicated switching chip, then to the internal upstream port and internal downstream port in the virtual switching chip, and finally to the endpoint device, presenting the path level of signal transmission. The configuration information and routing information function of the access control service are divided as follows: The internal downstream port processing module is responsible for processing the ACS configuration information and process when this host domain is the downstream port of the switching device. The processing results include upstream redirection, violation handling, point-to-point transmission, etc. The internal upstream port processing module is responsible for re-judging the point-to-point transmission routing result after the ACS processing of the downstream port, and judging whether the target is within the routing range according to the packet type. The specific judgment process and results refer to Figure 6 .
[0065] Figure 6 Taking the example of the host 0 function of the EP1 device sending a packet, when the iUSP module detects, if the routing is within its range, the packet is routed to device 3; if the routing is not within the range during the first detection, the packet is routed upward, and when the second iUSP detects that the routing is within the range, the packet is routed to device x; if the ACS result is always upstream redirection, the packet is routed to the host of the corresponding host domain. In addition, the fixed-level topological structure virtual mapping scheme of this application ensures that in other routing cases, it also conforms to the routing rules of the PCIe protocol.
[0066] In summary, to solve the problem of too many cascaded general Switch levels under the multi-domain multi-function shared port of PCIe, this application proposes a fixed-level topological structure virtual mapping scheme for PCIe cross-domain ACS function. The EP devices are mapped one-to-one to the virtual Switch levels with a fixed number of levels according to the depth-first rule, reducing the packet routing levels, realizing the effective mapping of the multi-domain configuration space, and greatly reducing the packet routing delay.
[0067] In addition, this application can also propose an advanced dynamic data management and cache optimization mechanism. This mechanism can use intelligent algorithms to accurately identify the priorities and frequencies of data interactions between different host domains. On this basis, the information data of DSP and USP is carefully classified and stored, and dynamically scheduled according to the real-time system operation status. When the data traffic changes or the access pattern changes, this mechanism can flexibly adjust the allocation strategy of the on-chip cache, prioritize the storage of high-frequency access and critical task data, and at the same time reasonably transfer low-frequency data to external storage devices. In this way, without affecting the overall system performance, the demand for on-chip cache capacity can be significantly reduced, and the occupation of memory resources can be greatly reduced, providing support for the development goals of miniaturization and high efficiency of PCIe cross-domain communication devices.
[0068] It can be seen that this application proposes a topological virtual mapping method for cross-domain access control, including: remapping the configuration space of the target device of the target switching chip according to the topological results of each host domain to generate device configuration information corresponding to each host domain; the target device includes the downstream bridge device inside the target switching chip and the connected endpoint devices; generating an access control service configuration table based on the device configuration information, and storing the access control service configuration table in the multifunctional shared port inside the target switching chip; for each host domain, mapping the endpoint devices to the lowest layer of the virtual topological structure with a fixed number of levels according to the depth-first rule to generate an independent topological structure for each host domain; determining the routing transmission path of the target message based on the access control service configuration table and the independent topological structure; the target message originates from the multifunctional shared port. It can be seen that for each host domain, this application maps the endpoint devices to the lowest layer of the virtual topological structure with a fixed number of levels to generate an independent topological structure for each host domain. In this way, by mapping the endpoint devices to the virtual topological structure with a fixed number of levels, the hardware that was originally difficult to solidify and judge due to the dynamically changing number of levels can now be judged based on the fixed number of levels. Furthermore, the hardware can be designed specifically based on this fixed virtual topological structure without considering the dynamically changing number of levels, thus solving the problem that the hardware is difficult to solidify and judge. At the same time, this application remaps the configuration space of the target device to generate device configuration information, and then obtains the access control service configuration table, and determines the routing transmission path in combination with the independent topological structure. In this way, when the message is transmitted, there is no need to perform a large number of complex hierarchical mapping judgments, and the routing can be quickly and accurately determined based on the configuration table and the topological structure, greatly reducing the delay during the message transmission process and improving the system performance.
[0069] Correspondingly, the embodiment of this application also discloses a topological virtual mapping device for cross-domain access control. See Figure 7 As shown, this device includes:
[0070] A configuration information generation module 11, configured to remap a configuration space of a target device of a target switching chip according to a topology result of each host domain, so as to generate device configuration information corresponding to each host domain; wherein, the target device includes a downstream bridge device inside the target switching chip and an endpoint device connected thereto;
[0071] A configuration table generation module 12, configured to generate an access control service configuration table based on the device configuration information, and store the access control service configuration table into a multi-functional shared port inside the target switching chip;
[0072] A device mapping module 13, configured to, for each host domain, map endpoint devices to the bottom layer of a virtual topology structure with a fixed number of levels according to a depth-first rule, so as to generate an independent topology structure of each host domain;
[0073] A message path determination module 14, configured to determine a routing transmission path of a target message based on the access control service configuration table and the independent topology structure; wherein, the target message originates from the multi-functional shared port. Wherein, for more specific working processes of the above-mentioned respective modules, reference may be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0074] It can be seen that the present application proposes a topological virtual mapping method for cross-domain access control, including: remapping the configuration space of the target device of the target switching chip according to the topological results of each host domain to generate device configuration information corresponding to each host domain; the target device includes the downstream bridge device inside the target switching chip and the connected endpoint devices; generating an access control service configuration table based on the device configuration information, and storing the access control service configuration table in the multifunctional shared port inside the target switching chip; for each host domain, mapping the endpoint devices to the bottom layer of the virtual topological structure with a fixed number of levels according to the depth-first rule to generate an independent topological structure for each host domain; determining the routing transmission path of the target packet based on the access control service configuration table and the independent topological structure; the target packet originates from the multifunctional shared port. It can be seen that for each host domain, the present application maps the endpoint devices to the bottom layer of the virtual topological structure with a fixed number of levels to generate an independent topological structure for each host domain. In this way, by mapping the endpoint devices to the virtual topological structure with a fixed number of levels, the hardware that was originally difficult to solidify and judge due to the dynamic change of the number of levels can now be judged based on the fixed number of levels. Furthermore, the hardware can be designed specifically according to this fixed virtual topological structure without considering the dynamically changing number of levels, thus solving the problem that the hardware is difficult to solidify and judge. At the same time, the present application remaps the configuration space of the target device to generate device configuration information, and then obtains the access control service configuration table, and determines the routing transmission path in combination with the independent topological structure. In this way, when the packet is transmitted, there is no need to perform a large number of complex step-by-step mapping judgments, and the routing can be determined quickly and accurately based on the configuration table and the topological structure, greatly reducing the delay in the packet transmission process and improving the system performance.
[0075] Furthermore, an embodiment of the present application also provides an electronic device. Figure 8 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the scope of use of the present application.
[0076] Figure 8 It is a structural schematic diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a display screen 23, an input / output interface 24, a communication interface 25, a power supply 26, and a communication bus 27. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the topological virtual mapping method for cross-domain access control disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0077] In this embodiment, the power supply 26 is used to provide operating voltages for each hardware device on the electronic device 20; the communication interface 25 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed thereon herein; the input / output interface 24 is used to obtain external input data or output data to the outside, and the specific interface type thereof can be selected according to specific application requirements, and no specific limitation is imposed herein.
[0078] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc., and the resources stored thereon can include a computer program 221, and the storage method can be transient storage or permanent storage. Among them, in addition to the computer program capable of implementing the topology virtual mapping method for cross-domain access control executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 221 can further include a computer program capable of performing other specific tasks.
[0079] Furthermore, an embodiment of this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the topology virtual mapping method for cross-domain access control disclosed above is implemented.
[0080] For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.
[0081] The various embodiments in this application are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and reference can be made to the description in the method part for related parts.
[0082] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0083] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0084] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0085] The above has introduced in detail a topological virtual mapping method, apparatus, device, and storage medium for cross-domain access control provided by the present application. Specific examples are used herein to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A topology virtual mapping method for cross-domain access control, characterized in that: include: According to the topological result of each host domain, the configuration space of the target device of the target switching chip is remapped to generate device configuration information corresponding to each of the host domains; wherein the target device includes a downlink bridge device inside the target switching chip and a connected endpoint device; Generate an access control service configuration table based on the device configuration information, and store the access control service configuration table in a multi-function shared port in the target switching chip; For each of the host domains, mapping the endpoint device to the lowest layer of a virtual topology structure with a fixed number of levels according to a depth-first rule, so as to generate an independent topology structure for each of the host domains; Based on the access control service configuration table and the independent topology structure, a routing transmission path of the target message is determined; wherein the target message originates from the multi-functional shared port.
2. The topology virtual mapping method for cross-domain access control according to claim 1, characterized in that: The generating of the access control service configuration table based on the device configuration information comprises: Based on the device configuration information, extracting the access control service configuration information of the downstream bridge device; The access control service configuration item of the downlink port connected to the multi-functional shared port is set as uplink remapping, and the access control service configuration table is generated according to the access control service configuration information.
3. The topology virtual mapping method for cross-domain access control according to claim 1, characterized in that: After mapping the endpoint device to the lowest layer of the virtual topology structure with a fixed number of levels according to the depth-first rule for each of the host domains, the method further includes: All the endpoint devices are traversed, and for the endpoint devices whose functions all belong to the same host domain, the status of the endpoint devices is set to an offline state in other host domains.
4. The topology virtual mapping method for cross-domain access control according to any one of claims 1 to 3, characterized in that: Mapping the endpoint device to the lowest layer of a virtual topology structure with a fixed number of levels according to a depth-first rule to generate an independent topology structure for each host domain, including: Virtualizing the multifunctional shared port into a multi-stage switching device cascade structure, and determining the multi-stage switching device cascade structure as the virtual topology structure with a fixed number of stages; In the virtual topology structure with a fixed number of levels, the number of the endpoint devices mapped to the lowest layer of the virtual topology structure with a fixed number of levels is limited according to the protocol requirements of the high-speed serial computer expansion bus standard; wherein the protocol requirements include address space addressing characteristic requirements, system resource allocation characteristic requirements, link load capacity limitation requirements, and protocol compatibility specification requirements, the address space addressing characteristic requirements ensure the continuity and uniqueness of the address space of the endpoint devices, the system resource allocation characteristic requirements ensure the rationality of the bandwidth allocation of each of the host domains, the link load capacity limitation requirements ensure that the transmission rate and transmission bandwidth of the link meet the target requirements, and the protocol compatibility specification requirements ensure that the endpoint devices of different manufacturers can be compatible; A corresponding number of the endpoint devices are mapped to the lowest layer of the virtual topology structure with a fixed number of levels according to a depth-first rule, so as to generate an independent topology structure for each of the host domains.
5. The topology virtual mapping method for cross-domain access control according to claim 2, characterized in that: After generating the access control service configuration table based on the device configuration information, the method further includes: The target message from the multifunctional shared port is processed according to a target processing method; the target processing method includes uplink redirection processing, violation processing and point-to-point transmission processing.
6. The topology virtual mapping method for cross-domain access control according to claim 5, characterized in that: The processing of the target message from the multi-functional shared port according to the target processing method includes: If the target message needs to interact with the host domain, directing the target message to the direction of the host domain; If the target message does not comply with the preset access control rule, the target message is intercepted; If the receiving device of the target message is a designated endpoint device and does not need to be routed, the target message is directly transmitted to the designated endpoint device.
7. The topology virtual mapping method for cross-domain access control according to claim 6, characterized in that: After directly transmitting the target message to the designated endpoint device, the method further includes: It is determined whether the transmission result of the target message is within a preset routing range according to the message type of the target message, and if so, it is determined that the transmission path of the target message is valid.
8. A topology virtual mapping device for cross-domain access control, characterized in that: include: A configuration information generation module, used to remap the configuration space of the target device of the target switching chip according to the topology result of each host domain, so as to generate device configuration information corresponding to each of the host domains; wherein the target device includes a downlink bridge device inside the target switching chip and a connected endpoint device; A configuration table generating module, configured to generate an access control service configuration table based on the device configuration information, and store the access control service configuration table in a multi-function shared port in the target switching chip; A device mapping module, for mapping the endpoint device to the lowest layer of a virtual topology structure with a fixed number of levels according to a depth-first rule for each of the host domains, so as to generate an independent topology structure for each of the host domains; The message path determination module is used to determine the routing transmission path of the target message based on the access control service configuration table and the independent topology structure; wherein the target message originates from the multi-functional shared port.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the topology virtual mapping method for cross-domain access control as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program; wherein, when the computer program is executed by a processor, the topological virtual mapping method for cross-domain access control as described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Communication method of domain isolation switching equipment, networking system, product and equipment
CN120710957A
128*128 l-band matrix adaptive expansion configuration method
CN122824700A