Data processing method, electronic equipment and storage medium
By introducing local trusted processing units and pipeline processing units into network devices, and using fast read and write instruction registers, the rapid online reconfiguration of network device data processing logic is achieved, solving the dual challenges of configuration security and real-time in the prior art, and achieving safe and efficient business continuity.
Patent Information
- Application Number
- CN202510193227.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-06-13
AI Technical Summary
When implementing the dynamic configuration of network equipment data processing logic, the prior art faces the dual challenges of configuration security and real-time, resulting in increased hardware design complexity or uncontrollable service interruption time windows.
By introducing a local trusted processing unit and a pipeline processing unit into the network device, the fast online reconfiguration of pipeline configuration information is achieved using instruction registers that support fast read and write. The specific steps include receiving pipeline configuration information, converting it into pipeline configuration instructions, and registering it in the instruction register. The pipeline processing unit reads configuration instructions in real time, dynamically updates processing logic, and processing data according to the new logic.
It realizes rapid online reconfiguration of network equipment data processing logic, avoids the security risks of external configuration injection, and bypasses the delay bottleneck of traditional memory or bus access, so that pipeline policy switching takes effect instantly during the packet processing gap, ensuring the continuity of equipment services.
Smart Images

Figure CN120145461A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to, but are not limited to, the field of computer technology, and particularly relate to a data processing method, an electronic device, and a storage medium. Background Art
[0002] With the continuous increase in data processing requirements, the development of programmable data plane architectures has put forward higher requirements for the flexibility and processing efficiency of network devices. The current mainstream programmable data exchange architectures implement the dynamic configuration of packet processing logic through hardware description languages, but face the dual challenges of configuration security and real-time performance in actual deployment.
[0003] In related technologies, dynamic configuration schemes usually adopt the method of injecting configuration data through an external channel. This method requires the establishment of an independent physical isolation channel to prevent malicious attacks, resulting in a significant increase in the complexity of hardware design. Another typical scheme completes configuration updates by recompiling hardware description code offline. Although it avoids the security risks of external configuration, it requires interrupting services and experiencing a long compilation and deployment cycle, making it difficult to meet real-time service requirements. Summary of the Invention
[0004] The present application aims to solve at least one of the technical problems existing in the prior art. To this end, the present application provides a data processing method, an electronic device, and a storage medium, which can perform fast online reconfiguration of the data processing logic of network devices.
[0005] To achieve the above object, a first aspect of the embodiments of the present application proposes a data processing method, which is applied to a network device. The network device includes a local trusted processing unit and a pipeline processing unit. The local trusted processing unit is built-in with an instruction register that supports fast reading and writing. The pipeline processing unit is connected to the instruction register through a signal line. The method includes:
[0006] The local trusted processing unit receives pipeline configuration information, and according to a pre-configured pipeline extension instruction set, converts the pipeline configuration information into corresponding pipeline configuration instructions, and stores the pipeline configuration instructions in the instruction register;
[0007] The pipeline processing unit reads the pipeline configuration instructions from the instruction register, and dynamically updates the pipeline processing logic according to the pipeline configuration instructions to obtain an updated target pipeline processing logic;
[0008] The pipeline processing unit obtains data to be processed, and processes the data to be processed according to the target pipeline processing logic to obtain a pipeline processing result.
[0009] In some embodiments, the network device further includes a network interface, and before the pipeline processing unit obtains the data to be processed, the method further includes:
[0010] receiving the data to be processed from an external network through the network interface, and inputting the data to be processed into the pipeline processing unit;
[0011] After the data to be processed is processed according to the target pipeline processing logic to obtain the pipeline processing result, the method further includes:
[0012] The pipeline processing unit sends the pipeline processing result to the network interface in response to the pipeline processing result indicating that the processing of the to-be-processed data is completed;
[0013] The target network address is obtained through the network interface, and the pipeline processing result is sent to the target network address.
[0014] In some embodiments, the network device further comprises a processor cluster, the processor cluster has a built-in data exchange register supporting fast reading and writing, and the pipeline processing unit is connected to the data exchange register via a signal line;
[0015] After the pipeline processing unit acquires the data to be processed and processes the data to be processed according to the target pipeline processing logic to obtain the pipeline processing result, the method further includes:
[0016] The pipeline processing unit stores the pipeline processing result in the data exchange register in response to the pipeline processing result indicating that the data to be processed needs to enter the processor cluster for data processing;
[0017] The processor cluster reads the pipeline processing result from the data exchange register, and performs data processing on the pipeline processing data according to a preset processor processing logic to obtain a processor processing result;
[0018] The processor cluster stores the processor processing result in the data exchange register;
[0019] The pipeline processing unit reads the processor processing result from the data exchange register, and formats and encapsulates the processor processing result according to the target pipeline processing logic to obtain a target processing result;
[0020] The pipeline processing unit sends the pipeline processing result to the network interface;
[0021] Obtain a target network address through the network interface and send the pipeline processing result to the target network address.
[0022] In some embodiments, the converting the pipeline configuration information into corresponding pipeline configuration instructions according to a pre-configured pipeline extension instruction set includes:
[0023] Perform syntax parsing on the pipeline configuration information to obtain match table reconstruction information;
[0024] Convert the match table reconstruction information into pipeline configuration instructions recognizable by the pipeline processing unit based on the pipeline extension instruction set.
[0025] In some embodiments, the dynamically updating the pipeline processing logic according to the pipeline configuration instructions to obtain an updated target pipeline processing logic includes:
[0026] Parse the pipeline configuration instructions to obtain entries in the match table to be updated;
[0027] Query the target storage location of the entries in the match table to be updated in the reconfigurable match table;
[0028] Store the entries in the match table to be updated in the target storage location in the reconfigurable match table to obtain an updated reconfigurable match table.
[0029] In some embodiments, the storing the entries in the match table to be updated in the target storage location in the reconfigurable match table to obtain an updated reconfigurable match table includes:
[0030] Obtain the data processing status of the pipeline processing unit in real time;
[0031] If the data processing status indicates that the current status is an idle processing status, write the entries in the match table to be updated to the target storage location in the reconfigurable match table to obtain an updated reconfigurable match table;
[0032] If the data processing status indicates that the current status is a processing status, wait for the data processing status to convert to the idle processing status, and write the entries in the match table to be updated to the target storage location in the reconfigurable match table to obtain an updated reconfigurable match table.
[0033] In some embodiments, the pipeline processing unit includes a parser sub-unit, a key-value extraction sub-unit, a lookup sub-unit, and an action execution sub-unit. The processing the data to be processed according to the target pipeline processing logic to obtain a pipeline processing result includes:
[0034] The target data is parsed by the parser subunit to obtain target protocol features;
[0035] The target matching key value is extracted from the target protocol features by the key-value extraction subunit;
[0036] The corresponding target action instruction is searched for in the updated reconfigurable matching table by the lookup subunit according to the target matching key value;
[0037] The target data is processed by the action execution subunit according to the target action instruction.
[0038] In some embodiments, the processing of the target data by the action execution subunit according to the target action instruction includes:
[0039] When the action execution subunit detects that the target action instruction is a security filtering instruction, the abnormal filtering list is extracted from the target action instruction;
[0040] The data source address of the target data is matched in the abnormal address filtering list;
[0041] In response to the successful matching of the data source address, the target data is discarded and a security event log is generated;
[0042] In response to the failure of the data source address matching, a security marking field is added to the target data.
[0043] To achieve the above object, a second aspect of the embodiments of the present application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the data processing method described in the first aspect is implemented.
[0044] To achieve the above object, a third aspect of the embodiments of the present application provides a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, the data processing method described in the first aspect above is implemented.
[0045] The data processing method provided by an embodiment of this application is applied to a network device. The network device includes a local trusted processing unit and a pipeline processing unit. The local trusted processing unit is built with an instruction register that supports fast reading and writing. The pipeline processing unit is connected to the instruction register through a signal line. The method includes: First, the local trusted processing unit receives pipeline configuration information, and according to a pre-configured pipeline extension instruction set, converts the pipeline configuration information to obtain corresponding pipeline configuration instructions, and stores the pipeline configuration instructions in the instruction register; Then, the pipeline processing unit reads the pipeline configuration instructions from the instruction register, and dynamically updates the pipeline processing logic according to the pipeline configuration instructions to obtain an updated target pipeline processing logic; Finally, the pipeline processing unit obtains the data to be processed, and processes the data to be processed according to the target pipeline processing logic to obtain a pipeline processing result.
[0046] The data processing method provided by an embodiment of this application realizes the dynamic update of data processing logic through the direct connection architecture of the local trusted processing unit and the pipeline processing unit. First, the local trusted processing unit directly converts the pipeline configuration information into hardware-recognizable configuration instructions based on a pre-set pipeline extension instruction set, and stores them in a dedicated instruction register; The pipeline processing unit reads the configuration instructions in the register in real time through the signal line, and completes the online logic reconstruction of core components such as the parser and the match table without interrupting the data processing flow. Since the generation, storage, and reading of the configuration instructions are all completed in the local trusted environment, the security risk of external configuration injection is avoided. At the same time, the direct connection mechanism of the dedicated instruction register bypasses the latency bottleneck of traditional memory or bus access, enabling the switching of pipeline strategies to take effect instantaneously during packet processing intervals. Compared with the existing technologies that rely on offline compilation or external channels, it can perform fast online reconfiguration of the data processing logic of network devices while ensuring the continuity of device services.
[0047] Other features and advantages of this application will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing this application. The objectives and other advantages of this application can be realized and obtained through the structures specifically pointed out in the specification, the claims, and the drawings. Brief Description of the Drawings
[0048] Figure 1 is a flowchart of the data processing method provided by an embodiment of this application;
[0049] Figure 2 is a schematic structural diagram of a network device provided by an embodiment of this application;
[0050] Figure 3 is a schematic structural diagram of a network device provided by another embodiment of this application;
[0051] Figure 4 It is a schematic structural diagram of a network device provided by another embodiment of the present application;
[0052] Figure 5 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0053] Figure 6 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0054] Figure 7 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0055] Figure 8 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0056] Figure 9 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0057] Figure 10 It is a schematic flowchart of a data processing method provided by another embodiment of the present application;
[0058] Figure 11 It is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0059] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0060] It should be noted that although functional module division is performed in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order from the module division in the device or the order in the flowchart. Terms such as "first" and "second" in the specification, claims and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence.
[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application, and are not intended to limit the present application.
[0062] First, several nouns involved in the present application are analyzed:
[0063] The P4 programming language (Programming Protocol-independent Packet Processors) is a domain-specific language (DSL) designed specifically for the network data plane. Its core goal is to endow network devices with the ability to flexibly define and process data packets. By abstracting hardware details, this language allows developers to describe the parsing, matching, and forwarding logic of data packets in a software manner, thus getting rid of the dependence of traditional network devices on fixed protocols and fixed processing flows. The key feature of P4 lies in its protocol independence. Developers can customize the parsing rules for any protocol fields and implement dynamic data packet processing strategies through the Match-Action Table. In specific implementations, P4 programs usually include modules such as header definitions, parsers, control flows, and action instructions, and can be compiled into low-level configuration instructions executable by target hardware (such as programmable switching chips or FPGAs).
[0064] Reconfigurable Match Tables (RMT) are hardware data structures that support dynamic programming and are used for efficient processing of packet matching and action execution in network devices. Its core function is to dynamically configure matching rules and corresponding processing actions in a software-defined manner to adapt to diverse network protocols and real-time policy requirements.
[0065] Protocol Independent Switch Architecture (PISA) is a switch chip architecture that combines programmability and high-performance processing capabilities. It evolved from the RMT (Reconfigurable Match Tables) architecture. By decoupling the hardware processing pipeline from specific network protocols, it realizes the software definition of data plane forwarding logic. The core design concept of PISA is to abstract processing stages such as packet parsing, matching, and action execution into programmable modules (such as configurable parsers, dynamic match tables, multi-level action engines), allowing developers to flexibly define protocol processing flows through domain-specific programming languages, and at the same time maintaining line rate forwarding performance comparable to fixed-function chips with the parallel processing capabilities of the hardware pipeline.
[0066] Currently, in the field of network devices, the rise of software-defined networks (SDN) has promoted the development of data plane programmable technologies. At the same time, the development of programmable data plane architectures has put forward higher requirements for the flexibility and processing efficiency of network devices. The current mainstream programmable data exchange architectures implement the dynamic configuration of packet processing logic through hardware description languages, but face double challenges of configuration security and real-time performance in actual deployment.
[0067] In the related art, dynamic configuration solutions are usually implemented by injecting configuration data through an external channel. Such solutions inject data packets carrying configuration information into the switching chip through an external network port, and the pipeline parser extracts the configuration content and dynamically updates the matching table or adjusts the parsing logic. For example, in the Menshen architecture, the configuration packet is input through an independent physical port and directly written into the RMT entry or the pipeline-level state machine is modified after parsing. However, this solution has significant security risks: the source of the external configuration packet cannot be fully trusted, and an attacker can forge or hijack the configuration packet to tamper with the pipeline logic.
[0068] In addition, there is also a method of recompiling the P4 program into a hardware description file recognizable by the FPGA (such as Verilog code) offline, generating a bitstream file after synthesis, placement and routing, and then burning it into the FPGA to achieve the reconstruction of the pipeline logic. Taking nanoPu as an example, it relies on the Xilinx SDNet toolchain to complete the conversion from P4 to FPGA configuration. Although this method avoids the security risks of external configuration, however, the FPGA recompilation process takes dozens of minutes to several hours, and restarting the hardware is required to burn the new bitstream, resulting in an uncontrollable business interruption time window and being unable to meet the rapid iteration requirements of the data center.
[0069] Based on this, the embodiments of the present application provide a data processing method, an electronic device and a storage medium, aiming to perform fast online reconfiguration on the data processing logic of network devices.
[0070] The data processing method, electronic device and storage medium provided by the embodiments of the present application are specifically described through the following embodiments. First, the data processing method in the embodiments of the present application is described.
[0071] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is to use a digital computer or a machine controlled by a digital computer to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results of theory, method, technology and application system.
[0072] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0073] The data processing method provided by the embodiments of the present application relates to the field of computer technology. The data processing method provided by the embodiments of the present application can be applied to a terminal, or to a server side, or can also be software running on a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or can be configured as a server cluster or a distributed system composed of multiple physical servers, or can also be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the data processing method, etc., but is not limited to the above forms.
[0074] The present application can be used in many general or specific computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet-type devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0075] It should be noted that in each specific embodiment of the present application, when it comes to performing relevant processing based on data related to the user's identity or characteristics such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of the present application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or jumping to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the normal operation of the embodiments of the present application will be obtained.
[0076] Figure 1FIG. 0 is an optional flowchart of the data processing method provided by an embodiment of the present application. The data processing method in this embodiment is applied to a network device, which includes a local trusted processing unit and a pipeline processing unit. The local trusted processing unit is built-in with an instruction register that supports fast reading and writing. The pipeline processing unit is connected to the instruction register through a signal line. Figure 1 The method in Figure 1 may include, but is not limited to, steps 101 to 103.
[0077] Step 101, the local trusted processing unit receives pipeline configuration information, and according to a pre-configured pipeline extension instruction set, converts the pipeline configuration information to obtain corresponding pipeline configuration instructions, and stores the pipeline configuration instructions in the instruction register.
[0078] Step 102, the pipeline processing unit reads the pipeline configuration instructions from the instruction register, and dynamically updates the pipeline processing logic according to the pipeline configuration instructions to obtain an updated target pipeline processing logic.
[0079] Step 103, the pipeline processing unit obtains data to be processed, and processes the data to be processed according to the target pipeline processing logic to obtain a pipeline processing result.
[0080] Steps 101 to 103 illustrated in the embodiment of the present application realize dynamic update of the data processing logic through a direct connection architecture between the local trusted processing unit and the pipeline processing unit. First, the local trusted processing unit directly converts the pipeline configuration information into hardware-recognizable configuration instructions based on a pre-set pipeline extension instruction set, and stores them in a dedicated instruction register; the pipeline processing unit reads the configuration instructions in the register in real time through a signal line, and completes the online logic reconstruction of core components such as a parser and a match table without interrupting the data processing flow. Since the generation, storage, and reading of the configuration instructions are all completed in a local trusted environment, the security risk of external configuration injection is avoided. At the same time, the direct connection mechanism of the dedicated instruction register bypasses the latency bottleneck of traditional memory or bus access, enabling the switching of pipeline strategies to take effect instantaneously during packet processing intervals. Compared with the prior art that relies on offline compilation or external channels, it can perform fast online reconfiguration of the data processing logic of the network device while ensuring the continuity of device services.
[0081] As Figure 2 shown, the network device 200 provided by the embodiment of the present application includes a local trusted processing unit 210 and a pipeline processing unit 220. The local trusted processing unit is built-in with an instruction register 211 that supports fast reading and writing. The pipeline processing unit 220 is connected to the instruction register 211 through a signal line.
[0082] In some embodiments, the local trusted processing unit 210 is a dedicated hardware module independently deployed in a network device. It is a dedicated microcontroller unit (MCU) adopting the RISC-V architecture, physically isolated from external network interfaces, and only allowing local users to input pipeline configuration information through the management plane to ensure the trustworthiness of the configuration generation environment. The instruction register 211 adopts a custom control and status register (CSR). CSR registers are a set of special registers used to manage and configure the processor state, and are crucial for implementing functions such as interrupt handling, exception handling, and system calls. RISC-V provides a set of dedicated CSR instructions to access these registers, including read, modify, and write operations. In this embodiment, the CSR register is dedicated to storing pipeline configuration instructions and is directly accessed through the RISC-V instruction set extension without going through the address translation of the memory management unit (MMU). The pipeline processing unit 220 is a programmable data plane engine based on the PISA architecture, which is directly connected to the CSR register 211 through dedicated physical signal lines to ensure the real-time injection of configuration instructions and zero-delay feedback of the pipeline state.
[0083] In step 101 of some embodiments, the pipeline configuration information is a user-defined policy file used to describe the logical behavior of the data processing pipeline, usually written in a high-level language (such as P4), and usually includes protocol parsing rules for defining how to parse the packet header (such as the field structures of Ethernet, IP, and VXLAN); match table entries for specifying the match field (Key), execution action (Action), and priority; and action instructions for describing packet modification, forwarding, or statistical operations (such as adding a tunnel header and discarding malicious traffic). The pipeline extension instruction set is a custom instruction set designed specifically for pipeline hardware to convert high-level configuration information into low-level instructions recognizable by the hardware.
[0084] Among them, the local trusted processing unit receives the pipeline configuration information locally input by the user (such as a configuration file in JSON format) through a preset configuration interface. The pipeline extension instruction set is pre-stored inside the unit, which contains binary instruction encoding rules corresponding to the hardware architecture of the pipeline processing unit. The configuration information is parsed item by item through an instruction conversion module: first, the match condition fields (such as source IP address range and protocol type) and corresponding action instructions (such as forwarding, discarding, and filtering actions) in the configuration information are identified, and then they are converted into pipeline configuration instructions with a fixed format according to the mapping relationship of the instruction set. The pipeline configuration instructions can specifically include fields such as an operation code, a target register address, and a data payload. After the conversion is completed, the pipeline configuration instructions are stored in the instruction register through a direct write operation.
[0085] In step 102 of some embodiments, the pipeline processing unit monitors the status flag of the instruction register in real time through hardware signal lines. When it detects the arrival of a new instruction, it immediately starts the instruction reading process: sequentially reads each field of the pipeline configuration instruction from the specified address of the instruction register. During the dynamic update process, the pipeline processing unit parses the operation code in the instruction to determine the update type (such as adding a new table entry, modifying an existing table entry), and according to the target storage location information carried in the instruction (such as the matching table index number), writes the data payload (such as a new matching key value and the corresponding action code) in the instruction to the corresponding position of the reconfigurable matching table inside the pipeline. After the writing is completed, the pipeline processing logic immediately switches to the updated configuration state to achieve interruption-free update of the processing logic.
[0086] In step 103 of some embodiments, the pipeline processing unit obtains the data packet to be processed from the data input port and executes the processing flow according to the updated target pipeline processing logic. The processing logic generally may include the following stages:
[0087] Data parsing stage: extracts the protocol header information of the data packet (such as Ethernet MAC address, IP header fields) and generates metadata;
[0088] Matching search stage: combines the key fields in the metadata into a matching key and performs a parallel search in the reconfigurable matching table;
[0089] Action execution stage: performs corresponding operations on the data packet according to the action instructions recorded in the found matching table entry (such as modifying the target port, adding a VLAN tag);
[0090] Result output stage: sends the processed data packet into the output queue and generates a pipeline processing result including the processing status (such as successful forwarding, discard reason).
[0091] As Figure 3 shown, in some embodiments, the network device 200 further includes a network interface 230. Among them, the network interface 230 is a hardware module integrating a MAC controller 231 and a DMA engine 232, receives external network data through a physical port (such as RJ45), and the MAC controller 231 completes the link layer parsing. At the same time, the MAC controller 231 is also used to encapsulate the data processed by the pipeline processing unit into a frame structure conforming to the link layer protocol (such as adding an Ethernet header) and send it to the external network through the physical port. The DMA engine 232 is directly connected to the buffer of the pipeline processing unit through signal lines. When the MAC controller 231 completes the data frame parsing, the DMA engine 232 writes the payload data into the buffer of the pipeline processing unit. The DMA engine 232 is also used to read data from the buffer and submit it to the MAC controller 231 for frame encapsulation and sending.
[0092] In some embodiments, before step 103, the following steps may also be included, but are not limited to:
[0093] Receive data to be processed from an external network through a network interface and input the data to be processed into the pipeline processing unit.
[0094] Among them, the network interface receives the data to be processed from the external network through a physical connection port (such as an Ethernet interface). The DMA engine built into the network interface directly writes the received data into the input buffer pre-allocated by the pipeline processing unit. After the data storage is completed, the pipeline processing unit is notified that the data is ready through a hardware interrupt signal or a status register flag bit. This process does not require the intervention of the processor, ensuring the efficient transmission of data to the pipeline processing unit.
[0095] In some embodiments, after step 103, the following steps may also be included, but are not limited to:
[0096] The pipeline processing unit responds to the indication that the data to be processed is completed in the pipeline processing result and sends the pipeline processing result to the network interface.
[0097] Obtain the target network address through the network interface and send the pipeline processing result to the target network address.
[0098] Among them, when the pipeline processing result is marked as "processing completed", the pipeline processing unit writes the pipeline processing result into the send buffer of the network interface. The network interface extracts the predefined target network address from the metadata of the result data, and then encapsulates the pipeline processing result into a frame structure conforming to the network protocol through the MAC controller and sends it to the device corresponding to the target network address through the physical port. The entire sending process is driven by the DMA engine to ensure the fast transmission of data from the send buffer to the network link.
[0099] As Figure 4 shown, in some embodiments, the network device 200 further includes a processor cluster 240. The processor cluster 240 is built with a data exchange register 241 that supports fast reading and writing. The pipeline processing unit 220 is connected to the data exchange register 241 through a signal line.
[0100] Among them, the processor cluster 240 responsible for data plane processing obtains data from the pipeline processing unit 220 by reading the data exchange register 241, and outputs data to the pipeline processing unit 220 by writing to the data exchange register 241. The data exchange register can also use a custom control and status register (CSR). Compared with the traditional solution where the CPU and the pipeline exchange information through memory access, this solution bypasses the memory latency and does not require using load store instructions to access the bus. The data exchange rate only depends on the rate at which the CPU executes CSR instructions. Compared with the solution of accessing the general register file in nanoPU, this solution does not change the instruction set architecture, does not require additional functional processing restrictions on the compiler, and does not additionally occupy two general registers, which can maximize the computing efficiency of the CPU.
[0101] As Figure 5 shown, in some embodiments, after step 103, it may further include, but is not limited to, steps 501 to 506:
[0102] Step 501, in response to the pipeline processing result indicating that the data to be processed needs to enter the processor cluster for data processing, the pipeline processing unit stores the pipeline processing result in the data exchange register.
[0103] Step 502, the processor cluster reads the pipeline processing result from the data exchange register and performs data processing on the pipeline processing data according to the preset processor processing logic to obtain the processor processing result.
[0104] Step 503, the processor cluster stores the processor processing result in the data exchange register.
[0105] Step 504, the pipeline processing unit reads the processor processing result from the data exchange register and performs formatting and encapsulation processing on the processor processing result according to the target pipeline processing logic to obtain the target processing result.
[0106] Step 505, the pipeline processing unit sends the pipeline processing result to the network interface.
[0107] Step 506, obtain the target network address through the network interface and send the pipeline processing result to the target network address.
[0108] In step 501 of some embodiments, when the pipeline processing unit detects that the pipeline processing result is marked for further processing (such as carrying a "needs processor cluster processing" status code), it writes the current processing result data (including the packet payload and metadata) to the specified storage location of the data exchange register built in the processor cluster, and the write operation is completed through a direct connection signal line.
[0109] In step 502 of some embodiments, the processor cluster monitors the write status of the data exchange register through a polling or interrupt mechanism. When new data is detected, it reads the pipelined processing result data from the corresponding address of the data exchange register and calls a preset processor processing logic (such as a load balancing algorithm, an encryption and decryption algorithm) to perform calculations and generate a processor processing result.
[0110] In step 503 of some embodiments, the processor cluster writes the processed result data to the same or adjacent storage location of the data exchange register, overwriting the original data or storing it in a new area, and notifies the pipelined processing unit of the data ready status through a hardware signal line.
[0111] In step 504 of some embodiments, the pipelined processing unit reads the processor processing result from the target address of the data exchange register and performs a formatting and encapsulation operation according to the dynamically updated target pipelined processing logic to generate target processed result data that conforms to the network transmission specification.
[0112] In steps 505 to 506 of some embodiments, the pipelined processing unit writes the encapsulated target processed result to the send buffer of the network interface, triggering the network interface to start the data sending process. The network interface extracts a preset target network address (such as the destination IP address + UDP port) from the metadata of the target processed result, encapsulates the data into a network frame (such as an Ethernet frame), and sends it to the external device corresponding to this address through a physical port.
[0113] Through steps 501 to 506, this embodiment realizes efficient data interaction and task division between the pipelined processing unit and the processor cluster. When the pipelined processing unit identifies data that requires complex calculations, it transfers the data to the processor cluster through the fast read and write capabilities of the data exchange register, avoiding the latency loss caused by multiple copies of data through the system memory in the traditional solution; after the processor cluster executes the customized processing logic using the multi-core heterogeneous architecture, the result is returned through the same register, and the pipelined processing unit then performs standardized encapsulation and drives the network interface to send, forming a closed-loop process of "pipelined preprocessing - cluster in-depth processing - pipelined postprocessing". This design not only retains the line speed forwarding performance of the pipelined processing unit, but also expands the service processing flexibility through the processor cluster. At the same time, with the help of the hardware-level register direct connection and signal line synchronization mechanism, the overall data exchange efficiency is improved.
[0114] As Figure 6 shown, in some embodiments, the steps in step 101 to convert the pipeline configuration information into corresponding pipeline configuration instructions according to a pre-configured pipeline extension instruction set may include, but are not limited to, steps 601 to 602.
[0115] Step 601: Parse the syntax of the pipeline configuration information to obtain the matching table reconstruction information.
[0116] Step 602: Based on the pipeline extension instruction set, convert the matching table reconstruction information into pipeline configuration instructions recognizable by the pipeline processing unit.
[0117] In step 601 of some embodiments, the pipeline configuration information is usually written in a high-level configuration language (such as P4 language), including match field definitions (such as source IP address, protocol type) and corresponding action instructions (such as forward, discard). The syntax parsing process first splits the configuration text into legal symbols, then generates an abstract syntax tree according to predefined syntax rules, identifies the matching table name, match key structure, and action association relationship, and finally outputs structured matching table reconstruction information, including metadata such as table item index, match key bit width, and action code pointer.
[0118] In step 602 of some embodiments, the pipeline extension instruction set contains instruction encoding rules supported by the hardware. The local trusted processing unit can encode each entry in the matching table reconstruction information into binary instructions executable by the pipeline processing unit according to the pipeline extension instruction (for example, "write to table A, key value X → action Y")
[0119] Through steps 601 to 602, the high-level configuration information is directly converted into binary encoding of the predefined instruction set, avoiding the time-consuming process of passing through multiple software compilation chains in the traditional scheme. Based on the fixed encoding rules of the pipeline extension instruction set, a one-to-one fast conversion from configuration information to machine instructions is achieved, eliminating complex steps such as syntax tree optimization and register allocation required by general compilers, enabling configuration updates to take effect in real time, and meeting the requirements of network devices for rapid deployment of service policies.
[0120] As Figure 7 shown, in some embodiments, the steps in step 102, dynamically update the pipeline processing logic according to the pipeline configuration instructions to obtain the updated target pipeline processing logic, which may include, but is not limited to, steps 701 to 703.
[0121] Step 701: Parse the pipeline configuration instructions to obtain the entries to be updated in the matching table.
[0122] Step 702: Query the target storage location of the entries to be updated in the matching table in the reconfigurable matching table.
[0123] Step 703: Store the entries to be updated in the matching table in the target storage location in the reconfigurable matching table to obtain the updated reconfigurable matching table.
[0124] In step 701 of some embodiments, after the pipeline processing unit receives the pipeline configuration instruction from the instruction register, it first identifies the operation type (such as add, modify, or delete) in the instruction header field, extracts the matching key values (such as destination IP address range, protocol type) and associated action codes (such as forwarding port number, discard flag) carried in the instruction payload. The parsed output is the entry to be updated in the matching table, and its data structure includes the operation type, matching key values, priority, and action code pointer, which are used to clarify the specific content to be updated.
[0125] In step 702 of some embodiments, based on the table identifier in the entry to be updated in the matching table, query the metadata index of the reconfigurable matching table to determine the logical location where the entry should be stored. For the add operation, obtain the next available storage address through the free address manager; for the modify or delete operation, directly locate the existing table entry address according to the entry index number.
[0126] In step 703 of some embodiments, write the matching key values, priority, and action code in the entry to be updated in the matching table into the target storage address according to the physical storage format of the reconfigurable matching table. The write operation is completed through hardware atomic instructions to avoid data inconsistency caused by partial writes during the update process. After the write is completed, the reconfigurable matching table takes effect immediately, and the pipeline processing unit performs data matching and processing based on the updated table entries.
[0127] Through steps 701 to 703, based on the instruction parsing and address query mechanism, ensure that each table entry update accurately acts on the target storage location, avoid matching errors caused by address offsets in the traditional scheme, and the updated reconfigurable matching table takes effect immediately, supporting millisecond-level switching of business policies, so as to achieve dynamic and interruption-free update of the pipeline processing logic.
[0128] As Figure 8 shown, in some embodiments, step 703 may include, but is not limited to, steps 801 to 803.
[0129] Step 801, obtain the data processing status of the pipeline processing unit in real time.
[0130] Step 802, if the data processing status indicates that the current status is the idle processing status, write the entry to be updated in the matching table into the target storage location in the reconfigurable matching table to obtain the updated reconfigurable matching table.
[0131] Step 803, if the data processing status indicates that the current status is the processing status, wait for the data processing status to convert to the idle processing status, and write the entry to be updated in the matching table into the target storage location in the reconfigurable matching table to obtain the updated reconfigurable matching table.
[0132] In step 801 of some embodiments, the pipeline processing unit has a built-in status register that continuously records the current data processing status (such as "idle processing status" or "processing status"). The pipeline processing unit reads the status value in real time through polling or interrupt. The data processing status reflects whether the pipeline processing unit is in a data packet processing cycle.
[0133] In step 802 of some embodiments, when the status register indicates that the current is the "idle processing status" (that is, no data packet is being processed), the control module immediately initiates a write operation: writing the entry to be updated in the matching table to the target storage location pre-queried in the reconfigurable matching table through the data bus. The write operation is completed within one clock cycle, and the updated reconfigurable matching table takes effect immediately.
[0134] In step 803 of some embodiments, if the status register indicates that the current is the "processing status", the write operation is suspended, and the status register is continuously monitored until it switches to the "idle processing status". After the status switch, the write operation in step 802 is immediately executed to ensure that the update process does not interfere with the ongoing pipeline data processing.
[0135] Through steps 801 to 803, this embodiment completes the update by combining the microsecond-level idle gaps of the pipeline processing unit, avoids the matching table access conflicts caused by the concurrency of the update operation and data processing, eliminates the data errors caused by the race conditions in the traditional scheme, and ensures that the update operation does not truncate or overwrite the table entries being used through the hardware-level status monitoring and waiting mechanism, guaranteeing the consistency of the processing logic.
[0136] Please refer to Figure 9 , in some embodiments, the pipeline processing unit includes a parser subunit, a key-value extraction subunit, a lookup subunit, and an action execution subunit. Step 103 may include, but is not limited to, steps 901 to 904.
[0137] Step 901, parsing the target data through the parser subunit to obtain the target protocol feature.
[0138] Step 902, extracting the target matching key value from the target protocol feature through the key-value extraction subunit.
[0139] Step 903, looking up the corresponding target action instruction in the updated reconfigurable matching table according to the target matching key value through the lookup subunit.
[0140] Step 904, performing data processing on the target data according to the target action instruction through the action execution subunit.
[0141] In step 901 of some embodiments, after receiving the data packet to be processed, the parser subunit strips the data packet headers layer by layer according to the preset protocol parsing order. First, it parses the Ethernet header to obtain the source MAC address, destination MAC address, and Ethernet type field; then, based on the Ethernet type field, it determines that the upper-layer protocol is the IP protocol and continues to parse the source IP address, destination IP address, protocol type, and TTL value in the IP header; if the upper layer is the TCP protocol, it further parses the source port, destination port, and flag bits in the TCP header. The protocol fields extracted in the parsing process are output in the form of metadata to form a complete target protocol feature for use by subsequent processing units.
[0142] In step 902 of some embodiments, the key-value extraction subunit dynamically combines keyword fields from the target protocol feature according to the matching rules configured by the current pipeline processing logic. For example, in the traffic classification stage, it extracts the source IP address, destination IP address, protocol type, source port, and destination port and concatenates them into a 104-bit five-tuple matching key value; in the application identification stage, it extracts the Host field in the HTTP request and calculates its hash value to generate a 32-bit application-layer matching key value. The extracted key values are transmitted to the lookup subunit through a dedicated data path.
[0143] In step 903 of some embodiments, after receiving the target matching key value, the lookup subunit performs a parallel lookup operation in the updated reconfigurable matching table. During the lookup process, all table entries are compared with the input key value simultaneously. If there are multiple matching entries, it selects the entry with the highest priority and reads the corresponding action instruction address from it (such as the microcode storage location pointing to "forward to port 5"). When there is no match, it returns the default action instruction to ensure the integrity of the data processing flow.
[0144] In step 904 of some embodiments, the action execution subunit performs specific operations according to the target action instruction. For example, when modifying the TTL value or rewriting the MAC address, it directly operates on the data packet header fields; during the processing, it synchronously updates the metadata status, and the processed data packet is sent to the output queue to wait for direct output or is passed to the processor cluster for further processing. If the action is to discard, it releases the data packet buffer and generates a statistical count.
[0145] Through steps 901 to 904, through the pipelined processing of parsing, key-value extraction, lookup, and action execution, this solution achieves efficient and flexible data processing capabilities. The multi-layer protocol parsing of the parser subunit ensures the integrity of protocol features. The dynamic combination mechanism of the key-value extraction subunit adapts to the matching requirements of different service scenarios. The hardware-accelerated lookup of the reconfigurable match table reduces the matching latency to the microsecond level. The microcode-driven operation of the action execution subunit ensures the accuracy and consistency of processing actions. Each subunit is tightly connected to the hardware pipeline through a dedicated data path, while maintaining the line rate forwarding performance, supporting the dynamic update of service policies, and meeting the dual requirements of modern network devices for high performance and high flexibility.
[0146] As Figure 10 shown, in some embodiments, step 904 may include, but is not limited to, steps 1001 to 1004.
[0147] Step 1001, when the action execution subunit detects that the target action instruction is a security filtering instruction, extract the abnormal filtering list from the target action instruction.
[0148] Step 1002, match the data source address of the target data against the abnormal address filtering list.
[0149] Step 1003, in response to a successful match of the data source address, discard the target data and generate a security event log.
[0150] Step 1004, in response to a failed match of the data source address, add a security marking field to the target data.
[0151] In step 1001 of some embodiments, when the action execution subunit detects that the target action instruction is a security filtering instruction, parse out the preset abnormal filtering list from the instruction data payload. The abnormal filtering list contains a set of illegal data source addresses to be intercepted, such as an IP address blacklist and a malicious MAC address list.
[0152] In step 1002 of some embodiments, the action execution subunit extracts the data source address from the protocol features of the target data (such as the source MAC address of an Ethernet frame and the source IP address of an IP packet), and compares it with the entries in the abnormal filtering list.
[0153] In step 1003 of some embodiments, if the data source address matches successfully in the abnormal filtering list, the action execution subunit immediately discards the target data packet, releases the buffer resources it occupies, and records the discard operation through a hardware event counter. At the same time, write the security event log (including timestamp, source address, match rule ID) into the preset security log register for external security management systems to read and analyze.
[0154] In step 1004 of some embodiments, if the data source address is not successfully matched in the abnormal filtering list, the action execution subunit adds a security tag field in the metadata area of the target data, and the tag is used to indicate that the data has passed the preliminary security check. Subsequent pipeline processing stages or network interfaces can perform differential processing based on this tag, thereby eliminating the need to repeatedly perform source address filtering.
[0155] Through steps 1001 to 1004, this embodiment implements an efficient security filtering mechanism at the hardware level: the action execution subunit directly parses the security instructions and loads the filter list, uses the hardware parallel matching capability to complete the source address verification at the nanosecond level, immediately discards malicious data and generates an audit log when the match is successful, and adds a tag field when the match fails for subsequent modules to quickly identify legitimate traffic, and reduces the repeated verification overhead through the tag transmission mechanism, thereby maintaining line-speed processing performance while ensuring network security.
[0156] In some embodiments, the target action instruction may also be a protocol header modification instruction. When the action execution subunit detects that the target action instruction is a protocol header modification instruction, the protocol header field to be modified and the new value are parsed from the instruction data payload. Then, the target protocol header field is located according to the modification position parameter, and the corresponding field in the data packet memory is directly modified through the hardware bit operation circuit, and the modified data packet is sent to the next processing stage or output queue.
[0157] The data processing method proposed in the embodiment of the present application realizes the dynamic update of data processing logic through the direct connection architecture between the local trusted processing unit and the pipeline processing unit. First, the local trusted processing unit directly converts the pipeline configuration information into hardware-recognizable configuration instructions based on the preset pipeline extension instruction set, and stores it in the dedicated instruction register; the pipeline processing unit reads the configuration instructions in the register in real time through the signal line, and completes the online logic reconstruction of the core components such as the parser and the matching table without interrupting the data processing flow. Since the generation, storage and reading of the configuration instructions are all completed in the local trusted environment, the security risks of external configuration injection are avoided. At the same time, the direct connection mechanism of the dedicated instruction register bypasses the delay bottleneck of traditional memory or bus access, so that the switching of the pipeline strategy can take effect instantly during the data packet processing interval. Compared with the existing technology that relies on offline compilation or external channels, it can quickly reconfigure the data processing logic of the network device online while ensuring the continuity of the device business.
[0158] See also Figure 11 , Figure 11 The hardware structure of an electronic device of another embodiment is illustrated, and the electronic device includes:
[0159] The processor 1101 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application;
[0160] The memory 1102 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 1102 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1102 and are called by the processor 1101 to execute the data processing method of the embodiments of the present application;
[0161] The input / output interface 1103 is used to implement information input and output;
[0162] The communication interface 1104 is used to implement communication interaction between this device and other devices, and can implement communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as mobile network, WIFI, Bluetooth, etc.);
[0163] The bus 1105 transmits information between the various components of the device (such as the processor 1101, the memory 1102, the input / output interface 1103, and the communication interface 1104);
[0164] Among them, the processor 1101, the memory 1102, the input / output interface 1103, and the communication interface 1104 achieve communication connections with each other inside the device through the bus 1105.
[0165] The embodiments of the present application also provide a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the above-mentioned data processing method is implemented.
[0166] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0167] The data processing method proposed in the embodiment of the present application realizes the dynamic update of data processing logic through the direct connection architecture between the local trusted processing unit and the pipeline processing unit. First, the local trusted processing unit directly converts the pipeline configuration information into hardware-recognizable configuration instructions based on the preset pipeline extension instruction set, and stores it in the dedicated instruction register; the pipeline processing unit reads the configuration instructions in the register in real time through the signal line, and completes the online logic reconstruction of the core components such as the parser and the matching table without interrupting the data processing flow. Since the generation, storage and reading of the configuration instructions are all completed in the local trusted environment, the security risks of external configuration injection are avoided. At the same time, the direct connection mechanism of the dedicated instruction register bypasses the delay bottleneck of traditional memory or bus access, so that the switching of the pipeline strategy can take effect instantly during the data packet processing interval. Compared with the existing technology that relies on offline compilation or external channels, it can quickly reconfigure the data processing logic of the network device online while ensuring the continuity of the device business.
[0168] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0169] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0170] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0171] Those of ordinary skill in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or a suitable combination thereof.
[0172] As used in the specification of this application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data may be interchanged under appropriate circumstances so that the embodiments of the application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0173] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the relationship between associated objects and indicates that three relationships may exist. For example, "A and / or B" may mean: only A exists, only B exists, and both A and B exist simultaneously. Here, A and B may be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or a similar expression means any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c may mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c may be single or multiple.
[0174] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned unit division is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other may be through some interfaces, and the indirect coupling or communication connection of devices or units may be in electrical, mechanical, or other forms.
[0175] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0176] In addition, each functional unit in various embodiments of the present application may be integrated into a processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0177] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store programs.
[0178] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall fall within the scope of the rights of the embodiments of the present application.
Claims
1. A data processing method, characterized in that: Applied to a network device, the network device includes a local trusted processing unit and a pipeline processing unit, the local trusted processing unit has a built-in instruction register supporting fast reading and writing, the pipeline processing unit is connected to the instruction register via a signal line, and the method includes: The local trusted processing unit receives the pipeline configuration information, and according to the pre-configured pipeline extension instruction set, converts the pipeline configuration information into corresponding pipeline configuration instructions, and stores the pipeline configuration instructions in the instruction register; The pipeline processing unit reads the pipeline configuration instruction from the instruction register, and dynamically updates the pipeline processing logic according to the pipeline configuration instruction to obtain an updated target pipeline processing logic; The pipeline processing unit acquires the data to be processed, and processes the data to be processed according to the target pipeline processing logic to obtain a pipeline processing result.
2. The data processing method according to claim 1, characterized in that: The network device further includes a network interface. Before the pipeline processing unit obtains the data to be processed, the method further includes: receiving the data to be processed from an external network through the network interface, and inputting the data to be processed into the pipeline processing unit; After the data to be processed is processed according to the target pipeline processing logic to obtain the pipeline processing result, the method further includes: The pipeline processing unit sends the pipeline processing result to the network interface in response to the pipeline processing result indicating that the processing of the to-be-processed data is completed; The target network address is obtained through the network interface, and the pipeline processing result is sent to the target network address.
3. The data processing method according to claim 2, characterized in that: The network device further comprises a processor cluster, the processor cluster is built with a data exchange register supporting fast reading and writing, and the pipeline processing unit is connected to the data exchange register via a signal line; After the pipeline processing unit acquires the data to be processed and processes the data to be processed according to the target pipeline processing logic to obtain the pipeline processing result, the method further includes: The pipeline processing unit stores the pipeline processing result in the data exchange register in response to the pipeline processing result indicating that the data to be processed needs to enter the processor cluster for data processing; The processor cluster reads the pipeline processing result from the data exchange register, and performs data processing on the pipeline processing data according to a preset processor processing logic to obtain a processor processing result; The processor cluster stores the processor processing result in the data exchange register; The pipeline processing unit reads the processor processing result from the data exchange register, and formats and encapsulates the processor processing result according to the target pipeline processing logic to obtain a target processing result; The pipeline processing unit sends the pipeline processing result to the network interface; The target network address is obtained through the network interface, and the pipeline processing result is sent to the target network address.
4. The data processing method according to claim 1, characterized in that: The step of converting the pipeline configuration information into corresponding pipeline configuration instructions according to the pre-configured pipeline extension instruction set includes: Performing syntax analysis on the pipeline configuration information to obtain matching table reconstruction information; The matching table reconstruction information is converted into a pipeline configuration instruction recognizable by the pipeline processing unit based on the pipeline extension instruction set.
5. The data processing method according to claim 4, characterized in that: The dynamically updating the pipeline processing logic according to the pipeline configuration instruction to obtain the updated target pipeline processing logic includes: Parsing the pipeline configuration instruction to obtain the entry to be updated in the matching table; Querying a target storage location of the entry to be updated in the reconfigurable matching table; The entry to be updated in the matching table is stored in a target storage location in the reconfigurable matching table to obtain an updated reconfigurable matching table.
6. The data processing method according to claim 5, characterized in that: The step of storing the entry to be updated in the matching table into a target storage location in the reconfigurable matching table to obtain an updated reconfigurable matching table includes: Acquire the data processing status of the pipeline processing unit in real time; If the data processing state indicates that the current state is an idle processing state, writing the entry to be updated in the matching table into a target storage location in the reconfigurable matching table to obtain an updated reconfigurable matching table; If the data processing state indicates that the current state is the processing state, wait for the data processing state to be converted into the idle processing state, write the entry to be updated in the matching table into the target storage position in the reconfigurable matching table, and obtain an updated reconfigurable matching table.
7. The data processing method according to claim 5, characterized in that: The pipeline processing unit includes a parser subunit, a key value extraction subunit, a search subunit and an action execution subunit, and the data to be processed is processed according to the target pipeline processing logic to obtain a pipeline processing result, including: Parsing the target data by the parser subunit to obtain target protocol features; Extracting a target matching key value from the target protocol feature by the key value extraction subunit; Searching the corresponding target action instruction in the updated reconfigurable matching table according to the target matching key value by the search subunit; The target data is processed by the action execution subunit according to the target action instruction.
8. The data processing method according to claim 7, characterized in that: The performing data processing on the target data according to the target action instruction by the action execution subunit includes: When the target action instruction is detected as a security filtering instruction by the action execution subunit, an abnormal filtering list is extracted from the target action instruction; Matching the data source address of the target data with the abnormal address filtering list; In response to the data source address successfully matching, discarding the target data and generating a security event log; In response to the data source address matching failure, a security tag field is added to the target data.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores a computer program, and the processor implements the data processing method according to any one of claims 1 to 8 when executing the computer program.
10. A computer-readable storage medium, characterized in that: The storage medium stores a program, and the program is executed by the processor to implement any one of claims 1-8 The data processing method described in item.