Method and device for managing flow table items and electronic equipment

By rewriting the tree structure of the flow table entry into a relational structure and storing it in a relational database, the memory limitation problem of SDN controllers when storing flow table entry in large capacity is solved, significantly improving stability and read and write performance.

CN120186067APending Publication Date: 2025-06-20RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311771386.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-20
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the data center, because the flow table entries occupy a large amount of memory, the stability and garbage collection pressure of the SDN controller are increasing, making it difficult to support large-capacity storage flow table entries.

Method used

By rewriting the tree structure of the flow table entry into a relational structure and storing it in a relational database, avoiding occupancy of the SDN controller's memory, thereby achieving mass storage of flow table entry.

Benefits of technology

It significantly improves the stability and read and write performance of SDN controllers, reduces the pressure of garbage collection, and supports larger data centers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186067A_ABST
    Figure CN120186067A_ABST
Patent Text Reader

Abstract

The invention provides a method and a device for managing flow table items and electronic equipment, which are used for avoiding the problem that a large-capacity flow table cannot be stored in an SDN (Software Defined Network) controller due to the limitation of a physical memory of a server at present. The method comprises the following steps: receiving flow table item information; wherein the flow table item information comprises a flow table item and a service rule identifier corresponding to the flow table item, and a data structure of the flow table item is a tree structure; based on the business rule identifier, rewriting the tree structure into a relational structure; wherein the relational structure comprises the service rule identifier and a target field of the flow table item; and based on the relational database, storing the relational structure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technologies, and in particular, to a method, an apparatus, and an electronic device for managing flow table entries. Background Art

[0002] Compared with traditional networks, Software Defined Network (SDN) has shown significant improvements in terms of scale, functionality, control, and flexibility. The SDN controller realizes unified management of all network devices through southbound interface protocols such as Openflow and Netconf, thus playing the role of a traditional network deployment model: the SDN controller converts the security group that provides network security functions externally into a flow table for storage and issues the flow table configuration.

[0003] The flow table, as an important data structure used to implement traffic forwarding and processing in network switching devices, realizes functions such as routing, forwarding, filtering, and load balancing of data packets by matching the characteristics of data packets and executing corresponding operations. The flow table is a tree structure defined by Yang and is stored in the tree database of the SDN controller: the in-memory database DataStore. Please refer to Figure 1 , in the data center scenario, the flow table entries are issued to the virtual switch (VitrualSwitch, abbreviated as vSwitch) on the computing node. The vSwitch processes the data packets through the flow table entries and transmits the processed data packets between the virtual machines (Virtual Machine, abbreviated as VM) on the computing node. As Figure 1 shown, the flow table entries issued by the SDN controller to the vSwitch are control flows, and the data packets transmitted between VMs constitute data flows. Among them, the border device of the data center network is used to connect the internal network of the data center and the external network (for example, the Internet), and it is responsible for processing the traffic exchange and connection between the data center and the external network, providing functions such as security, routing, and connection management. The backbone device (Spine) is used to connect devices at different levels of the network architecture in the data center, such as Leaf devices, Border devices, and other Spine devices, to provide efficient forwarding and routing of internal data center traffic. The leaf device (Leaf) plays the role of connecting internal servers, storage devices, and other network devices in the data center, and is used to provide local traffic forwarding and connection within the data center.

[0004] As the scale of the data center increases, the number of computing nodes in the data center also increases, and the space occupied by the flow table also increases accordingly. For example, when the number of computing nodes is 5,000, the number of flow table entries exceeds hundreds of millions. When the flow table entries are stored in the in-memory database DataStore, the average memory occupied by each flow table entry is 2KB, and the total memory space occupied by 100 million flow table entries reaches 200G. It can be seen that the flow table entries occupy a large amount of memory space, and the SDN controller runs on the JAVA virtual machine. Such high heap memory management also poses higher requirements for garbage collection (abbreviated as GC), ultimately making the memory of the server and the stability of the SDN controller face huge challenges. Summary of the Invention

[0005] The present application provides a method, device and electronic device for managing flow table entries to avoid the problem that currently, due to the limitation of the physical memory of the server, a large-capacity flow table cannot be stored in the SDN controller.

[0006] In a first aspect, an embodiment of the present application provides a method for managing flow table entries, including:

[0007] Receiving flow table entry information; wherein, the flow table entry information includes a flow table entry and a service rule identifier corresponding to the flow table entry, and the data structure of the flow table entry is a tree structure;

[0008] Based on the service rule identifier, rewriting the tree structure into a relational structure; wherein, the relational structure includes the service rule identifier and the target field of the flow table entry;

[0009] Based on the relational database, saving the relational structure.

[0010] In the method provided by the embodiment of the present application, according to the service rule identifier, the data structure of the flow table entry (the tree structure defined by Yang) is rewritten into a relational structure, so as to achieve the purpose of storing the flow table entries of the relational structure through the relational database, thereby avoiding the problem that it is difficult to support large-capacity storage of flow table entries on the SDN controller due to the limitation of the physical memory of the server, and reducing the heap memory required by the SDN controller, reducing the pressure on the SDN controller's GC, and significantly improving the stability of the SDN controller.

[0011] A possible implementation manner, the saving the relational structure based on the relational database specifically includes: saving the relational structure to the disk of the SDN controller through the relational database.

[0012] In this implementation manner, based on the relational database, the relational structure is saved to the disk of the SDN controller, which significantly improves the capacity of the flow table entries that can be stored in the SDN controller.

[0013] A possible implementation manner, based on the service rule identifier, rewriting the tree structure into a relational structure includes:

[0014] Based on the service rule identifier and the tree structure, determining a string; wherein, the string includes the target field recorded in the tree structure;

[0015] Based on the string, determining the relational structure; wherein, the relational structure includes the string.

[0016] A possible implementation manner, based on the service rule identifier and the tree structure, determining a string includes:

[0017] Based on the service rule identifier, determining a string format; wherein, the string format includes the attribute field of the target field of the flow table entry and the order of the attribute field in the string;

[0018] In the tree structure, extracting the attribute value corresponding to the attribute;

[0019] Based on the string format, splicing the attribute values to obtain the string.

[0020] A possible implementation manner, based on the string, determining the relational structure includes:

[0021] Based on the corresponding relationship between the service rule identifier and the string, determining a two-dimensional table; wherein, the attribute columns of the two-dimensional table include the service rule identifier and the string.

[0022] In this implementation manner, by using the service rule identifier and the string to determine the two-dimensional table, all relational structures are stored in a single two-dimensional table, thus effectively improving the read and write performance of the flow table entries.

[0023] A possible implementation manner, the relational structure further includes an identifier of a target device corresponding to the flow table entry;

[0024] Then, after saving the relational structure based on the relational database, it further includes:

[0025] Based on the identifier of the target device, querying a first flow table entry stored in the target device; wherein, the first flow table entry is a tree structure;

[0026] Based on the identifier of the target device, reading a target string corresponding to the target device in the relational database;

[0027] In response to the first flow entry not matching the target string, modify the first flow entry based on the target string.

[0028] By invoking the target string corresponding to the target device in the relational structure and the first flow entry stored in the target device, verify the first flow entry stored in the target device, so as to correct the first flow entry in a timely manner and reduce the impact on services caused by incorrect information in the flow entry.

[0029] A possible implementation, the step of in response to the first flow entry not matching the target string, modifying the first flow entry based on the target string includes:

[0030] Based on the service rule identifier corresponding to the target string, rewrite the target string into a tree structure to obtain a second flow entry;

[0031] In response to the tree structure of the first flow entry not matching the tree structure of the second flow entry, in the second flow entry, determine the attribute field that corresponds to and is different from the first flow entry as the key field;

[0032] Send the key field and the attribute value of the key field to the target device, so that the device modifies the first flow entry; wherein, the attribute of the key field corresponds to the attribute value of the key field.

[0033] In a second aspect, an embodiment of the present application provides an apparatus for managing flow entries, including:

[0034] A receiving unit, configured to receive flow entry information; wherein, the flow entry information includes a flow entry and a service rule identifier corresponding to the flow entry, and the data structure of the flow entry is a tree structure;

[0035] A rewriting unit, configured to rewrite the tree structure into a relational structure based on the service rule identifier; wherein, the relational structure includes the service rule identifier and the target field of the flow entry;

[0036] A saving unit, configured to save the relational structure based on the relational database.

[0037] A possible implementation, save the relational structure to the disk of the SDN controller through the relational database.

[0038] A possible implementation, the rewriting unit is specifically configured to determine a string based on the service rule identifier and the tree structure; wherein, the string includes the target field recorded in the tree structure; determine the relational structure based on the string; wherein, the relational structure includes the string.

[0039] A possible implementation manner, wherein the rewriting unit is specifically configured to determine a string format based on a service rule identifier; wherein the string format includes an attribute field of a target field of the flow table entry and an order of the attribute field in the string; in the tree structure, extract an attribute value corresponding to the attribute; and splice the attribute values based on the string format to obtain the string.

[0040] A possible implementation manner, wherein the rewriting unit is specifically configured to determine a two-dimensional table based on a correspondence between the service rule identifier and the string; wherein an attribute column of the two-dimensional table includes the service rule identifier and the string.

[0041] A possible implementation manner, wherein the relational structure further includes an identifier of a target device corresponding to the flow table entry; then the apparatus further includes a matching unit, and the matching unit is specifically configured to query a first flow table entry stored in the target device based on the identifier of the target device; wherein the first flow table entry is in a tree structure; read a target string corresponding to the target device in the relational database based on the identifier of the target device; and in response to a match between the first flow table entry and the target string, modify the first flow table entry based on the target string.

[0042] A possible implementation manner, wherein the matching unit is further configured to rewrite the target string into a tree structure based on the service rule identifier corresponding to the target string to obtain a second flow table entry; in response to a non-conformity between the tree structure in the first flow table entry and the tree structure in the second flow table entry, determine, in the second flow table entry, an attribute field corresponding to and different from the first flow table entry as a key field; and send the key field and an attribute value of the key field to the target device so that the device modifies the first flow table entry; wherein the attribute of the key field corresponds to the attribute value of the key field.

[0043] In a third aspect, an embodiment of the present application further provides a readable storage medium, including,

[0044] a memory,

[0045] The memory is configured to store a computer program, and when the computer program is executed by a processor, it causes an apparatus including the readable storage medium to complete the method as described in the first aspect and any possible implementation manner.

[0046] In a fourth aspect, an embodiment of the present application provides an electronic device, including:

[0047] a memory for storing a computer program;

[0048] A processor, when executing the computer program stored on the memory, is configured to implement the method as described in the first aspect and any possible implementation manner.

[0049] One or more technical solutions provided in the embodiments of the present invention have at least the following technical effects:

[0050] First, in the method for managing flow table entries provided in the embodiments of the present application, according to the service rule identifier in the received flow table entry information, the flow table entry with a tree structure defined by Yang in the data structure is rewritten into a relational structure, so as to achieve the purpose of storing the relational structure based on a relational database. In this way, the large-capacity storage requirement of the SDN controller is no longer limited by physical memory, which helps to increase the scale of the data center managed by the SDN controller. Moreover, since the heap memory required by the SDN controller is significantly reduced, the pressure on the SDN controller's GC is reduced, thereby significantly improving the stability of the SDN controller.

[0051] Second, when the attribute values corresponding to the attribute fields of the flow table entry are aggregated into a string, and a two-dimensional table is set for the relational structure in combination with the attribute fields corresponding to the service rule identifier, in fact, each element is used as an attribute column to form a single two-dimensional table. In this way, the reading and writing efficiency of the flow table entry can be effectively improved, and problems such as low reading and writing efficiency and resource consumption caused by separately setting the target field or attribute field in multiple tables for association can be avoided.

[0052] Other features and advantages of the present application will be described in the following specification, and some of them will become obvious from the specification or be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. Description of the Drawings

[0053] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0054] Figure 1 A schematic diagram of a data center scenario applicable to the embodiments of the present application;

[0055] Figure 2 A flowchart of a method for managing flow table entries provided in the embodiments of the present application;

[0056] Figure 3 Schematic diagram of a tree structure of flow table entries provided by an embodiment of the present application;

[0057] Figure 4 Flow chart of a method for determining a relational structure provided by an embodiment of the present application;

[0058] Figure 5 Schematic diagram of a structure of a device for managing flow table entries provided by an embodiment of the present application;

[0059] Figure 6 Schematic diagram of a structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0060] To better understand the above technical solutions, the technical solutions of the present application will be described in detail below through the accompanying drawings and specific embodiments. It should be understood that the specific features in the embodiments of the present application and the embodiments are detailed descriptions of the technical solutions of the present application, rather than limitations on the technical solutions of the present application. Without conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.

[0061] The terms "first" and "second" in the specification, claims and drawings of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices. "Multiple" in the present application may represent at least two, for example, it may be two, three or more, and the embodiments of the present application do not make limitations.

[0062] The inventive concept of the embodiments of the present application will be briefly introduced as follows:

[0063] Although the traditional technology increases the memory of the SDN controller to increase the capacity of the in-memory database (DataStore), thereby increasing the storage space for flow table entries. However, due to the limited physical memory of the server, and in the case of a large-capacity flow table scenario, it is easy to have frequent GCs and long GC times, resulting in the stability of the SDN controller not being guaranteed. Therefore, currently limited by the physical memory of the server, the storage problem of large-capacity flow tables needs to be solved urgently.

[0064] In view of the above problems, an embodiment of the present application provides a method for managing flow table entries. By converting the tree structure of flow table entries into a relational structure for storage in a relational database, it avoids occupying SDN memory, thereby achieving the purpose of storing a large number of flow tables on the SDN controller without being limited by the physical memory of the server, and avoiding the situation where the SDN controller has unstable performance due to occupying its memory.

[0065] Please refer to Figure 2 , the present application proposes a method for managing flow table entries, which can be applied to an SDN controller. The method specifically includes the following implementation steps:

[0066] Step 201: Receive flow table entry information.

[0067] Among them, the flow table entry information includes a flow table entry and a service rule identifier corresponding to the flow table entry.

[0068] The service rule identifier can correspond one-to-one with the forwarding rules in the corresponding service scenarios.

[0069] In some embodiments, the service rule identifier can be a service rule code (full name: Rule Identity document, abbreviation: Rule ID).

[0070] Furthermore, the above flow table entry information includes a flow table identifier of the flow table entry, so that after the flow table entry is sent to the target device, the target device can determine the flow table in which the flow table entry is stored based on the flow table identifier.

[0071] The data structure of the flow table entry is a tree structure. The tree structure includes the target field of the flow table entry, the attribute field of the target field, and the attribute value of the attribute field.

[0072] The difference between the above target field and the attribute field is that in each flow table entry, the attribute field uniquely corresponds to the attribute value, while the target field can contain multiple attribute fields. And because different flow table entries correspond to forwarding rules in different service scenarios, the attribute fields of the same target field in different flow table entries can be the same or different.

[0073] Figure 3 FIG. is a schematic diagram of a tree structure of a flow table entry provided by an embodiment of the present application. As Figure 3 shown, the target fields in the tree structure include a match field and an instruction set field. And both match and instruction, as target fields, include multiple attribute fields.

[0074] The above match field is used to match data packets; the instruction set field is used to process data packets based on the instruction set after the data packets match successfully with the match field.

[0075] Further, the above target fields may further include Priority and Counters.

[0076] Among them, the priority is used to indicate the order of matching packets when there is the same matching domain. The counter is used to count the number of packets that match this flow table entry in the target device after the flow table entry is sent to the target device.

[0077] Please continue to refer to Figure 3 , in the tree structure of the flow table entry, in addition to the target fields, it also includes the identifier (device ID) of the target device corresponding to this flow table entry. Then, based on the identifier of the target device and according to the OpenFlow protocol, the flow table entry can be sent to the target device, so that the target device can determine the flow table according to the received flow table entry to process the received packets.

[0078] Step 202: Rewrite the tree structure into a relational structure based on the service rule identifier.

[0079] Among them, the relational structure includes the service rule identifier and the target fields of the flow table entry.

[0080] Specifically, in this relational structure, the target fields of the flow table entry corresponding to the service rule can be rewritten as a string. The following is a detailed description, please refer to Figure 4 :

[0081] Step 401: Determine the string based on the service rule identifier and the tree structure.

[0082] Among them, the string includes the target fields recorded in the tree structure. The target fields include the attribute values of its attribute fields.

[0083] The attribute values of the attribute fields are determined according to the information recorded in the tree structure. The attribute values of the attribute fields can be one or more digital codes.

[0084] Specifically, in the current data center scenario, the types of flow table entries used in the SDN controller are 90. In each type of flow table entry, the attribute fields of the matching domain field and the instruction set field are fixed, while the attribute values corresponding to the attribute fields vary with the type of the flow table entry.

[0085] Each of the above flow table entries is actually divided according to the forwarding rules in the service scenario. Therefore, according to the service rule identifier indicating the forwarding rules in the service scenario, the attribute fields of the target fields in the corresponding flow table entry can be determined. The target fields at least include the matching domain field and the instruction set field.

[0086] Meanwhile, the service rule identifier can also be used to indicate: the order of the predefined attribute fields and the connection method of the attribute values of the attribute fields, for example, connecting each attribute value through a delimiter. The delimiter can be "@".

[0087] In this way, the string format can be determined first through the service rule identifier. The string format includes the attribute fields of the target field of the flow table entry and the order of the attribute fields in the string, and the connection method of the attribute values corresponding to the attribute fields.

[0088] Then, according to the attribute fields in the string format, the attribute values corresponding to the attribute fields are extracted from the tree structure of the flow table entry.

[0089] Finally, based on the connection order of the attribute values specified by the string format, the attribute values are concatenated to obtain a string.

[0090] The following are examples of forwarding rules and their service rule identifiers in several service scenarios, the attribute fields of the target field determined according to the service rule identifier, the attribute values corresponding to the attribute fields extracted from the flow table entry, and the finally determined string. In this example, the attribute values in the string are connected by the delimiter "@". Please refer to Table 1.

[0091] Table 1

[0092]

[0093] Note: ARP refers to the Address Resolution Protocol, and its full English name is Address Resolution Protocol.

[0094] Step 402: Determine the relational structure based on the string.

[0095] Among them, the relational structure includes a string.

[0096] This relational structure includes at least a service rule identifier and a string.

[0097] Among them, the service rule identifier is used to indicate the string format, that is, to indicate the attribute fields corresponding to each array in the string as attribute values and the target fields to which the attribute fields belong.

[0098] Then, in order to further improve the read and write performance of the SDN controller for flow table entries, in some embodiments, a two-dimensional table can be determined based on the correspondence between the service rule identifier and the string.

[0099] Among them, the attribute columns of the two-dimensional table include a service rule identifier and a string. In the two-dimensional table, each row corresponds to the above information of a flow table entry.

[0100] In some embodiments, the relational structure includes a target device identifier and / or a flow table entry identifier.

[0101] Among them, the target device identifier is used to indicate the device that receives the flow table entry. The target device identifier corresponds to the device that stores the flow table entry. The flow table entry identifier is used by the SDN controller to query the flow table entry. The flow table entry identifier corresponds to the flow table entry one by one.

[0102] When the relational structure includes the aforementioned information at the same time, the two-dimensional table attribute columns are composed of the aforementioned information, namely the target device identifier, the flow table entry identifier, the service rule identifier, and the string. Please refer to Table 2.

[0103] Table 2

[0104] Identifier of the target device Identifier of the flow table entry Business rule identifier String …… …… …… …… …… …… …… …… …… …… …… ……

[0105] Step 203: Save the relational structure based on the relational database.

[0106] The relational database includes but is not limited to oracle (full name: Oracle Database), db2 (full name: db2 universal database), sybase (full name: sybase Database).

[0107] Specifically, the relational structure can be saved to the SDN controller through the relational database.

[0108] After saving the relational structure, consistency reconciliation can be performed to ensure that the flow table entries in the target device are correct.

[0109] The consistency reconciliation can be performed at regular intervals or when the target device goes online each time. The following is a detailed description:

[0110] First, based on the identifier of the target device, query the flow table entries stored in the target device, denoted as the first flow table entries. Here, the query is still based on OpenFlow, and the data structure of the first flow table entries is a tree structure.

[0111] Then, based on the identifier of the target device, read the target string corresponding to the target device in the relational database. At the same time, read the device rule identifier corresponding to the target string to facilitate determining the attribute fields corresponding to the arrays used as attribute values in the target string.

[0112] Finally, compare the first flow table entries with the target string. Based on the response that the first flow table entries do not match the target string, modify the first flow table entries based on the target string. That is, record the attribute fields and / or attribute values in the target string that do not match the first flow table entries, and reissue them to the target device to cause the target device to make corresponding modifications.

[0113] When reading the target string corresponding to the target device in the database according to the identifier of the target device, the service rule identifier corresponding to the target string is also read. Then, according to the string format corresponding to the service rule identifier, the array used as the attribute value in the target string, as well as the attribute field and target field corresponding to the attribute value can be determined.

[0114] Thus, in some embodiments, based on the service rule identifier corresponding to the target string, the target string can be rewritten into a tree structure to facilitate comparison with the first flow table entry in the tree structure. Then the second flow table entry is obtained.

[0115] In response to the tree structure of the first flow table entry not matching the tree structure of the second flow table entry, in the second flow table entry, the attribute field that corresponds to and is different from the first flow table entry is determined as the key field. Here, corresponding and different means that on the nodes at the corresponding positions in the tree structure, the nodes with different attribute fields.

[0116] The attribute value of the key field in the second flow table entry together with the key field is sent to the target device, so that the device can make corresponding modifications in the first flow table entry according to the key field and the attribute value of the key field.

[0117] Thus, after performing consistency reconciliation, the information to be modified is sent to the target device, enabling the target device to make timely modifications.

[0118] The above target device can be a virtual switch.

[0119] Based on the same inventive concept, an apparatus for managing flow table entries is provided in an embodiment of the present application. This apparatus corresponds to the Figure 2 method for managing flow table entries shown above. The specific implementation of this apparatus can refer to the description in the method embodiment part above. For repeated parts, they will not be elaborated again. Refer to Figure 5 , this apparatus includes:

[0120] A receiving unit 501, configured to receive flow table entry information.

[0121] Wherein, the flow table entry information includes a flow table entry and a service rule identifier corresponding to the flow table entry, and the data structure of the flow table entry is a tree structure;

[0122] A rewriting unit 502, configured to rewrite the tree structure into a relational structure based on the service rule identifier.

[0123] Wherein, the relational structure includes the service rule identifier and the target field of the flow table entry.

[0124] The rewriting unit 502 is specifically configured to determine a string based on the service rule identifier and the tree structure; wherein, the string includes the target field recorded in the tree structure; and determine the relational structure based on the string; wherein, the relational structure includes the string.

[0125] The rewriting unit 502 is specifically configured to determine a string format based on the service rule identifier; wherein, the string format includes the attribute field of the target field of the flow table entry and the order of the attribute field in the string; extract the attribute value corresponding to the attribute in the tree structure; and splice the attribute value based on the string format to obtain the string.

[0126] The rewriting unit 502 is specifically configured to determine a two-dimensional table based on the correspondence between the service rule identifier and the string; wherein, the attribute columns of the two-dimensional table include the service rule identifier and the string.

[0127] The saving unit 503 is configured to save the relational structure based on the relational database.

[0128] Save the relational structure to the disk of the SDN controller through the relational database.

[0129] The relational structure further includes an identifier of a target device corresponding to the flow table entry; then the apparatus further includes a matching unit, and the matching unit is specifically configured to query a first flow table entry stored in the target device based on the identifier of the target device; wherein, the first flow table entry is a tree structure; read a target string corresponding to the target device in the relational database based on the identifier of the target device; and modify the first flow table entry based on the target string in response to a match between the first flow table entry and the target string.

[0130] The above-mentioned matching unit is further configured to rewrite the target string into a tree structure based on the service rule identifier corresponding to the target string to obtain a second flow table entry; in response to a mismatch between the tree structure in the first flow table entry and the tree structure in the second flow table entry, determine an attribute field that corresponds to and is different from the first flow table entry in the second flow table entry as a key field; and send the key field and the attribute value of the key field to the target device so that the device modifies the first flow table entry; wherein, the attribute of the key field corresponds to the attribute value of the key field.

[0131] Based on the same inventive concept, an embodiment of the present application further provides a readable storage medium, including:

[0132] A memory,

[0133] The memory is used to store a computer program, which, when executed by a processor, enables the device including the readable storage medium to complete the method for managing flow table entries as described above.

[0134] Based on the same inventive concept as the above method for managing flow table entries, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing method for managing flow table entries. Please refer to Figure 6 , the electronic device includes:

[0135] At least one processor 601 and a memory 602 connected to the at least one processor 601. In the embodiment of the present application, the specific connection medium between the processor 601 and the memory 602 is not limited. Figure 6 In [description], it is taken as an example that the processor 601 and the memory 602 are connected through a bus 600. The bus 600 is represented by a thick line in Figure 6 . The connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 600 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6 it is only represented by a thick line in [description], but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 601 can also be referred to as a controller, and the name is not limited.

[0136] In the embodiment of the present application, the memory 602 stores instructions executable by the at least one processor 601. By executing the instructions stored in the memory 602, the at least one processor 601 can execute the method for managing flow table entries described above. The processor 601 can implement Figure 5 the functions of each module in the device shown in [figure].

[0137] Among them, the processor 601 is the control center of the device. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 602 and calling the data stored in the memory 602, various functions of the device and process data, so as to monitor the device as a whole.

[0138] In a possible design, the processor 601 may include one or more processing units. The processor 601 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 601. In some embodiments, the processor 601 and the memory 602 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.

[0139] The processor 601 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method for managing flow table entries disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0140] The memory 602, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 602 may include at least one type of storage medium, for example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, etc. The memory 602 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 602 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0141] By designing and programming the processor 601, the code corresponding to the method for managing flow table entries introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 2 the steps of the method for managing flow table entries shown. How to design and program the processor 601 is a well-known technology to those skilled in the art and will not be elaborated here.

[0142] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. For the specific working processes of the systems, devices, and units described above, reference can be made to the corresponding processes in the foregoing method embodiments, and details are not described herein again.

[0143] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0144] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0145] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0146] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as a Universal Serial Bus flash disk, a mobile hard disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc.

[0147] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A method for managing flow table entries, characterized in that, including: receiving flow table entry information; wherein, the flow table entry information includes a flow table entry and a service rule identifier corresponding to the flow table entry, and the data structure of the flow table entry is a tree structure; rewriting the tree structure into a relational structure based on the service rule identifier; wherein, the relational structure includes the service rule identifier and the target fields of the flow table entry; saving the relational structure based on the relational database.

2. The method according to claim 1, characterized in that, The saving the relational structure based on the relational database specifically includes: saving the relational structure to the disk of the SDN controller through the relational database.

3. The method according to claim 1 or 2, characterized in that, The rewriting the tree structure into a relational structure based on the service rule identifier includes: determining a string based on the service rule identifier and the tree structure; wherein, the string includes the target fields recorded in the tree structure; determining the relational structure based on the string; wherein, the relational structure includes the string.

4. The method according to claim 3, characterized in that, The determining a string based on the service rule identifier and the tree structure includes: determining a string format based on the service rule identifier; wherein, the string format includes the attribute fields of the target fields of the flow table entry and the order of the attribute fields in the string; extracting the attribute values corresponding to the attributes in the tree structure; concatenating the attribute values based on the string format to obtain the string.

5. The method according to claim 3, characterized in that, The determining the relational structure based on the string includes: determining a two-dimensional table based on the corresponding relationship between the service rule identifier and the string; wherein, the attribute columns of the two-dimensional table include the service rule identifier and the string.

6. The method according to any one of claims 1-2, 4-5, characterized in that, The relational structure further includes the identifier of the target device corresponding to the flow table entry; then after saving the relational structure based on the relational database, it further includes: querying the first flow table entry stored in the target device based on the identifier of the target device; wherein, the first flow table entry is a tree structure; reading the target string corresponding to the target device in the relational database based on the identifier of the target device; in response to the first flow table entry not matching the target string, modifying the first flow table entry based on the target string.

7. The method according to claim 6, characterized in that, The in response to the first flow table entry not matching the target string, modifying the first flow table entry based on the target string includes: rewriting the target string into a tree structure based on the service rule identifier corresponding to the target string to obtain a second flow table entry; in response to the tree structure of the first flow table entry not matching the tree structure of the second flow table entry, determining, in the second flow table entry, the attribute fields corresponding to and different from the first flow table entry as key fields; sending the key fields and the attribute values of the key fields to the target device so that the device modifies the first flow table entry; wherein, the attributes of the key fields correspond to the attribute values of the key fields.

8. A device for managing flow table entries, characterized in that, including: A receiving unit, configured to receive flow table entry information; wherein, the flow table entry information includes a flow table entry and a service rule identifier corresponding to the flow table entry, and the data structure of the flow table entry is a tree structure; A rewriting unit, configured to rewrite the tree structure into a relational structure based on the service rule identifier; wherein, the relational structure includes the service rule identifier and the target field of the flow table entry; A saving unit, configured to save the relational structure based on the relational database.

9. A readable storage medium, characterized in that, Comprising, A memory, The memory is configured to store a computer program, and when the computer program is executed by a processor, the device including the readable storage medium completes the method according to any one of claims 1-7.

10. An electronic device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to execute the computer program stored on the memory to implement the method according to any one of claims 1-7.