Deep data packet detection method, network element equipment and computer readable medium
By decomposing tasks of the computing power resources of the host network element device and using the target auxiliary network element device to collaborate on DPI analysis tasks, the problem of high resource requirements in the existing technology is solved, and the timeliness of business-level perception guarantee is improved.
Patent Information
- Application Number
- CN202311787927.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-06-24
AI Technical Summary
In the prior art, DPI has high requirements for the CPU and memory resources of network element devices, making it difficult to identify and guarantee all services of all users at the same time, affecting user perception and network performance.
By decomposing the computing power resources of the host network element device, the DPI analysis task is divided into non-target first-level DPI decomposition tasks and target first-level DPI decomposition tasks. The target auxiliary network element device is used to coordinate the processing of target first-level DPI decomposition tasks to improve resource utilization.
It realizes the rapid and effective use of the auxiliary computing resources of the host network element equipment for user service-level perception guarantee, and improves the timeliness of service-level perception guarantee.
Smart Images

Figure CN120200930A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular, to a deep packet detection method, a network element device, and a computer-readable medium. Background Art
[0002] DPI (Deep Packet Inspection) is a technology that determines the specific content and information of a service by parsing a data packet, and further obtains the flow service rule according to the behavior characteristics of the packet. After the network device uses the DPI function, it is expected to identify the service type through DPI and perform corresponding service guarantee and enhanced optimization at the air interface. For example, real-time services need to ensure the timeliness of air interface scheduling, large traffic download services are not sensitive to latency but have high requirements for air interface bandwidth resources, and security services can perform conservative scheduling to ensure accuracy, etc.
[0003] However, since DPI has high requirements for the computing power of the CPU (Central Processing Unit), memory resources, etc. of the network element device, it is difficult for the network element device to ensure the identification and guarantee of all services of all users, thus affecting the user perception and network performance of the network element device. Summary of the Invention
[0004] Embodiments of the present disclosure provide a deep packet detection method, a network element device, and a computer-readable medium.
[0005] In a first aspect, an embodiment of the present disclosure provides a deep packet detection method for a host network element device, which includes:
[0006] Based on the idle computing power resources of the host network element device and the computing power resources corresponding to the DPI parsing task, decompose the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task;
[0007] Based on the target first-level DPI decomposition task, receive the target parsing result of the target first-level DPI decomposition task fed back by the target auxiliary network element device corresponding to the host network element device;
[0008] Determine the DPI parsing result of the DPI parsing task according to the target parsing result.
[0009] In a second aspect, an embodiment of the present disclosure provides a deep packet detection method for a target auxiliary network element device, which includes:
[0010] Based on the target first-level DPI decomposition task sent by the host network element device, determine the target parsing result of the target first-level DPI decomposition task;
[0011] Send the target parsing result to the host network element device.
[0012] In a third aspect, an embodiment of the present disclosure provides a network element device, including:
[0013] One or more processors;
[0014] A memory storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the deep packet inspection method described in the first aspect or the second aspect.
[0015] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable medium storing a computer program, which when executed by a processor, implements the deep packet inspection method described in the first aspect or the second aspect.
[0016] The deep packet inspection method provided by the embodiments of the present disclosure decomposes the DPI parsing tasks that cannot be processed by the computing power resources of the host network element device, and sends the decomposed target first-level DPI decomposition tasks to the target auxiliary network element device for collaborative processing, quickly and effectively utilizing the auxiliary computing power resources of the host network element device to ensure user service-level perception, and improving the timeliness of service-level perception guarantee. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a network structure diagram of a core network with an independently deployed DPI processing node provided by an embodiment of the present disclosure;
[0018] Figure 2 It is a network structure diagram of a centralized node device of a network with an independently deployed DPI processing node provided by an embodiment of the present disclosure;
[0019] Figure 3 It is a network structure diagram of a base station with DPI deployed in a downlink provided by an embodiment of the present disclosure;
[0020] Figure 4 It is a network structure diagram of another base station with DPI deployed in a downlink provided by an embodiment of the present disclosure;
[0021] Figure 5 It is a flowchart of a deep packet inspection method provided by an embodiment of the present disclosure;
[0022] Figure 6 It is a flowchart of a specific implementation method of step S2 in an embodiment of the present disclosure;
[0023] Figure 7 It is a flowchart of task decomposition provided by an embodiment of the present disclosure;
[0024] Figure 8Schematic diagram of the first-level DPI decomposition task and its task priority provided by an embodiment of the present disclosure;
[0025] Figure 9 Flowchart of a specific implementation method for step S2 in an embodiment of the present disclosure;
[0026] Figure 10 Flowchart of a specific implementation method for step S21 in an embodiment of the present disclosure;
[0027] Figure 11 Schematic diagram of the structure of a computing power cloud provided by an embodiment of the present disclosure;
[0028] Figure 12 Schematic diagram of the process of an exemplary shared computing power service provided by an embodiment of the present disclosure;
[0029] Figure 13 Schematic diagram of the update of an exemplary first auxiliary computing power list provided by an embodiment of the present disclosure;
[0030] Figure 14 Flowchart of another deep packet detection method provided by an embodiment of the present disclosure;
[0031] Figure 15 Flowchart of a specific implementation method for step 1401 in an embodiment of the present disclosure;
[0032] Figure 16 Schematic diagram of the process of sending a target first-level DPI decomposition task according to the association priority provided by an embodiment of the present disclosure;
[0033] Figure 17 Schematic diagram of the structure of a network element device provided by an embodiment of the present disclosure;
[0034] Figure 18 Schematic diagram of the structure of a computer-readable medium provided by an embodiment of the present disclosure;
[0035] Figure 19 Flowchart of an exemplary deep packet detection method provided by an embodiment of the present disclosure;
[0036] Figure 20 Flowchart of an exemplary deep packet detection method provided by an embodiment of the present disclosure when the idle computing power resources of the host network element device are insufficient. Detailed implementation manners
[0037] To enable those skilled in the art to better understand the technical solutions of the present disclosure, the control method, electronic device, and computer-readable medium provided by the present disclosure will be described in detail below with reference to the accompanying drawings.
[0038] Example embodiments will be described more fully hereinafter with reference to the accompanying drawings, but the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0039] In the case of no conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0040] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0041] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms "comprises" and / or "consists of" are used in this specification, it specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0042] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.
[0043] The host network element device and the target auxiliary network element device in the embodiments of the present disclosure may be a core network that independently deploys a DPI processing node or a centralized node device of a network, or may be a base station with DPI deployed in a sinking manner. The present disclosure is not limited thereto.
[0044] Hereinafter, a core network that independently deploys a DPI processing node or a centralized node device of a network, and a base station with DPI deployed in a sinking manner will be described respectively:
[0045] Figure 1 This is a network structure diagram of a core network that independently deploys a DPI processing node provided for the embodiments of the present disclosure. Refer to Figure 1, in some embodiments, the mobile communication network includes: CN (Core Network), RAN (Radio Access Network), and mobile terminals (such as mobile phones, personal computers, etc.). Among them, CN can be used for data processing, voice routing, network interconnection, billing, user authentication, and service quality and mobility management, etc. RAN can specifically be a base station NodeB with a RAN system, which includes an RNLU (Radio Network Layer Unit) for processing user plane data. RAN can access user equipment to the network through wireless signals, be responsible for the transmission and processing of wireless signals, provide network coverage, and manage wireless resources and interfaces, etc. CN is connected to an independently deployed DPI processing node.
[0046] Figure 2 It is a network structure diagram of a centralized node device of a network with an independently deployed DPI processing node provided by an embodiment of the present disclosure. Refer to Figure 2 , in some embodiments, relevant intermediate network element devices are connected between CN and RAN, and their functions are to provide effective data transmission, coordinate communication between the core network and RAN, and process network signal conversion and routing, etc. Among them, the intermediate network element devices are connected to an independently deployed DPI processing node.
[0047] Figure 1 and Figure 2 Both are independently deploying DPI processing nodes in the mobile communication network structure. This deployment method, on the one hand, has a high cost, and on the other hand, after using the functions of the DPI processing node, since the deployment location of the DPI processing node is farther away from the mobile terminal and RAN closer to the user side, the optimization effect will be smaller. Since there are high real-time requirements for the guarantee of user perception for the results of DPI recognition, this deployment method will affect the user perception and network performance of network element devices.
[0048] Figure 3 It is a network structure diagram of a base station with DPI deployed in a sinking manner provided by an embodiment of the present disclosure. Refer to Figure 3 , in some embodiments, the mobile communication network includes: CN, intermediate network element devices, RAN, and mobile terminals. Among them, the DPI processing function shares a service board with the RNLU in the base station NodeB.
[0049] Figure 4 It is another network structure diagram of a base station with DPI deployed in a sinking manner provided by an embodiment of the present disclosure. Refer to Figure 4, in some embodiments, the mobile communication network includes: a CN, an intermediate network element device, a RAN, and a mobile terminal. Among them, by adding a DPI service single board to the base station NodeB, the DPI service single board has DPI processing capabilities.
[0050] Figure 3 and Figure 4 both deploy DPI processing nodes in the RAN base station single boards in the mobile communication network structure. However, since the current designs of 4G or 5G base station single boards are all for 3GPP L1 / L2 / L3 protocol processing to complete the basic signaling and data services of the UE (User Equipment), the basic signaling and data services of the UE require most of the computing power resources, that is, the base station rarely has extra CPU computing power resources and memory computing power resources to process DPI. Therefore, the performance of the DPI processing function deployed on the base station single board is weak, and the number of UEs or traffic flows that can be used to support identification is small. In some embodiments, for scenarios with a large number of UEs / traffic flows in large-capacity sites, due to the limited computing power resources of the RAN base station, it is difficult to identify and guarantee all services of all users, and it is also difficult to further improve user perception and network performance. Additionally, in some embodiments, although there are abundant computing power resources in non-large-capacity RAN base stations near the RAN base station, due to the complexity of the network architecture, data transmission and management, as well as the limitations of related technologies and cost factors, it is very difficult to effectively allocate these resources to large-capacity RAN base stations that require more computing resources.
[0051] Figure 5 The flowchart of a deep packet detection method provided by an embodiment of the present disclosure. In a first aspect, referring to Figure 5 , an embodiment of the present disclosure provides a deep packet detection method for a host network element device, including:
[0052] S1. Based on the idle computing power resources of the host network element device and the computing power resources corresponding to the DPI parsing task, decompose the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task;
[0053] S2. Based on the target first-level DPI decomposition task, receive the target parsing result of the target first-level DPI decomposition task fed back by the target auxiliary network element device corresponding to the host network element device;
[0054] S3. Determine the DPI parsing result of the DPI parsing task according to the target parsing result.
[0055] In an embodiment of the present disclosure, when the idle computing power resources in the host network element device cannot meet the computing power resources required for DPI parsing tasks, that is, when the idle computing power resources of the host network element device cannot complete the processing of all DPI parsing tasks, the DPI parsing tasks are decomposed. The target first-level DPI decomposition tasks (including non-target first-level DPI decomposition tasks and target first-level DPI decomposition tasks) among the decomposed multiple first-level DPI decomposition tasks are sent to each target auxiliary network element device for collaborative parsing processing, and the non-target first-level DPI decomposition tasks other than the target first-level DPI decomposition tasks among the multiple first-level DPI decomposition tasks are processed by the host network element device itself to obtain non-target parsing results. According to the target parsing results and non-target parsing results fed back by the target auxiliary network element device, collaborative processing between the host network element device and the target auxiliary network element device can be realized to obtain the DPI parsing results of the DPI parsing tasks, so that the auxiliary computing power resources of the host network element device can be quickly and effectively utilized for user service-level perception guarantee, and the timeliness of service-level perception guarantee is improved.
[0056] It should be noted that, in some embodiments, the computing power resources required for DPI parsing tasks are determined according to the traffic volume and parsing tasks of the host network element device.
[0057] In some embodiments, the DPI parsing tasks include service identification and service evaluation. When enabling the base station to process the DPI parsing tasks, the plaintext data of the received first data packet is copied and transmitted by the service board PDCP (Packet Data Convergence Protocol) or the higher layer to the corresponding DPI processing unit, and is parsed through the metadata of the quadruple (including at least one of the user identification ID, bearer identification ID, direction identification ID, and its service flow ID unique identification). The parsing results returned after parsing include the service type AppId (Application Identifier Business Type) and the evaluation results. The DPI processing unit sends the DPI parsing results and metadata to the service board, and further the service board can perform user service-level perception guarantee based on the parsing results to improve the timeliness of service-level perception guarantee.
[0058] In some embodiments, the target auxiliary network element device may be a homogeneous network element device of the host network element device or a heterogeneous network element device, and the present disclosure is not limited thereto. Among them, the homogeneous network element device refers to the same type of network element device, and the heterogeneous network element device refers to different types of network element devices.
[0059] In one example, when the host network element device is a base station and the target auxiliary network element device is also a base station, the target auxiliary network element device is a homogeneous network element device of the host network element device.
[0060] In another example, when the host network element device is a base station and the target auxiliary network element device is an edge network element device, the target auxiliary network element device is a homogeneous network element device of the host network element device. Here, the edge network element device refers to a logical unit device separated from the base station. For example, it can be an MEC (Multi-Access Edge Computing, edge gateway server), a server used for independent DPI deployment, etc.
[0061] In some embodiments, before S1, the following steps are further included:
[0062] Obtain the transmission delay between the auxiliary network element device and the host network element device, and the idle computing power resources of the auxiliary network element device;
[0063] Determine the first auxiliary network element device based on the idle computing power resources of the auxiliary network element device, the preset computing power resources, the transmission delay, and the preset delay;
[0064] Construct a first auxiliary computing power list according to the first auxiliary network element device; the first auxiliary computing power list is used to record the idle computing power resources corresponding to each first auxiliary network element device.
[0065] In this embodiment, the host network element device can determine whether to add an auxiliary network element device to the first auxiliary computing power list based on factors such as the transmission delay between the host network element device and the auxiliary network element device, the idle or remaining CPU computing power resources, memory computing power resources, and bandwidth computing power resources.
[0066] In some embodiments, determining the first auxiliary network element device based on the idle computing power resources of the auxiliary network element device, the preset computing power resources, the transmission delay, and the preset delay includes:
[0067] Compare the idle computing power resources of the auxiliary network element device with the preset computing power resources to obtain a first comparison result, and compare the transmission delay with the preset delay to obtain a second comparison result;
[0068] When the first comparison result shows that the idle computing power resources of the auxiliary network element device are more than or equal to the preset computing power resources, and the second comparison result shows that the transmission delay is less than the preset delay, determine the auxiliary network element device as the first auxiliary network element device.
[0069] In this embodiment, the preset computing power resource is the minimum computing power resource of the auxiliary network element device that can be added to the first auxiliary computing power list, and the preset time delay is the maximum time delay of the auxiliary network element device that can be added to the first auxiliary computing power list. When the idle computing power resource and the transmission time delay of the auxiliary network element device both meet the requirements of the preset computing power resource and the preset time delay, it is determined that the auxiliary network element device is the first auxiliary network element device that can be added to the first auxiliary computing power list.
[0070] It should be noted that in the embodiments of the present disclosure, other factors can also be used to measure whether an auxiliary network element device can be added to the first auxiliary computing power list. For example, bandwidth, packet loss rate, response time, etc. The present disclosure is not limited thereto.
[0071] Figure 6 This is a flowchart of a specific implementation method for step S2 in the embodiments of the present disclosure. Refer to Figure 6 , in some embodiments, S1 includes:
[0072] S11. Compare the idle computing power resource of the host network element device with the computing power resource corresponding to the DPI parsing task to obtain a comparison result;
[0073] S12. When the comparison result shows that the idle computing power resource of the host network element device is less than the computing power resource corresponding to the DPI parsing task, decompose the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task.
[0074] In the embodiments of the present disclosure, when the idle computing power resource in the host network element device is less than the computing power resource required for the DPI parsing task, it means that the idle computing power resource maintained in the host network element device cannot complete all the DPI parsing tasks. Therefore, the DPI parsing task is decomposed to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task. The target first-level DPI decomposition task is sent to the target auxiliary network element device for processing, and the remaining non-target first-level DPI decomposition tasks except the target first-level DPI decomposition task are processed by the host network element device to obtain a non-target parsing result.
[0075] In some embodiments, S12 includes:
[0076] Decompose the DPI parsing task to obtain multiple first-level DPI decomposition tasks;
[0077] Determine at least some of the first-level DPI decomposition tasks as target first-level DPI decomposition tasks, and determine the remaining first-level DPI decomposition tasks as non-target first-level DPI decomposition tasks; the sum of the computing power resources required for the non-target first-level DPI decomposition tasks is equal to or less than the idle computing power resource in the host network element device.
[0078] After determining that the first-level DPI decomposition task of the remaining part is a non-target first-level DPI decomposition task, it further includes: processing the non-target first-level DPI decomposition task to determine a non-target parsing result.
[0079] It should be noted that the total computing power resources required for this non-target first-level DPI decomposition task should be less than the idle computing power resources in the host network element device.
[0080] The total computing power resources required for the target first-level DPI decomposition task can be equal to or less than the total idle computing power resources maintained by the target auxiliary network element device, or can be more than the total idle computing power resources maintained by the target auxiliary network element device. The present disclosure does not make special limitations on this. In some embodiments, when the total computing power resources required for the target first-level DPI decomposition task are more than the total idle computing power resources maintained by the target auxiliary network element device, since the target auxiliary network element device cannot complete the target first-level DPI decomposition task either, the target auxiliary network element device can further decompose the target first-level DPI decomposition task, and then sink the decomposed task to a lower-level network element device for processing.
[0081] In some embodiments, determining that the first-level DPI decomposition task of the remaining part is a non-target first-level DPI decomposition task includes:
[0082] Selecting at least some of the first-level DPI decomposition tasks from multiple first-level DPI decomposition tasks as non-target first-level DPI decomposition tasks in the order of the task priorities corresponding to each first-level DPI decomposition task from high to low.
[0083] In the embodiments of the present disclosure, since decomposing the target first-level DPI decomposition task to the target auxiliary network element device for processing will reduce the timeliness of processing this target first-level DPI decomposition task, and the determinants of this timeliness include data transmission delay, DPI processing performance of the target auxiliary network element device, etc. Therefore, in the order of the task priorities corresponding to each first-level DPI decomposition task from high to low, the host network element device preferentially processes the first-level DPI decomposition tasks with higher task priorities, determines these first-level DPI decomposition tasks as non-target first-level DPI decomposition tasks, and the remaining first-level DPI decomposition tasks are target first-level DPI decomposition tasks. The target first-level DPI decomposition task is a task that needs to be transmitted to the target auxiliary network element device for processing, that is, the host network element device arranges computing power resources according to the task priorities for the first-level DPI parsing tasks that it cannot complete, so as to initiate each target auxiliary network element device to assist the host network element device with DPI computing power resources.
[0084] In some embodiments, the DPI processing unit in the host network element device may be hierarchically divided according to the service type and application scenario corresponding to each first-level DPI decomposition task. The task priority of each first-level DPI decomposition task can be adjusted according to the actual situation, and the present disclosure is not limited thereto. The embodiments of the present disclosure do not make special limitations on the number of task priorities and the number of tasks corresponding to each task priority.
[0085] In one example, if the service type is voice, the tasks of this type need to be guaranteed, and its task priority is the highest level, that is, Slevel1; if the service type is an evaluation service type that is intuitively perceived by users, its task priority is the second highest level, that is, Slevel2; if the service type is other types other than voice and the evaluation service type that is intuitively perceived by users, its task priority is Slevel3.
[0086] Figure 7 This is a flowchart of task decomposition provided by the embodiments of the present disclosure. Refer to Figure 7 , in some embodiments, after the host network element device analyzes the first data packet, a DPI parsing task is obtained. When the idle computing power resources of the host network element device are less than the DPI parsing task, the host network element device further decomposes the DPI parsing task and determines each first-level DPI decomposition task and its task priority Slevel. Among them, the task is decomposed according to the data unit, the Slevel corresponding to the service type of each first-level DPI decomposition task, the required CPU computing power resources, memory computing power resources, and bandwidth computing power resources, and a task list with task priorities is obtained.
[0087] Figure 8 This is a schematic diagram of the first-level DPI decomposition task and its task priority provided by the embodiments of the present disclosure. Refer to Figure 8 , after the DPI parsing task is decomposed, first-level DPI decomposition tasks with task priorities of Slevel1, Slevel2, and Slevel3 are obtained, and the first-level DPI decomposition tasks corresponding to each task priority can be one or more.
[0088] Figure 9 This is a flowchart of a specific implementation method of step S2 in the embodiments of the present disclosure. Refer to Figure 9 , in some embodiments, S2 includes:
[0089] S21. Send the target first-level DPI decomposition task to the target auxiliary network element device;
[0090] S22. Receive the target parsing result of the target first-level DPI decomposition task fed back by the target auxiliary network element device.
[0091] In this embodiment, based on the target parsing result and non-target parsing result fed back by the target auxiliary network element device, collaborative processing of the DPI parsing task by the host network element device and the target auxiliary network element device can be achieved.
[0092] Figure 10 It is a flowchart of a specific implementation method for step S21 in the embodiments of the present disclosure. Refer to Figure 10 In some embodiments, S21 includes:
[0093] S211. Determine the first auxiliary network element device corresponding to the target first-level DPI decomposition task in the first auxiliary computing power list; the first auxiliary computing power list is used to record the idle computing power resources corresponding to each first auxiliary network element device;
[0094] S212. Send the target first-level DPI decomposition task to the corresponding target auxiliary network element device.
[0095] In the embodiments of the present disclosure, the first auxiliary computing power list is maintained by the host network element device, which records the idle computing power resources corresponding to each first auxiliary network element device, and one or more of the first auxiliary network element devices are determined as target auxiliary network element devices. The first auxiliary network element device is a network element device that can provide external DPI computing power services for the host network element device, that is, the first auxiliary network element device can process at least part of the first-level DPI decomposition tasks decomposed by the host network element device.
[0096] According to the idle computing power resources corresponding to each first auxiliary network element device recorded in the first auxiliary computing power list, select one or more from the first auxiliary network element devices as target auxiliary network element devices, and the sum of the idle computing power resources of the target auxiliary network element devices is more than or equal to the sum of the computing power resources required for the target first-level DPI decomposition task, and then send the target first-level DPI decomposition task to the corresponding target auxiliary network element device.
[0097] In some embodiments, each first auxiliary network element device in the first auxiliary computing power list and the host network element device belong to the same local virtual network element cluster, and each first auxiliary network element device in this local virtual network element cluster (which can also be simply referred to as a computing power cloud cluster) can share its computing power resources with the host network element device (i.e., the cluster network element device).
[0098] In some embodiments, when both the first auxiliary network element device and the host network element device are base stations with DPI deployed in a downlink manner, the first auxiliary network element device and the host network element device can be directly connected through the X2 interface to transmit computing power resource information, primary DPI parsing tasks, target parsing results, etc. to each other. Compared with the core network or the centralized node device of the network where the first auxiliary network element device and the host network element device are both independently deployed DPI processing nodes, or when the first auxiliary network element device can be a heterogeneous network element device of the host network element device, the data interaction latency is lower and the efficiency is higher when the first auxiliary network element device and the host network element device are directly connected through the X2 interface.
[0099] Since the host network element device and the target auxiliary network element device can be the core network or the centralized node device of the network where DPI processing nodes are independently deployed, or can be base stations with DPI deployed in a downlink manner, and the first auxiliary network element device can be a homogeneous network element device of the host network element device or a heterogeneous network element device, a single computing power cloud cluster can include multiple base stations with DPI deployed in a downlink manner and / or the core network or the centralized node device of the network where DPI processing nodes are independently deployed.
[0100] Figure 11 The structural schematic diagram of a computing power cloud provided by an embodiment of the present disclosure. Refer to Figure 11 , as an example, the shared computing power cloud cluster includes multiple base stations with DPI deployed in a downlink manner, and these base stations can serve as shared computing power nodes to provide shared computing power services for each node within the shared computing power cloud cluster. As another example, the shared computing power cloud cluster can also include multiple core networks or centralized node devices of the network where DPI processing nodes are independently deployed (not shown in the figure), and this core network or device can also serve as a shared computing power node to provide shared computing power services for each node within the shared computing power cloud cluster.
[0101] In some embodiments, multiple computing power cloud clusters can further provide shared computing power services for the core network or the centralized node device of the network where DPI processing nodes are independently deployed, that is, each shared computing power node within these computing power cloud clusters can provide shared computing power services for the core network or the centralized node device of the network where DPI processing nodes are independently deployed. Correspondingly, the core network or the centralized node device of the network where DPI processing nodes are independently deployed providing shared computing power services can also provide shared computing power services for each shared computing power node within each computing power cloud cluster.
[0102] Figure 12 The schematic flow diagram of an exemplary shared computing power service provided by an embodiment of the present disclosure. Refer to Figure 12, as an example, in the case where the core network with independently deployed DPI processing nodes or the central node device of the network is used as the host network element device, the shared computing power cloud clusters 1 to 5 can provide shared computing power resources for the host network element device.
[0103] Correspondingly, in some embodiments, before S21, it further includes:
[0104] Sending a computing power request to each first auxiliary network element device in the first auxiliary computing power list;
[0105] Receiving the computing power resource situation feedback by the first auxiliary network element device;
[0106] Updating the first auxiliary computing power list according to the computing power resource situation.
[0107] In this embodiment, the host network element device sends a computing power request to the first auxiliary network element device and receives the computing power resource situation feedback by the first auxiliary network element device, realizing the update of the first auxiliary computing power list. In some embodiments, the host network element device periodically sends a computing power request to each first auxiliary network element device in the first auxiliary computing power list to maintain the information of the idle computing power resources corresponding to each first auxiliary network element device recorded in the list. The computing power resources that each first auxiliary network element device needs to provide to its corresponding host network element device include at least one of idle or remaining CPU computing power resources, memory computing power resources, and bandwidth computing power resources. In addition, the first auxiliary computing power list can also record the transmission delay between each first auxiliary network element device and it.
[0108] In some embodiments, a response time can be set for the computing power request. If no response is received after the timeout, the computing power request will continue to be sent to the next first auxiliary network element device until the computing power request has been sent to all the first auxiliary network element devices. If no response is received after the timeout, it will cause the total computing power resources of the first auxiliary network element devices in the current first auxiliary computing power list to decrease. In some embodiments, it further includes the host network element device issuing a warning about the decrease in computing power resource capacity.
[0109] In some embodiments, the host network element device can maintain the information of the idle computing power resources corresponding to multiple first auxiliary network element devices in parallel, and the present disclosure does not impose special restrictions on the number of first auxiliary network element devices in the first auxiliary computing power list.
[0110] In some embodiments, the first auxiliary network element device in the first auxiliary computing power list can also be added or deleted. When the host network element device has insufficient idle computing power resources available for DPI processing, the first auxiliary network element device in the first auxiliary computing power list can be added and its idle computing power resources can be recorded, so as to achieve the purpose of improving the DPI parsing ability of the host network element device. In some embodiments, the host network element device can adjust the preset computing power resources and / or preset delay to add the first auxiliary network element device recorded in the list during the next update of the first auxiliary computing power list.
[0111] Figure 13 FIG. is a schematic diagram of updating an exemplary first auxiliary computing power list provided by an embodiment of the present disclosure. Referring to Figure 13 , as an example, a certain first auxiliary network element device can provide shared computing power resources for multiple host network element devices (i.e., Node). The first auxiliary network element device is a heterogeneous network element device corresponding to the Node. Then, the Node sends a computing power request to the first auxiliary network element device, receives the computing power resource situation fed back by the first auxiliary network element device, and then updates the first auxiliary computing power list maintained by the Node. The Nodes can also achieve computing power interaction through the X2 interface.
[0112] It should be noted that the interaction between the first auxiliary network element device and the host network element device is not limited to updating the first auxiliary computing power list, and may also include transmitting the first-level DPI decomposition task and the target parsing result allocated to the first auxiliary network element device.
[0113] Based on the first auxiliary computing power list of the host network element device, when the host network element device knows the idle computing power resources of each first auxiliary network element device, it can send the target first-level DPI decomposition task to the corresponding target auxiliary network element device according to the computing power resources.
[0114] Correspondingly, in some embodiments, when the idle computing power resources of the target auxiliary network element device are less than the computing power resources required for the target first-level DPI decomposition task, after S21, it may further include:
[0115] According to the weight ratio of the idle computing power resources corresponding to each target auxiliary network element device in the first auxiliary computing power list and the computing power resources required for the remaining target first-level DPI decomposition tasks (i.e., at least part of the target first-level DPI decomposition tasks that cannot be completed by the idle computing power resources of the target auxiliary network element device), the remaining target first-level DPI decomposition tasks are sent to the corresponding target auxiliary network element device.
[0116] In an embodiment of the present disclosure, since the target auxiliary network element device can further decompose and sink the target first-level DPI decomposition task when it cannot complete the target first-level DPI decomposition task, therefore, when the total computing power resources required for the target first-level DPI decomposition task are greater than the total idle computing power resources of all target auxiliary network element devices, the target first-level DPI decomposition task can be sent to the target auxiliary network element device in excess according to the weight ratio of the idle computing power resources corresponding to each target auxiliary network element device and the computing power resources required for each target first-level DPI decomposition task, that is, each target auxiliary network element device can allocate the excess target first-level DPI decomposition task in excess according to the weight ratio of its idle computing power resources.
[0117] In some embodiments, S21 includes:
[0118] Send the target first-level DPI decomposition task to the target auxiliary network element device with the highest associated priority according to the idle computing power resources and the associated priority corresponding to the target auxiliary network element device; wherein, the associated priority of each target auxiliary network element device is divided according to at least one of transmission delay, central processing unit (CPU) resources, memory resources, and bandwidth resources;
[0119] In the case where the total idle computing power resources of the target auxiliary network element device with the highest associated priority are less than the total computing power resources required for the target first-level DPI decomposition task, select the target auxiliary network element device with a lower level of associated priority in descending order of the associated priority step by step to send the remaining target first-level DPI decomposition task until all the target first-level DPI decomposition tasks are sent or have been sent to all the target auxiliary network element devices.
[0120] In this embodiment, the associated priority of each target auxiliary network element device is divided according to at least one of transmission delay, central processing unit (CPU) resources, memory resources, and bandwidth resources, and this associated priority is used to indicate the priority of sending the first-level DPI decomposition task to the target auxiliary network element device when the idle computing power resources in the host network element device are less than the computing power resources required for the DPI parsing task.
[0121] In the case where the total idle computing power resources of the target auxiliary network element device with the highest associated priority are less than the total computing power resources required for the target first-level DPI decomposition task, select the target auxiliary network element device with a lower level of associated priority in descending order of the associated priority step by step to send the remaining target first-level DPI decomposition task until all the target first-level DPI decomposition tasks are sent or have been sent to all the target auxiliary network element devices.
[0122] It should be noted that in some embodiments, for the remaining target first-level DPI decomposition tasks after being sent to all target auxiliary network element devices, the remaining target first-level DPI decomposition tasks can be over-sent to one of the target auxiliary network element devices, or over-sent according to the weight ratio of the idle computing power resources corresponding to each target auxiliary network element device in the first auxiliary computing power list, so that the target auxiliary network element device can further decompose and sink the target first-level DPI decomposition tasks.
[0123] In the embodiments of the present disclosure, the number of association priorities is not particularly limited.
[0124] In some related technologies, since DPI needs to parse the application layer content code stream of L4-L7 in the OSI (Open System Interconnect) network model, that is, the depth of the TCP / IP (Transmission Control Protocol / Internet Protocol) code stream to be parsed is up to nearly the size of the message MTU (Maximum Transmission Unit) (such as 1500 Byte), therefore, the overhead of CPU computing power resources and memory computing power resources is very large, and it is difficult for DPI-related network element devices to ensure the identification and guarantee of all services of all users, thus affecting the user perception and network performance of the network element devices.
[0125] Compared with some related technologies, the above embodiments of the present disclosure can quickly and effectively utilize the auxiliary computing power resources of the host network element device to ensure user service-level perception, improving the timeliness of service-level perception guarantee.
[0126] Figure 14 This is a flowchart of another deep packet detection method provided by the embodiments of the present disclosure. Second, referring to Figure 14 , the embodiments of the present disclosure provide a deep packet detection method for a target auxiliary network element device, including:
[0127] Step 1401: Determine the target parsing result of the target first-level DPI decomposition task based on the target first-level DPI decomposition task sent by the host network element device;
[0128] Step 1402: Send the target parsing result to the host network element device.
[0129] This embodiment is a deep packet inspection method on the target auxiliary network element device side. The target auxiliary network element device is used to process the remaining target first-level DPI decomposition tasks that cannot be processed by the idle computing power resources of the host network element device, that is, the target auxiliary network element device is used to receive the target first-level DPI decomposition tasks sunk from the host network element device side.
[0130] When the target auxiliary network element device processes the target first-level DPI decomposition tasks, the target auxiliary network element device can be regarded as the current host network element device. That is, the target auxiliary network element device can also send computing power requests to its surrounding auxiliary network element devices regularly to pool the computing power resources of homogeneous and heterogeneous network element devices (that is, a second auxiliary computing power list corresponding to the target auxiliary network element device can be constructed) to achieve further computing power resource sharing and collaborative task processing.
[0131] Figure 15 It is a specific implementation method flowchart of step 1401 in the present disclosure embodiment. Refer to Figure 15 Accordingly, in some embodiments, step 1401 includes:
[0132] Step 14011: Based on the idle computing power resources of the target auxiliary network element device and the computing power resources corresponding to the target first-level DPI decomposition tasks, decompose the target first-level DPI decomposition tasks to obtain non-target second-level DPI decomposition tasks and target second-level DPI decomposition tasks;
[0133] Step 14012: Based on the target second-level DPI decomposition tasks, receive the first parsing results of the target second-level DPI decomposition tasks fed back by the first auxiliary network element device corresponding to the target auxiliary network element device;
[0134] Step 14013: Determine the target parsing results of the target first-level DPI decomposition tasks according to the first parsing results.
[0135] In this embodiment, when the idle computing power resources in the target auxiliary network element device are less than the required computing power resources of the target first-level DPI decomposition tasks, the target first-level DPI decomposition tasks can be further decomposed and sink-parsed so that when the host network element device needs DPI service enhancement, that is, when more computing power resources for DPI parsing tasks are needed, DPI services can be invoked through heterogeneous or homogeneous network element devices to implement the parsing and feature extraction of the target first-level DPI decomposition tasks that exceed its computing power resource capabilities, enabling the host network element device to implement a DPI service mechanism that supports more UEs / service flows, improving the computing power resource capabilities of the DPI deployment of the host network element device, and being applicable to the guarantee of improving user perception.
[0136] In some embodiments, the auxiliary network element devices at the first level and the auxiliary network element devices at the second level can be divided in the network structure by the cascade level. Among them, the auxiliary network element device directly connected to the host network element device is divided into the auxiliary network element device at the cascade level of the first level, and the auxiliary network element device that needs to be further forwarded by 1 network element device is divided into the auxiliary network element device at the cascade level of the second level... and so on. The auxiliary network element device that needs to be forwarded by n network element devices is divided into the auxiliary network element device at the cascade level of the n + 1 level.
[0137] In one example, since the transmission delay between homogeneous network element devices is lower, when the first auxiliary network element device is a heterogeneous network element device of the host network element device, the heterogeneous network element device directly connected to this network element device can be used as the auxiliary network element device at the cascade level of the second level. When the computing power resources of each auxiliary network element device (i.e., the first auxiliary network element device) at the cascade level of the first level are insufficient, it is possible to determine whether to utilize the computing power resources of this heterogeneous network element device according to the delay of the auxiliary network element device at the cascade level of the first level. Compare the delay situations of the heterogeneous auxiliary network element devices and the homogeneous auxiliary network element devices among the auxiliary network element devices at the cascade level of the second level to decide the auxiliary network element device to be preferentially used.
[0138] It should be noted that in some embodiments, the execution priority of the cascade level in the network structure is higher than the association priority. That is, when the association priority and the cascade level are both divided, first send the target first-level DPI decomposition tasks in the order of the association priority from high to low in the highest-level cascade level. When the idle computing power resources among the first auxiliary network element devices at the cascade level of the first level are less than the required computing power resources of all the target first-level DPI decomposition tasks, then sink the remaining target first-level DPI decomposition tasks that cannot be processed completely to the auxiliary network element devices at the cascade level of the second level, and send the remaining target first-level DPI decomposition tasks that cannot be processed completely in the order of the association priority from high to low, and so on, until all the target first-level DPI decomposition tasks are sent or have been sent to all the target auxiliary network element devices.
[0139] In the embodiments of the present disclosure, there are no special limitations on the number of cascade levels.
[0140] Figure 16 This is a schematic flowchart of sending the target first-level DPI decomposition tasks according to the association priority provided by the embodiments of the present disclosure. Refer to Figure 16, NodeB 2 and NodeB 5 with an association priority of level1, NodeB3 and NodeB 6 with an association priority of level2, and NodeB 1 and NodeB 4 with an association priority of level3 are used as the target auxiliary network element devices at the first-level cascade level. The network element devices with independent DPI computing power and NodeB 7, NodeB 8, and NodeB9 that need to be sent through NodeB 5 are used as the target auxiliary network element devices at the second-level cascade level.
[0141] The host network element device sends the target first-level DPI decomposition task to each NodeB at the first-level cascade level, that is, it first actively initiates a computing power resource query to the surrounding NodeB and other network element devices at level1 according to the minimum number of auxiliary resources for the disassembled target first-level DPI decomposition task, and completes the task deployment of the target first-level DPI decomposition task.
[0142] If it is confirmed that the resources are sufficient after the query, the task of Slevel2 is continued to be deployed. If the computing power resources are insufficient after the query, the computing power resources of the surrounding NodeB and other network element devices at level2 are continued to be queried, and so on, until the task deployment of all target first-level DPI decomposition tasks is completed;
[0143] If the computing power resources of the network element devices at the first-level cascade level are still insufficient, it can be further decomposed and deployed to the second-level cascade level.
[0144] In the above embodiments of the present disclosure, the DPI parsing task that cannot be processed by the computing power resources of the host network element device is decomposed, and the decomposed target first-level DPI decomposition task is sent to the target auxiliary network element device for collaborative processing. The target auxiliary network element device can further decompose and sink the target first-level DPI decomposition task for parsing processing until all the decomposition tasks of the DPI parsing task are completed, so as to realize the rapid and effective use of the auxiliary computing power resources of the host network element device to ensure the user service-level perception, and improve the timeliness of the service-level perception guarantee. And since the host network element device and each auxiliary network element device can be heterogeneous or homogeneous, it not only solves the problem of insufficient computing power resources for DPI deployment, but also can cope with the scenario where heterogeneous network element devices do not support DPI deployment.
[0145] In the third aspect, referring to Figure 17 , the embodiments of the present disclosure provide a network element device, which includes:
[0146] One or more processors 1701;
[0147] A memory 1702, on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement the deep packet detection method of any one of the above.
[0148] One or more I / O interfaces 1703, connected between the processor and the memory, are configured to enable information interaction between the processor and the memory.
[0149] Among them, the processor 1701 is a device with data processing capabilities, including but not limited to a central processing unit (CPU), etc.; the memory 1702 is a device with data storage capabilities, including but not limited to a random access memory (RAM, more specifically such as SDRAM, DDR, etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (FLASH); the I / O interface (read / write interface) 1703 is connected between the processor 1701 and the memory 1702 and can enable information interaction between the processor 1701 and the memory 1702, including but not limited to a data bus (Bus), etc.
[0150] In a fourth aspect, referring to Figure 18 , the embodiments of the present disclosure provide a computer-readable medium, on which a computer program is stored, and when the program is executed by a processor, any one of the above-mentioned deep packet detection methods is implemented.
[0151] In order to enable those skilled in the art to more clearly understand the technical solutions provided by the embodiments of the present disclosure, the following uses specific embodiments to elaborate in detail on the technical solutions provided by the embodiments of the present disclosure:
[0152] Embodiment 1: The host network element device and the first auxiliary network element device in this embodiment can be a core network or a centralized node device of an independently deployed DPI processing node, or a base station with DPI deployed in a sinking manner, and can be applicable to a variety of application scenarios:
[0153] In one example, referring to Figure 3 and Figure 4 , the host network element device is a host base station NodeB equipped with a DPI processing unit with DPI function. The DPI processing unit can be deployed in a service single board shared with the RNLU in the base station NodeB, or a separate DPI service single board can be added in the host base station NodeB for deployment. The host base station NodeB is a 4G or 5G base station, and computing power resources are shared between the host base station NodeB and multiple other first auxiliary network element devices. It can handle scenarios where there is no independently deployed DPI processing node in the core network or the centralized node device of the network.
[0154] In another example, referring to Figure 1 , 2, 3, 4, and 13, the host network element device is the host base station NodeB deployed with a DPI processing unit with DPI function. The first auxiliary network element device is the core network or the centralized node device of the network independently deploying DPI processing nodes, such as MEC, EPC, 5GC, etc. The host network element device can share computing power resources with the first auxiliary network element device. This scenario can handle the scenario where there are both base stations deployed with DPI processing units with DPI function and core networks or centralized node devices of the network independently deploying DPI processing nodes in the network environment.
[0155] In another example, refer to Figure 11 and Figure 12 , the host network element device is the host base station NodeB deployed with a DPI processing unit with DPI function. The first auxiliary network element device is the core network or the centralized node device of the network independently deploying DPI processing nodes. A pooled computing power grid is composed of multiple base stations and core networks or centralized node devices of the network independently deploying DPI processing nodes.
[0156] Embodiment 2: Figure 19 This is a flowchart of an exemplary deep packet detection method provided by the embodiments of the present disclosure. Refer to Figure 19 , the host network element device is the host base station NodeB. The host base station NodeB maintains a first auxiliary computing power list, which includes multiple first auxiliary network element devices. The host base station NodeB performs computing power scheduling on each of the surrounding first auxiliary network element devices by periodically obtaining the computing power resource status of each first auxiliary network element device in the first auxiliary computing power list, and maintains a first auxiliary computing power list with an associated priority from high to low to achieve rapid selection of effective auxiliary computing power resources. Among them, the process of the host base station maintaining the first auxiliary computing power list is as follows:
[0157] The first auxiliary network element device supports reporting computing power resources K*{c, m, b} as an integer multiple of the minimum required computing power resources {c, m, b}, where K*c is the CPU computing power resource of the first auxiliary network element device, K*m is the memory computing power resource of the first auxiliary network element device, and K*b is the bandwidth computing power resource of the first auxiliary network element device. The host network element device can communicate with the surrounding first auxiliary network element devices;
[0158] The host network element device supports performing a latency test π with the first auxiliary network element device {P,S} , and the associated priority of the first auxiliary network element device can be determined based on the latency between the host network element device and the first auxiliary network element device. Among them, P is the host base station and S is the auxiliary base station. The process of its latency test is as follows:
[0159] According to a preset period (for example, each period is 7 days long and the interval is 1800 s), a computing power request is sent to the surrounding first auxiliary network element device, and the computing power resource situation and measurement delay π responded by the first auxiliary network element device according to the computing power request are obtained. {P,S} The first auxiliary network element device reports its available computing power resources to the host network element device in integer multiples of {c, m, b}, and the computing power resources less than one integer multiple are reported as 0, which can reduce computing resources.
[0160] The host network element device calculates the average delay of each first auxiliary network element device. Among them, π i is the delay of each measurement, n is n sample points in a period, that is, the total number of times the first auxiliary network element device reports the delay. When the delay π {P,S} is less than or equal to Delay_min, the association priority of this first auxiliary network element device is Level1; when π {P,S} is greater than Delay_min and less than Delay_max, the association priority of this first auxiliary network element device is Level2; when π {P,S} is greater than or equal to Delay_max, the association priority of this first auxiliary network element device is Level3.
[0161] The host network element device calculates that the average computing power of each first auxiliary network element device is aven*{c, m, b}, where the symbol represents rounding down, K i *{c, m, b} is the computing power resource reported by the first auxiliary network element device for the i-th time in the same period, and n is the total number of times the first auxiliary network element device reports the computing power resource.
[0162] In the same association priority, the computing power resources of the first auxiliary network element devices are sorted from largest to smallest according to the average computing power aven, so as to quickly request sufficient resources in the follow-up and reduce the performance consumed by traversal.
[0163] It should be noted that after the host network element device decomposes the DPI parsing task to the first auxiliary network element device, this first auxiliary network element device also maintains the auxiliary computing power list it maintains through the above process.
[0164] Correspondingly, the process of the host base station NodeB performing deep packet detection is as follows:
[0165] Step 1901, the host base station receives the first data packet.
[0166] Step 1902: Calculate the computing power resources required for the DPI parsing task corresponding to the first data packet, and decompose the DPI parsing task. Specifically, the DPI parsing task is decomposed according to CPU computing power resources, memory computing power resources, and bandwidth computing power resources. After decomposition, multiple first-level DPI decomposition tasks are obtained. The task priorities of each decomposed first-level DPI decomposition task are sorted, and the task priorities of the decomposed first-level DPI decomposition tasks are Slevel1, Slevel2, and Slevel3 in sequence.
[0167] Specifically, when decomposing the DPI parsing task, each DPI parsing task is decomposed according to the minimum required computing power resources {c, m, b}, where c is the required CPU computing power resources, m is the required memory resources, and b is the required bandwidth resources.
[0168] Step 1903: The host base station NodeB calculates the required computing power resources (M1 + M2 + M3) * {c, m, b} according to the traffic flow specifications of the DPI parsing task it receives, where M1 is the computing power resources required for the first-level DPI decomposition task of Slevel1, M2 is the computing power resources required for the first-level DPI decomposition task of Slevel2, and M3 is the computing power resources required for the first-level DPI decomposition task of Slevel3. The host base station NodeB judges whether the idle computing power resources of the host base station NodeB are greater than or equal to the required computing power resources of the DPI parsing task according to the available computing power resources C * {c, m, b} corresponding to its own idle computing power resources.
[0169] If C >= (M1 + M2 + M3), then execute 19041; if C < (M1 + M2 + M3), then the computing power resources that require DPI enhancement assistance are needed, that is, at least one of the first-level DPI decomposition tasks is determined as the target first-level DPI decomposition task to be decomposed, and execute 19042.
[0170] Step 19041: The host base station NodeB completes the DPI task parsing.
[0171] Step 19042: Judge whether the task to be parsed is the first-level DPI decomposition task with the task priority of Slevel1. If M1 > C, it means that there is a first-level DPI decomposition task with the task priority of Slevel1 that requires computing power assistance, then execute Step 19051; if M1 <= C, it means that the host base station NodeB has completed the first-level DPI decomposition task M1 * {c, m, b} with the task priority of Slevel1, then execute Step 19052.
[0172] Step 19051: Check if the idle computing power resources of the host base station NodeB are sufficient to process the first-level DPI decomposition task with a task priority of Slevel1. If yes, execute Step 19041; if not, execute Step 1907.
[0173] Step 19052: Determine whether the task to be parsed is a first-level DPI decomposition task with a task priority of Slevel2. If M2 > C - M1, it means that there is a first-level DPI decomposition task with a task priority of Slevel2 that requires computing power assistance, so execute Step 19051; if M2 <= C - M1, it means that the host base station NodeB has completed the first-level DPI decomposition tasks (M1 + M2)*{c, m, b} with task priorities of Slevel1 and Slevel2, so execute Step 1906.
[0174] Step 1906: Determine whether the task to be parsed is a first-level DPI decomposition task with a task priority of Slevel3. If M3 > C - M1 - M2, it means that there is a first-level DPI decomposition task with a task priority of Slevel3 that requires computing power assistance, so execute Step 19051; otherwise, execute Step 1907.
[0175] Step 1907: After using up all the idle computing power resources of the host base station NodeB, send the target first-level DPI decomposition task to the target auxiliary network element device.
[0176] Embodiment 3: Figure 20 This is a flowchart of an exemplary deep packet detection method when the idle computing power resources of the host network element device are insufficient provided by this public embodiment. Refer to Figure 20 , based on Step 1906 in Embodiment 2, that is, the deep packet detection method when the idle computing power resources of the host network element device are insufficient includes:
[0177] Step 2001: When the idle computing power resources of the host base station NodeB are insufficient, send the target first-level DPI decomposition task to the target auxiliary network element device. Task decomposition can improve the timeliness of priority parsing of key tasks.
[0178] Step 2002: Determine whether the target first-level DPI decomposition task is a task with a task priority of Slevel1. If yes, execute 2004; if not, execute 2003.
[0179] Step 2003: If not, it means that there is no task with a task priority of Slevel1 in the target first-level DPI decomposition task, so decompose the task with a task priority of Slevel2. If there is no Slevel2 task, decompose the Slevel3 task.
[0180] Step 2004, if so, it is necessary to decompose the computing power R1*{c,m,b} required for the target first-level DPI decomposition task with task priority Slevel1 according to the task priority, and the idle computing power resources C1*{c,m,b} of the target auxiliary network element device of level1 maintained, that is, execute Step 2005.
[0181] Step 2005, determine whether the computing power resources of the target auxiliary network element device of level1 are greater than or equal to the computing power required for the target first-level DPI decomposition task with task priority Slevel1, that is, whether C1>=R1 is satisfied. If so, execute 2006; if not, execute 2007.
[0182] Step 2006, if C1>=R1 is satisfied, it means that the host base station NodeB decomposes the target first-level DPI decomposition task with task priority Slevel1 to the target auxiliary network element device of level1. On this basis, since the target auxiliary network element device is dynamic, that is, it is possible that its own or other host network element devices have used its computing power resources during the update period of the first auxiliary computing power list, resulting in the situation that the computing power resources of the target auxiliary network element device cannot complete the target first-level DPI decomposition task as scheduled. At this time, the target auxiliary network element device can be used as a new host base station to decompose tasks to more downlink auxiliary network element devices.
[0183] Step 2007, if C1>=R1 is not satisfied, that is, C1<R1, the host base station NodeB decomposes part of the task C1 to the target auxiliary network element device of level1, and the remaining target first-level DPI decomposition task (R1 - C1)*{c,m,b} is decomposed to the target auxiliary network element device C2*{c,m,b} of Level2 for processing. If there is no target auxiliary network element device of level2, the remaining target first-level DPI decomposition task (R1 - C1)*{c,m,b} is decomposed to the target auxiliary network element device C3*{c,m,b} of level3 for processing. If there is also no target auxiliary network element device of level3, then transfer to Step 20013.
[0184] Step 2008, determine whether the computing power resources of the target auxiliary network element device of level2 are greater than or equal to the computing power required for the remaining all target first-level DPI decomposition tasks with task priority Slevel1, that is, whether C2>=(R1 - C1) is satisfied. If so, execute 2009; if not, execute 20010.
[0185] Step 2009, if C2 >= (R1 - C1) is satisfied, it means that the host base station NodeB decomposes all the remaining target first-level DPI decomposition tasks with task priority Slevel1 to the target auxiliary network element device at level 2. Similarly, on this basis, since the target auxiliary network element device is dynamic, that is, it is possible that its computing power resources cannot complete the target first-level DPI decomposition tasks as scheduled due to reasons such as its own or other host network element devices having used its computing power resources during the update period of the first auxiliary computing power list. At this time, the target auxiliary network element device can be used as a new host base station to decompose tasks to more downstream auxiliary network element devices.
[0186] Step 20010, if C2 >= (R1 - C1) is not satisfied, that is, C2 < (R1 - C1), then the host base station NodeB decomposes part of the remaining target first-level DPI decomposition tasks C2 with task priority Slevel1 to the target auxiliary network element device at level 2, and the remaining target first-level DPI decomposition tasks (R1 - C1 - C2) * {c, m, b} are decomposed to the target auxiliary network element device C3 * {c, m, b} at level 3 for processing. If there is no target auxiliary network element device at level 3, then go to step 20013.
[0187] Step 20011, determine whether the computing power resources of the target auxiliary network element device at level 3 are greater than or equal to the computing power required for all the remaining target first-level DPI decomposition tasks with task priority Slevel1, that is, whether C3 >= (R1 - C1 - C2) is satisfied. If so, execute 20012. If not, that is, C3 < (R1 - C1 - C2), then the host base station NodeB decomposes part of the remaining target first-level DPI decomposition tasks C2 with task priority Slevel1 to the target auxiliary network element device at level 3, and the remaining target first-level DPI decomposition tasks (R1 - C1 - C2) * {c, m, b} can be over-decomposed to the first-level cascaded devices at level 3 in the order of task priorities Slevel1, Slevel2, and Slevel3.
[0188] Step 20012, if C3 >= (R1 - C1 - C2) is satisfied, it means that the host base station NodeB decomposes all the remaining target first-level DPI decomposition tasks with a task priority of Slevel1 to the target auxiliary network element device at level 3. Similarly, on this basis, since the target auxiliary network element device is dynamic, that is, it is possible that its computing power resources cannot complete the target first-level DPI decomposition tasks as scheduled due to reasons such as its own or other host network element devices having used its computing power resources during the update period of the first auxiliary computing power list. At this time, the target auxiliary network element device can be used as a new host base station to decompose tasks to more downstream auxiliary network element devices.
[0189] Step 20013, determine whether the target auxiliary network element device can complete all the target first-level DPI decomposition tasks. If so, execute Step 20014; if not, execute Step 20015.
[0190] Step 20014, in the case where the target auxiliary network element device has completed all the target first-level DPI decomposition tasks, return the target analysis result to the host base station.
[0191] Step 20015, in the case where the target auxiliary network element device has not completed all the target first-level DPI decomposition tasks, determine whether the delay from the host base station to the independently deployed DPI processing node with a cascade level of two is less than the delay to the second auxiliary network element device. If so, execute Step 20017; if not, execute Step 20016.
[0192] Step 20016, if the delay C 独立 from the host base station to the independently deployed DPI processing node with a cascade level of two 第一辅助 is less than C 第二辅助 + C 第一辅助 + C 第二辅助 where C 第一辅助 is the delay from the host base station to the target auxiliary network element device, C 第二辅助 is the delay from the target auxiliary network element device to the second auxiliary network element device, and C
[0193] Step 20017, if there is no independently deployed DPI processing node, or the delay C 独立 from the host base station to the independently deployed DPI processing node with a cascade level of two 第一辅助 is greater than or equal to C 第二辅助, then use the target auxiliary network element device at Level1 as the new host base station to decompose the remaining tasks to the second auxiliary network element device. The transfer of cascaded tasks can further improve the computing power.
[0194] After all the DPI parsing tasks after the above decomposition are completed, the parsing results are returned along the original path, and the host network element device makes corresponding guarantees and reports as needed.
[0195] Embodiment 4: On the basis of Embodiment 1, all the over-allocated target first-level DPI decomposition tasks of Slevel1 are allocated to the target auxiliary network element devices at Level1 according to the weight ratio. If each target auxiliary network element device can complete all the target first-level DPI decomposition tasks it receives, then return the target parsing result; if it cannot complete all the target first-level DPI decomposition tasks it receives, then use the target auxiliary network element device at Level1 as the new host base station and distribute tasks to its corresponding second auxiliary network element device.
[0196] After the processing of the target first-level DPI decomposition tasks of Slevel1 is completed, the target first-level DPI decomposition tasks of Slevel2 and Slevel3 are processed in sequence. The steps are similar to the above processing process and will not be elaborated here.
[0197] It can be seen from the above Embodiments 1 to 4 that, compared with deploying the DPI processing unit to an independently deployed DPI processing node, deploying the DPI processing unit to the host network element device for DPI task sinking can more effectively guarantee user perception and improve network performance, reduce the overhead of independent deployment, and effectively reduce the deployment cost; each node in the same shared computing power cloud cluster shares computing power resources, which can increase the computing power resource capacity for processing DPI task sinking deployment; in addition, the update and orchestration of the computing power resources of the host network element device for the auxiliary network element device can effectively save the time for computing and determining the appropriate auxiliary network element device.
[0198] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0199] Example embodiments have been disclosed herein, and although specific terms have been employed, they are used only and should be interpreted only as general illustrative meanings and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly stated, features, characteristics, and / or elements described in connection with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in connection with other embodiments. Accordingly, those skilled in the art will understand that various forms and details may be changed without departing from the scope of the disclosure as set forth by the appended claims.
Claims
1. A Deep Packet Inspection (DPI) method for a host network element device, wherein, The method includes: Based on the idle computing power resources of the host network element device and the computing power resources corresponding to the DPI parsing task, decompose the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task; Based on the target first-level DPI decomposition task, receive the target parsing result of the target first-level DPI decomposition task fed back by the target auxiliary network element device corresponding to the host network element device; According to the target parsing result, determine the DPI parsing result of the DPI parsing task.
2. The deep packet detection method according to claim 1, wherein Before the step of decomposing the DPI parsing task based on the idle computing power resources of the host network element device and the computing power resources corresponding to the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task, it further includes: Obtain the transmission delay between the auxiliary network element device and the host network element device, and the idle computing power resources of the auxiliary network element device; Based on the idle computing power resources of the auxiliary network element device, the preset computing power resources, the transmission delay, and the preset delay, determine the first auxiliary network element device; According to the first auxiliary network element device, construct a first auxiliary computing power list; the first auxiliary computing power list is used to record the idle computing power resources corresponding to each first auxiliary network element device.
3. The deep packet detection method according to claim 2, wherein The step of determining the first auxiliary network element device based on the idle computing power resources of the auxiliary network element device, the preset computing power resources, the transmission delay, and the preset delay includes: Compare the idle computing power resources of the auxiliary network element device with the preset computing power resources to obtain a first comparison result, and compare the transmission delay with the preset delay to obtain a second comparison result; In the case where the first comparison result shows that the idle computing power resources of the auxiliary network element device are more than or equal to the preset computing power resources, and the second comparison result shows that the transmission delay is less than the preset delay, determine the auxiliary network element device as the first auxiliary network element device.
4. The deep packet detection method according to claim 1, characterized in that The step of decomposing the DPI parsing task based on the idle computing power resources of the host network element device and the computing power resources corresponding to the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task includes: Compare the idle computing power resources of the host network element device with the computing power resources corresponding to the DPI parsing task to obtain a comparison result; In the case where the comparison result shows that the idle computing power resources of the host network element device are less than the computing power resources corresponding to the DPI parsing task, decompose the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task.
5. The deep packet detection method according to claim 4, wherein, The step of decomposing the DPI parsing task to obtain a non-target first-level DPI decomposition task and a target first-level DPI decomposition task includes: Decompose the DPI parsing task to obtain a plurality of first-level DPI decomposition tasks; Determine that at least part of the first-level DPI decomposition tasks are target first-level DPI decomposition tasks, and determine that the remaining first-level DPI decomposition tasks are non-target first-level DPI decomposition tasks; the total computing power resources required for the non-target first-level DPI decomposition tasks are equal to or less than the idle computing power resources in the host network element device.
6. The deep packet inspection method according to claim 5, wherein, The determining that the remaining first-level DPI decomposition tasks are non-target first-level DPI decomposition tasks includes: Select at least part of the first-level DPI decomposition tasks from multiple first-level DPI decomposition tasks as non-target first-level DPI decomposition tasks in the order of the task priorities corresponding to each first-level DPI decomposition task from high to low.
7. The deep packet detection method according to claim 1, wherein Based on the target first-level DPI decomposition tasks, receiving the target parsing results of the target first-level DPI decomposition tasks fed back by the corresponding target auxiliary network element device of the host network element device includes: Sending the target first-level DPI decomposition tasks to the target auxiliary network element device; Receiving the target parsing results of the target first-level DPI decomposition tasks fed back by the target auxiliary network element device.
8. The deep packet inspection method according to claim 7, wherein, The sending the target first-level DPI decomposition tasks to the target auxiliary network element device includes: Determine the first auxiliary network element device corresponding to the target first-level DPI decomposition task in the first auxiliary computing power list; the first auxiliary computing power list is used to record the idle computing power resources corresponding to each first auxiliary network element device; Send the target first-level DPI decomposition tasks to the corresponding target auxiliary network element device.
9. The deep packet detection method according to claim 7, wherein, Before sending the target first-level DPI decomposition tasks to the target auxiliary network element device, it further includes: Sending a computing power request to each first auxiliary network element device in the first auxiliary computing power list; Receiving the computing power resource status fed back by the first auxiliary network element device; Updating the first auxiliary computing power list according to the computing power resource status.
10. The deep packet detection method according to claim 7, wherein, The sending the target first-level DPI decomposition tasks to the corresponding target auxiliary network element device includes: Send the target first-level DPI decomposition tasks to the target auxiliary network element device with the highest associated priority according to the idle computing power resources and the associated priority corresponding to the target auxiliary network element device; In the case where the total idle computing power resources of the target auxiliary network element device with the highest associated priority are less than the total computing power resources required for the target first-level DPI decomposition tasks, select the target auxiliary network element device with a lower associated priority step by step in the order of the associated priority from high to low to send the remaining target first-level DPI decomposition tasks until all the target first-level DPI decomposition tasks are sent or have been sent to all the target auxiliary network element devices.
11. A deep packet inspection method for a target auxiliary network element device, wherein, The method includes: Based on the target first-level DPI decomposition tasks sent by the host network element device, determine the target parsing results of the target first-level DPI decomposition tasks; Send the target parsing results to the host network element device.
12. The deep packet inspection method according to claim 11, wherein, The based on the target first-level DPI decomposition tasks sent by the host network element device, determining the target parsing results of the target first-level DPI decomposition tasks includes: Decompose the target first-level DPI decomposition task based on the idle computing power resources of the target auxiliary network element device and the computing power resources corresponding to the target first-level DPI decomposition task, to obtain a non-target second-level DPI decomposition task and a target second-level DPI decomposition task; Based on the target second-level DPI decomposition task, receive the first parsing result of the target second-level DPI decomposition task fed back by the second auxiliary network element device corresponding to the target auxiliary network element device; Determine the target parsing result of the target first-level DPI decomposition task according to the first parsing result.
13. A network element device, comprising: One or more processors; A memory storing one or more programs, which when executed by the one or more processors cause the one or more processors to implement the deep packet inspection method according to any one of claims 1 to 12.
14. A computer-readable medium storing a computer program, which when executed by a processor implements the deep packet inspection method according to any one of claims 1 to 12.