Message transmission method of network equipment, network equipment and network system

By using the first conversion unit and processing unit in the network device for message transmission and using the index value set to check tables, the problem that the message table check operation in the prior art occupies large bit-wide resources, and the efficient utilization of resources and the efficiency of table lookup operations are achieved.

CN120200969APending Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311788347.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Existing network devices occupy a large bit width resource in message table lookup operation, resulting in waste of resources.

Method used

By introducing a first conversion unit and a processing unit into the network device, receiving messages and outputting an index value set, the processing unit looks up the table based on the index value set and outputs the second index value set. This method reduces the bit width requirement of the data bus and optimizes the bit width resource usage of table lookup operations.

Benefits of technology

It effectively reduces the bit width requirement of the data bus, improves the efficiency of table lookup operations, and reduces resource overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200969A_ABST
    Figure CN120200969A_ABST
Patent Text Reader

Abstract

The invention provides a message transmission method of network equipment, the network equipment and a network system, which are applied to the field of internet computing and are used for solving the problem of resource waste caused by the fact that the previous network equipment occupies a relatively large bit width resource when executing a table look-up operation. The network equipment comprises a first interface, a first conversion unit, a processing unit, a second conversion unit, a switching unit and a second interface. When the method is executed, a first conversion unit receives a first message input by a first interface and outputs a first index value set; wherein the first index value set comprises index values of a plurality of tuples in the message header of the first message. Each tuple represents one piece of domain segment information in the message header. The processing unit can look up the table according to a plurality of index values in the first index value set and output a second index value set. And then, the second index value set can be recovered into a data packet through the second conversion unit, and is output from the second interface under the forwarding of the switching unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technologies, and in particular, to a method for transmitting packets by a network device, a network device, and a network system. Background Art

[0002] When transmitting data in a network, it is necessary to encapsulate it, that is, add the corresponding header information of each layer in the network reference model. In each layer of the Ethernet hierarchical model, a header is attached to the data being sent, and this header contains the necessary information for that layer, such as the destination address to be sent and protocol-related information. During the data forwarding process, network devices used for forwarding data (such as switches, routers, bridges, etc.) may need to extract the encapsulation information of the packet for data transmission and forwarding control. Among them, such network devices need to extract the tuples in the data encapsulation header for table lookup, and perform corresponding action processing on packets that match specific characteristics. Currently, the transmission and forwarding control in network devices generally adopts a pipeline structure, and the processing circuits at each level of the pipeline correspond to different service controls. A packet may need to complete the lookup and processing of one or more service entries in a network device used for forwarding the packet. In the current table lookup method, the tuple information set is transmitted on the data bus of the network device. The processing circuits corresponding to each service table extract the required tuple information from the data bus according to the service characteristics to form a lookup key for service table lookup operations. However, when using the above method for table lookup, it requires a large bit-width resource, increasing the resource overhead of table lookup. Therefore, there is an urgent need to provide a solution to solve the above problems. Summary of the Invention

[0003] Embodiments of this application provide a method for transmitting packets by a network device, a network device, and a network system to solve the problem of resource waste caused by currently large bit-width resources occupied by network devices during table lookup operations based on packets.

[0004] To solve the above problems, the technical solutions provided by the embodiments of this application are as follows.

[0005] In a first aspect, a method for transmitting packets of a network device is provided. The network device includes a first interface, a first conversion unit coupled to the first interface, and a processing unit coupled to the first conversion unit. When the packet transmission method is executed, the first conversion unit can receive a first packet input by the first interface and output a first set of index values. Among them, the first set of index values includes index values of multiple tuples in the packet header of the first packet. Each tuple represents a field segment information in the packet header. Then, the processing unit performs a look-up table based on the multiple index values in the first set of index values and outputs a second set of index values. In this way, when performing a look-up table in the packet transmission method provided by the present application, the data bus in the processing unit transmits a set of index values instead of a set of tuple information, reducing the bit-width requirement of the data bus. At the same time, the processing unit performs a look-up table through index values and also outputs a set of index values, which can also occupy less bit-width resources.

[0006] In a possible implementation, when the first conversion unit receives the first packet input by the first interface and outputs the first set of index values, it can perform a look-up table based on each tuple in the first packet to output the first set of index values. In this way, the first conversion unit can directly read the look-up table to obtain the index values of each tuple in the first packet and form a set of index values according to the index values, without performing too many operations, improving the query efficiency.

[0007] In a possible implementation, the processing unit includes multiple processing circuits coupled by a data bus. Among them, when the processing unit performs a look-up table based on the multiple index values in the first set of index values and outputs the second set of index values, the multiple processing circuits can perform a look-up table through a search keyword composed of the multiple index values in the first set of index values to obtain the second set of index values. Among them, each processing circuit uses a different search keyword for the look-up table. In this way, different processing circuits can extract the required index values from the set of index values transmitted by the data bus according to their own executed functions to form a search keyword, and perform a look-up table operation according to the search keyword. Compared with the existing method of extracting multiple tuples from a set of tuple information to form a search keyword and querying service entries according to the formed search keyword, the above method reduces the bit-width resources occupied by the search keyword.

[0008] In a possible implementation, each of the above processing circuits performs a look-up table from the same or different memories in the network device. In this way, the multiple processing circuits in the processing unit can perform a look-up table from the same or different memories according to actual needs, so as to select the storage method of the look-up table according to actual needs.

[0009] In a possible implementation, the above network device further includes a switching unit, a second conversion unit, and a second interface. Among them, the switching unit is coupled to the processing unit, and the second interface is coupled to the switching unit through the second conversion unit. Based on this, when the above message transmission method is executed, the switching unit can forward the second index value set to the second conversion unit. Then, the second conversion unit receives the second index value set and outputs a second message to the second interface. Among them, the second message and the first message are the same or different messages. In the above manner, the switching unit only needs to forward the second index value set, which can improve the forwarding efficiency.

[0010] In a possible implementation, the above network device further includes a switching unit, a second conversion unit, and a second interface. Among them, the second conversion unit is coupled to the processing unit, and the second interface is coupled to the second conversion unit through the switching unit. Based on this, when the above message transmission method is executed, the second conversion unit can receive the second index value set and output a second message. Among them, the second message and the first message are the same or different messages. Then, the switching unit forwards the second message to the second interface. In the above manner, the switching unit can directly output the second message from the second interface, thereby reducing the subsequent processing process.

[0011] In a possible implementation, when the second conversion unit receives the second index value set and outputs a second message, it can perform a look-up table according to each index value in the second index value set to output the second message. In the above manner, the second conversion unit can perform a look-up table according to the second index value set by means of a look-up table and output the second message, without excessive operations, thereby improving the transmission efficiency.

[0012] In a second aspect, a network device is provided. The network device includes a first interface, a first conversion unit coupled to the first interface, and a processing unit coupled to the first conversion unit. Among them, the first conversion unit can receive a first message input by the first interface and output a first index value set. Among them, the above first index value set includes index values of multiple tuples in the message header of the first message. Each tuple represents a field segment information in the message header. Then, the processing unit performs a look-up table according to the multiple index values in the first index value set and outputs a second index value set.

[0013] In a possible implementation, the first conversion unit can perform a look-up table according to each tuple in the first message to output the first index value set.

[0014] In a possible implementation, the above-mentioned processing unit includes a plurality of processing circuits coupled by a data bus. When the processing unit looks up a table according to a plurality of index values in the first index value set and outputs a second index value set, the above-mentioned plurality of processing circuits can look up the table with a search keyword composed of the plurality of index values in the first index value set to obtain the second index value set. Each processing circuit uses a different search keyword to look up the table.

[0015] In a possible implementation, each of the above-mentioned processing circuits looks up the table from the same or different memories in the network device.

[0016] In a possible implementation, the above-mentioned network device further includes a switching unit, a second conversion unit, and a second interface. The switching unit is coupled to the processing unit, and the second interface is coupled to the switching unit through the second conversion unit. The switching unit can forward the second index value set to the second conversion unit. Then, the second conversion unit receives the second index value set and outputs a second message to the second interface. The second message and the first message are the same or different messages.

[0017] In a possible implementation, the above-mentioned network device further includes a switching unit, a second conversion unit, and a second interface. The second conversion unit is coupled to the processing unit, and the second interface is coupled to the second conversion unit through the switching unit. The second conversion unit can receive the second index value set and output a second message. The second message and the first message are the same or different messages. Then, the switching unit forwards the second message to the second interface.

[0018] In a possible implementation, when the second conversion unit receives the second index value set and outputs a second message, it can look up the table according to each index value in the second index value set to output the second message.

[0019] In a third aspect, a network system is provided. The network system includes a plurality of terminal devices and a plurality of network devices according to any possible implementation in the second aspect above. The plurality of terminal devices are communicatively connected through the plurality of network devices.

[0020] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a network device, the message transmission method in any possible implementation manner in the first aspect above is implemented.

[0021] In a fifth aspect, a computer program product is provided. When the computer program product is executed by a network device, the message transmission method in any possible implementation manner in the first aspect above is implemented.

[0022] For the technical effects brought by the above second aspect to the fifth aspect and possible embodiments, reference can be made to the description of the technical effects brought by the above first aspect and possible embodiments, which will not be elaborated here. Description of the Drawings

[0023] Figure 1 It is a schematic diagram of the hierarchical encapsulation process of Ethernet data provided by an embodiment of the present application;

[0024] Figure 2 It is a schematic diagram of the architecture of a network system provided by an embodiment of the present application;

[0025] Figure 3 It is a schematic diagram of the forwarding process of Ethernet data provided by an embodiment of the present application;

[0026] Figure 4 It is a schematic diagram of the transmission and forwarding pipeline structure of a network device provided by an embodiment of the present application;

[0027] Figure 5 It is a schematic diagram of the structure of different service entries provided by an embodiment of the present application;

[0028] Figure 6 It is a schematic diagram of the structure of a network device provided by an embodiment of the present application;

[0029] Figure 7 It is a schematic diagram of the process of a message transmission method of a network device provided by an embodiment of the present application;

[0030] Figure 8 It is another schematic diagram of the structure of a network device provided by an embodiment of the present application;

[0031] Figure 9 It is another schematic diagram of the process of a message transmission method of a network device provided by an embodiment of the present application;

[0032] Figure 10 It is still another schematic diagram of the structure of a network device provided by an embodiment of the present application. Detailed Embodiments

[0033] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0034] To facilitate a clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner for easy understanding.

[0035] When describing some embodiments, expressions such as "coupled" and "connected" and their derivatives may be used. For example, when describing some embodiments, the term "connected" may be used to indicate that two or more components have direct physical contact or point contact with each other. Another example is that when describing some embodiments, the term "coupled" may be used to indicate that two or more components have direct physical contact or electrical contact, and may also refer to two or more components that do not have direct contact with each other, but still cooperate or interact with each other. The embodiments disclosed herein are not necessarily limited to the content herein. Additionally, for ease of understanding, the following first introduces the technical terms related to the embodiments of the present application.

[0036] Tuple: The field segment information extracted from the message header of a message (i.e., the headers of each layer in the network reference model), which can represent some basic attributes of a network message. These field segment information are called tuples. The combined form of several different attribute field segment information is called an n-tuple.

[0037] The following provides a detailed description of the present application in conjunction with the drawings and embodiments:

[0038] Data transmitted in the network needs to be encapsulated, that is, add the corresponding header information of each layer in the network reference model. Such as Figure 1As shown in the figure, assume that the reference model in the terminal device is an Ethernet hierarchical model that includes the application layer, transport layer, network layer, data link layer, and physical layer. Then, during the process of transmitting data, each layer of the terminal device acting as the sender will attach a header to the user data being sent. For example, in front of the user data, the header of the application layer (Appl header), the header of the transport layer (TCP header), the header of the network layer (IP header), and the Ethernet header of the data link layer are attached in sequence. These headers contain the necessary information of this layer, such as the destination address to be sent and protocol-related information. Before data is sent, according to the reference model from top to bottom, when the data passes through each layer, protocol header information needs to be added. After the data is encapsulated, it can be forwarded to the terminal device acting as the receiver through the network devices in the network system. After the terminal device acting as the receiver receives the packet, the packet then removes the protocol header information in the order from bottom to top according to the reference model, and restores and merges the packet into the original communication data.

[0039] As Figure 2 shown, in the network system 200, multiple terminal devices 210 can achieve communication connections through multiple network devices 220. When multiple terminal devices 210 communicate with each other, the communication data is first segmented and encapsulated in a packet at the terminal device acting as the sender (such as Figure 2 the terminal device 1 in), and injected into the network. Then, it is transmitted through the routing and forwarding of multiple network devices 220 (such as Figure 2 the network device 1, network device 2, network device 3, network device 4 in). Finally, the packet reaches the terminal device acting as the receiver (such as Figure 2 the terminal device 2 in), and is restored and merged into the original communication data. Among them, the above-mentioned network devices 220 include but are not limited to switches, routers, hubs, etc. In the above implementation process, the network device 220 performs independent routing and forwarding on each packet. Specifically, when a packet arrives at the input port of the network device 220, the network device 220 determines the output port of the packet based on the address information in the packet, such as the destination MAC address or destination IP address, and exchanges the packet from the input port to the output port. Usually, the process of "determining the output port of the packet" is called "routing", and the process of "exchanging the packet from the input port to the output port" is called "forwarding". In most network devices 220, the routing of packets is achieved by looking up a table. Among them, there is one or more logical "lookup tables" in the network device 220, also called "routing tables". Each table contains one or more table entries, and each table entry contains address matching information and output port information, etc. The network device 220 extracts the address information in the packet and matches it with the address information in the table entry to determine the matching table entry, and extracts the output port information from the matching table entry to determine the output port.

[0040] Exemplarily, as Figure 3 As shown, assume that the terminal devices in a certain network system 300 include terminal device 1 and terminal device 2. The network devices include switch 1, router 1, router 2, and switch 2. Among them, terminal device 1 establishes a communication connection with terminal device 2 through switch 1, router 1, router 2, and switch 2 in sequence. During a certain data transmission process, if terminal device 1 is the sending end and terminal device 2 is the receiving end, the message to be transmitted in terminal device 1 can first be looked up in the table by switch 1 and forwarded to router 1. Then, the message is looked up in the table by router 1 and forwarded to router 2. Then, the message is forwarded to switch 2 by router 2 looking up the table. Finally, the message is forwarded to terminal device 2 by switch 2 looking up the table. Among them, switch 1 and switch 2 are network devices at the data link layer. Therefore, switch 1 and switch 2 only forward and process the message at the physical layer and the data link layer. Router 1 and router 2 are network devices at the network layer. Therefore, router 1 and router 2 need to forward and process the message at the physical layer, the data link layer, and the network layer. The message will perform different action processes according to different data characteristics in each network device. That is, the network devices between the two terminal devices may need to extract the message header of the message for data forwarding processing. Among them, the network device can extract the tuples in the message header to form a search keyword for looking up the table, and the message that matches a specific feature will perform the corresponding action. For example, different destination port addresses look up the table to obtain different path forwarding output ports.

[0041] As Figure 4As shown, the forwarding processing in the network device 220 generally adopts a pipelined structure. In this pipelined structure, packets go through multiple processing stages inside the network device, and each stage is responsible for by an independent module. These modules can work in parallel, and each module is responsible for a specific function. For example, packet parsing, forwarding decision-making, routing calculation, forwarding table update, etc. By splitting the processing process of the network device into multiple modules and processing them in a pipelined manner, the network device can process multiple packets simultaneously, improving the processing efficiency. Since each module works independently, module combination and adjustment can be carried out according to requirements to adapt to different service industries. The pipelined architecture of the network device is an efficient, flexible and reliable architecture that can provide better network performance and service quality. In the pipelined structure of the network device, each level of module corresponds to different service controls. For example, the access control list (ACL) completes the admission control of packets to avoid network malicious attacks. The network address transfer (NAT) table / network address port transfer (NAPT) table completes the network address transfer of packets to realize data transfer between internal and external networks. The forwarding information table (FIB) completes the source port learning within the local network and the destination forwarding port lookup, and establishes communication between the terminal device at the sending end and the terminal device at the receiving end. Among them, each level of module can be implemented by an independent processing circuit (for example Figure 4The processing circuits 1 to n). A packet may need to complete the lookup and processing of one or more service entries in a network device. Different tuples (feature information in the encapsulation header) are required for different table lookup services. Typical ones include triples, quadruples, and quintuples. Among them, the structure of a triple can be expressed as {internet protocol address (IP), protocol, port address (media access control address, MAC)}. The structure of a quadruple can be expressed as {source internet protocol address (SIP), destination internet protocol address (DIP), source media access control address (SMAC), destination media access control address (DMAC)}. The structure of a quintuple can be expressed as {SIP, SMAC, DIP, DMAC, protocol}. Different tuple compositions require the data bus of the network device to carry these tuple information sets, facilitating different table lookup services to extract different tuples to form table lookup keys (keys), perform lookups, and execute the actions specified in the entries (such as modifying, deleting, or adding tuples, receiving or discarding packets, etc.). However, the bit widths of tuples with the same meaning in different network protocol definitions may be different, and in practical applications, they need to be aligned for transmission, resulting in low resource utilization. For example, Table 1 shows the packet header structure of the IPv4 network, and Table 2 shows the packet header structure of the IPv6 network. It can be seen from Table 1 and Table 2 that there are obvious differences in the packet header structures of packets in the IPv6 network and the IPv4 network. Among them, the bit widths of the source address and destination address in the IPv6 network are 128 bits, and the bit widths of the source address and destination address in the IPv4 network are 32 bits. In the case of needing to support the IPv6 network, if the IPv4 network coexists, all address tuples of IPv4 need to be aligned to the bit width corresponding to the IPv6 address, that is, 128 bits, so that the bit width of the table lookup key involving address tuple information will be stretched very large.

[0042] Table 1

[0043]

[0044] Table 2

[0045]

[0046] In existing network devices, all tuples required for search keywords in table lookup services are transmitted on the data bus (or called pipeline bus) in the form of a tuple information set. The processing circuits corresponding to different table lookup services extract the tuples on the data bus as needed to form table lookup keywords, resulting in a large consumption of bit-width resources. For example, Figure 5 as shown, the composition of the search keyword for the ACL table is {SIP, DIP, SMAC, DMAC, VLAN}. The composition of the search keyword for the NAT table is {SIP, DIP, differentiated services code point (DSCP)}. The composition of the search keyword for the NAPT table is {SIP, DIP, source port (SPORT), destination port (DPORT)}. The composition of the search keyword for the input port (FIB_ic) in the FIB table is {SMAC, VLAN}. The composition of the search keyword for the input port (FIB_pp) in the FIB table is {DMAC, VLAN}. From Figure 5 it can be seen that the tuples in the table lookup keyword have a large bit-width but few specifications. However, using the above method still causes the problem of waste of bit-width resources for table lookup keywords. For example, assume that there are only 2 terminal devices at the receiving end, then the corresponding destination media access control address (DMAC) is 2, and the virtual local area network (VLAN) address is divided into 3. Among them, the composition of the table lookup keyword for the forwarding information table is {DMAC, VLAN}, then the table lookup space can support a maximum of 6 queries for search keywords. The bit-width of each search keyword is 64 bit (i.e., 48 bit of DMAC + 16 bit of VLAN). It can be seen that for only 6 search keywords, the matching bit-width requires 64 bit, resulting in a waste of bit-width resources.

[0047] To solve the above problems, as Figure 6As shown in the figure, an embodiment of the present application provides a network device 600. The network device 600 includes a first interface P1, a first conversion unit 610, a processing unit 620, a switching unit 630, a second conversion unit 640, and a second interface P2. Among them, the first conversion unit 610 is coupled to the first interface P1. The processing unit 620 is coupled to the first conversion unit 610. The switching unit 630 is coupled to the processing unit 620. The second interface P2 is coupled to the switching unit 630 through the second conversion unit 640. Among them, the first conversion unit 610 can receive the first packet input by the first interface P1 and output a first set of index values. Among them, the above first set of index values includes the index values of multiple tuples in the packet header of the first packet. Each tuple represents a field segment information in the packet header. The processing unit 620 can perform a look-up table based on the multiple index values in the first set of index values and output a second set of index values. The switching unit 630 can forward the second set of index values to the second conversion unit 640. Then, the second conversion unit 640 receives the second set of index values and outputs a second packet to the second interface P2. Among them, the second packet and the first packet are the same or different packets.

[0048] In an implementation, still as Figure 6 shown, the above processing unit 620 may include a plurality of processing circuits (such as Figure 6 the first processing circuit to the nth processing circuit in) coupled by a data bus 621. The above plurality of processing circuits can form a pipelined structure through the data bus 621, and the above plurality of processing circuits can run in parallel. Among them, the above plurality of processing circuits can perform a look-up table through the search keywords composed of the multiple index values in the first set of index values to obtain the second set of index values. Among them, each processing circuit can use different search keywords (such as Figure 6 K1 to Kn in) to perform a look-up table.

[0049] In the network device 600, it is usually necessary to perform look-up table operations on different table entries such as the ACL table, NAT table, NAPT table, and FIB table. Among them, from Figure 5 the corresponding description, it can be seen that the search keywords required for different look-up table operations are also different. When using the packet transmission method provided by the present application for look-up table, the data bus in the processing unit 620 transmits a set of index values, rather than a set of tuple information, reducing the bit width requirement of the data bus. At the same time, the processing unit 620 performs a look-up table through index values and also outputs a set of index values, which can also occupy less bit width resources.

[0050] In one embodiment, the first conversion unit 610 may look up a table according to each tuple in the first message to output a set of first index values. Among them, the look-up table for the first conversion unit 610 to look up the table may include the correspondence between tuples such as SIP, DIP, SMAC, DMAC, etc. and index values. The correspondence between various tuples and the corresponding index values may be stored in different storage areas in the memory and cached in different buffers in the first conversion unit 610, so as to obtain the index values of various tuples more orderly.

[0051] In one example, it is assumed that there are 2 SIPs and 2 DIPs, 3 SMACs and 3 DMACs, and 3 VLANs in the message. Then the two SIPs can be distinguished by index values 0 and 1; the two DIPs can also be distinguished by index values 0 and 1; the three SMACs can be distinguished by index values 00, 01 and 10; the three DMACs can be distinguished by index values 00, 01 and 10; the three VLANs can be distinguished by 00, 01 and 10. Among them, if the index value of the SIP in a certain message after looking up the table is 0; the index value of the DIP after looking up the table is 1; the index value of the SMAC after looking up the table is 00; the index value of the DMAC after looking up the table is 01; and the VLAN is 00. Then the set of index values output by the first conversion unit 610 is {0, 1, 00, 01, 00}. If a processing circuit is performing a look-up table operation on the input port (FIB_ic) in the FIB table at this time, then from Figure 5 the look-up table key structure, it can be seen that the look-up table key constructed according to the index value is {00, 00}. If a processing circuit is performing a look-up table operation on the ACL table at this time, then from Figure 5 the look-up table key structure, it can be seen that the look-up table key constructed according to the index value is {0, 1, 00, 01, 00}.

[0052] In the above manner, the original 32-bit or 128-bit SIP can be replaced with a 2-bit or 1-bit index value. At the same time, 2-bit index values can also be used to replace SMAC and DMAC, greatly reducing the occupancy of tuple bit-width resources. Of course, the above embodiment is only an example provided by the embodiments of the present application. The number of index values in the above set of index values can be adaptively adjusted according to the look-up table types that the processing unit 620 needs to execute, and the embodiments of the present application will not elaborate on this here.

[0053] In one embodiment, the above-mentioned first conversion unit 610 and second conversion unit 640 can be implemented by multiple logic devices or circuits, or by a processor / die, etc. The above-mentioned first processing circuit to the nth processing circuit can be implemented by multiple logic devices or circuits. In one embodiment, the above-mentioned first processing circuit to the nth processing circuit can be implemented by different processing cores / dies in a processor, or by multiple processors. In one example, when the first processing circuit to the nth processing circuit is implemented by multiple processors, the above-mentioned multiple processors can be integrated in one or more chips, and the multiple chips can be regarded as a chipset. When the above-mentioned multiple processors are integrated in the same chip, the chip is also called a system on a chip (SOC). In addition to the above-mentioned multiple processors, the network device 600 further includes one or more other necessary components, such as a memory 650. The memory 650 can store lookup tables such as an ACL table, a NAT table, a NAPT table, and a FIB table. Of course, the memory 650 can also store the program instructions of the first conversion unit 610 and the program instructions of each processing circuit in the processing unit 620 to support each processing circuit in the first conversion unit 610 and the processing unit 620 to perform corresponding operations. In one possible implementation manner, the memory 650 can be located in the same system on a chip in the network device 600 as the above-mentioned multiple processors, that is, the memory 650 is integrated in the network device 600 as shown in Figure 6 above. At this time, the memory 650 can include on-chip random access memory (RAM).

[0054] In one embodiment, each of the above-mentioned processing circuits can look up a table from the same or different memories in the network device, so as to adjust according to the storage method of the lookup table according to actual requirements.

[0055] In one embodiment, the second conversion unit 640 can look up a table according to each index value in the second index value set to output a second message. Among them, the second conversion unit 640 can share a lookup table with the first conversion unit 610 to reduce the occupation of storage space.

[0056] In one embodiment, as Figure 7 shown, the embodiment of the present application further provides a message transmission method for a network device 600. The specific process of the message transmission method is as follows.

[0057] S701. The first conversion unit receives a first message input by a first interface and outputs a first index value set.

[0058] Among them, the above first index value set includes index values of multiple tuples in the message header of the message. Each tuple represents a field segment information in the message header.

[0059] In an implementation, the first conversion unit 610 may first obtain a lookup table from the memory 650. Then, extract the index values of each tuple from the lookup table to form the first index value set, and output the first index value set to the data bus of the processing unit 620. Among them, the above lookup table includes the correspondence between each tuple and each index value. In the above manner, the first conversion unit 610 can directly convert each tuple in the message header of the received message into the corresponding index value by means of the lookup table. Of course, the first conversion unit 610 can also calculate the index values of each tuple through the corresponding index value algorithm (such as the hash algorithm), which is not elaborated in this embodiment of the present application.

[0060] In an implementation, the above lookup table may include the correspondence between tuples such as SIP, DIP, SMAC, DMAC and index values. Among them, the correspondence between various tuples and the corresponding index values can be stored in different storage areas in the memory 650 and cached in different buffers in the first conversion unit 610, so as to obtain the index values of various tuples more orderly.

[0061] S702. The processing unit performs a table lookup according to multiple index values in the first index value set and outputs a second index value set.

[0062] In one embodiment, the above-mentioned processing unit 620 may include multiple processing circuits. For example, the above-mentioned processing unit 620 may include a first processing circuit, a second processing circuit, a third processing circuit, and a fourth processing circuit. Among them, the first processing circuit may extract the index values corresponding to each tuple in the lookup table keywords {SIP, DIP, SMAC, DMAC, VLAN} from the above-mentioned first index value set to form a first lookup table keyword, and look up the corresponding first service entry from the ACL table through this first lookup table keyword. Among them, the service entries in the ACL table are used to indicate the operation of permitting packet forwarding or the operation of discarding packets. After the first processing circuit obtains the first service entry, it may execute the corresponding operation and output the corresponding index value. The second processing circuit may extract the index values corresponding to each tuple in the lookup table keywords {SIP, DIP, DSCP} from the above-mentioned first index value set to form a second lookup table keyword, and look up the corresponding second service entry from the NAT table through this second lookup table keyword. Among them, the service entries in the NAT table are used to indicate the IP address conversion operation that needs to be performed on the packet header of the packet. For example, after the second processing circuit obtains the second service entry, it may convert the index values corresponding to SIP and DIP in the local area network into the index values corresponding to SIP and DIP in the Ethernet. The third processing circuit may extract the index values corresponding to each tuple in the lookup table keywords {SIP, DIP, SPORT, DPORT} from the above-mentioned first index value set to form a third lookup table keyword, and look up the corresponding third service entry from the NAPT table through this second lookup table keyword. Among them, the service entries in the NAPT table are used to indicate the IP address conversion operation and port conversion operation that need to be performed on the packet header of the packet. After the third processing circuit obtains the third service entry, it may output the index values corresponding to the corresponding IP address and port address. The fourth processing circuit may extract the index values corresponding to each tuple in the lookup table keywords {SMAC, VLAN} from the above-mentioned first index value set to form a fourth lookup table keyword, and look up the corresponding fourth service entry from the FIB table through this second lookup table keyword. The service entries in the FIB table are used to indicate the source port and the destination port to establish communication between the source port and the destination port. After the fourth processing circuit obtains the above-mentioned fourth service entry, it can output the index values corresponding to the source port address and the destination port address.

[0063] In one example, it is assumed that there are 2 SIPs and 2 DIPs in the packet, 3 SMACs and 3 DMACs, and 3 VLANs. Then the two SIPs can be distinguished by index values 0 and 1; the two DIPs can also be distinguished by index values 0 and 1; the three SMACs can be distinguished by index values 00, 01, and 10; the three DMACs can be distinguished by index values 00, 01, and 10; the three VLANs can be distinguished by 00, 01, and 10. Among them, if the index value of the SIP in a certain packet after looking up the table is 0; the index value of the DIP after looking up the table is 1; the index value of the SMAC after looking up the table is 00; the index value of the DMAC after looking up the table is 01; and the VLAN is 00. Then the index value set output by the first conversion unit 610 is {0, 1, 00, 01, 00}. If the look-up operation of the input port (FIB_ic) in the FIB table is performed at this time, the fourth look-up key constructed by the fourth processing circuit according to the index value is {00, 00}. If the look-up operation of the ACL table is performed at this time, the first look-up key constructed by the first processing circuit according to the index value is {0, 1, 00, 01, 00}.

[0064] In the above manner, the original 32 - bit or 128 - bit SIP can be replaced with a 2 - bit or 1 - bit index value. At the same time, 2 - bit index values can also be used to replace SMAC and DMAC, greatly reducing the occupancy of tuple bit - width resources. Of course, the above implementation is only an example provided by the embodiments of the present application. The number of index values in the above index value set can be adaptively adjusted according to the look - up table types that the processing unit 620 needs to execute, which is not elaborated in the embodiments of the present application.

[0065] In addition, in the above implementation process, each processing circuit can obtain the required service entries from the same or different memories, or from different storage areas of the same memory, so as to make full use of the storage space of the memory.

[0066] It should be understood that the processing circuits included in the above processing unit 620 are only an example provided by the embodiments of the present application. The operator can expand or delete the processing circuits in the processing unit 620 according to the look - up table services that the network device 600 needs to execute. For example, the above at least one processing circuit may also only include the first processing circuit and the second processing circuit. Among them, the first processing circuit obtains the first service entry from the corresponding look - up table in the memory 650 according to the first look - up key determined by the index value set. The second processing circuit obtains the second service entry from the corresponding look - up table in the memory 650 according to the second look - up key determined by the index value set.

[0067] S703. The switching unit forwards the second index value set to the second conversion unit.

[0068] Among them, the switching unit 630 can forward the second index value set to the second conversion unit 640 according to the forwarding path determined by the index values of the source port and the destination port.

[0069] S704. The second conversion unit receives the second index value set and outputs a second message to the second interface.

[0070] In one implementation, the second conversion unit 640 can perform a look-up table based on each index value in the second index value set to output a second message. Among them, the second conversion unit 640 can share a look-up table with the first conversion unit 610 to reduce the occupation of storage space.

[0071] Through the above implementation, the embodiments of the present application can perform look-up tables on each tuple in the message header of the message in the first conversion unit 610 and the second conversion unit 640, and converge the tuples into index values according to service specifications (for example, for 2 DMAC addresses, the 48-bit DMAC tuple is converged into an index value of 01 or 10, and the bit width of the index value is 2 bits). What is transmitted on the data bus is the index value set, and there is no need to transmit the tuple information set on the path, and the processing circuits corresponding to different look-up table services use index value look-up tables, reducing the bit width resources for look-up tables.

[0072] In one implementation, as Figure 8 shown, the embodiments of the present application also provide a network device 800. The network device 800 includes a first interface P1, a first conversion unit 810, a processing unit 820, a second conversion unit 830, a switching unit 840, and a second interface P2. Among them, the first conversion unit 810 is coupled to the first interface P1. The processing unit 820 is coupled to the first conversion unit 810. The second conversion unit 830 is coupled to the processing unit 820. The second interface P2 is coupled to the second conversion unit 830 through the switching unit 840. Among them, the first conversion unit 810 can receive a first message input by the first interface P1 and output a first index value set. Among them, the above first index value set includes the index values of multiple tuples in the message header of the first message. Each tuple represents a field segment information in the message header. The processing unit 820 can perform a look-up table based on the multiple index values in the first index value set and output a second index value set. The second conversion unit 830 can receive the second index value set and output a second message. Among them, the second message and the first message are the same or different messages. The switching unit 840 can forward the second message to the second interface P2.

[0073] In one implementation, still as Figure 8 shown, the above processing unit 820 may include a plurality of processing circuits (for example Figure 8The first processing circuit to the nth processing circuit). The above-mentioned multiple processing circuits can form a pipelined structure through the data bus 821, and the above-mentioned multiple processing circuits can run in parallel. Among them, the above-mentioned multiple processing circuits can perform a look-up table through the search keywords composed of multiple index values in the first index value set to obtain the second index value set. Among them, each processing circuit can use different search keywords (such as Figure 8 K1 to Kn in

[0074] In one embodiment, as Figure 9 shown, the embodiment of the present application also provides a message transmission method applied to the network device 800. The specific process of this message transmission method is described as follows.

[0075] S901. The first conversion unit receives the first message input by the first interface and outputs the first index value set.

[0076] Among them, when the first conversion unit 810 receives the first message input by the first interface P1 and outputs the first index value set, it can refer to the description of the corresponding part of the above S701, and the embodiment of the present application will not repeat it here.

[0077] S902. The processing unit performs a look-up table according to the multiple index values in the first index value set and outputs the second index value set.

[0078] Among them, when the processing unit performs a look-up table according to the multiple index values in the first index value set and outputs the second index value set, it can refer to the description of the corresponding part of the above S702, and the embodiment of the present application will not repeat it here.

[0079] S903. The second conversion unit receives the second index value set and outputs the second message.

[0080] Among them, in one embodiment, the second conversion unit can perform a look-up table according to each index value in the second index value set to output the second message. Among them, the second conversion unit can share a look-up table with the first conversion unit 810 to reduce the occupation of storage space.

[0081] S904. The switching unit forwards the second message to the second interface.

[0082] Among them, the switching unit can forward the second message to the second conversion unit according to the forwarding path determined by the index values of the source port and the destination port.

[0083] In one embodiment, as Figure 10 shown, take Figure 6Based on the network device 600, the above-mentioned first conversion unit 610 may include a processor 611. The processor 611 may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processing circuit (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips. The computer program instructions run by the above controller may convert each tuple in the packet header of the received packet into a corresponding index value to form an index value set. Among them, the computer program instructions of the above controller may also be stored in the memory 650.

[0084] In one implementation, still as Figure 10 shown, the first conversion unit 610 may further include a plurality of buffers 612. The lookup table required by the first conversion unit 610 may be stored in the memory 650. The lookup table contains the corresponding relationship between each tuple and the corresponding index value. In one example, assume that both the SIP and DIP included in the packet are 2, both the SMAC and DMAC are 3, and the VLAN is three. Then, the two SIPs can be distinguished by the index values 0 and 1. Among them, one SIP corresponds to the index value 0, and the other SIP corresponds to the index value 1. The two DIPs can also be distinguished by the index values 0 and 1. Among them, one DIP corresponds to the index value 0, and the other DIP corresponds to the index value 1. The three SMACs can be distinguished by the index values 00, 01, and 10. Among them, the first SMAC corresponds to the index value 00; the second SMAC corresponds to the index value 01; the first SMAC corresponds to the index value 10. The three DMACs can be distinguished by the index values 00, 01, and 10. Among them, the first DMAC corresponds to the index value 00; the second DMAC corresponds to the index value 01; the first DMAC corresponds to the index value 10. The three VLANs can be distinguished by 00, 01, and 10. Among them, the first VLAN corresponds to the index value 00; the second VLAN corresponds to the index value 01; the first VLAN corresponds to the index value 10.

[0085] Of course, the correspondence between the tuples and the index values in the above lookup table is only an example given in the embodiments of the present application. The correspondence between each tuple in the lookup table and the corresponding index value can also be adjusted according to actual needs, and the embodiments of the present application do not make specific limitations thereon.

[0086] In some embodiments, still as Figure 10 shown, the network device 600 provided by the embodiments of the present application further includes an off-chip memory 660. The off-chip memory 660 can be used to store lookup tables such as an ACL table, a NAT table, a NAPT table, and a FIB table. Store the program instructions of the first conversion unit 610 and the program instructions of each processing circuit in the processing unit 630 to support each processing circuit in the first conversion unit 610 and the processing unit 630 to perform corresponding operations. Since the off-chip memory 660 has a larger storage space, it can replace the memory 650 to store larger units of lookup tables or program instructions.

[0087] In one embodiment, still as Figure 10 shown, the network device 600 provided by the embodiments of the present application may further include a controller 670. The controller 670 may also be located in the same system-on-chip in the network device 600 together with the above-mentioned multiple processors, that is, the controller 670 is integrated in the network device 600 as shown above Figure 6 shown. Necessary software programs or software plugins can be run through the controller 670 to drive the first conversion unit 610, the processing unit 620, the switching unit 630, and the second conversion unit 640 to perform corresponding operations. Among them, the controller 670 may be a central processing unit (CPU).

[0088] In the above implementation process, Figure 8 the network device 800 in Figure 10 may also include the off-chip memory, the controller, and the processor in

[0089] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0090] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices and modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0091] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or modules can be in electrical, mechanical, or other forms.

[0092] The modules described above as separate components may or may not be physically separated. The components displayed as modules may or may not be physical modules, that is, they can be located in one device or distributed to multiple devices. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0093] In addition, in each embodiment of this application, the functional modules can be integrated in one device, or each module can exist physically alone, or two or more modules can be integrated in one device.

[0094] The method steps in this embodiment can be implemented in the form of hardware modules or by the processor executing software instructions. The software instructions can be composed of corresponding software modules. The software modules can be stored in a random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), register, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in the terminal device. Of course, the processor and the storage medium can also exist as discrete components in a network device or a terminal device.

[0095] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions of the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).

[0096] The above are only the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for transmitting packets of a network device, characterized in that, The network device includes: a first interface, a first conversion unit coupled to the first interface, and a processing unit coupled to the first conversion unit. The method includes: The first conversion unit receives a first packet input by the first interface and outputs a first set of index values; the first set of index values includes index values of multiple tuples in the packet header of the first packet; each of the tuples represents a field segment information in the packet header. The processing unit performs a table lookup based on the multiple index values in the first set of index values and outputs a second set of index values.

2. The method according to claim 1, wherein The first conversion unit receives a first packet input by the first interface and outputs a first set of index values, including: The first conversion unit performs a table lookup according to each of the tuples in the first packet to output the first set of index values.

3. The method according to claim 1 or 2, characterized in that, The processing unit includes multiple processing circuits coupled by a data bus. The processing unit performs a table lookup based on the multiple index values in the first set of index values and outputs a second set of index values, including: The multiple processing circuits perform a table lookup using a search keyword composed of the multiple index values in the first set of index values to obtain the second set of index values; wherein, each of the processing circuits performs a table lookup using a different search keyword.

4. The method according to claim 3, characterized in that, Each of the processing circuits performs a table lookup from the same or different memories in the network device.

5. The method according to any one of claims 1-4, characterized in that, The network device further includes a switching unit, a second conversion unit, and a second interface; the switching unit is coupled to the processing unit; the second interface is coupled to the switching unit through the second conversion unit; the method further includes: The switching unit forwards the second set of index values to the second conversion unit. The second conversion unit receives the second set of index values and outputs a second packet to the second interface; the second packet and the first packet are the same or different packets.

6. The method according to any one of claims 1 to 4, characterized in that The network device further includes a switching unit, a second conversion unit, and a second interface; the second conversion unit is coupled to the processing unit; the second interface is coupled to the second conversion unit through the switching unit; the method further includes: The second conversion unit receives the second set of index values and outputs a second packet; the second packet and the first packet are the same or different packets. The switching unit forwards the second packet to the second interface.

7. The method according to claim 5 or 6, characterized in that, The second conversion unit receives the second set of index values and outputs a second packet, including: The second conversion unit performs a table lookup according to each of the index values in the second set of index values to output the second packet.

8. A network device, characterized in that, including a first interface, a first conversion unit coupled to the first interface, and a processing unit coupled to the first conversion unit; The first conversion unit is configured to receive a first packet input by the first interface and output a first set of index values; the first set of index values includes index values of multiple tuples in the packet header of the first packet; each of the tuples represents a field segment information in the packet header. The processing unit is configured to perform a table lookup based on the multiple index values in the first set of index values and output a second set of index values.

9. The network device according to claim 8, wherein The first conversion unit is specifically configured to: Look up a table according to each of the tuples in the first message to output the first index value set.

10. The network device according to claim 8 or 9, characterized in that, The processing unit includes a plurality of processing circuits coupled through a data bus; The plurality of processing circuits are configured to look up a table with a search keyword composed of a plurality of index values in the first index value set to obtain the second index value set; wherein, each of the processing circuits uses a different search keyword to look up the table.

11. The network device according to claim 10, characterized in that, Each of the processing circuits looks up a table from the same or different memories in the network device.

12. The network device according to any one of claims 8-11, characterized in that, The network device further includes a switching unit, a second conversion unit, and a second interface; the switching unit is coupled to the processing unit; the second interface is coupled to the switching unit through the second conversion unit; The switching unit is configured to forward the second index value set to the second conversion unit; The second conversion unit is configured to receive the second index value set and output a second message to the second interface; the second message and the first message are the same or different messages.

13. The network device according to any one of claims 8-11, characterized in that, The network device further includes a switching unit, a second conversion unit, and a second interface; the second conversion unit is coupled to the processing unit; the second interface is coupled to the second conversion unit through the switching unit; The second conversion unit is configured to receive the second index value set and output a second message; The second message and the first message are the same or different messages; The switching unit is configured to forward the second message to the second interface.

14. The network device according to claim 12 or 13, characterized in that, The second conversion unit is specifically configured to: Look up a table according to each of the index values in the second index value set to output the second message.

15. A network system, characterized in that, Including a plurality of terminal devices and a plurality of network devices according to any one of claims 8-14; the plurality of terminal devices are communicatively connected through the plurality of network devices.