Time-sensitive network flow control method and control system
Through the combination of the two-speed dual-bucket token bucket algorithm and CAM table, the precise control of traffic in a time-sensitive network and the optimized configuration of resources are achieved, solving the problem of the inability to effectively control real-time data traffic in the existing technology, and improving the efficiency and reliability of the network.
Patent Information
- Application Number
- CN202510580038.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art is difficult to effectively control real-time data traffic, and cannot stably transmit traffic without exceeding the bandwidth limit, while allowing non-critical traffic to use additional bandwidth when the network is idle.
The dual-speed dual-bucket token bucket algorithm is adopted, and the token generation rate and capacity are dynamically adjusted through the collaborative overflow mechanism of C bucket and E bucket, and combined with the CAM table and token statistics table, precise traffic control and optimized resource configuration are achieved.
It realizes efficient and accurate traffic control, improves the tolerance of burst traffic, reduces packet loss rate, improves transmission efficiency and resource utilization, and adapts to different network needs and traffic modes.
Smart Images

Figure CN120200979A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer networks, and particularly relates to a method and a control system for time-sensitive network traffic control. Background Art
[0002] Time-Sensitive Network (TSN) is a network technology that supports real-time communication and time-sensitive applications, aiming to meet the requirements of precise synchronization and low latency. As a representative of the next-generation real-time communication technology, TSN provides strong support for technological innovation in the aviation field. Through precise time synchronization and traffic scheduling mechanisms, TSN technology can ensure low-latency and jitter-free transmission of key data packets such as flight control, navigation, and communication in avionics equipment and mission systems, support multi-tasking and multi-system integration, and improve the response speed and accuracy of the system. Based on Ethernet technology, TSN has good standardization and compatibility, can be seamlessly integrated with existing network devices, and reduces the development and maintenance costs of avionics systems.
[0003] Traffic control in a network is a function in network devices (such as switches, routers, etc.) used to manage and limit the traffic passing through the network. Its main purpose is to prevent network congestion, ensure the normal transmission of critical service traffic, while optimizing the utilization of network resources and improving performance. Traffic control avoids network congestion caused by a large number of frame transmissions by adjusting the rate of the device's transmission end system frames, ensuring the efficiency and stability of network traffic. In the aviation field, the traffic control requirements of TSN mainly focus on aspects such as real-time performance, determinism, priority management, and bandwidth management. Through reasonable traffic control strategies, the performance and reliability of avionics systems can be effectively improved to meet the strict requirements for data transmission.
[0004] Adopting traffic control technology ensures that data in the TSN network can be transmitted efficiently and reliably according to the predetermined time requirements, ensuring the effective operation of the entire network. By setting the control rates for different service types, restricting the network sending bandwidth and the determined time characteristics, controlling the sending frequency of frames, and realizing the dynamic management and optimal configuration of network resources in the case of imbalance between service demand and resource supply.
[0005] The leaky bucket algorithm adopted by traditional traffic control regards network traffic as water flow, uses a bucket with a fixed capacity to cache data, and the data leaks out of the bucket at a constant rate, that is, the data is sent to the network at a fixed rate. When the bucket is full, new data packets will be discarded or delayed. This method forcibly restricts the data transmission rate to ensure smooth traffic and is relatively simple to implement. However, it may lead to idle resources due to the fixed rate limit and may cause significant delays in the case of burst traffic.
[0006] The traditional token bucket algorithm controls the data transmission rate through a "bucket". Tokens are generated in the bucket at a fixed rate, and each token represents the sending permission for a data packet. Before transmission, a data packet needs to obtain a token. If there are not enough tokens in the bucket, the data packet will be delayed or discarded. This method allows a certain degree of bursty traffic compared to the leaky bucket algorithm, but the size of the burst is still limited by the bucket capacity. The dual-rate dual-bucket token bucket algorithm extends the basic token bucket concept and uses two different rates and two independent token buckets to control the average rate and bursty traffic respectively.
[0007] In a TSN network, the main purpose of switch traffic control is to discard frames with excessive traffic to avoid network congestion and latency, rather than strictly shaping the input frames. How to achieve stable data transmission rate without exceeding the bandwidth limit while allowing non-critical traffic to use additional bandwidth when the network is idle is a difficult problem to be solved urgently in the TSN network. Summary of the Invention
[0008] The purpose of the present invention is to provide a time-sensitive network traffic control method and control system to solve the deficiency in the prior art that the real-time data traffic cannot be effectively controlled. Through the administrator can reasonably set the configuration according to the real-time requirements and resource conditions of the network throughout the process, which can not only ensure the priority transmission of actual sensitive traffic, but also avoid the excessive occupation and waste of network resources, and can adapt to different network requirements and traffic patterns.
[0009] To achieve the above purpose, the present invention provides the following technical solutions: A time-sensitive network traffic control method includes the following steps: S1. Establish a configuration table and an index table: Construct a C bucket configuration table, define the maximum capacity (CBS) of the C bucket, the token generation rate (CIR), the token calculation mode (by the number of data packets or bytes), and the adaptive rate enable flag (adaptive_rate); Construct an E bucket configuration table, define the maximum capacity (EBS) of the E bucket, the token recovery rate (EIR), the yellow traffic discard flag (drop_yellow), and the global red mark flag (mark_all_red); Establish a CAM table, generate a unique flow index based on the source MAC address, destination MAC address, VLAN ID, and priority of the data frame for matching authorized traffic; Establish a time and red data statistical table, record the last processing time (last_time_cycle) and the red traffic count (red_cnt); Establish a token statistical table to store the current token numbers (c_last_token, e_last_token) of the C bucket and the E bucket; S2. Flow Identification and Authorization Verification: When data enters, match the flow index according to the CAM table. If the match fails, the data is regarded as malicious traffic and discarded; if the match is successful, read the configurations and statistical information of Bucket C and Bucket E. S3. Global Red Marking Check: If mark_all_red = 1 in the E - bucket configuration table, directly mark the data as red and discard it; otherwise, perform token calculation. S4. Token Calculation and Color Marking: Calculate the token recovery amounts of Bucket C and Bucket E according to the time interval, and judge in combination with the current token quantity: Green: The tokens in Bucket C meet the data requirements (by quantity or byte count), mark it as green and forward it. Yellow: The tokens in Bucket C are insufficient but those in Bucket E are sufficient. Mark it as yellow and decide whether to discard it according to the drop_yellow flag. Red: The tokens in Bucket E are insufficient, mark it as red and discard it. Set mark_all_red = 1 when triggered for the first time. S5. Update the token quantity, timestamp, and red - traffic count in the token statistics table.
[0010] Preferably, when the token quantity in Bucket C exceeds CBS, the overflow tokens are automatically transferred to Bucket E; when the token quantity in Bucket E reaches EBS, the subsequent overflow tokens are directly discarded; the token generation rate of Bucket E is the sum of CIR and EIR until Bucket E is full.
[0011] Preferably, when the adaptive - rate enable flag (adaptive_rate) is 1 and the network bandwidth occupancy rate ≥ 80%, the token generation rates of Bucket C and Bucket E synchronously drop to 80% of the original rate.
[0012] Preferably, in the token - calculation mode, critical traffic calculates token consumption by byte count, ordinary traffic calculates by packet quantity, and the mode is switched through the number_or_byte flag set in the Bucket C configuration table.
[0013] Preferably, the flow index of the CAM table consists of the source MAC address (64 bits), destination MAC address (64 bits), VLAN ID (12 bits), and priority (4 bits), a total of 144 bits. Packets that fail to match trigger the recording of security - alert logs.
[0014] Preferably, integrate the IEEE 802.1Qci flow - filtering strategy to perform frame - length priority filtering, internal - priority correction, and burst - traffic speed limiting on abnormal traffic, and link with the global red - marking mechanism to intercept malicious data.
[0015] Also involved is a control system for a time-sensitive network traffic control method, characterized in that it includes a traffic police control module: verifying traffic authorization based on the CAM table, and directly discarding unauthorized traffic; a reading module: loading the C bucket, E bucket configurations and statistical information; a calculation module: calculating the number of tokens and making decisions on color markings, supporting adaptive rate adjustment; a data marking module: performing green forwarding, yellow selective discarding or red forced discarding; a dynamic configuration interface: adjusting the CIR, EIR, CBS, EBS and security policy parameters in real time.
[0016] Preferably, the dynamic configuration interface is coordinated with and supported by an SDN controller to map time-sensitive flows to the 5G URLLC network slice, realizing end-to-end deterministic transmission.
[0017] Compared with the prior art, the beneficial effects of the present invention are: 1. High efficiency and precise control. The dual-speed dual-bucket cooperative overflow mechanism (transferring C bucket token overflow to the E bucket) improves the tolerance of burst traffic and effectively reduces the packet loss rate; critical traffic calculates token consumption by byte count, and ordinary traffic is processed by the number of data packets, improving the transmission efficiency; 2. Dynamic adaptability and flexibility. The adaptive token generation rate reduces congestion, optimizes resource utilization, the dynamic configuration interface supports real-time parameter adjustment, and is linked with the 5G network slice (such as URLLC), reducing the end-to-end delay fluctuation; 3. Security and reliability. The CAM table quadruple verification and the IEEE 802.1Qci flow filtering strategy (frame length filtering, priority correction) intercept malicious traffic; the global red marking linkage mechanism (the first red marking triggers subsequent interception) combined with dynamic key rotation reduces the risk of key leakage; 4. Hardware resource optimization: The FPGA multi-port sharing design reduces the occupation of logic resources and supports the parallel management of 1024 flows; the pipeline processing and time slice rotation technology improve the throughput and meet the requirements of high-real-time scenarios such as aviation and vehicle-mounted. Description of the Drawings
[0018] Figure 1 It is a flowchart of the processing of data by the traffic police control module in the present invention; Figure 2 It is a model diagram of the dual-speed dual-bucket token bucket algorithm in the present invention; Figure 3 It is a structural diagram of the traffic control of the application example of the present invention in the overall switch. Detailed Embodiments
[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] Referring to Figure 1 As shown, the present invention provides a time-sensitive network traffic control system, including a traffic policing module, a reading module, a calculation module, and a data marking module.
[0021] When data information enters the traffic policing module and it is determined whether it is authorized traffic, the reading module reads the parameter configuration, and then the calculation module calculates the current number of tokens and determines whether the tokens meet the conditions. If so, it is marked as passed through the data marking module; if not, it is marked as not passed through the data marking module and discarded.
[0022] Specifically, through the time-sensitive network traffic control system, the control is more efficient and accurate, and the sending permission of tokens can be controlled as the number of data packets or the number of data bytes. The former is executed for ordinary traffic, with higher processing efficiency; the latter is executed for critical traffic, and more refined control can be achieved through accurate calculation.
[0023] Referring to Figures 2 - 3 As shown, the present invention also provides a time-sensitive network traffic control method, including the following steps: S1. Establish the required ram tables, including a C bucket configuration table, an E bucket configuration table, a time and red-marked data statistical table, and a token statistical table. The content in the tables includes the parameter names and the bit positions they use; It is also necessary to establish a cam table for finding the address of the ram table index. The index cam table of the stream is as shown in Table 1 below: Table 1 ; Specifically, in S11, in the C bucket configuration table, CBS and CIR are the maximum capacity and token generation rate of the C bucket in the two buckets; number_or_byte is to calculate by the number of data packets or the number of bytes when configuring the token to pass. By default, 0 is used to calculate by the number, and 1 is used to calculate by the byte; adaptive_rate is the enable of the adaptive token generation speed; In S12, in the E bucket configuration table, EBS and EIR are the maximum capacity and token recovery rate of the E bucket in the two buckets; drop_yellow indicates whether the data sequence marked as yellow is to be discarded; mark_all_red indicates whether all subsequent data is to be marked as red; In S13, in the time and red - marked data statistical table, last_time_cycle is the time record when processing this flow last time; red_cnt is the number of data sequences of the traffic marked as red, and the initial values of the parameters are both 0. In S14, in the token statistical table, store the token capacities c_last_token and e_last_token of bucket C and bucket E when processing this flow last time, and the initial values are the configured CBS and EBS. In the flow index cam table, daddr is the destination MAC address, saddr is the source MAC address, priority is the priority, and these, together with the Vlan id (Virtual Local Area Network identifier), are the information carried in the data sequence. In S2, when data enters, by identifying the content of the frame, use its source MAC, destination MAC, Vlan id, and priority to search the flow index cam table. A match indicates that the flow is authorized and further operations can be performed; otherwise, it is regarded as malicious traffic and discarded. Then, read the bucket C configuration table, bucket E configuration table, time and red - marked data statistical table, and token statistical table through the indexed address. Among them, the bucket C configuration table is as follows in Table 2: Table 2 ; The bucket E configuration table is as follows in Table 3: Table 3 ; The time and red - marked data statistical table is as follows in Table 4: Table 4 ; The token statistical table is as follows in Table 5: Table 5 ; In S3, check whether mark_all_red read in step S2 is 1. If so, the data is directly marked as red and jump to S5. The meaning of red is that the traffic is seriously over - speed. Mark the packet as red and discard the packet. If mark_all_red is 0, then calculate the token quantities in the two buckets at this time. Specifically, in S31, the data passing through will consume the tokens in the bucket. During the idle period, the tokens will be continuously restored. Green tokens are filled into bucket C at the rate of CIR, and yellow tokens are filled into bucket E at the rate of EIR. When adaptive_rate is 1, this rate will be reduced to 80% of the original when the bandwidth occupancy reaches 80%, and when the tokens collected in the bucket reach the maximum capacity of the bucket, it will overflow. S32. When the tokens collected in bucket C reach CBS, the overflow tokens from bucket C will be loaded into bucket E. That is, when bucket E does not overflow, the rate of adding tokens to bucket E is CIR plus EIR. When the tokens collected in bucket E reach EBS, the subsequent tokens will also overflow and be directly discarded. S33. Calculate the number of tokens recovered by bucket C and bucket E respectively during the interval between two processes of this flow based on the parameters last_time_cycle, CIR, and EIR obtained in step S32. Combining c_last_token and e_last_token can calculate the number of tokens in the current two buckets. S4. Color-mark the data sequence according to the number of tokens in the current bucket C and bucket E, the number of data, or the frame length. The data traffic is divided into three levels: red, yellow, and green. The marking judgment method is as follows Figure 2 shown. It can control the number of data sent to the network and allow the sending of burst data. Specifically, S41. When there are still tokens in bucket C, or when number_or_byte is 1 and the length of the data sequence is less than the current number of tokens in bucket C, enter S41, and the data is marked as green. Green: It means the traffic is not speeding. Mark the packet as green and forward it directly. Then jump to S5. S42. When there are no tokens in bucket C but there are tokens in bucket E, or when number_or_byte is 1 and the length of the data sequence is greater than the current number of tokens in bucket C and less than the current number of tokens in bucket E, enter S42, and the data is marked as yellow. Yellow: It means the traffic is slightly speeding. Mark the packet as yellow, and it can be set whether to forward it. S43. If the data is marked as yellow traffic and drop_yellow = 1, then discard the data. If drop_yellow = 0, the data can continue to be transmitted. Then jump to S5. S44. When there are no tokens in bucket E, or when number_or_byte is 1 and the length of the data sequence is greater than the current number of tokens in bucket E, enter S44, and the data is marked as red and discarded. When the data of a certain flow is first marked as red, mark_all_red in S12 can be set to 1. S5. Update the number of tokens in the newly calculated two buckets and the time of calculation to the token statistics table and the time and data red marking statistics table. If the data is marked as red and discarded, red_cnt will also be updated.
[0024] There is also a token overflow mechanism. When the tokens in bucket C exceed CBS, the overflow tokens are transferred to bucket E at a rate of CIR + EIR; if bucket E reaches its EBS capacity, the overflow tokens are directly discarded. For example, the peak burst traffic is 12 Gbps, bucket C is configured with CIR = 5 Gbps (CBS = 1000 tokens), and bucket E has EIR = 3 Gbps (EBS = 500 tokens).
[0025] Result: Without cooperative overflow: The overflow tokens in bucket C are discarded, and the packet loss rate is 28%; With cooperative overflow enabled: Bucket E receives the overflow tokens, and the packet loss rate is reduced to 6%.
[0026] In a specific embodiment, in practical applications, the design in the present invention is applied after the ingress module and before the crossbar module in a time-sensitive network switch, and interacts with the ingress module. The specific location is as Figure 3 shown. The switch uses 44 2.5G ports and 4 10G ports. The interval for the traffic shaping module to continuously process a data sequence requires two cycles. In the case of 2.5G, processing a shortest frame of 84 bytes requires 33.6 cycles at a 312.5M clock. One traffic shaping instance supports 16 2.5G ports to enter data processing simultaneously, and 3 instances are used for 44 ports. In the case of 10G, the shortest frame plus the frame interval is 10 cycles, and 4 10G ports can share one traffic shaping instance, with a total of four used.
[0027] It can support the configuration of 1024 flows, allocate different bandwidths to the authorized traffic according to business requirements, set different token recovery rates and capacities, and other configuration parameters such as the token being the number of data or bytes, discarding yellow traffic, adaptively generating tokens, and directly marking and discarding in red. For critical traffic, the token configuration can be calculated by the number of bytes to achieve more precise control. When data enters multiple ports sharing a traffic control instance simultaneously, it will be processed in the order of the port numbers. When processing, it will first check the cam table to see if there is a corresponding index. If the index is found, it indicates authorized traffic and further queries the ram table configuration. After finding the configuration, it starts to calculate the number of tokens. The initial number of tokens is the capacity of the bucket. According to the comparison between the number of tokens in the two token buckets and the number or bytes of the data, if the number or frame length is less than the tokens in bucket C, the data packet is marked green; if it is greater than the tokens in bucket C and less than the tokens in bucket E, the data packet is marked yellow; if it is greater than the tokens in bucket E, the data packet is marked red. The color is used to distinguish whether it is regular traffic, burst traffic, and traffic that exceeds the standard and needs to be discarded. After marking, the number of tokens after this calculation and the local time during the calculation also need to be updated and stored in the statistical ram table used for calculation. When the data of this flow comes again next time, the number of tokens is calculated by reading the updated statistical ram and the configured token rate of the previous packet. When token adaptive generation is set, it is also necessary to consider whether the bandwidth occupancy reaches the condition.
[0028] During the use process, the parameter configuration of the existing traffic can be modified at any time, and when the business requirements change, the authorized traffic can be modified, added, or deleted at any time. In this way, flexible dynamic configuration can be achieved. When burst data comes in, the data flow with a small token recovery rate and capacity will be marked in red and discarded, while the data with a large token recovery rate and capacity will be temporarily marked in yellow, but it does not affect its normal forwarding. In this way, the total traffic in the network will neither exceed the maximum bandwidth and cause congestion, nor ensure the priority transmission of critical traffic, precisely control the real-time data traffic in the time-sensitive network, reduce latency, and improve bandwidth utilization.
[0029] Synchronously set with anomaly detection and red marking trigger: Trigger condition: When the data frame simultaneously meets any of the following conditions, the global red marking flag (mark_all_red = 1) is triggered: The frame length exceeds the limit and the priority is illegal (such as an ordinary flow carrying a priority 7 label); The burst traffic exceeds EBS and token borrowing is not passed; The cumulative number of flow filtering alarms exceeds the threshold (such as 10 times / second).
[0030] Linkage process: When triggered for the first time, mark the current data packet in red, discard it, and update red_cnt; At the same time, set mark_all_red = 1 for this flow, and directly discard all subsequent data packets matching the flow index.
[0031] Dynamic Key Update and Interception Enhancement: Key Rotation: When a certain flow triggers global red highlighting, the dynamic session key immediately becomes invalid, and a new key is generated; the new key is distributed to authorized devices through a secure channel, and subsequent traffic with an unupdated key is regarded as abnormal.
[0032] Interception Effect: Malicious traffic cannot pass the key verification, fails the CAM table match, and is directly marked as red and discarded.
[0033] Specifically, the following is the frame length filtering test: Scenario: Inject forged aviation control instructions (priority 7) with a length of 1600 bytes.
[0034] Result: The frame length exceeding the limit triggers an alarm, the priority label is corrected to 4, and the traffic enters the token calculation process; if the token is insufficient, it is marked as yellow and processed according to the drop_yellow flag.
[0035] Burst Traffic Rate Limiting Test: Scenario: Simulate the burst transmission of sensor logs (ordinary flow, CBS = 500 bytes).
[0036] Result: Transmitting 600 bytes within 1 ms (exceeding CBS + EBS = 700 bytes) triggers a rate limiting alarm; The traffic is marked as red, mark_all_red = 1 takes effect, and subsequent traffic is directly discarded.
[0037] Global Red Highlighting Linkage Test: Scenario: Continuously inject malicious traffic (abnormal frame length + priority tampering).
[0038] Result: After the first trigger, mark_all_red = 1 takes effect, and the interception rate of subsequent similar traffic is 100%; after the key is updated, the traffic of unauthorized devices cannot pass the verification, and the system security is improved.
[0039] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for controlling time-sensitive network traffic, characterized in that: The steps include: S1. Create configuration table and index table: Build the C bucket configuration table to define the maximum capacity CBS of the C bucket, the token generation rate CIR, the token calculation mode, and the adaptive rate enable flag adaptive_rate; Construct the E bucket configuration table to define the maximum capacity of the E bucket EBS, the token recovery rate EIR, the yellow traffic drop flag drop_yellow, and the global red flag mark_all_red; Establish a CAM table to generate a unique flow index based on the source MAC address, destination MAC address, VLAN ID and priority of the data frame for matching authorized traffic; Establish a time and red data statistics table to record the last processing time last_time_cycle and the red traffic count red_cnt; Create a token statistics table to store the current token counts c_last_token and e_last_token in buckets C and E. S2. Traffic identification and authorization verification: When data enters, the flow index is matched according to the CAM table. If the match fails, it is regarded as malicious traffic and discarded. If the match succeeds, the configuration and statistical information of bucket C and bucket E are read; S3, global red check: If mark_all_red=1 in the E bucket configuration table, directly mark the data as red and discard it; otherwise, perform token calculation; S4. Token calculation and color marking: Calculate the token recovery quantity of buckets C and E based on the time interval and combine it with the current number of tokens to determine: Green: Bucket C token meets the data requirement, is marked green and forwarded; Yellow: Bucket C has insufficient tokens but bucket E has sufficient tokens. The tokens are marked yellow and the decision on whether to discard the tokens is based on the drop_yellow flag. Red: Bucket E is short of tokens, so it is marked red and discarded. When it is triggered for the first time, mark_all_red=1 is set; S5. Update the token quantity, timestamp, and red traffic count in the token statistics table.
2. A time-sensitive network traffic control method according to claim 1, characterized in that: The collaborative overflow mechanism of the C bucket and the E bucket includes: when the number of tokens in the C bucket exceeds the CBS, the overflowed tokens are automatically transferred to the E bucket; when the number of tokens in the E bucket reaches the EBS, the subsequent overflowed tokens are directly discarded; the token generation rate of the E bucket is the sum of the CIR and the EIR until the E bucket is full.
3. A time-sensitive network traffic control method according to claim 1 or 2, characterized in that: When the adaptive rate enabling flag adaptive_rate is 1, when the network bandwidth occupancy rate is ≥80%, the token generation rate of buckets C and E is synchronously reduced to 80% of the original rate.
4. A time-sensitive network traffic control method according to claim 3, characterized in that: In the token calculation mode, the token consumption is calculated based on the number of bytes for critical traffic, and the token consumption is calculated based on the number of data packets for common traffic, and the mode is switched by the number_or_byte flag provided in the C bucket configuration table.
5. A time-sensitive network traffic control method according to claim 1, characterized in that: The flow index of the CAM table is composed of the source MAC address, the destination MAC address, the VLAN ID and the priority, and the data packet that fails to match triggers the security alarm log record.
6. A time-sensitive network traffic control method according to claim 1, characterized in that: It also integrates IEEE802.1Qci flow filtering strategies to perform frame length priority filtering, internal priority correction, and burst traffic rate limit on abnormal traffic, and works with the global red marking mechanism to intercept malicious data.
7. A control system for a time-sensitive network traffic control method according to any one of claims 1 to 6, characterized in that: Includes traffic police management module: Verifies traffic authorization based on CAM table, and directly discards unauthorized traffic; Reading module: loads C bucket, E bucket configuration and statistical information; Calculation module: calculates the number of tokens and determines the color tags, supporting adaptive rate adjustment; Data marking module: performs green forwarding, yellow selective discarding or red forced discarding; Dynamic configuration interface: real-time adjustment of CIR, EIR, CBS, EBS and security policy parameters.
8. The control system for a time-sensitive network traffic control method according to claim 7, characterized in that: The dynamic configuration interface collaborates with the SDN controller to map time-sensitive flows to 5G URLLC network slices to achieve end-to-end deterministic transmission.