Flow controllable forwarding method and system

By building a traffic model and implementing a multi-level traffic management strategy, the problem of poor traffic control accuracy in the existing technology is solved, precise control and management of network traffic is achieved, security and stability are improved, and traffic forwarding efficiency is improved.

CN120223643APending Publication Date: 2025-06-27BEIJING ZHIYE TECH IND CO LTD

Patent Information

Application Number
CN202510452571.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When processing important or priority traffic data, existing traffic forwarding technologies have poor control accuracy, affect management and security, and are prone to data loss or transmission errors, and have poor network stability.

Method used

By building a traffic model, including traffic scheduler, switch, bandwidth monitoring module, security module and cache management module, traffic monitoring and evaluation, classification and priority setting, bandwidth limit and rate control, load balancing, resource reservation, packet encryption and verification, traffic caching and data loss prevention, dynamic adjustment of forwarding strategies, and achieving accurate control and management of network traffic.

Benefits of technology

It realizes precise control and management of network traffic, improves the security and stability of data in the forwarding process, avoids data loss, and improves traffic forwarding efficiency.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to the technical field of flow forwarding, in particular to a controllable flow forwarding method. The method comprises the following steps: S1, demand analysis, S2, traffic model construction, S3, equipment initial configuration, S4, traffic monitoring and evaluation, S5, traffic classification and priority setting, S6, bandwidth limitation and rate control, S7, load balancing, S8, resource reservation, S9, security encryption and verification of a data packet, S10, traffic caching and data loss prevention, and S11, dynamic adjustment of a forwarding strategy. According to the method, accurate control and management of network traffic are realized through traffic model construction, traffic monitoring and evaluation, traffic classification and priority setting, bandwidth limitation and rate control, load balancing and resource reservation, the security of data in a forwarding process is improved through security encryption and verification of a data packet, log recording and performance monitoring, and the data forwarding efficiency is improved. And data loss is avoided through flow caching, data loss prevention and dynamic adjustment of a forwarding strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of traffic forwarding, and specifically, to a traffic controllable forwarding method and system. Background Art

[0002] Traffic forwarding refers to the process of forwarding network traffic from a source address to one or more destination addresses in a network. It usually plays a role of transit and forwarding in the network architecture, responsible for receiving requests from clients, forwarding them to the destination servers, and at the same time processing the returned data and sending it back to the clients. Traffic forwarding can achieve various functions, including load balancing, cache acceleration, and security protection, etc., so as to improve the performance and security of websites.

[0003] A traffic forwarding method and system are disclosed in a Chinese patent (authorization announcement number CN112383511B). This patented technology deploys a node drainage module on existing terminal devices, saving costs. At the same time, port binding is also performed for access to non-open ports, and false services are provided through the corresponding bound ports of the honeypot. However, in the above traffic forwarding method, the traffic forwarding operation is directly performed on the processed traffic, and the traffic data is sent randomly or sequentially. The accuracy of traffic control during the sending process is relatively poor, affecting the sending of important or priority traffic data, which is not conducive to the management of traffic forwarding. The control of traffic forwarding data is inaccurate, affecting the security during the traffic data forwarding process. During the traffic forwarding process, affected by the network, it is easy to cause problems such as traffic data loss or traffic data sending errors, and the stability of the network is relatively poor, which is not conducive to the traffic forwarding efficiency. Therefore, those skilled in the art have provided a traffic controllable forwarding method and system to solve the problems raised in the above background art. Summary of the Invention

[0004] The purpose of the present invention is to provide a traffic controllable forwarding method and system to solve the problems raised in the above background art.

[0005] To achieve the above purpose, the present invention provides the following technical solution: A traffic controllable forwarding method, the steps are as follows:

[0006] S1. Requirement analysis: Closely communicate with each business department to understand the types of services carried by the network, record the network performance indicators of bandwidth, latency, and jitter for each service, and analyze the recorded data through an analysis module;

[0007] S2. Traffic Model Construction: According to the results of requirements analysis, collect historical traffic data, use professional network traffic monitoring tools to collect data at key nodes of the network. The collected data covers traffic characteristics in different time periods. Conduct statistical analysis on the collected traffic data to determine the distribution law of traffic. Based on the above data, construct a traffic model, which includes a traffic scheduler, a switch, a bandwidth monitoring module, a security module, and a cache management module;

[0008] S3. Initial Device Configuration: Perform software configuration, including setting network parameters such as the IP address, subnet mask, and default gateway of the device to enable normal communication in the network. Configure the username and password of the device, adopt a high-strength password policy to prevent unauthorized access. Enable the logging function of the device to record the operating status and operation record information of the device for traceability during fault troubleshooting. According to the network environment, set traffic control policies to determine the upper and lower limits of the forwarding speed and adjustment policies under different network conditions;

[0009] S4. Traffic Monitoring and Evaluation: Deploy monitoring tools for data analysis and problem location. The monitoring tools include core routers, switches, and server clusters;

[0010] S5. Traffic Classification and Priority Setting: Classify traffic according to data types and application requirements, and set priorities according to the classification results;

[0011] S6. Bandwidth Limitation and Rate Control: Limit the bandwidth usage of traffic, perform traffic control through token bucket and leaky bucket algorithms to ensure that traffic does not exceed the predetermined bandwidth limit. Set the upper and lower limits of the data sending rate, send data according to the set rate, monitor the network condition, and dynamically adjust the sending rate;

[0012] S7. Load Balancing: Use load balancing algorithms to distribute traffic to multiple network nodes;

[0013] S8. Resource Reservation: Reserve network bandwidth, cache space, and processing capabilities. Transmit data according to the reserved resources, monitor the resource usage situation to ensure that the reserved resources are not occupied by other applications. When resources are insufficient, dynamically adjust the reservation strategy;

[0014] S9. Security Encryption and Verification of Data Packets: Ensure the confidentiality and integrity of data. The transmitted data packets are encrypted and verified. Use encryption protocols to encrypt the data during transmission, and at the same time use hash algorithms for data integrity verification to prevent data from being tampered with during transmission;

[0015] S10. Traffic Caching and Data Loss Prevention: When the network fails, becomes congested, or the bandwidth is unstable, adopt a traffic caching mechanism to cache data streams and continue to forward them after the network conditions recover;

[0016] S11, Dynamic adjustment of forwarding policy: Dynamically adjust the forwarding policy according to the requirements of traffic controllable forwarding and the real-time network status;

[0017] S12, Log recording and performance monitoring: Record the traffic forwarding process, monitor the forwarding performance, alarm in time when abnormalities are found, and solve potential problems;

[0018] S13, Testing and optimization: Conduct stress testing through the stress testing module, simulate the network performance under high traffic load conditions, optimize the system configuration according to the test results, and adjust the bandwidth, routing selection, and caching policy.

[0019] As a further solution of the present invention: In S2, the traffic scheduler: Responsible for global traffic management and scheduling, determining the forwarding path, rate, and priority of data packets;

[0020] Switch: Used for data packets to be forwarded according to the scheduling rules;

[0021] Bandwidth monitoring module: Used to monitor the usage of network bandwidth in real time, detect network congestion, and adjust the forwarding rate;

[0022] Security module: Used for data encryption, authentication, and verification;

[0023] Cache management module: Cache the traffic that cannot be forwarded temporarily.

[0024] As a further solution of the present invention: The traffic data in S2 includes the source address, destination address, port number, protocol type, traffic size, and the time when peaks and valleys occur.

[0025] As a further solution of the present invention: In S4, deploy monitoring tools: At key nodes of the network, collect traffic parameters in real time, including traffic size, flow rate, data packet type, source and destination addresses, and port numbers;

[0026] Data analysis: Regularly analyze the monitored traffic data, combine with the previously constructed traffic model, judge whether the traffic is abnormal, and find out the reasons for traffic changes by comparing historical data and current data;

[0027] Problem location: Use the data analysis results for problem location. When it is found that abnormal traffic leads to a decline in network performance, trace back to the source of the problem by viewing the source and destination addresses and port number information of the traffic.

[0028] A system for a traffic controllable forwarding method, including:

[0029] Analysis module: Used for recording data analysis;

[0030] Traffic model: used to predict network congestion in advance and provide a scientific basis for formulating traffic regulation strategies;

[0031] Monitoring tool: used for data analysis and problem location;

[0032] Stress test module: used to simulate network performance under high traffic load conditions and optimize system configuration according to test results.

[0033] Compared with the prior art, the beneficial effects of the present invention are:

[0034] 1. A traffic controllable forwarding method of the present invention realizes precise control and management of network traffic through traffic model construction, traffic monitoring and evaluation, traffic classification and priority setting, bandwidth limitation and rate control, load balancing, and resource reservation;

[0035] 2. By securely encrypting and verifying data packets, and logging and monitoring performance, the security of data during forwarding is improved;

[0036] 3. By traffic caching and data loss prevention, and dynamically adjusting forwarding strategies, data loss is avoided, the stability of forwarding is improved, and the traffic forwarding efficiency is increased. Detailed implementation manner

[0037] Embodiment

[0038] A traffic controllable forwarding method, the steps are as follows:

[0039] S1. Requirement analysis: Communicate closely with each business department to understand the types of services carried by the network, such as: real-time video conferencing, online transactions, file downloads, email, record the network performance indicators of bandwidth, latency, and jitter for each service, and analyze the recorded data through an analysis module;

[0040] S2. Traffic model construction: According to the results of requirement analysis, collect historical traffic data, use professional network traffic monitoring tools, such as: SolarWinds, Wireshark, to collect data at key nodes of the network. The collected data covers traffic characteristics in different time periods, such as: weekdays, weekends, peak hours, off-peak hours. Statistically analyze the collected traffic data. The traffic data includes the source address, destination address, port number, protocol type, traffic size, and the time of peak and off-peak of the traffic. Determine the distribution law of the traffic. Based on the above data, construct a traffic model. The traffic model includes a traffic scheduler, a switch, a bandwidth monitoring module, a security module, and a cache management module. Traffic scheduler: responsible for global traffic management and scheduling, and determining the forwarding path, rate, and priority of data packets;

[0041] Switch: used to forward data packets according to scheduling rules;

[0042] Bandwidth Monitoring Module: Used to monitor the usage of network bandwidth in real time, detect network congestion and adjust the forwarding rate;

[0043] Security Module: Used for data encryption, authentication and verification;

[0044] Cache Management Module: Caches traffic that cannot be forwarded temporarily;

[0045] S3. Initial Device Configuration: Perform software configuration, including setting network parameters such as the device's IP address, subnet mask, and default gateway to enable normal communication in the network. Configure the device's username and password, adopting a high-strength password policy, e.g., including uppercase and lowercase letters, numbers, special characters, and with a length of at least 8 digits to prevent unauthorized access. Enable the device's logging function to record the device's operating status and operation record information for traceability during fault troubleshooting. Set traffic control policies according to the network environment, determining the upper and lower limits of the forwarding speed and adjustment policies under different network conditions;

[0046] S4. Traffic Monitoring and Evaluation: Deploy monitoring tools for data analysis and problem localization. The monitoring tools include core routers, switches, and server clusters. Deploy monitoring tools: At key nodes of the network, collect traffic parameters in real time, including traffic volume, flow rate, packet type, source and destination addresses, and port numbers;

[0047] Data Analysis: Regularly analyze the monitored traffic data, and in combination with the previously constructed traffic model, determine whether the traffic is abnormal. By comparing historical data and current data, find the reasons for traffic changes, e.g., whether there is a new service launched, a network attack occurred, or a device failure;

[0048] Problem Localization: Use the data analysis results for problem localization. When it is found that abnormal traffic leads to a decline in network performance, trace back to the source of the problem by viewing the source and destination addresses and port number information of the traffic. For example, if it is found that the traffic of a certain network segment suddenly increases, causing congestion in the entire network, by analyzing the traffic monitoring data, it is found that a certain server in that network segment has been hacked and is sending a large number of malicious packets outward, and then take targeted measures, such as isolating the server and blocking the malicious traffic source;

[0049] S5. Traffic Classification and Priority Setting: Classify traffic according to data types and application requirements, and set priorities according to the classification results. For example, set video streams, voice calls, and real-time game traffic to low latency and higher priorities, while set file downloads and backup traffic to low priorities;

[0050] S6, Bandwidth Limitation and Rate Control: Limit the bandwidth usage of traffic, perform traffic control through token bucket and leaky bucket algorithms to ensure that the traffic does not exceed the predetermined bandwidth limit, set the upper and lower limits of the data sending rate, send data according to the set rate, monitor the network condition, and dynamically adjust the sending rate. For example, when the network condition is good, allow data to be sent at an over-speed; when the network is congested, reduce the sending rate;

[0051] S7, Load Balancing: Use load balancing algorithms to distribute traffic to multiple network nodes;

[0052] S8, Resource Reservation: Reserve network bandwidth, cache space, and processing capacity, perform data transmission according to the reserved resources, monitor the resource usage, ensure that the reserved resources are not occupied by other applications, and dynamically adjust the reservation strategy when resources are insufficient;

[0053] S9, Secure Encryption and Verification of Data Packets: Ensure the confidentiality and integrity of data. The transmitted data packets are encrypted and verified. Use encryption protocols to encrypt the data during transmission, and at the same time use hash algorithms for data integrity verification to prevent data from being tampered with during transmission;

[0054] S10, Traffic Caching and Data Loss Prevention: When the network fails, is congested, or the bandwidth is unstable, adopt a traffic caching mechanism to cache the data stream and continue to forward it after the network condition recovers;

[0055] S11, Dynamic Adjustment of Forwarding Strategy: Dynamically adjust the forwarding strategy according to the requirements of controllable traffic forwarding and the real-time network state. For example, when there is a bottleneck in the network bandwidth, automatically lower the priority, reduce the forwarding rate of traffic, and release the bandwidth for high-priority traffic;

[0056] S12, Log Recording and Performance Monitoring: Record the traffic forwarding process, monitor the forwarding performance, alarm in time when anomalies are found, and solve potential problems;

[0057] S13, Testing and Optimization: Perform stress testing through a stress testing module to simulate the network performance under high traffic loads, optimize the system configuration according to the test results, and adjust the bandwidth, routing selection, and caching strategy.

[0058] A system for a traffic controllable forwarding method, including:

[0059] Analysis Module: Used for recording data analysis;

[0060] Traffic Model: Used to predict network congestion in advance and provide a scientific basis for formulating traffic regulation strategies;

[0061] Monitoring Tool: Used for data analysis and problem location;

[0062] Pressure testing module: used to simulate network performance under high traffic loads and optimize system configuration according to the test results.

[0063] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A flow controllable forwarding method, characterized in that: Here are the steps: S1. Demand analysis: Communicate closely with each business department to understand the types of services carried by the network, record the network performance indicators of bandwidth, delay, and jitter for each service, and analyze the recorded data through the analysis module; S2. Traffic model construction: According to the demand analysis results, historical traffic data is collected, and professional network traffic monitoring tools are used to collect data at key nodes of the network. The collected data covers traffic characteristics in different time periods, and statistical analysis is performed on the collected traffic data to determine the distribution pattern of traffic. Based on the above data, a traffic model is constructed. The traffic model includes a traffic scheduler, a switch, a bandwidth monitoring module, a security module, and a cache management module; S3. Initial configuration of the device: perform software configuration, including setting the device's IP address, subnet mask, and default gateway network parameters to enable normal communication in the network, configure the device's username and password, adopt a high-strength password policy to prevent unauthorized access, enable the device's log function to record the device's operating status and operation record information for easy tracing during troubleshooting, set the flow control strategy according to the network environment, determine the upper and lower limits of the forwarding speed, and adjust the strategy under different network conditions; S4, Traffic monitoring and evaluation: Deploy monitoring tools to perform data analysis and problem location. Monitoring tools include core routers, switches, and server clusters. S5. Traffic classification and priority setting: Classify traffic according to data type and application requirements, and set priority based on the classification results; S6, Bandwidth limitation and rate control: Limit the bandwidth usage of traffic, control traffic through token bucket and leaky bucket algorithms to ensure that traffic does not exceed the preset bandwidth limit, set the upper and lower limits of data transmission rate, send data according to the set rate, monitor network conditions, and dynamically adjust the transmission rate; S7, Load balancing: Use load balancing algorithms to distribute traffic to multiple network nodes; S8, Resource Reservation: Reserve network bandwidth, cache space, and processing power, perform data transmission based on the reserved resources, monitor resource usage, ensure that the reserved resources are not occupied by other applications, and dynamically adjust the reservation strategy when resources are insufficient; S9. Secure encryption and verification of data packets: To ensure the confidentiality and integrity of data, the transmitted data packets are encrypted and verified, and the encryption protocol is used to encrypt and transmit the data. At the same time, the hash algorithm is used to verify the data integrity to prevent the data from being tampered with during the transmission process; S10, Traffic caching and data loss prevention: When the network fails, is congested, or the bandwidth is unstable, a traffic caching mechanism is used to cache the data flow and continue forwarding after the network conditions are restored; S11, Dynamic adjustment of forwarding strategy: Dynamically adjust the forwarding strategy according to the controllable traffic forwarding requirements and the real-time network status; S12, Logging and performance monitoring: Log the traffic forwarding process, monitor forwarding performance, and promptly issue alarms when anomalies are found to solve potential problems; S13, Testing and Optimization: Perform stress testing through the stress testing module to simulate network performance under high traffic load conditions, optimize system configuration based on test results, and adjust bandwidth, routing selection, and caching strategies.

2. A flow controllable forwarding method according to claim 1, characterized in that: The traffic scheduler in S2 is responsible for global traffic management and scheduling, and determines the forwarding path, rate and priority of data packets; Switch: used to forward data packets according to scheduling rules; Bandwidth monitoring module: used to monitor network bandwidth usage in real time, detect network congestion and adjust forwarding rate; Security module: used for data encryption, authentication and verification; Cache management module: caches traffic that cannot be forwarded temporarily.

3. A flow controllable forwarding method according to claim 1, characterized in that: The traffic data in S2 includes the source address, destination address, port number, protocol type, traffic volume, and the time when peak and trough occur.

4. A flow controllable forwarding method according to claim 1, characterized in that: Deploy monitoring tools in S4: collect traffic parameters in real time at key nodes of the network, including traffic size, flow rate, data packet type, source and destination addresses, and port numbers; Data analysis: Regularly analyze the monitored traffic data, combine it with the traffic model built in the early stage, determine whether the traffic is abnormal, and find out the reasons for traffic changes by comparing historical data with current data; Problem location: Use data analysis results to locate problems. When it is found that traffic anomalies cause network performance to deteriorate, the source of the problem can be traced back by checking the source and destination addresses and port number information of the traffic.

5. A system for implementing the flow controllable forwarding method according to any one of claims 1 to 4, characterized in that: include: Analysis module: used to record data analysis; Traffic model: used to predict network congestion in advance and provide a scientific basis for the formulation of traffic control strategies; Monitoring tools: used for data analysis and problem location; Stress test module: used to simulate network performance under high traffic load and optimize system configuration according to test results.

Citation Information

Patent Citations

  • A traffic forwarding method and system

    CN112383511B

Cited By

  • Secure data transmission method based on multi-thread control

    CN121309207A

  • A secure data transmission method based on multi-thread control

    CN121309207B