Detection method and device

By using a table entry group structure to store unicast routing and stream specification table entries in network equipment, quickly locate changing target unicast table entries, and only relevant stream specification table entries are detected, solving the problem of waste of computing resources caused by changes in unicast routing table entries and improving detection efficiency.

CN120263727AActive Publication Date: 2025-07-04NEW H3C TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510402983.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-04
Estimated Expiration
2045-03-31

AI Technical Summary

Technical Problem

In network devices, frequent changes in unicast routing table items lead to frequent detection of validity of stream specification table items, wasting a lot of computing resources.

Method used

The structures of the first table entry group, the second table entry group and the third table entry group are used to store unicast routing table items and stream specification table items. Through these table entry groups, the changing target unicast table items are quickly positioned, and only the relevant stream specification table items are tested to reduce the number of detections.

Benefits of technology

When the unicast routing table entry changes, only a part of the stream specification table entry needs to be detected, which reduces the consumption of computing resources and improves detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263727A_ABST
    Figure CN120263727A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a detection method and device, relates to the technical field of networks and is applied to network equipment, and the network equipment stores a first table item group, a second table item group and a third table item group corresponding to a first destination address for each first destination address. The method comprises the following steps: determining a changed target unicast table entry; acquiring at least one second destination address from the plurality of first destination addresses according to the destination address; and for each second destination address, based on the first table item group and the second table item group corresponding to the second destination address, detecting whether the flow specification table item in the third table item group corresponding to the second destination address is invalid. By applying the scheme provided by the embodiment of the invention, computing resources consumed by validity detection of the flow specification table item can be saved when the unicast routing table item is changed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technologies, and in particular, to a detection method and apparatus. Background Art

[0002] The traffic control policy of Flow Specification can accurately match specific traffic (source address, destination address, source port, destination port, protocol type, etc.), and there are multiple selection actions for specific traffic: discard, rate limit, traffic redirection, etc.

[0003] With the multi - protocol extension ability of BGP (Border Gateway Protocol), the traffic control policy of Flow Specification can be distributed by a network device to other network devices configured with BGP and issued as flow specification entries in the forwarding plane for traffic forwarding according to the traffic control policy.

[0004] When the flow specification entry performs traffic matching control for a specific destination address, it is necessary to perform validity detection on the destination address in the flow specification entry. The flow specification entry that fails the validity detection will not take effect. The process of validity detection needs to compare the destination address of the flow specification entry with the destination address in the unicast routing table entry. Therefore, as long as the unicast routing table entry changes, it is possible to cause the change of the validity detection result of the flow specification entry, and it is necessary to re - perform the validity detection on each flow specification entry. In the actual network environment, the unicast routing table entries in the network device change frequently, so it will cause frequent validity detection of the flow specification entries, wasting a large amount of computing resources. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a detection method and apparatus to save the computing resources consumed by the validity detection of flow specification entries when the unicast routing table entry changes. The specific technical solutions are as follows:

[0006] In a first aspect, the embodiments of this application provide a detection method applied to a network device. For each first destination address, the network device stores a first table entry group, a second table entry group, and a third table entry group corresponding to the first destination address;

[0007] The first table entry group includes: a first unicast routing table entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing table entry;

[0008] The second table entry group includes: a second unicast routing table entry, the destination address in the second unicast routing table entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing table entry is different from the first destination address;

[0009] The third table entry group includes: a flow specification table entry whose destination address is the first destination address;

[0010] The method includes:

[0011] Determine a target unicast table entry whose change occurs, where the destination address in the target unicast table entry is a target address, and the target unicast table entry is a newly added unicast routing table entry, or a unicast routing table entry removed from the routing table, or a unicast routing table entry whose contained information is updated;

[0012] According to the target address, obtain at least one second destination address from multiple first destination addresses, where the second destination address is in the network segment corresponding to the target address, or in the case where the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address;

[0013] For each second destination address, based on the first table entry group and the second table entry group corresponding to the second destination address, detect whether the flow specification table entry in the third table entry group corresponding to the second destination address is invalid.

[0014] In an embodiment of the present application, if the second destination address is in the network segment corresponding to the target address, the detecting whether the flow specification table entry in the third table entry group corresponding to the second destination address is invalid based on the first table entry group and the second table entry group corresponding to the second destination address includes:

[0015] Update the first table entry group corresponding to the second destination address based on the target unicast table entry;

[0016] When the first optimal table entry in the first table entry group is updated, determine that the first flow specification table entry corresponding to the first optimal table entry is invalid. The first flow specification table entry includes the second destination address and is different from the source node of the first optimal table entry. The source node is another network device that initiates table entry synchronization to this network device. The first optimal table entry is: the table entry determined from the first table entry group corresponding to the second destination address according to the longest mask matching principle and matching the second destination address;

[0017] If any one of each first autonomous domain is different from the second autonomous domain, it is determined that the second flow specification entry is invalid. The second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the first flow specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization. The current autonomous domain is the autonomous domain where the network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization.

[0018] In an embodiment of the present application, in each first entry group corresponding to a first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The method for determining whether the first optimal entry in the first entry group is updated is as follows:

[0019] If the unicast routing entry ranked first in the first entry group is updated, it is determined that the first optimal entry in the first entry group is updated.

[0020] In an embodiment of the present application, when the target address is different from the second destination address and the target address is in the network segment corresponding to the second destination address, detecting whether the flow specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address includes:

[0021] Updating the second entry group corresponding to the second destination address based on the target unicast entry;

[0022] If any one of each third autonomous domain is different from the fourth autonomous domain, it is determined that the third flow specification entry is invalid;

[0023] The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address. The third autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization. The current autonomous domain is the autonomous domain where the network device is located. The fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization. The first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the longest mask matching principle.

[0024] In one embodiment of the present application, within each second entry group corresponding to a first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier within the autonomous system path (ASPATH), where the ASPATH contains the identifiers of the autonomous systems passed through during entry synchronization;

[0025] Determine whether any one of each third autonomous system is different from a fourth autonomous system in the following manner:

[0026] If both the first autonomous system identifier and the second autonomous system identifier are the same as the third autonomous system identifier, it is determined that each third autonomous system is the same as the fourth autonomous system;

[0027] Wherein, the first autonomous system identifier is: the identifier of the highest bit within the ASPATH of the unicast routing entry with the first arrangement order in the second entry group corresponding to the second destination address;

[0028] The second autonomous system identifier is: the identifier of the highest bit within the ASPATH of the unicast routing entry with the last arrangement order in the second entry group corresponding to the second destination address;

[0029] The third autonomous system identifier is: the identifier of the highest bit within the ASPATH of the first optimal entry corresponding to the second destination address.

[0030] In one embodiment of the present application, the method further includes:

[0031] If there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the newly added flow specification entry, add the newly added flow specification entry to the third entry group corresponding to the third destination address;

[0032] If there are no first entry group, second entry group, and third entry group corresponding to the third destination address, create a first entry group, a second entry group, and a third entry group corresponding to the third destination address;

[0033] If the source node of the newly added flow specification entry is different from that of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous system is different from a sixth autonomous system, it is determined that the newly added flow specification entry is invalid;

[0034] Among them, the first optimal entry corresponding to the third destination address is: the entry that is determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matches the third destination address. The source node is another network device that initiates entry synchronization to this network device. The fifth autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing entry corresponding to the third destination address passes through during synchronization. The current autonomous domain is the autonomous domain where this network device is located. The sixth autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal entry corresponding to the third destination address passes through during synchronization.

[0035] In an embodiment of the present application, the method further includes:

[0036] Determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device;

[0037] If the first optimal entry corresponding to the fourth destination address of the target flow specification entry is different from the source node of the target flow specification entry, or any one of each seventh autonomous domain is different from the eighth autonomous domain, then determine that the target flow specification entry is invalid;

[0038] Among them, the first optimal entry corresponding to the fourth destination address is: the entry that is determined from the first entry group corresponding to the fourth destination address according to the longest mask matching principle and matches the fourth destination address. The seventh autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing entry corresponding to the fourth destination address passes through during synchronization. The current autonomous domain is the autonomous domain where this network device is located. The eighth autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal entry corresponding to the fourth destination address passes through during synchronization.

[0039] In a second aspect, an embodiment of the present application provides a detection device, which is applied to a network device. The network device stores a first entry group, a second entry group, and a third entry group corresponding to each first destination address;

[0040] The first entry group includes: a first unicast routing entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing entry;

[0041] The second entry group includes: a second unicast routing entry, the destination address in the second unicast routing entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing entry is different from the first destination address;

[0042] The third table entry group includes: a flow specification table entry whose destination address is the first destination address;

[0043] The apparatus includes:

[0044] A unicast table entry determination module, configured to determine a target unicast table entry that has changed, where the destination address in the target unicast table entry is a target address, and the target unicast table entry is a newly added unicast routing table entry, or a unicast routing table entry removed from the routing table, or a unicast routing table entry whose contained information has been updated;

[0045] A second address determination module, configured to obtain at least one second destination address from a plurality of first destination addresses according to the target address, where the second destination address is in the network segment corresponding to the target address, or when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address;

[0046] A first table entry detection module, configured to, for each second destination address, detect whether the flow specification table entry in the third table entry group corresponding to the second destination address is invalid based on the first table entry group and the second table entry group corresponding to the second destination address.

[0047] In an embodiment of the present application, if the second destination address is in the network segment corresponding to the target address, the first table entry detection module is specifically configured to:

[0048] For each second destination address, update the first table entry group corresponding to the second destination address based on the target unicast table entry;

[0049] When the first optimal table entry in the first table entry group is updated, determine that the first flow specification table entry corresponding to the first optimal table entry is invalid. The first flow specification table entry includes the second destination address and is different from the source node of the first optimal table entry. The source node is another network device that initiates table entry synchronization to the network device. The first optimal table entry is: the table entry that is determined from the first table entry group corresponding to the second destination address according to the longest mask matching principle and matches the second destination address;

[0050] If any one of each first autonomous domain is different from the second autonomous domain, determine that the second flow specification table entry is invalid. The second flow specification table entry is: other flow specification table entries in the third table entry group corresponding to the second destination address except the first flow specification table entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing table entry corresponding to the second destination address passes through during synchronization. The current autonomous domain is the autonomous domain where the network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal table entry corresponding to the second destination address passes through during synchronization.

[0051] In one embodiment of the present application, in the first entry group corresponding to each first destination address, based on the principle of the longest mask match, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The following module is used to determine whether the first optimal entry in the first entry group is updated:

[0052] The entry change determination module is configured to determine that the first optimal entry in the first entry group is updated if the unicast routing entry ranked first in the first entry group is updated.

[0053] In one embodiment of the present application, if the target address is in the network segment corresponding to the second destination address when the target address is different from the second destination address, the first entry detection module is specifically configured to:

[0054] For each second destination address, update the second entry group corresponding to the second destination address based on the target unicast entry;

[0055] If any one of each third autonomous domain is different from the fourth autonomous domain, determine that the third flow specification entry is invalid;

[0056] The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address. The third autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization. The current autonomous domain is the autonomous domain where the network device is located. The fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization. The first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the principle of the longest mask match.

[0057] In one embodiment of the present application, within the second entry group corresponding to each first destination address, the unicast routing entries are arranged in ascending or descending order of the value of the highest bit identifier within the autonomous system path (ASPATH). The ASPATH includes the identifiers of the autonomous domains passed during entry synchronization;

[0058] The following module is used to determine whether any one of each third autonomous domain is different from the fourth autonomous domain:

[0059] The autonomous domain determination module is configured to determine that each third autonomous domain is the same as the fourth autonomous domain if the first autonomous domain identifier and the second autonomous domain identifier are both the same as the third autonomous domain identifier;

[0060] Among them, the first autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked first in the second entry group corresponding to the second destination address;

[0061] The second autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked last in the second entry group corresponding to the second destination address;

[0062] The third autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the first optimal entry corresponding to the second destination address.

[0063] In an embodiment of the present application, the device further includes:

[0064] An entry adding module, configured to add the new flow specification entry to the third entry group corresponding to the third destination address if there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the new flow specification entry;

[0065] An entry group constructing module, configured to create a first entry group, a second entry group, and a third entry group corresponding to the third destination address if there are no first entry group, second entry group, and third entry group corresponding to the third destination address;

[0066] A second entry detecting module, configured to determine that the new flow specification entry is invalid if the source node of the new flow specification entry is different from that of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous domain is different from the sixth autonomous domain;

[0067] Among them, the first optimal entry corresponding to the third destination address is: the entry matching the third destination address determined from the first entry group corresponding to the third destination address according to the longest mask matching principle, the source node is another network device that initiates entry synchronization to this network device, the fifth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the third destination address during synchronization, the current autonomous domain is the autonomous domain where this network device is located, and the sixth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the third destination address during synchronization.

[0068] In an embodiment of the present application, the device further includes:

[0069] A flow specification entry determining module, configured to determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device;

[0070] The third table entry detection module is used to determine that the target flow specification table entry is invalid if the first optimal table entry corresponding to the fourth destination address of the target flow specification table entry is different from the source node of the target flow specification table entry, or any one of each seventh autonomous region is different from the eighth autonomous region;

[0071] Wherein, the first optimal table entry corresponding to the fourth destination address is: the table entry determined from the first table entry group corresponding to the fourth destination address according to the longest mask matching principle and matching the fourth destination address. The seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing table entry corresponding to the fourth destination address passes through during synchronization. The current autonomous region is the autonomous region where the network device is located. The eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal table entry corresponding to the fourth destination address passes through during synchronization.

[0072] In a third aspect, an embodiment of the present application provides a network device, and the network device includes:

[0073] A processor;

[0074] A transceiver;

[0075] A machine-readable storage medium storing machine-executable instructions executable by the processor, and for each first destination address, storing a first table entry group, a second table entry group, and a third table entry group corresponding to the first destination address;

[0076] The first table entry group includes: a first unicast routing table entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing table entry;

[0077] The second table entry group includes: a second unicast routing table entry, the destination address in the second unicast routing table entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing table entry is different from the first destination address;

[0078] The third table entry group includes: a flow specification table entry with the destination address being the first destination address;

[0079] The machine-executable instructions cause the processor to perform the following steps:

[0080] Determine a target unicast table entry that has changed, the destination address in the target unicast table entry is the target address, the target unicast table entry is a newly added unicast routing table entry, or a unicast routing table entry removed from the routing table, or a unicast routing table entry whose contained information has been updated;

[0081] Obtain at least one second destination address from multiple first destination addresses, where the second destination address is in the network segment corresponding to the target address, or when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address;

[0082] For each second destination address, based on the first entry group and the second entry group corresponding to the second destination address, detect whether the flow specification entry in the third entry group corresponding to the second destination address is invalid.

[0083] In an embodiment of the present application, when the second destination address is in the network segment corresponding to the target address, the detecting whether the flow specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address specifically includes:

[0084] Update the first entry group corresponding to the second destination address based on the target unicast entry;

[0085] When the first optimal entry in the first entry group is updated, determine that the first flow specification entry corresponding to the first optimal entry is invalid. The first flow specification entry includes the second destination address and is different from the source node of the first optimal entry. The source node is another network device that initiates entry synchronization to this network device. The first optimal entry is: the entry that is determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matches the second destination address;

[0086] If any one of each first autonomous domain is different from the second autonomous domain, determine that the second flow specification entry is invalid. The second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the first flow specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing entry corresponding to the second destination address passes through during synchronization. The current autonomous domain is the autonomous domain where this network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal entry corresponding to the second destination address passes through during synchronization.

[0087] In an embodiment of the present application, in the first entry group corresponding to each first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The following method is used to determine whether the first optimal entry in the first entry group is updated:

[0088] If the unicast routing entry ranked first in the arrangement order in the first entry group is updated, determine that the first optimal entry in the first entry group is updated.

[0089] In one embodiment of the present application, if the target address is in the network segment corresponding to the second destination address when the target address is different from the second destination address, detecting whether the flow specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address specifically includes:

[0090] Updating the second entry group corresponding to the second destination address based on the target unicast entry;

[0091] If any one of each third autonomous domain is different from the fourth autonomous domain, it is determined that the third flow specification entry is invalid;

[0092] The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address, the third autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization, the current autonomous domain is the autonomous domain where the network device is located, the fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization, and the first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the longest mask matching principle.

[0093] In one embodiment of the present application, within the second entry group corresponding to each first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier in the autonomous system path (ASPATH), and the ASPATH includes the identifiers of the autonomous domains passed during entry synchronization;

[0094] Determining whether any one of each third autonomous domain is different from the fourth autonomous domain in the following way:

[0095] If both the first autonomous domain identifier and the second autonomous domain identifier are the same as the third autonomous domain identifier, it is determined that each third autonomous domain is the same as the fourth autonomous domain;

[0096] Wherein, the first autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked first in the second entry group corresponding to the second destination address;

[0097] The second autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked last in the second entry group corresponding to the second destination address;

[0098] The third autonomous domain identifier is: the identifier of the highest bit in the ASPATH of the first optimal entry corresponding to the second destination address.

[0099] In one embodiment of the present application, the machine-executable instructions further cause the processor to perform the following steps:

[0100] If there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the newly added flow specification entry, add the newly added flow specification entry to the third entry group corresponding to the third destination address;

[0101] If there are no first entry group, second entry group, and third entry group corresponding to the third destination address, create a first entry group, a second entry group, and a third entry group corresponding to the third destination address;

[0102] If the source node of the newly added flow specification entry is different from the source node of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous region is different from the sixth autonomous region, determine that the newly added flow specification entry is invalid;

[0103] Wherein, the first optimal entry corresponding to the third destination address is: an entry determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matching the third destination address, the source node is another network device that initiates entry synchronization to this network device, the fifth autonomous region is: the last autonomous region different from the current autonomous region passed through during the synchronization of each second unicast routing entry corresponding to the third destination address, the current autonomous region is the autonomous region where this network device is located, and the sixth autonomous region is: the last autonomous region different from the current autonomous region passed through during the synchronization of the first optimal entry corresponding to the third destination address.

[0104] In one embodiment of the present application, the machine-executable instructions further cause the processor to perform the following steps:

[0105] Determine a target flow specification entry, where the field representing the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device;

[0106] If the first optimal entry corresponding to the fourth destination address of the target flow specification entry is different from the source node of the target flow specification entry, or if any one of each seventh autonomous region is different from the eighth autonomous region, determine that the target flow specification entry is invalid;

[0107] Among them, the first optimal entry corresponding to the fourth destination address is: the entry that is determined from the first entry group corresponding to the fourth destination address according to the principle of longest mask matching and matches the fourth destination address. The seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the fourth destination address passes through during synchronization. The current autonomous region is the autonomous region where the network device is located. The eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the fourth destination address passes through during synchronization.

[0108] Fourthly, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method steps of any one of the first aspects are implemented.

[0109] Fifthly, an embodiment of the present application further provides a computer program product containing instructions, which when running on a computer, causes the computer to execute the method steps of any one of the above first aspects.

[0110] Beneficial effects of the embodiments of the present application:

[0111] In the detection method provided by the embodiments of the present application, the first entry group, the second entry group, and the third entry group corresponding to the first destination address are used to record the unicast routing entries and flow specification entries related to the first destination address in the form of entry groups respectively. In the case where a target unicast entry that has changed appears, the second destination address can be quickly located. The second destination address is in the network segment corresponding to the target address, or the target address is in the network segment corresponding to the second destination address. The validity of the flow specification entry with the second destination address as the destination address may be affected by the target unicast entry. And the unicast routing entries related to the flow specification entry with the second destination address as the destination address are all in the first entry group and the second entry group corresponding to the second destination address. Therefore, it is only necessary to use the first entry group and the second entry group corresponding to the second destination address to detect the entries in the third entry group. Thus, it can be seen that when the unicast routing entries change, the solution provided by the embodiments of the present application only needs to detect a part of the flow specification entries based on a part of the unicast routing entries, which can greatly reduce the number of entries to be processed during detection and improve the detection efficiency. Description of the Drawings

[0112] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application, and those of ordinary skill in the art can also obtain other embodiments based on these drawings.

[0113] Figure 1 Schematic flow diagram of the first detection method reminded by the embodiments of the present application;

[0114] Figure 2 Schematic flow diagram of the second detection method provided by the embodiments of the present application;

[0115] Figure 3 Schematic flow diagram of the third detection method provided by the embodiments of the present application;

[0116] Figure 4 Schematic flow diagram of the fourth detection method provided by the embodiments of the present application;

[0117] Figure 5 Schematic flow diagram of the fifth detection method provided by the embodiments of the present application;

[0118] Figure 6 Schematic structural diagram of a network device provided by the embodiments of the present application;

[0119] Figure 7 Schematic structural diagram of a detection device provided by the embodiments of the present application. Detailed implementation manners

[0120] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art based on the present application belong to the scope of protection of the present application.

[0121] In order to better reflect the differences between the present application and the related technologies, the related technologies will be described first.

[0122] Related technology one: Whenever a BGP unicast routing table entry changes, all flow specification table entries containing the destination address are re-detected. Since the check requires comparing each flow specification table entry with each unicast routing table entry separately, it is necessary to traverse all flow specification table entries and traverse all unicast routing table entries for each flow specification table entry, which will consume a large amount of CPU resources and memory resources. If the number of unicast routing table entries and flow specification table entries is large, a large amount of computing resources will be consumed, resulting in a decline in device performance and affecting the normal services of the network device. Therefore, in a related technology, a cyclic timer is enabled to check whether the unicast routing table entry has changed regularly (for example, every 60 seconds), and if it has changed, the flow specification table entries are re-checked.

[0123] Although the above method reduces the consumption of the device's computing resources, it cannot immediately respond to changes in unicast routing table entries, which will slow down the convergence speed of the legality check of flow specification entries. Moreover, if it is found during regular checks that there are changes in unicast routing table entries, all flow specification entries containing the destination address need to be traversed again, and the efficiency is still very low.

[0124] Related art two: Build a radix tree using the destination address in the flow specification entry as the index, or build a hash table using the hash value of the destination address as the index. Each node in the radix tree corresponds to a destination address, and each entry in the hash table corresponds to a destination address. Flow specification entries with the same destination address form a storage structure, so that flow specification entries with the same destination address are recorded in the same storage structure. If the subsequent unicast routing table entry changes, only need to query which destination addresses the change of the unicast routing table entry will affect in the corresponding radix tree or hash table, and then only re-check the invalidity of the flow specification entries in the storage structure corresponding to the destination address. Thus, the number of flow specification entries that need to be checked can be reduced, and the efficiency of checking the invalidity of flow specification entries can be improved.

[0125] However, although the method of related art two can quickly find the flow specification entries that need to be checked, for each flow specification entry that needs to be checked, all unicast routing table entries need to be traversed for alignment and checking, and the checking efficiency is still relatively low.

[0126] To solve the above problems, the embodiments of the present application provide a detection method and device.

[0127] The embodiments of the present application are applied to a network device. For each first destination address, the network device stores a first table entry group, a second table entry group, and a third table entry group corresponding to the first destination address. The first destination address is the destination address in the flow specification entry in the above network device.

[0128] In an embodiment of the present application, a radix tree can be constructed, and each node on the radix tree corresponds to a first destination address. The first table entry group, the second table entry group, and the third table entry group are created on each node. Or a hash table is constructed, and the hash value of a first destination address is recorded in each entry in the hash table. The first table entry group, the second table entry group, and the third table entry group are created in each entry. The above first table entry group, second table entry group, and third table entry group can be in the form of a linked list, a queue, a stack, etc.

[0129] The above first table entry group includes: a first unicast routing table entry. The above first destination address is within the network segment corresponding to the destination address in the first unicast routing table entry. The first destination address being within the network segment corresponding to the destination address in the first unicast routing table entry includes the case where the first destination address is the same as the destination address in the first unicast routing table entry.

[0130] The nodes in the above first table entry group can directly record the corresponding first unicast routing table entry, or record the address of the corresponding first unicast routing table entry.

[0131] The above second table entry group includes: the destination address in the above second unicast routing table entry is within the network segment corresponding to the first destination address, and the destination address of the above second unicast routing table entry is different from the above first destination address. The nodes in the above second table entry group can directly record the corresponding second unicast routing table entry, or record the address of the corresponding second unicast routing table entry.

[0132] It should be noted that if the network device is configured with BGP route preference rules, only the preferred routing table entries that meet the BGP route preference rules will play a role when the network device forwards packets and will affect the validity of the traffic specification table entries. Therefore, the first table entry group and the second table entry group in this application can only include the preferred routing table entries that meet the above regulations.

[0133] The above third table entry group includes: a traffic specification table entry with the destination address being the first destination address. The nodes in the above third table entry group can directly record the corresponding traffic specification table entry, or record the address of the corresponding traffic specification table entry.

[0134] See Figure 1 , which is a schematic flowchart of the first detection method reminded in the embodiments of this application. The above method includes the following steps S101 - step S103.

[0135] S101: Determine the target unicast table entry that has changed.

[0136] Among them, the destination address in the above target unicast table entry is the target address, and the above target unicast table entry is a newly added unicast routing table entry, or a unicast routing table entry removed from the routing table, or a unicast routing table entry whose contained information has been updated.

[0137] If the first table entry group and the second table entry group only include preferred routing table entries, then the target unicast table entry is a unicast routing table entry newly added as a preferred routing table entry, or a unicast routing table entry removed from the preferred routing table entries (including the case where a unicast routing table entry that was originally a preferred routing table entry becomes a non-preferred routing table entry after update, and the unicast routing table entry itself is deleted), or a preferred routing table entry whose contained information has been updated.

[0138] S102: Obtain at least one second destination address from multiple first destination addresses according to the above-mentioned destination address.

[0139] Among them, the above-mentioned second destination address is in the network segment corresponding to the above-mentioned destination address, or when the above-mentioned destination address is different from the above-mentioned second destination address, the above-mentioned destination address is in the network segment corresponding to the above-mentioned second destination address.

[0140] S103: For each second destination address, based on the first entry group and the second entry group corresponding to the second destination address, detect whether the flow specification entry in the third entry group corresponding to the second destination address is invalid.

[0141] If there is a second destination address, execute step S103; if there is no second destination address, do not execute step S103.

[0142] In an embodiment of the present application, determine whether the flow specification entry in the third entry group is invalid according to the following rules.

[0143] Rule 1: For a flow specification entry, the source node of the flow specification entry must be the same as the source node of the third unicast routing entry. According to the longest mask matching principle, match an entry in the fourth unicast routing entry for the destination address of the flow specification entry, and the matched one is the third unicast routing entry. The destination address of the flow specification entry is in the network segment corresponding to the destination address of the fourth unicast routing entry. This is used to ensure that there is an available third unicast routing entry in the network device, so that the traffic specified by the policy specified by the flow specification entry detected by Rule 1 can reach the device targeted by the policy.

[0144] Rule 2: There cannot be a fifth unicast routing entry. The fifth unicast routing entry and the third unicast routing entry corresponding to the flow specification entry to be detected come from different neighbor autonomous domains, and its destination address is in the network segment corresponding to the destination address of the flow specification entry to be detected, and its destination address is different from the destination address of the flow specification entry to be detected. Since the fifth unicast routing entry is included in the network segment corresponding to the destination address of the flow specification entry, the destination address of the fifth unicast routing entry is more specific than the destination address of the flow specification entry, and the flow specification entry cannot restrict the traffic forwarded according to the more specific fifth unicast routing entry. Also, since the fifth unicast routing entry and the third unicast routing entry come from different neighbor autonomous domains, the fifth unicast routing entry will direct the traffic to other neighbor autonomous domains, posing a security risk. Therefore, when there is a fifth unicast routing entry, the flow specification entry to be detected is invalid.

[0145] In this embodiment, the destination addresses of the flow specification entries in the third entry group are all the second destination address. The first entry group corresponding to the second destination address contains all the first unicast routing entries corresponding to the second destination address, and the second destination address is within the network segment corresponding to the destination address in the first unicast routing entry. Therefore, for the flow specification entry with the destination address being the second destination address, the fourth unicast routing entry is the unicast routing entry in the first entry group. The third unicast routing entry is the first optimal entry in the first entry group. The first optimal entry is the entry determined from the first entry group corresponding to the second destination address according to the principle of the longest mask match and matching the second destination address.

[0146] Therefore, for the flow specification entries in the third entry group corresponding to the second destination address, it is only necessary to compare the source nodes of each flow specification entry with the first optimal entry in the first entry group in sequence. The unicast routing entries with different source nodes are invalid.

[0147] The above source node is another network device that initiates entry synchronization to this network device. In one case, when the AS (Autonomous System) does not enable the RFC (Request For Comments) 4456 reflection function, the source node is the BGP neighbor of this network device, and the entry is synchronized to this network device by the BGP neighbor, and the source node is the network device corresponding to the neighbor address recorded in the entry. In another case, the network devices in the same AS domain enable the RFC 4456 reflection function, that is, the network devices in the same AS domain are all BGP neighbors with the same network device (such as network device A). In this case, if network device B needs to synchronize an entry to network device C, then network device B will first synchronize the entry with network device A, and then network device A will synchronize the entry with network device C. In this case, the synchronized entry will carry an ORIGINATOR_ID field, and the network device B is recorded in the source field, indicating that the network device that initiates entry synchronization to network device A is network device B.

[0148] Therefore, if both the compared unicast routing entry and the flow specification entry carry a source field, then compare whether the source fields of the two are the same. If they are the same, it is determined that the source nodes of the unicast routing entry and the flow specification entry are the same. If at least one of the compared unicast routing entry and the flow specification entry does not carry a source field, then determine the address of the BGP neighbor that synchronizes the entry to this network device through the neighbor address attribute value recorded in the entry, and compare whether the addresses of the BGP neighbors carried by the two are the same. If they are the same, it is determined that the BGP neighbors that synchronize the two entries to this network device are the same, that is, it is determined that the source nodes of the unicast routing entry and the flow specification entry are the same.

[0149] If all the flow specification entries in the third entry group corresponding to the second destination address do not conform to the above Rule 1, it is not necessary to continue with subsequent detections, and it can be directly determined that all the flow specification entries in the third entry group corresponding to the second destination address are invalid, thus saving the computing resources consumed by the detections.

[0150] If there is a flow specification entry in the third entry group corresponding to the second destination address that conforms to Rule 1, continue the detection based on Rule 2.

[0151] Suppose the following situation. If a unicast routing entry is synchronized from network device A to network device B, and network device B synchronizes it to network device C. Network device A is in autonomous system 1, network device B is in autonomous system 2, and network device C is in autonomous system 3. Then, for network device B, the neighbor autonomous system of this unicast routing entry is autonomous system 1, and for network device C, the neighbor autonomous system of this unicast routing entry is autonomous system 2. The neighbor autonomous system is: the last autonomous system different from the current autonomous system passed through during entry synchronization, and the current autonomous system is the autonomous system where the network device storing the entry is located. To record the autonomous systems passed through during the synchronization process of the unicast routing entry, there is an ASPATH (autonomous system path) field in the unicast routing entry. The value of the ASPATH field in the unicast routing entry recorded in network device B is 1, indicating that this unicast routing entry is synchronized from autonomous system 1. The value of the ASPATH field in the unicast routing entry recorded in network device C is 21, that is, the identifier 2 of autonomous system 2 is added to the high - order part of the ASPATH field recorded in network device B, indicating that this unicast routing entry is synchronized to network device C through autonomous system 1 and autonomous system 2 in sequence. For each network device, by querying the identifier of the highest - order bit in the ASPATH field, it can be determined which autonomous system is the neighbor autonomous system for this unicast routing entry.

[0152] In another example, if a unicast routing entry is synchronized from network device A to network device B, and network device B synchronizes it to network device C. If network device A, network device B, and network device C are all in the same autonomous system, there is no neighbor autonomous system. Then the values of the ASPATH fields in the unicast routing entries stored in network device A, network device B, and network device C are all empty.

[0153] Therefore, the neighbor autonomous system corresponding to the unicast routing entry can be determined based on the identifier of the highest - order bit in the ASPATH (which can be called LeftAS) in the unicast routing entry.

[0154] In one embodiment of the present application, the unicast routing entries in the second entry group corresponding to the second destination address can be traversed in sequence to determine whether the neighbor autonomous domain thereof is the same as the neighbor autonomous domain of the first optimal entry in the first entry group corresponding to the second destination address. If there is any difference, it is determined that all flow specification entries in the third entry group corresponding to the second destination address are invalid.

[0155] As can be seen from the above, in the present application, the first entry group, the second entry group, and the third entry group corresponding to the first destination address are used to record the unicast routing entries and flow specification entries related to the first destination address in the form of entry groups respectively. In the case where a target unicast entry that has changed appears, the second destination address can be quickly located. The second destination address is in the network segment corresponding to the target address, or the target address is in the network segment corresponding to the second destination address. The validity of the flow specification entries with the second destination address as the destination address may be affected by the target unicast entry. And the unicast routing entries related to the flow specification entries with the second destination address as the destination address are all in the first entry group and the second entry group corresponding to the second destination address. Therefore, only the first entry group and the second entry group corresponding to the second destination address need to be used to detect the entries in the third entry group. Thus, when the unicast routing entries change, by using the solution provided in the embodiment of the present application, only a part of the flow specification entries need to be detected based on a part of the unicast routing entries, which can greatly reduce the number of entries to be processed during detection and improve the detection efficiency.

[0156] See Figure 2 , which is a schematic flowchart of the second detection method provided by the embodiment of the present application. For the second destination address included in the network segment corresponding to the destination address of the above target unicast entry, the above step S103 is implemented through the following steps S103A - S103C.

[0157] S103A: Update the first entry group corresponding to the second destination address based on the above target unicast entry.

[0158] If the above target unicast entry is a newly added unicast routing entry, add the target unicast entry to the first entry group.

[0159] If the above target unicast entry is a unicast routing entry removed from the routing table, remove the target unicast entry from the first entry group.

[0160] If the above target unicast entry is a unicast routing entry whose included information has been updated, when the first unicast routing entry is directly recorded at the node in the first entry group, update the target unicast entry recorded in the first entry group; when the address of the first unicast routing entry is recorded at the node in the first entry group, the first entry group remains unchanged.

[0161] S103B: When the first optimal entry in the first entry group is updated, determine that the first flow specification entry corresponding to the first optimal entry is invalid.

[0162] Among them, the above first flow specification entry includes the second destination address and is different from the source node of the above first optimal entry. The source node is another network device that initiates entry synchronization to this network device. The above first optimal entry is: determined from the first entry group corresponding to the second destination address according to the longest mask matching principle, and is an entry that matches the second destination address.

[0163] S103C: If any one of each first autonomous domain is different from the second autonomous domain, determine that the second flow specification entry is invalid.

[0164] Among them, the above second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the above first flow specification entry. The above first autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when each second unicast routing entry corresponding to the second destination address is synchronized. The above current autonomous domain is the autonomous domain where this network device is located. The above second autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when the first optimal entry corresponding to the second destination address is synchronized.

[0165] Referring to the above Rule 1 and Rule 2, it can be seen that whether it is Rule 1 or Rule 2, it is to compare with the first optimal entry corresponding to the second destination address, and then determine whether the flow specification entry in the third entry group is invalid. Therefore, if the target unicast entry causes the first optimal entry in the first entry group to be updated, this update may cause a change in the judgment result of whether the flow specification entry in the third entry group is valid. Therefore, subsequent validity detection is required. So in this embodiment, steps S103B and step 103C are both executed when the first optimal entry in the first entry group is updated. On the contrary, if the target unicast entry does not cause the update of the first optimal entry, the target unicast entry will not cause a change in the validity of the flow specification entry in the third entry group, and subsequent validity detection is not required.

[0166] There may be the following three situations where the target unicast entry causes the first optimal entry in the first entry group corresponding to the second destination address to be updated.

[0167] Situation 1: The target unicast entry is a newly added unicast routing entry, newly added to the first entry group and becomes the new first optimal entry.

[0168] Case 2: The target unicast entry is a unicast routing entry removed from the routing table. The target unicast entry was originally the first best entry in the first entry group corresponding to the second destination address. Since it is deleted, the first best entry in the first entry group changes.

[0169] Case 3: The information contained in the target unicast entry is updated, and the target unicast entry is the first best entry in the first entry group corresponding to the second destination address.

[0170] When the first best entry is updated, re-detect whether each flow specification entry in the third entry group is invalid based on the method described in the foregoing step S103. The specific implementation method will not be elaborated here.

[0171] In an embodiment of the present application, the identifier of the last autonomous domain different from the current autonomous domain passed when the first best entry in the first entry group is synchronized can be separately recorded, that is, the identifier of the highest bit in the ASPATH of the first best entry. When the source field is included in the first best entry, the source field is separately recorded, which is convenient for directly detecting the validity of the flow specification entry based on the recorded identifier of the highest bit and the source field, without the need to re-determine the above-mentioned identifier of the highest bit and the source field during detection. Furthermore, a judgment result field indicating whether each first autonomous domain is the same as the second autonomous domain can be separately recorded. Then, when neither the first best entry nor the unicast routing entry in the second entry group changes, regardless of how the flow specification entry in the third entry group changes, it can be directly determined whether each first autonomous domain is the same as the second autonomous domain based on this judgment result field, so as to directly complete the judgment of Rule 2 without the need to re-judge, which can improve the detection efficiency.

[0172] Furthermore, if the information contained in the target unicast entry is updated, and the target unicast entry is the first best entry in the first entry group, and the updated information is the source field or ASPATH, referring to the foregoing Rule 1 and Rule 2, it can be known that the above update will affect the validity of the flow specification entry. In this case, the validity of the flow specification entry can be re-detected. If other information is updated, there is no need to re-detect the validity.

[0173] In an embodiment of the present application, in each first entry group corresponding to each first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. Then, for each first destination address, the unicast routing entry at the top of the first entry group corresponding to the first destination address is the first best entry in the first entry group.

[0174] Therefore, it is possible to determine whether the first best entry in the first entry group is updated based on the following step A.

[0175] Step A: If the unicast routing entry ranked first in the first entry group is updated, it is determined that the first optimal entry in the first entry group is updated.

[0176] Specifically, if the above-mentioned target unicast entry is a newly added unicast routing entry, and if the above-mentioned target unicast entry is added to the first place of the first entry group corresponding to the second destination address, it is determined that the first optimal entry is updated.

[0177] If the above-mentioned target unicast entry is a unicast routing entry removed from the routing table, and if the above-mentioned target unicast entry was originally located at the first place of the first entry group corresponding to the second destination address, it is determined that the first optimal entry is updated. The updated first optimal entry is the unicast routing entry originally located at the second place.

[0178] If the information contained in the above-mentioned target unicast entry is updated, and if the above-mentioned target unicast entry is located at the first place of the first entry group corresponding to the second destination address, it is determined that the first optimal entry is updated.

[0179] If the first entry group is constructed according to this embodiment, it is only necessary to directly determine whether the unicast routing entry at the first place of the first entry group is updated to determine whether the first optimal entry is updated. The determination method is relatively simple and there is no need to traverse the first entry group to find the first optimal entry therein.

[0180] As can be seen from the above, in this embodiment, only when the first optimal entry corresponding to the first entry group is updated, the validity of the flow specification entry in the third entry group corresponding to the second destination address is re-detected, and no re-detection is performed in other cases, which can further save the number of validity detections and further save computing resources.

[0181] See Figure 3 , which is a schematic flowchart of the third detection method provided by the embodiment of the present application. Compared with the embodiment shown in the foregoing Figure 1 , if the above-mentioned target address is in the network segment corresponding to the second destination address when the above-mentioned target address is different from the above-mentioned second destination address, the above-mentioned step S103 can be implemented by the following steps S103D - S103E.

[0182] S103D: Update the second entry group corresponding to the second destination address based on the above-mentioned target unicast entry.

[0183] If the above-mentioned target unicast entry is a newly added unicast routing entry, add the target unicast entry to the second entry group.

[0184] If the above-mentioned target unicast entry is a unicast routing entry removed from the routing table, remove the target unicast entry from the second entry group.

[0185] If the above target unicast entry is the preferred routing entry whose contained information has been updated, when the nodes in the second entry group directly record the second unicast routing entry, update the target unicast entry recorded in the second entry group; when the nodes in the second entry group record the address of the second unicast routing entry, the second entry group remains unchanged.

[0186] Since only the second entry group changes in the Figure 3 shown situation, from the foregoing descriptions of Rule 1 and Rule 2, it can be seen that Rule 1 is detected based on the first entry group and the third entry group, and Rule 2 is detected based on the first entry group and the second entry group. Therefore, the detection result based on Rule 1 has nothing to do with the second entry group, and the change of the second entry group will not affect the detection result based on Rule 1. So in this case, the flow specification entry can be re-detected only based on Rule 2, and then step S103E is executed.

[0187] S103E: If any one of each third autonomous domain is different from the fourth autonomous domain, determine that the third flow specification entry is invalid.

[0188] Wherein, the above third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address, the above third autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization, the above current autonomous domain is the autonomous domain where the above network device is located, the above fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization, and the above first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the longest mask matching principle.

[0189] Specifically, the manner of determining whether the flow specification entry in the third entry group is invalid based on the third autonomous domain and the fourth autonomous domain can refer to the description of step S103 above, which will not be elaborated here.

[0190] It should be noted that if all the third autonomous domains are the same as the fourth autonomous domain, the state of whether the third flow specification entry in the third entry group corresponding to the second destination address is valid remains unchanged, that is, it is consistent with the result of the previous detection, rather than directly determining that all the third flow specification entries corresponding to the second destination address are valid. However, if any one of each third autonomous domain is different from the fourth autonomous domain, directly determine that all the third flow specification entries are invalid.

[0191] In one embodiment of the present application, within each second entry group corresponding to a first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier within the ASPATH, where the ASPATH includes the identifiers of the autonomous domains passed through during entry synchronization.

[0192] In this case, it is determined whether any one of each third autonomous domain is different from the fourth autonomous domain through the following step B.

[0193] Step B: If both the first autonomous domain identifier and the second autonomous domain identifier are the same as the third autonomous domain identifier, it is determined that each third autonomous domain is the same as the fourth autonomous domain.

[0194] Among them, the above-mentioned first autonomous domain identifier is: the identifier of the highest bit within the ASPATH of the unicast routing entry ranked first in the second entry group corresponding to the second destination address (specifically, the updated second entry group).

[0195] The above-mentioned second autonomous domain identifier is: the identifier of the highest bit within the ASPATH of the unicast routing entry ranked last in the second entry group corresponding to the second destination address.

[0196] The above-mentioned third autonomous domain identifier is: the identifier of the highest bit within the ASPATH of the first optimal entry corresponding to the second destination address.

[0197] The arrangement order of the unicast routing entries in the second entry group is related to the value of the identifier of the highest bit within the ASPATH. The closer to the first place, the larger, or the closer to the first place, the smaller. In this case, the first autonomous domain identifier is the identifier of the highest bit within the ASPATH of the unicast routing entry ranked first in the second entry group. The second autonomous domain identifier is the identifier of the highest bit within the ASPATH of the unicast routing entry ranked last in the second entry group. Therefore, the first autonomous domain identifier and the second autonomous domain identifier should be the two extreme values of the values of the identifiers of the highest bit within the ASPATH of all unicast routing entries in the second entry group respectively. If the first autonomous domain identifier and the second autonomous domain identifier are the same, it means that the maximum value and the minimum value of the identifiers of the highest bit within the ASPATH of all unicast routing entries in the entire second link are the same, that is, the identifiers of the highest bit within the ASPATH of all unicast routing entries are the same.

[0198] On this basis, if both the first autonomous domain identifier and the second autonomous domain identifier are the same as the identifier of the highest bit within the ASPATH of the second optimal entry (i.e., the third autonomous domain identifier), it means that all third autonomous domains corresponding to the unicast routing entries in the second entry group are the same as the fourth autonomous domain.

[0199] Therefore, when constructing the second entry group using this embodiment, when detecting the validity of the flow specification entries in the third entry group, only three autonomous domain identifiers need to be compared, without having to traverse the entire second entry group to sequentially determine whether the third autonomous domain of all unicast routing entries in the second entry group is the same as the fourth autonomous domain, which can save more computing power.

[0200] It should be noted that if the ASPATH in a unicast routing entry is a null value, the identifier of its highest bit is also null. If the first autonomous domain identifier, the second autonomous domain identifier, and the third autonomous domain identifier are all null, it is also considered that the first autonomous domain identifier, the second autonomous domain identifier, and the third autonomous domain identifier are the same.

[0201] As can be seen from the above, when detecting the flow specification entries using this embodiment, if the second entry group corresponding to the second destination address is updated, only by comparing the third autonomous domain and the fourth autonomous domain based on the first entry group and the second entry group, it can be determined whether the invalid state of the flow specification entry in the third entry corresponding to the second destination address needs to be updated. Only a small number of unicast routing entries in the first entry group and the second entry group are involved in this process, and even the comparison of the flow specification entries in the third entry group is not involved. Therefore, less computing resources are consumed.

[0202] See Figure 4 , which is a schematic flowchart of the fourth detection method provided by the embodiment of the present application. Compared with the embodiment shown in the foregoing Figure 1 , the following steps S104 - step S106 are further included.

[0203] S104: If there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the newly added flow specification entry, add the above newly added flow specification entry to the third entry group corresponding to the above third destination address.

[0204] S105: If there are no such first entry group, second entry group, and third entry group corresponding to the third destination address, create a first entry group, a second entry group, and a third entry group corresponding to the above third destination address.

[0205] In this case, it is necessary to traverse the unicast routing entries to determine the first unicast routing entry corresponding to the third destination address therein, so as to construct the first entry group, and determine the second unicast routing entry corresponding to the third destination address therein, so as to construct the second entry group. The third entry group contains the newly added flow specification entry.

[0206] S106: If the source node of the above newly added flow specification entry is different from the first optimal entry corresponding to the above third destination address, or if any one of each fifth autonomous domain is different from the sixth autonomous domain, determine that the above newly added flow specification entry is invalid.

[0207] Among them, the first optimal entry corresponding to the above third destination address is: the entry that is determined from the first entry group corresponding to the above third destination address according to the longest mask matching principle and matches the third destination address. The above source node is another network device that initiates entry synchronization to this network device. The above fifth autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the above third destination address passes through during synchronization. The above current autonomous region is the autonomous region where this network device is located. The above sixth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the above third destination address passes through during synchronization.

[0208] Specifically, the implementation manner of step S106 is similar to that of the foregoing step S103 and will not be elaborated here.

[0209] It should be noted that if there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the newly added flow specification entry, and the newly added flow specification entry is added to the third entry group, then since rule 2 is judged based on the first entry group and the second entry group, inserting the newly added flow specification entry into the third entry group will not affect the judgment result of rule 2. Therefore, if the foregoing judgment result field is recorded for the first entry group corresponding to the third destination address, it can be determined whether each fifth autonomous region is the same as the sixth autonomous region based on the judgment result field, and this judgment does not need to be performed again, which can save the calculation amount.

[0210] As can be seen from the above, in this embodiment, in the case of the newly added flow specification entry, the newly added flow specification entry can be inserted into the existing third entry group, or new first entry group, second entry group, and third entry group can be constructed for the newly added flow specification entry, and then it can be detected whether the newly added flow specification entry is valid. This process only needs to use the newly added flow specification entry and the unicast routing entries in the first entry group and the second entry group corresponding to its third destination address, and there is no need to traverse the unicast routing entries for detection. Therefore, calculation resources can also be saved when re-detecting the validity of the newly added flow specification entry.

[0211] See Figure 5 , which is a schematic flowchart of the fifth detection method provided by the embodiment of the present application. Compared with the foregoing Figure 1 shown embodiment, it further includes the following steps S107 - step S108.

[0212] S107: Determine the target flow specification entry.

[0213] The field representing the source node in the above target flow specification entry is updated, and the above source node is another network device that initiates entry synchronization to this network device.

[0214] As can be seen from the validity judgment process of the flow specification entry described above, for the flow specification entry, only the source node of it is used to judge its validity. Therefore, only when the field representing the source node in the flow specification entry is updated will it affect the validity of the flow specification entry. Therefore, in this application, it is necessary to determine the target flow specification entry whose field representing the source node is updated and re-detect it.

[0215] S108: If the first optimal entry corresponding to the fourth destination address of the above target flow specification entry is different from the source node of the above target flow specification entry, or any one of each seventh autonomous region is different from the eighth autonomous region, then determine that the above target flow specification entry is invalid.

[0216] Among them, the first optimal entry corresponding to the above fourth destination address is: the entry that is determined from the first entry group corresponding to the above fourth destination address according to the longest mask matching principle and matches the fourth destination address; the seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the above fourth destination address passes through during synchronization; the current autonomous region is the autonomous region where the above network device is located; the eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the above fourth destination address passes through during synchronization.

[0217] Specifically, the implementation manner of step S108 is similar to the foregoing step S103 and will not be elaborated here.

[0218] It should be noted that since rule 2 is judged based on the first entry group and the second entry group, the change of the information included in the target flow specification entry in the third entry group will not affect the judgment result of rule 2. Therefore, if the judgment result field mentioned above is recorded for the first entry group corresponding to the fourth destination address, then based on the judgment result field, it can be determined whether each seventh autonomous region is the same as the eighth autonomous region, and this judgment does not need to be performed again, which can save the calculation amount.

[0219] As can be seen from the above, this embodiment can re-detect whether the target flow specification entry is valid in the presence of the target flow specification entry. This process only needs to use the target flow specification entry and the unicast routing entries in the first entry group and the second entry group corresponding to its fourth destination address, without traversing all unicast routing entries. Therefore, it can also save computing resources when re-detecting the validity of the target flow specification entry.

[0220] Corresponding to the foregoing detection method applied to a network device, an embodiment of this application also provides a network device.

[0221] See Figure 6, which is a schematic structural diagram of a network device provided by an embodiment of the present application. The above network device includes:

[0222] A processor 601;

[0223] A transceiver 604;

[0224] A machine-readable storage medium 602, where the machine-readable storage medium 602 stores machine-executable instructions that can be executed by the processor 601, and for each first destination address, a first entry group, a second entry group, and a third entry group corresponding to the first destination address are stored;

[0225] The first entry group includes: a first unicast routing entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing entry;

[0226] The second entry group includes: a second unicast routing entry, the destination address in the second unicast routing entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing entry is different from the first destination address;

[0227] The third entry group includes: a traffic specification entry with the destination address being the first destination address;

[0228] The machine-executable instructions cause the processor 601 to perform the following steps:

[0229] Determine a target unicast entry that has changed. The destination address in the target unicast entry is a target address. The target unicast entry is a newly added unicast routing entry, or a unicast routing entry removed from the routing table, or a unicast routing entry whose contained information has been updated;

[0230] According to the target address, obtain at least one second destination address from multiple first destination addresses. The second destination address is in the network segment corresponding to the target address, or in the case where the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address;

[0231] For each second destination address, based on the first entry group and the second entry group corresponding to the second destination address, detect whether the traffic specification entry in the third entry group corresponding to the second destination address is invalid.

[0232] If Figure 6As shown, the network device may further include a communication bus 603. The processor 601, the machine-readable storage medium 602, and the transceiver 604 communicate with each other through the communication bus 603. The communication bus 603 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus 603 may be divided into an address bus, a data bus, a control bus, etc.

[0233] The transceiver 604 may be a wireless communication module. Under the control of the processor 601, the transceiver 604 performs data interaction with other devices.

[0234] The machine-readable storage medium 602 may include a Random Access Memory (RAM), and may also include a Non-Volatile Memory (NVM), such as at least one disk memory. Additionally, the machine-readable storage medium 602 may also be at least one storage device located far from the aforementioned processor.

[0235] The processor 601 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0236] As can be seen from the above, in this application, the first entry group, the second entry group, and the third entry group corresponding to the first destination address are adopted, and the unicast routing entries and flow specification entries related to the first destination address are respectively recorded in the form of entry groups. In the case where a target unicast entry changes, the second destination address can be quickly located. The second destination address is in the network segment corresponding to the target address, or the target address is in the network segment corresponding to the second destination address. The validity of the flow specification entry with the second destination address as the destination address may be affected by the target unicast entry. And the unicast routing entries related to the flow specification entry with the second destination address as the destination address are all in the first entry group and the second entry group corresponding to the second destination address. Therefore, only the first entry group and the second entry group corresponding to the second destination address need to be used to detect the entries in the third entry group. Thus, it can be seen that when the unicast routing entries change, adopting the solution provided by the embodiment of this application only needs to detect a part of the flow specification entries based on a part of the unicast routing entries, which can greatly reduce the number of entries to be processed during detection and improve the detection efficiency.

[0237] In an embodiment of this application, if the second destination address is in the network segment corresponding to the target address, detecting whether the flow specification entries in the third entry group corresponding to the second destination address are invalid based on the first entry group and the second entry group corresponding to the second destination address specifically includes:

[0238] Updating the first entry group corresponding to the second destination address based on the target unicast entry;

[0239] When the first optimal entry in the first entry group is updated, determining that the first flow specification entry corresponding to the first optimal entry is invalid. The first flow specification entry includes the second destination address and is different from the source node of the first optimal entry. The source node is another network device that initiates entry synchronization to this network device. The first optimal entry is: the entry that is determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matches the second destination address;

[0240] If any one in each first autonomous domain is different from the second autonomous domain, determining that the second flow specification entry is invalid. The second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the first flow specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing entry corresponding to the second destination address passes through during synchronization. The current autonomous domain is the autonomous domain where this network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal entry corresponding to the second destination address passes through during synchronization.

[0241] As can be seen from the above, in this embodiment, only when the first optimal entry corresponding to the first entry group is updated, the validity of the flow specification entry in the third entry group corresponding to the second destination address is redetected. In other cases, no redetection is performed, which can further save the number of validity detections and further save computing resources.

[0242] In one embodiment of the present application, in the first entry group corresponding to each first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The following method is used to determine whether the first optimal entry in the first entry group is updated:

[0243] If the unicast routing entry ranked first in the first entry group is updated, it is determined that the first optimal entry in the first entry group is updated.

[0244] As can be seen from the above, if the first entry group is constructed using this embodiment, directly determining whether the unicast routing entry at the head of the first entry group is updated can determine whether the first optimal entry is updated. The determination method is relatively simple and does not require traversing the first entry group to find the first optimal entry therein.

[0245] In one embodiment of the present application, if the target address is in the network segment corresponding to the second destination address when the target address is different from the second destination address, based on the first entry group and the second entry group corresponding to the second destination address, it is detected whether the flow specification entry in the third entry group corresponding to the second destination address is invalid. Specifically, it includes:

[0246] Update the second entry group corresponding to the second destination address based on the target unicast entry;

[0247] If any one of each third autonomous domain is different from the fourth autonomous domain, it is determined that the third flow specification entry is invalid;

[0248] The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address. The third autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the second destination address during synchronization. The current autonomous domain is the autonomous domain where the network device is located. The fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the second destination address during synchronization. The first optimal entry is: the entry determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matching the second destination address.

[0249] As can be seen from the above, when detecting the flow specification entries in this embodiment, if the second entry group corresponding to the second destination address is updated, it is only necessary to compare the third autonomous system and the fourth autonomous system based on the first entry group and the second entry group, and then it can be determined whether the invalid status of the flow specification entry in the third entry corresponding to the second destination address needs to be updated. Only a small number of unicast routing entries in the first entry group and the second entry group are involved in this process, and even the comparison of the flow specification entries in the third entry group is not involved. Therefore, less computing resources are consumed.

[0250] In one embodiment of the present application, within the second entry group corresponding to each first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier within the autonomous system path ASPATH, and the ASPATH includes the identifiers of the autonomous systems passed through during entry synchronization;

[0251] Determine whether any one of each third autonomous system is different from the fourth autonomous system in the following manner:

[0252] If both the first autonomous system identifier and the second autonomous system identifier are the same as the third autonomous system identifier, it is determined that each third autonomous system is the same as the fourth autonomous system;

[0253] Wherein, the first autonomous system identifier is: the identifier of the highest bit within the ASPATH in the unicast routing entry that ranks first in the second entry group corresponding to the second destination address;

[0254] The second autonomous system identifier is: the identifier of the highest bit within the ASPATH in the unicast routing entry that ranks last in the second entry group corresponding to the second destination address;

[0255] The third autonomous system identifier is: the identifier of the highest bit within the ASPATH in the first optimal entry corresponding to the second destination address.

[0256] As can be seen from the above, in the case of constructing the second entry group using this embodiment, when detecting the validity of the flow specification entries in the third entry group, only three autonomous system identifiers need to be compared, and it is not necessary to traverse the entire second entry group to sequentially determine whether all the third autonomous systems in the second entry group are the same as the fourth autonomous system, which can save more computing power.

[0257] In one embodiment of the present application, the machine-executable instructions further cause the processor 601 to perform the following steps:

[0258] If there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address with newly added flow specification entries, add the newly added flow specification entries to the third entry group corresponding to the third destination address;

[0259] If there are no first entry group, second entry group, and third entry group corresponding to the third destination address, create the first entry group, second entry group, and third entry group corresponding to the third destination address;

[0260] If the source node of the newly added flow specification entry is different from that of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous region is different from the sixth autonomous region, determine that the newly added flow specification entry is invalid;

[0261] Among them, the first optimal entry corresponding to the third destination address is: the entry that is determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matches the third destination address. The source node is another network device that initiates entry synchronization to this network device. The fifth autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the third destination address passes through during synchronization. The current autonomous region is the autonomous region where this network device is located. The sixth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the third destination address passes through during synchronization.

[0262] As can be seen from the above, in this embodiment, in the case of the existence of a newly added flow specification entry, the newly added flow specification entry can be inserted into the existing third entry group, or a new first entry group, second entry group, and third entry group can be constructed for the newly added flow specification entry, and then it is detected whether the newly added flow specification entry is valid. This process only needs to use the newly added flow specification entry and the unicast routing entries in the first entry group and the second entry group corresponding to its third destination address, without traversing the unicast routing entries for detection. Therefore, computing resources can also be saved when re-detecting the validity of the newly added flow specification entry.

[0263] In an embodiment of the present application, the machine-executable instructions further cause the processor 601 to execute the following steps:

[0264] Determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device;

[0265] If the first optimal entry corresponding to the fourth destination address of the target flow specification entry is different from the source node of the target flow specification entry, or if any one of each seventh autonomous region is different from the eighth autonomous region, determine that the target flow specification entry is invalid;

[0266] Among them, the first optimal entry corresponding to the fourth destination address is: the entry that is determined from the first entry group corresponding to the fourth destination address according to the principle of the longest mask match and matches the fourth destination address. The seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the fourth destination address passes through during synchronization. The current autonomous region is the autonomous region where the network device is located. The eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the fourth destination address passes through during synchronization.

[0267] As can be seen from the above, this embodiment can re-detect the validity of the target flow specification entry in the presence of the target flow specification entry. This process only needs to use the target flow specification entry and the unicast routing entries in the first entry group and the second entry group corresponding to its fourth destination address, without traversing all unicast routing entries. Therefore, computing resources can also be saved when re-detecting the validity of the target flow specification entry.

[0268] Corresponding to the foregoing detection method applied to a network device, an embodiment of the present application further provides a detection device applied to a network device.

[0269] See Figure 7 , which is a schematic structural diagram of a detection device provided by an embodiment of the present application, applied to a network device. The network device stores, for each first destination address, a first entry group, a second entry group, and a third entry group corresponding to the first destination address;

[0270] The first entry group includes: a first unicast routing entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing entry;

[0271] The second entry group includes: a second unicast routing entry, the destination address in the second unicast routing entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing entry is different from the first destination address;

[0272] The third entry group includes: a flow specification entry with the destination address being the first destination address;

[0273] The device includes:

[0274] A unicast entry determination module 701, configured to determine a target unicast entry that has changed. The destination address in the target unicast entry is a target address. The target unicast entry is a newly added unicast routing entry, or a unicast routing entry removed from the routing table, or a unicast routing entry whose contained information has been updated;

[0275] The second address determination module 702 is configured to obtain at least one second destination address from multiple first destination addresses according to the target address, where the second destination address is in the network segment corresponding to the target address, or when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address;

[0276] The first entry detection module 703 is configured to, for each second destination address, detect whether the flow specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address.

[0277] As can be seen from the above, in this application, the first entry group, the second entry group, and the third entry group corresponding to the first destination address are used to record the unicast routing entries and the flow specification entries related to the first destination address in the form of entry groups respectively. In the case of a changed target unicast entry, the second destination address can be quickly located, where the second destination address is in the network segment corresponding to the target address, or the target address is in the network segment corresponding to the second destination address. The validity of the flow specification entry with the second destination address as the destination address may be affected by the target unicast entry. And the unicast routing entries related to the flow specification entry with the second destination address as the destination address are all in the first entry group and the second entry group corresponding to the second destination address. Therefore, only the first entry group and the second entry group corresponding to the second destination address need to be used to detect the entries in the third entry group. It can be seen that when the unicast routing entry changes, adopting the solution provided by the embodiment of this application only needs to detect a part of the flow specification entries based on a part of the unicast routing entries, which can greatly reduce the number of entries to be processed during detection and improve the detection efficiency.

[0278] In an embodiment of this application, if the second destination address is in the network segment corresponding to the target address, the first entry detection module 703 is specifically configured to:

[0279] For each second destination address, update the first entry group corresponding to the second destination address based on the target unicast entry;

[0280] When the first optimal entry in the first entry group is updated, determine that the first flow specification entry corresponding to the first optimal entry is invalid. The first flow specification entry includes the second destination address and is different from the source node of the first optimal entry. The source node is another network device that initiates entry synchronization to this network device. The first optimal entry is: the entry that is determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matches the second destination address;

[0281] If any one of each first autonomous domain is different from the second autonomous domain, it is determined that the second flow specification entry is invalid. The second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the first flow specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when synchronizing each second unicast routing entry corresponding to the second destination address. The current autonomous domain is the autonomous domain where the network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when synchronizing the first optimal entry corresponding to the second destination address.

[0282] As can be seen from the above, in this embodiment, only when the first optimal entry corresponding to the first entry group is updated, the validity of the flow specification entries in the third entry group corresponding to the second destination address is re-detected. In other cases, no re-detection is performed, which can further save the number of validity detections and further save computing resources.

[0283] In an embodiment of the present application, in each first entry group corresponding to each first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The following module is used to determine whether the first optimal entry in the first entry group is updated:

[0284] The entry change determination module is configured to determine that the first optimal entry in the first entry group is updated if the unicast routing entry ranked first in the arrangement order in the first entry group is updated.

[0285] As can be seen from the above, if the first entry group is constructed using this embodiment, it is only necessary to directly determine whether the unicast routing entry at the head of the first entry group is updated to determine whether the first optimal entry is updated. The determination method is relatively simple and there is no need to traverse the first entry group to find the first optimal entry therein.

[0286] In an embodiment of the present application, if the target address is in the network segment corresponding to the second destination address when the target address is different from the second destination address, the first entry detection module 703 is specifically configured to:

[0287] For each second destination address, update the second entry group corresponding to the second destination address based on the target unicast entry;

[0288] If any one of each third autonomous domain is different from the fourth autonomous domain, it is determined that the third flow specification entry is invalid;

[0289] The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address. The third autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the second destination address passes through during synchronization. The current autonomous region is the autonomous region where the network device is located. The fourth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the second destination address passes through during synchronization. The first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the principle of the longest mask match.

[0290] As can be seen from the above, when detecting the flow specification entry in this embodiment, if the second entry group corresponding to the second destination address is updated, it is only necessary to compare the third autonomous region with the fourth autonomous region based on the first entry group and the second entry group to determine whether the invalid state of the flow specification entry in the third entry corresponding to the second destination address needs to be updated. Only a small number of unicast routing entries in the first entry group and the second entry group are involved in this process, and even the comparison of the flow specification entries in the third entry group is not involved. Therefore, less computing resources are consumed.

[0291] In an embodiment of the present application, within the second entry group corresponding to each first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier in the autonomous system path ASPATH, and the ASPATH includes the identifiers of the autonomous regions passed through during entry synchronization;

[0292] Determine whether any one of each third autonomous region is different from the fourth autonomous region through the following module:

[0293] The autonomous region determination module is used to determine that each third autonomous region is the same as the fourth autonomous region if both the first autonomous region identifier and the second autonomous region identifier are the same as the third autonomous region identifier;

[0294] Among them, the first autonomous region identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked first in the second entry group corresponding to the second destination address;

[0295] The second autonomous region identifier is: the identifier of the highest bit in the ASPATH of the unicast routing entry ranked last in the second entry group corresponding to the second destination address;

[0296] The third autonomous region identifier is: the identifier of the highest bit in the ASPATH of the first optimal entry corresponding to the second destination address.

[0297] As can be seen from the above, when constructing the second entry group using this embodiment, when detecting the validity of the flow specification entry in the third entry group, only three autonomous domain identifiers need to be compared, without traversing the entire second entry group to sequentially determine whether the third autonomous domain of all unicast routing entries in the second entry group is the same as the fourth autonomous domain, which can save more computing power.

[0298] In one embodiment of the present application, the device further includes:

[0299] An entry addition module, configured to add the newly added flow specification entry to the third entry group corresponding to the third destination address if there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the newly added flow specification entry;

[0300] An entry group construction module, configured to determine that the newly added flow specification entry is invalid if the source node of the newly added flow specification entry is different from the source node of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous domain is different from the sixth autonomous domain;

[0301] Wherein, the first optimal entry corresponding to the third destination address is: the entry determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matching the third destination address, the source node is another network device that initiates entry synchronization to this network device, the fifth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by each second unicast routing entry corresponding to the third destination address during synchronization, the current autonomous domain is the autonomous domain where this network device is located, and the sixth autonomous domain is: the last autonomous domain different from the current autonomous domain passed by the first optimal entry corresponding to the third destination address during synchronization.

[0302] As can be seen from the above, this embodiment can, in the case of a newly added flow specification entry, insert the newly added flow specification entry into the existing third entry group, or construct new first, second, and third entry groups for the newly added flow specification entry, and then detect whether the newly added flow specification entry is valid. This process only needs to use the newly added flow specification entry and the unicast routing entries in the first and second entry groups corresponding to its third destination address, without traversing the unicast routing entries for detection. Therefore, computing resources can also be saved when re-detecting the validity of the newly added flow specification entry.

[0303] In one embodiment of the present application, the device further includes:

[0304] A flow specification entry determination module, configured to determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device;

[0305] The third table entry detection module is configured to determine that the target flow specification table entry is invalid if the first optimal table entry corresponding to the fourth destination address of the target flow specification table entry is different from the source node of the target flow specification table entry, or any one of each seventh autonomous region is different from the eighth autonomous region.

[0306] Wherein, the first optimal table entry corresponding to the fourth destination address is: the table entry that is determined from the first table entry group corresponding to the fourth destination address according to the longest mask matching principle and matches the fourth destination address; the seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing table entry corresponding to the fourth destination address passes through during synchronization; the current autonomous region is the autonomous region where the network device is located; the eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal table entry corresponding to the fourth destination address passes through during synchronization.

[0307] As can be seen from the above, this embodiment can re-detect whether the target flow specification table entry is valid in the presence of the target flow specification table entry. This process only needs to use the target flow specification table entry and the unicast routing table entries in the first table entry group and the second table entry group corresponding to its fourth destination address, without traversing all unicast routing table entries. Therefore, computing resources can also be saved when re-detecting the validity of the target flow specification table entry.

[0308] In another embodiment provided by this application, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of any of the above detection methods are implemented.

[0309] In another embodiment provided by this application, a computer program product containing instructions is further provided. When it runs on a computer, the computer is caused to execute any of the detection methods in the above embodiments.

[0310] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

[0311] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device that includes a series of elements includes not only those elements but also other elements that are not explicitly listed, or also includes elements that are inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device that includes the element.

[0312] Each embodiment in this specification is described in a related manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the embodiments of network devices, apparatuses, computer-readable storage media, and computer program products, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0313] The above are only the preferred embodiments of the present application and are not intended to limit the protection scope of the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application are all included in the protection scope of the present application.

Claims

1. A detection method, characterized in that, Applied to a network device, for each first destination address, the network device stores a first entry group, a second entry group, and a third entry group corresponding to the first destination address; The first entry group includes: a first unicast routing entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing entry; The second entry group includes: a second unicast routing entry, the destination address in the second unicast routing entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing entry is different from the first destination address; The third entry group includes: a traffic specification entry with the destination address being the first destination address; The method includes: Determine a target unicast entry whose information has changed. The target unicast entry includes a target address, and the target unicast entry is a newly added unicast routing entry, or a unicast routing entry removed from the routing table, or a unicast routing entry whose contained information has been updated; According to the target address, obtain at least one second destination address from multiple first destination addresses. The second destination address is in the network segment corresponding to the target address, or when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address; For each second destination address, based on the first entry group and the second entry group corresponding to the second destination address, detect whether the traffic specification entry in the third entry group corresponding to the second destination address is invalid.

2. The method according to claim 1, wherein If the second destination address is in the network segment corresponding to the target address, the detecting whether the traffic specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address includes: Update the first entry group corresponding to the second destination address based on the target unicast entry; When the first optimal entry in the first entry group is updated, determine that the first traffic specification entry corresponding to the first optimal entry is invalid. The first traffic specification entry includes the second destination address and is different from the source node of the first optimal entry. The source node is another network device that initiates entry synchronization to the network device. The first optimal entry is: determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matching the second destination address; If any one of each first autonomous domain is different from the second autonomous domain, determine that the second traffic specification entry is invalid. The second traffic specification entry is: other traffic specification entries in the third entry group corresponding to the second destination address except the first traffic specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain passed through during the synchronization of each second unicast routing entry corresponding to the second destination address. The current autonomous domain is the autonomous domain where the network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain passed through during the synchronization of the first optimal entry corresponding to the second destination address.

3. The method according to claim 2, wherein In each first table entry group corresponding to a first destination address, based on the principle of longest mask matching, the unicast routing table entries are arranged in descending order of the matching degree with the first destination address. The following method is used to determine whether the first optimal table entry in the first table entry group is updated: If the unicast routing table entry ranked first in the first table entry group is updated, it is determined that the first optimal table entry in the first table entry group is updated.

4. The method according to claim 1, characterized in that, If the target address is in the network segment corresponding to the second destination address when the target address is different from the second destination address, based on the first table entry group and the second table entry group corresponding to the second destination address, it is detected whether the flow specification table entry in the third table entry group corresponding to the second destination address is invalid, including: Updating the second table entry group corresponding to the second destination address based on the target unicast table entry; If any one of each third autonomous domain is different from the fourth autonomous domain, it is determined that the third flow specification table entry is invalid; The third flow specification table entry is: the flow specification table entry in the third table entry group corresponding to the second destination address. The third autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when each second unicast routing table entry corresponding to the second destination address is synchronized. The current autonomous domain is the autonomous domain where the network device is located. The fourth autonomous domain is: the last autonomous domain different from the current autonomous domain passed through when the first optimal table entry corresponding to the second destination address is synchronized. The first optimal table entry is: the table entry matching the second destination address determined from the first table entry group corresponding to the second destination address according to the principle of longest mask matching.

5. The method according to claim 4, characterized in that, Within each second table entry group corresponding to a first destination address, the unicast routing table entries are arranged in ascending or descending order of the value of the highest bit identifier within the autonomous system path (ASPATH). The ASPATH contains the identifiers of the autonomous domains passed through during table entry synchronization. The following method is used to determine whether any one of each third autonomous domain is different from the fourth autonomous domain: If the first autonomous domain identifier and the second autonomous domain identifier are both the same as the third autonomous domain identifier, it is determined that each third autonomous domain is the same as the fourth autonomous domain; Among them, the first autonomous domain identifier is: the highest bit identifier within the ASPATH of the unicast routing table entry ranked first in the second table entry group corresponding to the second destination address; The second autonomous domain identifier is: the highest bit identifier within the ASPATH of the unicast routing table entry ranked last in the second table entry group corresponding to the second destination address; The third autonomous domain identifier is: the highest bit identifier within the ASPATH of the first optimal table entry corresponding to the second destination address.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: If there are a first table entry group, a second table entry group, and a third table entry group corresponding to a third destination address with a newly added flow specification table entry, the newly added flow specification table entry is added to the third table entry group corresponding to the third destination address; If there are no first table entry group, second table entry group, and third table entry group corresponding to the third destination address, create the first table entry group, second table entry group, and third table entry group corresponding to the third destination address; If the source node of the newly added flow specification entry is different from that of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous region is different from the sixth autonomous region, it is determined that the newly added flow specification entry is invalid; Among them, the first optimal entry corresponding to the third destination address is: the entry that is determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matches the third destination address. The source node is another network device that initiates entry synchronization to this network device. The fifth autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the third destination address passes through during synchronization. The current autonomous region is the autonomous region where this network device is located. The sixth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the third destination address passes through during synchronization.

7. The method according to any one of claims 1-5, characterized in that The method further includes: Determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device; If the first optimal entry corresponding to the fourth destination address of the target flow specification entry is different from the source node of the target flow specification entry, or if any one of each seventh autonomous region is different from the eighth autonomous region, it is determined that the target flow specification entry is invalid; Among them, the first optimal entry corresponding to the fourth destination address is: the entry that is determined from the first entry group corresponding to the fourth destination address according to the longest mask matching principle and matches the fourth destination address. The seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the fourth destination address passes through during synchronization. The current autonomous region is the autonomous region where this network device is located. The eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the fourth destination address passes through during synchronization.

8. A detection device, characterized in that, Applied to a network device, the network device stores a first entry group, a second entry group, and a third entry group corresponding to each first destination address; The first entry group includes: a first unicast routing entry, and the first destination address is in the network segment corresponding to the destination address in the first unicast routing entry; The second entry group includes: a second unicast routing entry, the destination address in the second unicast routing entry is in the network segment corresponding to the first destination address, and the destination address of the second unicast routing entry is different from the first destination address; The third entry group includes: a flow specification entry with the destination address being the first destination address; The device includes: A unicast entry determination module, configured to determine a target unicast entry that has changed. The destination address in the target unicast entry is the target address. The target unicast entry is a newly added unicast routing entry, or a unicast routing entry removed from the routing table, or a unicast routing entry whose contained information has been updated; A second address determination module, configured to obtain at least one second destination address from multiple first destination addresses according to the target address, where the second destination address is in the network segment corresponding to the target address, or when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address; A first entry detection module, configured to, for each second destination address, detect whether the flow specification entry in the third entry group corresponding to the second destination address is invalid based on the first entry group and the second entry group corresponding to the second destination address.

9. The device according to claim 8, characterized in that, If the second destination address is in the network segment corresponding to the target address, the first entry detection module is specifically configured to: For each second destination address, update the first entry group corresponding to the second destination address based on the target unicast entry; When the first optimal entry in the first entry group is updated, determine that the first flow specification entry corresponding to the first optimal entry is invalid. The first flow specification entry includes the second destination address and is different from the source node of the first optimal entry. The source node is another network device that initiates entry synchronization to this network device. The first optimal entry is: the entry that is determined from the first entry group corresponding to the second destination address according to the longest mask matching principle and matches the second destination address; If any one of each first autonomous domain is different from the second autonomous domain, determine that the second flow specification entry is invalid. The second flow specification entry is: other flow specification entries in the third entry group corresponding to the second destination address except the first flow specification entry. The first autonomous domain is: the last autonomous domain different from the current autonomous domain that each second unicast routing entry corresponding to the second destination address passes through during synchronization. The current autonomous domain is the autonomous domain where this network device is located. The second autonomous domain is: the last autonomous domain different from the current autonomous domain that the first optimal entry corresponding to the second destination address passes through during synchronization.

10. The device according to claim 9, characterized in that In each first entry group corresponding to each first destination address, based on the longest mask matching principle, the unicast routing entries are arranged in descending order of the matching degree with the first destination address. The following module is used to determine whether the first optimal entry in the first entry group is updated: An entry change determination module, configured to, if the unicast routing entry ranked first in the first entry group is updated, determine that the first optimal entry in the first entry group is updated.

11. The device according to claim 8, wherein If, when the target address is different from the second destination address, the target address is in the network segment corresponding to the second destination address, the first entry detection module is specifically configured to: For each second destination address, update the second entry group corresponding to the second destination address based on the target unicast entry; If any one of each third autonomous domain is different from the fourth autonomous domain, determine that the third flow specification entry is invalid; The third flow specification entry is: the flow specification entry in the third entry group corresponding to the second destination address. The third autonomous system is: the last autonomous system different from the current autonomous system that each second unicast routing entry corresponding to the second destination address passes through during synchronization. The current autonomous system is the autonomous system where the network device is located. The fourth autonomous system is: the last autonomous system different from the current autonomous system that the first optimal entry corresponding to the second destination address passes through during synchronization. The first optimal entry is: the entry matching the second destination address determined from the first entry group corresponding to the second destination address according to the longest mask matching principle.

12. The device according to claim 11, wherein Within each second entry group corresponding to a first destination address, the unicast routing entries are arranged in ascending or descending order according to the value of the highest bit identifier within the autonomous system path ASPATH. The ASPATH contains the identifiers of the autonomous systems passed through during entry synchronization. Determine whether any one of each third autonomous system is different from the fourth autonomous system through the following module: An autonomous system determination module, configured to determine that each third autonomous system is the same as the fourth autonomous system if both the first autonomous system identifier and the second autonomous system identifier are the same as the third autonomous system identifier. Among them, the first autonomous system identifier is: the highest bit identifier within the ASPATH in the unicast routing entry ranked first in the second entry group corresponding to the second destination address. The second autonomous system identifier is: the highest bit identifier within the ASPATH in the unicast routing entry ranked last in the second entry group corresponding to the second destination address. The third autonomous system identifier is: the highest bit identifier within the ASPATH in the first optimal entry corresponding to the second destination address.

13. The device according to any one of claims 8 - 12, characterized in that The device further includes: An entry addition module, configured to add the new flow specification entry to the third entry group corresponding to the third destination address if there are a first entry group, a second entry group, and a third entry group corresponding to the third destination address of the new flow specification entry. An entry group construction module, configured to create a first entry group, a second entry group, and a third entry group corresponding to the third destination address if there are no first entry group, second entry group, and third entry group corresponding to the third destination address. A second entry detection module, configured to determine that the new flow specification entry is invalid if the source node of the new flow specification entry is different from that of the first optimal entry corresponding to the third destination address, or if any one of each fifth autonomous system is different from the sixth autonomous system. Among them, the first optimal entry corresponding to the third destination address is: the entry that is determined from the first entry group corresponding to the third destination address according to the longest mask matching principle and matches the third destination address. The source node is another network device that initiates entry synchronization to this network device. The fifth autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the third destination address passes through during synchronization. The current autonomous region is the autonomous region where this network device is located. The sixth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the third destination address passes through during synchronization.

14. The device according to any one of claims 8-12, characterized in that, The device further includes: A flow specification entry determination module, configured to determine a target flow specification entry, where the field indicating the source node in the target flow specification entry is updated, and the source node is another network device that initiates entry synchronization to this network device; A third entry detection module, configured to determine that the target flow specification entry is invalid if the first optimal entry corresponding to the fourth destination address of the target flow specification entry is different from the source node of the target flow specification entry, or any one of each seventh autonomous region is different from the eighth autonomous region; Among them, the first optimal entry corresponding to the fourth destination address is: the entry that is determined from the first entry group corresponding to the fourth destination address according to the longest mask matching principle and matches the fourth destination address. The seventh autonomous region is: the last autonomous region different from the current autonomous region that each second unicast routing entry corresponding to the fourth destination address passes through during synchronization. The current autonomous region is the autonomous region where this network device is located. The eighth autonomous region is: the last autonomous region different from the current autonomous region that the first optimal entry corresponding to the fourth destination address passes through during synchronization.

Citation Information

Patent Citations

  • Path selection method and device

    CN115277536A

  • Extending border gateway protocol (BGP) FlowSpec initiation authorization using path attribute

    CN117426071A

  • Transmission control method and apparatus for vxlan packet, and device and storage medium

    WO2025001904A1