Hierarchical session management method and device based on FPGA

By adopting a hierarchical session management method on FPGA, using Bloom filters and different types of memory, dynamically adjusting the hash length, solving the efficiency and latency problems of traditional hash tables in high concurrency scenarios, and achieving low-latency and efficient session query and storage management.

CN120281710AActive Publication Date: 2025-07-08HANGZHOU XINQI ELECTRONIC TECH CO LTD

Patent Information

Application Number
CN202510772037.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-08
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

Traditional hash tables are difficult to effectively manage tens of millions or even billions of sessions in high concurrency scenarios, resulting in large fluctuations in query delays and high memory usage. Especially in high concurrency scenarios, the hash table conflicts frequently, which increases the uncertainty of query time and hardware resource consumption.

Method used

Using a hierarchical session management method based on FPGA, the Bloom filter is used to match ACL rules, combining block random access memory BRAM, high bandwidth memory HBM and dual-rate synchronous dynamic random memory DDR, the hash length is dynamically adjusted according to the session life cycle type, and the session is stored in different memory, including short session storage to BRAM, medium session storage to HBM, and long session storage to DDR.

Benefits of technology

It significantly reduces redundant memory access, improves query efficiency and system performance, reduces system latency and memory usage, improves resource utilization, and can meet the real-time requirements of high-performance network equipment and data centers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281710A_ABST
    Figure CN120281710A_ABST
Patent Text Reader

Abstract

The invention discloses an FPGA-based hierarchical session management method. The method comprises the steps of obtaining quintuple information in a to-be-processed message; determining a plurality of first hash values corresponding to the quintuple information, and performing ACL rule matching on the plurality of first hash values based on a Bloom filter; determining a session lifecycle type based on the protocol type; if the session is a short session, selecting low X bits from the second hash value as a first storage address, and storing the quintuple information and the second hash value into the BRAM; if the session is a middle session, selecting low Y bits from the second hash value as a second storage address, and storing the quintuple information and the second hash value into the HBM; and if the session is a long session, selecting low Z bits from the second hash value as a third storage address, and storing the quintuple information and the second hash value into the DDR. According to the invention, low-delay and high-efficiency session query and storage management can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of session management, and in particular, to a hierarchical session management method and device based on FPGA. Background Art

[0002] In traditional network systems, session management usually uses hash tables to achieve fast lookup. However, with the explosive growth of network traffic, the management of tens of millions or even hundreds of millions of sessions has become the norm, which leads to problems such as large fluctuations in query latency and high memory occupancy in the traditional hash table lookup scheme. Especially in high-concurrency scenarios, hash table conflicts are frequent, which not only increases the uncertainty of query time but also increases the consumption of hardware resources. Summary of the Invention

[0003] The purpose of this application is to provide a hierarchical session management method based on FPGA, which can achieve low-latency and high-efficiency session query and storage management.

[0004] In a first aspect, this application provides a hierarchical session management method based on FPGA. The FPGA includes a block random access memory BRAM, a high-bandwidth memory HBM, and a double data rate synchronous dynamic random access memory DDR. The method includes: Obtain the five-tuple information in the packet to be processed; Determine multiple first hash values corresponding to the five-tuple information, and match the access control list ACL rules based on the multiple first hash values using a Bloom filter; In response to the five-tuple information hitting the ACL rules, determine the session life cycle type of the packet to be processed based on the protocol type in the five-tuple information, and use any one of the multiple first hash values as the second hash value; If the session life cycle type is a short session, select the lower X bits from the second hash value as the first storage address, and store the five-tuple information and the second hash value in the first storage space corresponding to the first storage address in the BRAM; If the session life cycle type is a medium session, select the lower Y bits from the second hash value as the second storage address, and store the five-tuple information and the second hash value in the second storage space corresponding to the second storage address in the HBM; If the session life cycle type is a long session, select the lower Z bits from the second hash value as the third storage address, and store the five-tuple information and the second hash value in the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

[0005] Optionally, determining multiple first hash values corresponding to the five-tuple information and matching the access control list ACL rules based on the multiple first hash values using a Bloom filter includes: Performing hash operations on the quintuple information respectively using k different hash functions to obtain k first hash values; Based on the k first hash values, in multiple fourth storage spaces of the Bloom filter, querying the fourth storage spaces that match each of the k first hash values, and obtaining the bitmap index values in each of the matching fourth storage spaces, where the Bloom filter is configured to: for each ACL rule, performing calculations using k different hash functions to obtain corresponding k hash arrays, and configuring the bitmap index values in the fourth storage spaces corresponding to the k hash arrays to 1; If all the bitmap index values are 1, determining that the quintuple information hits the ACL rule; otherwise, discarding the quintuple information.

[0006] Optionally, the method further includes: Obtaining session information in the to-be-processed packet, where the session information includes quintuple information, session type, creation time, packet statistics value, byte statistics value, and source port, and the creation time is the time when the to-be-processed packet is first received; If the session lifecycle type is a short session, selecting the lower X bit positions from the second hash value as the first storage address, and storing the session information, the second hash value, and the first timestamp information corresponding to the storage time of the session information into the first storage space corresponding to the first storage address in the BRAM; If the session lifecycle type is a medium session, selecting the lower Y bit positions from the second hash value as the second storage address, and storing the session information, the second hash value, and the second timestamp information corresponding to the storage time of the session information into the second storage space corresponding to the second storage address in the HBM; If the session lifecycle type is a long session, selecting the lower Z bit positions from the second hash value as the third storage address, and storing the session information, the second hash value, and the third timestamp information corresponding to the storage time of the session information into the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

[0007] Optionally, the method further includes: Obtaining the session activity of each session information in the BRAM, judging whether the session information is in an inactive state based on the session activity, and migrating the session information in the inactive state to the HBM; Obtaining the session activity of each session information in the HBM, judging whether the session information is in an inactive state based on the session activity, and migrating the session information in the inactive state to the DDR; Obtaining the session activity of each session information in the DDR, judging whether the session information is in an inactive state based on the session activity, and performing an aging operation on the session information in the inactive state.

[0008] Optionally, obtain the session activity of each session information in the BRAM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the HBM, including: For each first storage address in the BRAM, obtain each first timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the first timestamp information and the time point of the current polling; If the session activity is not greater than M times the preset polling period, the session information, the second hash value, and the first timestamp information corresponding to the first storage address remain unchanged; If the session activity is greater than M times the preset polling period, obtain the second hash value corresponding to the first storage address, select the lower Y bits from the second hash value as the new second storage address, store the session information, the second hash value, and the first timestamp information corresponding to the first storage address in the second storage space corresponding to the new second storage address in the HBM, and release the first storage address.

[0009] Optionally, obtain the session activity of each session information in the HBM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the DDR, including: For each second storage address in the HBM, obtain each second timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the second timestamp information and the time point of the current polling; If the session activity is not greater than N times the preset polling period, the session information, the second hash value, and the second timestamp information corresponding to the second storage address remain unchanged; If the session activity is greater than N times the preset polling period, obtain the second hash value corresponding to the second storage address, select the lower Z bits from the second hash value as the new third storage address, store the session information, the second hash value, and the second timestamp information corresponding to the second storage address in the third storage space corresponding to the new third storage address in the DDR, and release the second storage address.

[0010] Optionally, obtain the session activity of each session information in the DDR, determine whether the session information is in an inactive state based on the session activity, and perform an aging operation on the session information in the inactive state, including: For each third storage address in the DDR, obtain each third timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the third timestamp information and the time point of the current polling; If the session activity is not greater than P times the preset polling period, the session information, the second hash address, and the third timestamp information corresponding to the third storage address remain unchanged; If the session activity is greater than P times the preset polling period, age the session information, the second hash value, and the third timestamp information corresponding to the third storage address.

[0011] Optionally, the method further includes: For each first storage address in the BRAM, determine the corresponding session survival time based on the difference between the corresponding creation time and the current polling time point. If the session survival time exceeds the first time threshold, when receiving a pending packet with the same five-tuple information as the corresponding one next time, select the lower Y bits from the corresponding second hash value as the second storage address, and store the session information, the second hash value, and the second timestamp information corresponding to the session information storage in the second storage space corresponding to the second storage address in the HBM; For each second storage address in the HBM, determine the corresponding session survival time based on the difference between the corresponding creation time and the current polling time point. If the session survival time exceeds the second time threshold, when receiving a pending packet with the same five-tuple information as the corresponding one next time, select the lower Z bits from the corresponding second hash value as the third storage address, and store the session information, the second hash value, and the third timestamp information corresponding to the session information storage in the third storage space corresponding to the third storage address in the DDR.

[0012] In a second aspect, the present application provides a hierarchical session management method device based on an FPGA. The device includes: An acquisition module, configured to acquire five-tuple information in a pending packet; A Bloom filter, configured to determine multiple first hash values corresponding to the five-tuple information, perform matching of access control list (ACL) rules based on the Bloom filter for the multiple first hash values, and in response to the five-tuple information hitting the ACL rule, determine the session life cycle type of the pending packet based on the protocol type in the five-tuple information, and use any one of the multiple first hash values as the second hash value; A block random access memory (BRAM), configured to, if the session life cycle type is a short session, select the lower X bits from the second hash value as the first storage address, and store the five-tuple information and the second hash value in the first storage space corresponding to the first storage address in the BRAM; A high bandwidth memory (HBM), configured to, if the session life cycle type is a medium session, select the lower Y bits from the second hash value as the second storage address, and store the five-tuple information and the second hash value in the second storage space corresponding to the second storage address in the HBM; Dual-rate synchronous dynamic random access memory DDR, which is used to select the lower Z bit positions from the second hash value as the third storage address if the session life cycle type is a long session, and store the five-tuple information and the second hash value into the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

[0013] In a third aspect, the present application provides a communication device, including the FPGA-based hierarchical session management device as described above.

[0014] The present application performs ACL rule matching on the five-tuple information in the received packet through a Bloom filter, which can filter out most of the invalid queries in advance, greatly reducing the query pressure on the subsequent hierarchical compression hash architecture, improving the query efficiency of the entire hash architecture, and reducing the overall latency of the system; according to the different session life cycle types, dynamically adjust and compress the length of the hash value, and use the adjusted hash value as the storage address of different memories, reducing redundant memory access and further improving the performance of the system; according to the different session life cycle types, store the session into different memories, and by adopting a hierarchical hash architecture, effectively reduce the memory occupation and unnecessary memory access, and can achieve more efficient query and storage management, greatly improving the response speed and processing capacity of the system, improving the resource utilization rate, and reducing the system operation cost; the hierarchical hash architecture is flexibly designed and has scalability, and can better adapt to the needs of future network development. Description of the Drawings

[0015] Figure 1 It is the first flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 2 It is the second flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 3 It is the third flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 4 It is the fourth flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 5 It is the fifth flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 6 It is the sixth flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 7 It is the seventh flow chart of the FPGA-based hierarchical session management method provided by the embodiment of the present application; Figure 8System block diagram of the FPGA-based hierarchical session management device provided by the embodiment of the present application; Figure 9 System block diagram of the communication device provided by the embodiment of the present application. Detailed implementation manners

[0016] The present application will be described in detail below in conjunction with the specific implementation manners shown in the drawings. However, these implementation manners do not limit the present application, and any structural, method, or functional transformation made by those of ordinary skill in the art according to these implementation manners is included in the protection scope of the present application.

[0017] Please refer to Figure 1 , the embodiment of the present application provides a hierarchical session management method based on FPGA. The FPGA includes a block random access memory BRAM (Block RAM), a high bandwidth memory HBM (High Bandwidth Memory), and a double data rate synchronous dynamic random access memory DDR (Double Data Rate Generation Synchronous Dynamic Random Access Memory). The method includes steps S101-S106.

[0018] S101, obtain the five-tuple information in the to-be-processed packet.

[0019] Receive the to-be-processed packet, parse the to-be-processed packet, and obtain the five-tuple information and session type in the to-be-processed packet. The five-tuple information includes the source IP address, destination IP address, source port, destination port, and protocol type. The five-tuple information is used to uniquely identify a session. In network communication, a session refers to a communication connection established between two or more network devices. These sessions can be TCP connections, user login sessions, network service sessions, etc. The embodiment of the present application does not limit this.

[0020] S102, determine multiple first hash values corresponding to the five-tuple information, and match the access control list ACL rules for the multiple first hash values based on the Bloom filter.

[0021] Perform hash operations on the five-tuple information using different hash functions to obtain the corresponding multiple first hash values.

[0022] The Bloom Filter is an efficient data structure commonly used to determine whether an element is in a set. According to multiple obtained first hash values, a query is performed in the Bloom Filter to obtain the Access Control List (ACL) rules that match the multiple first hash values. The access control list technology is widely adopted in modern network devices (routers, switches). Network devices such as routers often use ACLs to control the reception or rejection of data packets. The principle of ACL is mainly to set a series of rules, which include the rule content that can match the packet and the operations to be performed on the packet after successful matching. For example, each ACL is composed of a series of rules, and each rule is composed of a matching item and an action. Source IP address, destination IP address, source port number, destination port number, protocol number, etc. can all be matching items in the ACL rules. The action determines the processing of the matching packet, such as allowing or rejecting. Allowing means forwarding or processing the packet, and rejecting means discarding the packet.

[0023] In this embodiment, the Bloom Filter is used to implement the ACL rule matching for the five-tuple information of the packet, to determine whether the received five-tuple information hits the ACL rule. If it does not hit, the packet is discarded; if it hits, the packet is processed subsequently. By adopting the Bloom Filter mechanism for the five-tuple information in the received packet, a large number of invalid queries are directly filtered out without entering the subsequent hash structure search process, thus significantly reducing 75% of the redundant memory access, greatly reducing the query pressure on the subsequent hierarchical compression hash architecture, especially reducing the redundant access to the relatively slow HBM and DDR4 memories.

[0024] S103, in response to the five-tuple information hitting the ACL rule, determine the session life cycle type of the packet to be processed based on the protocol type in the five-tuple information, and use any one of the multiple first hash values as the second hash value.

[0025] When it is determined that the five-tuple information hits the ACL rule, determine the session life cycle type according to the protocol type in the five-tuple information of the packet, and use any one of the multiple first hash values as the second hash value.

[0026] Determine the session lifecycle type according to the protocol type in the five-tuple information in the message. Exemplarily, if the protocol type is TCP long connection, UDP, WebSocket, VPN, SSH, etc., determine the session lifecycle type as a long session. A long session generally has characteristics such as a long session duration, frequent and stable data interaction, for example, the session duration is greater than 1 minute. For example, video streaming, long-term game connections, etc. If the protocol type is DNS, ICMP, DHCP, etc., determine the session lifecycle type as a short session. A short session generally has characteristics such as a short session duration and less data interaction, for example, the session duration is less than 2 seconds. For example, IoT probe packets, DNS queries, etc. If the protocol type is HTTP short connection, QUIC, SMTP, short connection in MQTT, etc., determine the session lifecycle type as a medium session. A medium session has characteristics such as a moderate session duration and may have multiple rounds of interactive data. Determine the session lifecycle type as a medium session, for example, the session duration is about 2 seconds to 1 minute, for example, a mobile APP quickly accesses and exits, requests from WeChat and Alipay Apps, periodic heartbeat sending of IoT devices, etc.

[0027] S104, if the session lifecycle type is a short session, select the lower X bit positions from the second hash value as the first storage address, and store the five-tuple information and the second hash value into the first storage space corresponding to the first storage address in the BRAM.

[0028] During the session management process, dynamically adjust the length of the hash value according to the lifecycle of the session. For a short session, it is usually some temporary network connections, such as a short HTTP request session during web browsing. Since the duration of such a session is short and the data volume is relatively small, a hash value with a shorter length can be used as the storage address to meet the identification requirements of the five-tuple information.

[0029] Therefore, if the session lifecycle type is a short session, select the lower X bit positions from the second hash value as the first storage address of the BRAM, and store the five-tuple information and the second hash value into the first storage space corresponding to the first storage address in the BRAM. The on-chip BRAM of the FPGA has the advantage of extremely fast access speed, and the access latency is usually less than 10μs, but its storage capacity is limited, generally designed with 1K - 4K number of entries. Therefore, the BRAM can store active sessions or frequently accessed session data. For example, in a network device, the sessions currently in data transmission or the sessions that frequently initiate requests within a short period of time, the data of these sessions are stored in the BRAM, which can ensure fast access and meet the application scenarios with high real-time requirements.

[0030] S105, if the session lifecycle type is a medium session, select the lower Y bits from the second hash value as the second storage address, and store the quintuple information and the second hash value in the second storage space corresponding to the second storage address in the HBM.

[0031] For medium sessions, the session data is not particularly active. A hash value with a longer length can be used as the storage address to meet the identification requirements of the quintuple information. Therefore, if the session lifecycle type is a medium session, select the lower Y bits from the second hash value as the second storage address of the HBM, and store the quintuple information and the second hash value in the second storage space corresponding to the second storage address in the HBM.

[0032] The on-chip HBM of the FPGA has a relatively fast access speed and a storage capacity larger than that of the BRAM, usually designed with 1M - 32M entries. Compared with the BRAM, its access latency is slightly longer, but it can still meet the requirements of most high-performance scenarios. Therefore, the HBM can store inactive session data that may be accessed in the future.

[0033] S106, if the session lifecycle type is a long session, select the lower Z bits from the second hash value as the third storage address, and store the quintuple information and the second hash value in the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

[0034] For long sessions, such as long-term online game sessions or continuous data transfer sessions, since these sessions have a long duration and a large amount of data, a hash value with an even longer length can be used as the storage address to meet the identification requirements of the quintuple information. Therefore, if the session lifecycle type is a long session, select the lower Z bits from the second hash value as the third storage address of the DDR, and store the quintuple information and the second hash value in the third storage space corresponding to the third storage address in the DDR.

[0035] The DDR memory has a large storage capacity, usually designed with 64M - 1G entries (specifically depending on the number of external DDRs and the capacity of each DDR), but its access speed is relatively slow. Therefore, the DDR can store session data that is long-term inactive or rarely accessed.

[0036] In this embodiment, the five-tuple information in the received packet is matched with the ACL rules through the Bloom filter, which can filter out most of the invalid queries in advance, significantly reduce 75% of the redundant memory access, greatly relieve the query pressure on the subsequent hierarchical compression hash architecture, especially reduce the redundant access to the relatively slow HBM and DDR4 memories, improve the query efficiency of the entire hash architecture, and reduce the overall latency of the system; according to the different types of session life cycles, the length of the hash value is dynamically adjusted and compressed, and the adjusted hash value is used as the storage address of different memories, reducing the redundant memory access and further improving the performance of the system; according to the different types of session life cycles, the sessions are stored in different memories. By adopting a hierarchical hash architecture, the memory occupancy and unnecessary memory access are effectively reduced. Based on the parallel computing ability of the FPGA, more efficient query and storage management can be achieved, greatly improving the response speed and processing ability of the system, increasing the resource utilization rate, and reducing the system operation cost; it can comprehensively consider the access speed and storage capacity of the network, and is suitable for scenarios with extremely high requirements for session management performance such as high-performance network devices and data centers; the hierarchical hash architecture is flexible in design and has scalability. By increasing hash functions, expanding the capacity of the hash table, etc., the system performance can be improved and the function can be extended, and it can better meet the needs of future network development. This embodiment has been actually tested on the Xilinx FPGA platform. The test results show that the single-session query latency is stable within 15 nanoseconds. Compared with the traditional hash table, the query latency is greatly reduced, which can meet the strict requirements for real-time performance of high-performance network devices and data centers. The system can support up to 120 million query operations per second, significantly improving the throughput of session management and effectively coping with the scenario of large-scale session concurrent queries.

[0037] One embodiment of the present application is as Figure 2 shown. Determine a plurality of first hash values corresponding to the five-tuple information, and perform matching of access control list ACL rules on the plurality of first hash values based on the Bloom filter, including steps S201-S203.

[0038] S201, perform hash operations on the five-tuple information respectively using k different hash functions to obtain k first hash values; S202, based on the k first hash values, query, in a plurality of fourth storage spaces of the Bloom filter, the fourth storage space that matches each of the k first hash values, and obtain the bitmap index value in each matching fourth storage space. Wherein, the Bloom filter is configured to: for each ACL rule, calculate using k different hash functions to obtain the corresponding k hash arrays, and configure the bitmap index value in the fourth storage space corresponding to the k hash arrays to 1; S203. If all bitmap index values are 1, it is determined that the five-tuple information hits the ACL rule; otherwise, the five-tuple information is discarded.

[0039] According to actual requirements, multiple ACL rules can be set in advance. Each ACL rule includes configured five-tuple information. For each ACL rule, k different hash functions are used for calculation, that is, for each configured five-tuple information, k different hash functions are used for calculation to obtain the corresponding k hash arrays, and the bitmap index values in the fourth storage space corresponding to the k hash arrays are configured as 1. Exemplarily, k is taken as 3, and three different hash functions are used for calculation to obtain the corresponding 3 hash values.

[0040] Exemplarily, the Bloom filter has multiple fourth storage spaces, and each storage space can store 1-bit bitmap index values. Thus, it can be known that the total storage capacity of the Bloom filter is relatively low, only occupying a small amount of storage resources of the FPGA and not affecting the data processing efficiency of the FPGA.

[0041] Use k different hash functions to perform hash operations on the five-tuple information respectively to obtain k first hash values. In the multiple fourth storage spaces of the Bloom filter, the k first hash values are used as the k read addresses of the Bloom filter to read the bitmap index values stored in the corresponding fourth storage spaces. If the k read bitmap index values are all 1, it is determined that the five-tuple information hits the ACL rule, and the packet hits the matching rule, and subsequent packet processing is continued; otherwise, the five-tuple information is discarded, that is, the packet is discarded.

[0042] In this embodiment, through a large number of experiments, it is verified that the Bloom filter mechanism can filter out 98.7% of non-hit queries. Therefore, in the actual query process, a large number of invalid queries are directly filtered out, thereby significantly reducing 75% of redundant memory accesses, greatly reducing the query pressure on the subsequent hierarchical hash architecture, especially reducing the redundant access to the relatively slow HBM and DDR4 memories. For example, when processing millions of query requests per second, the Bloom filter can filter out most of the invalid queries in advance, enabling BRAM, HBM, and DDR4 to focus on processing the truly hit query requests, improving the query efficiency of the entire hash architecture and reducing the overall latency of the system. By designing multiple hash functions, the session identifier (five-tuple information) can be mapped to different levels of hash structures. For example, hash functions such as MD5 and SHA-1 can be used.

[0043] An embodiment of the present application, as Figure 3 shown, the method further includes steps S301 - S304.

[0044] S301. Obtain the session information in the message to be processed. The session information includes five-tuple information, session type, creation time, packet statistics value, byte statistics value, and source port, where the creation time is the time when the message to be processed is first received. S302. If the session life cycle type is a short session, select the lower X bit positions from the second hash value as the first storage address, and store the session information, the second hash value, and the first timestamp information corresponding to the time when the session information is stored into the first storage space corresponding to the first storage address in the BRAM. S303. If the session life cycle type is a medium session, select the lower Y bit positions from the second hash value as the second storage address, and store the session information, the second hash value, and the second timestamp information corresponding to the time when the session information is stored into the second storage space corresponding to the second storage address in the HBM. S304. If the session life cycle type is a long session, select the lower Z bit positions from the second hash value as the third storage address, and store the session information, the second hash value, and the third timestamp information corresponding to the time when the session information is stored into the third storage space corresponding to the third storage address in the DDR.

[0045] Exemplarily, when the message to be processed is received for the first time, record the time when the message is received as the creation time of the session, and obtain the session information in the message to be processed. The session information includes five-tuple information, session type, creation time, packet statistics value, byte statistics value, and source port. If the session life cycle type is a short session, select the lower X bit positions from the second hash value as the first storage address, and store the session information, the second hash value, and the first timestamp information corresponding to the time when the session information is stored into the first storage space corresponding to the first storage address in the BRAM. When the same message to be processed is received for the second time, obtain the session information in the message to be processed. Based on the same processing method above, since the five-tuple information of the message to be processed is the same, the first storage address in the BRAM is the same. Therefore, the information stored last time in the first storage address is overwritten, that is, store the session information, the second hash value, and the first timestamp information corresponding to the time when the session information in the second received message is stored into the first storage space corresponding to the first storage address in the BRAM. The first timestamp information at this time is the time when the session information in the second received message is stored. Therefore, when a new message is received, the first timestamp information is refreshed. The processing methods for the medium session and the long session described below are similar and will not be elaborated here.

[0046] Exemplarily, X takes the value of 12. If the session life cycle type is a short session, the first 12 bits are selected from the second hash value as the first storage address of the BRAM, that is, the first storage address is the 12-bit second hash value. The session information, the second hash value, and the first timestamp information corresponding to the storage time of the session information are stored in the first storage space corresponding to the first storage address in the BRAM. The first timestamp information is the storage time when the session information is written into the BRAM.

[0047] Exemplarily, Y takes the value of 16. If the session life cycle type is a medium session, the first 16 bits are selected from the second hash value as the second storage address of the HBM, that is, the second storage address is the 16-bit second hash value. The session information, the second hash value, and the second timestamp information corresponding to the storage time of the session information are stored in the second storage space corresponding to the second storage address in the HBM. The second timestamp information is the storage time when the session information is written into the HBM.

[0048] Exemplarily, Z takes the value of 24. If the session life cycle type is a long session, the first 24 bits are selected from the second hash value as the second storage address, that is, the third storage address is the 24-bit second hash value. The session information, the second hash value, and the third timestamp information corresponding to the storage time of the session information are stored in the third storage space corresponding to the third storage address in the DDR. The third timestamp information is the storage time when the session information is written into the DDR.

[0049] In this embodiment, the length of the hash value is dynamically adjusted based on the session cycle type. Compared with the traditional fixed-length encoding (such as uniformly using 32 bits), when storing the same number of session data, about 22% of the storage space is saved. This method not only reduces the storage cost, but also reduces the memory read and write overhead, further improving the system performance. At the same time, due to reducing the redundant memory access, the demand for memory bandwidth is reduced, thereby reducing the hardware cost.

[0050] An embodiment of the present application, as Figure 4 shown, the method further includes steps S401 - S403.

[0051] S401, obtain the session activity of each session information in the BRAM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the HBM; S402, obtain the session activity of each session information in the HBM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the DDR; S403, obtain the session activity of each session information in the DDR, determine whether the session information is in an inactive state based on the session activity, and perform an aging operation on the session information in the inactive state.

[0052] In this embodiment, for each session information in BRAM, HBM, and DDR, the session activity of the session information is obtained. Based on the session activities of each session information, the position of the session information in different hash storage architectures is dynamically adjusted. For example, active sessions (such as recently accessed or frequently accessed sessions) are migrated to a faster storage level (such as BRAM), and inactive sessions are migrated to a slower storage level (such as HBM or DDR4) to balance the access speed and storage capacity of the sessions. When the session activity of the session information changes, the migration operation of the session information is automatically triggered and dynamically adjusted according to the load conditions of each level of hash structure to ensure that the session data is always stored in the most suitable storage level.

[0053] A specific embodiment of the present application, such as Figure 5 shown, obtains the session activity of each session information in BRAM, determines whether the session information is in an inactive state based on the session activity, and migrates the session information in the inactive state to HBM, including steps S501 - S504.

[0054] S501, for each first storage address in BRAM, obtains each first timestamp information corresponding to the current polling period, and determines the session activity of the corresponding session information based on the difference between the first timestamp information and the time point of the current polling; S502, if the session activity is not greater than M times the preset polling period, the session information, the second hash value, and the first timestamp information corresponding to the first storage address remain unchanged; S503, if the session activity is greater than M times the preset polling period, obtains the second hash value corresponding to the first storage address, selects the lower Y bit positions from the second hash value as the new second storage address, stores the session information, the second hash value, and the first timestamp information corresponding to the first storage address in the second storage space corresponding to the new second storage address in HBM, and releases the first storage address.

[0055] For the session information in each first storage address in BRAM, the session activity of the session information is obtained. A polling period is preset. For example, the polling period can be set to 0.1 ms or 0.2 ms, etc., and the user can set it according to the actual situation. The system performs regular polling on BRAM based on this polling period, that is, regularly reads the first timestamp information in each first storage address in BRAM. Based on the above description, it can be known that the first timestamp information is continuously refreshed. Therefore, the session activity of the corresponding session information is determined based on the difference between the first timestamp information obtained by each polling and the time point of the current polling to determine whether the session information is in an active state.

[0056] Exemplarily, M is set to 2. If the session activity is not greater than 2 times the preset polling period, it is determined that the session information is in an active state, and the session information corresponding to the first storage address, the second hash value, and the first timestamp information are still stored in the BRAM. If the session activity is greater than 2 times the preset polling period, it is determined that the session information is in an inactive state, and the corresponding session information is migrated to the HBM, that is, the second hash value corresponding to the first storage address is obtained, and the lower Y bit positions are selected from the second hash value as the new second storage address, and the session information, the second hash value, and the first timestamp information corresponding to the first storage address are stored in the second storage space corresponding to the new second storage address in the HBM, and the first storage address is released.

[0057] In this embodiment, when new session information is received, the first timestamp information in the BRAM is refreshed. The refresh of the first timestamp information can cause a change in the session activity. By periodically polling the first timestamp information, the session activity of each session information is judged, and the session information with a reduced session activity is migrated to the HBM, releasing the storage space of the BRAM, so as to ensure that active sessions or frequently accessed session data can be stored in the BRAM, reducing the burden on the BRAM, ensuring the reasonable utilization of storage resources, and improving the overall performance of the system. For example, for sessions with frequent real-time interactions in VR applications, ensure that these sessions are always stored in the BRAM with fast access speed to ensure the smoothness of the user experience. When session data migrates in the hash structure, the system will update the corresponding storage address at the same time. For example, when a session migrates from the BRAM to the HBM, the corresponding storage address in the BRAM will be released, and at the same time, a new storage address will be created in the HBM, which can avoid data redundancy or loss and ensure the accuracy and stability of the system during the data migration process.

[0058] A specific embodiment of the present application is as Figure 6 shown, obtaining the session activity of each session information in the HBM, judging whether the session information is in an inactive state based on the session activity, and migrating the session information in the inactive state to the DDR, including steps S601 - S603.

[0059] S601, for each second storage address in the HBM, obtain each second timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the second timestamp information and the current polling time point; S602, if the session activity is not greater than N times the preset polling period, the session information, the second hash value, and the second timestamp information corresponding to the second storage address remain unchanged; S603, if the session activity is greater than N times the preset polling period, obtain the second hash value corresponding to the second storage address, select the lower Z bits from the second hash value as the new third storage address, store the session information, the second hash value, and the second timestamp information corresponding to the second storage address in the third storage space corresponding to the new third storage address in the DDR, and release the second storage address.

[0060] For the session information in each second storage address in the HBM, obtain the session activity of the session information. Preset the polling period. For example, the polling period can be set to 0.1 ms or 0.2 ms, etc., and the user can set it according to the actual situation. The system performs regular polling on the HBM based on this polling period, that is, regularly reads the second timestamp information in each second storage address in the HBM. Based on the above description, it can be known that the second timestamp information is continuously refreshed. Therefore, through the second timestamp information obtained by each polling, the difference between the second timestamp information and the current polling time point is used to determine the session activity of the corresponding session information to determine whether the session information is active.

[0061] Exemplarily, N is set to 5. If the session activity is not greater than 5 times the preset polling period, it is determined that the session information is active, and the session information, the second hash value, and the second timestamp information corresponding to the second storage address are still stored in the HBM. If the session activity is greater than 5 times the preset polling period, it is determined that the session information is inactive, and the corresponding session information is migrated to the DDR, that is, obtain the second hash value corresponding to the second storage address, select the lower Z bits from the second hash value as the new third storage address, store the session information, the second hash value, and the second timestamp information corresponding to the second storage address in the third storage space corresponding to the new third storage address in the DDR, and release the second storage address.

[0062] In this embodiment, when new session information is received, the second timestamp information in the HBM is refreshed. The refresh of the second timestamp information can cause a change in the session activity. By regularly polling the second timestamp information, the session activity of each session information is judged, and the session information with reduced session activity is migrated to the DDR to release the storage space of the HBM, so as to ensure that the HBM can store inactive but potentially accessible session data in the future, reduce the burden on the HBM, ensure the reasonable utilization of storage resources, and improve the overall performance of the system. The HBM supports fast access. While ensuring a certain storage capacity, it can ensure that inactive but potentially useful session data can be quickly obtained. When the session data migrates in the hash structure, the system will update the corresponding storage address at the same time, which can avoid data redundancy or loss and ensure the accuracy and stability of the system during the data migration process.

[0063] A specific embodiment of the present application is as follows Figure 7 As shown, obtain the session activity of each session information in the DDR, determine whether the session information is in an inactive state based on the session activity, and age the session information in the inactive state, including steps S701 - S703.

[0064] S701, for each third storage address in the DDR, obtain each third timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the third timestamp information and the time point of the current poll; S702, if the session activity is not greater than P times the preset polling period, the session information, the second hash address, and the third timestamp information corresponding to the third storage address remain unchanged; S703, if the session activity is greater than P times the preset polling period, age the session information, the second hash value, and the third timestamp information corresponding to the third storage address.

[0065] For the session information in each third storage address in the DDR, obtain the session activity of the session information. Preset the polling period. For example, the polling period can be set to 0.1ms or 0.2ms, etc., and the user can set it according to the actual situation. The system performs regular polling on the DDR based on this polling period, that is, regularly reads the third timestamp information in each third storage address in the DDR. Based on the above description, it can be known that the third timestamp information is continuously refreshed. Therefore, the session activity of the corresponding session information is determined by the difference between the third timestamp information obtained by each poll and the time point of the current poll to determine whether the session information is in an active state.

[0066] Exemplarily, P is taken as 15. If the session activity is not greater than 15 times the preset polling period, it is determined that the session information is in an active state, and the session information, the second hash value, and the third timestamp information corresponding to the third storage address are still stored in the DDR. If the session activity is greater than 15 times the preset polling period, it is determined that the session information is in an inactive state, age the corresponding session information, and release the third storage address.

[0067] In this embodiment, when new session information is received, the third timestamp information of the DDR is refreshed. The refresh of the third timestamp information can cause a change in the activity of the session information. By periodically polling the third timestamp information, the session activity of each session information is judged, and the session information with reduced session activity is aged to ensure that the DDR can store session data that is inactive or rarely accessed for a long time, so as to reduce the burden on the DDR and improve the overall performance of the system. When the session data migrates in the hash structure, the system will simultaneously update the corresponding storage address, which can avoid data redundancy or loss and ensure the accuracy and stability of the system during the data migration process. For example, for a large number of small-data-volume and long-life-cycle sessions generated by Internet of Things devices, the storage is further optimized by dynamically compressing the hash value, and at the same time, the hierarchical hash architecture is used to reasonably allocate the storage location to improve the system's management ability for new application sessions.

[0068] In an embodiment of the present application, for each first storage address in the BRAM, the corresponding session survival time is determined by the difference between the corresponding creation time and the current polling time point. If the session survival time exceeds the first time threshold, when the next pending packet with the same five-tuple information as the corresponding one is received, the lower Y bits are selected from the corresponding second hash value as the second storage address, and the session information, the second hash value, and the corresponding second timestamp information when the session information is stored in the pending packet are stored in the second storage space corresponding to the second storage address in the HBM.

[0069] In this embodiment, the session information in the BRAM is periodically polled to determine the survival time of the session information. If the survival time exceeds the first time threshold, it is determined that the session information is in an inactive state. When the next packet with the same five-tuple information is received, the session information is stored in the HBM. By dynamically adjusting the length of the hash value corresponding to the five-tuple information in the packet, the inactive session information is stored in the HBM to further improve the system performance.

[0070] In an embodiment of the present application, for each second storage address in the HBM, the corresponding session survival time is determined by the difference between the corresponding creation time and the current polling time point. If the session survival time exceeds the second time threshold, when the next pending packet with the same five-tuple information is received, the lower Z bits are selected from the corresponding second hash value as the third storage address, and the session information, the second hash value, and the corresponding third timestamp information when the session information is stored in the pending packet are stored in the third storage space corresponding to the third storage address in the DDR.

[0071] In this embodiment, the session information in the HBM is periodically polled to determine the survival time of the session information. If the survival time exceeds the second time threshold, it is determined that the session information is in an inactive state. When a packet with the same five-tuple information is received next time, the session information is stored in the DDR. By dynamically adjusting the length of the hash value corresponding to the five-tuple information in the packet, the inactive session information is stored in the DDR to further improve the system performance.

[0072] In one embodiment of the present application, a corresponding session management packet is generated based on the session information corresponding to each storage address in the BRAM, and a corresponding session management packet is generated based on the session information corresponding to each storage address in the HBM, and a corresponding session management packet is generated based on the session information corresponding to each storage address in the DDR. For example, the session management packet can adopt the Netflow protocol.

[0073] Based on the same inventive concept, an embodiment of the present application also provides a hierarchical session management device based on an FPGA. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following hierarchical session management devices based on an FPGA can refer to the limitations on the hierarchical session management method based on an FPGA in the above text, and will not be repeated here.

[0074] Please refer to Figure 8 , an embodiment of the present application provides a hierarchical session management device based on an FPGA. The device further includes: An acquisition module 801, configured to acquire five-tuple information in a packet to be processed; A Bloom filter 802, configured to determine a plurality of first hash values corresponding to the five-tuple information, match the access control list (ACL) rules based on the Bloom filter for the plurality of first hash values, and in response to the five-tuple information hitting the ACL rules, determine the session life cycle type of the packet to be processed based on the protocol type in the five-tuple information, and use any one of the plurality of first hash values as a second hash value; A block random access memory (BRAM) 803, configured to, if the session life cycle type is a short session, select the lower X bit positions from the second hash value as a first storage address, and store the five-tuple information and the second hash value in a first storage space corresponding to the first storage address in the BRAM; A high bandwidth memory (HBM) 804, configured to, if the session life cycle type is a medium session, select the lower Y bit positions from the second hash value as a second storage address, and store the five-tuple information and the second hash value in a second storage space corresponding to the second storage address in the HBM; Dual-rate synchronous dynamic random access memory DDR805, which is used to select the lower Z bit positions from the second hash value as the third storage address if the session life cycle type is a long session, and store the quintuple information and the second hash value into the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

[0075] As an example, please refer to Figure 9 , which shows a schematic structural diagram of a communication device provided by an embodiment of the present application. The network device includes a hierarchical session management device 901 based on FPGA, a communication interface 902, a processor 903, a memory 904, and a bus 905. The processor 903, the memory 904, the communication interface 902, and the hierarchical session management device 901 based on FPGA are communicatively connected to each other through the bus 905. The memory 904 can be used to store computer programs, and the computer programs can include instructions and data. In the embodiments of the present application, the memory 904 can be various types of storage media, such as random access memory, static random access memory, non-volatile RAM, DDR, etc. The memory 904 can include a hard disk and / or internal memory. The processor 903 can be a general-purpose processor, and the general-purpose processor can be a processor that executes specific steps and / or operations by reading and executing the computer program stored in a memory (such as the memory 904), and the general-purpose processor is used to process the data output by the hierarchical session management device 901 based on FPGA. The general-purpose processor can be, for example but not limited to, a central processing unit. In addition, the processor 903 can also be a dedicated processor, and the dedicated processor can be a processor specifically designed to execute specific steps and / or operations, and the dedicated processor can be, for example but not limited to, ASIC and FPGA, etc. In addition, the processor 903 can also be a combination of multiple processors, such as a multi-core processor. The communication interface 902 can include input / output interfaces, physical interfaces, and logical interfaces, etc., for implementing the interconnection of components inside the network device, and interfaces for implementing the interconnection of the network device with other devices (such as network devices). The physical interface can be a gigabit Ethernet interface, which can be used to implement the interconnection of the network device with other devices, and the logical interface is an interface inside the network device, which can be used to implement the interconnection of components inside the network device. The bus 905 can be of any type, a communication bus for implementing the interconnection of the processor 903, the memory 904, the communication interface 902, and the hierarchical session management device 901 based on FPGA, such as a system bus. The structure of the hierarchical session management device 901 based on FPGA can refer to Figure 8 the shown embodiment of

[0076] The embodiments disclosed in this application also provide a computer-readable storage medium, in which instructions are stored. When it runs on a computer, it causes the computer to execute the FPGA-based hierarchical session management method described in any one of the above embodiments.

[0077] Although the preferred embodiments of this application have been disclosed for illustrative purposes, those of ordinary skill in the art will recognize that various improvements, additions, and substitutions are possible without departing from the scope and spirit of this application as disclosed by the appended claims.

Claims

1. A hierarchical session management method based on FPGA, characterized in that, The FPGA includes a Block Random Access Memory (BRAM), a High Bandwidth Memory (HBM), and a Double Data Rate Synchronous Dynamic Random Access Memory (DDR). The method includes: Obtain the five-tuple information in the packet to be processed; Determine multiple first hash values corresponding to the five-tuple information, and perform matching of Access Control List (ACL) rules on the multiple first hash values based on a Bloom filter; In response to the five-tuple information hitting the ACL rule, determine the session life cycle type of the packet to be processed based on the protocol type in the five-tuple information, and use any one of the multiple first hash values as a second hash value; If the session life cycle type is a short session, select the lower X bit positions from the second hash value as a first storage address, and store the five-tuple information and the second hash value in the first storage space corresponding to the first storage address in the BRAM; If the session life cycle type is a medium session, select the lower Y bit positions from the second hash value as a second storage address, and store the five-tuple information and the second hash value in the second storage space corresponding to the second storage address in the HBM; If the session life cycle type is a long session, select the lower Z bit positions from the second hash value as a third storage address, and store the five-tuple information and the second hash value in the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

2. The method for hierarchical session management based on FPGA according to claim 1, wherein Determine multiple first hash values corresponding to the five-tuple information, and perform matching of Access Control List (ACL) rules on the multiple first hash values based on a Bloom filter, including: Perform hash operations on the five-tuple information respectively using k different hash functions to obtain k first hash values; Based on the k first hash values, query, in multiple fourth storage spaces of the Bloom filter, the fourth storage spaces that match each of the k first hash values, and obtain the bitmap index values in each matching fourth storage space. The Bloom filter is configured to: for each ACL rule, perform calculations using k different hash functions to obtain corresponding k hash arrays, and configure the bitmap index values in the fourth storage spaces corresponding to the k hash arrays to 1; If all the bitmap index values are 1, determine that the five-tuple information hits the ACL rule; otherwise, discard the five-tuple information.

3. The hierarchical session management method based on FPGA according to claim 1, wherein The method further includes: Obtain the session information in the packet to be processed. The session information includes five-tuple information, session type, creation time, packet statistics value, byte statistics value, and source port, where the creation time is the time when the packet to be processed is first received; If the session life cycle type is a short session, select the lower X bit positions from the second hash value as a first storage address, and store the session information, the second hash value, and the first timestamp information corresponding to the storage time of the session information in the first storage space corresponding to the first storage address in the BRAM; If the session lifecycle type is a medium session, select the lower Y bits from the second hash value as the second storage address, and store the session information, the second hash value, and the second timestamp information corresponding to the session information when it is stored into the second storage space corresponding to the second storage address in the HBM; If the session lifecycle type is a long session, select the lower Z bits from the second hash value as the third storage address, and store the session information, the second hash value, and the third timestamp information corresponding to the session information when it is stored into the third storage space corresponding to the third storage address in the DDR.

4. The hierarchical session management method based on FPGA according to claim 3, wherein The method further includes: Obtain the session activity of each session information in the BRAM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the HBM; Obtain the session activity of each session information in the HBM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the DDR; Obtain the session activity of each session information in the DDR, determine whether the session information is in an inactive state based on the session activity, and perform an aging operation on the session information in the inactive state.

5. The hierarchical session management method based on FPGA according to claim 4, wherein, Obtain the session activity of each session information in the BRAM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the HBM, including: For each first storage address in the BRAM, obtain each first timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the first timestamp information and the time point of the current poll; If the session activity is not greater than M times the preset polling period, the session information, the second hash value, and the first timestamp information corresponding to the first storage address remain unchanged; If the session activity is greater than M times the preset polling period, obtain the second hash value corresponding to the first storage address, select the lower Y bits from the second hash value as the new second storage address, store the session information, the second hash value, and the first timestamp information corresponding to the first storage address into the second storage space corresponding to the new second storage address in the HBM, and release the first storage address.

6. The method for hierarchical session management based on FPGA according to claim 4, wherein Obtain the session activity of each session information in the HBM, determine whether the session information is in an inactive state based on the session activity, and migrate the session information in the inactive state to the DDR, including: For each second storage address in the HBM, obtain each second timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the second timestamp information and the time point of the current poll; If the session activity is not greater than N times the preset polling period, the session information, the second hash value, and the second timestamp information corresponding to the second storage address remain unchanged; If the session activity is greater than N times the preset polling period, obtain the second hash value corresponding to the second storage address, select the lower Z bit positions from the second hash value as the new third storage address, store the session information, the second hash value, and the second timestamp information corresponding to the second storage address in the third storage space corresponding to the new third storage address in the DDR, and release the second storage address.

7. The method for hierarchical session management based on FPGA according to claim 4, wherein Obtain the session activity of each session information in the DDR, determine whether the session information is in an inactive state based on the session activity, and perform an aging operation on the session information in the inactive state, including: For each third storage address in the DDR, obtain each third timestamp information corresponding to the current polling period, and determine the session activity of the corresponding session information based on the difference between the third timestamp information and the time point of the current poll; If the session activity is not greater than P times the preset polling period, the session information, the second hash address, and the third timestamp information corresponding to the third storage address remain unchanged; If the session activity is greater than P times the preset polling period, age the session information, the second hash value, and the third timestamp information corresponding to the third storage address.

8. The hierarchical session management method based on FPGA according to claim 3, characterized in that, The method further includes: For each first storage address in the BRAM, determine the session survival time based on the difference between the corresponding creation time and the time point of the current poll. If the session survival time exceeds the first time threshold, when the next pending packet with the same five-tuple information is received, select the lower Y bit positions from the corresponding second hash value as the second storage address, and store the session information, the second hash value, and the second timestamp information corresponding to the session information when it is stored in the second storage space corresponding to the second storage address in the HBM; For each second storage address in the HBM, determine the session survival time based on the difference between the corresponding creation time and the time point of the current poll. If the session survival time exceeds the second time threshold, when the next pending packet with the same five-tuple information is received, select the lower Z bit positions from the corresponding second hash value as the third storage address, and store the session information, the second hash value, and the third timestamp information corresponding to the session information when it is stored in the third storage space corresponding to the third storage address in the DDR.

9. A method and device for hierarchical session management based on FPGA, characterized in that, The apparatus includes: An obtaining module, configured to obtain five-tuple information in a pending packet; A Bloom filter, configured to determine multiple first hash values corresponding to the five-tuple information, perform matching of access control list (ACL) rules on the multiple first hash values based on the Bloom filter, in response to the five-tuple information hitting the ACL rule, determine the session life cycle type of the pending packet based on the protocol type in the five-tuple information, and use any one of the multiple first hash values as the second hash value; Block Random Access Memory (BRAM), which is used to select the lower X bit positions from the second hash value as the first storage address if the session life cycle type is a short session, and store the quintuple information and the second hash value into the first storage space corresponding to the first storage address in the BRAM; High Bandwidth Memory (HBM), which is used to select the lower Y bit positions from the second hash value as the second storage address if the session life cycle type is a medium session, and store the quintuple information and the second hash value into the second storage space corresponding to the second storage address in the HBM; Double Data Rate Synchronous Dynamic Random Access Memory (DDR), which is used to select the lower Z bit positions from the second hash value as the third storage address if the session life cycle type is a long session, and store the quintuple information and the second hash value into the third storage space corresponding to the third storage address in the DDR, where Y is greater than X and less than Z.

10. A communication device, characterized in that, Comprising the FPGA-based hierarchical session management device according to claim 9.

Citation Information

Patent Citations

  • Network session management method and device, equipment and storage medium

    CN114221847A

  • Message processing method and device based on FPGA (Field Programmable Gate Array) and accelerator card

    CN118264615A

  • Method and system for quickly searching network full-flow session flow

    CN119011249A

  • Fast routing lookup method applied to satellite-borne router

    CN119363661A

  • High-performance hash table implementation method suitable for FPGA (Field Programmable Gate Array)

    CN119690965A

Cited By

  • Method and device for processing forwarding mapping table based on FPGA (Field Programmable Gate Array)

    CN122476061A