Network traffic control method and device, chip, network interface card, computer equipment, readable storage medium and program product

The RISC-V architecture-based network traffic control method addresses inefficiencies in existing systems by using hardware token bucket updates to manage traffic efficiently and intelligently, reducing system complexity and performance impact.

CN120321189AActive Publication Date: 2025-07-15SHENZHEN JAGUAR MICROSYSTEMS CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510822034.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-19
Publication Date
2025-07-15
Estimated Expiration
2045-06-19

AI Technical Summary

Technical Problem

The existing network traffic control method has high system complexity in multi-core scenarios, real-time refresh of table items increases the system burden, and the software locking mechanism affects performance.

Method used

The hardware features of RISC-V design are adopted to read and update the number of overdraft tokens in the token bucket through hardware, realize atomic operation of the speed limit configuration table, avoid software locking, and improve processing efficiency.

Benefits of technology

It improves the processing efficiency and intelligence level of network traffic control, reduces the system burden, and improves the accuracy of speed limit and plastic surgery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321189A_ABST
    Figure CN120321189A_ABST
Patent Text Reader

Abstract

The invention relates to a network flow control method and device, a chip, a network interface card, computer equipment, a computer readable storage medium and a computer program product. The method is applied to a chip comprising an RISC-V architecture processor core, and comprises the following steps: determining the number of tokens to be updated corresponding to a token bucket; reading the number of overdraft tokens corresponding to the token bucket in the speed limit configuration table based on hardware characteristics of RISC-V design, and reading the number of current tokens; based on the number of tokens to be updated, the number of overdraft tokens and the number of current tokens, updating the number of current tokens in a speed limit configuration table; reading the speed limit configuration table, and marking a message to be sent based on the number of the current tokens, the number of the overdraft tokens and the length of the message to be sent in the speed limit configuration table; and processing the flow corresponding to the message to be sent based on the action corresponding to each mark in the speed limit configuration table. By adopting the method, the processing efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technologies, and particularly to a network traffic control method, apparatus, chip, network interface card, computer device, computer-readable storage medium, and computer program product. Background Art

[0002] With the development of network cloud technology and data centers, the demand for private clouds and personal cloud hosts is gradually increasing. Restricting and shaping the traffic of devices or cloud hosts is a strong requirement during operation. It is necessary to measure and limit the rate and burst of traffic. Currently, not only the existing token bucket method is needed to meet this requirement, but sometimes parameter configuration is required for special scenarios to achieve traffic rate limiting or shaping.

[0003] However, the current solution is to adjust traffic rate limiting in a timely manner by configuring multiple parameter tables and recording multiple traffic status tables, which may require real-time refreshing of table entries. This design increases system complexity, and real-time refreshing of table entries also increases the system burden. Or in a multi-core scenario, a software locking mechanism is combined with a certain algorithm to improve the efficiency and accuracy of rate limiting. Although the locking mechanism can solve the resource conflict problem in multi-core scenarios, this mechanism has a great impact on performance. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a network traffic control method, apparatus, chip, network interface card, computer device, computer-readable storage medium, and computer program product that can improve processing efficiency.

[0005] In a first aspect, the present application provides a network traffic control method applied to a chip including a RISC-V architecture processor core. The method includes:

[0006] Determine the number of tokens to be updated corresponding to the token bucket;

[0007] Based on the hardware characteristics designed by RISC-V, clear the number of overdrawn tokens corresponding to the token bucket in the rate limiting configuration table and read the current number of tokens;

[0008] Update the current number of tokens in the rate limiting configuration table based on the number of tokens to be updated, the number of overdrawn tokens, and the current number of tokens;

[0009] Read the rate limiting configuration table, and mark the packet to be sent based on the current number of tokens, the number of overdrawn tokens, and the length of the packet to be sent in the rate limiting configuration table;

[0010] Process the packet to be sent based on the actions corresponding to each mark in the rate limiting configuration table.

[0011] In one embodiment, the method further includes:

[0012] Receiving a configuration instruction for the speed limit configuration table, where the configuration instruction includes at least one of a token bucket configuration instruction, a speed limit mode configuration instruction, and a marking and action mapping relationship configuration instruction, and where the token bucket configuration instruction is used to configure at least one of the priority of each token bucket, the token increase rate in each token bucket, the token bucket size, and whether to allow overflow to a lower-priority token bucket;

[0013] Configuring the speed limit configuration table based on the configuration instruction.

[0014] In one embodiment, the determining the number of tokens to be updated corresponding to the token bucket includes:

[0015] Obtaining a pre-configured speed limit configuration table and reading the token increase rate corresponding to each token bucket from the speed limit configuration table;

[0016] Obtaining the number of tokens to be updated corresponding to each token bucket based on each of the token increase rates.

[0017] In one embodiment, each of the token buckets has a priority; the updating the current token quantity in the speed limit configuration table based on the number of tokens to be updated, the number of overdrawn tokens, and the current token quantity includes:

[0018] For each token bucket of each priority, obtaining an initial token quantity based on the number of tokens to be updated, the number of overdrawn tokens, and the current token quantity; where, when the priority of the token bucket is not the highest priority and tokens in a higher-priority token bucket are allowed to overflow into the token bucket, the current token quantity of the token bucket is updated based on the tokens overflowing from the higher-priority token bucket;

[0019] Correcting the initial token quantity based on the initial token quantity and the token bucket size of the token bucket to obtain a target token quantity, and replacing the current token quantity corresponding to the token bucket with the target token quantity.

[0020] In one embodiment, the marking the message to be sent based on the current token quantity, the number of overdrawn tokens, and the length of the message to be sent in the speed limit configuration table includes:

[0021] Reading the speed limit mode in the speed limit configuration table and the priority of the token bucket;

[0022] Based on the speed limit mode and the priority of the token bucket, determine the relationship between the available token quantity and the token quantity to be consumed in each token bucket in sequence, where the token quantity to be consumed is the sum of the overdrawn token quantity and the length of the message to be sent;

[0023] Based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the flag indicating whether overflow to a low-priority token bucket is allowed, mark the message to be sent.

[0024] In one embodiment, after marking the message to be sent based on the current token quantity, the overdrawn token quantity, and the length of the message to be sent in the speed limit configuration table, it further includes:

[0025] Based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the flag indicating whether overflow to a low-priority token bucket is allowed, determine the target token bucket for processing the message to be sent;

[0026] Update the overdrawn token quantity of the target token bucket based on the overdrawn token quantity of the target token bucket and the length of the message to be sent.

[0027] In a second aspect, the present application further provides a network traffic control device, which is applied to a chip including a RISC-V architecture processor core, and the device includes:

[0028] A to-be-updated token quantity determination module, configured to determine the to-be-updated token quantity corresponding to the token bucket;

[0029] A reading module, configured to clear the overdrawn token quantity corresponding to the token bucket in the speed limit configuration table and read the current token quantity based on the hardware characteristics designed by RISC-V;

[0030] An update module, configured to update the current token quantity in the speed limit configuration table based on the to-be-updated token quantity, the overdrawn token quantity, and the current token quantity;

[0031] A marking module, configured to read the speed limit configuration table and mark the message to be sent based on the current token quantity, the overdrawn token quantity, and the length of the message to be sent in the speed limit configuration table;

[0032] A traffic processing module, configured to process the traffic corresponding to the message to be sent based on the actions corresponding to each mark in the speed limit configuration table.

[0033] In a third aspect, the present application further provides a chip, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method in any one of the above embodiments are implemented.

[0034] In a fourth aspect, the present application further provides a network interface card, including a chip and a plurality of interfaces in any of the above embodiments, where the chip processes data or communicates externally through the interfaces.

[0035] In a fifth aspect, the present application further provides a computer device, including the network interface card in any of the above embodiments, where the network interface card is used to process data or communicate externally.

[0036] In a sixth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in any of the above embodiments are implemented.

[0037] In a seventh aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the method in any of the above embodiments are implemented.

[0038] For the above network traffic control method, device, chip, network interface card, computer device, computer-readable storage medium, and computer program product, the method includes determining the number of tokens to be updated corresponding to the token bucket; based on the hardware characteristics of the RISC-V design, clearing the number of overdrawn tokens corresponding to the token bucket in the rate limit configuration table and reading the current number of tokens; updating the current number of tokens in the rate limit configuration table based on the number of tokens to be updated, the number of overdrawn tokens, and the current number of tokens; reading the rate limit configuration table, and based on the current number of tokens, the number of overdrawn tokens, and the length of the packet to be sent in the rate limit configuration table, marking the packet to be sent; and processing the traffic corresponding to the packet to be sent based on the actions corresponding to the marks in the rate limit configuration table. In this way, by introducing the hardware characteristics of the RISC-V design, the rate limit configuration table is locked in a hardware manner without software locking. Compared with the software locking processing method, the efficiency is higher, and the actions corresponding to the marks can be configured, with a higher level of intelligence. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for describing the embodiments of the present application or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1 It is a flowchart of the network traffic control method in an embodiment;

[0041] Figure 2 It is a schematic flowchart of the token bucket update step in an embodiment;

[0042] Figure 3 It is a schematic flowchart of the rate limiting step in an embodiment;

[0043] Figure 4 It is a structural block diagram of a network traffic control device in an embodiment;

[0044] Figure 5 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0045] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0046] With the development of network cloud technology and data centers, the demand for private clouds and personal cloud hosts is gradually increasing. Restricting device traffic or cloud host traffic and shaping the traffic are strong requirements during operation. It is necessary to measure and limit the rate and burst of traffic. Currently, not only the existing token bucket method is needed to meet this requirement, but sometimes parameter configuration is required for special scenarios to achieve rate limiting or shaping.

[0047] To solve at least one of the above technical problems, in an exemplary embodiment, as Figure 1 shown, the present application provides a network traffic control method. In this embodiment, it is exemplified that the method is applied to a chip including a RISC-V architecture processor core. In this embodiment, the method includes the following steps:

[0048] S102: Determine the number of tokens to be updated corresponding to the token bucket.

[0049] Among them, the number of tokens in the token bucket is updated periodically. In the present application, it includes two parts. One part is responsible for updating the number of tokens in the token bucket, and this part does not process traffic data. The other part is responsible for rate limiting the traffic data according to the algorithm rules. Therefore, both parts need to process the number of tokens in the token bucket.

[0050] In step S102 of the present application, the number of tokens to be updated is the process of injecting tokens into the token bucket.

[0051] In some alternative embodiments, determining the number of tokens to be updated corresponding to the token bucket includes: obtaining a pre-configured rate limiting configuration table, and reading the token increase rate corresponding to each token bucket from the rate limiting configuration table; obtaining the number of tokens to be updated corresponding to each token bucket based on each token increase rate.

[0052] The speed limit configuration table includes the token addition rate corresponding to each token bucket. The number of tokens to be updated is equal to the time multiplied by the token addition rate.

[0053] The calculation of time is related to the token bucket update period. The setting of the token bucket update period is related to the clock frequency of the hardware CPU and the unit of the token bucket. At least 1 byte of tokens are generated in each update period. The update period is equal to 1s divided by the token bucket unit. For example, if the token bucket unit is 8KB and the CPU is 1GHz, then the update period is 125us. It should be noted that the calculated token bucket update period should be less than the clock frequency of the hardware CPU.

[0054] After determining the token bucket update period, obtain the current time. Subtract the time read after the last token bucket update is completed from the current time to get a time difference. Divide this time difference by the token bucket update period to get a cycle count value. The number of tokens to be updated within this time difference should be CIR * counter, where CIR is the token addition rate in the speed limit configuration table and counter is the cycle count value.

[0055] It should be noted that the speed limit configuration table can include at least one token bucket, and different token addition rates can be set for each token bucket, without specific limitations here. When calculating the number of tokens to be updated corresponding to each token bucket, it can be calculated sequentially based on the priorities of each token bucket, or the number of tokens to be updated corresponding to each token bucket can be calculated in parallel, without specific limitations here.

[0056] Since only the data in the speed limit configuration table is read in this step and the data is not modified, there is no need to perform a locking operation on the speed limit configuration table in this step.

[0057] S104: Read and clear the overdrawn token quantity corresponding to the token bucket in the speed limit configuration table based on the hardware characteristics of the RISC-V design, and read the current token quantity.

[0058] S106: Update the current token quantity in the speed limit configuration table based on the number of tokens to be updated, the overdrawn token quantity, and the current token quantity.

[0059] Among them, the hardware feature of the RISC-V design is that while reading the speed limit configuration table, it clears the value of a certain area in the table. Currently, it clears the value of the overdraft token area in the speed limit configuration table, which ensures atomic operations in hardware. Software can read the table resources without locks, and then update the current token quantity in the speed limit configuration table based on the quantity of tokens to be updated, the quantity of overdraft tokens, and the current token quantity. After the update is completed, the hardware lock on the speed limit configuration table is released. In this way, since the hardware processing is faster, the overall efficiency can be improved.

[0060] The method for updating each token bucket includes adding the quantity of tokens in the current token bucket to the calculated quantity of tokens to be updated CIR * counter, and then subtracting the quantity of overdraft tokens recorded in the speed limit configuration table. The final value is the quantity of tokens updated to the token bucket. However, due to the size problem of the token bucket, it may cause token overflow in the token bucket. In this application, if the token bucket supports overflow, then update the quantity of tokens in the token bucket. Specifically, check whether it is necessary to correct the calculated quantity of tokens updated to the token bucket. If the calculated quantity of tokens updated to the token bucket is larger than the depth of the token bucket, then the calculated quantity of tokens updated to the token bucket is corrected to be equal to CBS1. At this time, if another token bucket supports overflow, then the current token quantity of the other token bucket needs to add the value of the calculated quantity of tokens updated to the token bucket minus CBS1; if the calculated quantity of tokens updated to the token bucket is smaller than the negative CBS of the depth of the token bucket, then the value of the calculated quantity of tokens updated to the token bucket is corrected to be equal to -CBS, and in other cases, there is no need to adjust the calculated quantity of tokens updated to the token bucket.

[0061] S108: Read the speed limit configuration table, and mark the message to be sent based on the current token quantity, overdraft token quantity, and the length of the message to be sent in the speed limit configuration table.

[0062] S110: Process the message to be sent based on the actions corresponding to each mark in the speed limit configuration table.

[0063] Steps S102 to S106 involve the process of updating the token bucket, while steps S108 to S110 involve the speed limit process.

[0064] In this application, the speed limit process also needs to read the speed limit configuration table and use the corresponding tokens in it. In this application, read the speed limit configuration table, and mark the message to be sent based on the current token quantity, overdraft token quantity, and the length of the message to be sent in the speed limit configuration table.

[0065] Among them, based on the current token quantity, overdrawn token quantity in the speed limit configuration table, and the length of the packet to be sent, the relationship between the available token quantity and the token quantity to be consumed in each token bucket can be determined, so that the packet to be sent can be marked based on the algorithm rules, such as marking by coloring and the like.

[0066] Moreover, the speed limit configuration table in this application can also include the actions corresponding to each mark. The relationship between the mark and the action can be pre-configured. After each packet to be sent is marked, read the action corresponding to the mark in the speed limit configuration table, and then execute the corresponding action to perform speed limit processing on the packet to be sent.

[0067] Among them, the mark can be the color corresponding to the coloring. The number of such colors is not specifically limited. In addition, the action can include but is not limited to at least one of continuing to forward, discarding the packet, counting the size of the traffic limited by speed, counting the number of packets and the number of bytes of the packets lost due to speed limit.

[0068] The above network traffic control method includes determining the token quantity to be updated corresponding to the token bucket; clearing the overdrawn token quantity corresponding to the token bucket in the speed limit configuration table based on the hardware characteristics designed based on RISC-V, and reading the current token quantity; updating the current token quantity in the speed limit configuration table based on the token quantity to be updated, the overdrawn token quantity, and the current token quantity; reading the speed limit configuration table, and marking the packet to be sent based on the current token quantity, the overdrawn token quantity, and the length of the packet to be sent in the speed limit configuration table; processing the traffic corresponding to the packet to be sent based on the actions corresponding to each mark in the speed limit configuration table. In this way, by introducing the hardware characteristics designed based on RISC-V, atomic operations are guaranteed on the hardware, and the table resources can be read without locks in software. Compared with the software locking processing method, the efficiency is higher, and the actions corresponding to the marks can be configured, with a higher level of intelligence.

[0069] In one optional embodiment, the method further includes a configuration process, which is mainly the configuration of the speed limit configuration table. The configuration process mainly includes: receiving a configuration instruction for the speed limit configuration table, where the configuration instruction includes at least one of a token bucket configuration instruction, a speed limit mode configuration instruction, and a mark-action mapping relationship configuration instruction. The token bucket configuration instruction is used to configure at least one of the priority of each token bucket, the token increase rate in each token bucket, the token bucket size, and whether to allow overflow to a lower-priority token bucket; configuring the speed limit configuration table based on the configuration instruction.

[0070] Each instantiation of the speed limit configuration table corresponds to an entry ID, which can be associated with a traffic flow or a cloud host, etc., so as to achieve the purpose of speed limiting and shaping the specified traffic flow or cloud host. The speed limit configuration table includes two parts. One part is the speed limit parameter configuration part. To implement the existing token bucket method, these parameters include the token addition rate CIR (also known as the committed information rate) of each token bucket and the token bucket size CBS (also known as the committed burst size). Other parameters include the number of tokens in the current token bucket (i.e., the remaining number of tokens), and the number of overdrawn tokens in the current token bucket. The remaining number of tokens and the number of overdrawn tokens can be negative values. In addition, since there are multiple token buckets, the token buckets also have priorities. Each token bucket can also include a token bucket priority parameter. The non-lowest priority token buckets also include whether to allow overflow to the low-priority token buckets af (allow overflow).

[0071] For the speed limit action part, it includes the actions corresponding to the speed limit mode mode (speed limiting based on bit stream or based on the number of packets), and the flags (green / yellow / red). The actions include discard actions and continue forwarding actions, etc. For details, please refer to the above text.

[0072] For the convenience of taking two token buckets as an example, the corresponding speed limit configuration table is as follows:

[0073]

[0074] In this embodiment, the priority is represented by the sorting in the speed limit configuration table, that is, the priority of the first token bucket is higher than that of the second token bucket. The user can configure at least one of the priority of the token bucket, the token addition rate in each token bucket, the token bucket size, and whether to allow overflow to the low-priority token bucket. The speed limit mode and the mapping relationship between the marking and the action can also be configured. For example, the action corresponding to green action in the table is to continue forwarding when it is 0 and to discard the packet when it is 1. Similarly, the yellow action and the red action can also be configured with corresponding actions. The table only takes the action as continuing forwarding when it is 0 and discarding the packet when it is 1 as an example. In other embodiments, other actions can also be used. In addition, the number and type of the markings can also be other. For example, there can be 4 markings, 5 markings, etc. The markings can be made by coloring, or by other means. No specific limitation is made here.

[0075] In the above embodiment, the configuration process includes the mapping of coloring and actions, so as to expand the corresponding actions and have a higher level of intelligence.

[0076] In one alternative embodiment, each token bucket has a priority; updating the current token quantity in the rate limit configuration table based on the quantity of tokens to be updated, the quantity of overdrawn tokens, and the current token quantity includes: for each token bucket with a specific priority, obtaining an initial token quantity based on the quantity of tokens to be updated, the quantity of overdrawn tokens, and the current token quantity; wherein, when the priority of the token bucket is not the highest priority and tokens in a higher-priority token bucket are allowed to overflow into the token bucket, the current token quantity of the token bucket is obtained by updating based on the tokens overflowing from the higher-priority token bucket; correcting the initial token quantity based on the initial token quantity and the token bucket size of the token bucket to obtain a target token quantity, and replacing the current token quantity corresponding to the token bucket with the target token quantity.

[0077] Among them, this application includes multiple token buckets, and the update of each token bucket includes both an initial token quantity calculation step and a step of correcting the initial token quantity. The initial token quantity calculation step is obtained based on the quantity of tokens to be updated, the quantity of overdrawn tokens, and the current token quantity. Specifically, the initial token quantity new_token = current_token + CIR * counter - loan_token, where current_token is the current token quantity, i.e., read from the rate limit configuration table, and loan_token is the quantity of overdrawn tokens, which is read from the rate limit configuration table.

[0078] The step of correcting the initial token quantity is to obtain the correct target token quantity to replace the current token quantity with the target token quantity. The correction of the target table token quantity includes: checking whether the calculated initial token quantity new_token needs to be corrected. If new_token is larger than the bucket depth CBS of the token bucket, then the value of new_token is corrected to be equal to CBS, that is, the target token quantity is CBS. If new_token is smaller than the negative value of the bucket depth CBS of the token bucket, then the value of new_token is corrected to be equal to -CBS, that is, the target token quantity is 1CBS. In other cases, new_token does not need to be adjusted, that is, the target token quantity is new_token.

[0079] Among them, since new_token is larger than the bucket depth CBS of the token bucket, that is, there are excess tokens. At this time, if overflow to a lower-priority token bucket is supported, then the current token quantity current_token of the lower-priority token bucket needs to be added with the value of new_token calculated by the overflowing token bucket minus the CBS value corresponding to the overflowing token bucket, that is, the current token quantity of the lower-priority token bucket is updated.

[0080] For convenience, still taking two token buckets as an example for illustration, the token bucket update steps can be referred to Figure 2 as shown below, and specifically include the following steps:

[0081] First, obtain the current time. Subtract the time read after the last token bucket update is completed from this time to get a time difference. Divide this time difference by the token bucket update period to obtain the corresponding number of periods counter within this time difference. Calculate the number of tokens to be updated CIR * counter based on the number of periods and the token increment rate CIR. Since this step is performed for each token bucket, if calculating the number of tokens to be updated corresponding to the first token bucket, the token increment rate is CIR1; if calculating the number of tokens to be updated corresponding to the second token bucket, the token increment rate is CIR2.

[0082] Second, read the corresponding rate limit configuration table according to the instantiated id, and clear the value of the overdrawn tokens in this table. This step is mainly based on the hardware characteristics of the RISC-V design. While clearing the table entry, clear the value of a certain area in the table. Currently, it is to clear the value of the overdrawn token area in the rate limit configuration table, which ensures atomic operations in hardware and allows lock-free reading of the table resources in software.

[0083] Third, calculate the number of tokens that should be updated to the first token bucket. The calculation method is to add the number of tokens currently in the first token bucket to the first calculated number of tokens to be updated CIR * counter, and then subtract the number of overdrawn tokens recorded in the rate limit configuration table. The final value is the number of tokens new_token1 updated to the first token bucket.

[0084] Fourth, check whether it is necessary to correct the number of tokens new_token1 updated to the first token bucket calculated in the third step. If new_token1 is larger than the bucket depth CBS1 of the first token bucket, then the value of new_token1 is corrected to be equal to CBS1. At this time, if overflowing the second token bucket is supported, then the current number of tokens current_token2 in the second token bucket needs to be added with the value of new_token1 minus CBS1; if new_token1 is smaller than the negative CBS1 of the bucket depth of the first token bucket, then the value of new_token1 is corrected to be equal to -CBS1; in other cases, new_token1 does not need to be adjusted.

[0085] Fifth, calculate the number of tokens new_token2 that should be updated to the second token bucket. The calculation method is the same as the third step.

[0086] Sixth, check whether it is necessary to correct the number of tokens new_token2 updated to the second token bucket calculated in the fifth step. If new_token2 is larger than the bucket depth CBS2 of the second token bucket, then the value of new_token2 is corrected to be equal to CBS2; if new_token2 is smaller than the negative CBS2 of the bucket depth of the first token bucket, then the value of new_token2 is corrected to be equal to -CBS, and in other cases, new_token2 does not need to be adjusted.

[0087] In the above embodiments, the software lock-free operation based on the RISC-V hardware device improves the processing efficiency.

[0088] In one alternative embodiment, based on the current number of tokens, the overdrawn number of tokens, and the length of the message to be sent in the rate limit configuration table, mark the message to be sent, including: reading the rate limit mode and the priority of the token bucket in the rate limit configuration table; based on the rate limit mode and the priority of the token bucket, successively determine the relationship between the available number of tokens and the number of tokens to be consumed in each token bucket, where the number of tokens to be consumed is the sum of the overdrawn number of tokens and the length of the message to be sent; mark the message to be sent based on the relationship between the available number of tokens and the number of tokens to be consumed in each token bucket and the flag indicating whether overflow to a lower-priority token bucket is allowed.

[0089] Among them, the rate limit mode includes packet rate limit and bit rate limit. Packet rate limit is to limit the rate for the whole packet, regardless of the packet length of the data packet. When rate-limiting, the packet length is a fixed value. As long as the number of tokens in the token bucket is greater than this fixed value, the rate limit passes. This mode can meet the scenarios with rate limit requirements for packet forwarding rate. Bit rate limit means that each bit in the rate-limited traffic requires a token, and the rate limit accuracy is high.

[0090] During rate limiting, first read the corresponding rate limit configuration table according to the instantiated id, and judge whether to rate-limit based on the number of packets. If so, for each packet of the traffic, use a fixed length to deduct the token bucket. In this application, the fixed value is set to 8K bytes; if not, use the actual length of each packet of the traffic to deduct the token bucket.

[0091] Among them, the priority is used to determine the judgment order of the token buckets. For example, first judge the token bucket with a higher priority, and then judge the token bucket with a lower priority. The key point of the judgment process is to determine the relationship between the available number of tokens and the number of tokens to be consumed in each token bucket. The number of tokens to be consumed is the sum of the overdrawn number of tokens and the length of the message to be sent, and mark the message to be sent differently based on the obtained relationship.

[0092] In one alternative embodiment, after marking the message to be sent based on the current token quantity, overdrawn token quantity, and the length of the message to be sent in the speed limit configuration table, the method further includes: determining a target token bucket for processing the message to be sent based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the identifier indicating whether overflow to the low-priority token bucket is allowed; and updating the overdrawn token quantity of the target token bucket based on the overdrawn token quantity of the target token bucket and the length of the message to be sent.

[0093] In addition, after determining the target token bucket for processing the message to be sent, the overdrawn token quantity corresponding to the target token bucket is also updated.

[0094] For ease of understanding, as shown in Figure 3 shown, Figure 3 is a flowchart of the speed limit step in an embodiment. In this embodiment, still taking two token buckets as an example, it should be noted that in the present application, not only can the traffic data (message to be sent) be speed-limited, but also the traffic data can be colored and corresponding actions can be executed, specifically including:

[0095] First, read the corresponding speed limit configuration table according to the instantiated id.

[0096] Second, determine whether to perform speed limit based on the number of packets. If so, for each packet of the traffic, a fixed length is used to deduct the token bucket. In this embodiment, the fixed value is set to 8K bytes, and in other embodiments, it can be other numbers of bytes; if not, the actual length of each packet of the traffic is used to deduct the token bucket.

[0097] Third, it is necessary to determine whether the token quantity in the token bucket can be deducted by the total value of the length of the message to be sent plus the overdrawn token quantity. If it is determined that the token quantity in the first token bucket is less than the length of the message to be sent plus the overdrawn token quantity in the first token bucket, and if the token quantity in the second token bucket is also less than the length of the current message plus the overdrawn token quantity in the second token bucket, then the message to be sent is colored red and the actions corresponding to red are executed. At this time, if the token quantity in the second token bucket is not less than the length of the current message plus the overdrawn token quantity in the second token bucket, then the message is colored yellow and the actions corresponding to yellow are executed. The overdrawn token quantity of the second token bucket plus the length of the message to be sent is used as the new overdrawn token quantity of the second token bucket.

[0098] Fourth, when the token quantity in the first token bucket is not less than the length of the message to be sent plus the overdrawn token quantity in the first token bucket, if it does not support the overflow of the token quantity in the first token bucket to the second token bucket when full, then the message is colored green and the actions corresponding to green are executed. The overdrawn token quantity of the first token bucket plus the length of the message to be sent is used as the new overdrawn token quantity of the first token bucket.

[0099] Fifth, when the number of tokens in the first token bucket is not less than the length of the message to be sent plus the number of overdrawn tokens, and if the number of tokens in the second token bucket is less than the current length of the message to be sent plus the number of overdrawn tokens in the second token bucket, the message is colored red and the action corresponding to red is performed. If the number of tokens in the second token bucket is not less than the current length of the message to be sent plus the number of overdrawn tokens in the second token bucket, the message is colored green and the action corresponding to green is performed. The number of overdrawn tokens in the first token bucket plus the length of the message to be sent is used as the new number of overdrawn tokens in the first token bucket, and the number of overdrawn tokens in the second token bucket plus the length of the message to be sent is used as the new number of overdrawn tokens in the second token bucket.

[0100] In the above embodiment, in the scenario of smart network card, the traffic can be speed-limited or shaped, supporting customized traffic speed-limiting rules and supporting the definition of easily extensible speed-limiting actions, which greatly adapts to QOS and speed-limiting applications in data center or network cloud scenarios.

[0101] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0102] Based on the same inventive concept, the embodiment of the present application also provides a network traffic control device for implementing the network traffic control method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more network traffic control device embodiments provided below can refer to the limitations of the network traffic control method above, and will not be repeated here.

[0103] In an exemplary embodiment, Figure 4 As shown, a network traffic control device is provided, which is applied to a chip including a RISC-V architecture processor core, including: a to-be-updated token quantity determination module 401, a reading module 402, an update module 403, a marking module 404 and a traffic processing module 405, wherein:

[0104] The module 401 for determining the number of tokens to be updated is used to determine the number of tokens to be updated corresponding to the token bucket;

[0105] A reading module 402, configured to read the overdrawn token quantity corresponding to the token bucket in the speed limit configuration table based on the hardware characteristics of the RISC-V design, and read the current token quantity;

[0106] An updating module 403, configured to update the current token quantity in the speed limit configuration table based on the to-be-updated token quantity, the overdrawn token quantity, and the current token quantity;

[0107] A marking module 404, configured to read the speed limit configuration table, and mark the to-be-sent message based on the current token quantity, the overdrawn token quantity, and the length of the to-be-sent message in the speed limit configuration table;

[0108] A traffic processing module 405, configured to process the traffic corresponding to the to-be-sent message based on the actions corresponding to the marks in the speed limit configuration table.

[0109] In one alternative embodiment, the above-mentioned apparatus further includes:

[0110] A configuration module, configured to receive a configuration instruction for the speed limit configuration table, where the configuration instruction includes at least one of a token bucket configuration instruction, a speed limit mode configuration instruction, and a mark-action mapping relationship configuration instruction, and the token bucket configuration instruction is used to configure at least one of the priorities of each token bucket, the token increasing rate in each token bucket, the token bucket size, and whether to allow overflow to a lower-priority token bucket; configure the speed limit configuration table based on the configuration instruction.

[0111] In one alternative embodiment, the above-mentioned to-be-updated token quantity determining module 401 is specifically configured to obtain a pre-configured speed limit configuration table, and read the respective token increasing rates corresponding to each token bucket from the speed limit configuration table; obtain the to-be-updated token quantity corresponding to each token bucket based on the respective token increasing rates.

[0112] In one alternative embodiment, each of the token buckets has a priority; the above-mentioned updating module 403 is specifically configured to, for each token bucket with a certain priority, obtain an initial token quantity based on the to-be-updated token quantity, the overdrawn token quantity, and the current token quantity; wherein, when the priority of the token bucket is not the highest priority and it is allowed that the tokens in a higher-priority token bucket overflow to the token bucket, the current token quantity of the token bucket is updated based on the tokens overflowing from the higher-priority token bucket; correct the initial token quantity to obtain a target token quantity based on the initial token quantity and the token bucket size of the token bucket, and replace the current token quantity corresponding to the token bucket with the target token quantity.

[0113] In one optional embodiment, the above-mentioned marking module 404 is specifically configured to read the speed limit mode and the priority of the token bucket in the speed limit configuration table; based on the speed limit mode and the priority of the token bucket, determine the relationship between the available token quantity and the token quantity to be consumed in each token bucket in sequence, where the token quantity to be consumed is the sum of the overdrawn token quantity and the length of the packet to be sent; based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the flag indicating whether to allow overflow to the low-priority token bucket, mark the packet to be sent.

[0114] In one optional embodiment, the above-mentioned device further includes: an overdrawn token quantity determination module, configured to determine a target token bucket for processing the packet to be sent based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the flag indicating whether to allow overflow to the low-priority token bucket; update the overdrawn token quantity of the target token bucket based on the overdrawn token quantity of the target token bucket and the length of the packet to be sent.

[0115] Each module in the above network traffic control device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0116] In one embodiment, a chip is provided. The chip includes a memory and a processor, and the memory stores a computer program. When the processor executes the computer program, the above access control method is implemented. Among them, the chip can be a Data Processing Unit (DPU) chip.

[0117] In one embodiment, a network interface card is provided. The network interface card includes the above chip and multiple interfaces, and the chip communicates externally through the interfaces. The interfaces include PCI / PCIE interfaces, network interfaces, etc.

[0118] In an exemplary embodiment, a computer device is provided. The computer device includes a processor and the above network interface card. The network interface card is used to schedule the packet to the processor or the network interface card itself for processing, and the processor is used to process the packet scheduled by the network interface card. The computer device can be a server, and its internal structure diagram can be as Figure 5As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store corresponding data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a network traffic control method.

[0119] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0120] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are implemented.

[0121] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0122] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0123] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0124] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, Resistive Random Access Memory (ReRAM), Magnetoresistive Random Access Memory (MRAM), Ferroelectric Random Access Memory (FRAM), Phase Change Memory (PCM), graphene memory, etc. Volatile memory can include Random Access Memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, Artificial Intelligence (AI) processors, etc., without limitation.

[0125] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0126] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A network traffic control method, characterized in that, Applied to a chip including a RISC-V architecture processor core, the method includes: Determine the number of tokens to be updated corresponding to the token bucket; Based on the hardware characteristics designed by RISC-V, clear the overdrawn token number corresponding to the token bucket in the rate limit configuration table and read the current token number; Update the current token number in the rate limit configuration table based on the number of tokens to be updated, the overdrawn token number, and the current token number; Read the rate limit configuration table and mark the message to be sent based on the current token number, the overdrawn token number, and the length of the message to be sent in the rate limit configuration table; Process the message to be sent based on the actions corresponding to each mark in the rate limit configuration table.

2. The method according to claim 1, characterized in that, The method further includes: Receive a configuration instruction for the rate limit configuration table, where the configuration instruction includes at least one of a token bucket configuration instruction, a rate limit mode configuration instruction, and a mark-action mapping relationship configuration instruction. The token bucket configuration instruction is used to configure at least one of the priority of each token bucket, the token increase rate in each token bucket, the token bucket size, and whether to allow overflow to a lower-priority token bucket; Configure the rate limit configuration table based on the configuration instruction.

3. The method according to claim 1, characterized in that, The determination of the number of tokens to be updated corresponding to the token bucket includes: Obtain a pre-configured rate limit configuration table and read the token increase rate corresponding to each token bucket from the rate limit configuration table; Obtain the number of tokens to be updated corresponding to each token bucket based on each token increase rate.

4. The method according to claim 1, wherein Each of the token buckets has a priority; the update of the current token number in the rate limit configuration table based on the number of tokens to be updated, the overdrawn token number, and the current token number includes: For each token bucket with a specific priority, obtain an initial token number based on the number of tokens to be updated, the overdrawn token number, and the current token number. Wherein, when the priority of the token bucket is not the highest priority and it is allowed that the tokens in a higher-priority token bucket overflow to this token bucket, the current token number of this token bucket is updated based on the tokens overflowing from the higher-priority token bucket; Correct the initial token number based on the initial token number and the token bucket size of the token bucket to obtain a target token number, and replace the current token number corresponding to the token bucket with the target token number.

5. The method according to any one of claims 1 to 4, characterized in that The marking of the message to be sent based on the current token number, the overdrawn token number, and the length of the message to be sent in the rate limit configuration table includes: Read the rate limit mode in the rate limit configuration table and the priority of the token bucket; Based on the rate limit mode and the priority of the token bucket, sequentially determine the relationship between the available token number and the token number to be consumed in each token bucket. The token number to be consumed is the sum of the overdrawn token number and the length of the message to be sent; Mark the message to be sent based on the relationship between the available token number and the token number to be consumed in each token bucket and the identifier indicating whether overflow to a lower-priority token bucket is allowed.

6. The method according to claim 5, characterized in that, After marking the message to be sent based on the current token quantity, the overdrawn token quantity, and the length of the message to be sent in the speed limit configuration table, it further includes: Determining a target token bucket for processing the message to be sent based on the relationship between the available token quantity and the token quantity to be consumed in each token bucket and the identifier indicating whether overflow to the low-priority token bucket is allowed; Updating the overdrawn token quantity of the target token bucket based on the overdrawn token quantity of the target token bucket and the length of the message to be sent.

7. A network traffic control device, characterized in that, Applied to a chip including a RISC-V architecture processor core, the device includes: A to-be-updated token quantity determination module, configured to determine the to-be-updated token quantity corresponding to the token bucket; A reading module, configured to clear the overdrawn token quantity corresponding to the token bucket in the speed limit configuration table and read the current token quantity based on the hardware characteristics designed by RISC-V; An updating module, configured to update the current token quantity in the speed limit configuration table based on the to-be-updated token quantity, the overdrawn token quantity, and the current token quantity; A marking module, configured to read the speed limit configuration table and mark the message to be sent based on the current token quantity, the overdrawn token quantity, and the length of the message to be sent in the speed limit configuration table; A traffic processing module, configured to process the message to be sent based on the actions corresponding to each mark in the speed limit configuration table.

8. A chip, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A network interface card, characterized in that, Including the chip according to claim 8 and multiple interfaces, and the chip processes data or communicates externally through the interfaces.

10. A computer device, characterized in that, Including the network interface card according to claim 9, and the network interface card is used to process data or communicate externally.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 6.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Token processing method and device

    CN106453127A

  • Traffic control method and device, electronic equipment and computer readable storage medium

    CN113992594A

  • Traffic management method and device, electronic equipment and storage medium

    CN116455828A

  • Traffic speed limiting method and device, electronic equipment and storage medium

    CN116708315A

  • Method for realizing lock-free speed limit through multi-core dynamic rate adjustment

    CN117880208A