Flow table optimization processing method and system

By introducing query unit identification and logical subtable identification in flow table processing, the query bit width is dynamically adjusted, which solves the problems of intensifying inter-protocol interference and low efficiency in traditional flow table processing, and realizes efficient and secure multi-protocol traffic processing.

CN120354443APending Publication Date: 2025-07-22SONGSHAN LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510219934.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Traditional flow table processing methods are difficult to effectively isolate and efficiently process multiple protocol traffic, resulting in low processing efficiency and poor data security, especially when the traffic load increases between protocols.

Method used

By introducing query unit identification, modal type identification and logical subtable identification, the query bit width is dynamically adjusted to realize independent flow table resource processing for different network protocols, ensuring that each protocol uses independent flow table space, avoid inter-protocol interference, and match logical subtables in parallel to improve query efficiency.

Benefits of technology

It significantly improves the efficiency and security of flow table processing, realizes differentiated processing of multi-protocol traffic and resource isolation, avoids interference between protocols, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354443A_ABST
    Figure CN120354443A_ABST
Patent Text Reader

Abstract

The invention provides a flow table optimization processing method and system, and the method comprises the steps: obtaining a flow table query request which comprises a keyword, a protocol type and a query style of a to-be-queried flow table item; according to the protocol type, obtaining a query unit identifier, a modal type identifier and a logic sub-table identifier corresponding to the to-be-queried flow table item in a flow table deployment record; determining a first target query block unit to which the to-be-queried flow table item belongs according to the query unit identifier; according to the query style, dynamically adjusting the query bit width of the first target query block unit, and according to the adjusted query bit width, the modal type identifier and the logic sub-table identifier, searching a TCAM core of the first target query block unit for a first target logic sub-table matched with the protocol type and the flow table item type of the to-be-queried flow table item; and querying the data content of the to-be-queried flow table item in the first target logic sub-table according to the keyword. According to the method, the multi-mode network is supported, and the flow table processing efficiency is optimized while the data security is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technologies, and in particular, to a method and system for optimizing flow table processing. Background Art

[0002] With the progress of network technologies, modern networks have gradually shifted to a multi-modal environment, including the processing of protocol traffic supporting multiple protocols. In a multi-modal network environment, the processing methods for different protocol traffic vary greatly.

[0003] Traditional flow table processing methods often uniformly process protocol traffic of multiple protocols without distinction using a ternary content-addressable memory (TCAM), making it difficult to effectively isolate and efficiently process multiple protocol traffic, and to solve the problem of increased interference between protocols when the traffic load increases. As a result, the flow table processing efficiency is low and the data security is poor.

[0004] Therefore, there is an urgent need for a method and system for optimizing flow table processing to solve the above technical problems. Summary of the Invention

[0005] The present invention provides a method and system for optimizing flow table processing to solve the defects in the prior art that it is difficult to effectively isolate and efficiently process multiple protocol traffic, and to solve the problem of increased interference between protocols when the traffic load increases. It realizes simple and convenient independent flow table resource processing for different network protocols, thereby achieving resource isolation between protocols, ensuring data security and improving processing efficiency.

[0006] The present invention provides a method for optimizing flow table processing, including: Obtaining a flow table query request; the flow table query request includes the keyword of the flow table entry to be queried, the network modal protocol type of the flow table entry to be queried, and the query style; According to the network modal protocol type, obtaining the query unit identifier, modal type identifier, and logical sub-table identifier corresponding to the flow table entry to be queried in the flow table deployment record; According to the query unit identifier, determining the first target query block unit to which the flow table entry to be queried belongs in the query system; According to the query style, dynamically adjusting the query bit width of the first target query block unit, and according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier, searching for the first target logical sub-table that matches the network modal protocol type and flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit; Querying the data content of the flow table entry to be queried in the first target logical sub-table according to the keyword.

[0007] A flow table optimization processing method provided by the present invention, wherein the query unit identifier includes a query module identifier and a query block identifier; Determining, according to the query unit identifier, a first target query block unit to which the to-be-query flow table entry belongs in a query system includes: Determining, according to the query module identifier, a target query module unit to which the to-be-query flow table entry belongs in the query system; Determining the first target query block unit from among a plurality of query block units included in the target query module unit according to the query block identifier.

[0008] A flow table optimization processing method provided by the present invention, wherein searching, according to the adjusted query bit width, the modality type identifier, and the logical sub-table identifier, for a first target logical sub-table that matches the network modality protocol type and the flow table entry type of the to-be-query flow table entry in a TCAM core in the first target query block unit includes: Determining at least one target TCAM core in the first target query block unit according to the adjusted query bit width; Based on at least one of the target TCAM cores, parallelly matching the modality type identifier and the logical sub-table identifier with the modality type identifier and the logical sub-table identifier of each logical sub-table in the TCAM core of the first target query block unit to obtain at least one candidate logical sub-table that matches the network modality protocol type and the flow table entry type of the to-be-query flow table entry; Determining the first target logical sub-table from among at least one of the candidate logical sub-tables according to the priority encoding address of each candidate logical sub-table.

[0009] A flow table optimization processing method provided by the present invention, the method further includes: When an update request for the flow table query request is received in the current cycle, determining the cycle type to which the current cycle belongs and the operating status of each TCAM core in the query system; When it is determined that the current cycle belongs to a non-query cycle and the operating status of each TCAM core in the query system is an idle state, updating the flow table query request according to the update request; When it is determined that the current cycle belongs to a query cycle, or the operating status of any one TCAM core in the query system is a working state, prohibiting the update of the flow table query request.

[0010] A flow table optimization processing method provided by the present invention, the method further includes: Receiving a flow table deployment request; the flow table deployment request includes the network modality protocol type of the to-be-deployed flow table entry and the to-be-deployed data content; According to the resource occupancy of each query block unit in the query system, determine a second target query block unit in the query system for processing the flow table deployment request; Determine the query bit width of the second target query block unit according to the network modal protocol type of the flow table entry to be deployed; According to the query bit width of the second target query block unit, determine a target configuration style among multiple supported configuration styles of the second target query block unit; Determine the flow table resource address of the flow table entry to be deployed according to the target configuration style, the network modal protocol type and the flow table entry type of the flow table entry to be deployed; Write the data content to be deployed into a second target logic sub-table in the TCAM core of the second target query block unit according to the flow table resource address; When it is determined that the deployment of the flow table entry to be deployed is completed, establish an association relationship between the modal type identifier and the logic sub-table identifier corresponding to the second target logic sub-table, the query unit identifier corresponding to the second target query block unit, and the network modal protocol type of the flow table entry to be deployed, and update the association relationship to the flow table deployment record.

[0011] According to a flow table optimization processing method provided by the present invention, the method further includes: Store the modal type identifier and the logic sub-table identifier corresponding to the second target logic sub-table as header information in the high-order part of the target column of the TCAM core of the second target query block unit; Wherein, the target column is the column to which the second target logic sub-table belongs; the high-order part is multiple bit positions with a higher address bit sorting.

[0012] According to a flow table optimization processing method provided by the present invention, the method further includes: Obtain a query result corresponding to the flow table query request; Feed back the query result to the upper protocol stack of the query system through the output path of the first target query block unit to perform data processing on the data content of the flow table entry to be queried; Wherein, the data processing includes at least one of forwarding, modifying and discarding.

[0013] The present invention also provides a flow table optimization processing system, including: An obtaining unit, configured to obtain a flow table query request; the flow table query request includes a keyword, a network modal protocol type and a query style of a flow table entry to be queried; A configuration unit is used to obtain, in the flow table deployment record, the query unit identifier, the modality type identifier, and the logical sub-table identifier corresponding to the to-be-query flow table entry according to the network modality protocol type; A first query unit is used to determine, in the query system, the first target query block unit to which the to-be-query flow table entry belongs according to the query unit identifier; A second query unit is further used to dynamically adjust the query bit width of the first target query block unit according to the query style, and to search, in the TCAM core in the first target query block unit, for a first target logical sub-table that matches the network modality protocol type and the flow table entry type of the to-be-query flow table entry according to the adjusted query bit width, the modality type identifier, and the logical sub-table identifier; A processing unit is used to query, in the first target logical sub-table, the data content of the to-be-query flow table entry according to the keyword.

[0014] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the flow table optimization processing method as described in any one of the above is implemented.

[0015] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the flow table optimization processing method as described in any one of the above is implemented.

[0016] The present invention further provides a computer program product, including a computer program. When the computer program is executed by a processor, the flow table optimization processing method as described in any one of the above is implemented.

[0017] The flow table optimization processing method and system provided by the present invention obtain the keyword, the network modality protocol type, and the query style in the flow table query request, and allocate independent query unit identifiers, modality type identifiers, and logical sub-table identifiers according to the network modality protocol type, so as to simply and conveniently perform independent flow table resource processing for different network protocols by combining the query unit identifier, the modality type identifier, and the logical sub-table identifier, realize differential processing, independent processing, and flow table resource isolation of different protocol traffic, enable each protocol to use an independent flow table space during the query process, avoid interference between flow table entries of different protocols, ensure data security, and at the same time dynamically adjust the query bit width according to the query style to optimize the query efficiency and hardware resources, thereby effectively solving the problems of increased interference between protocols, low processing efficiency, and poor data security in the traditional flow table processing method, and significantly improving the efficiency and security of flow table processing. Description of the Drawings

[0018] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0019] Figure 1 It is one of the flow chart diagrams of the flow table optimization processing method provided by the present invention.

[0020] Figure 2 It is the structural diagram of the query system provided by the present invention.

[0021] Figure 3 It is the second flow chart diagram of the flow table optimization processing method provided by the present invention.

[0022] Figure 4 It is the first flow chart diagram of the flow table deployment steps provided by the present invention.

[0023] Figure 5 It is the second flow chart diagram of the flow table deployment steps provided by the present invention.

[0024] Figure 6 It is the structural diagram of the flow table optimization processing system provided by the present invention.

[0025] Figure 7 It is the structural diagram of the electronic device provided by the present invention. Detailed implementation manners

[0026] To make the objectives, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0027] With the progress of network technology, modern networks have gradually shifted towards a multi-modal environment, which can support the processing of data streams of multiple protocols, such as Internet Protocol Version 4 (IPv4), Internet Protocol Version 6 (IPv6), Named Data Networking (NDN), Multi-Frequency Network Protocol (MF), etc., and can also support the processing of data streams of different traffic types, such as voice, video, data, etc. In a multi-modal network environment, the query and processing methods for different protocol traffic vary greatly. Traditional flow table configuration methods often fail to effectively support the isolation and efficient processing of multiple protocol traffic. Especially when the traffic load increases, the interference problem between different protocols becomes more prominent. In order to improve the query efficiency, resource utilization rate, and data security of network devices, how to achieve the isolation and independent processing of flow table entries at the hardware level has become an important issue in the design of current network devices.

[0028] Since TCAM has been widely used in high-speed network devices, in related technologies, TCAM is proposed as a hardware component for accelerating flow table queries to perform flow table processing. Although TCAM has efficient parallel query capabilities, conventional ternary content-addressable memories can often only uniformly process the protocol traffic of multiple protocols without discrimination, making it difficult to effectively isolate and efficiently process multiple protocol traffic, and to solve the problem of increased interference between protocols when the traffic load increases. As a result, the flow table processing efficiency is low and the data security is poor. Therefore, in a multi-protocol, multi-modal network environment, how to effectively achieve protocol isolation, ensure the independent operation of flow table resources, while improving the processing efficiency and data security, remains a bottleneck in the current technological development of the industry.

[0029] In response to this, the present application provides a flow table optimization processing method, which is a method that supports multi-modal networks and can optimize flow table processing through resource isolation technology and support for different query bit widths. By introducing a query unit identifier, a modal type identifier, and a logical sub-table identifier in the process of flow table processing, it can simply and conveniently perform independent flow table resource processing for different network protocols, thereby realizing the query and flow table resource isolation of multiple network modal protocol types, especially suitable for flow table query and management in network devices, to provide efficient query processing and flow table resource isolation in a multi-modal network environment, effectively improving the query efficiency and security of network devices.

[0030] Figure 1It is one of the flow chart diagrams of the flow table optimization processing method provided by the present invention. The execution subject of this method can be a network device, and the network device here can be a switch, a virtualized network device, etc., and this embodiment does not make specific limitations in this regard. This method is effectively applicable to the independent query of different protocol traffic in a multi-modal network environment, ensuring resource isolation between traffic and improving data security and network stability; the multi-modal network environment here includes but is not limited to network protocols such as IPv4, IPv6, Segment Routing over IPv6 (SRv6), NDN, MF, and satellite network (GEO).

[0031] As Figure 1 shown, the flow table optimization processing method specifically includes step 110, step 120, step 130, step 140, and step 150.

[0032] Step 110, obtain a flow table query request; the flow table query request includes the keyword of the flow table entry to be queried, the network mode protocol type, and the query style.

[0033] The flow table query request here is used to request a flow table query. It can be user input entered by the user on the front-end interface, or information generated by other controllers or other devices under certain conditions, such as a flow table query request triggered regularly. The so-called user input can be information input through a command-line interface, a graphical interface, a touch input, a drop-down selection input, a voice input, a gesture input, a visual input, a brain-computer input, etc., and this embodiment does not make specific limitations in this regard.

[0034] Optionally, the network device can obtain the flow table query request in real time through the flow table query request interface bus. At least the keyword of the flow table entry to be queried, the network mode protocol type, and the query style are carried in the flow table query request here.

[0035] Among them, the keyword of the flow table entry to be queried is used to identify the characteristics of the flow table entry to be queried, including but not limited to the target Internet Protocol (IP) address, the source IP address, the port number, etc., and this embodiment does not make specific limitations in this regard.

[0036] The network mode protocol type is used to indicate which network protocol the data to be queried for the flow table entry belongs to, such as it can be network protocols such as IPv4, IPv6, SRv6, NDN, MF, or GEO.

[0037] The query style refers to the configuration style that supports different query bit widths. For example, it can be at least one of the 15 configuration styles from CFG00 to CFG14, and can be adaptively and dynamically configured according to the actual query requirements of the flow table entries to be queried. That is, the query bit width of each query unit can be dynamically adjusted according to the network modal protocol type. For example, the IPv4 protocol requires an 80-bit query bit width, while the IPv6 or MPLS protocol requires a 160-bit or wider query bit width.

[0038] Among them, CFG00:80Wx128D is the default configuration style, which specifically represents a configuration style with a width of 80 bits and a depth of 128 entries. CFG01 / CFG02 / CFG03:160Wx64D, which specifically represents a configuration style with a width of 160 bits and a depth of 64 entries. CFG04 / CFG05 / CFG06 / CFG07 / CFG08 / CFG09:160Wx32D+80Wx64D, which specifically represents a mixed bit width configuration style, where one part has a width of 160 bits and 32 entries, and the other part has a width of 80 bits and 64 entries. CFG10 / CFG11 / CFG12 / CFG13:240Wx32D+80Wx32D, which specifically represents a mixed bit width configuration style, where one part has a width of 240 bits and 32 entries, and the other part has a width of 80 bits and 32 entries. CFG14:320Wx32D, which specifically represents a configuration style with a width of 320 bits and a depth of 32 entries.

[0039] Step 120, according to the network modal protocol type, obtain the query unit identifier, modal type identifier, and logical sub-table identifier corresponding to the flow table entry to be queried in the flow table deployment record.

[0040] Optionally, after receiving the flow table query request, it may be to parse the network modal protocol type field in the flow table query request to obtain the network modal protocol type of the flow table entry to be queried. For example, IPv4 or IPv6, etc. Then, based on the network modal protocol type of the flow table entry to be queried, in the flow table deployment record, the configuration information associated with the flow table entry to be queried is obtained. The configuration information specifically includes the query unit identifier, modal type identifier, and logical sub-table identifier corresponding to the flow table entry to be queried. Here, the flow table deployment record refers to the record information generated during the flow table deployment process, which at least includes the association relationship between the network modal protocol type of each flow table entry established during the configuration process and the query unit identifier, modal type identifier, and logical sub-table identifier. For example, IPv4 maps the modal type ID number to 0 according to its type field 0x0800, which is used to support the deployment of multiple network modal logical sub-tables on the same physical resource.

[0041] Among them, the query unit identifier (also called query unit ID) can be constructed by one or more identifiers, which is used to identify different query units. Through the query unit identifier, the location of the flow table entry to be queried can be quickly located, thereby improving the query efficiency.

[0042] The modal type identifier (also called modal type ID) is used to distinguish different network modal protocol types, and the logical sub-table identifier (also called logical sub-table ID) is used to distinguish the flow table entries of the logical sub-table. The two together achieve the logical isolation of the flow table entries of different network protocol logical sub-tables on the same physical resource to ensure that the queries between different network protocol traffic do not interfere with each other.

[0043] Step 130, according to the query unit identifier, determine the first target query block unit to which the flow table entry to be queried belongs in the query system.

[0044] Here, the query system is a hardware architecture based on the TCAM core. The specifications of each TCAM core can be set according to actual needs. For example, the specifications of each TCAM core can be 80-bit x 32D, that is, each TCAM core supports a query bit width of 80-bit (that is, the bit width of each entry is fixed at 80-bit) and stores 32-depth flow table entries.

[0045] The query system includes at least two levels of query units, namely, a first-level query module unit (also referred to as a query group unit) and a second-level query block unit (also referred to as a query bank unit). Specifically, the query system is composed of multiple query group units; each query group unit is composed of multiple query bank units, and the specific quantity can be set according to actual requirements. For example, each query group unit is composed of 4 query bank units; each query bank unit is composed of multiple TCAM cores, and the specific quantity can be set according to actual requirements. For example, each query bank unit is composed of 4 TCAM cores. When the software configuration uses a TCAM entry as the minimum query unit, a query bank unit can accommodate up to 128 flow table entries; when the software configuration uses a TCAM block as the minimum query unit, a query bank unit can support different query bit widths, such as 80-bit, 160-bit, 240-bit, or 320-bit, etc., and there are 15 configuration styles from CFG00 to CFG14. That is, each query block unit has flexible and variable query bit width and configuration style support, and its query bit width and configuration style can be flexibly extended to support flow table queries with different scales and different protocol requirements.

[0046] Figure 2 It is a schematic structural diagram of the query system provided by the present invention; as Figure 2 It shows the composition of the query group unit and the query bank unit, as well as the composition structure of the query bank unit and the relationship between each TCAM core. Thus, query unit management can be carried out through the query group unit ID and the query bank unit ID.

[0047] Figure 3 It is the second schematic flowchart of the flow table optimization processing method provided by the present invention; as Figure 3 As shown, after obtaining the query unit identifier, it can be to locate the query block unit corresponding to the query unit identifier in the query system, that is, to locate the query block unit accessed by the flow table query request of the flow table entry to be queried, so as to determine it as the first target query block unit to which the flow table entry to be queried belongs; the first target query block unit here can be one or more, and can be specifically determined according to the quantity of the query unit identifier and the identifier association content. For example, when the flow table entry to be queried corresponds to one network modal protocol type, one or more query block units can be scheduled to process the flow table query request. For example, when the flow table entry to be queried corresponds to multiple network modal protocol types, multiple query units can be scheduled to process traffic of different protocols.

[0048] Step 140: Dynamically adjust the query bit width of the first target query block unit according to the query style, and in the TCAM core of the first target query block unit, look up the first target logic sub-table that matches the network modal protocol type and flow table entry type of the to-be-query flow table entry according to the adjusted query bit width, the modal type identifier, and the logic sub-table identifier. Step 150: Query the data content of the to-be-query flow table entry in the first target logic sub-table according to the keyword.

[0049] It should be noted that during the flow table configuration process, multiple logic sub-tables of different network modalities can be deployed in the TCAM core of each query bank unit. By allocating independent logic sub-tables for each protocol, each logic sub-table can use independent resources, thereby realizing effective isolation and flexible deployment of flow table resources, ensuring that data packets of different protocols will not be cross-queryed, improving data isolation and data security, and further enabling only the flow table entries corresponding to the protocol to be accessed during the flow table query process, without being interfered by the traffic of other protocols.

[0050] Therefore, as Figure 3 shown, after obtaining the flow table query request, it can also be to parse the query style field and keyword field in the flow table query request to obtain the query style and keyword of the to-be-query flow table entry. After obtaining the query style and keyword, it can be to dynamically adjust the query bit width of the first target query block unit according to the configured query style to determine the mode of the query operation. And, call the first target query block unit, and match the logic sub-table associated with the modal type identifier and the logic sub-table identifier in the TCAM core of the first target query block unit according to the query operation mode corresponding to the adjusted query bit width, so that the query request is correctly directed to the sub-table that matches its network protocol, to locate the sub-table required for processing the flow table query request by the network device, and then accurately find the first target logic sub-table that matches the network modal protocol type and flow table entry type of the to-be-query flow table entry, thereby realizing matching only the sub-table associated with the network modal protocol type and flow table entry type, improving the precise scheduling of the query, effectively avoiding resource conflicts or query interference between different network protocols, and thus effectively ensuring the isolation and security of the flow table resources.

[0051] After obtaining the first target logic sub-table, it can be to query the data content that matches the keyword in the first target logic sub-table according to the keyword. The mode of the query operation here can be parallel query of multiple TCAM cores or single TCAM core query, and can be flexibly configured according to the query requirements corresponding to the adjusted query bit width.

[0052] Once the data content matching the keyword is found, the matching data content is read out through the flow table entry reading interface bus and used as the data content of the flow table entry to be queried, and a query result including the data content of the flow table entry to be queried is generated; if the data content matching the keyword is not found, a query result including fields such as "query failed" or "not matched" is generated. The data content here can be data operation content, such as the next-hop address or the next-hop action, etc.

[0053] It should be noted that the flow table query request here can also carry a query mode, so as to determine the matching mode adaptively according to the query model in the associated query, and then perform keyword matching according to the determined matching mode, so as to more flexibly process complex query requirements and improve the accuracy and efficiency of the query. Exemplarily, the query mode here can include exact matching or fuzzy matching. Among them, fuzzy matching is to perform partial matching by setting a bit mask to ignore the values of some field bits in the keyword; exact matching requires that each field in the keyword needs to be exactly the same as the corresponding field in the first target logical sub-table without ignoring any bit.

[0054] In addition, after obtaining the query result, the query result can be returned as response information through the flow table query response interface bus for subsequent data stream processing, such as discarding the data packet or forwarding it to the default route.

[0055] Exemplarily, in some embodiments, after processing the flow table query request, the method further includes: Obtaining the query result corresponding to the flow table query request; Feeding back the query result to the upper protocol stack of the query system through the output path of the first target query block unit to perform data processing on the data content of the flow table entry to be queried; Wherein, the data processing includes at least one of forwarding, modifying, and discarding.

[0056] Optionally, after obtaining the query result corresponding to the flow table query request, the query result can be fed back to the upper protocol stack of the query system through the output path of the first target query block unit for subsequent processing of the data packet, such as forwarding, modifying, or discarding the data content of the flow table entry to be queried, thereby realizing efficient processing of the data packet.

[0057] The method provided in this embodiment obtains the keyword, network modal protocol type, and query style in the flow table query request, and assigns independent query unit identifiers, modal type identifiers, and logical sub-table identifiers according to the network modal protocol type. By combining the query unit identifier, modal type identifier, and logical sub-table identifier, it can simply and conveniently perform independent flow table resource processing for different network protocols, realizing differential processing, independent processing, and flow table resource isolation of different protocol traffic, enabling each protocol to use an independent flow table space during the query process, avoiding interference between flow table entries of different protocols, ensuring data security, and dynamically adjusting according to the query style. Thus, it effectively solves the problems of increased interference between protocols, low processing efficiency, and poor data security in traditional flow table processing methods, and significantly improves the efficiency and security of flow table processing.

[0058] In some embodiments, the query unit identifier includes a query module identifier and a query block identifier; Optionally, the query unit identifier can be composed of a query module identifier (also referred to as a query group ID) and a query block identifier (also referred to as a query bank ID) to hierarchically identify different query units, thereby quickly locating the position of the flow table entry to be queried and improving the query efficiency.

[0059] Correspondingly, step 130 specifically includes: According to the query module identifier, determine the target query module unit to which the flow table entry to be queried belongs in the query system; According to the query block identifier, determine the first target query block unit among the multiple query block units included in the target query module unit.

[0060] It should be noted that each query block unit has a unique combination of query group ID number and query bank ID, and this group of ID numbers is used to quickly index to the query block unit during the flow table query process.

[0061] Therefore, during the query block unit positioning process, the query group ID can be used as the first-level matching identifier in the table lookup process to match the target query module unit to which the flow table entry to be queried belongs in the query system, and then the query bank ID can be used as the second-level matching identifier in the table lookup process to efficiently locate the query bank unit where the flow table entry to be queried is located, that is, the first target query block unit, without traversing the entire query unit one by one, greatly improving the flow table query efficiency.

[0062] In some embodiments, step 140 specifically includes: According to the adjusted query bit width, determine at least one target TCAM core in the first target query block unit; Based on at least one of the target TCAM cores, the mode type identifier and the logical sub - table identifier are parallelly and correspondingly matched with the mode type identifiers and logical sub - table identifiers of each logical sub - table in the TCAM core of the first target query block unit to obtain at least one candidate logical sub - table that matches the network mode protocol type and the flow - table entry type of the to - be - queried flow - table entry; According to the priority - encoded addresses of each candidate logical sub - table, the first target logical sub - table is determined among at least one of the candidate logical sub - tables.

[0063] Optionally, after the first target query block unit is located, the query style, mode type identifier, logical sub - table identifier, and keyword can be routed to the first target query block unit to call the first target query block unit to dynamically adjust the query bit - width of the first target query block unit according to the query bit - width corresponding to the query style, and based on the adjusted query bit - width, at least one target TCAM core capable of processing the flow - table query request is determined in the first target query block unit, and the following query operations are parallelly executed through at least one target TCAM core: The mode type identifier and the logical sub - table identifier are correspondingly matched with the mode type identifiers and logical sub - table identifiers of each logical sub - table stored in each row of the TCAM core of the first target query block unit, so as to determine the matched logical sub - table as a candidate logical sub - table that matches the network mode protocol type and the flow - table entry type of the to - be - queried flow - table entry.

[0064] Moreover, when the number of candidate logical sub - tables is one, the candidate logical sub - table is directly located as the first target logical sub - table; when the number of candidate logical sub - tables is multiple, one candidate logical sub - table can be located among the multiple candidate logical sub - tables as the first target logical sub - table according to the priority - encoded addresses of each candidate logical sub - table. For example, a candidate logical sub - table with a higher priority - encoded address bit can be located as the first target logical sub - table.

[0065] The priority - encoded addresses of each candidate logical sub - table here can be encoded and determined by the priority encoder unit in the first target query block unit, which is used to represent the priority order of each candidate logical sub - table when processing the flow - table query request.

[0066] It should be noted that during the parallel query process of multiple TCAM cores, since each TCAM core stores at most 32 flow - table entries, each TCAM core can perform the matching operation of 32 flow - table entries at the same moment, which can effectively improve the processing efficiency of flow - table optimization.

[0067] The method provided in this embodiment uses a flexible query bandwidth and a priority-encoded address to perform an efficient and accurate parallel matching mechanism for the TCAM core, thereby significantly improving the flow table query efficiency, reducing interference between protocols, and optimizing traffic load processing.

[0068] In some embodiments, the method further includes: When an update request for the flow table query request is received in the current cycle, determine the cycle type to which the current cycle belongs and the operating status of each TCAM core in the query system; When it is determined that the current cycle belongs to a non-query cycle and the operating status of each TCAM core in the query system is an idle state, update the flow table query request according to the update request; When it is determined that the current cycle belongs to a query cycle, or the operating status of any TCAM core in the query system is a working state, prohibit updating the flow table query request.

[0069] It should be noted that a flow table configuration register interface is configured in the network device. This interface can be used to receive update requests for the flow table query request in real time, and can configure and update the query style (such as 15 configuration styles from CFG00 to CFG14), query mode (fuzzy matching or exact matching), and query unit ID (including query group ID and query bank ID) of the flow table query request according to the update request. It can also provide functions for writing and deleting flow table entries, as well as providing a flow table query interface function.

[0070] The cycle type here includes a non-query cycle or a query cycle, and the operating status includes an idle state or a working state.

[0071] Optionally, when the flow table configuration register interface receives an update request for the flow table query request, it can determine the cycle type to which the current cycle belongs and the operating status of each TCAM core in the query system, so that when it is determined that the current cycle belongs to a non-query cycle and the operating status of each TCAM core in the query system is an idle state, the flow table query request can be updated according to the update content in the update request, such as switching the query style, query mode, etc. When it is determined that the current cycle belongs to a query cycle or the operating status of any TCAM core in the query system is a working state, updating the flow table query request is prohibited. Thus, by allowing the flow table query request to be updated in a non-query cycle and when the TCAM core is in an idle state, and at the same time using the flow table configuration register interface to achieve dynamic configuration of the query style, mode, etc., it is possible to flexibly adapt to the flow table update requirements while ensuring the query efficiency, avoid query cycle conflicts and resource occupation, and thus optimize the flow table processing performance.

[0072] In some embodiments, the method further includes: Receive a flow table deployment request; the flow table deployment request includes the network modal protocol type of the flow table entry to be deployed and the data content to be deployed. According to the resource occupancy of each query block unit in the query system, determine a second target query block unit in the query system to process the flow table deployment request. Determine the query bit width of the second target query block unit according to the network modal protocol type of the flow table entry to be deployed. Determine a target configuration style from multiple supported configuration styles of the second target query block unit according to the query bit width of the second target query block unit. Determine the flow table resource address of the flow table entry to be deployed according to the target configuration style, the network modal protocol type of the flow table entry to be deployed, and the flow table entry type. Write the data content to be deployed into a second target logic sub-table in the TCAM core of the second target query block unit according to the flow table resource address. When it is determined that the deployment of the flow table entry to be deployed is completed, establish an association relationship between the modal type identifier and the logic sub-table identifier corresponding to the second target logic sub-table, the query unit identifier corresponding to the second target query block unit, and the network modal protocol type of the flow table entry to be deployed, and update the association relationship to the flow table deployment record.

[0073] Figure 4 It is one of the schematic flowcharts of the flow table deployment steps provided by the present invention; as Figure 4 shown, in addition to the TCAM core, each query bank unit also includes a peripheral control part, including but not limited to a TCAM configuration unit, a key generator unit, a TCAM core query control unit, a priority encoder unit, a TCAM core read / write configuration unit, etc. Among them, the TCAM configuration unit is used to obtain configuration data, including but not limited to a query group ID, a query bank ID, and a network modal protocol type, etc. The key generator unit is used to parse the keyword or data content of the flow table entry from the request; the TCAM core query control unit is used to perform query unit positioning according to the query group ID and query bank ID in the configuration data, and control the TCAM core in the located query unit; the priority encoder unit can perform priority re-encoding on the request processing result to give priority to the processing result with a higher priority. The TCAM core read / write configuration unit is used to perform precise writing and reading of the flow table entry.

[0074] Therefore, through the above-mentioned peripheral control unit, each query bank unit can implement functions such as writing and reading flow table entries, request parsing function, request processing result recoding function, etc. For example, in the process of writing flow table entries, the upper-layer network can send configuration data through the configuration path, so that each query bank unit can obtain the query group ID and query bank ID, and determine whether it is the configuration data within the current query group unit according to the query group ID, and then perform secondary matching of the query bank ID. When a specific query bank unit is matched, according to the network mode protocol type and flow table entry type, the data content of the flow table entry to be routed to a specific column of a specific TCAM core among the 4 internal TCAM cores is parsed, so as to achieve the precise configuration function of the flow table entry.

[0075] Figure 5 is the second schematic diagram of the flow chart of the flow table deployment steps provided by the present invention; as Figure 5 shown, in the process of flow table deployment, the network device can first receive a flow table deployment request, which can be user input entered by the user through the front end, or can be triggered periodically by other devices. This embodiment does not make specific limitations on this.

[0076] After receiving the flow table deployment request, the network device can call one or more query bank units according to the network mode protocol type in the flow table deployment request, so as to use the peripheral control unit inside the query bank unit to cooperate to execute the following flow table deployment process: Parse and obtain the network mode protocol type of the flow table entry to be deployed and the data content to be deployed from the flow table deployment request. The data content to be deployed here, that is, the data content of the flow table entry to be deployed, includes but is not limited to matching information such as the destination IP, source IP, port number, etc., and the corresponding operations or forwarding actions.

[0077] In addition, according to the resource occupancy of each query block unit in the query system, the query system determines the second target query block unit that can process the flow table deployment request. For example, the query block unit with the least resource occupancy can be determined as the second target query block unit, etc., to ensure that the flow table deployment request is allocated to a query block unit with sufficient resources and optimal performance, and avoid resource conflicts and performance bottlenecks.

[0078] In addition, identify the network mode protocol type of the flow table entry to be deployed, so as to flexibly configure the query bit width of the second target query block unit according to the network mode protocol type. For example, in the IPv4 protocol, since the header field is small, the query bit width can be configured to 80 bits, while in the IPv6 protocol, since the field is large, the query bit width is configured to 160 bits, and MPLS can be configured with a 320-bit query bit width.

[0079] After determining the query bit width, it is possible to further determine the target configuration style among multiple configuration styles supported by the second target query block unit (such as 15 configuration styles from CFG00 to CFG14), so as to allocate corresponding flow table resource addresses for the flow table entries to be deployed according to the target configuration style, the network modal protocol type of the flow table entries to be deployed, and the flow table entry type, so as to allocate flow table entries of different protocols to different logical sub-tables. Specifically, it can be to independently write the data content to be deployed into the second target logical sub-table in the TCAM core of the second target query block unit according to the flow table resource address, thereby realizing the isolated storage of flow table resources under different protocols.

[0080] When it is determined that the deployment of the flow table entries to be deployed is completed, establish the association relationship between the modal type identifier and the logical sub-table identifier corresponding to the second target logical sub-table, the query unit identifier corresponding to the second target query block unit, and the network modal protocol type of the flow table entries to be deployed, and update this association relationship to the flow table deployment record in real time, so as to identify the data content of each flow table entry through the modal type ID and the logical sub-table ID, thereby ensuring the independent storage of flow table entries between protocols and facilitating subsequent queries to independently process flow table resources for different network protocols based on the modal type identifier, the logical sub-table identifier, and the query unit identifier, and further effectively improving the query efficiency and security of the flow table.

[0081] In the actual configuration process, according to the above flow table configuration steps, the flow table resources of different network modalities can be isolated and deployed simultaneously. For example, the flow table entries of modalities such as IPv4, IPv6, SRv6, NDN, MF, and GEO can be deployed simultaneously. As Figure 4 shown, the flow table entries of modalities such as IPv4, IPv6, SRv6, NDN, MF, and GEO are allocated according to the upper layer. Different network protocol flow table entries can be flexibly deployed in different TCAM columns of the same query bank unit, or scattered in different TCAM columns of different query bank units, which improves the flexibility of flow table resource allocation and deployment while ensuring the resource isolation of multi-modal network protocol flow table entries.

[0082] The method provided in this embodiment realizes the efficient deployment and isolation of flow table resources by dynamically selecting query block units with sufficient resources, flexibly configuring the query bit width according to the network modal protocol type, isolating and storing flow table entries of different protocols in independent logical sub-tables, and updating the association relationship in real time, improving the query efficiency and security of the flow table, and avoiding resource conflicts and performance bottlenecks at the same time.

[0083] In some embodiments, the method further includes: Store the modal type identifier and the logical sub-table identifier corresponding to the second target logical sub-table as header information in the high-order part of the target column of the TCAM core of the second target query block unit; Wherein, the target column is the column to which the second target logical sub-table belongs; the high-order part is multiple bits with a higher address bit sorting.

[0084] Optionally, during the flow table deployment process, the mode type identifier and the logical sub-table identifier corresponding to the second target logical sub-table can be used as header information and stored in the high-order part of the column to which the second target logical sub-table belongs in the TCAM core of the second target query block unit, so that the high-order part of each column of each TCAM core contains the mode type ID and the logical sub-table ID, to effectively identify the logical sub-table of the network protocol to which the flow table entry written in each column of each TCAM core belongs, and ensure resource isolation between different protocol traffic.

[0085] For example, each column of the TCAM core can have 80 bits, and the mode type ID and the logical sub-table ID can be configured in the high 4 bits of the column to which the second target logical sub-table belongs in the TCAM core of the second target query block unit.

[0086] The flow table optimization processing system provided by the present invention will be described below. The flow table optimization processing system described below can be correspondingly referred to the flow table optimization processing method described above.

[0087] Figure 6 It is a schematic structural diagram of the flow table optimization processing system provided by the present invention. As Figure 6 shown, the system includes: An obtaining unit 610 is configured to obtain a flow table query request; the flow table query request includes a keyword of a flow table entry to be queried, a network mode protocol type, and a query style; A configuration unit 620 is configured to obtain a query unit identifier, a mode type identifier, and a logical sub-table identifier corresponding to the flow table entry to be queried in a flow table deployment record according to the network mode protocol type; A first query unit 630 is configured to determine a first target query block unit to which the flow table entry to be queried belongs in a query system according to the query unit identifier; A second query unit 640 is further configured to dynamically adjust a query bit width of the first target query block unit according to the query style, and search for a first target logical sub-table that matches the network mode protocol type and the flow table entry type of the flow table entry to be queried in the TCAM core in the first target query block unit according to the adjusted query bit width, the mode type identifier, and the logical sub-table identifier; A processing unit 650 is configured to query data content of the flow table entry to be queried in the first target logical sub-table according to the keyword.

[0088] The system provided in this embodiment obtains the keywords, network modal protocol type, and query style in the flow table query request, and assigns independent query unit identifiers, modal type identifiers, and logical sub-table identifiers according to the network modal protocol type, so as to simply and conveniently perform independent flow table resource processing for different network protocols by combining the query unit identifier, modal type identifier, and logical sub-table identifier, realizing differential processing, independent processing, and flow table resource isolation of different protocol traffic, enabling each protocol to use an independent flow table space during the query process, avoiding interference between flow table entries of different protocols, ensuring data security, and dynamically adjusting according to the query style, thus effectively solving the problems of increased interference between protocols, low processing efficiency, and poor data security in traditional flow table processing methods, and significantly improving the efficiency and security of flow table processing.

[0089] The system provided by the present invention is used to execute the above method embodiments. For the specific process and detailed content, please refer to the above embodiments and will not be elaborated here.

[0090] Figure 7 An entity structure diagram of an electronic device is exemplified, as Figure 7 shown. The electronic device may include: a processor 710, a communication interface 720, a memory 730, and a communication bus 740. Among them, the processor 710, the communication interface 720, and the memory 730 complete communication with each other through the communication bus 740. The processor 710 can call the logical instructions in the memory 730 to execute the flow table optimization processing method, which includes: obtaining a flow table query request; the flow table query request includes the keywords of the flow table entry to be queried, the network modal protocol type of the flow table entry to be queried, and the query style; according to the network modal protocol type, obtaining the query unit identifier, modal type identifier, and logical sub-table identifier corresponding to the flow table entry to be queried in the flow table deployment record; according to the query unit identifier, determining the first target query block unit to which the flow table entry to be queried belongs in the query system; according to the query style, dynamically adjusting the query bit width of the first target query block unit, and according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier, searching for the first target logical sub-table that matches the network modal protocol type and the flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit; querying the data content of the flow table entry to be queried in the first target logical sub-table according to the keywords.

[0091] In addition, when the logical instructions in the above-mentioned memory 730 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0092] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the flow table optimization processing method provided by the above-mentioned various methods. The method includes: obtaining a flow table query request; the flow table query request includes a keyword of the flow table entry to be queried, the network modal protocol type of the flow table entry to be queried, and a query style; according to the network modal protocol type, in the flow table deployment record, obtaining the query unit identifier, modal type identifier, and logical sub-table identifier corresponding to the flow table entry to be queried; according to the query unit identifier, determining the first target query block unit to which the flow table entry to be queried belongs in the query system; according to the query style, dynamically adjusting the query bit width of the first target query block unit, and according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier, searching for a first target logical sub-table that matches the network modal protocol type and flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit; according to the keyword, querying the data content of the flow table entry to be queried in the first target logical sub-table.

[0093] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the flow table optimization processing method provided by the above-mentioned various methods. The method includes: obtaining a flow table query request; the flow table query request includes a keyword of a flow table entry to be queried, a network modal protocol type of the flow table entry to be queried, and a query style; according to the network modal protocol type, obtaining a query unit identifier, a modal type identifier, and a logical sub-table identifier corresponding to the flow table entry to be queried in a flow table deployment record; according to the query unit identifier, determining a first target query block unit to which the flow table entry to be queried belongs in a query system; dynamically adjusting a query bit width of the first target query block unit according to the query style, and searching for a first target logical sub-table that matches the network modal protocol type and the flow table entry type of the flow table entry to be queried in a TCAM core in the first target query block unit according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier; querying data content of the flow table entry to be queried in the first target logical sub-table according to the keyword.

[0094] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0095] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for optimizing flow table processing, characterized in that, Including: Obtaining a flow table query request; The flow table query request includes a keyword of a flow table entry to be queried, a network modal protocol type of the flow table entry to be queried, and a query style; According to the network modal protocol type, in the flow table deployment record, obtaining a query unit identifier, a modal type identifier, and a logical sub-table identifier corresponding to the flow table entry to be queried; According to the query unit identifier, determining a first target query block unit to which the flow table entry to be queried belongs in the query system; According to the query style, dynamically adjusting the query bit width of the first target query block unit, and according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier, searching for a first target logical sub-table that matches the network modal protocol type and the flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit; According to the keyword, querying the data content of the flow table entry to be queried in the first target logical sub-table.

2. The flow table optimization processing method according to claim 1, wherein The query unit identifier includes a query module identifier and a query block identifier; The determining, according to the query unit identifier, a first target query block unit to which the flow table entry to be queried belongs in the query system includes: According to the query module identifier, determining a target query module unit to which the flow table entry to be queried belongs in the query system; According to the query block identifier, determining the first target query block unit among a plurality of query block units included in the target query module unit.

3. The flow table optimization processing method according to claim 1, wherein The searching, according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier, for a first target logical sub-table that matches the network modal protocol type and the flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit includes: According to the adjusted query bit width, determining at least one target TCAM core in the first target query block unit; Based on at least one of the target TCAM cores, parallelly matching the modal type identifier and the logical sub-table identifier with the modal type identifier and the logical sub-table identifier of each logical sub-table in the TCAM core of the first target query block unit to obtain at least one candidate logical sub-table that matches the network modal protocol type and the flow table entry type of the flow table entry to be queried; According to the priority coding address of each candidate logical sub-table, determining the first target logical sub-table among at least one of the candidate logical sub-tables.

4. The flow table optimization processing method according to any one of claims 1-3, characterized in that, The method further includes: When an update request for the flow table query request is received in the current cycle, determining the cycle type to which the current cycle belongs and the running states of each TCAM core in the query system; When it is determined that the current cycle belongs to a non-query cycle and the running states of each TCAM core in the query system are all idle states, updating the flow table query request according to the update request; When it is determined that the current cycle belongs to a query cycle, or the running state of any TCAM core in the query system is a working state, prohibiting the update of the flow table query request.

5. The flow table optimization processing method according to any one of claims 1-3, characterized in that The method further includes: Receive a flow table deployment request; the flow table deployment request includes the network modal protocol type of the flow table entry to be deployed and the data content to be deployed. According to the resource occupancy of each query block unit in the query system, determine a second target query block unit in the query system to process the flow table deployment request. Determine the query bit width of the second target query block unit according to the network modal protocol type of the flow table entry to be deployed. According to the query bit width of the second target query block unit, determine a target configuration style among multiple supported configuration styles of the second target query block unit. Determine the flow table resource address of the flow table entry to be deployed according to the target configuration style, the network modal protocol type of the flow table entry to be deployed, and the flow table entry type. According to the flow table resource address, write the data content to be deployed into a second target logical sub-table in the TCAM core of the second target query block unit. When it is determined that the deployment of the flow table entry to be deployed is completed, establish an association relationship between the modal type identifier and the logical sub-table identifier corresponding to the second target logical sub-table, the query unit identifier corresponding to the second target query block unit, and the network modal protocol type of the flow table entry to be deployed, and update the association relationship to the flow table deployment record.

6. The flow table optimization processing method according to claim 5, characterized in that The method further includes: Store the modal type identifier and the logical sub-table identifier corresponding to the second target logical sub-table as header information in the high-order part of the target column of the TCAM core of the second target query block unit. Wherein, the target column is the column to which the second target logical sub-table belongs; the high-order part is multiple bit positions with a higher address bit sorting.

7. The flow table optimization processing method according to any one of claims 1 to 3, characterized in that The method further includes: Obtain the query result corresponding to the flow table query request. Feed back the query result to the upper protocol stack of the query system through the output path of the first target query block unit to perform data processing on the data content of the flow table entry to be queried. Wherein, the data processing includes at least one of forwarding, modifying, and discarding.

8. A flow table optimization processing system, characterized in that, Includes: An acquisition unit for acquiring a flow table query request. The flow table query request includes a keyword, a network modal protocol type, and a query style of the flow table entry to be queried. A configuration unit for obtaining the query unit identifier, the modal type identifier, and the logical sub-table identifier corresponding to the flow table entry to be queried in the flow table deployment record according to the network modal protocol type. A first query unit for determining a first target query block unit to which the flow table entry to be queried belongs in the query system according to the query unit identifier. A second query unit is further configured to dynamically adjust the query bit width of the first target query block unit according to the query style, and search for a first target logical sub-table matching the network modal protocol type and the flow table entry type of the flow table entry to be queried in the TCAM core of the first target query block unit according to the adjusted query bit width, the modal type identifier, and the logical sub-table identifier. A processing unit for querying the data content of the flow table entry to be queried in the first target logical sub-table according to the keyword.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the flow table optimization processing method according to any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the flow table optimization processing method according to any one of claims 1 to 7.