Storage method, device, equipment, medium and product
By using an intelligent ACL shared management algorithm to dynamically manage TCAM and cascaded RAM resources, the problem of ACL entry storage efficiency under limited TCAM resources is solved, achieving efficient storage space utilization and ensuring the security and stability of automotive network communication.
Patent Information
- Application Number
- CN202510359552.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-03-25
AI Technical Summary
In existing technologies, the storage efficiency of Access Control List (ACL) entries in automotive network communication is low, making it difficult to meet the ever-increasing data traffic demands. Especially when TCAM resources are limited, traditional storage methods cannot allocate resources reasonably, resulting in insufficient capacity.
By employing an intelligent ACL shared management algorithm, and combining TCAM and cascaded RAM, TCAM resources are dynamically allocated, released, and fragmented to achieve shared storage management of multiple ACL entries, thereby optimizing storage space utilization.
Without increasing storage space, the storage efficiency and resource utilization of ACLs are improved, ensuring the security and stability of automotive network communication.
Smart Images

Figure CN120653189B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to a storage method, apparatus, device, medium and product. Background Technology
[0002] With the continuous advancement of automotive technology and the rapid development of intelligent connected vehicles, automotive network communication systems are becoming increasingly complex. In automotive network communication, Access Control Lists (ACLs) play a crucial role as an important tool for network security management. ACL entries define which systems or devices are authorized to access services on the network, thereby ensuring the security and reliability of in-vehicle communications. However, with the increasing number of sensors, controllers, and actuators in vehicles, and the growing richness of in-vehicle applications and services, the data traffic in automotive network communication is also continuously increasing. This increase in data traffic places higher demands on the capacity of ACL entries.
[0003] In existing technologies, ACL tables are mainly stored using ternary content addressable memory (TCAM). The traditional method of storing ACL entries involves dividing the TCAM into several blocks of different sizes. Each block can be assigned to an ACL entry, and the business key initiates parallel lookups of multiple blocks for an ACL entry. However, this storage method is inefficient and does not make full use of storage space.
[0004] Therefore, it is necessary to propose a scheme to improve the storage efficiency of ACL in a limited storage space, so as to improve the utilization of storage space. Summary of the Invention
[0005] The main objective of this application is to provide a storage method, apparatus, device, medium, and product, aiming to propose a solution to improve the storage efficiency of ACL in a limited storage space, thereby increasing the utilization rate of storage space.
[0006] To achieve the above objectives, embodiments of this application provide a storage method, the method comprising:
[0007] Obtain information about the storage space and the access control list;
[0008] Select the target access control list sharing algorithm model based on the information of the storage space and the access control list;
[0009] Based on the target access control list sharing algorithm model, the access control list entries are managed in the storage space.
[0010] This application embodiment also provides a storage device, the device comprising:
[0011] The acquisition module is used to obtain information about the storage space and the access control list.
[0012] The selection module is used to select or determine the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list;
[0013] The management module is used to manage the entries of the access control list in the storage space based on the target access control list sharing algorithm model.
[0014] This application also provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the storage method described above.
[0015] This application embodiment also provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the storage method described above.
[0016] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the storage method described above.
[0017] This application discloses a storage method comprising: acquiring information about storage space and information about access control lists (ACLs); selecting or determining a target ACL sharing algorithm model based on the storage space information and the ACL information; and managing ACL entries in the storage space based on the target ACL sharing algorithm model. The method allows for adaptive selection of the target ACL sharing algorithm model based on the storage space information and the ACL information. By managing ACL entries in the storage space using the target ACL sharing algorithm model, the storage efficiency of the ACL can be improved without increasing storage space, thus increasing the utilization rate of storage space. Attached Figure Description
[0018] Figure 1 This is an exemplary flowchart of the storage method in the embodiments of this application;
[0019] Figure 2 This is a schematic diagram of the access control list sharing algorithm management system in the embodiments of this application;
[0020] Figure 3This is a schematic diagram of the access control list structure in an embodiment of this application;
[0021] Figure 4 This is a schematic diagram of the storage structure of the tri-state content-addressable memory in the embodiments of this application;
[0022] Figure 5 This is a schematic diagram illustrating model selection in an embodiment of this application;
[0023] Figure 6 This is a schematic diagram illustrating the storage methods of different table entry bit widths in TCAM in the embodiments of this application;
[0024] Figure 7 This is a schematic diagram illustrating the correspondence between base address and index in an embodiment of this application;
[0025] Figure 8 This is a schematic diagram of the simultaneous hit selection mode in the embodiments of this application;
[0026] Figure 9 Add a flowchart to the table entries in the embodiments of this application;
[0027] Figure 10 This is a schematic diagram of the table entry deletion process in an embodiment of this application;
[0028] Figure 11 This is a schematic diagram of the application process for a three-state content-addressable memory block in an embodiment of this application;
[0029] Figure 12 This is a schematic diagram of the fragmentation and defragmentation process in an embodiment of this application;
[0030] Figure 13 This is another exemplary flowchart of the storage method in the embodiments of this application;
[0031] Figure 14 This is a schematic diagram illustrating the first effect of data entry relocation in an embodiment of this application;
[0032] Figure 15 This is a schematic diagram illustrating the second effect of data entry relocation in an embodiment of this application;
[0033] Figure 16 This is a schematic diagram illustrating the third effect of data entry relocation in an embodiment of this application;
[0034] Figure 17 This is a schematic diagram illustrating the fourth effect of data entry relocation in the embodiments of this application;
[0035] Figure 18 This is a schematic diagram of the storage device structure provided in the embodiments of this application.
[0036] The realization of the purpose of this application, its functional features and advantages will be further described in conjunction with the embodiments and with reference to the accompanying drawings. Specific Embodiments
[0037] It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0038] Technical terms involved in the embodiments of this application:
[0039] ACL: Access Control List, access control list;
[0040] TCAM: Ternary Content Addressable Memory, ternary content addressable memory;
[0041] RAM: Random Access Memory, random access memory;
[0042] Bit: bit;
[0043] Key_mode: table entry storage bit width / key value;
[0044] Block: block.
[0045] With the continuous progress of automotive technology and the rapid development of intelligent connected vehicles, automotive network communication systems are becoming increasingly complex. In automotive network communication, the access control list ACL plays a crucial role as an important tool for network security management. ACL entries are used to define which systems or devices are authorized to access services on the network, thus ensuring the security and reliability of in-vehicle communication. However, with the continuous increase in the number of various sensors, controllers, and actuators on the vehicle, as well as the increasing richness of in-vehicle applications and services, the data traffic in automotive network communication is also continuously growing. This growth in data traffic places higher requirements on the capacity of ACL entries. ACL is mainly stored using the ternary content addressable memory TCAM. The characteristics of TCAM are that it can support parallel search and has a low search latency; the disadvantages are high cost, high power consumption, and limited capacity.
[0046] The traditional method for storing ACL entries is to divide the TCAM into several Block spaces of a certain size. Each block can be allocated to an ACL entry, and the service key value Key initiates a parallel search for multiple blocks of an ACL entry. This storage method is less efficient, especially in a large network environment where the number of ACL entries is huge, and the traditional storage method is difficult to meet the capacity requirements. Therefore, how to improve the capacity of ACL under limited TCAM resources has become an urgent problem to be solved in the field of automotive communication technology.
[0047] Currently, regarding the issue of how to increase ACL capacity, in addition to the direct method of increasing TCAM resource space, the industry has explored a variety of optimization schemes, mainly including: (1) One block can store two ACL table entries, and the two ACL tables are written to according to different address directions to achieve resource sharing of one block; (2) Two blocks store one type of ACL table entry, and the two ACL tables are written to according to different address directions. By adjusting the size of the block, resource sharing of the block can be achieved. However, these two schemes are not feasible for scenarios where more than three ACL entries share resources; (3) By loading the same ACL rules in multiple ACLs as ACL shared segments separately, the purpose of saving memory space can be achieved. However, the number of ACL shared segments that can be found in scheme (3) is limited, which has strong limitations.
[0048] Taking a TCAM with 16 blocks, each with a space of 1k*640bit, as an example, in practical applications, different services have different requirements for the bit width of ACL entries. For example, service 1 requires a bit width of 160bit, with a maximum resource requirement of 12k*640bit; service 2 increases to a bit width of 320bit, also requiring a maximum resource of 12k*640bit; service 3 is even higher at 640bit, but its maximum resource requirement remains at the level of 12k*640bit. However, when the ACL entries of these three services coexist in the network, the total maximum resource required will exceed the existing configuration of 16k*640bit. If the traditional storage method is used to allocate 12k*640bit resources to each service separately, it is obviously impossible to meet the needs of the three services coexisting, resulting in insufficient resource allocation. Therefore, developing an efficient ACL entry storage sharing scheme becomes particularly urgent to ensure that the ACL table can receive reasonable resource allocation under various service scenarios, thereby maintaining the security and stability of automotive network communication.
[0049] This application proposes a solution that, given limited TCAM and cascaded RAM space, provides users with an efficient shared ACL entry storage management method based on existing TCAM storage rules and an intelligent ACL shared management algorithm. Multiple entries share a single space, and TCAM resource sharing is achieved through dynamic allocation, release, and fragmentation processes via TCAM block locking.
[0050] Reference Figure 1 , Figure 1 This is an exemplary flowchart illustrating a storage method in an embodiment of this application. The storage method includes:
[0051] Step S10: Obtain information about the storage space and the access control list;
[0052] For example, the information of the storage space includes at least one of the following: the resource size of the tri-state content-addressable memory block, the resource address management method of the tri-state content-addressable memory block, and the cascaded resource size.
[0053] For example, the information in an access control list includes the bit width of the key value for each entry and / or the size of the shared resources that each entry can request.
[0054] Reference Figure 2 , Figure 2 This is a schematic diagram of the access control list sharing algorithm management system in the embodiments of this application, such as... Figure 2 As shown, the access control list sharing algorithm management system in this embodiment includes at least one entry information processing unit, one sharing algorithm processing unit, and one storage unit. The storage unit includes at least one TCAM interface and a cascaded RAM interface.
[0055] Reference Figure 3 , Figure 3 This is a schematic diagram of the access control list structure in an embodiment of this application, as shown below. Figure 3 As shown, the ACL table consists of two parts: ACL rules and results. ACL rules are stored in the TCAM, and results are stored in the cascaded RAM. The key first searches for the ACL rules stored in the TCAM. When an ACL rule in the TCAM matches, the position of its entry is used as the handle, and the handle is used as an index to search the cascaded RAM again to obtain the results.
[0056] Reference Figure 4 , Figure 4 This is a schematic diagram of the storage structure of the tri-state content-addressable memory in an embodiment of this application, as shown below. Figure 4 As shown, in this embodiment of the application, a TCAM consisting of 16 blocks is used as an example for illustration. Each block includes 8 TCAM units, and each TCAM unit is 1k(1024)*80 bits.
[0057] Step S20: Select a target access control list sharing algorithm model based on the information of the storage space and the access control list;
[0058] For example, the aforementioned Figure 2The table entry information processing unit can select an appropriate target access control list sharing algorithm model (i.e., ACL sharing algorithm model) to manage ACL tables based on the user's TCAM block resource size, TCAM block resource address management method, cascading resource size, key value bit width of each table entry, and the size of shared resources that each table entry can request.
[0059] For example, the target access control list sharing algorithm model includes at least one of the first access control list sharing algorithm model, the second access control list sharing algorithm model, the third access control list sharing algorithm model, and the fourth access control list sharing algorithm model.
[0060] For example, the steps of selecting a target access control list sharing algorithm model based on the storage space information and the access control list information include:
[0061] Identify whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition;
[0062] If the information of the storage space and the information of the access control list satisfy the first condition and the second condition, the first access control list sharing algorithm model is selected.
[0063] If the information in the storage space and the information in the access control list do not meet the first condition but meet the second condition, the second access control list sharing algorithm model is selected.
[0064] If the information in the storage space and the information in the access control list satisfy the first condition but do not satisfy the second condition, the third access control list sharing algorithm model is selected.
[0065] If the information in the storage space and the information in the access control list do not meet the first and second conditions, the fourth access control list sharing algorithm model is selected.
[0066] For example, the tri-state content-addressable memory block resource address management method includes the configuration range of the base address of the tri-state content-addressable memory block and / or the mode in which multiple blocks simultaneously hit the computation processing.
[0067] For example, the step of identifying whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition includes:
[0068] Based on the bit width of each table entry key value, the size of the shared resources that each table entry can apply for, and the size of the tri-state content addressing memory block resources, it is determined whether the cascaded resource size meets the resource requirements, and whether the configuration range of the base address meets the range requirements.
[0069] If the cascaded resource size meets the resource requirements and the configuration range of the base address meets the range requirements, it is determined that the information of the storage space and the information of the access control list meet the first condition.
[0070] If the size of the cascaded resources does not meet the resource requirements or the configuration range of the base address does not meet the range requirements, it is determined that the information of the storage space and the information of the access control list do not meet the first condition.
[0071] When the multiple blocks simultaneously hit the computation processing mode in the first mode, it is determined that the information of the storage space and the information of the access control list satisfy the second condition;
[0072] If the computation processing mode of the multiple blocks is simultaneously hit is the second mode, it is determined that the information of the storage space and the information of the access control list do not meet the second condition.
[0073] Reference Figure 5 , Figure 5 This is a schematic diagram of model selection in an embodiment of this application, such as... Figure 5 As shown, four models are selected based on the following two conditions: First condition: Are the resources of the cascaded RAM sufficient, or is the range of base_addr sufficient? Second condition: If multiple blocks are simultaneously selected, is the handle mode the first mode? If the first condition is not met, the block base address needs to be adjusted to ensure that the order of the base addresses is the block used by the 640-bit block, the block used by the 320-bit block, and the block used by the 160-bit block. If the second condition is not met, the order of the block_ids within the tab needs to be ensured to be ascending. Based on the first and second conditions, at least one of the following access control list sharing algorithm models—the first, second, third, and fourth—is selected to request resources.
[0074] For example, the first mode includes: when different tri-state content-addressable memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressable memory block with the smaller base address, and using the result corresponding to the index calculated using the base address of the selected tri-state content-addressable memory block as the hit result.
[0075] For example, the second mode includes: when different tri-state content-addressable memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressable memory block with the smaller sequence number, and using the result corresponding to the index calculated using the base address of the selected tri-state content-addressable memory block as the hit result.
[0076] Reference Figure 6 , Figure 6 This is a schematic diagram illustrating the storage methods of different table entry bit widths in TCAM in the embodiments of this application, such as... Figure 6 As shown, for key modes of 80-bit, 160-bit, 320-bit, and 640-bit widths, each row of TCAM0 to TCAM7 is 80 bits, totaling 640 bits. This 640-bit space can store eight 80-bit ACL rules, four 160-bit ACL rules, two 320-bit ACL rules, or one 640-bit ACL rule. For example, if multiple entries in the same block can be matched simultaneously, such as ACL rule 1 and ACL rule 1022, the entry with the smaller position (handle = 1) is selected.
[0077] Reference Figure 7 , Figure 7 This is a schematic diagram illustrating the correspondence between base address and index in an embodiment of this application, as shown below. Figure 7 As shown in the embodiments of this application, two corresponding modes for the base address (base_addr) and handle index of ACL entries tcam block are provided. The first mode allocates a cascaded RAM for each table, so the tcam_handle calculated using the base address (base_addr) for each table starts from 0. The second mode shares a single cascaded RAM with all tables, and the tcam_handles calculated using base_addr cannot overwrite each other. The advantage of the first mode is a small configuration range for base_addr, but the disadvantage is the need for multiple cascaded RAMs. The advantage of the second mode is that only one cascaded RAM is needed, but the disadvantage is a larger range for base_addr. Furthermore, the calculation formulas for base_addr and the initial tcam_handle within the block include: tcam_handle = base_addr * 1024 * 640 / key_mode, where tcam_handle is the index of the cascaded RAM, base_addr is the base address, and key_mode is the key value.
[0078] Reference Figure 8 , Figure 8 This is a schematic diagram of the simultaneous hit selection mode in the embodiments of this application, such as... Figure 8As shown, the embodiments of this application mainly include two modes for selecting the handle when multiple TCAM blocks are hit simultaneously. The first mode compares the handle size calculated according to base_addr and selects the smaller handle as the hit result. The second mode compares the block_id size and calculates the handle based on the base_addr with the smaller block_id as the hit result.
[0079] Step S30: Based on the target access control list sharing algorithm model, manage the access control list entries in the storage space.
[0080] For example, the aforementioned Figure 2 The shared algorithm processing unit in the system can, when adding or deleting ACL entries, perform TCAM block allocation, release, fragmentation, entry relocation, address adjustment, and cascade RAM entry relocation according to the selected ACL shared algorithm model.
[0081] For example, an access control list includes access control list entries to be added and / or access control list entries to be deleted.
[0082] For example, the steps of managing entries of the access control list in the storage space based on the target access control list sharing algorithm model include:
[0083] If the allocated resource storage corresponding to the access control list entry to be added is full, based on the target access control list sharing algorithm model, the storage space is allocated, released, and / or fragmented to obtain a target tri-state content-addressed memory block, and the access control list entry to be added is stored in the target tri-state content-addressed memory block; and / or,
[0084] Based on the target access control list sharing algorithm model, the index corresponding to the access control list entry to be deleted is released in the storage space, and the access control list rules and cascading resources corresponding to the access control list entry to be deleted are deleted.
[0085] For example, based on the target access control list sharing algorithm model, the steps of applying for, releasing, and / or defragmenting the storage space to obtain the target tri-state content-addressable memory block include:
[0086] Based on the target access control list sharing algorithm model, a three-state content-addressable memory block is requested, and a base address is allocated to the requested three-state content-addressable memory block to obtain the target three-state content-addressable memory block;
[0087] In the event that the application for a three-state content-addressable memory block fails, the access control list of the applied three-state content-addressable memory block is defragmented and / or the applied three-state content-addressable memory block is released, and the process returns to the steps of applying for a three-state content-addressable memory block based on the target access control list sharing algorithm model and subsequent steps, until the target three-state content-addressable memory block is obtained.
[0088] If the application for a tri-state content-addressable memory block is successful, an index is allocated to the applied tri-state content-addressable memory block and access control list rules and cascading resources are configured to obtain the target tri-state content-addressable memory block.
[0089] Reference Figure 9 , Figure 9 Add a flowchart to the table entries in the embodiments of this application, such as... Figure 9 As shown, the process of adding an ACL entry includes: first, determining whether a block needs to be requested based on whether the storage of the resource allocated to the entry is full; if so, requesting a block from the resource pool and allocating a base_addr; if the request fails, triggering fragmentation and defragmentation of other entries to release the block, requesting the block again, then allocating a tcam_handle by the software, and finally configuring hardware ACL rules and cascading RAM.
[0090] Reference Figure 10 , Figure 10 This is a schematic diagram of the table entry deletion process in an embodiment of this application, such as... Figure 10 As shown, the ACL entry deletion process includes: releasing the software-allocated tcam_handle, and then directly deleting the corresponding data from the TCAM and cascaded RAM.
[0091] Reference Figure 11 , Figure 11 This is a schematic diagram of the application process for a tri-state content-addressable memory block in an embodiment of this application, as shown below. Figure 11 As shown, from left to right, the processes for allocating three-state content-addressable memory blocks are illustrated by the first, second, third, and fourth access control list sharing algorithm models.
[0092] For example, the steps of requesting blocks for a tri-state content-addressable memory based on a first access control list sharing algorithm model include: requesting unused block numbers from the resource pool of the tri-state content-addressable memory in a first order.
[0093] For example, the steps of applying for a tri-state content-addressable memory block based on the second access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a first order, calculating the base address of the block number, and moving the cascade table according to the base address of the block number.
[0094] For example, the steps of applying for a tri-state content addressing memory block based on the third access control list sharing algorithm model and allocating a base address for the applied tri-state content addressing memory block include: applying for unused block numbers from the resource pool of the tri-state content addressing memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the tri-state content addressing memory table according to the base address of the adjusted block numbers.
[0095] For example, the steps of applying for a tri-state content-addressable memory block based on the fourth access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the cascade table and the tri-state content-addressable memory table according to the base address of the adjusted block numbers.
[0096] For example, the first sequence includes: from the first block number (0) of the tri-state content-addressable memory block to the last block number (n) of the tri-state content-addressable memory block.
[0097] For example, the second sequence includes: from the largest requested block number (last_b lock_id) to the last block number of the tri-state content-addressable memory block, and from the first block number (0) of the tri-state content-addressable memory block to the largest requested block number (last_b lock_id).
[0098] Reference Figure 12 , Figure 12 This is a schematic diagram of the fragmentation and defragmentation process in an embodiment of this application, such as... Figure 12 As shown, the steps for performing fragmentation defragmentation on the access control list of an already requested tri-state content-addressable memory block include:
[0099] Check the access control list (tab le) of each of the applied tri-state content addressing memory blocks to determine if there is an access control list that can release the block (block lock);
[0100] If an access control list that can release blocks exists, move the tri-state content-addressable memory entries (tcam entries) and cascaded resources (as_data) corresponding to the access control list that can release blocks one by one to release the tri-state content-addressable memory blocks.
[0101] Identify whether the target access control list sharing algorithm model used during the application phase of the released three-state content-addressable memory block is the first access control list sharing algorithm model or the third access control list sharing algorithm model;
[0102] If the target access control list sharing algorithm model used during the application phase of the released tri-state content-addressable memory block is either the first access control list sharing algorithm model or the third access control list sharing algorithm model, then according to the released tri-state content-addressable memory block relocation cascade table, including adjusting handles and relocating as_data one by one at the block lock granularity, and then configuring the base address base_addr of the block lock.
[0103] For example, ACL entries can be stored based on the results calculated by the ACL sharing algorithm.
[0104] This embodiment, through the above-described scheme, specifically obtains information about the storage space and the access control list (ACL); selects or determines a target ACL sharing algorithm model based on the storage space and ACL information; and manages ACL entries in the storage space based on the target ACL sharing algorithm model. By adaptively selecting the target ACL sharing algorithm model based on the storage space and ACL information, and managing ACL entries in the storage space using the target ACL sharing algorithm model, the storage efficiency of the ACL can be improved without increasing storage space, thus increasing storage space utilization.
[0105] Reference Figure 13 , Figure 13 This is another exemplary flowchart illustrating the storage method in this application embodiment, the method comprising:
[0106] Step 1: Obtain the hardware TCAM storage space. This includes 16 blocks, each with a storage space of 1024*640 bits.
[0107] Step 2: Obtain the address management method of the hardware TCAM resources. The configuration range of the base address is 0 to 63. When multiple blocks hit simultaneously, the mode for calculating the handle is selected as mode 2 (the handle is calculated based on the base_addr with the smaller block_id and output as the hit result).
[0108] Step 3: Obtain the space for the cascaded RAM resources. The cascaded RAM contains only one set of data, i.e., 128k of RAM capacity;
[0109] Step 4: Obtain the bit width (key_mode) and the threshold of shared resources (share_block_num) for all tab le entries. Tab le0 has a bit width of 160 bits and share_block_num = 16; tab le1 has a bit width of 320 bits and share_block_num = 16; tab le2 has a bit width of 640 bits and share_block_num = 16.
[0110] Step 5: Obtain the corresponding ACL sharing algorithm model. Based on steps 2-3, we know that... Figure 5 The first and second conditions are not met. Therefore, the fourth access control list sharing algorithm model is selected to request resources from the shared pool.
[0111] Step 6: Obtain the sample operation flow for adding and deleting various table entries. Flow: ① Tab le0 first adds an 8k 640-bit entry, ② Tab le2 adds a 16k 160-bit entry, ③ Tab le1 adds an 8k 320-bit entry, ④ Tab le2 deletes a high-priority 8k (entries in block 8 and block 9) 160-bit entry, ⑤ Tab le1 adds a 4k 320-bit entry.
[0112] Step 7: Store the data based on the fourth access control list sharing algorithm model. (Refer to...) Figure 14 - Figure 17 , Figure 14 - Figure 17 The diagrams shown represent the first, second, third, and fourth effects of data entry relocation in this application embodiment. In process ①, all blocks are unused, so blocks are allocated directly starting from block 0, and base_addr is calculated. In process ②, since the table entry width of tab le2 is 160 bits, it is directly inserted into tab le0 (640 bits) before calculating base_addr. The effect after insertion is as follows. Figure 14 As shown. In process ③, since the bit width of tab le1 is 320 bits and it is necessary to ensure that the base address is sufficient (the base address order is: 640 bits use block, 320 bits use block, 160 bits use block), the base address of the block of tab le2 needs to be adjusted before inserting the block of tab le1. The effect after insertion is as follows. Figure 15 As shown. Step 4: Delete the entry in tab le2 and execute. Figure 10 The ACL entry deletion process in the table. In step ⑤, since all blocks are used up, a defragmentation process is needed. It is determined that tab le2 can release two blocks, and tab le2 also satisfies... Figure 5 The fourth access control list sharing algorithm model in the text requires the relocation of the cascading table. The effect after relocation is as follows: Figure 16 As shown. Next, a block request is made. Since tab le2 uses the fourth access control list sharing algorithm model, the cascaded RAM corresponding to tab le2 needs to be moved first, then the tcam table needs to be moved, and finally the insertion result is as shown. Figure 17 As shown.
[0113] This embodiment, through the above-described scheme, specifically selects an appropriate ACL sharing algorithm model based on the user's TCAM block resource size, TCAM block resource address management method, cascaded resource size, key width of each table entry, and the amount of shared resources that each table entry can request. When adding or deleting ACL entries, the selected ACL sharing algorithm model is used to allocate, release, defragment, move entries, adjust addresses, and move entries in cascaded RAM, thereby achieving ACL table management and realizing TCAM resource sharing.
[0114] Furthermore, embodiments of this application also provide a storage device, with reference to... Figure 18 , Figure 18 This is a schematic diagram of a storage device structure provided in an embodiment of this application. The device includes:
[0115] Module 10 is used to obtain information about the storage space and the access control list.
[0116] Selection module 20 is used to select or determine the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list;
[0117] Management module 30 is used to manage the access control list entries in the storage space based on the target access control list sharing algorithm model.
[0118] This application also provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the storage method described above.
[0119] This application embodiment also provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the storage method described above.
[0120] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the storage method described above.
[0121] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.
[0122] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or computing device, etc.) to execute the methods described in the various embodiments of this application.
[0123] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A storage method, characterized in that, include: Obtain information about the storage space and the access control list, wherein the information about the storage space includes at least one of the following: the resource size of the tri-state content-addressable memory block, the resource address management method of the tri-state content-addressable memory block, and the cascaded resource size; and the information about the access control list includes the key width of each entry and / or the shareable resource size that each entry can apply for. Select the target access control list sharing algorithm model based on the information of the storage space and the access control list; Based on the target access control list sharing algorithm model, the access control list entries are managed in the storage space; The target access control list sharing algorithm model includes at least one of a first access control list sharing algorithm model, a second access control list sharing algorithm model, a third access control list sharing algorithm model, and a fourth access control list sharing algorithm model. The step of selecting the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list includes: Identify whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition; If the information of the storage space and the information of the access control list satisfy the first condition and the second condition, the first access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first condition but meet the second condition, the second access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list satisfy the first condition but do not satisfy the second condition, the third access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first and second conditions, the fourth access control list sharing algorithm model is selected.
2. The storage method as described in claim 1, characterized in that, The tri-state content-addressable memory block resource address management method includes the configuration range of the base address of the tri-state content-addressable memory block and / or the mode of multiple blocks simultaneously hitting the computation processing. The step of identifying whether the information of the storage space and the information of the access control list meet the first condition and the second condition includes: Based on the bit width of each table entry key value, the size of the shared resources that each table entry can apply for, and the size of the tri-state content addressing memory block resources, it is determined whether the cascaded resource size meets the resource requirements, and whether the configuration range of the base address meets the range requirements. If the cascaded resource size meets the resource requirements and the configuration range of the base address meets the range requirements, it is determined that the information of the storage space and the information of the access control list meet the first condition. If the size of the cascaded resources does not meet the resource requirements or the configuration range of the base address does not meet the range requirements, it is determined that the information of the storage space and the information of the access control list do not meet the first condition. When the multiple blocks simultaneously hit the computation processing mode in the first mode, it is determined that the information of the storage space and the information of the access control list satisfy the second condition; If the computation processing mode of the multiple blocks is simultaneously hit is the second mode, it is determined that the information of the storage space and the information of the access control list do not meet the second condition.
3. The storage method as described in claim 2, characterized in that, The first mode includes: when different tri-state content-addressed memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressed memory block with the smaller base address, and using the result of the index calculated using the base address of the selected tri-state content-addressed memory block as the hit result; and / or, The second mode includes: when different tri-state content-addressable memory blocks simultaneously hit the access control list rules, selecting the tri-state content-addressable memory block with the smaller sequence number, and using the result corresponding to the index calculated by the base address of the selected tri-state content-addressable memory block as the hit result.
4. The storage method as described in claim 1, characterized in that, The access control list includes access control list entries to be added and / or access control list entries to be deleted. The step of managing the access control list entries in the storage space based on the target access control list sharing algorithm model includes: If the allocated resource storage corresponding to the access control list entry to be added is full, based on the target access control list sharing algorithm model, the storage space is allocated, released, and / or fragmented to obtain a target tri-state content-addressed memory block, and the access control list entry to be added is stored in the target tri-state content-addressed memory block; and / or, Based on the target access control list sharing algorithm model, the index corresponding to the access control list entry to be deleted is released in the storage space, and the access control list rules and cascading resources corresponding to the access control list entry to be deleted are deleted.
5. The storage method as described in claim 4, characterized in that, The steps of allocating, releasing, and / or defragmenting tri-state content-addressable memory blocks in the storage space based on the target access control list sharing algorithm model to obtain the target tri-state content-addressable memory block include: Based on the target access control list sharing algorithm model, a three-state content-addressable memory block is requested, and a base address is allocated to the requested three-state content-addressable memory block to obtain the target three-state content-addressable memory block; In the event that the application for a three-state content-addressable memory block fails, the access control list of the applied three-state content-addressable memory block is defragmented and / or the applied three-state content-addressable memory block is released, and the process returns to the steps of applying for a three-state content-addressable memory block based on the target access control list sharing algorithm model and subsequent steps, until the target three-state content-addressable memory block is obtained. If the application for a tri-state content-addressable memory block is successful, an index is allocated to the applied tri-state content-addressable memory block and access control list rules and cascading resources are configured to obtain the target tri-state content-addressable memory block.
6. The storage method as described in claim 5, characterized in that, The method further includes at least one of the following: The steps for requesting blocks in a tri-state content-addressable memory based on the first access control list sharing algorithm model include: requesting unused block numbers from the resource pool of the tri-state content-addressable memory in a first order; The steps of applying for a three-state content addressing memory block based on the second access control list sharing algorithm model and allocating a base address for the applied three-state content addressing memory block include: applying for unused block numbers from the resource pool of the three-state content addressing memory in a first order, calculating the base address of the block number, and moving the cascade table according to the base address of the block number; The steps of applying for a three-state content addressing memory block based on the third access control list sharing algorithm model and allocating a base address for the applied three-state content addressing memory block include: applying for unused block numbers from the resource pool of the three-state content addressing memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the three-state content addressing memory table according to the base address of the adjusted block numbers; The steps of applying for a tri-state content-addressable memory block based on the fourth access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a second order; adjusting the block order according to the block numbers; calculating the base address of the adjusted block numbers; and moving the cascade table and the tri-state content-addressable memory table according to the base address of the adjusted block numbers.
7. The storage method as described in claim 6, characterized in that, The first sequence includes: from the first block number of the tri-state content-addressable memory block to the last block number of the tri-state content-addressable memory block; and / or, The second sequence includes: from the largest requested block number to the last block number of the tri-state content-addressable memory block, and from the first block number of the tri-state content-addressable memory block to the largest requested block number.
8. The storage method as described in claim 5, characterized in that, The step of performing fragmentation defragmentation on the access control list of the applied tri-state content-addressable memory block includes: Check the access control list of each of the applied tri-state content-addressable memory blocks one by one to determine whether there is an access control list that can release the block; If an access control list that can release blocks exists, move the tri-state content-addressed memory entries and cascaded resources corresponding to the access control list that can release blocks one by one to release the tri-state content-addressed memory blocks. Identify whether the target access control list sharing algorithm model used during the application phase of the released three-state content-addressable memory block is the first access control list sharing algorithm model or the third access control list sharing algorithm model; If the target access control list sharing algorithm model used during the application phase of the released tri-state content-addressable memory block is either the first access control list sharing algorithm model or the third access control list sharing algorithm model, the cascade table is moved according to the released tri-state content-addressable memory block.
9. A storage device, characterized in that, The device includes: The acquisition module is used to acquire information about the storage space and the access control list. The information about the storage space includes at least one of the following: the resource size of the tri-state content-addressable memory block, the resource address management method of the tri-state content-addressable memory block, and the cascaded resource size. The information about the access control list includes the key width of each entry and / or the shareable resource size that each entry can apply for. The selection module is used to select or determine the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list; The management module is used to manage the access control list entries in the storage space based on the target access control list sharing algorithm model; The target access control list sharing algorithm model includes at least one of a first access control list sharing algorithm model, a second access control list sharing algorithm model, a third access control list sharing algorithm model, and a fourth access control list sharing algorithm model. The selection module is specifically used for: Identify whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition; If the information of the storage space and the information of the access control list satisfy the first condition and the second condition, the first access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first condition but meet the second condition, the second access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list satisfy the first condition but do not satisfy the second condition, the third access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first and second conditions, the fourth access control list sharing algorithm model is selected.
10. A network device, characterized in that, The network device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the storage method as described in any one of claims 1 to 8.
11. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the storage method as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the storage method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Item management method and apparatus
CN104935517A
Routing table item storage method and device and routing table item search method and device
CN113992579A