Data transmission method and device, electronic equipment and computer readable storage medium
By modifying label routing and tunnel encapsulation techniques, the high cost of equipment and the limited traffic scheduling between virtual routing forwarding instances were solved, enabling flexible traffic scheduling and efficient transmission.
Patent Information
- Application Number
- CN202410572777.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-09
- Publication Date
- 2025-11-11
AI Technical Summary
In existing technologies, traffic isolation between virtual routing forwarding instances requires devices to support the MPLS protocol, resulting in high equipment and maintenance costs. Furthermore, it cannot schedule traffic to non-originating VRFs, limiting the flexibility and reliability of traffic.
By receiving and modifying the label information of the label route, and using the target virtual route forwarding instance for tunnel encapsulation and decapsulation, flexible traffic scheduling is achieved, reducing dependence on device protocol support and improving transmission flexibility and reliability.
It enables free traffic forwarding between multiple virtual routing forwarding instances, enhances the dynamic convergence capability of routing, reduces equipment and maintenance costs, and improves the flexibility and reliability of traffic transmission.
Smart Images

Figure CN120935102A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to a data transmission method, apparatus, electronic device, and computer-readable storage medium. Background Technology
[0002] Network communication technology is a comprehensive field involving multiple aspects such as computers, communications, networks, and information technology. It primarily studies how to achieve the transmission and communication of various types of information within a network. This field includes, but is not limited to, technologies related to local area networks (LANs), wide area networks (WANs), and broadcast networks, as well as technologies related to data communication, network protocols, network architecture, network security, network management, and multimedia communication.
[0003] With the popularization of the Internet and the continuous expansion of application scenarios, the field of network communication technology plays an increasingly important role in today's society. Among related technologies, virtual private networks (VPNs) can be built to provide data isolation for different users and avoid the risk of data being exposed on the Internet. However, building VPNs is costly, requires high-end equipment, and has significant limitations on traffic scheduling. Summary of the Invention
[0004] This application provides a data transmission method, apparatus, electronic device, and computer-readable storage medium that can achieve flexible traffic scheduling based on virtual routing forwarding instances.
[0005] The technical solution of this application embodiment is implemented as follows:
[0006] This application provides a data transmission method applied to a first edge device, including:
[0007] Receive a tag route sent by a second edge device, wherein the tag route carries initial tag information;
[0008] In response to a tag modification request, the initial tag information carried by the tag route is modified to the target tag information;
[0009] Import the label route into the target virtual route forwarding instance corresponding to the target label information;
[0010] The first message to be sent is received through the target virtual route forwarding instance;
[0011] Based on the label route in the target virtual route forwarding instance, the first message to be sent is tunnel-encapsulated to obtain the first encapsulated message;
[0012] Send the first encapsulated message to the second edge device.
[0013] This application provides a data transmission method applied to a second edge device, including:
[0014] Send a tag route carrying initial tag information to the first edge device;
[0015] The first encapsulated message sent by the first edge device is received, wherein the first encapsulated message is obtained by the first edge device through tunnel encapsulation based on the label route in the target virtual route forwarding instance, the target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information, and the target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route;
[0016] The first encapsulated message is decapsulated through a tunnel to obtain the original message of the first encapsulated message.
[0017] This application provides a data transmission device applied to a first edge device, comprising:
[0018] The first routing management module is used to receive a label route sent by the second edge device, wherein the label route carries initial label information; in response to a label modification request, the module modifies the initial label information carried by the label route to target label information; and imports the label route into the target virtual route forwarding instance corresponding to the target label information.
[0019] The first message receiving module is used to receive the first message to be sent through the target virtual routing forwarding instance;
[0020] The first message processing module is used to perform tunnel encapsulation on the first message to be sent based on the label route in the target virtual route forwarding instance to obtain a first encapsulated message.
[0021] The first message sending module is used to send the first encapsulated message to the second edge device.
[0022] This application provides a data transmission device applied to a second edge device, comprising:
[0023] The second routing management module is used to send a tag route carrying initial tag information to the first edge device;
[0024] The second message receiving module is used to receive the first encapsulated message sent by the first edge device, wherein the first encapsulated message is obtained by the first edge device through tunnel encapsulation based on the label route in the target virtual route forwarding instance, the target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information, and the target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route;
[0025] The second message processing module performs tunnel decapsulation on the first encapsulated message to obtain the original message of the first encapsulated message.
[0026] This application provides an electronic device, the electronic device comprising:
[0027] Memory is used to store executable instructions for a computer;
[0028] A processor, when executing computer-executable instructions stored in the memory, implements the method provided in the embodiments of this application.
[0029] This application provides a computer-readable storage medium storing a computer program or computer-executable instructions, which, when executed by a processor, implements the data transmission method provided in this application.
[0030] This application provides a computer program product, including a computer program or computer executable instructions. When the computer program or computer executable instructions are executed by a processor, they implement the data transmission method provided in this application.
[0031] The embodiments of this application have the following beneficial effects:
[0032] By responding to tag information modification requests, arbitrary modification of tag information in tag routing can be achieved, thereby enabling arbitrary forwarding of traffic between multiple virtual routing forwarding instances and enhancing the dynamic convergence capability of routing. By encapsulating packets through tunnels, it can be ensured that the encapsulated packets are not limited by the protocol support of various edge devices, thereby improving the flexibility and reliability of traffic transmission and realizing free forwarding of traffic across networks. Attached Figure Description
[0033] Figure 1 This is a schematic diagram of the data transmission system architecture provided in the embodiments of this application;
[0034] Figure 2A This is a schematic diagram of the structure of a first electronic device for data transmission provided in an embodiment of this application;
[0035] Figure 2BThis is a schematic diagram of the structure of a second electronic device for data transmission provided in an embodiment of this application;
[0036] Figure 3A This is a first flowchart illustrating the data transmission method provided in an embodiment of this application;
[0037] Figure 3B This is a second flowchart illustrating the data transmission method provided in an embodiment of this application;
[0038] Figure 3C This is a third flowchart illustrating the data transmission method provided in an embodiment of this application;
[0039] Figure 3D This is a fourth flowchart illustrating the data transmission method provided in this application embodiment;
[0040] Figure 3E This is a fifth flowchart illustrating the data transmission method provided in this application embodiment;
[0041] Figure 3F This is a sixth flowchart illustrating the data transmission method provided in this application embodiment;
[0042] Figure 4 This is a schematic diagram of the method of the related technology provided in the embodiments of this application;
[0043] Figure 5 This is a schematic diagram of a data transmission method in a traffic scheduling scenario provided in an embodiment of this application;
[0044] Figure 6 This is a schematic diagram of a data transmission method in a centralized security protection scenario provided in this application embodiment;
[0045] Figure 7 This is a schematic diagram of the structure of the tunnel message provided in the embodiments of this application.
[0046] It should be noted that the terms "first" and "second" mentioned above are only used to distinguish between different options and do not represent the degree of superiority or inferiority of the options or their priority in the implementation process. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0048] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0049] In the following description, the terms "first, second, third" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0050] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0051] Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in the embodiments of this application is for the purpose of describing the embodiments of this application only and is not intended to limit this application.
[0052] In the implementation of this application, the collection and processing of relevant data should strictly comply with the requirements of relevant national laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.
[0053] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.
[0054] 1) Provider Edge (PE): This refers to devices located at the edge of the service provider network, directly connected to the user network, and serving as the interface between the user network and the service provider network. Provider Edge devices are typically high-performance switches or routers, capable of handling large data flows and providing high-speed connections to ensure that the user network can efficiently and reliably access various network services provided by the service provider.
[0055] 2) Customer Edge (CE): This refers to the edge device that connects the end-user network and the service provider network. For example, it is a home router or an edge router in an enterprise network. The customer edge device is responsible for managing the data flow into and out of the home or enterprise network.
[0056] 3) Internet Service Provider (ISP): This refers to companies that provide users with services such as Internet access, information retrieval, and online games, enabling users to access the Internet and use various network services. These typically include telecommunications operators, network service providers, and virtual private network providers.
[0057] 4) Virtual Routing and Forwarding Instances (VRF): Also known as virtual routing forwarding, it is a network virtualization technology implemented on routers or Layer 3 switches. Multiple virtual routing and forwarding instances created on the same device can be regarded as independent logical routers, used to create multiple isolated network environments on the same device, each with its own routing table and address space.
[0058] 5) Tunnel Encapsulation: This refers to the technique of encapsulating data packets into packets of different protocols for transmission by establishing a virtual channel between different network protocols. By adding extra header information to the original data packet, a tunnel is created, enabling the data packet to be transmitted through a network that is not directly supported.
[0059] 6) Autonomous System (AS): An Autonomous System is a network consisting of one or more blocks of network IP addresses, managed and controlled by a single administrative authority or entity. Routers within an AS use the Interior Gateway Protocol (IGP) to exchange routing information, while routers between ASs use the Border Gateway Protocol (BGP) to exchange routing information.
[0060] 7) Border Gateway Protocol (BGP): BGP is a routing protocol for autonomous systems that runs on TCP. BGP is the only protocol designed to handle networks the size of the Internet and is also the only one capable of effectively handling multiple connections between unrelated routing domains. BGP builds upon the experience gained from EGP. The primary function of a BGP system is to exchange network reachability information with other BGP systems. This network reachability information includes information about listed Autonomous Systems (AS). This information effectively constructs a topology map of interconnected ASes, thereby eliminating routing loops and enabling policy decisions at the AS level.
[0061] During the implementation of the embodiments of this application, the applicant discovered the following problems with the related technology:
[0062] In related technologies, to achieve traffic isolation between various Virtual Router Forwarding Instances (VRFs), such as... Figure 4 As shown, different virtual route forwarding instances are configured between the Service Provider Edge (PE) and the User Network Edge (CE). To transmit routing information and establish a Multiprotocol Label Switching (MPLS) tunnel between the PEs, the Multiprotocol Border Gateway Protocol (MP-BGP) is typically used. In this protocol, a Route Reflector (RR) is used to reflect routing information from the near-end PE to the far-end PE. The near-end PE assigns outer label information to different VRFs and passes this information to the far-end PE during route reflection. The inner label is assigned by the far-end PE based on the destination address of the data packet. In the packet forwarding process, a packet is sent from PE. The outer label of the packet indicates that the packet travels from PE to CE via the MPLS tunnel, and the inner label indicates that the packet travels from PE to CE.
[0063] However, in practical applications, the relevant technologies still have the following technical problems:
[0064] 1) Related technologies require all relevant equipment to support the MPLS protocol and meet the transmission capability of the label switching path to achieve label distribution, resulting in relatively high equipment and maintenance costs.
[0065] 2) In related technologies, tunnel creation and labeling are triggered and automatically assigned based on the original routes learned from the user network edge devices, making it impossible to route traffic to non-originating VRFs, such as... Figure 4In this scenario, Service Provider Edge Device 2 learns the original route from User Network Edge Device 10, and Service Provider Edge Device 2 is unable to forward traffic with the route prefix of VRF1 to VRF2 of User Network Edge Device 20.
[0066] This application provides a data transmission method, apparatus, electronic device, and computer-readable storage medium that can achieve flexible traffic scheduling based on virtual routing forwarding instances.
[0067] The data transmission system provided in the embodiments of this application is described below. See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of the data transmission system 10 provided in this application embodiment. In order to support a data transmission application, the terminals (terminal 100 and terminal 200) are connected to the server 400 through the network 300. The network 300 can be a wide area network or a local area network, or a combination of the two.
[0068] Terminal 100 is used to receive a label route carrying initial label information sent by terminal 200, respond to a label modification request sent by server 400, modify the initial label information carried by the label route to label information, perform tunnel encapsulation on the first message to be sent based on the label route to obtain a first encapsulated message, and send the first encapsulated message to terminal 200.
[0069] Terminal 200 is used to send a tag route carrying initial tag information to terminal 100, and to receive a first encapsulated message sent by terminal 100, and to perform tunnel decapsulation on the first encapsulated message.
[0070] Server 400 is used to send tag modification requests to terminal 100.
[0071] In some embodiments, server 400 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms. Terminal 100 and terminal 200 can be implemented as various types of terminal devices such as routers, switches, multi-layer switches, firewalls, laptops, and desktop computers, but are not limited to these. The electronic devices provided in this application embodiment can be implemented as terminals or servers. Terminals and servers can be directly or indirectly connected via wired or wireless communication, which is not limited in this application embodiment.
[0072] See Figure 2A , Figure 2AThis is a schematic diagram of the structure of a first electronic device for data transmission provided in an embodiment of this application, wherein, Figure 2A The electronic device 500 shown can be Figure 1 Terminal 100 in the middle, Figure 2A The illustrated electronic device 500 includes at least one processor 510, a memory 550, and at least one network interface 520. The various components in the electronic device 500 are coupled together via a bus system 540. It is understood that the bus system 540 is used to implement communication between these components. In addition to a data bus, the bus system 540 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 2A The general labeled all buses as Bus System 540.
[0073] The processor 510 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0074] The memory 550 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state storage, hard disk drives, optical disk drives, etc. The memory 550 may optionally include one or more storage devices physically located away from the processor 510.
[0075] The memory 550 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 550 described in this application embodiment is intended to include any suitable type of memory.
[0076] In some embodiments, memory 550 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or supersets thereof, as illustrated below.
[0077] Operating system 551 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;
[0078] The network communication module 552 is used to reach other electronic devices via one or more (wired or wireless) network interfaces 520, exemplary network interfaces 520 including: Bluetooth, WiFi, and Universal Serial Bus (USB), etc.
[0079] The input processing module 553 is used to detect and translate one or more user inputs or interactions from one or more input devices 532.
[0080] In some embodiments, the apparatus provided in this application can be implemented in software. Figure 2A A data transmission device 554 stored in memory 550 is shown. This device can be software in the form of programs and plug-ins, and includes the following software modules: a first routing management module 5541, a first message receiving module 5542, a first message processing module 5543, and a first message sending module 5544. These modules are logically connected and can therefore be arbitrarily combined or further divided according to their implemented functions. The functions of each module will be described below.
[0081] See Figure 2B , Figure 2B This is a schematic diagram of the structure of a second electronic device for data transmission provided in an embodiment of this application, wherein, Figure 2B The electronic device 600 shown can be Figure 1 Terminal 200 in the middle, Figure 2B The illustrated electronic device 600 includes at least one processor 610, a memory 650, and at least one network interface 620. The various components of the electronic device 600 are coupled together via a bus system 640. The memory 650 includes an operating system 651, a network communication module 652, and an input processing module 653. It should be noted that... Figure 2B The function of the structure in Figure 2A The structure in it functions similarly.
[0082] In some embodiments, the apparatus provided in this application can be implemented in software. Figure 2B A data transmission device 654 stored in memory 650 is shown. This device can be software in the form of programs and plug-ins, and includes the following software modules: a second routing management module 6541, a second message receiving module 6542, and a second message processing module 6543. These modules are logically linked and can therefore be arbitrarily combined or further separated according to their implemented functions. The functions of each module will be described below.
[0083] In other embodiments, the apparatus provided in this application can be implemented in hardware. For example, the apparatus provided in this application can be a processor in the form of a hardware decoding processor, which is programmed to execute the data transmission method provided in this application. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.
[0084] The data transmission method provided in the embodiments of this application is described below. This data transmission method can be implemented by the terminal alone, or by the server and the terminal working together. See also... Figure 3A , Figure 3A This is a first flowchart illustrating the data transmission method provided in this application embodiment. The following will be combined with... Figure 3A The steps shown are explained below. Figure 3A The execution entity of the steps is the first edge device (such as...) Figure 1 Terminal 100 in the middle).
[0085] In step 101, the tag route sent by the second edge device is received.
[0086] Here, the first edge device receives the label route sent by the second edge device, wherein the label route carries the initial label information.
[0087] As an example, label routing is routing data received by the first edge device from the second edge device. The first edge device and the second edge device can be two edge devices in the same autonomous system. The first edge device receives and learns label routing from the second edge device through a route reflector. The first edge device and the second edge device can also be peers in the same autonomous system that have established a neighbor relationship. Based on the border gateway protocol, the first edge device can receive and learn label routing from the second edge device.
[0088] As an example, label routing is routing data that carries initial label information. The value corresponding to the label field of a label route is the initial label information. For example, when the label field of a label route is "label": "1", the label information carried by the label route is 1, or the label value of the label route is 1.
[0089] In step 102, in response to the label modification request, the initial label information carried by the label route is modified to the target label information.
[0090] As an example, in response to a label modification request, the first edge device modifies the initial label information carried by the label route to the target label information. For example, if the initial label information carried by the label route is 1 and the label field of the label route is "label": "1", in response to the label modification request, the initial label information 1 of the label route is modified to the target label information 2, and the label field of the modified label route is "label": "2".
[0091] In some embodiments, Figure 3A Step 102 shown can be implemented in the following way: in response to the label modification operation of the first edge device, obtain the local routing import rule of the label route corresponding to the label modification operation; when the destination address of the label route is detected to be the target address according to the local routing import rule, modify the initial label information carried by the label route to the target label information.
[0092] The label modification request is implemented through the label modification operation. The local route import rule is used to indicate that when the destination address of the label route is the target address, the label information carried by the label route should be modified to the target label information.
[0093] As an example, a tag modification request is generated through a local tag modification operation. When the first edge device receives the tag route, it obtains the local route import rule corresponding to the tag modification operation through the destination address field of the tag route. The local route import rule is a route import rule stored locally on the first edge device. The first edge device stores at least one local route import rule, which is usually manually written by technicians when configuring the first edge device.
[0094] As an example of a route import rule, a route import rule can be a conditional statement, including an address discriminant and a label modification operation. When the address discriminant of the route import rule is satisfied, the label modification operation is executed. For example, the address discriminant of a local route import rule can be: "Determine whether the destination address of the label route is address A1", and the label modification operation of the local route import rule can be "Modify the label information carried by the label route to label information L1". Specifically, when the destination address of the label route is address A1, the address discriminant of the above local route import rule is satisfied, and the label modification operation of the above local route import rule is executed to modify the label information carried by the label route to label information L1.
[0095] In some embodiments, Figure 3A Step 102 shown can be implemented in the following way: receiving a label modification request sent by the controller; when the destination address of the label route is detected as the target address according to the remote route import rules, modifying the initial label information carried by the label route to the target label information.
[0096] The label modification request includes remote route import rules, which are route import rules issued by the controller. The remote route import rules are used to indicate that when the destination address of the label route is the target address, the label information carried by the label route should be modified to the target label information.
[0097] As an example, the receiving controller sends a label modification request carrying remote route import rules. For example, the address discrimination formula of the remote route import rule can be: "determine whether the destination address of the label route is address A2", and the label modification operation of the remote route import rule is "modify the label information carried by the label route to label information L2". Specifically, when the destination address of the label route is address A2, the above address discrimination formula of the remote route import rule is satisfied, and the above label modification operation of the remote route import rule is executed to modify the label information carried by the label route to label information L2.
[0098] Compared to the problem in related technologies where traffic between different virtual routing forwarding instances cannot communicate with each other, in the data transmission method of this application embodiment, the controller can dynamically modify the label information carried by the label route by issuing routing import rules, thereby realizing flexible scheduling of packet sending paths and flexible scheduling of traffic based on virtual routing forwarding instances.
[0099] In step 103, the label route is imported into the target virtual route forwarding instance corresponding to the target label information.
[0100] As an example of a virtual routing forwarding instance, each virtual routing forwarding instance is equivalent to a logical virtual router. Correspondingly, each virtual routing forwarding instance has its own Internet Protocol address (IP address) and routing table, in which the routing table of the virtual routing forwarding instance is used to store routing data.
[0101] As an example, there is a one-to-one correspondence between label information and virtual route forwarding instances. The target label information corresponds to the target virtual route forwarding instance. When the label information of the label route is the target label information, the label route is added to the routing table of the target virtual route forwarding instance. For example, when the label information of the label route is 2, the value of the label field of all route data in the routing table of the corresponding target virtual route forwarding instance is 2.
[0102] In step 104, the first message to be sent is received through the target virtual route forwarding instance.
[0103] As an example, the first message to be sent refers to an Internet Protocol (IP) message sent from a certain device. Its source address is the Internet Protocol address (IP address) of the sending device. For example, the source address of the first message to be sent can be the IP address of any device in the data center, and the next-hop address points to the IP address of the target virtual routing forwarding instance of the first edge device. When the first message to be sent is transmitted to the IP address of the target virtual routing forwarding instance, the first message to be sent is received through the target virtual routing forwarding instance.
[0104] In step 105, the first packet to be sent is tunnel-encapsulated based on the label route in the target virtual route forwarding instance to obtain the first encapsulated packet.
[0105] As an example, after the target virtual routing forwarding instance receives the first packet to be sent, it searches for routing data that matches the destination address of the first packet to be sent in the routing table of the target virtual routing forwarding instance to obtain the label route. Based on the label route, the first packet to be sent is tunnel encapsulated to obtain the first encapsulated packet.
[0106] In some embodiments, Figure 3A Step 105 shown can be implemented through the following steps: determining the local Internet Protocol address of the first edge device as the source address in the tunnel packet header, and determining the next-hop address of the label routing as the destination address in the tunnel packet header; determining the label field in the tunnel packet header based on the target label information of the label routing; determining the payload data of the tunnel packet based on the first packet to be sent; and constructing the first encapsulated packet based on the source address, destination address, label field, and payload data.
[0107] As an example, based on a tunneling protocol, the packet to be sent is encapsulated in a tunnel. The tunneling protocol can be a Generalized Routing Protocol (GRE), Internet Security Protocol (IPsec), Point-to-Point Tunneling Protocol (PPTP), Layer 2 Tunneling Protocol (L2TP), etc., and is not limited here. By encapsulating the packet in a tunnel, the forwarding of the packet is not limited by the protocol support (packet transmission protocol or routing transmission protocol) of each edge device. This allows for the free transmission of traffic across various heterogeneous networks. Furthermore, because the network devices in this embodiment do not need to uniformly support a fixed protocol, the equipment cost and maintenance cost are relatively low.
[0108] Taking the Generic Routing Protocol (GRE) as an example, the steps for tunneling the first packet to be sent are explained: Figure 7 As shown, Figure 7 This is a schematic diagram of the structure of a tunnel packet encapsulated based on the GRE protocol provided in this application embodiment. The tunnel packet consists of a tunnel packet header and tunnel packet payload data. The tunnel packet header consists of a network layer protocol header (IP header) and a tunnel encapsulation protocol header (GRE header). The IP header of the tunnel packet includes the source address field of the tunnel packet (corresponding to...). Figure 7 The outer source address and destination address fields (corresponding to) Figure 7 The outer destination address in the tunnel packet is used to write the IP address of the first edge device into the source address field of the tunnel packet header, and the next-hop address of the label route is written into the destination address field of the tunnel packet header; the GRE header of the tunnel packet includes a label field (corresponding to the outer destination address). Figure 7 The Key field in the header of the tunnel message has a length of 4 bytes. The target label information of the label routing is written into the label field of the GRE header of the tunnel message. The payload data of the tunnel message is the original message carried by the tunnel message. The first message to be sent is directly written as the payload data of the tunnel message.
[0109] In step 106, the first encapsulated message is sent to the second edge device.
[0110] As an example, before sending the first encapsulated message to the second edge device, a tunnel connection can be established between the first edge device and the second edge device based on the tunneling protocol of the first encapsulated message. The tunnel connects the endpoint of the target routing forwarding instance of the first edge device and the endpoint of the second edge device. The first encapsulated message travels from the endpoint of the target routing forwarding instance of the first edge device to the endpoint of the second edge device through the tunnel, thereby realizing the sending of the first encapsulated message.
[0111] See Figure 3B , Figure 3BThis is a second flowchart illustrating the data transmission method provided in this application embodiment. The data transmission method provided in this application embodiment can also be implemented through the following steps 201 to 205, which will be described in detail below. Figure 3B The execution entity of the steps is the first edge device.
[0112] In step 201, in response to the high-priority route delivery request, the first high-priority label route is obtained.
[0113] See Figure 6 , Figure 6 This is a schematic diagram of a data transmission method in a centralized security protection scenario provided in this application embodiment. When abnormal transmission behavior of packets in the current network is detected, for example, when abnormal transmission behavior of a packet sent from host 2 to host 1 is detected, the controller generates a high-priority route distribution request and distributes the request carrying a first high-priority route to the initial virtual route forwarding instance (i.e., virtual route forwarding instance 1) in the first edge device (i.e., edge device 1) connected to host 1. The first high-priority label route has a higher priority than the label route, and the next-hop address of the first high-priority label route points to the second edge device connected to the security protection device. The detection of abnormal packet transmission behavior can be achieved by detecting the packet sending frequency and packet size within a short period, or by using specialized network security detection tools; no limitation is imposed here.
[0114] In step 202, the first high-priority label route is imported into the initial virtual route forwarding instance corresponding to the initial label information.
[0115] As an example, the initial label information corresponds to the initial virtual route forwarding instance. The initial virtual route forwarding instance includes a routing table. The first high-priority label route is temporary routing data issued by the controller in response to a high-priority route issuance request. Therefore, it can be stored in the existing virtual route forwarding instance of the first edge device. See [link to relevant documentation]. Figure 6 In the centralized security protection scenario provided in this application embodiment, the first high-priority route issued by the controller is imported into the routing table of the existing initial virtual route forwarding instance (virtual route forwarding instance 1).
[0116] In step 203, the second message to be sent by the third edge device is received through the initial virtual routing forwarding instance.
[0117] See Figure 6The port of the initial virtual routing forwarding instance (virtual routing forwarding instance 1 of edge device 3) of the third edge device is connected to the host 2 that sent the abnormal message. The host 2 sends the second message to be sent to the initial virtual routing forwarding instance of the third edge device, and then the initial virtual routing forwarding instance of the third edge device sends the second message to the initial virtual routing forwarding instance of the first edge device (virtual routing forwarding instance 1 of edge device 1).
[0118] In step 204, based on the first high-priority label route imported in the initial virtual route forwarding instance, the second message to be sent is tunnel-encapsulated to obtain the second encapsulated message.
[0119] As an example, based on the first high-priority label routing, the second packet to be sent is tunnel-encapsulated to obtain the second encapsulated packet. For the specific steps, please refer to the method of tunnel encapsulating the first packet to be sent in step 105 above, which will not be repeated here.
[0120] In step 205, a second encapsulated message is sent to the second edge device pointed to by the next-hop address of the first high-priority label route.
[0121] As an example, a tunnel connection is established between the endpoint of the initial routing forwarding instance of the first edge device and the endpoint of the second edge device to enable the transmission of the second encapsulated message. This is similar to the method of sending the first encapsulated message to the second edge device. For specific steps, please refer to step 106 above, which will not be repeated here.
[0122] The data transmission method provided in the embodiments of this application is described below. This data transmission method can be implemented by the terminal alone, or by the server and the terminal working together. See also... Figure 3C , Figure 3C This is a schematic diagram of the third process of the data transmission method provided in the embodiments of this application. The following will be combined with... Figure 3C The steps shown are explained below. Figure 3C The execution entity for this step is the second edge device (terminal 200).
[0123] In step 301, a tag route carrying initial tag information is sent to the first edge device.
[0124] In some embodiments, Figure 3C Before step 301 shown, the following steps may also be performed: assign target label information to the target virtual route forwarding instance; and create a target Layer 3 tunnel interface on the second edge device based on the target label information.
[0125] As an example, an initial virtual routing forwarding instance is created on the second edge device. Initial label information is assigned to the initial virtual routing forwarding instance. A Layer 3 tunnel interface corresponding to the initial label information is created on the port of the initial virtual routing forwarding instance. For example, if the initial label information assigned to the initial virtual routing forwarding instance is 1, it means that the label value of each route data in the initial virtual routing forwarding instance is 1. A Layer 3 tunnel interface with a mapping relationship to the label value 1 is created on the port of the initial virtual routing forwarding instance. The virtual routing forwarding instance contains multiple ports that can be used to create Layer 3 tunnel interfaces. The mapping relationship between the label value and the Layer 3 tunnel interface can be stored by storing the label value as any field of the port, or by creating a mapping relationship table between the port and the label value on the edge device. No limitation is imposed here.
[0126] As an example, a target virtual route forwarding instance can also be created on the second edge device, target label information can be assigned to the target virtual route forwarding instance, and a Layer 3 tunnel interface corresponding to the target label information can be created on the port of the target virtual route forwarding instance. For example, if the target label information assigned to the target virtual route forwarding instance is 2, it means that the label value of each route data in the target virtual route forwarding instance is 2, and a Layer 3 tunnel interface with a mapping relationship to the label value 2 can be created on the port of the target virtual route forwarding instance.
[0127] In step 302, the first encapsulated message sent by the first edge device is received.
[0128] As an example, the second edge device receives the first encapsulated message sent by the first edge device through a tunnel. The first encapsulated message is obtained by the first edge device through tunnel encapsulation of the first message to be sent based on the label route in the target virtual route forwarding instance. The target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information. The target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route.
[0129] In step 303, the first encapsulated message is tunneled and decapsulated to obtain the original message of the first encapsulated message.
[0130] As an example, when the second edge device receives the first encapsulated message, it identifies the header of the first encapsulated message, obtains the tunnel protocol of the first encapsulated message, and decapsulates the first encapsulated message based on the tunnel protocol.
[0131] In some embodiments, step 303 can be implemented in the following ways: obtaining the original message of the first encapsulated message based on the payload data of the first encapsulated message; determining the target tag information carried by the original message based on the tag field of the tunnel message header of the first encapsulated message.
[0132] As an example, based on the tunneling protocol, the first encapsulated message is decapsulated through tunneling. Taking the Generic Routing Protocol (GRE) as an example, the payload data of the first encapsulated message is used as the original message of the first encapsulated data, and the value of the tag field in the GRE header of the first encapsulated message is used as the tag information carried in the original message. The tag information carried in the first encapsulated message is the target tag information, and the original message of the first encapsulated message is the first message to be sent.
[0133] In some embodiments, see Figure 3D , Figure 3D This is a schematic diagram of the fourth process of the data transmission method provided in the embodiments of this application. Figure 3C After step 303 shown, steps 304 to 306 can also be executed, as explained in detail below.
[0134] In step 304, the target Layer 3 tunnel interface corresponding to the target label information carried by the original message is determined, and the original message is transferred to the target virtual route forwarding instance corresponding to the target Layer 3 tunnel interface.
[0135] As an example, based on the mapping relationship between the Layer 3 tunnel interface and the label information, the target Layer 3 tunnel interface corresponding to the target label information carried by the original packet is determined. The target Layer 3 tunnel interface is created on the port of the target virtual routing forwarding instance, and then the original packet is forwarded to the target virtual routing forwarding instance through the target Layer 3 tunnel interface.
[0136] In step 305, the target label route corresponding to the original packet is obtained based on the target virtual route forwarding instance.
[0137] As an example, the target virtual route forwarding instance includes a routing table. The target label route is obtained by looking up the routing data in the routing table of the target virtual route forwarding instance that matches the destination address of the original packet.
[0138] In step 306, the original message is sent based on the target label routing.
[0139] As an example, the original message is sent to the next-hop address of the target label route, where the next-hop address of the target label route can point to other edge devices or to a user device in the data center, without limitation.
[0140] See Figure 3E , Figure 3E This is a fifth flowchart illustrating the data transmission method provided in this application embodiment. The data transmission method provided in this application embodiment can also be implemented through the following steps 401 to 403, which will be described in detail below. Figure 3E The execution entity for this step is the second edge device.
[0141] In step 401, in response to the high-priority route delivery request, the second high-priority label route is obtained.
[0142] See Figure 6 , Figure 6 This is a schematic diagram of a data transmission method in a centralized security protection scenario provided in this application embodiment. When abnormal transmission behavior of packets in the current network is detected, for example, when abnormal transmission behavior of the packet sent by host 2 to host 1 is detected, the controller generates a high-priority route delivery request and sends a high-priority route delivery request carrying a second high-priority route to the initial virtual forwarding instance in the second edge device (i.e., the virtual route forwarding instance 1 in device 2). The second high-priority label route has a higher priority than the label route.
[0143] In some embodiments, Figure 3E After step 401 shown, the following steps can also be performed: import the second high-priority label route into the initial virtual route forwarding instance corresponding to the initial label information; create a high-priority Layer 3 tunnel interface corresponding to the high-priority label information.
[0144] As an example, the second high-priority label route carrying high-priority label information is imported into the routing table of the initial virtual route forwarding instance. For example, if the high-priority label information carried by the second high-priority label route is 3, the second high-priority label route with a label value of 3 is imported into the routing table of the initial virtual route forwarding instance. At the same time, a Layer 3 tunnel interface with a mapping relationship with the high-priority label information is created on the port of the initial virtual route forwarding instance of the second edge device.
[0145] In step 402, the second encapsulated message sent by the first edge device is received.
[0146] As an example, the second edge device receives a second encapsulated message sent by the first edge device through a tunnel. The second encapsulated message is obtained by the first edge device through tunnel encapsulation of the second message to be sent based on the first high-priority label routing.
[0147] In step 403, the second encapsulated message is tunneled and decapsulated to obtain the original message of the second encapsulated message.
[0148] As an example, when the second edge device receives the second encapsulated message, it identifies the message header of the second encapsulated message, obtains the tunnel protocol of the second encapsulated message, and decapsulates the second encapsulated message based on the tunnel protocol. Based on the payload data of the second encapsulated message, it obtains the original message of the second encapsulated message, and determines the high-priority tag information carried by the original message based on the tag field of the tunnel message header of the second encapsulated message.
[0149] In some embodiments, see Figure 3F , Figure 3F This is a sixth flowchart illustrating the data transmission method provided in this application embodiment. Figure 3E After step 403 shown, steps 404 to 405 can also be executed, as explained in detail below.
[0150] In step 404, the original packet of the second encapsulated packet is transferred to the initial virtual route forwarding instance corresponding to the high-priority Layer 3 tunnel interface.
[0151] As an example, based on the mapping relationship between the Layer 3 tunnel interface and the label information, the high-priority Layer 3 tunnel interface corresponding to the high-priority label information is determined. The high-priority Layer 3 tunnel interface is created on the port of the initial virtual routing forwarding instance, and then the original packet of the second encapsulated packet is forwarded to the initial virtual routing forwarding instance corresponding to the high-priority Layer 3 tunnel interface.
[0152] In step 405, the next-hop address of the second high-priority label route imported in the initial virtual routing forwarding instance is determined, and the original packet of the second encapsulated packet is sent to the target device pointed to by the next-hop address through the initial virtual routing forwarding instance.
[0153] See Figure 6 The next-hop address of the second high-priority label route points to the security protection device. The original packet of the second encapsulated message is sent to the security protection device through the initial virtual routing forwarding instance of the second edge device (virtual routing forwarding instance 1 of edge device 2). By controlling the traffic transmission path through the high-priority label route issued by the controller, traffic scrubbing among multiple virtual routing forwarding instances in a security protection scenario is achieved.
[0154] The following will describe exemplary applications of the embodiments of this application in practical application scenarios.
[0155] In related technologies, the use of Multiprotocol Label Switching (MPLS) Layer 3 Virtual Private Network (L3VPN) technology to achieve traffic forwarding between Virtual Router Forwarding Instances (VRFs) requires all related devices to support the MPLS protocol, resulting in relatively high equipment and maintenance costs. Furthermore, in MPLS L3VPN technology, the VRF instances (VRFs) in the Provider Edge device (PE) receive and learn the original routes from the user network edge device, thereby triggering tunnel creation and automatic label allocation. Therefore, it is impossible to schedule traffic to other VRFs, and thus, arbitrary traffic forwarding is not possible.
[0156] To address the aforementioned issues, this application proposes a data transmission method. This method involves creating a Layer 3 tunnel interface (network layer tunnel interface) in the VRF of the sending service provider edge device and binding different VRFs based on different labels. Then, the local routing appended label information is transmitted to the entire network via the Multiprotocol Border Gateway Protocol (MP-IBGP). The sending service provider edge device encapsulates the original Internet Protocol (IP) packets in its local VRF using the label information in the routing and then sends them to the receiving service provider edge device. The receiving service provider edge device imports traffic into different VRFs through different tunnel interfaces. While achieving traffic forwarding, flexible traffic scheduling between any VRFs is achieved through flexible label distribution and modification of labels via routing policies.
[0157] The implementation of the scheme in this application mainly includes four parts: label allocation, label routing, forwarding table entry mapping for label routing, tunnel encapsulation, and decapsulation. The specific implementation of each part is as follows:
[0158] 1) Tag assignment
[0159] By assigning labels to routing data, different types of routing data can be classified, and the label values of routing data can be modified through routing policies to achieve more flexible label generation.
[0160] The routing data label is 24 bits long (4 bytes), which can accommodate very large networks and ensure that the routing label is unique throughout the network, thus ensuring the isolation between tunnels.
[0161] Based on the coarse-to-fine dimensions of label allocation, route label allocation methods include: allocation by VRF, allocation by Border Gateway Protocol Peer (BGP Peer), and allocation by route next hop. Among them, VRF allocation means that all routes in a VRF are assigned the same label, and packets carrying the same label travel through the same tunnel; BGP Peer allocation means that each pair of BGP peers is assigned the same label, and packets carrying the same label travel through the same tunnel; in scenarios where routes transmitted by BGP peers have many next hops, a label can also be assigned for each next hop.
[0162] Label allocation can be divided into automatic label allocation and manual label allocation. For automatic label allocation, after allocation, a tunnel interface corresponding to the label needs to be created on the VRF where the routing data of the assigned label is located. The tunnel interface is distinguished according to the label value. The tunnel interface is used to receive tunnel-encapsulated packets carrying the same label from other edge devices. For manual label allocation, technicians usually need to manually or through the software-defined network controller (SDN controller) to orchestrate routing labels and create tunnel interfaces corresponding to the labels to avoid tunnel traffic black holes.
[0163] 2) Tag routing forwarding
[0164] The protocol-reachable network layer routing information (MP_REACH_NLRI) in the relevant routing protocol of the Multiprotocol Internal Border Gateway Protocol (MP-IBGP) is used to transmit routes and labels to edge devices throughout the network. See Table 1. The protocol-reachable network layer routing information (NLRI) consists of the Length of NLRI field, the Label field, the Route Distinguisher field, and the IP Prefix field. The Label field is fixed at 3 bytes. By writing different label values into the Label field, label information is assigned to the routing data. The Label field can also guide tunnel encapsulation and forwarding. Other fields in the protocol-reachable network layer routing information should conform to the standard protocol definition.
[0165] Table 1. Routing Field Definition Comparison Table
[0166] Fields describe Address Family Identifier Address family information, 2 bytes Address Family Identifier Sub-address family attribute information, 1 byte Length of Next Hop Network Address The length of the next-hop address is 1 byte. Next Hop Network Address Information Next-hop address information, variable length Reserved Reserved field, 1 byte Length of NLRI The length of the network layer routing information that can be reached by the protocol is 1 byte. Label Tag, 3 bytes Route Distinguisher Router Differentiator, Variable Length IP Prefix Routing prefix, variable length
[0167] 3) Mapping of forwarding entries for tag routing
[0168] When an edge device receives a label route, it sends forwarding table entries. If a route entry matching the label route's prefix exists in the routing table, the next-hop address (Next Hop Network AddressInformation) field of the label route is used as the destination address for tunnel encapsulation, the local IP address is used as the source address for tunnel encapsulation, and the label is used as the key field for tunnel encapsulation. When sending a packet, the IP packet to be forwarded is directly encapsulated as payload data and transmitted to the other end, thus achieving tunnel forwarding.
[0169] 4) Tunnel encapsulation and decapsulation
[0170] Taking the Generic Routing Protocol Encapsulation (GRE) as an example, the encapsulated message format is as follows: Figure 7 When the sending end sends the encapsulated message, it performs tunnel encapsulation on the message. The outer destination address of the tunnel is the next-hop field of the routing data, and the outer source address is the local IP address. In the Generic Routing Protocol (GRE) header, the K flag is set to 1, and the tag value of the routing data is written in the key field. Other fields are written according to the GRE standard protocol. The content of the original message is not changed in any way and is used as the payload data of the encapsulated message.
[0171] After receiving the GRE-encapsulated packet, the receiving end finds that the destination address of the packet is the local IP. It then decapsulates the packet. First, after recognizing that the header of the packet is a GRE header, it decapsulates the GRE header, reads the tag information from the Key field, finds the Layer 3 tunnel interface mapped by the tag information, and forwards the original packet traffic to the VRF connected to the Layer 3 tunnel interface. In the VRF, it queries the corresponding route and continues to forward the traffic, thus realizing Layer 3 tunnel forwarding based on tag routing between the VRFs of each PE.
[0172] The following describes the application scenarios of the data transmission method provided in the embodiments of this application.
[0173] like Figure 5 As shown, Figure 5 This is a schematic diagram of a traffic scheduling scenario provided in the embodiments of this application. Specifically, the data transmission method of this embodiment can realize the function of scheduling traffic among multiple Internet Service Providers (ISPs). Here, we take the Internet exits of two Internet Service Providers as an example for illustration.
[0174] like Figure 5As shown, edge device 2 is the internet exit point, and internet service provider 1 is a regional operator that establishes a connection with edge device 2 through VRF1 to collect detailed routes. Internet service provider 2 is a global operator that establishes a connection with edge device 2 through VRF2 to collect default routes. Internet service provider 1 and internet service provider 2 are connected to Autonomous System 1 (AS), and traffic can access devices in AS through internet service provider 1 and internet service provider 2. Different label information is assigned to different VRFs, and Layer 3 tunnel interfaces corresponding to the labels are created on the VRFs. Specifically, the label value of VRF1 is set to 1 (label = 1), and Layer 3 tunnel interface 1 (the Layer 3 tunnel interface of tunnel 1) is created on VRF1 of edge device 2. The label value of VRF2 is set to 2 (label = 2), and Layer 3 tunnel interface 2 (the Layer 3 tunnel interface of tunnel 2) is created on VRF2 of edge device 1.
[0175] Normally, since only Internet Service Provider 1 (ISP 1) announces the detailed network segment of Autonomous System 1, when service traffic needs to access Autonomous System 1, it will access Autonomous System 1 through ISP 1 connected to VRF1 of ISP Edge Device 2. However, when network quality detection finds that the service traffic accessing the network segment corresponding to Autonomous System 1 has better quality (lower packet loss rate, lower latency) through ISP 2, the routes of VRF1 and VRF2 in ISP Edge Device 2 are reflected back to ISP Edge Device 1 through the Route Reflector (RR). Based on the route cross-import policy of VRF3, ISP Edge Device 1 imports routes from both ISP 1 and ISP 2 into VRF3. The route cross-import policy of VRF3 is: when the destination address of the service traffic is Autonomous System 1, the label value of the route in VRF3 is modified to 2.
[0176] When traffic from the data center (DC) accesses Autonomous System 1, it queries the label value of the route in VRF3 as 2, encapsulates and sends the service traffic packets based on tunnel 2, and decapsulates them when they reach Service Provider Edge Device 2. Then, it accesses Autonomous System 1 through Internet Service Provider 2 connected to VRF2 of Service Provider Edge Device 2. This allows the label information of the route at the packet sender to be modified through the route cross-import strategy, enabling the service traffic to be forwarded to any designated VRF and flexibly scheduled based on network quality.
[0177] like Figure 6 As shown, Figure 6This is a schematic diagram of a data transmission method in a centralized security protection scenario provided in this application embodiment. The security protection device (Anti-DDOS) is only mounted and deployed next to the area where the service provider edge device 2 is located. It establishes a connection with the edge device 1 through VRF1 (host 1 publishes routes to the VRF1 of the service provider edge device 1) and sets the label value of VRF1 to 1 (label=1). A Layer 3 tunnel interface of tunnel 1 is created on the VRF1 of the service provider edge device 1. The routes with the label value equal to 1 in the VRF1 of the service provider edge device 1 are reflected to the service provider edge device 2 and the service provider edge device 3 through a route reflector. That is, VRF1 is created in the service provider edge device 2 and the service provider edge device 3, and the routes with the label value equal to 1 are imported. Create VRF2 in Service Provider Edge Device 2. Import the route of Host 1 from VRF1 in Service Provider Edge Device 2 into VRF2, and modify the label value of the imported route from 1 to 2. Create VRF2 in Service Provider Edge Device 1 and import the original route of Host 1 (route data without label value). Create a Layer 3 tunnel interface for Tunnel 2 on VRF2 of Service Provider Edge Device 1.
[0178] Normally, service traffic is forwarded only within VRF1 of Service Provider Edge Device 2, Service Provider Edge Device 1, and Service Provider Edge Device 3. However, when the security system detects an attack, it orchestrates the Layer 3 tunnel interface and changes the label values of the routes to perform attack traffic scrubbing and reinjection between different VRFs, thereby achieving secure data transmission. Specifically:
[0179] When host 2 in data center 2 attempts to attack host 1, the controller issues a high-priority scheduling route for host 1 to VRF1 of service provider edge device 1 and VRF1 of service provider edge device 2. The label value of the high-priority route for host 1 issued by VRF1 of service provider edge device 1 is 3, the next-hop address is service provider edge device 2, and the next-hop address for host 1 issued by VRF1 of service provider edge device 2 is the security protection device. A layer 3 tunnel interface of tunnel 3 is established on VRF1 of service provider edge device 2.
[0180] The traffic forwarding path at this time is as follows Figure 6As shown by the arrow, the attack traffic from host 2 is sent to VRF1 of service provider edge device 3. The label value of the host 1 route in VRF1 of service provider edge device 3 is found to be 1. The attack traffic is then forwarded to VRF1 of service provider edge device 1 through tunnel 1. The label value of the high-priority route of host 1 in VRF1 of service provider edge device 3 is found to be 3, and the next-hop address is service provider edge device 2. The attack traffic is then forwarded to VRF1 of service provider edge device 2 through tunnel 3. The next-hop address of the high-priority route of host 1 in VRF1 of service provider edge device 2 is found to be the security protection device. The attack traffic is then forwarded to the security protection device. After the attack traffic is cleaned in the security protection device, it is sent to VRF2 of service provider edge device 2. The label value of the host 1 route in VRF2 of service provider edge device 2 is found to be 2. The attack traffic is then tunneled to VRF2 of service provider edge device 1 through tunnel 2. Finally, the route of host 1 is found on VRF2, and the cleaned traffic is sent back to host 1 via ordinary IP forwarding.
[0181] In summary, the data transmission method proposed in this application can efficiently realize arbitrary traffic forwarding based on VRF between edge devices and improve the dynamic convergence capability of routing; by tunneling and encapsulating packets for transmission, it is not limited by the protocol support of each edge device and can realize free transmission of traffic across various heterogeneous networks; in addition, it can allocate and modify labels based on the routing policy issued by the controller, thereby realizing packet forwarding and routing scheduling capabilities for any service chain.
[0182] The following description continues to illustrate the exemplary structure of the data transmission device 554 provided in the embodiments of this application as a software module. In some embodiments, such as... Figure 2A As shown, a software module stored in a data transmission device 554 of the memory 540 may include:
[0183] The first routing management module 5541 is used to receive a label route sent by the second edge device, wherein the label route carries initial label information; in response to a label modification request, the initial label information carried by the label route is modified to target label information; and the label route is imported into the target virtual route forwarding instance corresponding to the target label information.
[0184] The first message receiving module 5542 is used to receive the first message to be sent through the target virtual routing forwarding instance.
[0185] The first message processing module 5543 is used to perform tunnel encapsulation on the first message to be sent based on the label route in the target virtual route forwarding instance to obtain a first encapsulated message.
[0186] The first message sending module 5544 is used to send the first encapsulated message to the second edge device.
[0187] In some embodiments, the first routing management module 5541 is further configured to, in response to the label modification operation local to the first edge device, obtain the local routing import rule of the label route corresponding to the label modification operation, wherein the label modification request is implemented through the label modification operation, and the local routing import rule is used to instruct that when the destination address of the label route is the target address, the label information carried by the label route is modified to the target label information; when the destination address of the label route is detected to be the target address according to the local routing import rule, the initial label information carried by the label route is modified to the target label information.
[0188] In some embodiments, the first routing management module 5541 is further configured to receive the label modification request sent by the controller, wherein the label modification request includes a remote routing import rule, the remote routing import rule being configured to instruct that when the destination address of the label route is the target address, the label information carried by the label route be modified to the target label information; and when the destination address of the label route is detected to be the target address according to the remote routing import rule, the initial label information carried by the label route be modified to the target label information.
[0189] In some embodiments, the first message processing module 5543 is further configured to determine the local Internet Protocol address of the first edge device as the source address in the tunnel message header, and determine the next-hop address of the label routing as the destination address in the tunnel message header; determine the label field in the tunnel message header based on the target label information of the label routing; determine the payload data of the tunnel message based on the first message to be sent; and construct the first encapsulated message based on the source address, the destination address, the label field, and the payload data.
[0190] In some embodiments, the first routing management module 5541 is further configured to, in response to a high-priority route issuance request, obtain a first high-priority label route, wherein the priority of the first high-priority label route is higher than the priority of the label route, and the next-hop address of the first high-priority label route points to the second edge device; and import the first high-priority label route into the initial virtual route forwarding instance corresponding to the initial label information.
[0191] In some embodiments, the first message receiving module 5542 is further configured to receive a second message to be sent by a third edge device through the initial virtual routing forwarding instance.
[0192] In some embodiments, the first message processing module 5543 is further configured to perform tunnel encapsulation on the second message to be sent based on the first high-priority label route imported in the initial virtual routing forwarding instance, to obtain a second encapsulated message.
[0193] In some embodiments, the first message sending module 5544 is further configured to send the second encapsulated message to the second edge device pointed to by the next-hop address of the first high-priority label route.
[0194] The following description continues to illustrate the exemplary structure of the data transmission device 654 provided in the embodiments of this application as a software module. In some embodiments, such as... Figure 2B As shown, a software module stored in a data transmission device 654 of the memory 640 may include:
[0195] The second routing management module 6541 is used to send a tag route carrying initial tag information to the first edge device.
[0196] The second message receiving module 6542 is used to receive a first encapsulated message sent by the first edge device, wherein the first encapsulated message is obtained by the first edge device through tunnel encapsulation based on the label route in the target virtual route forwarding instance, the target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information, and the target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route.
[0197] The second message processing module 6543 performs tunnel decapsulation on the first encapsulated message to obtain the original message of the first encapsulated message.
[0198] In some embodiments, the second message processing module 6543 is further configured to obtain the original message of the first encapsulated message based on the payload data of the first encapsulated message; and to determine the target tag information carried by the original message based on the tag field of the tunnel message header of the first encapsulated message.
[0199] In some embodiments, the second message sending module 6544 is configured to determine the target Layer 3 tunnel interface corresponding to the target label information carried in the original message, and forward the original message to the target virtual route forwarding instance corresponding to the target Layer 3 tunnel interface; obtain the target label route corresponding to the original message based on the target virtual route forwarding instance; and send the original message based on the target label route.
[0200] In some embodiments, the second routing management module 6541 is further configured to allocate the target label information to the target virtual routing forwarding instance; and create a target Layer 3 tunnel interface on the second edge device based on the target label information.
[0201] In some embodiments, the second routing management module 6541 is further configured to obtain a second high-priority label route in response to a high-priority route issuance request, wherein the priority of the second high-priority label route is higher than the priority of the label route.
[0202] In some embodiments, the second message receiving module 6542 is further configured to receive a second encapsulated message sent by the first edge device, wherein the second encapsulated message is obtained by the first edge device performing tunnel encapsulation on a second message to be sent based on the first high-priority label routing.
[0203] In some embodiments, the second message processing module 6543 is further configured to perform tunnel decapsulation on the second encapsulated message to obtain the original message of the second encapsulated message.
[0204] In some embodiments, the second routing management module 6541 is further configured to import the second high-priority label route into the initial virtual route forwarding instance corresponding to the initial label information, wherein the second high-priority label route carries high-priority label information; and create a high-priority Layer 3 tunnel interface corresponding to the high-priority label information.
[0205] In some embodiments, the second message sending module 6544 is further configured to transfer the original message of the second encapsulated message to the initial virtual routing forwarding instance corresponding to the high-priority Layer 3 tunnel interface; determine the next-hop address of the second high-priority label route imported in the initial virtual routing forwarding instance; and send the original message of the second encapsulated message to the target device pointed to by the next-hop address through the initial virtual routing forwarding instance.
[0206] This application provides a computer program product, which includes a computer program or computer-executable instructions stored in a computer-readable storage medium. A processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, causing the electronic device to perform the data transmission method described above in this application.
[0207] This application provides a computer-readable storage medium storing computer-executable instructions or a computer program. When the computer-executable instructions or the computer program are executed by a processor, the processor will execute the data transmission method provided in this application. For example, ... Figures 3A to 3F The data transmission method is shown.
[0208] In some embodiments, the computer-readable storage medium may be a memory such as RAM, ROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or it may be a variety of devices including one or any combination of the above-mentioned memories.
[0209] In some embodiments, computer-executable instructions may take the form of programs, software, software modules, scripts, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as stand-alone programs or as modules, components, subroutines, or other units suitable for use in a computing environment.
[0210] As an example, computer-executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple co-located files (e.g., files that store one or more modules, subroutines, or code sections).
[0211] As an example, computer-executable instructions can be deployed to execute on a single electronic device, or on multiple electronic devices located in one location, or on multiple electronic devices distributed across multiple locations and interconnected via a communication network.
[0212] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.
Claims
1. A data transmission method, characterized in that, Applied to a first edge device, the method includes: Receive a tag route sent by a second edge device, wherein the tag route carries initial tag information; In response to a tag modification request, the initial tag information carried by the tag route is modified to the target tag information; Import the label route into the target virtual route forwarding instance corresponding to the target label information; The first message to be sent is received through the target virtual route forwarding instance; Based on the label route in the target virtual route forwarding instance, the first message to be sent is tunnel-encapsulated to obtain the first encapsulated message; Send the first encapsulated message to the second edge device.
2. The method according to claim 1, characterized in that, The tag modification request is implemented through a tag modification operation; The step of responding to a label modification request by modifying the initial label information carried by the label route to the target label information includes: In response to the label modification operation on the first edge device, the local routing import rule of the label route corresponding to the label modification operation is obtained, wherein the local routing import rule is used to indicate that when the destination address of the label route is the target address, the label information carried by the label route is modified to the target label information; When the destination address of the label route is detected to be the target address according to the local route import rule, the initial label information carried by the label route is modified to the target label information.
3. The method according to claim 1, characterized in that, The step of responding to a label modification request by modifying the initial label information carried by the label route to the target label information includes: The label modification request sent by the controller is received, wherein the label modification request includes a remote route import rule, and the remote route import rule is used to indicate that when the destination address of the label route is the target address, the label information carried by the label route is modified to the target label information; When the destination address of the label route is detected to be the target address according to the remote route import rule, the initial label information carried by the label route is modified to the target label information.
4. The method according to any one of claims 1-3, characterized in that, The first packet to be sent is tunnel-encapsulated based on the label route in the target virtual route forwarding instance to obtain a first encapsulated packet, including: The local Internet Protocol address of the first edge device is determined as the source address in the tunnel packet header, and the next-hop address of the label routing is determined as the destination address in the tunnel packet header; Based on the target label information of the label routing, the label field in the tunnel packet header is determined; Based on the first message to be sent, determine the payload data of the tunnel message; The first encapsulated message is constructed based on the source address, the destination address, the tag field, and the payload data.
5. The method according to any one of claims 1-3, characterized in that, The method further includes: In response to a high-priority route delivery request, a first high-priority label route is obtained, wherein the priority of the first high-priority label route is higher than the priority of the label route, and the next-hop address of the first high-priority label route points to the second edge device; Import the first high-priority label route into the initial virtual route forwarding instance corresponding to the initial label information; The initial virtual routing forwarding instance receives the second message to be sent from the third edge device. Based on the first high-priority label route imported in the initial virtual routing forwarding instance, the second message to be sent is tunnel-encapsulated to obtain the second encapsulated message. Send the second encapsulated message to the second edge device pointed to by the next-hop address of the first high-priority label route.
6. A data transmission method, characterized in that, Applied to a second edge device, the method includes: Send a tag route carrying initial tag information to the first edge device; The first encapsulated message sent by the first edge device is received, wherein the first encapsulated message is obtained by the first edge device through tunnel encapsulation based on the label route in the target virtual route forwarding instance, the target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information, and the target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route; The first encapsulated message is decapsulated through a tunnel to obtain the original message of the first encapsulated message.
7. The method according to claim 6, characterized in that, The step of tunneling and decapsulating the first encapsulated message to obtain the original message of the first encapsulated message includes: Based on the payload data of the first encapsulated message, the original message of the first encapsulated message is obtained.
8. The method according to claim 7, characterized in that, When obtaining the original message of the first encapsulated message based on the payload data of the first encapsulated message, the method further includes: Based on the tag field in the tunnel header of the first encapsulated message, the target tag information carried by the original message is determined; After performing tunnel decapsulation on the first encapsulated message to obtain the original message of the first encapsulated message, the method further includes: Determine the target Layer 3 tunnel interface corresponding to the target label information carried in the original message, and forward the original message to the target virtual route forwarding instance corresponding to the target Layer 3 tunnel interface; Based on the target virtual route forwarding instance, obtain the target label route corresponding to the original packet; Based on the target label routing, the original message is sent.
9. The method according to any one of claims 6-8, characterized in that, Before sending the tag route carrying the initial tag information to the first edge device, the method further includes: Assign the target label information to the target virtual route forwarding instance; Based on the target tag information, a target three-layer tunnel interface is created on the second edge device.
10. The method according to claim 6, characterized in that, The method further includes: In response to a high-priority route delivery request, a second high-priority label route is obtained, wherein the priority of the second high-priority label route is higher than the priority of the label route; The first edge device receives a second encapsulated message, wherein the second encapsulated message is obtained by the first edge device performing tunnel encapsulation on a second message to be sent based on the first high-priority label routing. The second encapsulated message is tunneled and decapsulated to obtain the original message of the second encapsulated message.
11. The method according to claim 10, characterized in that, After responding to a high-priority route delivery request and obtaining the second high-priority label route, the method further includes: The second high-priority label route is imported into the initial virtual route forwarding instance corresponding to the initial label information, wherein the second high-priority label route carries high-priority label information; Create a high-priority Layer 3 tunnel interface corresponding to the high-priority tag information; After performing tunnel decapsulation on the second encapsulated message to obtain the original message of the second encapsulated message, the method further includes: The original packet of the second encapsulated packet is forwarded to the initial virtual route forwarding instance corresponding to the high-priority Layer 3 tunnel interface; The next-hop address of the second high-priority label route imported in the initial virtual route forwarding instance is determined, and the original packet of the second encapsulated packet is sent to the target device pointed to by the next-hop address through the initial virtual route forwarding instance.
12. A data transmission device, characterized in that, Applied to a first edge device, the device includes: The first routing management module is used to receive a label route sent by the second edge device, wherein the label route carries initial label information; in response to a label modification request, the module modifies the initial label information carried by the label route to target label information; and imports the label route into the target virtual route forwarding instance corresponding to the target label information. The first message receiving module is used to receive the first message to be sent through the target virtual routing forwarding instance; The first message processing module is used to perform tunnel encapsulation on the first message to be sent based on the label route in the target virtual route forwarding instance to obtain a first encapsulated message. The first message sending module is used to send the first encapsulated message to the second edge device.
13. A data transmission device, characterized in that, Applied to a second edge device, the device includes: The second routing management module is used to send a tag route carrying initial tag information to the first edge device; The second message receiving module is used to receive the first encapsulated message sent by the first edge device, wherein the first encapsulated message is obtained by the first edge device through tunnel encapsulation based on the label route in the target virtual route forwarding instance, the target virtual route forwarding instance is the virtual route forwarding instance corresponding to the target label information, and the target label information is the label information obtained by the first edge device after modifying the initial label information carried by the label route; The second message processing module performs tunnel decapsulation on the first encapsulated message to obtain the original message of the first encapsulated message.
14. An electronic device, characterized in that, The electronic device includes: Memory is used to store executable instructions for a computer; Memory is used to store executable instructions for a computer; A processor, when executing computer-executable instructions or computer programs stored in the memory, implements the data transmission method according to any one of claims 1 to 11.
15. A computer-readable storage medium storing computer-executable instructions or a computer program, characterized in that, When the computer-executable instructions or computer program are executed by a processor, the data transmission method according to any one of claims 1 to 11 is implemented.