Method and device for processing message
By employing a parallel ACL lookup mechanism and priority processing, the problem of low ACL lookup efficiency in network devices is solved, achieving efficient multi-dimensional packet control and resource optimization.
Patent Information
- Application Number
- CN202511152854.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-18
- Publication Date
- 2025-11-11
AI Technical Summary
Existing ACL lookup methods in network devices are insufficient to meet the needs of complex scenarios, cannot implement multi-dimensional packet control policies, and are inefficient due to sequential multiple lookups, failing to meet the real-time requirements of high-performance network devices.
A multi-key parallel lookup mechanism is adopted. The corresponding ACL group is generated according to the packet type, and the ACL entries corresponding to each key are searched in parallel to avoid invalid calculations. Rule conflicts are handled by priority to improve lookup efficiency.
It achieves line-speed processing capabilities, reduces ACL lookup latency, improves resource utilization, and meets the needs of complex business scenarios.
Smart Images

Figure CN120935284A_ABST
Abstract
Description
Technical Field
[0001] This application relates to a data communication-related technical field, and in particular to a method and apparatus for processing messages. Background Technology
[0002] To meet the ever-increasing demands of network traffic, network devices need to possess efficient data processing capabilities. Access Control Lists (ACLs) are a packet matching technology. An ACL entry consists of a series of matching rules, which can be the destination MAC address, source IP address, Layer 4 port number, etc., and each entry corresponds to a set of actions. Currently, ACL technology is commonly used in network devices such as switches and routers to implement network security, QoS, and other services.
[0003] Currently, the commonly used ACL lookup methods in network devices mainly include single lookup and sequential multi-lookup. However, as network services become more complex, existing methods often struggle to meet the demands of complex scenarios, exhibiting the following drawbacks:
[0004] On the one hand, existing single-ACL lookup methods perform rule matching only once per packet, failing to support multi-dimensional composite policies. For example, some scenarios require both forwarding and redirection of packets with specific destination MAC addresses and rate limiting based on TCP port numbers. If the destination MAC address and TCP port number are not in the same ACL rule, a single ACL lookup is insufficient to meet complex requirements. This prevents network devices from implementing fine-grained packet control policies, limiting the flexibility and scalability of network services.
[0005] On the other hand, existing sequential multiple ACL lookup methods have low lookup efficiency due to their serial processing. The latency of sequential lookup is a multiple of that of a single lookup, making it difficult to achieve line-speed packet processing. This fails to meet the real-time requirements of high-performance network devices and affects the overall performance of network devices.
[0006] On the other hand, using the sequential multiple ACL lookup method still requires checking IP-related fields for non-IP packets (such as ARP), resulting in invalid calculations.
[0007] Therefore, in this context, how to provide a method for processing packets, enabling multiple ACL lookups on packets, applying appropriate lookup rules to different packet types, reducing computational resource waste, improving ACL lookup efficiency, and meeting the needs of complex business scenarios are technical problems that need to be solved. Summary of the Invention
[0008] In view of the above-mentioned problems of the prior art, this application provides a method and apparatus for processing messages, which can provide a method for processing messages, realize multiple ACL lookups on messages, adopt corresponding lookup rules for different message types, reduce the waste of computing resources, improve ACL lookup efficiency, and meet the needs of complex business scenarios.
[0009] To achieve the above objectives, the first aspect of this application provides a method for processing messages, comprising the following steps:
[0010] Obtain the message and parse the message to determine the message type;
[0011] Generate a set of keys supported by the message type based on the message type. Each key in the set of keys corresponds to an Access Control List (ACL) group. The key determines the hit entry by matching whether the field matches the rules in the ACL.
[0012] In parallel, each key is used to look up the corresponding ACL group to obtain the hit ACL entries and determine the action corresponding to the hit ACL entries;
[0013] The message is processed according to the action described.
[0014] As described above, by employing a parallel lookup mechanism using multiple keys, the matching process for different types of ACL rules can be executed synchronously in their respective independent groups. This eliminates the sequential waiting latency inherent in traditional serial lookup methods, reducing the processing latency of the ACL lookup process to the level of a single lookup, achieving line-rate processing capabilities matching the physical interface speed. Key selection based on packet type avoids invalid matching of irrelevant fields, improving resource utilization. Multiple ACL lookups for a single packet can be combined with strategies of different dimensions to meet the needs of various business scenarios.
[0015] As one possible implementation of the first aspect, when multiple ACL entries are hit within an ACL group, the hit result of the ACL entries within that ACL group is determined according to the priority of the ACL entries.
[0016] As shown above, by setting the rule priority, rule conflicts caused by multiple keys having duplicate matching fields are avoided.
[0017] As one possible implementation of the first aspect, the ACL entries within an ACL group are arranged sequentially according to their priority order;
[0018] When multiple ACL entries are hit within an ACL group, the hit result of the ACL entries within that ACL group is determined according to the order in which the ACL entries are listed.
[0019] By placing higher-priority rules at higher address locations, the priority rules do not require complex logical judgments or additional configuration work, thus reducing the complexity of system design.
[0020] As one possible implementation of the first aspect, it also includes:
[0021] When searching multiple ACL groups to obtain multiple matched ACL entries and determining the multiple actions corresponding to these ACL entries...
[0022] If there is a conflict among the multiple actions, the action that takes effect will be selected according to the priority configured for each action in advance.
[0023] As described above, by setting action priorities, we can ensure that the actions of each rule are executed according to business importance in the event of a conflict, thus avoiding policy confusion.
[0024] As one possible implementation of the first aspect, the message type and the set of keys it supports include:
[0025] The IPv4 type supports a set of keys including at least the following eight keys: SMAC, SIP4, MAC, SMAC_SIP4, DMAC_DIP4, IP4, CUSTOM, and IP4_MAC.
[0026] The IPv6 type supports a set of keys including at least the following eight keys: SMAC, SIP6, MAC, SMAC_SIP6, DMAC_DIP6, CUSTOM, IP6, and IP6_MAC.
[0027] The ARP type supports a set of keys that include at least the following four keys: SMAC, MAC, ARP, CUSTOM; or / and
[0028] Other types support a set of keys including at least the following three keys: SMAC, MAC, and CUSTOM.
[0029] As described above, by classifying common messages and using multiple keys to perform parallel searches for the same type, the efficiency of searching for preprocessed messages is improved.
[0030] As one possible implementation of the first aspect, the key includes the following combinations of fields: consisting solely of the address information field, or consisting of one or more combinations of the address information field and network identification information, protocol information, and message payload information.
[0031] The address information includes source MAC address, destination MAC address, source IP address, and destination IP address; the network identification information includes Ethernet type and virtual LAN identifier; the protocol information includes source port number, destination port number, protocol type, fragmentation flag, message operation type, and service type; and the message payload information includes payload.
[0032] As described above, by limiting the combination of fields in the key content, the flexibility and adaptability of ACL rule matching are further improved.
[0033] A second aspect of this application provides an apparatus for processing messages, comprising:
[0034] The message parsing module is used to acquire messages and parse the messages to determine the message type;
[0035] The group key module is used to generate a group of keys supported by the packet type according to the packet type, and each key in the group of keys corresponds to an ACL group;
[0036] The lookup control module is used to search for the ACL group corresponding to each key in parallel to obtain the matched ACL entries and determine the action corresponding to the matched ACL entries.
[0037] An action processing module is used to process the message according to the action.
[0038] A third aspect of this application provides a computing device, including: a processor and a memory storing program instructions thereon, the program instructions, when executed by the processor, causing the processor to perform the message processing method according to any one of the first aspects.
[0039] A fourth aspect of this application provides a computer-readable storage medium having program instructions stored thereon, which, when executed by a computer, cause the computer to perform the message processing method described in any of the first aspects.
[0040] The fifth aspect of this application provides a computer program product including program instructions that, when executed by a computer, cause the computer to perform the message processing method described in any of the first aspects. Attached Figure Description
[0041] Figure 1 This is a flowchart of the message processing method provided in the first embodiment of this application;
[0042] Figure 2a This is a flowchart of the message processing method provided in the second embodiment of this application;
[0043] Figure 2bThis is a schematic diagram illustrating the principle of message processing provided in the second embodiment of this application;
[0044] Figure 2c This is a flowchart illustrating the message processing implementation provided in the second embodiment of this application;
[0045] Figure 3 This is a schematic diagram of the message processing apparatus provided in the third embodiment of this application;
[0046] Figure 4 This is a schematic structural diagram of a computing device provided in an embodiment of this application.
[0047] It should be understood that the dimensions and shapes of the blocks in the above structural diagrams are for reference only and should not constitute an exclusive interpretation of the embodiments of the present invention. The relative positions and inclusion relationships between the blocks presented in the structural diagrams are only schematic representations of the structural relationships between the blocks, and are not intended to limit the physical connection methods of the embodiments of the present invention. Detailed Implementation
[0048] The technical solutions provided in this application will be further described below with reference to the accompanying drawings and embodiments. It should be understood that the system architecture and business scenarios provided in the embodiments of this application are mainly for illustrating possible implementations of the technical solutions of this application and should not be construed as the sole limitation on the technical solutions of this application. Those skilled in the art will recognize that the technical solutions provided in this application are equally applicable to similar technical problems as system architectures evolve and new business scenarios emerge.
[0049] It should be understood that the message processing solutions provided in the embodiments of this application include message processing methods, apparatus, computing devices, computer-readable storage media, and computer program products. Since these technical solutions solve problems based on the same or similar principles, some repetitive details may not be repeated in the following descriptions of specific embodiments. However, it should be considered that these specific embodiments have mutual references and can be combined with each other.
[0050] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. In case of any inconsistency, the meaning set forth in this specification or derived from the content described herein shall prevail. Furthermore, the terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application. To accurately describe the technical content of this application and to accurately understand the invention, the following explanations or definitions of the terms used in this specification are provided before describing specific embodiments:
[0051] 1) Ternary Content-Addressable Memory (TCAM): This is a special storage device that can simultaneously compare input data with all stored content and return a matching address. TCAM supports three states: "0, 1, and X (independent state)," making it suitable for high-speed parallel lookup scenarios. It is commonly used for ACL rule matching and routing table lookup in network devices.
[0052] 2) Static Random-Access Memory (SRAM): This is a type of volatile memory that stores data through flip-flops and retains information without needing to be refreshed. SRAM features high-speed read / write and low latency, and is typically used for caching or storing critical data that requires fast access, such as ACL action tables and other scenarios with high real-time requirements.
[0053] 3) ACL tables, ACL entries, and ACL entry groups:
[0054] An ACL table, or access control list, is a broad concept in this application that contains individual ACL rules.
[0055] An ACL entry, in this application, refers to each item in an ACL table, with one ACL entry corresponding to one ACL rule.
[0056] In this application, ACL entry groups are formed by classifying ACL rules according to different key types. Each ACL entry group contains multiple ACL entries for a specific key type.
[0057] The message processing scheme provided in this application involves acquiring a message, parsing the message to determine the message type, generating a set of keys supported by the message type, where each key corresponds to an ACL group, using each key in parallel to search the corresponding ACL group to obtain the matched ACL entries, and determining the action corresponding to the matched ACL entries; and processing the message according to the action. This method provides a way to process messages, enabling multiple ACL searches on the message, applying appropriate search rules to different message types, reducing computational resource waste, and improving ACL search efficiency. The embodiments of this invention can be applied to scenarios requiring access control in the fields of data communication and network security, including but not limited to network traffic filtering, Quality of Service (QoS) policy enforcement, and security threat protection. The embodiments of this application are described in detail below with reference to the accompanying drawings.
[0058] The first embodiment of this application provides a method for processing messages, which will be described below in conjunction with... Figure 1The implementation of each step of the method is described in detail, including steps S10-S40.
[0059] S10: Obtain the message and parse the message to determine the message type.
[0060] In some embodiments, the method of obtaining packets includes receiving packets from a network interface, obtaining packets from a mirror port, injecting packets into the CPU, or obtaining packet information from forwarded packets. The parsing includes extracting the header fields and payload fields of each layer of the packet (such as the data link layer, network layer, and transport layer) to obtain the packet content. The parsing can be performed by a network processor, a switching chip, or a dedicated parsing engine.
[0061] In some embodiments, the message types include IPv4, IPv6, ARP, and others, wherein the other types include message types that are not IPv4, IPv6, or ARP; for example, custom protocol messages, non-IP messages, control messages, etc. The message type classification is determined based on the message's Ethernet type field, IP protocol version field, ARP opcode field, or other protocol identification fields.
[0062] In some embodiments, the step of classifying the message into a preset type based on the message content includes: First, extracting the Ethernet type field (EtherType) from the data link layer header fields of the message. The Ethernet type field is located in the data link layer header of the message and is used to identify the upper-layer protocol type. Then, based on the value of the Ethernet type field, a preliminary determination of the message type is made: if the value of the Ethernet type field is 0x0800, the message is preliminarily determined to be an IPv4 type message; if the value of the Ethernet type field is 0x86DD, the message is preliminarily determined to be an IPv6 type message; if the value of the Ethernet type field is 0x0806, the message is preliminarily determined to be an ARP type message; if the value of the Ethernet type field is other values, the message is preliminarily determined to be another type of message.
[0063] In some embodiments, the IPv4 and IPv6 type packets can be further divided into TCP / UDP type, non-TCP / UDP type, etc., and the other types of packets can be further divided into SAP type, SNAP type, PTP type, etc.
[0064] S20: Generate a set of keys supported by the message type according to the message type. Each key in the set of keys corresponds to an Access Control List (ACL) group. The key determines the hit entry by matching whether the field matches the rules in the ACL.
[0065] In some embodiments, the independent group in the ACL rule base corresponding to each key stores only the rules associated with that key.
[0066] In some embodiments, the key content includes a matching field, packet forwarding information, packet content, and key type. The packet forwarding information includes: MAC address table lookup results and routing table lookup results.
[0067] In some embodiments, the matching field of the key is formed by extracting and combining fields from the message content. These fields include: network identification information, address information, protocol information, and message payload information. The network identification information includes Ethernet type (EtherType) and Virtual LAN identifier (VLAN_ID). The address information includes source MAC address (SMAC), destination MAC address (DMAC), source IP address (SIP), and destination IP address (DIP). The protocol information includes source port number, destination port number, protocol type, fragmentation flag, and Type of Service (TOS). The message payload information includes the payload. For SAP type messages, the protocol information also includes Destination Service Access Point (DSAP), Source Service Access Point (SSAP), and Control Field (CTRL). For SNAP type messages, the protocol information also includes Organization Unique Identifier (OUI). For PTP type messages, the protocol information also includes Exact Time Protocol (DomainNumber) and Subdomain Identifier (SdoID). For ARP type messages, the protocol information also includes Message Operation Type (OP_Code) and the source MAC address of the ARP message sender (Sender_MAC). All fields are derived from the header and payload fields of each layer. The source IP address, destination IP address, source port number, destination port number, and protocol type constitute the IP 5-tuple.
[0068] In some embodiments, the message type and the set of keys it supports include: IPv4 type, which supports a set of keys including at least the following eight keys: SMAC, SIP4, MAC, SMAC_SIP4, DMAC_DIP4, IP4, CUSTOM, IP4_MAC; IPv6 type, which supports a set of keys including at least the following eight keys: SMAC, SIP6, MAC, SMAC_SIP6, DMAC_DIP6, CUSTOM, IP6, IP6_MAC; ARP type, which supports a set of keys including at least the following four keys: SMAC, MAC, ARP, CUSTOM; or / and other types, which support a set of keys including at least the following three keys: SMAC, MAC, CUSTOM.
[0069] In some embodiments, the matching field of the key includes the following combination methods: the key is composed solely of the address information field, or the key is composed of one or more combinations of the address information field and network identification information, protocol information, and message payload information.
[0070] In some embodiments, a user can specify the offset and length of a field in the message content to combine to obtain the matching field of the key.
[0071] In some embodiments, the key selection strategy is dynamically adjusted based on information such as the distribution of message types and the frequency of use of ACL rules to optimize key selection.
[0072] S30: Simultaneously using all selected keys, initiate searches in the corresponding independent groups to check if a matching rule exists.
[0073] In some embodiments, it is supported to perform ACL lookups using multiple keys simultaneously. Each key is used only in its own group for lookup, and multiple groups can be processed in parallel.
[0074] In some embodiments, when multiple ACL entries are hit within an ACL group, the hit result of the ACL entries within that ACL group is determined based on the priority of the ACL entries. The priority can be encoded using address encoding; for example, a higher address is encoded as a higher priority. By placing higher-priority rules at higher address positions, the priority is determined without complex logical judgments or additional configuration work, reducing the complexity of the system design.
[0075] In some embodiments, the ACL entries within an ACL group are arranged sequentially according to their priority order; when multiple ACL entries are hit within an ACL group, the ACL entry hit result within the ACL group is determined according to the order in which the ACL entries are arranged.
[0076] In some embodiments, the key to be searched is divided into multiple stages, and a portion of the key is searched in parallel in each stage. Based on the results, it is determined whether to search the remaining key in parallel in the next stage.
[0077] S40: Process the message content according to the action corresponding to the matched rule.
[0078] In some embodiments, the actions are stored in an action table, which includes packet drop flags, forwarding methods, redirection information, priority flags, traffic rate limiting information, etc.
[0079] In some embodiments, the ACL rule base is implemented using a tri-state content-addressable memory (TCAM), and the actions corresponding to the ACL rules are stored in an action table, which is implemented using static random access memory (SRAM). The TCAM is used to store ACL rules and supports parallel lookup and fuzzy matching; the SRAM is used to store action information and supports fast read and write operations.
[0080] In some embodiments, when searching multiple ACL groups to obtain multiple matched ACL entries and determining the multiple actions corresponding to these ACL entries, if there are action conflicts among the multiple actions, the action that takes effect is selected according to the priority pre-configured for each action. For example, the action priority is determined by the priority field in the action table; the larger the value of the priority field, the higher the priority of the action. The action conflict handling process includes comparing the priorities of multiple actions and selecting the action with the highest priority as the final effective action to be executed.
[0081] In some embodiments, the packet processing results are statistically analyzed to optimize ACL rule configuration and key selection. The statistical analysis process includes recording information such as packet matching, action execution, and processing latency to provide a basis for network management and optimization.
[0082] The second embodiment of this application provides a method for processing messages. The following will refer to... Figure 2a The flowchart shown illustrates that the method provided in this second embodiment includes the following steps S200-S230.
[0083] S200: Acquire and parse messages, and classify them by type.
[0084] like Figure 2b As shown in the embodiment of this application, taking a switching chip as an example, after the network switching device receives a message and message forwarding information, it extracts the field information of the message through a message parsing module to obtain the message content.
[0085] The extracted field information may include: network identification information, address information, protocol information, and packet payload information. Specifically, the network identification information includes Ethernet type (EtherType) and Virtual LAN identifier (VLAN_ID); the address information includes source MAC address, destination MAC address, source IP address, and destination IP address; the protocol information includes source port number, destination port number, protocol type, fragmentation flag, and Type of Service (TOS); and the packet payload information includes the payload. For SAP type packets, the protocol information also includes Destination Service Access Point (DSAP), Source Service Access Point (SSAP), and Control Field (CTRL); for SNAP type packets, the protocol information also includes Organization Unique Identifier (OUI); and for PTP type packets, the protocol information also includes Exact Time Protocol (DomainNumber) and Subdomain Identifier (SdoID). The source IP address, destination IP address, source port number, destination port number, and protocol type constitute an IP 5-tuple.
[0086] The packets are categorized based on the extracted Ethernet type field. For example, if the Ethernet type field value is 0x0800, the packet is initially identified as an IPv4 packet; if the value is 0x86DD, the packet is initially identified as an IPv6 packet; if the value is 0x0806, the packet is initially identified as an ARP packet; and if the value is any other, the packet is initially identified as another type of packet.
[0087] After initial assessment, further analysis is performed using the IP protocol number, LLC header field, etc., to categorize IPv4 and IPv6 packets as TCP / UDP or non-TCP / UDP types; other types of packets are categorized as SAP, SNAP, or PTP types. For example, if the Ethernet type field value is 0x0806, it is identified as an IPv4 packet. The IP protocol number field value is then read; if it is 6 or 17, it is a TCP / UDP type. This step can also be performed after selecting the key.
[0088] S210: Select at least one preset key according to the type of the message.
[0089] Select the corresponding key based on the message type (i.e.) Figure 2c The group keys in the ACL rule base are as shown in Table 1. For example, IPv4 packets cannot use the key type corresponding to the IPv6 packet type; non-IP type packets cannot use the key type corresponding to the IP type. Each key corresponds to an independent (table entry) group in the ACL rule base.
[0090] As shown in Table 1, in this embodiment of the application, a message can have up to 8 key types (groups of 8 keys) and can be searched 8 times.
[0091] Table 1 shows the key types supported by the message type.
[0092]
[0093]
[0094] The descriptions of each key type in Table 1 are shown in Table 2. This application embodiment provides 16 key types, corresponding to 16 independent (table entry) ACL groups. In addition to the matching fields in the table, the key content also includes packet forwarding information, packet content, and the key type value.
[0095] Table 2 Key Types and Matching Fields
[0096]
[0097] S220: Initiate an ACL lookup using the key and determine the rules.
[0098] After completing the key matching field combination, the key is sent to the lookup control module. The lookup module includes ACL entries and an action table. The ACL entries are implemented using TCAM, and the action table is stored in SRAM. They can be associated with each other through addresses. For example, an ACL entry may record two SRAM addresses, corresponding to two actions in the action table.
[0099] like Figure 2c As shown, after receiving multiple keys, the lookup control module first verifies the validity of the ACL lookup request, and then initiates multiple ACL lookups simultaneously, searching for the corresponding ACL entry groups (i.e., ...) for different key types. Figure 2c (Group in the text).
[0100] If multiple ACL entries are hit within each group, the ACL entry corresponding to the highest address is selected as the hit address for this search, and the corresponding action is read from the action table based on the hit address.
[0101] S230: Determine the effective action and process the message content.
[0102] After a lookup of each key type is successful, the corresponding action for the matched table entry will be retrieved. The actions supported by this application's embodiments are described in Table 3.
[0103] When multiple actions contain the same action, there may be conflicts. For example, after the search is completed, action0 and action7 are obtained, both of which are configured with REDIR_CMD. In this case, the action with the largest value of ACT_PRIO should be selected as the effective action and executed.
[0104] Table 3 ACL Action Descriptions
[0105]
[0106] Finally, the action processing module performs corresponding processing based on the final action obtained. For example, if the CPU_COPY_ENA action is required, the packet needs to be copied to the CPU; if the POLICE_ENA action is required, the traffic needs to be rate-limited.
[0107] The third embodiment of this application provides an apparatus for processing messages. This apparatus can be used to implement the message processing method in the above embodiments, such as... Figure 2b and 3 As shown, the device for processing messages includes:
[0108] The message parsing module is used to acquire messages and parse the messages to determine the message type; specifically, the message parsing module can be used to implement step S10 in the first embodiment and its optional embodiments.
[0109] The group key module is used to generate a group of keys supported by the packet type according to the packet type, and each key in the group of keys corresponds to an ACL group; specifically, the group key module can be used to implement step S20 in the first embodiment and its optional embodiments.
[0110] The lookup control module is used to search for the ACL group corresponding to each key in parallel to obtain the matched ACL entries and determine the action corresponding to the matched ACL entries; specifically, the lookup control module can be used to implement step S30 in the first embodiment and its optional embodiments.
[0111] An action processing module is used to process the message according to the action. Specifically, the action processing module can be used to implement step S40 in the first embodiment and its optional embodiments.
[0112] Figure 4 This is a schematic structural diagram of a computing device 900 provided in an embodiment of this application. This computing device can execute various optional embodiments of the methods described above. The computing device can be a terminal, or a chip or chip system within the terminal. Figure 4 As shown, the computing device 900 includes: a processor 910, a memory 920, and a communication interface 930.
[0113] It should be understood that Figure 4 The communication interface 930 in the computing device 900 shown can be used to communicate with other devices, and may specifically include one or more transceiver circuits or interface circuits.
[0114] The processor 910 can be connected to the memory 920. The memory 920 can be used to store the program code and data. Therefore, the memory 920 can be a storage unit inside the processor 910, an external storage unit independent of the processor 910, or a component that includes both the storage unit inside the processor 910 and the external storage unit independent of the processor 910.
[0115] Optionally, the computing device 900 may also include a bus. The memory 920 and communication interface 930 can be connected to the processor 910 via the bus. The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 The symbol is represented by a line without an arrow, but this does not mean that there is only one bus or one type of bus.
[0116] It should be understood that in the embodiments of this application, the processor 910 may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor. Alternatively, the processor 910 may employ one or more integrated circuits to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0117] The memory 920 may include read-only memory and random access memory, and provides instructions and data to the processor 910. A portion of the processor 910 may also include non-volatile random access memory. For example, the processor 910 may also store device type information.
[0118] When the computing device 900 is running, the processor 910 executes computer execution instructions stored in the memory 920 to perform any of the operational steps of the above method and any of the optional embodiments thereof.
[0119] It should be understood that the computing device 900 according to the embodiments of this application can correspond to the corresponding subject in executing the methods according to the various embodiments of this application, and the above and other operations and / or functions of each module in the computing device 900 are respectively for implementing the corresponding processes of the methods of this embodiment. For the sake of brevity, they will not be described in detail here.
[0120] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0121] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0122] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0123] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0124] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0125] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0126] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is used to perform the above-described method, which includes at least one of the schemes described in the above embodiments.
[0127] The computer storage medium in this application embodiment can be any combination of one or more computer-readable media. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0128] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.
[0129] The program code contained on a computer-readable medium may be transmitted using any suitable medium, including, but not limited to, wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0130] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0131] Furthermore, the terms "first, second, third, etc." or similar terms such as module A, module B, and module C used in the specification and claims are only used to distinguish similar objects and do not represent a specific ordering of objects. It is understood that, where permissible, a specific order or sequence may be interchanged so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0132] In the above description, the labels of the steps involved, such as S110, S120, etc., do not mean that the steps will necessarily be executed. The order of the steps can be interchanged or executed simultaneously if permitted.
[0133] The term "comprising" as used in the specification and claims should not be construed as limiting itself to what follows; it does not exclude other elements or steps. Therefore, it should be interpreted as specifying the presence of the mentioned feature, integral, step, or component, but does not exclude the presence or addition of one or more other features, integrals, steps, or components, or groups thereof. Thus, the statement "device comprising means A and B" should not be limited to a device consisting solely of components A and B.
[0134] The terms "an embodiment" or "an embodiment" as used in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in at least one embodiment of this application. Therefore, the terms "in one embodiment" or "in an embodiment" appearing throughout this specification do not necessarily refer to the same embodiment, but may refer to the same embodiment. Furthermore, in one or more embodiments, the particular features, structures, or characteristics can be combined in any suitable manner, as will be apparent to those skilled in the art from this disclosure.
[0135] Note that the above are merely preferred embodiments and the technical principles employed in this application. Those skilled in the art will understand that this application is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of this application. Therefore, although this application has been described in detail through the above embodiments, this application is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of this application, all of which fall within the scope of protection of this application.
Claims
1. A method for processing messages, characterized in that, include: Obtain the message and parse the message to determine the message type; Generate a set of keys supported by the message type based on the message type. Each key in the set of keys corresponds to an Access Control List (ACL) group. The key determines the hit entry by matching whether the field matches the rules in the ACL. In parallel, each key is used to look up the corresponding ACL group to obtain the hit ACL entries and determine the action corresponding to the hit ACL entries; The message is processed according to the action described.
2. The method according to claim 1, characterized in that, Also includes: When multiple ACL entries are hit within an ACL group, the hit result for the ACL entries within that ACL group is determined based on the priority of the ACL entries.
3. The method according to claim 2, characterized in that, The ACL entries within an ACL group are arranged sequentially according to their priority. When multiple ACL entries are hit within an ACL group, the hit result of the ACL entries within that ACL group is determined according to the order in which the ACL entries are listed.
4. The method according to claim 2 or 3, characterized in that, Also includes: When searching multiple ACL groups to obtain multiple matched ACL entries and determining the multiple actions corresponding to these ACL entries... If there is a conflict among the multiple actions, the action that takes effect will be selected according to the priority configured for each action in advance.
5. The method according to claim 1, characterized in that, The message types and the set of keys they support include: The IPv4 type supports a set of keys including at least the following eight keys: SMAC, SIP4, MAC, SMAC_SIP4, DMAC_DIP4, IP4, CUSTOM, and IP4_MAC. The IPv6 type supports a set of keys including at least the following eight keys: SMAC, SIP6, MAC, SMAC_SIP6, DMAC_DIP6, CUSTOM, IP6, and IP6_MAC. The ARP type supports a set of keys that include at least the following four keys: SMAC, MAC, ARP, CUSTOM; or / and Other types support a set of keys including at least the following three keys: SMAC, MAC, and CUSTOM.
6. The method according to claim 1, characterized in that, The key includes fields that can be combined in the following ways: consisting solely of the address information field, or consisting of one or more combinations of the address information field and network identification information, protocol information, and message payload information. The address information includes source MAC address, destination MAC address, source IP address, and destination IP address; the network identification information includes Ethernet type and virtual LAN identifier; the protocol information includes source port number, destination port number, protocol type, fragmentation flag, message operation type, and service type; and the message payload information includes payload.
7. An apparatus for processing messages, characterized in that, include: The message parsing module is used to acquire messages and parse the messages to determine the message type; The group key module is used to generate a group of keys supported by the packet type according to the packet type, and each key in the group of keys corresponds to an ACL group; The lookup control module is used to search for the ACL group corresponding to each key in parallel to obtain the matched ACL entries and determine the action corresponding to the matched ACL entries. An action processing module is used to process the message according to the action.
8. A computing device, characterized in that, include: processor, and A memory having stored program instructions thereon, which, when executed by the processor, cause the processor to perform the method for processing messages as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, It stores program instructions that, when executed by a computer, cause the computer to perform the message processing method according to any one of claims 1 to 6.
10. A computer program product, characterized in that, It includes program instructions that, when executed by a computer, cause the computer to perform the message processing method according to any one of claims 1 to 6.