Service traffic replication method, apparatus and system based on switching chip

By using a full-link telemetry mechanism and conflict fingerprinting, combined with access control lists and hash chain deduplication, the high load problem of switch mirroring replication is solved, the stability of the replicated link and adaptive allocation of resources are achieved, and the operation and maintenance efficiency and equipment performance are improved.

CN121037330BActive Publication Date: 2026-03-06INNER MONGOLIA HUARONG POWER TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511361872.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2026-03-06
Estimated Expiration
2045-09-23

AI Technical Summary

Technical Problem

In existing technologies, switch mirroring leads to increased packet loss rate and forwarding latency under high load conditions. It is also complex to configure, wastes resources significantly, and makes it difficult to achieve fine-grained filtering and deduplication, thus increasing the complexity and cost of operation and maintenance.

Method used

By constructing a full-link telemetry mechanism to generate a replication pressure index heatmap, using conflict fingerprints and access control lists for policy partitioning, combining signatures and hash chains to deduplicate redundant traffic, and integrating fault tolerance and control mechanisms, adaptive resource allocation and closed-loop control are achieved.

Benefits of technology

It improves the stability and efficiency of replication, reduces the load on core devices, enables real-time visualization and dynamic control of the replication chain, and has good engineering feasibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037330B_ABST
    Figure CN121037330B_ABST
Patent Text Reader

Abstract

This invention discloses a service traffic replication method, apparatus, and system based on a switching chip, relating to the field of communication technology. The method includes the following steps: S001, by constructing a full-link telemetry mechanism on the backbone data channel, real-time collection of latency fluctuations and packet loss trajectories is achieved, and a replication pressure index heatmap is generated to characterize the resource occupancy range of the mirror session on the forwarding plane; S002, based on the replication pressure index heatmap and combined with real-time port statistics, a conflict fingerprint is generated in the three-state content addressing storage. The conflict fingerprint is used to locate high-frequency replication hotspots, cross-port policy conflicts, and repeated entry paths, providing a reference for policy convergence. This invention perceives resource occupancy through telemetry heatmaps, implements policy partitioning using conflict fingerprints and access control lists, combines signatures and hash chains to deduplicate redundant traffic, integrates fault tolerance and control mechanisms to adaptively allocate resources, constructs a replication closed loop, improves stability and execution efficiency, reduces the load on core equipment, and has engineering feasibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and more specifically to a method, apparatus, and system for copying service traffic based on a switching chip. Background Technology

[0002] As digital transformation deepens and network security systems and operational management levels continue to improve, critical information infrastructure sectors such as finance, telecommunications, and government are placing higher demands on real-time monitoring, in-depth analysis, and security protection of network traffic. To achieve auditing, detection, and performance monitoring of link traffic, the industry commonly employs switch port mirroring (SPAN) technology to replicate and distribute service traffic to intrusion detection systems (IDS), intrusion prevention systems (IPS), deep packet inspection (DPI) systems, and network performance monitoring devices (NPMD). SPAN technology, as a built-in switch function, can meet the access needs of a single monitoring device and has been widely used in scenarios with low-speed links or limited device scale. However, with the expansion of business scale and the increase in the number of monitoring devices deployed, the traditional switch-based mirroring method is gradually showing significant limitations.

[0003] Existing technologies have the following shortcomings: Under current conditions, each new monitoring device added to the core switch requires the creation of a separate mirroring session. When the number of replicated ports exceeds two, the CPU load on the switching chip increases by an average of 35%–40%, which can easily lead to increased packet loss and forwarding latency in high-speed links of 10 Gigabit and above, severely impacting service stability. Furthermore, SPAN policy configuration is complex; each time a device is added or replaced, the switch policy needs to be reconfigured. In heterogeneous environments with multiple devices, incomplete traffic replication and port conflicts often occur, with single debugging sessions taking several hours, significantly increasing operational complexity. In addition, traditional mirroring mechanisms lack fine-grained traffic filtering and deduplication capabilities, resulting in a large amount of invalid or duplicate traffic entering the analysis device, wasting storage and computing resources and increasing users' procurement and maintenance costs.

[0004] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0005] The purpose of this invention is to provide a service traffic replication method, apparatus, and system based on a switching chip. It uses telemetry heatmaps to detect resource occupancy, utilizes conflict fingerprints and access control lists to implement policy partitioning, combines signatures and hash chains to deduplicate redundant traffic, integrates fault tolerance and control mechanisms to adaptively allocate resources, constructs a replication closed loop, improves stability and execution efficiency, reduces the load on core equipment, and has engineering feasibility, thereby solving the problems in the aforementioned background technology.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a service traffic replication method based on a switching chip, comprising the following steps:

[0007] S001, by building a full-link telemetry mechanism in the backbone data channel, real-time collection of latency fluctuations and packet loss trajectories is carried out, and a replication pressure index heat map is generated to characterize the resource occupation range of the mirror session on the forwarding plane.

[0008] S002, based on the replication pressure index heatmap and combined with real-time port statistics, generates conflict fingerprints in the three-state content addressing storage. The conflict fingerprints are used to locate high-frequency replication hotspots, cross-port policy conflicts and repeated entry paths, providing a reference for policy convergence.

[0009] S003, driven by conflict fingerprinting, builds an access control list baseline containing twenty key fields within the policy engine, and performs hierarchical filtering and gating according to the five-tuple, virtual LAN identifier and quality of service identifier, thereby transforming areas with concentrated replication pressure into policy partitions.

[0010] S004, based on the results of hierarchical screening and gating, introduces the bidirectional mutual exclusion signature and time-series hash chain of the deduplication engine to remove loopback packets and duplicate packets from the partitioned replication traffic, and feeds the deduplication results back to the strategy engine to form an iterative comparison, so as to compress the invalid traffic entering the analysis probe.

[0011] S005, based on the deduplication results, deploys hardware-level power failure pass-through protection and mode switching DIP switches on the replication link, and uses deduplication feedback information to perform weight calibration on bypass replication and serial replication, thereby forming a fault-tolerant orchestration, and writes the fault-tolerant status back to the replication pressure index heatmap.

[0012] S006, after the fault-tolerant orchestration is completed, a quantum negative pressure backflow control loop is superimposed on the strategy engine and the deduplication engine. Based on the dynamic calculation results of jitter entropy and congestion entropy, the replication weight and channel time slot are allocated in real time, thereby realizing the reverse pumping and self-balancing adjustment of the overload strategy. The adjusted state is then injected into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic control.

[0013] Preferably, step S001 includes:

[0014] In the backbone link, the inbound and outbound timestamps of each data frame are collected by switching equipment with multi-port high-speed forwarding capabilities and the forwarding delay is calculated. At the same time, the number of bytes occupied by the buffer in the forward buffer and the backward buffer are counted and the number of data frames received and forwarded is compared to confirm whether there is a packet loss event.

[0015] Based on the collected forwarding latency, cache utilization ratio, packet loss quantity and bit error rate, the performance difference of the replication path under the conditions of replication and non-replication is compared, and the pressure level is marked by a percentage index to form a replication path pressure data set.

[0016] Based on the replication path pressure dataset, a two-dimensional heat map is constructed with the replication source port and target port as the horizontal axis and time as the vertical axis. The pressure level is then mapped to a five-level color scale to generate a replication pressure index heat map.

[0017] The replication paths that are at the level of severe congestion and extreme congestion for three consecutive time periods are selected from the replication pressure index heatmap. Combined with the port queue length, the number of dropped frames, and the receiving capability of the target device, these paths are marked as conflict replication paths and warning information is output.

[0018] Preferably, step S002 includes:

[0019] The replication path information at high pressure levels is extracted from the replication pressure index heatmap and combined with real-time statistical data of the switching device ports to form a set of paths to be analyzed.

[0020] Then, for the path to be analyzed, data entries containing seven types of fields are constructed, including the source address, target address, source port number, target port number, protocol type identifier, copy time information, and target device number, and written into the tri-state content addressing storage to form a matching index table;

[0021] The matching logic identifies replication hotspot overlap conflicts, cross-port resource conflicts, and replication path re-entry conflicts, and generates a conflict fingerprint containing a unique identifier, a combination of trigger fields, a hit time, and a conflict type.

[0022] By mapping conflict fingerprints to replication pressure index heatmaps and establishing a conflict fingerprint accumulation table, high-risk replication conflict paths can be identified and inputs can be provided for policy convergence.

[0023] Preferably, step S003 includes:

[0024] Extract source port number, target port number, source Internet Protocol address, target Internet Protocol address, transport layer port number, protocol type value, replication time information and target device port status from high-risk replication paths to form a multi-dimensional data matrix;

[0025] Access control rule entries containing twenty fixed fields are generated based on a multidimensional data matrix and written to a high-speed table entry storage area. Field matching is completed through parallel comparison.

[0026] The business data frames entering the replication process are sequentially filtered in layers. The first layer determines the communication direction based on the five-tuple field. The second layer identifies the priority based on the virtual LAN number and the quality of service label value. The third layer determines whether to classify them into an independent policy domain based on the hit frequency, port bandwidth utilization, cache utilization, and bit error rate.

[0027] The generated policy domain results are written back to the replication pressure index heatmap, and grouping, concurrency control, and dynamic adjustment are performed in the replication schedule according to the policy domain rules.

[0028] Preferably, step S004 includes:

[0029] After completing the layered filtering, the source Internet Protocol address, target Internet Protocol address, transport layer protocol field, source port number, target port number, data frame length, frame sequence number, payload header bytes and timestamp field are extracted from the copied data frames entering the target device, a bidirectional mutual exclusion signature is generated and written to the deduplication cache;

[0030] A time-series hash chain is constructed to store signature values, occurrence times, hit counts, policy domain numbers, and target port numbers, and duplicate frames and loopback packets are determined by comparison.

[0031] For duplicate frames, interrupt copying and forwarding are performed; loopback packets are written to the discard buffer; and the number of packets removed, the removal rate, and the hit field information are counted. The statistical results are then transmitted to the policy field control logic for comparison.

[0032] Establish a feedback structure to create a closed-loop linkage between the removal event indicators and the replication strategy. When the removal rate or loopback rate exceeds the threshold, automatically adjust the field matching rules and port configuration, and synchronize the updated results back to the replication pressure index heatmap to complete dynamic adjustment.

[0033] Preferably, step S005 includes:

[0034] A physical bypass structure is deployed in the main business flow replication link. Under normal conditions, the business flow is replicated and forwarded through the switching chip. When the equipment is powered off, restarted, or fails, the electromagnetic relay switch is closed to achieve direct forwarding to ensure that the main link is not interrupted.

[0035] A three-position DIP switch is set in the replication link control plane. The first position controls the replication mode selection, the second position controls the strategy execution status, and the third position controls the fault recovery. This allows the replication mode to be switched between serial mode and bypass mode, and the original strategy configuration can be maintained when the device is brought back online.

[0036] Based on the deduplication statistics and the replication pressure index heatmap, the effectiveness index of each replication path is calculated, and the replication path weight is adjusted according to the rejection rate and the target device load. When the path pressure is too high, the bypass mode is switched and the scheduling cycle is reduced. When the rejection rate is low and the target device load is sufficient, the serial mode is maintained and the replication priority is appropriately increased.

[0037] The replication mode switching status, weight adjustment status, fault protection records and path effectiveness indicators are written into the replication pressure index heatmap, and the replication mode, priority, fault tolerance protection status and policy adjustment time are marked and displayed in real time in the operation and maintenance platform to realize the visualization and closed-loop control of fault tolerance orchestration.

[0038] Preferably, step S006 includes:

[0039] The arrival interval of data frames is collected and jitter entropy is calculated in the replication path. At the same time, the length of the port buffer queue and the queuing time are collected and congestion entropy is calculated. The two are used as inputs for path operation indicators.

[0040] Based on the changing trends of jitter entropy and congestion entropy, the replication weight and channel time slots are dynamically adjusted. Quantum level control is used to control replication frequency, scheduling interval and bandwidth allocation. When a path is in a congested state, its replication priority is reduced and channel time slots are released. When the path is stable, its replication priority is increased and the scheduling cycle is increased.

[0041] Based on the adjustment operation record path number, weight level, adjustment direction, entropy value change and scheduling parameters, a state transition matrix is ​​established and high fluctuation paths are identified to limit their frequent switching. At the same time, the affected fields and target device addresses are recorded for subsequent convergence.

[0042] The control results are written into the end-to-end telemetry structure, and the data frames are labeled with the replication weight level, path fluctuation level, current control trend and last adjustment time. The data is then output at a fixed period to achieve closed-loop control of the strategy layer, link layer and control layer.

[0043] A service traffic replication system based on a switching chip includes a full-link telemetry module, a collision detection module, a policy partitioning module, a traffic deduplication module, a fault-tolerant orchestration module, and a dynamic control module.

[0044] The end-to-end telemetry module, by constructing an end-to-end telemetry mechanism on the backbone data channel, collects latency fluctuations and packet loss trajectories in real time, and generates a replication pressure index heatmap to characterize the resource consumption range of the mirror session on the forwarding plane.

[0045] The conflict detection module generates conflict fingerprints in the three-state content addressing storage based on the replication pressure index heatmap and combined with real-time port statistics. It uses the conflict fingerprints to locate high-frequency replication hotspots, cross-port policy conflicts, and repeated entry paths, providing a reference for policy convergence.

[0046] The policy partitioning module, driven by conflict fingerprints, builds an access control list baseline containing twenty key fields within the policy engine, and performs hierarchical filtering and gating according to the five-tuple, virtual LAN identifier and quality of service identifier, thereby transforming areas with concentrated replication pressure into policy partitions.

[0047] The traffic deduplication module, based on the results of hierarchical filtering and gating, introduces the bidirectional mutual exclusion signature and time-series hash chain of the deduplication engine to remove loopback packets and duplicate packets from the partitioned replicated traffic, and feeds the deduplication results back to the strategy engine to form an iterative comparison, so as to compress invalid traffic entering the analysis probe.

[0048] The fault-tolerant orchestration module, based on the deduplication results, deploys hardware-level power failure pass-through protection and mode switching DIP switches on the replication link, and uses deduplication feedback information to perform weight calibration on bypass replication and serial replication, thereby forming a fault-tolerant orchestration, and writes the fault-tolerant status back to the replication pressure index heatmap.

[0049] The dynamic control module, after fault-tolerant orchestration is completed, superimposes a quantum negative pressure backflow control loop on the strategy engine and deduplication engine. Based on the dynamic calculation results of jitter entropy and congestion entropy, it allocates replication weight and channel time slots in real time, thereby realizing the reverse extraction and self-balancing adjustment of the overload strategy. The controlled state is then injected into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic control.

[0050] A service traffic replication device based on a switching chip, including the service traffic replication system based on a switching chip as described in claim 8.

[0051] The technical effects and advantages provided by the present invention in the above technical solution are as follows:

[0052] This invention achieves real-time visualization of resource occupancy in the replication link by constructing a full-link telemetry mechanism and a replication pressure index heatmap; it identifies and partitions high-frequency conflict paths using conflict fingerprints and access control list baselines; further, it achieves precise removal of redundant replication traffic by combining bidirectional mutual exclusion signatures and time-series hash chains; and it achieves adaptive balanced allocation of replication policies and link resources while ensuring replication reliability through hardware-level fault-tolerant orchestration mechanisms and quantum control loops. Ultimately, this method constructs a closed-loop process from replication status awareness, conflict identification, policy optimization, traffic deduplication to fault-tolerant control and feedback adjustment, significantly improving the performance stability and policy execution efficiency of replication behavior, reducing dependence on core device computing resources, and demonstrating good engineering feasibility. Attached Figure Description

[0053] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0054] Figure 1 This is a flowchart of the service traffic replication method based on a switching chip according to the present invention.

[0055] Figure 2 This is a schematic diagram of the service traffic replication system based on a switching chip according to the present invention. Detailed Implementation

[0056] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that the description of this disclosure will be more complete and fully convey the concept of the exemplary embodiments to those skilled in the art.

[0057] This invention provides, for example Figure 1 and Figure 2 The service traffic replication method, apparatus, and system based on the switching chip shown include the following steps:

[0058] S001, by building a full-link telemetry mechanism in the backbone data channel, real-time collection of latency fluctuations and packet loss trajectories is carried out, and a replication pressure index heat map is generated to characterize the resource occupation range of the mirror session on the forwarding plane.

[0059] To effectively obtain the dynamic impact of replication operations on backbone performance and provide real-time, quantitative data for subsequent strategy optimization and resource scheduling, a telemetry execution process covering the entire business channel can be constructed to gradually monitor and visualize business replication pressure. This method includes the following steps:

[0060] Switching equipment with multi-port high-speed forwarding capabilities is deployed in the physical transceiver channels of the backbone link. Each data transceiver port of this equipment is connected to an external network physical link, forming a complete service inbound and outbound path. By embedding hardware-level time stamping circuits in each transceiver port, all Ethernet data frames passing through the equipment are appended with timestamp information with a clock synchronization mechanism before entering and leaving the equipment. The timestamp generation is driven by the internal crystal oscillator clock and reference clock of the equipment, ensuring time consistency between different ports. The latency measurement process for each service flow is obtained by calculating the difference between the inbound and outbound timestamps and precisely calibrating it in microseconds. In addition, forward buffers and backward buffers are set up in the data forwarding path. The number of bytes occupied in the buffers within each time period (e.g., 100 milliseconds) is collected in real time by hardware counters to obtain the dynamic changes in the link's temporary storage capacity. To further capture potential packet loss events, a data frame reception and forwarding count relationship is established between all input and output ports involved in the mirroring operation. The total number of incoming and outgoing data packets is compared within a fixed time window, and combined with the error flags of forwarding failures (such as CRC errors and frame format errors), it is confirmed whether any data is dropped during the copying or forwarding process.

[0061] Based on the latency, buffer usage ratio, packet loss count, and transmission error rate collected for each mirror path, a multi-dimensional analysis of the forwarding pressure caused by each mirror replication action is performed. Specifically, for each link channel between the source and target ports, the forwarding latency, packet loss rate, buffer usage, and data frame error rate are recorded under conditions of no replication operation and active replication operation, and a performance change comparison table is established using a matrix approach. In this table, each row represents a replication path, and each column records the percentage increase in forwarding latency, the number of bytes increased in buffer usage, the increase in data frame anomaly count, and the frequency of packet loss events, respectively, and these parameters are uniformly measured as percentage indicators. In the indicator conversion process, mathematical function modeling is not used; instead, a weighted combination of the cumulative values ​​of actual observation results within a unit time window is performed. For example, when the forwarding latency increases by more than 20 microseconds, the buffer usage increases by more than 25%, and the data frame error rate increases by more than 0.2%, the replication behavior of this path is marked as a high-risk path and assigned a corresponding replication pressure score. This ultimately results in a set of stress data organized by replication path, where each element corresponds to the overall resource consumption level of a replication path in the current period.

[0062] To achieve a holistic understanding of the resource consumption status of multiple replication paths, a two-dimensional visual pressure chart is constructed based on the aforementioned replication path pressure data set. In the actual construction process, the source and target port combinations of each replication path are used as the horizontal axis, and the time axis (e.g., sampling once per minute) is used as the vertical axis. The pressure value of each replication path within each time period is mapped to a heatmap color scale. The color scale is set to five levels, corresponding to "normal," "mild congestion," "moderate congestion," "severe congestion," and "extreme congestion," respectively. The corresponding pressure value ranges are determined during the initial device configuration and can be dynamically adjusted according to network status. Each pixel in this chart corresponds to the pressure level of a certain replication path within a specific time period, and the color distribution clearly reflects the trend of the impact of replication behavior on the resources of each path. Compared to existing technologies that only use port utilization or forwarding delay as a single indicator to determine the impact of replication, this method reflects the complex resource pressure caused by replication through a combination of multi-dimensional indicators, possessing higher accuracy and foresight.

[0063] After generating the replication pressure heatmap, to achieve linkage with subsequent resource conflict identification operations, it is necessary to extract critical path regions based on the current pressure distribution results and conduct early warning detection. Specifically, this involves automatically filtering all replication paths that have been at the "severe congestion" or "extreme congestion" level for the past three consecutive time periods from the pressure heatmap, classifying them into a high-pressure path set. For each replication path in this set, its corresponding replication policy parameters are traced back, including source MAC address, destination MAC address, source IP address, destination IP address, ingress port number, egress port number, protocol type identifier, target device access status, and data processing capability level, and then arranged in a structured manner. Based on this, combined with the device's local port status registration information, including port queue length, number of forwarded dropped frames, and current queuing time, it is determined whether there are conflict states such as overlapping policy configurations, overlapping replication paths, or target device bandwidth saturation. If a strategy with the same replication source but overlapping target ports is found, or if the replication target device is saturated with processing capacity in the current cycle (e.g., the data receiving rate has reached more than 95% of the device's maximum capacity), it will be marked as a conflicting replication path, and its stress heatmap change trend will be recorded for reference by the subsequent strategy adjustment module.

[0064] The core function of this step is to establish a quantifiable and visualized dynamic assessment basis for the resource consumption of replication behavior in the backbone data channel, thereby enabling real-time monitoring and trend prediction of network replication pressure. By collecting key performance indicators such as forwarding latency, buffer usage, packet loss ratio, and bit error rate for each data frame in the forwarding path of the switching equipment, and mapping these multi-dimensional data to mirror replication operations, the specific impact of replication behavior on link resources can be effectively identified. Furthermore, by generating a replication pressure index heatmap, the resource usage of the replication path is graphically presented in terms of time series and port pairs, enabling network operators or policy engines to intuitively identify resource bottlenecks, overloaded paths, and potentially risky links. This assessment process not only provides a quantitative basis for subsequent conflict detection, policy selection, traffic deduplication, and fault-tolerant control, but also breaks through the technical bottleneck of the existing "black box" operation mode of SPAN mirroring policy, which cannot perceive the actual link load. It is the fundamental support for realizing intelligent and dynamic control of full-link replication.

[0065] S002, based on the replication pressure index heatmap and combined with real-time port statistics, generates conflict fingerprints in the three-state content addressing storage. The conflict fingerprints are used to locate high-frequency replication hotspots, cross-port policy conflicts and repeated entry paths, providing a reference for policy convergence.

[0066] To further accurately identify performance degradation issues caused by overlapping replication strategies, link resource contention, or replication path re-entry, based on the existing replication pressure index heatmap and combined with real-time statistical information from each data port of the switching equipment, a set of data features with discriminative capabilities is generated through a specific logical process to represent potential conflict behaviors in the current replication structure. This process adopts a conflict fingerprint construction method based on a three-state content-addressable storage architecture, and the specific implementation steps are as follows:

[0067] The replication pressure index heatmap generated in the previous stage is filtered to extract replication path information currently marked as "severe congestion" and "extreme congestion." These paths exhibit a forwarding latency increase greater than 100 microseconds in the previous period, port buffer occupancy exceeding 80%, packet loss increasing for two consecutive periods, and the proportion of error frames exceeding the current port's normal operating threshold. For replication paths meeting these conditions, their starting port number, destination port number, timestamp of the replication action, source address, destination address, protocol identifier, and physical port number of the target receiving device are extracted and used as the current set of paths to be analyzed. Subsequently, the status information of the forwarding chips associated with these ports is accessed to read the average inbound flow rate, outbound flow rate, average queue waiting length, error frame count, bit error rate, actual total packet loss, and queue overflow warning flag for each port during the specified time period, forming a set of port operating statuses fully bound to the path. This information is obtained by setting multiple dedicated hardware counters in the switching chip, refreshed every 100 milliseconds to ensure time consistency and real-time processing of the collected data.

[0068] For each path to be analyzed, a set of fields for matching is constructed. This set of fields includes the source address, destination address, source port number, destination port number, protocol type identifier, replication start time, replication end time, destination device number, current replication bandwidth value, real-time buffer utilization of the destination port, error frame growth rate, and last replication hit identifier. All fields are numbered and uniformly encoded according to a pre-defined structural order, combined into fixed-length data entries in 16-bit or 32-bit binary field format. These entries are sequentially written into a tri-state content-addressable storage structure within the switching chip, completing the construction of a field-level matching index table. This storage structure allows searching for specific field combinations using both exact match and prefix match methods. When a new replication request is received, it can quickly retrieve whether there are overlapping or conflicting entries in the existing path fields. Compared with the traditional static configuration judgment method, this storage method accelerates the path through hardware, ensuring that the comparison time for a single path does not exceed 50 nanoseconds, and has real-time conflict judgment capability.

[0069] The data entries in the three-state content addressing storage are cross-analyzed using matching logic to identify conflict behaviors within the current period. Conflict behaviors are categorized into three types. The first type is overlapping replication hotspot conflicts, where two or more replication paths share the same source and destination addresses, protocol identifiers, and target devices, with any overlap in their replication time windows. Simultaneously, the average output rate of the target port exceeds 85% of the current device port's maximum capacity. In this case, these path combinations are classified as overlapping replication hotspots, and a conflict fingerprint record numbered "C1" is generated. The second type is cross-port resource conflicts, determined when multiple replication paths originate from different ingress ports but replicate to the same target port, and the queue length of that target port consistently exceeds 60% of the port's defined queue capacity. At least one forwarding failure flag appears within the two periods prior to the hardware buffer overflow. In this case, a conflict fingerprint numbered "C2" is constructed, recording the path combination, timestamp, number of forwarding failures, and target port cache status. The third type is reentrancy conflict, which refers to a replication strategy repeatedly replicating the same business flow through different rule paths. This means that business data frames are repeatedly hit with replication conditions within a short period and distributed to multiple identical or different target devices, even though there is a merging relationship between the collection results of these target devices. If, after structural matching, the five-tuples are found to be completely identical, and the replication target devices are marked as belonging to the same data cluster or load balancing group in the configuration, then the replication behavior is considered to have a reentrancy conflict, generating a conflict fingerprint with the number "C3". All three types of conflict fingerprints include a unique identifier, a combination of triggering fields, a hit time, a conflict type identifier, the number of affected paths, and the current impact level.

[0070] All generated conflict fingerprints are structurally correlated with the aforementioned replication pressure index heatmap. Specifically, the replication path combinations within each conflict fingerprint are marked back to their corresponding positions on the heatmap, and these positions are visually highlighted, for example, using red to indicate "hotspot conflict," orange to indicate "port resource conflict," and yellow to indicate "path reentrancy conflict." This allows strategy analysts or subsequent automatic pruning logic to quickly identify weak points in the current replication structure. Simultaneously, a conflict fingerprint accumulation table is constructed, statistically analyzing the generation frequency of conflict fingerprints for each port and target device over several past periods. This frequency, along with port cache status, replication policy quantity, and data frame drop rate, forms a conflict trend assessment index. When a port accumulates more than three conflict fingerprints within three consecutive periods, and at least one of them contains a "C1" type fingerprint, it is marked as a "high-risk replication conflict path" and transferred to subsequent strategy adjustment logic for processing. This approach not only enables accurate identification and location of resource interference behaviors between strategies in complex replication environments, but also provides early warning of high-risk path evolution trends, supports targeted simplification and differentiation during strategy convergence, and significantly improves the stability, controllability, and operational efficiency of the overall replication chain.

[0071] This step, building upon existing replication pressure heatmaps and conflict fingerprinting, further enhances the precision of replication traffic filtering and path partitioning by constructing a basic rule set for access control lists. This provides an executable strategy framework for subsequent traffic deduplication and replication optimization. By extracting key characteristic fields from the replication traffic, such as source address, destination address, source port, destination port, protocol type, VLAN identifier, and QoS identifier, complex replication policies are configured in a structured and hierarchical manner. This allows replication flows with similar replication characteristics but located in high-pressure conflict areas to be categorized into relatively independent control domains. This process not only effectively avoids resource competition and cross-contamination between different policies but also enables the rational allocation of replication behavior between physical links and target devices. Compared to existing methods relying on static port mirroring configurations, this strategy partitioning method offers greater flexibility and dynamic adjustment capabilities, ensuring the accuracy, controllability, and adjustability of replication behavior. It is a crucial foundation for achieving fine-grained control of subsequent replication flows and efficient utilization of link resources.

[0072] S003, driven by conflict fingerprinting, builds an access control list baseline containing twenty key fields within the policy engine, and performs hierarchical filtering and gating according to the five-tuple, virtual LAN identifier and quality of service identifier, thereby transforming areas with concentrated replication pressure into policy partitions.

[0073] To effectively resolve link load concentration and replication flow conflicts caused by resource contention, configuration overlap, and limited target device capabilities between replication paths, it is necessary to construct an access control baseline rule set with complete field expression capabilities after identifying conflict fingerprints. Furthermore, multi-level filtering logic should be used to precisely partition replication traffic, thereby achieving spatial separation and balanced resource allocation of the replication strategy. This process can be divided into the following steps:

[0074] The replication traffic identified as high-risk paths in the aforementioned conflict fingerprint set is structurally extracted to obtain the fields involved in each conflict path. These fields include: source port number, destination port number, source Internet Protocol address of the replication traffic, destination Internet Protocol address, transport layer source port number, transport layer destination port number, transport protocol type value used by the replication flow, start timestamp of the replication action, end timestamp of the replication action, average length of the replication packets, physical address identifier of the target device associated with the replication path, current receive rate of the target device port, real-time occupancy percentage of the device port buffer, packet error rate, replication flow transmission direction, trigger frequency of the replication action in the previous period, and effective processing capacity level of the target device in the current period. The collection of these fields is performed by a statistical register unit dedicated to state mirroring in the hardware switching chip, with a collection period of 100 milliseconds, and is executed synchronously with the replication pressure index heatmap to ensure the temporal consistency of the field information. All collected fields will be structured into a multi-dimensional data matrix, serving as the basic building blocks for subsequent access control rule entries.

[0075] Based on the aforementioned multi-dimensional field matrix, access control rule entries are generated. Each entry contains a fixed set of twenty fields: source Internet Protocol address, destination Internet Protocol address, source media access control address, destination media access control address, source port number, destination port number, network protocol type, virtual LAN number, quality of service label value, packet length range start value, packet length range end value, replication flow direction flag, replication trigger timestamp, destination device address, destination device port number, device load level value, port queue waiting time (in microseconds), bit error rate range start value, bit error rate range end value, and replication flow hit count. All fields are stored using a fixed-length encoding format and are compared using sequential matching, without using dynamic functions. When constructing rule entries, fields are assigned matching priorities based on their type; for example, 5-tuple-related fields have higher priority than transport status fields, and transport status fields have higher priority than service identifier fields. The generated access control entries are written to the high-speed entry storage area of ​​the switching chip. This storage area has a 128-bit comparison bus, supports parallel comparison and priority matching, and enables the subsequent filtering process to be completed with nanosecond-level latency.

[0076] After the access control rule entries are constructed, all service data frames entering the replication process are matched and filtered one by one, and a hierarchical decision is executed. The hierarchical process consists of three layers of filtering logic. The first layer of filtering is based on the five-tuple fields, including the Internet Protocol address of the source and destination, the port number of the source and destination, and the protocol type field. This step is used to determine the session to which the traffic belongs and the direction of communication. The second layer of filtering is based on the Virtual LAN number field and the Quality of Service (QoS) tag value field to identify whether the service flow belongs to a special network area or carries a specific priority service. The third layer of filtering makes restriction decisions based on three parameters: replication flow hit frequency, bandwidth utilization of the target device's current port, cache utilization, and bit error rate. Any traffic with an excessively high hit frequency, device load above 85%, cache utilization above 70%, or bit error rate exceeding 0.5% for two consecutive periods will be marked as a high-pressure replication flow and forcibly assigned to an independent replication policy domain. Each policy domain will specify a unique replication time window, target device port group, and bandwidth allocation ratio, forming independent and non-overlapping replication management units.

[0077] The policy domain division results are written back to the replication pressure index heatmap, and the corresponding path positions in the heatmap are marked with their affiliation. Each replication path unit in the heatmap will include the current policy domain number, the average pressure value within that domain, the current matching entry index number, and the number of filter hits. During the replication scheduling phase, the device uses the markings in the heatmap and the policy domain rules to group replication flows, control policy concurrency, and sort the scheduling order, avoiding the risk of congestion and packet loss caused by multiple replication paths competing for the same target resource. Furthermore, during the operation of a policy domain, if the average pressure index of a replication path within a certain policy domain continues to rise and reaches a specified intervention threshold, the system will automatically adjust the access control field matching priority of that policy domain, reduce the replication frequency of traffic as needed, or replace the target device port, achieving dynamic adjustment of replication behavior.

[0078] This step aims to construct an access control list baseline containing twenty key fields and perform hierarchical filtering of replication traffic based on five-tuples, virtual LAN numbers, and quality of service tags. This enables precise identification and policy-based isolation of traffic in high-replication-pressure paths, further dividing resource-intensive replication behavior into independently controllable policy domains, thereby improving the flexibility of replication scheduling and the efficiency of link resource utilization. Through this hierarchical filtering mechanism, the device can complete the evaluation of each replicated data frame within nanoseconds, determining whether to initiate a replication operation based on its source and destination addresses, service level, transmission characteristics, and device load status, and assigning it to a specific replication policy domain. This step differs from traditional switching devices that rely solely on port mirroring or static rules for replication decisions. It features comprehensive field coverage, fine-grained filtering conditions, fast execution speed, and flexible adjustment mechanisms. It provides a clear data structure and control logic foundation for subsequent data stream deduplication, replication traffic pruning, and dynamic load adjustment, making it an indispensable intermediate step for dynamic optimization and closed-loop control of replication operations.

[0079] S004, based on the results of hierarchical screening and gating, introduces the bidirectional mutual exclusion signature and time-series hash chain of the deduplication engine to remove loopback packets and duplicate packets from the partitioned replication traffic, and feeds the deduplication results back to the strategy engine to form an iterative comparison, so as to compress the invalid traffic entering the analysis probe.

[0080] To address the resource waste, performance degradation, and probe overload issues caused by duplicate data frame forwarding and link loop feedback during replication, frame-level deduplication is required on the replication traffic, building upon the policy domain filtering results from the previous stage. This deduplication process uses a bidirectional mutually exclusive signature structure for identification and nanosecond-level timestamps for comparison. It constructs a time-series hash chain to accurately and efficiently identify replicated data frames and feeds the identification results back to the policy control logic, achieving dynamic linkage between replication behavior and policy configuration. This process includes the following steps:

[0081] After filtering access control fields and forming the policy domain structure, for each data frame about to enter the target device in each policy domain, its identification fields are extracted one by one, and a unique bidirectional mutually exclusive signature is generated. The signature construction process is as follows: nine items are selected from the data frame: source Internet Protocol address, destination Internet Protocol address, transport layer protocol field, source port number, destination port number, data frame length field, frame sequence number field, 8 consecutive bytes of the payload header, and timestamp field. These are then concatenated into a 128-bit fixed-length string in a predefined order. To distinguish directions, when generating a forward signature, the signature field order is source address-destination address-source port-destination port-protocol type; for a reverse signature, the order is reversed to destination address-source address-destination port-source port-protocol type, while the remaining fields remain the same. The completed signature, along with the data frame reception timestamp, is written to the deduplication buffer area within the switching chip. This buffer is implemented based on a dual-port static random access memory and has on-chip time synchronization logic to ensure that the consistency error of each entry's timestamp is controlled within 10 nanoseconds.

[0082] A time-series hash chain structure is constructed for matching and judgment. This structure stores all recent signature information and their occurrence time, supporting fast collision detection and time series difference judgment. The structure uses a hash index method, mapping the signature value to 256 fixed-address blocks through high-bit matching. Each block stores 16 chain structures containing the following fields: signature value, first occurrence timestamp, most recent occurrence timestamp, hit count, policy domain number, and corresponding target device port number. For each newly entered copied data frame, the system calculates its signature hash value and searches all linked list nodes in the corresponding block. If a node contains the same signature, and the time interval between the most recent occurrence of that signature and the current frame acquisition is less than 1 millisecond, the system determines that the frame is a duplicate data frame and will not copy or forward it. If the source address field and target address field are completely identical, the source port number and target port number are the same, the port number the data frame enters and the port number it is about to leave are the same, and the frame appears three times consecutively in the same policy domain, then the data frame is determined to be a loopback packet and must be completely removed. The above judgment is based entirely on static field values ​​and time difference calculations, without using hash digest compression or probabilistic judgment, ensuring that the results can be repeatedly verified and are feasible for industrial implementation.

[0083] After identifying duplicate data frames and loopback packets, the frame removal phase begins. For each policy domain, the device maintains a removal hit table and an output control channel. When a duplicate frame is identified, the copying process is interrupted, and the data frame is not written to any output buffer. If a loopback packet is identified, the frame is written to a dedicated discard buffer, which is periodically released by the device's background program. Within each second sampling period, the device counts the number of removed frames, duplicate frame removal rate, loopback packet removal rate, hit field structure, and path identifier for each policy domain. These statistics are transmitted to the policy field control logic via a preset hardwired connection and compared with the field settings in the current policy domain structure. If the duplicate removal rate of a policy domain exceeds 35% for two consecutive periods, or the loopback removal rate exceeds 5% of the total number of frames consecutively, the device will mark the policy domain as a "high-risk removal policy domain" and activate the field feedback analysis logic.

[0084] A feedback structure is constructed to establish a closed-loop linkage mechanism between the culling results and the replication control policy. This mechanism records detailed indicators of frame culling events within each policy domain, using path indexes as units. These indicators include: the signature value of the culled data frame, source address, target address, policy trigger time, number of culling attempts, involved fields, device port number, and target device status. When the source address duplication rate in culled data frames of a certain policy domain exceeds 70%, the system will automatically optimize the five-tuple field matching rules, increase the source address comparison weight, and limit broad-based matching. When loopback packets are concentrated on a specific outgoing port path, the system will forcibly remove the mirroring configuration permission for that outgoing port and notify the control logic to terminate the corresponding replication policy domain configuration. All field adjustment results will be immediately written to the access control field matching table, update the policy domain rules, and synchronize to the replication pressure heatmap, marking the corresponding path in the graph with a "culling policy optimization in progress" mark until the culling rate falls below an acceptable range after the new policy takes effect. This feedback mechanism ensures that replication behavior is precisely adjusted and the policy evolves throughout the entire policy lifecycle, effectively suppressing invalid data transmission behavior and improving link resource utilization efficiency and analysis probe processing performance.

[0085] The purpose of this step is to introduce a precise duplicate data identification and removal mechanism after the replicated traffic has undergone hierarchical filtering and structured strategy segmentation. This further reduces invalid traffic usage and improves the resource utilization efficiency of replication and the processing capacity of the target device. By constructing a bidirectional mutually exclusive signature structure, the feature fields of data frames are encoded in a fixed order, combined with nanosecond-level timestamps to form unique identification information, and stored and matched using a time-series hash chain. This enables rapid identification and classification of data frames that appear repeatedly within a short period of time and those exhibiting loop behavior. Based on this, the system performs physical removal operations on redundant data frames and feeds the removal statistics back to the front-end access control policy logic, forming an automatic closed-loop adjustment mechanism. This deduplication process not only reduces the repetitive load entering the analysis probe, improving analysis accuracy and resource allocation efficiency, but also provides a quantitative basis for subsequent policy iteration and replication optimization. Compared to the existing technology that forwards all replicated data without traffic identification and feedback mechanisms, this step achieves refined and intelligent control of replication operations, significantly enhancing the controllability, maintainability, and evolvability of the entire replication path.

[0086] S005, based on the deduplication results, deploys hardware-level power failure pass-through protection and mode switching DIP switches on the replication link, and uses deduplication feedback information to perform weight calibration on bypass replication and serial replication, thereby forming a fault-tolerant orchestration, and writes the fault-tolerant status back to the replication pressure index heatmap.

[0087] To improve service continuity of the replication link under abnormal conditions and enhance the flexibility and robustness of the replication strategy in high-load environments, hardware-level fault-tolerant protection mechanisms and dynamic switching mechanisms need to be introduced into the physical structure and control logic of the replication path. This mechanism uses the deduplication statistics of the replication traffic obtained in the previous stage as input, combines the characteristics of business flow replication, deploys a power-off pass-through protection structure on the data channel, and achieves rapid switching of replication modes based on hardware DIP switches. Simultaneously, based on the redundancy ratio, loopback rate, and processing capacity of the target device identified by deduplication, the replication weight allocation strategy is adjusted. This constructs a fault-tolerant control structure for the replication path with fault self-recovery capabilities, automatic replication mode adjustment capabilities, and real-time load awareness capabilities. The fault-tolerant operating status is synchronously updated in real-time to the replication pressure index heatmap, enabling visualized policy intervention. The specific process includes the following steps:

[0088] A physical bypass structure is deployed in the physical replication link of the main service flow to ensure uninterrupted main service during power outages. This structure consists of two parallel signal paths: a data processing channel for normal replication operations and a pass-through channel that is automatically triggered during power outages. The data processing channel includes an electrical-to-optical transceiver component, a switching chip, traffic marking logic, and a replication output interface, used to implement packet replication, policy matching, and target forwarding. The pass-through channel includes a set of electromagnetic relay switches, direct-connect signal pairs, and a physical isolation trigger circuit. When the replication equipment is in a normal powered-on state, the relay switches remain open, and all service data is replicated and forwarded via the switching chip. When the equipment experiences a power outage, abnormal restart, firmware failure, chip self-test failure, or temperature exceeding a threshold, the power status detection circuit outputs a low level, the relay switches immediately close, and the main link input port signal is forwarded directly to the output port at line speed without any processing, achieving physical layer data pass-through protection and preventing service interruption. The switching response delay of this protection structure during power outages does not exceed 20 milliseconds, ensuring continuous transmission requirements for carrier-grade core links.

[0089] A hardware DIP switch structure is embedded in the replication link control plane to enable rapid switching and configuration management of replication modes. The DIP switch component consists of three physical DIP switches, each controlling a set of replication behavior parameters: replication path type selection bit, policy execution control bit, and fault recovery enable bit. The first bit selects the replication mode. When the DIP switch is high, the current replication structure operates in serial mode, meaning that data frames enter the switching chip from the service inlet port, are processed by the replication logic, and are simultaneously output to the target probe device and the service outlet port. When the DIP switch is low, it operates in bypass mode, where service data is directly forwarded from the inlet port to the outlet port, and replication only asynchronously forwards data copies to the target probe device through the mirror port, without affecting the performance of the main link. The second bit is the policy execution control switch, used to enable or disable the access control policy matching function. The third bit is the fault recovery control bit, used to automatically restore the policy state to the state before the power failure after the device is brought back online, preventing misjudgment that could lead to the loss of replication policy configuration. By physically configuring the three-way DIP switch combination states, the copying method can be adjusted without relying on the software interface, providing high operability and manual repair capability in fault scenarios.

[0090] Based on the deduplication results and statistical data generated in the previous stage, and combined with the pressure level and packet rejection rate of each path in the replication pressure index heatmap, the replication paths in the replication policy domain are weighted and reallocated to build an adaptive fault-tolerant orchestration mechanism. Specifically, the device calculates the replication effectiveness index based on indicators such as the number of duplicate packets rejected, the number of loopback packets, the total rejection ratio, the rejection field distribution, and the target device load ratio in each policy domain, and sorts them by replication channel. For replication paths with a replication effectiveness index lower than a preset threshold (e.g., 0.65) and the target device is already under high load, the system automatically switches the path from serial mode to bypass mode and reduces its replication scheduling cycle. For policy domains with a rejection rate exceeding 50%, the device control logic downgrades its replication channel priority from high to medium and limits the maximum bandwidth ratio to no more than 20%. For policy domains with a stable rejection rate below 15%, no loopback behavior, and sufficient target probe load, the system maintains its serial mode and appropriately increases its replication priority. The adjustment results of all replication paths are recorded and linked with the current access control field configuration to ensure that replication behavior is continuously optimized and dynamically adjusted according to the current actual network operation status, thereby improving the accuracy of replication scheduling and the efficiency of resource allocation.

[0091] The results of the replication mode switching, weight adjustments, fault protection trigger records, and current effectiveness indicators of the replication path are written into the corresponding path unit of the replication pressure index heatmap to achieve a visual display and dynamic trend recording of the fault tolerance status. Specifically, in the two-dimensional path matrix of the replication pressure heatmap, each path unit embeds four status labels, including replication mode (serial / bypass), replication scheduling priority (high / medium / low), fault tolerance protection status (activated / inactive), and the timestamp of the most recent policy adjustment. When a replication path of the device triggers a power outage protection action, the corresponding unit of that path is marked "Pass-through protection triggered"; when the replication mode is switched from serial to bypass, it is marked "Replication mode switching completed"; if the replication policy priority is adjusted from medium to high, it is marked "Priority increased"; all the above labels are refreshed synchronously with the device's policy operation every cycle and are presented in real time on the operation and maintenance visualization platform, enabling operation and maintenance personnel to quickly grasp the fault tolerance orchestration status of the replication link and assess the system's operational stability and resource redundancy capabilities. This synchronization process realizes real-time linkage between fault tolerance control logic and traffic awareness visualization, which is a key support for improving the controllability of replication behavior.

[0092] This step aims to enhance the stability and availability of the replication link under abnormal conditions such as device failure, high load, or configuration conflicts, building upon the deduplication and policy filtering of the replicated traffic. This ensures that replication does not interfere with the main link's services and allows for adaptive optimization at the replication method and resource scheduling levels. By deploying a hardware-level power-off pass-through protection structure in the replication link, millisecond-level automatic bypass is achieved when the replication device experiences an abnormal power outage or restart, preventing service data interruption or blockage. Simultaneously, combined with physical DIP switch configuration, rapid switching between serial and bypass modes for replication allows the replication policy to be flexibly adjusted according to network conditions. When analyzed in conjunction with the deduplication statistics and traffic characteristic data obtained during the deduplication phase, the system can automatically identify inefficient channels, high-conflict policies, or target device overload in the replication path and adjust replication priorities and methods accordingly, thus constructing a fault-tolerant and self-adjusting replication link structure. Finally, this step achieves dynamic and visual management of replication behavior by writing replication status, protection actions, and policy changes back to the replication pressure index heatmap in real time, providing strong foundational support for link scheduling, policy iteration, and risk awareness.

[0093] S006, after the fault-tolerant orchestration is completed, a quantum negative pressure backflow control loop is superimposed on the strategy engine and the deduplication engine. Based on the dynamic calculation results of jitter entropy and congestion entropy, the replication weight and channel time slot are allocated in real time, thereby realizing the overload strategy's reverse extraction and self-balancing adjustment, and injecting the adjusted state into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic control.

[0094] To further enhance the adaptability of the replication link to changes in traffic pressure and achieve dynamic reallocation of replication resources, after completing policy selection, traffic deduplication, and fault-tolerant orchestration, a quantum negative pressure backflow control loop is superimposed on the policy control logic and traffic processing logic. This control loop takes link jitter and congestion states as input, calculates jitter and congestion entropy in the path in real time, constructs a feedback-driven replication scheduling strategy, autonomously adjusts replication priority, controls link time slot resource allocation, and forms a state feedback chain injected into the full-link telemetry channel, constructing a triple closed loop of analysis, identification, and control. This step is completed step by step through the following stages:

[0095] The system collects data packet forwarding behavior across each replication path and extracts two metrics—jitter entropy and congestion entropy—within a fine-grained time window to assess replication path stability. Jitter entropy measures the volatility of data packet arrival intervals within the replication path. The device, based on a high-precision time synchronization unit, records the arrival time of each frame in each replication path and calculates the time interval between adjacent frames, forming an inter-frame interval distribution sequence. Based on this distribution sequence, deterministic binning and probabilistic calculation methods are used to obtain the Shannon entropy value of the distribution, which measures the transmission volatility of the path per unit time. Congestion entropy is obtained through joint analysis of the length change and average queuing time of the switching chip's output port buffer queue. Specifically, on each replication path, the real-time queuing depth and queuing time of the buffer are recorded, and after joint distribution modeling, the congestion entropy value is derived based on a discrete entropy model. Both entropy values ​​are refreshed every 100 milliseconds, serving as direct input indicators of the path's operational status.

[0096] Based on the two entropy values ​​mentioned above, the replication weight and channel time slot resources allocated to each strategy path are dynamically adjusted. This adjustment employs a quantum structure, first dividing the replication priority into 16 discrete levels, each level corresponding to a set of replication scheduling strategy parameters, including replication frequency, scheduling interval, and maximum bandwidth limit. When the congestion entropy of a path exceeds 1.8 bits / cycle for two consecutive cycles, and its jitter entropy shows an increasing trend, the path is considered to face potential congestion risk, and the "negative pressure backflow" mechanism is immediately triggered. This mechanism instructs the device to lower the replication priority of the current path by two quantum levels and release the channel time slots it occupies to the resource pool for other high-quality paths to re-compete for. Conversely, when the path congestion entropy is stably less than 1.0 and the jitter entropy continues to decrease, it indicates that the path is stabilizing, the replication priority is increased by one level, more replication scheduling cycles and channel usage frequency are allocated, thereby enhancing its replication capability. The above adjustment process is strictly limited by the path state threshold to ensure the rationality and convergence of the control behavior.

[0097] Based on the weight adjustment operation results, a state-preserving structure for the control loop is established, forming a path control trajectory and performing iterative optimization of the control strategy. After each strategy path undergoes a replication priority adjustment, the system records its state before and after, including the path number, original weight level, adjustment direction, corresponding entropy value change, and adjusted scheduling parameters, and establishes a state transition matrix with the path as the dimension. When a replication path experiences two or more quantum level jumps within a monitoring period, the system marks it as a "high-fluctuation path," reduces its scheduling frequency in the next period, and prohibits further increases in replication level to prevent frequent oscillations in the path state in the short term, affecting the overall control stability. In addition, for all weight change operations, the system automatically records the affected fields (such as quintuples, VLAN identifiers, and quality of service levels) and the target probe address, facilitating subsequent strategy convergence or behavior reproduction.

[0098] The results of the aforementioned control operations and the current operational status of the strategy path are written back to the end-to-end telemetry structure, synchronizing control behavior with link status and providing basic data for upper-level analysis. Specifically, four fields are added to each replication path in the telemetry data frame: "Replication Weight Level," "Path Fluctuation Level," "Current Control Trend," and "Last Adjustment Time." The replication weight level is represented by W0 to W15, indicating the replication level of the current path; the path fluctuation level is divided into low, medium, and high based on the frequency of replication weight changes; the current control trend indicates whether a counter-pull or weighting was performed in this cycle; and the last adjustment time is used to help determine the rhythm of the path control cycle. The telemetry structure broadcasts the path status to the telemetry output of the switching chip every 500 milliseconds for use by the control closed loop and visualization platform. In this way, the system can present the control status, replication efficiency, and strategy adaptation effect of each path in real time, realizing a three-in-one coordinated control closed loop of the strategy layer, link layer, and control layer.

[0099] The purpose of this step is to introduce a quantum negative pressure feedback control loop into the policy control logic and traffic processing structure, thereby achieving adaptive adjustment of replication behavior and dynamic optimization of resource allocation. This addresses the problem of replication strategies struggling to respond in real-time to network state changes under high load conditions. Specifically, this step extracts two indicators—jitter entropy and congestion entropy—from each replication path to perceive the path's volatility and congestion level in real time, using these as input variables to drive the adjustment logic of replication weights and channel time slots. When a path is severely congested or replication stability is poor, the system automatically reduces its replication priority and releases bandwidth resources, achieving "reverse pull"; when path stability recovers, its replication weight is gradually increased, achieving "self-balancing". This dynamic control strategy effectively avoids resource congestion caused by excessive replication on hot paths and prevents inefficient paths from occupying resources for extended periods without releasing them. Simultaneously, the control results are injected into the telemetry channel in real time, allowing the trajectory of replication behavior changes to be monitored and tracked in real time, providing data support for upper-layer policy optimization and path convergence, and constructing a complete identification-control-feedback closed loop. This mechanism breaks through the bottleneck of static configuration and manual adjustment in traditional replication strategies, enabling the replication system to have real-time response, automatic evolution and intelligent control capabilities. It is a key means to achieve efficient, stable and controllable traffic replication behavior in high-density network environments.

[0100] This invention achieves real-time visualization of resource occupancy in the replication link by constructing a full-link telemetry mechanism and a replication pressure index heatmap; it identifies and partitions high-frequency conflict paths using conflict fingerprints and access control list baselines; further, it achieves precise removal of redundant replication traffic by combining bidirectional mutual exclusion signatures and time-series hash chains; and it achieves adaptive balanced allocation of replication policies and link resources while ensuring replication reliability through hardware-level fault-tolerant orchestration mechanisms and quantum control loops. Ultimately, this method constructs a closed-loop process from replication status awareness, conflict identification, policy optimization, traffic deduplication to fault-tolerant control and feedback adjustment, significantly improving the performance stability and policy execution efficiency of replication behavior, reducing dependence on core device computing resources, and demonstrating good engineering feasibility.

[0101] This invention provides, for example Figure 2 The service traffic replication system based on a switching chip shown includes a full-link telemetry module, a collision detection module, a policy partitioning module, a traffic deduplication module, a fault-tolerant orchestration module, and a dynamic control module.

[0102] The end-to-end telemetry module, by constructing an end-to-end telemetry mechanism on the backbone data channel, collects latency fluctuations and packet loss trajectories in real time, and generates a replication pressure index heatmap to characterize the resource consumption range of the mirror session on the forwarding plane.

[0103] The conflict detection module generates conflict fingerprints in the three-state content addressing storage based on the replication pressure index heatmap and combined with real-time port statistics. It uses the conflict fingerprints to locate high-frequency replication hotspots, cross-port policy conflicts, and repeated entry paths, providing a reference for policy convergence.

[0104] The policy partitioning module, driven by conflict fingerprints, builds an access control list baseline containing twenty key fields within the policy engine, and performs hierarchical filtering and gating according to the five-tuple, virtual LAN identifier and quality of service identifier, thereby transforming areas with concentrated replication pressure into policy partitions.

[0105] The traffic deduplication module, based on the results of hierarchical filtering and gating, introduces the bidirectional mutual exclusion signature and time-series hash chain of the deduplication engine to remove loopback packets and duplicate packets from the partitioned replicated traffic, and feeds the deduplication results back to the strategy engine to form an iterative comparison, so as to compress invalid traffic entering the analysis probe.

[0106] The fault-tolerant orchestration module, based on the deduplication results, deploys hardware-level power failure pass-through protection and mode switching DIP switches on the replication link, and uses deduplication feedback information to perform weight calibration on bypass replication and serial replication, thereby forming a fault-tolerant orchestration, and writes the fault-tolerant status back to the replication pressure index heatmap.

[0107] The dynamic control module, after fault-tolerant orchestration is completed, superimposes a quantum negative pressure backflow control loop on the strategy engine and deduplication engine. Based on the dynamic calculation results of jitter entropy and congestion entropy, it allocates replication weight and channel time slots in real time, thereby realizing the reverse extraction and self-balancing adjustment of the overload strategy. The controlled state is then injected into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic control.

[0108] The service traffic replication method based on a switching chip provided in this embodiment of the invention is implemented through the aforementioned service traffic replication system based on a switching chip. For details of the specific methods and processes of the service traffic replication system based on a switching chip, please refer to the embodiments of the service traffic replication method based on a switching chip described above, which will not be repeated here.

[0109] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A method for traffic flow replication based on a switching chip, characterized in that, The method comprises the following steps: S001, by constructing a full-link telemetry mechanism in the backbone data channel, collecting the delay fluctuation and packet loss trajectory in real time, and generating a replication pressure index heat map to represent the resource occupation range of the mirror session on the forwarding plane; S002, based on the replication pressure index heat map and combined with the port real-time statistical information, generate a conflict fingerprint in the three-state content addressable memory, use the conflict fingerprint to locate the high-frequency replication hotspots, cross-port policy conflicts and repeated entry paths, and provide a reference for policy convergence; S003, with the help of the conflict fingerprint, build an access control list baseline containing twenty key fields in the policy engine, and perform hierarchical screening gating according to the five-tuple, virtual local area network identifier and quality of service identifier, thereby converting the replication pressure concentration area into a policy partition; S004, on the basis of the result of hierarchical screening gating, introduce the bidirectional mutual exclusion signature and time sequence hash chain of the deduplication engine, and remove the loop packets and repeated packets of the partitioned replication traffic, and feed back the deduplication result to the policy engine to form an iterative comparison to compress the invalid traffic of the entry analysis probe; S005, relying on the deduplication result, deploying hardware-level power-off straight-through protection and mode switching dial code on the replication link, and using the deduplication feedback information to calibrate the weight of bypass replication and series replication, thereby forming fault-tolerant arrangement, and writing the fault-tolerant state to the replication pressure index heat map; S006, after the fault-tolerant arrangement is completed, superimpose a quantumized negative pressure backflow regulation loop on the policy engine and the deduplication engine, and based on the dynamic calculation results of jitter entropy and congestion entropy, real-time allocate the replication weight and channel time slot, thereby realizing the back-pulling and self-balancing adjustment of the overload strategy, and injecting the regulated state into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic regulation.

2. The switch-chip-based traffic flow replication method according to claim 1, wherein, Step S001 comprises: In the backbone link, collect the inbound timestamp and outbound timestamp of each data frame through the switching device with multi-port high-speed forwarding capability, calculate the forwarding delay, and compare the data frame receiving number and forwarding number in the forward cache area and backward cache area to confirm whether there is a packet loss event; Based on the collected forwarding delay, cache occupation ratio, packet loss number and bit error rate, compare the performance difference of the replication path under the conditions of with replication and without replication, mark the pressure level with a percentage index to form a replication path pressure data set; Based on the replication path pressure data set, construct a two-dimensional heat map with the replication source port and target port as the horizontal axis and time as the vertical axis, and map the pressure level to a five-level color scale to generate a replication pressure index heat map; In the replication pressure index heat map, select the replication paths that are in severe congestion and extreme congestion levels for three consecutive time periods, and mark them as conflict replication paths and output warning information in combination with the port queue length, discarded frame number and target device receiving capacity.

3. The switch-chip-based traffic flow replication method of claim 1, wherein, Step S002 comprises: Extract the replication path information in the high pressure level from the replication pressure index heat map, and form a to-be-analyzed path set in combination with the real-time statistical data of the switching device port; Then, a data entry containing seven fields of copy source address, copy target address, source port number, target port number, protocol type identification, copy time information and target device number is constructed for the path to be analyzed and written into the ternary content address memory to form a matching index table; Through matching logic, copy hotspot overlap conflict, cross-port resource conflict and copy path reentry conflict are identified, and a conflict fingerprint containing a unique identification number, a trigger field combination, a hit time and a conflict type is generated; The conflict fingerprint is marked and a conflict fingerprint accumulation table is established to identify copy conflict high-risk paths and provide input for policy convergence.

4. The switch-chip-based traffic flow replication method of claim 1, wherein, Step S003 includes: Source port number, target port number, source Internet protocol address, target Internet protocol address, transmission layer port number, protocol type value, copy time information and target device port state are extracted for high-risk copy paths to form a multi-dimensional data matrix; Based on the multi-dimensional data matrix, an access control rule entry containing twenty fixed fields is generated and written into a high-speed table item storage area, and field matching is completed through parallel comparison; The service data frames entering the copy process are sequentially subjected to hierarchical screening, the first layer determines the communication direction based on the five-tuple field, the second layer identifies the priority based on the virtual local area network number and the quality of service label value, and the third layer determines whether to divide into an independent policy domain based on the hit frequency, port bandwidth utilization, cache usage and bit error rate; The generated policy domain result is written back to the copy pressure index heat map, and grouping processing, concurrency control and dynamic adjustment are performed in the copy scheduling according to the policy domain rules.

5. The switch-chip-based traffic flow replication method of claim 1, wherein, Step S004 includes: After hierarchical screening is completed, source Internet protocol address, target Internet protocol address, transmission layer protocol field, source port number, target port number, data frame length, frame sequence number, payload header byte and time stamp field are extracted for copy data frames entering the target device to generate a bidirectional mutual exclusion signature and write it into a deduplication cache; A time sequence hash chain is constructed to store signature value, occurrence time, hit frequency, policy domain number and target port number, and repeated frames and loopback packets are determined by comparison; Repeated frames are interrupted for copy forwarding, and loopback packets are written into a discard buffer, and the number of rejected, rejection rate and hit field information are counted and transmitted to the policy field control logic for comparison; A feedback structure is established to form a closed-loop linkage of rejection event indicators and copy policies, and when the rejection rate or loopback rate exceeds a threshold, the field matching rules and port configuration are automatically adjusted, and the update result is synchronized back to the copy pressure index heat map for dynamic adjustment.

6. The switch-chip-based traffic flow replication method of claim 1, wherein, Step S005 includes: A physical bypass structure is deployed in the main service stream copy link, and under normal conditions, the service stream is copied and forwarded through the switch chip, and when the device is powered off, restarted or fails, the electromagnetic relay switch is closed to realize straight-through forwarding, ensuring that the main link is not interrupted; A three-position dial switch is set on the copy link control plane, the first position controls the copy mode selection, the second position controls the policy execution state, and the third position controls the fault recovery, so that the copy mode can be switched between the series mode and the bypass mode, and the original policy configuration can be maintained when the device is restored online; Based on the deduplication statistics and the replication pressure index heat map, the effectiveness index of each replication path is calculated, and the replication path weight is adjusted according to the elimination rate and the target device load. When the path pressure is too high, the bypass mode is switched to and the scheduling period is reduced. When the elimination rate is low and the target device load is sufficient, the cascade mode is maintained and the replication priority is moderately increased. The replication mode switching state, weight adjustment, fault protection record and path effectiveness index are written into the replication pressure index heat map, and the replication mode, priority, fault tolerance protection state and strategy adjustment time are marked, and real-time display is realized in the operation and maintenance platform, realizing the visualization and closed-loop control of fault tolerance arrangement.

7. The switch-chip-based traffic flow replication method of claim 1, wherein, Step S006 comprises: In the replication path, the data frame arrival interval is collected and the jitter entropy is calculated, and the port buffer queue length and queuing time are collected and the congestion entropy is calculated, which are used as path operation indexes; According to the change trend of jitter entropy and congestion entropy, the replication weight and channel time slot are dynamically adjusted. The replication frequency, scheduling interval and bandwidth allocation are controlled by quantum level. When the path is in a congested state, the replication priority is reduced and the channel time slot is released. When the path is stable, the replication priority is increased and the scheduling period is increased. According to the adjustment operation record path number, weight level, adjustment direction, entropy value change and scheduling parameter, a state transition matrix is established, and a high fluctuation path is identified to limit its frequent switching. The affected fields and target device addresses are recorded for subsequent convergence. The control results are written into the full-link telemetry structure, and the replication weight level, path fluctuation level, current control trend and last adjustment time are marked in the data frame, and are output at a fixed period, realizing the closed-loop adjustment of the strategy layer, link layer and control layer.

8. A system for replicating service traffic based on a switching chip for implementing the method for replicating service traffic based on a switching chip according to any one of claims 1 to 7, characterized in that, The full-link telemetry module, conflict detection module, strategy partitioning module, traffic deduplication module, fault tolerance arrangement module and dynamic control module are included: The full-link telemetry module constructs a full-link telemetry mechanism in the backbone data channel, collects delay fluctuation and packet loss trajectory in real time, and generates a replication pressure index heat map to represent the resource occupation range of the mirror session on the forwarding plane. The conflict detection module generates a conflict fingerprint in the three-state content addressable storage based on the replication pressure index heat map and real-time port statistical information, and uses the conflict fingerprint to locate high-frequency replication hotspots, cross-port strategy conflicts and repeated entry paths, providing a reference for strategy convergence. The strategy partitioning module constructs an access control list baseline containing twenty key fields in the strategy engine under the drive of the conflict fingerprint, and performs hierarchical screening gating according to the five-tuple, virtual local area network identifier and quality of service identifier, thereby converting the replication pressure concentration area into a strategy partition. The traffic deduplication module introduces the bidirectional mutual exclusion signature and time sequence hash chain of the deduplication engine based on the result of hierarchical screening gating, removes the looped and repeated packets of the partitioned replication traffic, and feeds back the deduplication result to the strategy engine to form iterative comparison, thereby compressing the invalid traffic entering the analysis probe. The fault-tolerant arrangement module, relying on the deduplication result, deploys hardware-level power-off straight-through protection and mode switching dials in the replication link, and uses deduplication feedback information to calibrate the weights of bypass replication and concatenation replication, thereby forming a fault-tolerant arrangement, and writing the fault-tolerant state back to the replication pressure index heat map; The dynamic control module, after the fault-tolerant arrangement is completed, superimposes a quantized negative pressure backflow control loop on the strategy engine and the deduplication engine, and performs real-time allocation of replication weights and channel time slots based on the dynamic calculation results of jitter entropy and congestion entropy, thereby realizing the back-pumping and self-balancing adjustment of the overload strategy, and injecting the regulated state into the full-link telemetry mechanism to form a closed loop of analysis, identification and dynamic control.

9. A service traffic replication device based on a switching chip, comprising the service traffic replication system based on a switching chip of claim 8.

Citation Information

Patent Citations

  • In-band network telemetering method and device

    CN113422707A

  • Cooperative hybrid congestion control method based on path recovery

    CN114828081A