Method and device for generating source address verification table item and electronic equipment
By collaborating between the target device and the ABR device, and utilizing the IGP protocol extension to generate source address verification entries across local area networks, the problem of the IGP protocol's inability to verify source addresses across local area networks is solved, achieving more efficient and accurate source address verification.
Patent Information
- Application Number
- CN202410712355.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-03
- Publication Date
- 2025-12-09
AI Technical Summary
The existing IGP protocol can only generate source address verification entries within the local area network (LAN), and cannot achieve source address verification across LANs, resulting in the inability to effectively verify the legitimacy of traffic source addresses across LANs.
Through collaboration between the target device and the Area Border Router (ABR) device, source address verification entries across local area networks are generated using IGP protocol extensions. The target device calculates the reverse shortest path based on link topology information and reverse cost, and combines this with network prefix information distributed by the ABR device to generate accurate source address verification entries.
It enables source address verification across local area networks, improves the accuracy and completeness of the generated source address verification table entries, reduces the path calculation requirements when the network topology changes, and improves the performance of linkage processing.
Smart Images

Figure CN121098522A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus and electronic device for generating source address verification entries. Background Technology
[0002] Source Address Validation (SAV) is a crucial method for eliminating source address spoofing attacks, and many existing defense solutions are based on it. The basic principle of SAV is to establish a mapping relationship between source addresses and the ingress interfaces of network devices, i.e., SAV entries. An SAV entry is a <source prefix, ingress interface> entry used to verify the legitimacy of the source address of traffic.
[0003] Currently, BGP (Border Gateway Protocol) or IGP (Interior Gateway Protocol) protocols are mainly used to extend the generation of SAV entries. For using IGP to extend support for source address authentication, one approach is to use a root node with SAV enabled. Based on the local area network's link topology and the reverse cost of each link, the shortest reverse path from the root node to the source router is calculated. Then, based on the interface corresponding to the shortest reverse path and the source address prefix connected to that source router, an SAV entry is generated.
[0004] like Figure 1 The diagram illustrates a scenario using the IGP protocol for source address verification. R1 is the root node with SAV enabled, 101.1.1.0 / 24 is the source address prefix, and R4 and R5 are the source routers connecting to the source address prefix. The cost value of each link between two nodes represents the cost of traversing that link. Taking R2-R4 as an example, the cost of R2→R4 is the forward cost of traversing this link, with a value of 10; the cost of R4→R2 is the reverse cost of traversing this link, with a value of 100. On R1, based on the link topology information of the local area network and the reverse cost of each link, the shortest reverse paths from R1 to R4 and R5 need to be calculated. This means calculating the reverse path with the minimum sum of the reverse costs of each link from R1 to R4 and R5. The corresponding SAV entries are then generated based on the interface corresponding to the shortest reverse path and the source address prefixes connected to R4 and R5.
[0005] However, the IGP protocol only operates within the local area network. When the root node and source address with SAV enabled are located across local area networks, the above solution cannot generate the corresponding SAV entries. Summary of the Invention
[0006] The application provides a method, device and electronic equipment for generating a source address verification entry to realize generation of an IGP inter-LAN source address verification entry.
[0007] In a first aspect, the application provides a method for generating a source address verification entry, which is applied to a target device that is enabled for source address verification, and is connected to an area border router (ABR) device. The method comprises the following steps:
[0008] According to link topology information of a first local area network (LAN1) and reverse cost of each link, a reverse shortest path cost from the target device to each ABR device in the LAN1 is calculated, wherein the reverse shortest path is a reverse path with the minimum sum of reverse costs of each link.
[0009] When receiving network prefix information sent by each ABR device respectively, a source address verification entry is generated according to the network prefix information and the reverse shortest path cost from the target device to each ABR device, wherein the ABR device is associated with the LAN1 and a second local area network (LAN2), the network prefix information comprises an address of the ABR device, a source address prefix of the LAN2, an address and address prefix of a source routing device in the LAN2, and a reverse shortest path cost from the ABR device to each source routing device, the source address prefix is connected to one or more source routing devices, and the source address verification entry at least comprises the source address prefix and a legal incoming interface corresponding to the source address prefix.
[0010] By receiving inter-LAN network prefix information distributed by the ABR device, the source address verification entry is generated based on IGP protocol extension, and the source address verification entry can realize inter-LAN source address verification. The network prefix information also carries an address of a source routing device connected to the source address prefix, so that the target device can know which source routing devices distribute the source address prefix, avoid missing possible paths, and more accurately determine one or more legal incoming interfaces corresponding to the source address prefix, thereby improving accuracy and integrity of the generated source address verification entry.
[0011] In a possible design, the generating the source address verification entry according to the network prefix information and the reverse shortest path cost of the target device to each ABR device includes: determining whether the source address prefix of the LAN2 is distributed by multiple ABR devices; if a first source address prefix is distributed by a single ABR device, finding the first reverse shortest path cost of the target device to a first target ABR device in the network prefix information, and taking an interface corresponding to the first reverse shortest path cost as a legal incoming interface of the first source address prefix, where the first target ABR device is the ABR device distributing the first source address prefix; if a second source address prefix is distributed by multiple ABR devices, calculating total reverse shortest path costs of the target device to each source routing device connected to the second source address prefix according to the network prefix information, and taking an interface corresponding to each total reverse shortest path cost as a legal incoming interface of the second source address prefix; and generating the source address verification entry based on each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0012] In a possible design, the method further includes: when receiving node network prefix information respectively sent by each ABR device, generating a first entry according to the node network prefix information, where the node network prefix information includes addresses and address prefixes of source routing devices in the LAN2, addresses of the ABR devices, and reverse shortest costs of the ABR devices to the source routing devices; when receiving non-node network prefix information respectively sent by each ABR device, generating a second entry according to the non-node network prefix information, where the non-node network prefix information includes source address prefixes connected by source routing devices in the LAN2 and addresses of the source routing devices; and combining the first entry and the second entry to generate the source address verification entry.
[0013] The method can more efficiently and accurately generate the source address verification entry, and in the case of network topology change, including link cost adjustment or link failure, only the node address prefix needs to be updated, and all subnet routing prefixes do not need to be changed, thereby improving the linkage processing performance between the source address verification entry and network change.
[0014] In a possible design, the generating the first table item according to the node network prefix information comprises: determining whether an address prefix of a source routing device in the LAN2 is distributed by a plurality of ABR devices; if an address prefix of a first source routing device is distributed by a single ABR device, finding a second reverse shortest path cost of the target device to a second target ABR device, taking an interface corresponding to the second reverse shortest path cost as a legal incoming interface of the address prefix of the first source routing device, where the second target ABR device is the ABR device distributing the address prefix of the first source routing device; if an address prefix of a second source routing device is distributed by a plurality of ABR devices, calculating a total reverse shortest path cost of the target device to the second source routing device according to reverse shortest path costs of the plurality of ABR devices to the second source routing device and reverse shortest path costs of the target device to the plurality of ABR devices, and taking an interface corresponding to the total reverse shortest path cost as a legal incoming interface of the address prefix of the second source routing device; and generating the first table item based on the address prefix of each source routing device and the legal incoming interface corresponding to the address prefix of each source routing device.
[0015] In a possible design, the generating the second table item according to the non-node network prefix information comprises: determining, from the first table item, a legal incoming interface corresponding to an address of a source routing device in the LAN2 according to the address of the source routing device; taking the legal incoming interface corresponding to each source routing device as a legal incoming interface corresponding to a source address prefix connected by each source routing device, and generating a second table item composed of each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0016] The application further provides a method for generating a source address verification table item, which is applied to an ABR device, and the ABR device is connected to a target device with source address verification enabled, and the method comprises the following steps.
[0017] calculating a reverse shortest path cost of the ABR device to a source routing device in the LAN2 according to link topology information of a second LAN2 and a reverse cost of each link, where the ABR device is associated with the LAN2 and a first LAN1, and the reverse shortest path is a reverse path with a minimum sum of each reverse cost;
[0018] distributing network prefix information to the target device in the LAN1, where the network prefix information comprises: an address of the ABR device, source address prefixes of the LAN2, addresses and address prefixes of source routing devices in the LAN2, and a reverse shortest cost of the ABR device to each source routing device.
[0019] By distributing the network prefix information to the target device in the LAN1 through the ABR device, the target device can generate a source address verification entry according to the network prefix information and the IGP protocol extension, and the source address verification entry can implement source address verification across the LANs. In addition, the network prefix information also carries the address of the source routing device connected to the source address prefix, so that the target device can know which source routing devices distribute the source address prefix, avoid missing possible paths, and more accurately determine one or more legal ingress interfaces corresponding to the source address prefix, thereby improving the accuracy and integrity of generating the source address verification entry.
[0020] In a possible design, the distributing the network prefix information to the target device in the LAN1 includes: distributing node network prefix information to the target device in the LAN1, where the node network prefix information includes the address and address prefix of the source routing device in the LAN2, the address of the ABR device, and the reverse shortest cost of the ABR to the source routing device in the LAN2; and distributing non-node network prefix information to the target device in the LAN1, where the non-node network prefix information includes the source address prefix of the LAN2 and the address of the source routing device connected to the source address prefix.
[0021] By sending the node network prefix information and the non-node network prefix information through the ABR device respectively, the target device can more efficiently and accurately generate the source address verification entry, and in the case of network topology change, including link cost adjustment or link failure, the target device only needs to perform path computation update on the node address prefix, without the need to change all subnet routing prefixes, thereby improving the linkage processing performance between the source address verification entry and network change.
[0022] In a second aspect, the present application provides a device for generating a source address verification entry, which is applied to a target device that starts source address verification, and the device includes:
[0023] a first calculation module configured to calculate the reverse shortest path cost of the target device in the LAN1 to each ABR device according to the link topology information of a first local area network (LAN1) and the reverse cost of each link, where the reverse shortest path is a reverse path with the minimum sum of reverse costs of each link;
[0024] The generating module generates a source address verification entry according to the network prefix information and the reverse shortest path cost of the target device to each ABR device when receiving the network prefix information respectively sent by each ABR device, wherein the ABR device is associated with the LAN1 and a second local area network LAN2, the network prefix information includes the address of the ABR device, the source address prefix of the LAN2, the address and address prefix of the source routing device within the LAN2, and the reverse shortest path cost of the ABR device to each source routing device, the source address prefix is connected to one or more source routing devices, and the source address verification entry at least includes the source address prefix and the legal incoming interface corresponding to the source address prefix.
[0025] In a possible design, the generating module is specifically configured to: determine whether the source address prefix of the LAN2 is distributed by multiple ABR devices; if a first source address prefix is distributed by a single ABR device, find the first reverse shortest path cost of the target device to a first target ABR device in the network prefix information, and take the interface corresponding to the first reverse shortest path as the legal incoming interface of the first source address prefix, wherein the first target ABR device is the ABR device distributing the first source address prefix; if a second source address prefix is distributed by multiple ABR devices, calculate the total reverse shortest path cost of the target device to each source routing device connected to the second source address prefix respectively according to the network prefix information, and take the interface corresponding to each total reverse shortest path as the legal incoming interface of the second source address prefix; and generate the source address verification entry based on each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0026] In a possible design, the apparatus further includes: a first generating module, configured to generate a first entry according to node network prefix information when receiving the node network prefix information respectively sent by each ABR device, wherein the node network prefix information includes the address and address prefix of the source routing device within the LAN2, the address of the ABR device, and the reverse shortest cost of the ABR to the source routing device; a second generating module, configured to generate a second entry according to non-node network prefix information when receiving the non-node network prefix information respectively sent by each ABR device, wherein the non-node network prefix information includes the source address prefix connected to the source routing device within the LAN2 and the address of the source routing device; and a combining module, configured to combine the first entry and the second entry to generate the source address verification entry.
[0027] In a possible design, the apparatus is further configured to: determine whether the address prefix of the source routing device in the LAN2 is distributed by multiple ABR devices; if the address prefix of the first source routing device is distributed by a single ABR device, find a second reverse shortest path cost of the target device to a second target ABR device, and take an interface corresponding to the second reverse shortest path as a legal incoming interface of the address prefix of the first source routing device, where the second target ABR device is the ABR device distributing the address prefix of the first source routing device; if the address prefix of the second source routing device is distributed by multiple ABR devices, calculate a total reverse shortest path cost of the target device to the second source routing device according to the reverse shortest path cost of the multiple ABR devices to the second source routing device and the reverse shortest path cost of the target device to the multiple ABR devices, and take an interface corresponding to the total reverse shortest path as a legal incoming interface of the address prefix of the second source routing device; and generate the first table item based on the address prefix of each source routing device and the legal incoming interface corresponding to the address prefix of each source routing device.
[0028] In a possible design, the apparatus is further configured to: determine, from the first table item, a legal incoming interface corresponding to the address of each source routing device in the LAN2 according to the address of each source routing device in the LAN2; take the legal incoming interface corresponding to the address of each source routing device as a legal incoming interface corresponding to the source address prefix connected by each source routing device, and generate a second table item composed of each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0029] The application further provides an apparatus for generating a source address verification table item, which is applied to an ABR device, and includes:
[0030] a second calculation module configured to calculate a reverse shortest path cost of the ABR device to a source routing device in a second LAN according to link topology information of the second LAN and a reverse cost of each link, where the ABR device is associated with the second LAN and a first LAN, and the reverse shortest path is a reverse path with the smallest sum of each reverse cost;
[0031] a distribution module configured to distribute network prefix information to the target device in the first LAN, where the network prefix information includes the address of the ABR device, the source address prefix of the second LAN, the address and address prefix of the source routing device in the second LAN, and the reverse shortest cost of the ABR device to each source routing device.
[0032] In a possible design, the distribution module is further configured to: distribute node network prefix information to the target device in the LAN1, where the node network prefix information includes addresses and address prefixes of source routing devices in the LAN2, an address of the ABR device, and reverse shortest costs of the ABR device to reach the source routing devices in the LAN2; and distribute non-node network prefix information to the target device in the LAN1, where the non-node network prefix information includes a source address prefix of the LAN2 and addresses of source routing devices connected to the source address prefix.
[0033] In a third aspect, the present application provides a network system, which includes: a target device enabled with source address verification, an area border router (ABR) device, and a source routing device, where the target device belongs to a first local area network (LAN1), the ABR device is associated with the LAN1 and a second local area network (LAN2), and the source routing device belongs to the LAN2.
[0034] The target device is configured to: calculate reverse shortest path costs of the target device to reach each ABR device in the LAN1 according to link topology information of the LAN1 and reverse costs of each link, where the reverse shortest path is a reverse path with the minimum sum of reverse costs of each link; and generate a source address verification table item according to the network prefix information and the reverse shortest path costs of the target device to reach each ABR device when receiving network prefix information sent by each ABR device, where the ABR device is associated with the LAN1 and a second local area network (LAN2), the network prefix information includes an address of the ABR device, a source address prefix of the LAN2, addresses and address prefixes of source routing devices in the LAN2, and reverse shortest path costs of the ABR device to reach each source routing device, the source address prefix is connected to one or more source routing devices, and the source address verification table item at least includes the source address prefix and a legal incoming interface corresponding to the source address prefix.
[0035] The ABR device is configured to: calculate reverse shortest path costs of the ABR device to reach source routing devices in the LAN2 according to link topology information of the LAN2 and reverse costs of each link, where the ABR device is associated with the LAN2 and a first local area network (LAN1), and the reverse shortest path is a reverse path with the minimum sum of reverse costs of each link; and distribute network prefix information to the target device in the LAN1, where the network prefix information includes an address of the ABR device, a source address prefix of the LAN2, addresses and address prefixes of source routing devices in the LAN2, and reverse shortest costs of the ABR device to reach each source routing device.
[0036] The source routing device is configured to send a connected source address prefix of the ABR device and an address and address prefix of the source routing device to the ABR device.
[0037] In a possible design of the target device, the target device is further configured to determine whether the source address prefixes of the LAN2 are distributed by a plurality of ABR devices; if a first source address prefix is distributed by a single ABR device, find, in the network prefix information, a first reverse shortest path cost of the target device to a first target ABR device, and take an interface corresponding to the first reverse shortest path as a legal ingress interface of the first source address prefix, where the first target ABR device is the ABR device distributing the first source address prefix; if a second source address prefix is distributed by a plurality of ABR devices, calculate, according to the network prefix information, total reverse shortest path costs of the target device to respective source routing devices connected to the second source address prefix, and take interfaces corresponding to the respective total reverse shortest paths as legal ingress interfaces of the second source address prefix; and generate, based on the respective source address prefixes and the legal ingress interfaces corresponding to the respective source address prefixes, the source address verification table item.
[0038] In a possible design of the target device, the target device is further configured to, when receiving node network prefix information respectively sent by the respective ABR devices, generate a first table item according to the node network prefix information, where the node network prefix information includes an address and address prefix of a source routing device in the LAN2, an address of the ABR device, and a reverse shortest cost of the ABR device to the source routing device; when receiving non-node network prefix information respectively sent by the respective ABR devices, generate a second table item according to the non-node network prefix information, where the non-node network prefix information includes a source address prefix connected by the source routing device in the LAN2 and an address of the source routing device; and combine the first table item and the second table item to generate the source address verification table item.
[0039] In a possible design, the target device is further configured to determine whether the address prefix of the source routing device in the LAN2 is distributed by multiple ABR devices; if the address prefix of the first source routing device is distributed by a single ABR device, find a second reverse shortest path cost of the target device to a second target ABR device, and take an interface corresponding to the second reverse shortest path as a legal incoming interface of the address prefix of the first source routing device, where the second target ABR device is the ABR device distributing the address prefix of the first source routing device; if the address prefix of the second source routing device is distributed by multiple ABR devices, calculate a total reverse shortest path cost of the target device to the second source routing device according to the reverse shortest path costs of the multiple ABR devices to the second source routing device and the reverse shortest path costs of the target device to the multiple ABR devices, and take an interface corresponding to the total reverse shortest path as a legal incoming interface of the address prefix of the second source routing device; and generate the first table item based on the address prefix of each source routing device and the legal incoming interface corresponding to the address prefix of each source routing device.
[0040] In a possible design, the target device is further configured to determine, from the first table item, a legal incoming interface corresponding to the address of each source routing device in the LAN2 according to the address of each source routing device in the LAN2; take the legal incoming interface corresponding to the address of each source routing device as a legal incoming interface corresponding to a source address prefix connected by each source routing device, and generate a second table item composed of each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0041] In a possible design, the ABR device is further configured to distribute node network prefix information to the target device in the LAN1, where the node network prefix information includes the address and address prefix of the source routing device in the LAN2, the address of the ABR device, and the reverse shortest cost of the ABR device to the source routing device in the LAN2; and distribute non-node network prefix information to the target device in the LAN1, where the non-node network prefix information includes the source address prefix of the LAN2 and the address of the source routing device connected to the source address prefix.
[0042] In a fourth aspect, the present application provides an electronic device, which comprises:
[0043] a memory configured to store a computer program;
[0044] a processor configured to execute the computer program stored in the memory, so as to implement the method steps of generating a source address verification table item.
[0045] In a fifth aspect, the present application provides a computer readable storage medium, wherein a computer program is stored in the computer readable storage medium, and the computer program is executed by a processor to implement the method steps of generating a source address verification entry.
[0046] The technical effects of each of the above-mentioned second to fifth aspects and each aspect that can be achieved are described above in relation to the first aspect or the various possible schemes in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0047] Figure 1 A schematic diagram of a possible application scenario of the present application is shown in the following figure:
[0048] Figure 2 A schematic diagram of a possible application scenario of the present application is shown in the following figure:
[0049] Figure 3 A flowchart of a method for generating a source address verification entry provided by the present application is shown in the following figure:
[0050] Figure 4 A flowchart of a method for generating a source address verification entry provided by the present application is shown in the following figure:
[0051] Figure 5 A schematic diagram of a possible reverse shortest path tree provided by the present application is shown in the following figure:
[0052] Figure 6 A structure diagram of a TLV example provided by the present application is shown in the following figure:
[0053] Figure 7 A schematic diagram of a device for generating a source address verification entry provided by the present application is shown in the following figure:
[0054] Figure 8 A schematic diagram of a device for generating a source address verification entry provided by the present application is shown in the following figure:
[0055] Figure 9 A schematic diagram of the structure of an electronic device provided by the present application is shown in the following figure. DETAILED DESCRIPTION
[0056] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments.
[0057] In the description of the present application, "multiple" is understood as "at least two". The association relationship of "and / or" describing the associated objects means that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist together, and B exists alone. A is connected with B, which can represent: A is directly connected with B and A is connected with B through C. In addition, in the description of the present application, "first", "second", and the like are used only for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor indicating or implying order.
[0058] The following will introduce the application scenarios to which the technical solutions of the embodiments of the present application can be applied. It should be noted that the following introduction of the application scenarios is only for the purpose of understanding the present application, and is not limiting. In the specific implementation process, the technical solutions provided by the embodiments of the present application can be flexibly applied according to actual needs.
[0059] The scheme provided by the embodiments of the present application can be applied to most network scenarios for source address verification, and is especially suitable for network scenarios for cross-local-area-network source address verification.
[0060] As shown in Figure 2 , it is a schematic diagram of an application scenario provided by the embodiments of the present application, in which the scenario can include: local area networks LAN1, LAN3 and LAN4, a target device R1 with an enabled source address verification function, area border router ABR devices R2, R3 and R6, source routing devices R4, R5, R7, R8 and R9, and source address prefixes 100.1.1.0 / 24, 101.1.1.0 / 24, 102.1.1.0 / 24 and 103.1.10 / 24 connected with the source routing devices. The node addresses of the routers R1-R9 are 1.1.1.1 / 32-9.9.9.9 / 32 respectively, and the OSPF protocol is run between these devices.
[0061] It should be noted that Figure 2 the diagram shown is only for illustration, and is not specifically limited in the embodiments of the present application. Of course, the method provided by the embodiments of the present application is not limited to the application scenario shown in Figure 2 , and can also be used in other possible application scenarios, which are not limited by the embodiments of the present application.
[0062] The method provided by the exemplary embodiments of the present application will be described below in combination with the above-described application scenario and with reference to the accompanying drawings. It should be noted that the above-described application scenario is only shown for the purpose of facilitating understanding of the spirit and principles of the present application, and the embodiments of the present application are not limited in this respect.
[0063] Referring to Figure 3As shown in the figure, a flowchart of a method for generating a source address verification entry is provided in the embodiment of the present application. The method is applied to a target device that is enabled for source address verification. The target device is connected to an area border router (ABR) device. The specific implementation procedure of the method is as follows:
[0064] Step 301: According to the link topology information of the first local area network (LAN1) and the reverse cost of each link, the reverse shortest path cost of the target device to each ABR device in LAN1 is calculated.
[0065] In the embodiment of the present application, the reverse shortest path is the reverse path with the minimum sum of the reverse cost of each link.
[0066] Specifically, the link state database information of LAN1 is acquired. With the target device as the root node, the reverse shortest path tree of the target device is calculated according to the link topology information of LAN1 and the reverse cost of each link, i.e., the reverse shortest path cost of the target device to each ABR device.
[0067] For example, the reverse shortest path cost of the target device R1 to the ABR devices R2, R3 and R6 is 10. Figure 2
[0068] Step 302: When the network prefix information sent by each ABR device is received, the source address verification entry is generated according to the network prefix information and the reverse shortest path cost of the target device to each ABR device.
[0069] In the embodiment of the present application, the ABR device is associated with two different local area networks, denoted as the first local area network (LAN1) and the second local area network (LAN2). The network prefix information contains the address of the ABR device that sends the network prefix information, the source address prefix of LAN2, the address and address prefix of the source routing device in LAN2, and the reverse shortest path cost of the ABR device to each source routing device in LAN2. The source address verification entry contains at least the source address prefix and the legal entry corresponding to the source address prefix.
[0070] Specifically, when the target device receives the network prefix information sent by each ABR device, it is determined whether the source address prefix of LAN2 is distributed by multiple ABR devices.
[0071] If the first source address prefix is distributed by a single ABR device, the first reverse shortest path cost of the target device to the first target ABR device is found in the network prefix information. The interface corresponding to the first reverse shortest path is taken as the legal entry of the first source address prefix, wherein the first target ABR device is the ABR device that distributes the first source address prefix.
[0072] For example, as shown in Fig. 1, the source address prefix 103.1.1.0 / 24 is distributed by a single ABR device R6, and the reverse shortest path cost from the target device R1 to the ABR device R6 is found to be 10, so the interface G10 / 2 corresponding to the reverse shortest path is the legal incoming interface of the source address prefix 103.1.1.0 / 24. Figure 2
[0073] If the second source address prefix is distributed by multiple ABR devices, the total reverse shortest path cost from the target device to each source routing device connected to the second source address prefix is calculated according to the network prefix information, specifically, the total reverse shortest path cost = the reverse shortest path cost from the target device to the ABR device + the reverse shortest path cost from the ABR device to the source routing device. Then the interfaces corresponding to the total reverse shortest paths are taken as the legal incoming interfaces of the second source address prefix.
[0074] For example, as shown in Fig. 1, the source address prefix 103.1.1.0 / 24 is distributed by a single ABR device R6, and the reverse shortest path cost from the target device R1 to the ABR device R6 is found to be 10, so the interface G10 / 2 corresponding to the reverse shortest path is the legal incoming interface of the source address prefix 103.1.1.0 / 24. Figure 2
[0075] Based on each source address prefix and the legal incoming interfaces corresponding to each source address prefix, a source address verification table item is generated, and the specific source address verification table item can be as shown in Table 1.
[0076] Source prefix Inbound interface 101.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 2 103.1.1.0 / 24 Gi0 / 2
[0077] Table 1
[0078] Further, the generated source address verification table item can further include the address prefix of each source routing device connected to the source address prefix and the legal incoming interface corresponding to the address prefix of each source routing device.
[0079] Specifically, each source routing device connected by the source address prefix is determined first, and then the total reverse shortest path cost of the target device to each source routing device is calculated, the interface corresponding to the total reverse shortest path cost is taken as the legal incoming interface corresponding to the address prefix of the source routing device, and the legal incoming interface corresponding to the source address prefix connected by the source routing device. At this time, the generated source address verification table item can be as shown in Table 2.
[0080] Prefix Inbound interface 4.4.4.4 / 32 Gi0 / 1 5.5.5.5 / 32 Gi0 / 1 7.7.7.7 / 32 Gi0 / 2 8.8.8.8 / 32 Gi0 / 2 101.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 2 103.1.1.0 / 24 Gi0 / 2
[0081] Table 2
[0082] The above method generates a source address verification table item based on IGP protocol extension by receiving the network prefix information distributed by the ABR device across the local area network, which can realize source address verification across the local area network. Moreover, the network prefix information also carries the address of the source routing device connected by the source address prefix, so that the target device can know which source routing devices distribute the source address prefix, avoid missing possible paths, and thus more accurately determine one or more legal incoming interfaces corresponding to the source address prefix, thereby improving the accuracy and integrity of the generated source address verification table item.
[0083] Based on the above scheme, for the target device, the present embodiment further provides a more optimal implementation manner, and the specific implementation process is as follows:
[0084] When the target device receives the node network prefix information sent by each ABR device respectively, a first table item is generated according to the node network prefix information.
[0085] In the present embodiment, the address prefix of the source routing device is defined as and the node network prefix, and the node network prefix information includes: the address and address prefix of the source routing device in the second local area network LAN2, the address of the ABR device sending the node network prefix information, and the reverse shortest cost of the ABR device to the source routing device in LAN2.
[0086] For example, Figure 2 The R1 receives the node network prefix information sent by R2, R3 and R6 respectively. After receiving the node network prefix information sent by R2, R3 and R6, the R1 stores it, which can be stored in the form of Table 3 as follows.
[0087]
[0088] Table 3
[0089] Specifically, when receiving the node network prefix information sent by each ABR device respectively, it is judged whether the address prefix of the source routing device in the LAN2 associated with the ABR device is distributed by multiple ABR devices.
[0090] If the address prefix of the first source routing device is distributed by a single ABR device, a second reverse shortest path cost of the target device reaching a second target ABR device is found, and an interface corresponding to the second reverse shortest path is taken as a legal incoming interface of the address prefix of the first source routing device, wherein the second target ABR device is the ABR device distributing the address prefix of the first source routing device.
[0091] For example Figure 2 In the example shown in FIG. 4, the address prefix 7.7.7.7 / 32 of R7 in LAN4 is only distributed by R6, a reverse shortest path cost of the target device R1 reaching the ABR device R6 is found to be 10, and an interface corresponding to the reverse shortest path with the cost of 10 is taken as a legal incoming interface of the address prefix 7.7.7.7 / 32 of R7.
[0092] If the address prefix of the second source routing device is distributed by multiple ABR devices, a total reverse shortest path cost of the target device reaching the second source routing device is calculated according to reverse shortest path costs of the multiple ABR devices respectively reaching the second source routing device and reverse shortest path costs of the target device reaching the multiple ABR devices, and an interface corresponding to the total reverse shortest path is taken as a legal incoming interface of the address prefix of the second source routing device.
[0093] For example, Figure 2 In the example shown in FIG. 4, the address prefix of R4 and R5 in LAN3 is distributed by the ABR devices R2 and R3, a total reverse shortest path of R1 reaching R4 is calculated to be R4->R3->R1 with a cost of 30, an interface corresponding to R4->R3->R1 is Gi0 / 1, and thus the legal incoming interface corresponding to the address prefix 4.4.4.4 / 32 of R4 is Gi0 / 1; a total reverse shortest path of R1 reaching R5 is R5->R4->R3->R1 with a cost of 50, an interface corresponding to R5->R4->R3->R1 is Gi0 / 1, and thus the legal incoming interface corresponding to the address prefix 5.5.5.5 / 32 of R5 is Gi0 / 1.
[0094] Based on the address prefix of each source routing device and the legal incoming interface corresponding to the address prefix of each source routing device, a first table item is generated. Specifically, the first table item can be in the form of Table 4 below.
[0095] Prefix Inbound interface 4.4.4.4 / 32 Gi0 / 1 5.5.5.5 / 32 Gi0 / 1 7.7.7.7 / 32 Gi0 / 2 8.8.8.8 / 32 Gi0 / 2
[0096] Table 4
[0097] When the target device receives the non-node network prefix information respectively sent by each ABR device, a second table item is generated according to the non-node network prefix information.
[0098] In the embodiment of the present application, the source address prefix of the source routing device connection is defined as a non-node network prefix, and the non-node network prefix information includes the source address prefix of the source routing device connection in the second local area network LAN2 and the address of the source routing device in the LAN2.
[0099] Specifically, according to the address of the source routing device in the LAN2, the legal incoming interface corresponding to the address of the source routing device in the LAN2 is determined from the generated first table item. The legal incoming interface corresponding to each source routing device is taken as the legal incoming interface corresponding to the source address prefix of each source routing device connection, and a second table item composed of each source address prefix and the legal incoming interface corresponding to each source address prefix is generated. Specifically, the second table item can be expressed in the form of Table 5 below.
[0100] Prefix Inbound interface 101.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 2 103.1.1.0 / 24 Gi0 / 2
[0101] Table 5
[0102] The first table item and the second table item are combined to generate a source address verification table item. The source address verification table item is expressed in the form of Table 6 below.
[0103] Prefix Inbound interface 4.4.4.4 / 32 Gi0 / 1 5.5.5.5 / 32 Gi0 / 1 7.7.7.7 / 32 Gi0 / 2 8.8.8.8 / 32 Gi0 / 2 101.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 2 103.1.1.0 / 24 Gi0 / 2
[0104] Table 6
[0105] Through the above-mentioned optimized implementation scheme, the source address verification table item can be generated more efficiently and accurately. In the case of network topology changes, including link cost adjustment or link failure, only the node address prefix needs to be updated by path calculation, and no changes need to be made to all subnet routing prefixes, thereby improving the linkage processing performance between the source address verification table item and network changes.
[0106] For example, as shown in Figure 2 When the link between R3 and R4 is disconnected, only the following convergence calculation needs to be performed on R3 using the optimized scheme:
[0107] 1. R3 takes itself as the root node, and calculates the reverse shortest path tree using the link topology information and the reverse cost of the link;
[0108] 2. R3 sends the updated node network prefix information to R1: 4.4.4.4 / 32, whose reverse shortest path cost is updated to 110; and 5.5.5.5 / 32, whose reverse shortest path cost is updated to 90.
[0109] When R1 receives the updated node network prefix information sent by R3, it triggers the update of the first entry of the node network prefix: <4.4.4.4 / 32, Gi0 / 0>, <5.5.5.5 / 32, Gi0 / 1>, that is, the valid inbound interface corresponding to the node network prefix 4.4.4.4 / 32 is updated to Gi0 / 0.
[0110] Then, R1 updates and iterates to the second entry of the non-node network prefix based on the node network prefix entry <4.4.4.4 / 32, Gi0 / 0>, that is, it updates the valid inbound interfaces of the non-node network prefixes 101.1.1.0 / 24 and 102.1.1.0 / 24. The updated second entry of the non-node network prefix on the R1 device is shown in Table 7 below:
[0111] Prefix Inbound interface 101.1.1.0 / 24 Gi0 / 0 101.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 0 102.1.1.0 / 24 Gi0 / 1 102.1.1.0 / 24 Gi0 / 2 103.1.1.0 / 24 Gi0 / 2
[0112] Table 7
[0113] See Figure 4 The diagram shown is a flowchart illustrating a method for generating source address verification entries according to an embodiment of this application. This method is applied to an Area Boundary Router (ABR) device, which is connected to a target device that has source address verification enabled. The specific implementation flow of this method is as follows:
[0114] Step 401: Based on the link topology information of the second local area network LAN2 and the reverse cost of each link, calculate the reverse shortest path cost from the ABR device to the source routing device in LAN2.
[0115] Specifically, the link state information database of the second local area network LAN2 associated with the ABR device is obtained. Based on the link topology information and the reverse cost of each link, the reverse shortest path tree with the ABR device as the root node is calculated, and the reverse shortest path cost from the ABR device to the source routing device in LAN2 is determined.
[0116] For example Figure 5 As shown, Figure 2 The shortest path tree in LAN3 with R2 as the root node is shown. The shortest path cost from R2 to the source routing device R4 is 100, and the shortest path cost from R2 to the source routing device R5 is 120.
[0117] Step 402: Distribute network prefix information to target devices within LAN1;
[0118] In the embodiment of the present application, the network prefix information comprises: the address of the ABR device sending the network prefix information, the source address prefix of the LAN2, the address and address prefix of the source routing device within the LAN2, and the reverse shortest cost of the ABR device to each source routing device within the LAN2. The address of the source routing device and the reverse shortest cost of the ABR device to the source routing device can be sent in the form of <address of the source routing device, reverse shortest cost of the ABR device to the source routing device>.
[0119] Specifically, the ABR device sends the source address prefix of the associated second local area network to the target device of the first local area network through a Summary LSA (Link State Advertisement Summary), and carries the address of the ABR device, the address and address prefix of the source routing device, and the reverse shortest cost of the ABR device to the source routing device on the distribution of the Summary LSA extension. The address of the source routing device and the reverse shortest cost of the ABR device to the source routing device can be in the form of TLV. Figure 6
[0120] By distributing the network prefix information to the target device across the local area network through the ABR device, the target device can generate a source address verification table item according to the network prefix information and the IGP protocol extension, and the source address verification table item can realize the source address verification across the local area network. In addition, the address of the source routing device connected to the source address prefix is also carried in the network prefix information, so that the target device can know which source routing devices distribute the source address prefix, avoid missing possible paths, and more accurately determine one or more legal ingress interfaces corresponding to the source address prefix, thereby improving the accuracy and integrity of generating the source address verification table item.
[0121] Based on the above method, for the ABR device, the present application further provides a more optimal implementation manner, and the specific process is as follows:
[0122] Step 4021: Distribute node network prefix information to the target device within the LAN1.
[0123] In the embodiment of the present application, the address prefix of the source routing device is defined as and the node network prefix, and the node network prefix information comprises: the address and address prefix of the source routing device within the LAN2, the address of the ABR device, and the reverse shortest path cost of the ABR device to each source routing device within the LAN2.
[0124] Specifically, the ABR device sends the node network prefix in LAN2 to the target device in LAN1 through the Summary LSA, and carries the address of the source routing device, the address of the ABR device, and the reverse shortest path cost of the ABR device to the source routing device in the extension of the distributed Summary LSA.
[0125] For example, Figure 2 In the embodiment, the ABR devices R2, R3 and R6 distribute the node network prefix information to R1 respectively. The node network prefix information sent by R2 can be as shown in Table 8 below.
[0126]
[0127] The node network prefix information sent by R3 can be as shown in Table 9 below.
[0128]
[0129] The node network prefix information sent by R6 can be as shown in Table 10 below.
[0130]
[0131] Table 10
[0132] Step 4022: distribute the non-node network prefix information to the target device in LAN1;
[0133] In the embodiment, the non-node network prefix information includes the source address prefix of LAN2 and the address of the source routing device connected to the source address prefix.
[0134] The address of the source routing device in LAN2 and the source address prefix connected by the source routing device in LAN2.
[0135] Specifically, the ABR device distributes the associated source address prefix of LAN2 to the target device in LAN1 through the Summary LSA, and carries the address of the source routing device connected to the source address prefix in the extension of the distributed Summary LSA.
[0136] For example, Figure 2 In the embodiment, the non-node network prefix information distributed by R2 to R1 can be as shown in Table 11 below.
[0137]
[0138] Table 11
[0139] The node network prefix information and the non-node network prefix information are respectively sent by the ABR device, so that the target device can generate the source address verification table item more efficiently and accurately, and in the case of network topology change, including link cost adjustment or link fault, the target device only needs to update the node address prefix, without changing all subnet routing prefixes, thereby improving the linkage processing performance between the source address verification table item and network change.
[0140] Based on the same inventive concept, the application further provides a device for generating a source address verification table item, which is applied to a target device for starting source address verification, and the device comprises Figure 7 , and the device further comprises:
[0141] A first calculation module 701 is configured to calculate a reverse shortest path cost from the target device to each ABR device in the first local area network LAN1 according to link topology information of the LAN1 and a reverse cost of each link, wherein the reverse shortest path is a reverse path with the minimum sum of reverse costs of each link.
[0142] A generation module 702 is configured to generate a source address verification table item according to network prefix information sent by each ABR device and the reverse shortest path cost from the target device to each ABR device when the network prefix information is received, wherein the ABR device is associated with the LAN1 and a second local area network LAN2, the network prefix information includes an address of the ABR device, a source address prefix of the LAN2, an address and an address prefix of a source routing device in the LAN2, and a reverse shortest path cost from the ABR device to each source routing device, the source address prefix is connected to one or more source routing devices, and the source address verification table item at least includes the source address prefix and a legal incoming interface corresponding to the source address prefix.
[0143] In a possible design, the generating module 702, in particular, is configured to: determine whether a source address prefix of the LAN2 is distributed by a plurality of ABR devices; if a first source address prefix is distributed by a single ABR device, find, in the network prefix information, a first reverse shortest path cost of the target device to a first target ABR device, and take an interface corresponding to the first reverse shortest path cost as a legal incoming interface of the first source address prefix, where the first target ABR device is the ABR device distributing the first source address prefix; if a second source address prefix is distributed by a plurality of ABR devices, calculate, according to the network prefix information, total reverse shortest path costs of the target device to respective source routing devices connected to the second source address prefix, and take interfaces corresponding to the respective total reverse shortest path costs as legal incoming interfaces of the second source address prefix; and generate, based on the respective source address prefixes and the legal incoming interfaces corresponding to the respective source address prefixes, the source address verification table item.
[0144] In a possible design, the apparatus is further configured to: generate, according to node network prefix information received from respective ABR devices, a first table item, where the node network prefix information includes addresses and address prefixes of source routing devices in the LAN2, addresses of the ABR devices, and reverse shortest costs of the ABR devices to the source routing devices; generate, according to non-node network prefix information received from respective ABR devices, a second table item, where the non-node network prefix information includes source address prefixes connected to source routing devices in the LAN2 and addresses of the source routing devices; and combine the first table item and the second table item to generate the source address verification table item.
[0145] In a possible design, the apparatus is further configured to: determine whether the address prefix of the source routing device in the LAN2 is distributed by multiple ABR devices; if the address prefix of the first source routing device is distributed by a single ABR device, find a second reverse shortest path cost of the target device to a second target ABR device, and take an interface corresponding to the second reverse shortest path cost as a legal ingress interface of the address prefix of the first source routing device, where the second target ABR device is the ABR device distributing the address prefix of the first source routing device; if the address prefix of the second source routing device is distributed by multiple ABR devices, calculate a total reverse shortest path cost of the target device to the second source routing device according to the reverse shortest path cost of the multiple ABR devices to the second source routing device and the reverse shortest path cost of the target device to the multiple ABR devices, and take an interface corresponding to the total reverse shortest path cost as a legal ingress interface of the address prefix of the second source routing device; and generate the first table item based on the address prefix of each source routing device and the legal ingress interface corresponding to the address prefix of each source routing device.
[0146] In a possible design, the apparatus is further configured to: determine, from the first table item, a legal ingress interface corresponding to the address of each source routing device in the LAN2 according to the address of each source routing device in the LAN2; take the legal ingress interface corresponding to the address of each source routing device as a legal ingress interface corresponding to a source address prefix connected by each source routing device, and generate a second table item composed of each source address prefix and the legal ingress interface corresponding to each source address prefix.
[0147] The application further provides an apparatus for generating a source address verification table item, which is applied to an ABR device, and the apparatus is shown as Figure 8 , and the apparatus comprises:
[0148] A second calculation module 801 is configured to calculate a reverse shortest path cost of the ABR device to a source routing device in a second local area network (LAN2) according to link topology information of the LAN2 and a reverse cost of each link, where the ABR device is associated with the LAN2 and a first local area network (LAN1), and the reverse shortest path is a reverse path with the smallest sum of each reverse cost.
[0149] A distribution module 802 is configured to distribute network prefix information to the target device in the LAN1, where the network prefix information comprises the address of the ABR device, the source address prefix of the LAN2, the address and address prefix of the source routing device in the LAN2, and the reverse shortest cost of the ABR device to each source routing device.
[0150] In a possible design, the distribution module 802 is further configured to: distribute node network prefix information to the target device in the LAN1, where the node network prefix information includes addresses and address prefixes of source routing devices in the LAN2, an address of the ABR device, and reverse shortest costs of the ABR device to reach the source routing devices in the LAN2; and distribute non-node network prefix information to the target device in the LAN1, where the non-node network prefix information includes a source address prefix of the LAN2 and addresses of source routing devices connected to the source address prefix.
[0151] Based on the same idea, the present application further provides a network system, which includes: a target device that enables source address verification, an area border router (ABR) device, and a source routing device, where the target device belongs to a first local area network (LAN1), the ABR device is associated with the LAN1 and a second local area network (LAN2), and the source routing device belongs to the LAN2.
[0152] The target device is configured to: calculate reverse shortest path costs of the target device to reach each ABR device in the LAN1 according to link topology information of the LAN1 and reverse costs of each link, where the reverse shortest path is a reverse path with the smallest sum of reverse costs of each link; and generate a source address verification table item according to the network prefix information and the reverse shortest path costs of the target device to reach each ABR device when receiving network prefix information sent by each ABR device, where the ABR device is associated with the LAN1 and a second local area network (LAN2), the network prefix information includes an address of the ABR device, a source address prefix of the LAN2, addresses and address prefixes of source routing devices in the LAN2, and reverse shortest path costs of the ABR device to reach each source routing device, the source address prefix is connected to one or more source routing devices, and the source address verification table item at least includes the source address prefix and a legal incoming interface corresponding to the source address prefix.
[0153] The ABR device calculates a reverse shortest path cost of the ABR device to reach a source routing device in the LAN2 according to link topology information of the second local area network LAN2 and a reverse cost of each link, wherein the ABR device is associated with the LAN2 and a first local area network LAN1, and the reverse shortest path is a reverse path with the minimum sum of each reverse cost; and the ABR device distributes network prefix information to the target device in the LAN1, wherein the network prefix information includes an address of the ABR device, a source address prefix of the LAN2, an address and an address prefix of the source routing device in the LAN2, and the reverse shortest cost of the ABR to reach each source routing device.
[0154] The source routing device is configured to send a connected source address prefix and an address and an address prefix of the source routing device to the ABR device.
[0155] In a possible design, the target device is further configured to determine whether the source address prefix of the LAN2 is distributed by a plurality of ABR devices; if a first source address prefix is distributed by a single ABR device, find a first reverse shortest path cost of the target device to reach a first target ABR device in the network prefix information, and take an interface corresponding to the first reverse shortest path as a legal incoming interface of the first source address prefix, wherein the first target ABR device is the ABR device distributing the first source address prefix; if a second source address prefix is distributed by a plurality of ABR devices, calculate total reverse shortest path costs of the target device to respectively reach source routing devices connected to the second source address prefix according to the network prefix information, and take interfaces corresponding to the total reverse shortest path costs as legal incoming interfaces of the second source address prefix; and generate a source address verification table item based on each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0156] In a possible design, the target device is further configured to generate a first table item according to node network prefix information sent by each ABR device when the node network prefix information is received, wherein the node network prefix information includes an address and an address prefix of a source routing device in the LAN2, an address of the ABR device, and a reverse shortest cost of the ABR to reach the source routing device; generate a second table item according to non-node network prefix information sent by each ABR device when the non-node network prefix information is received, wherein the non-node network prefix information includes a connected source address prefix of a source routing device in the LAN2 and an address of the source routing device; and combine the first table item and the second table item to generate the source address verification table item.
[0157] In a possible design, the target device is further configured to determine whether the address prefix of the source routing device in the LAN2 is distributed by a plurality of ABR devices; if the address prefix of the first source routing device is distributed by a single ABR device, find a second reverse shortest path cost of the target device to a second target ABR device, and take an interface corresponding to the second reverse shortest path as a legal incoming interface of the address prefix of the first source routing device, where the second target ABR device is the ABR device distributing the address prefix of the first source routing device; if the address prefix of the second source routing device is distributed by a plurality of ABR devices, calculate a total reverse shortest path cost of the target device to the second source routing device according to the reverse shortest path cost of the plurality of ABR devices to the second source routing device and the reverse shortest path cost of the target device to the plurality of ABR devices, and take an interface corresponding to the total reverse shortest path as a legal incoming interface of the address prefix of the second source routing device; and generate the first table item based on the address prefix of each source routing device and the legal incoming interface corresponding to the address prefix of each source routing device.
[0158] In a possible design, the target device is further configured to determine, from the first table item, a legal incoming interface corresponding to the address of each source routing device in the LAN2 according to the address of each source routing device in the LAN2; take the legal incoming interface corresponding to the address of each source routing device as a legal incoming interface corresponding to a source address prefix connected by each source routing device, and generate a second table item composed of each source address prefix and the legal incoming interface corresponding to each source address prefix.
[0159] In a possible design, the ABR device is further configured to distribute node network prefix information to the target device in the LAN1, where the node network prefix information includes the address and address prefix of the source routing device in the LAN2, the address of the ABR device, and the reverse shortest cost of the ABR device to the source routing device in the LAN2; and distribute non-node network prefix information to the target device in the LAN1, where the non-node network prefix information includes the source address prefix of the LAN2 and the address of the source routing device connected to the source address prefix.
[0160] Based on the same inventive concept, the embodiment of the present application further provides an electronic device, which can implement the functions of the foregoing source address verification table item generation apparatus, and the functions of the foregoing source address verification table item generation apparatus are implemented by the electronic device. Figure 9 The electronic device includes:
[0161] At least one processor 901 and a memory 902 connected to at least one processor 901. In this embodiment, the specific connection medium between the processor 901 and the memory 902 is not limited. Figure 9 The example shown is the connection between processor 901 and memory 902 via bus 900. Bus 900 is... Figure 9 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The Bus 900 can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 9 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 901 can also be called a controller; there is no restriction on the name.
[0162] In this embodiment, memory 902 stores instructions executable by at least one processor 901. By executing the instructions stored in memory 902, at least one processor 901 can perform the source address verification table generation method described above. Processor 901 can implement... Figure 7 , Figure 8 The functions of each module in the device shown.
[0163] The processor 901 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 902 and calling data stored in memory 902, the processor can monitor the device as a whole by performing various functions and processing data.
[0164] In one possible design, processor 901 may include one or more processing units. Processor 901 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 901. In some embodiments, processor 901 and memory 902 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.
[0165] Processor 901 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method for generating source address verification entries disclosed in the embodiments of this application can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.
[0166] The memory 902, as a non-volatile computer readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 902 can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. The memory 902 is any other medium capable of carrying or storing desired program codes in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto. The memory 902 in the embodiments of the present application can also be a circuit or any other device capable of realizing a storage function, used for storing program instructions and / or data.
[0167] By designing and programming the processor 901, the code corresponding to the method for generating a source address verification table item introduced in the foregoing embodiments can be fixed into the chip, so that the chip can execute the steps of the method for generating a source address verification table item of the embodiments shown in the foregoing embodiments at runtime. How to design and program the processor 901 is a technology known to those skilled in the art, and will not be described here. Figure 3 、 Figure 4 By designing and programming the processor 901, the code corresponding to the method for generating a source address verification table item introduced in the foregoing embodiments can be fixed into the chip, so that the chip can execute the steps of the method for generating a source address verification table item of the embodiments shown in the foregoing embodiments at runtime. How to design and program the processor 901 is a technology known to those skilled in the art, and will not be described here.
[0168] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, when the computer instructions run on a computer, the computer instructions make the computer execute the method for generating a source address verification table item discussed above.
[0169] In some possible implementation manners, various aspects of the method for generating a source address verification table item provided by the present application can also be implemented in the form of a program product, which includes program codes, when the program product runs on an apparatus, the program codes are used to make the control device execute the steps in the method for generating a source address verification table item according to various exemplary embodiments of the present application described above in the specification.
[0170] Those skilled in the art will appreciate that embodiments of the present application can be devised for a variety of other systems which are currently developed or later developed. Therefore, the present application is intended to cover all such modifications and variations of this application that are within the scope of the appended claims and their equivalents. It is intended that each element of claim 1 and 2 is independent of one another. No element of claim 1 and 2, or any other claim, is implied to depend on any other element or limitation of claim 1 and 2 or any other claim except where expressly recited in that claim.
[0171] The present application is described in reference to the flowchart and / or block diagram of the method, apparatus (system) and computer program product according to embodiments of the present application. It will be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0172] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0173] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0174] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A method for generating source address verification entries, characterized in that, The method is applied to a target device that enables source address verification, the target device being connected to an Area Border Router (ABR) device, and the method includes: Based on the link topology information of the first local area network LAN1 and the reverse cost of each link, the reverse shortest path cost from the target device to each ABR device within LAN1 is calculated, wherein the reverse shortest path is the reverse path with the smallest sum of the reverse costs of each link. When network prefix information is received from each ABR device, a source address verification entry is generated based on the network prefix information and the reverse shortest path cost from the target device to each ABR device. The ABR device is associated with LAN1 and the second LAN2. The network prefix information includes: the address of the ABR device, the source address prefix of LAN2, the address and address prefix of the source routing devices within LAN2, and the reverse shortest path cost from the ABR device to each source routing device. The source address prefix connects to one or more source routing devices. The source address verification entry includes at least: the source address prefix and the corresponding valid ingress interface.
2. The method as described in claim 1, characterized in that, The step of generating source address verification table entries based on the network prefix information and the reverse shortest path cost from the target device to each ABR device includes: Determine whether the source address prefix of LAN2 is distributed by multiple ABR devices; If the first source address prefix is distributed by a single ABR device, then the first reverse shortest path cost from the target device to the first target ABR device is found in the network prefix information, and the interface corresponding to the first reverse shortest path is taken as the legal ingress interface of the first source address prefix, wherein the first target ABR device is the ABR device that distributes the first source address prefix. If the second source address prefix is distributed by multiple ABR devices, the total reverse shortest path cost from the target device to each source routing device connected to the second source address prefix is calculated based on the network prefix information, and the interface corresponding to each total reverse shortest path is used as the legal inlet interface of the second source address prefix. Based on each source address prefix and the corresponding valid ingress interface, a source address verification entry is generated.
3. The method as described in claim 1, characterized in that, The method further includes: When the node network prefix information sent by each ABR device is received, a first entry is generated based on the node network prefix information. The node network prefix information includes: the address and address prefix of the source routing device in LAN2, the address of the ABR device, and the shortest reverse cost from the ABR to the source routing device. When receiving non-node network prefix information sent by each ABR device, a second entry is generated based on the non-node network prefix information, wherein the non-node network prefix information includes: the source address prefix connected to the source routing device in LAN2 and the address of the source routing device; The first and second entries are combined to generate the source address verification entry.
4. The method as described in claim 3, characterized in that, The step of generating the first entry based on the node network prefix information includes: Determine whether the address prefix of the source routing device within LAN2 is distributed by multiple ABR devices; If the address prefix of the first source routing device is distributed by a single ABR device, then the second reverse shortest path cost from the target device to the second target ABR device is found, and the interface corresponding to the second reverse shortest path is used as the legal inlet interface of the address prefix of the first source routing device, wherein the second target ABR device is the ABR device that distributes the address prefix of the first source routing device; If the address prefix of the second source routing device is distributed by multiple ABR devices, then the total shortest reverse path cost from the target device to the second source routing device is calculated based on the shortest reverse path cost from the multiple ABR devices to the second source routing device and the shortest reverse path cost from the target device to the multiple ABR devices. The interface corresponding to the total shortest reverse path is used as the valid inlet interface of the address prefix of the second source routing device. Based on the address prefixes of each source routing device and the valid inbound interfaces corresponding to the address prefixes of each source routing device, the first entry is generated.
5. The method as described in claim 3, characterized in that, The step of generating the second entry based on the non-node network prefix information includes: Based on the address of the source routing device within LAN2, determine the valid ingress interface corresponding to the address of the source routing device within LAN2 from the first entry; The valid inbound interfaces corresponding to the addresses of each source routing device are used as the valid inbound interfaces corresponding to the source address prefixes connected to each source routing device, and a second entry consisting of each source address prefix and the valid inbound interfaces corresponding to each source address prefix is generated.
6. A method for generating source address verification entries, characterized in that, The method is applied to an Area Border Router (ABR) device, which is connected to a target device that has source address verification enabled. The method includes: Based on the link topology information of the second local area network LAN2 and the reverse cost of each link, the reverse shortest path cost from the ABR device to the source routing device in LAN2 is calculated. The ABR device is associated with LAN2 and the first local area network LAN1. The reverse shortest path is the reverse path with the minimum sum of each reverse cost. Network prefix information is distributed to the target device within LAN1, wherein the network prefix information includes: the address of the ABR device, the source address prefix of LAN2, the address and address prefix of the source routing device within LAN2, and the shortest reverse cost from the ABR to each source routing device.
7. The method as described in claim 6, characterized in that, The distribution of network prefix information to the target device within LAN1 includes: Distribute node network prefix information to the target device within LAN1, wherein the node network prefix information includes: the address and address prefix of the source routing device within LAN2, the address of the ABR device, and the reverse shortest cost from the ABR to the source routing device within LAN2; Distribute non-node network prefix information to the target device within the LAN1, wherein the non-node network prefix information includes: the source address prefix of the LAN2 and the address of the source routing device connected to the source address prefix.
8. A network system, characterized in that, The system includes: a target device with source address verification enabled, an area boundary routing (ABR) device, and a source routing device. The target device belongs to a first local area network (LAN1), the ABR device is associated with LAN1 and a second local area network (LAN2), and the source routing device belongs to LAN2. The target device is configured to calculate the shortest reverse path cost from the target device to each ABR device within LAN1 based on the link topology information of the first local area network LAN1 and the reverse cost of each link, wherein the shortest reverse path is the reverse path with the smallest sum of the reverse costs of each link; when receiving network prefix information sent by each ABR device, it generates a source address verification table entry based on the network prefix information and the shortest reverse path cost from the target device to each ABR device, wherein the ABR device is associated with LAN1 and the second local area network LAN2, the network prefix information includes: the address of the ABR device, the source address prefix of LAN2, the address and address prefix of the source routing device within LAN2, and the shortest reverse path cost from the ABR device to each source routing device, the source address prefix connects one or more source routing devices, and the source address verification table entry includes at least: the source address prefix and the valid ingress interface corresponding to the source address prefix. The ABR device calculates the shortest reverse path cost from the ABR device to the source routing device within LAN2 based on the link topology information of the second LAN2 and the reverse cost of each link. The ABR device associates LAN2 with the first LAN1, and the shortest reverse path is the reverse path with the minimum sum of each reverse cost. The ABR device then distributes network prefix information to the target device within LAN1. This network prefix information includes: the address of the ABR device, the source address prefix of LAN2, the addresses and address prefixes of the source routing devices within LAN2, and the shortest reverse cost from the ABR to each source routing device. The source routing device is used to send the source address prefix of the connection, as well as the address and address prefix of the source routing device, to the ABR device.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method steps of any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-7.
Citation Information
Patent Citations
Routing computing method and network node based on link condition routing protocol
CN101272393A
IP address filtering method and device
CN102158497A
Intra-domain source address verification method and device based on boundary interface equivalence classes
CN111200611A
Source address validation for asymmetric routing
US11882019B1