Stream-following detection method and related equipment
By adding SIOAM protocol headers and node information to traffic data and combining it with NTP synchronization, efficient flow detection in the live network is achieved, solving the problems of high deployment requirements, limited detection scenarios and high overhead, and providing detailed network status monitoring and fault diagnosis.
Patent Information
- Application Number
- CN202511812607.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-01-09
AI Technical Summary
Existing flow detection technologies suffer from high deployment requirements, limited detection scenarios, high performance overhead for packet-by-packet processing, and complex standard packaging designs, making them particularly difficult to promote and use in existing networks with NTP clock synchronization.
By using the SIOAM protocol header to add timestamps and node information to the traffic data, and through the collaborative work of encapsulation nodes, transmission nodes and decapsulation nodes, end-to-end and hop-by-hop detection modes are achieved. Combined with NTP time synchronization, the dependence on high-precision PTP synchronization is reduced, and the detection header encapsulation design is simplified.
It enables flow-based detection even when NTP time synchronization accuracy is low, reducing deployment difficulty and cost, supporting more detection scenarios, reducing per-packet processing overhead, and providing detailed network status monitoring and fault diagnosis functions.
Smart Images

Figure CN121309418A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network technology, and in particular to a flow detection method and related equipment. Background Technology
[0002] With the continuous expansion of internet services and user scale, computer networks are evolving towards large-scale, high-speed, multi-access-point, and unpredictable trends, placing higher demands on network management and control. Network measurement, as a fundamental means of network management, is a crucial way to obtain network operational status data. Common network measurement methods are mainly divided into three categories: active measurement, passive measurement, and hybrid measurement. Active measurement protocols, represented by PING and Traceroute, offer high flexibility but also incur additional bandwidth and processing overhead. Passive measurement protocols (such as IPFIX) monitor through traffic information output, offering the advantage of not increasing the measurement load, but they cannot comprehensively reflect key data such as network status and packet loss rate.
[0003] Although hybrid measurement methods combine the advantages of active and passive measurement and can be used as a means of network measurement, current flow detection based on hybrid measurement methods generally suffers from drawbacks such as high deployment requirements, limited detection scenarios, large performance overhead for packet-by-packet processing, and complex standard encapsulation design. Summary of the Invention
[0004] To address at least one of the aforementioned technical problems, the present invention aims to provide a method and related equipment for in-flow detection.
[0005] On one hand, embodiments of the present invention include a flow-following detection method applied to encapsulated node devices, the flow-following detection method comprising the following steps: Obtain raw traffic data; A SIOAM protocol header is added to the raw traffic data to obtain first forwarded traffic data; the SIOAM protocol header includes the timestamp of the raw traffic data entering the encapsulation node device, and the SIOAM protocol header is used to trigger the first next-hop node to process it. Report the SIOAM protocol header to the network controller; The first forwarding traffic data is sent to the first transmission node device.
[0006] On the other hand, embodiments of the present invention also include a flow-following detection method applied to a first transmission node device, the flow-following detection method comprising the following steps: Receive third forwarding traffic data; the third forwarding traffic data is either the first forwarding traffic data sent by the encapsulated node device, or the second forwarding traffic data sent by the second transmission node device; In response to the SIOAM protocol header in the third forwarded traffic data, the flow detection mode is determined; According to the flow detection mode, the third forwarding traffic data is processed accordingly to obtain the fourth forwarding traffic data; The fourth forwarding traffic data is sent to the next hop node; the next hop node is either the third transmission node device or the decapsulation node device.
[0007] Further, the step of processing the third forwarding traffic data according to the flow detection mode to obtain the fourth forwarding traffic data includes: When the flow detection mode is end-to-end detection mode, the third forwarding traffic data is processed in its original form to obtain the fourth forwarding traffic data.
[0008] Further, the step of processing the third forwarding traffic data according to the flow detection mode to obtain the fourth forwarding traffic data includes: When the flow detection mode is hop-by-hop detection mode, the SIOAM node information corresponding to the first transmission node device is encapsulated into the third forwarding traffic data to obtain the fourth forwarding traffic data; the SIOAM node information includes the timestamp of the third forwarding traffic data entering the first transmission node device, and the node entry and exit information of the first transmission node device. Report the SIOAM protocol header and the SIOAM node information to the network controller.
[0009] On the other hand, embodiments of the present invention also include a flow-following detection method applied to a decapsulation node device, the flow-following detection method comprising: Receive fourth forwarding traffic data from the first transmission node device; Extract the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data; Report the SIOAM protocol header and all SIOAM node information to the network controller; The SIOAM protocol header and all SIOAM node information are deleted from the fourth forwarding traffic data to obtain the fifth forwarding traffic data. Forward the fifth forwarding traffic data.
[0010] On the other hand, embodiments of the present invention also include a flow detection method applied to a network controller, the flow detection method comprising: Receive SIOAM node information uploaded by each node device; the node device includes an encapsulation node device, a first transmission node device, and a decapsulation node device; Perform data analysis based on the SIOAM node information described above; Configure the first transmission node device according to the SIOAM node information.
[0011] Furthermore, the step of performing data analysis based on the information of each SIOAM node includes: Based on the SIOAM node information, the topology is reconstructed to obtain the forwarding topology information; Based on the SIOAM node information, latency statistics are performed to obtain the forwarding latency information between the node devices. The SIOAM node information is sampled to obtain multiple sampled information. The continuity of each sampled information is detected. Based on the continuity detection result, packet loss events are detected.
[0012] Furthermore, the sampling of the SIOAM node information to obtain multiple sampling information includes: The data traffic volume is determined based on the SIOAM node information described above; The sampling ratio is determined in a positive correlation with the data flow rate. Based on the sampling ratio, a corresponding number of SIOAM node information are randomly sampled as the sampling information.
[0013] Further, configuring the first transmission node device according to the SIOAM node information includes: Before detecting the packet loss event, the following detection mode of the first transmission node device is configured as end-to-end detection mode; When the packet loss event is detected, the flow detection mode is configured as a hop-by-hop detection mode.
[0014] On the other hand, embodiments of the present invention also include a communication network, the communication network comprising: A packaging node device is added; the packaging node device is used to perform the in-flow detection method in Embodiment 2; A first transmission node device; the first transmission node device is used to execute the flow detection method described in Embodiment 3; Decapsulation node device; the decapsulation node device is used to execute the flow detection method in Embodiment 4; Network controller; the network controller is used to execute the flow detection method in Embodiment 5; A time synchronization module; the time synchronization module performs time synchronization on the encapsulation node device, the first transmission node device, and the decapsulation node device via NTP or PTP.
[0015] The beneficial effects of the embodiments of the present invention are as follows: The communication network and the flow detection method executed in the embodiments realize SIOAM from flow detection packet encapsulation, detection information reporting, to the controller realizing the parsing and restoration of the actual forwarding path of the traffic, as well as packet loss alarm and delay alarm location diagnosis functions. Even when the communication network is time synchronized by NTP and the time synchronization accuracy is not high, the effect of flow detection fault diagnosis can still be achieved, thereby reducing the necessity of applying time synchronization technologies with higher costs such as PTP, and significantly reducing the deployment difficulty of flow detection. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of a communication network in the embodiment where the flow detection method can be applied; Figure 2 This is a schematic diagram of the steps of the flow detection method applied to the encapsulated node device in the embodiment; Figure 3 This is a schematic diagram of the SIOAM protocol header structure in the embodiment; Figure 4 This is a schematic diagram of the steps of the flow detection method applied to the first transmission node device in the embodiment; Figure 5 This is a schematic diagram illustrating the first transmission node device performing end-to-end detection mode in the embodiment; Figure 6 This is a schematic diagram of the third forwarding traffic data in the embodiment; Figure 7 This is a schematic diagram of the structure of the SIOAM protocol header and the added SIOAM node information in the embodiment; Figure 8 This is a schematic diagram illustrating the data forwarding process performed by the first transmission node device in the hop-by-hop detection mode in the embodiment. Figure 9 This is a schematic diagram of the first transmission node device in the embodiment performing the hop-by-hop detection mode to upload the SIOAM protocol header or SIOAM node information. Figure 10 This is a schematic diagram of the steps of the flow detection method applied to the decapsulation node device in the embodiment; Figure 11 This is a schematic diagram of the steps of the flow detection method applied to the network controller in the embodiment. Detailed Implementation
[0017] Terminology Explanation: IOAM: In-situ Operations, Administration, and Maintenance, is a network traffic monitoring technology that samples service traffic in real time and embeds OAM information (metadata such as device ID, timestamp, ingress / egress interface, etc.) directly into data packets. This enables real-time perception and measurement of network operating status (such as path and latency). It is a hybrid measurement method that combines the advantages of active and passive measurement, and can provide hop-by-hop, fine-grained network performance data for path verification and performance monitoring. NTP: Network Time Protocol, is an application layer protocol belonging to the TCP / IP protocol suite. It is used to synchronize clocks between distributed time servers and clients. It is based on IP and UDP, uses port 123 for transmission, and calculates time offset and network latency by exchanging timestamped messages between network devices. It achieves time synchronization with millisecond to tens of millisecond precision and is widely used in network management and application systems that require time consistency. PTP: Precision Time Protocol, is a high-precision time synchronization protocol primarily used within local area networks (LANs). Its standard is IEEE 1588. It aims to provide sub-microsecond clock synchronization accuracy for devices in the network. Through hardware timestamps and a master-slave clock hierarchy, it significantly reduces the uncertainty caused by software and network latency. It is commonly used in telecommunications, industrial automation, financial transactions, and other fields with extreme timing requirements. PTP's time synchronization accuracy (sub-microsecond level) is significantly higher than NTP's (millisecond to tens of millisecond levels), but PTP's implementation cost is also higher than NTP. Telemetry is a technology for remotely and rapidly acquiring data from physical or virtual devices. In this technology, the data source periodically and proactively sends data to the data destination in push mode, achieving more real-time and efficient data acquisition compared to the traditional pull mode. It can meet the high operational requirements of large-scale software-defined networking (SDN) and cloud environments, providing sub-second-level monitoring data to promptly detect and adjust network status while minimizing the impact on device performance.
[0018] IOAM (In-band Operation, Administration, and Maintenance) is a network measurement and monitoring technology. It samples service traffic in real-time and efficiently, embedding IOAM information into data packets. It proactively sends the collected data to an analyzer, thereby achieving real-time monitoring and awareness of network operational status. Current technology has the following problems: IOAM (In-band Operation, Administration, and Maintenance) is a typical network measurement and monitoring technology based on hybrid measurement methods. Therefore, IOAM faces typical problems inherent in network measurement and monitoring technologies based on hybrid measurement methods. IOAM mainly faces the following problems: High deployment requirements: IOAM flow detection technology solutions often require PTP high-precision clock synchronization to achieve latency measurement and forwarding path reconstruction. Currently, most networks only have NTP clock synchronization, making it difficult to promote and use flow detection. Limited detection scenarios: Most current IOAM detection solutions are implemented by inserting IOAM detection headers into MPLS or Srv6 protocol headers, thus limiting the detection scenarios to MPLS and Srv6 scenarios. Packet-by-packet processing incurs significant performance overhead: the mainstream approach encapsulates all matching traffic packets with IOAM and uses alternating coloring to count the number of packets; The standard package design is complex: In order to cope with different testing purposes, the standard IOAM package header has many and complex fields, resulting in a relatively large testing header.
[0019] Based on the above principles, a flow-following detection method and related equipment are proposed.
[0020] Example 1 In this embodiment, the in-flow detection method can be applied to... Figure 1 In the communication network shown. (Refer to...) Figure 1 The communication network includes devices such as encapsulation node devices, transmission node devices (one or more), decapsulation node devices, and a network controller. The communication network connects server host 1 and server host 2, where server host 1 is the data source and server host 2 is the data destination; that is, server host 1 sends data to server host 2, and this data can specifically be a data stream composed of multiple data packets. The communication network is used to receive data sent by server host 1 and forward this data to server host 2, thereby completing the data transmission from server host 1 to server host 2.
[0021] Specifically, refer to Figure 1The data sent by server host 1 is raw traffic data. This raw traffic data is first received by the encapsulation node device in the communication network. The encapsulation node device performs initial processing and forwards it to the next hop, which is one of the transmission node devices (specifically, a particular transmission node device, i.e., the first transmission node device). The first transmission node device processes the data forwarded by the encapsulation node device and forwards it to the next hop. Depending on the transmission link, the next hop of the first transmission node device may be another transmission node device (e.g., a third first transmission node device), thus forwarding data between multiple transmission node devices. Alternatively, it may be a decapsulation node device, which is the node device on the link closest to the data destination, i.e., server host 2. Since the processing and forwarding processes performed by other transmission node devices are the same as those of the first transmission node device, taking the decapsulation node device as the next hop of the first transmission node device as an example, after receiving the data sent by the first transmission node device, the decapsulation node device decapsulates the data, thereby eliminating the influence of the previous processing by the encapsulation node device and the first transmission node device, restoring the raw traffic data sent by server host 1, and then sending the raw traffic data to server host 2, completing the transmission process of the raw traffic data.
[0022] In this embodiment, the encapsulation node device, transmission node device, and decapsulation node device can report their processing results of the forwarded data to the network controller. The network controller processes the information reported by each node device, thereby realizing flow detection of the communication network. Specifically, during the transmission of raw traffic data, the encapsulation node device, transmission node device, decapsulation node device, and network controller each execute some steps of their own flow detection method, thereby realizing the forwarding and flow detection processing of raw traffic data.
[0023] In this embodiment, the entire communication network synchronizes the encapsulation node device, the first transmission node device, and the decapsulation node device through a time synchronization module. Specifically, the time synchronization module synchronizes the time of each node device using either NTP or PTP. Both NTP and PTP can maintain time synchronization among the node devices, ensuring that each node device keeps a unified time. This gives each node device a unified time reference for the timestamps added to the data it forwards and the information reported to the network controller, while PTP can achieve higher time synchronization accuracy than NTP.
[0024] Since PTP is generally more expensive to implement than NTP for the same network size, and some networks have not yet adopted PTP but are still using NTP on a large scale for cost reasons, each embodiment uses the example of the time synchronization module synchronizing the time of each node device through NTP to illustrate the effect of reducing the deployment difficulty and cost of flow detection and meeting the fault diagnosis needs of the existing network, even when the time synchronization accuracy is not high when using NTP.
[0025] Because PTP has the advantage of high time synchronization accuracy, under the same implementation conditions, when the time synchronization module performs time synchronization on each node device through PTP, each embodiment can achieve the same or better technical effect.
[0026] Example 2 In this embodiment, for the... Figure 1 The steps of the flow detection method performed by the encapsulated node device in the communication network shown are explained.
[0027] In this embodiment, by Figure 1 The flow detection method performed by the encapsulated node device in the communication network shown is as follows: Figure 2 As shown, it includes the following steps: S1A. Obtain raw traffic data; S2A. Adds a SIOAM protocol header to the raw traffic data to obtain the first forwarding traffic data; S3A. Reports the SIOAM protocol header to the network controller; S4A. Send the first forwarding traffic data to the first transmission node device.
[0028] In step S1A, the encapsulation node device receives the raw traffic data sent by server host 1. The raw traffic data specifically includes one or more data packets.
[0029] In this embodiment, the encapsulation node device can trigger the execution of steps S1A-S4A when a specific triggering condition is detected. Specifically, the triggering condition can be "the original traffic data hits the feature in the flow detection configuration information and is sampled by the encapsulation node device". The flow detection configuration information can be configured by the network controller to enable the encapsulation node device to filter and perform flow detection on the original traffic data with specific features.
[0030] In step S2A, the encapsulation node device generates a SIOAM protocol header and adds the SIOAM protocol header to the raw traffic data. In this embodiment, the structure of the SIOAM protocol header is as follows: Figure 3 As shown. (Refer to...) Figure 3The protocol header contains information such as the flow identifier, flow 5-tuple characteristics (IP mask, port, protocol number, DSCP, etc. of the original destination of the traffic), sequence ID, and the timestamp of the original traffic data entering the encapsulation node device (obtained by the encapsulation node device under time synchronization by the time synchronization module).
[0031] In step S2A, the raw traffic data with the SIOAM protocol header added becomes the first forwarded traffic data.
[0032] In step S3A, the encapsulated node device can report the SIOAM protocol header it added in step S2A to the network controller via Telemetry.
[0033] In step S4A, the encapsulation node device sends the first forwarding traffic data obtained in step S2A to the first transmission node device. The first forwarding traffic data received by the first transmission node device includes both the original traffic data and the SIOAM protocol header pushed in by the encapsulation node device.
[0034] In this embodiment, by having the encapsulation node device execute steps S1A-S4A, the first forwarded traffic data being forwarded to the first transmission node device can include a SIOAM protocol header. On one hand, the SIOAM protocol header contains the detection flow information added by the encapsulation node device, thereby enabling the accumulation of detection flow information in the forwarded data. On the other hand, the SIOAM protocol header can also trigger the first transmission node device to execute the steps of the flow detection method it intends to perform.
[0035] Example 3 In this embodiment, the steps of the flow detection method performed by the first transmission node device are described.
[0036] In this embodiment, the flow detection method performed by the first transmission node device is as follows: Figure 4 As shown, it includes the following steps: S1B. Receives third-party forwarding traffic data; S2B. In response to the SIOAM protocol header in the third forwarded traffic data, determines the flow detection mode; S3B. Based on the flow detection mode, the third forwarding traffic data is processed accordingly to obtain the fourth forwarding traffic data; S4B. Send the fourth forwarding traffic data to the next hop node.
[0037] In this embodiment, the first transmission node device is any transmission node device located between the encapsulation node device and the decapsulation node device in the communication network. If there are multiple transmission node devices in the link between the encapsulation node device and the decapsulation node device, and the first transmission node device is not the next-hop node of the encapsulation node device (for example, the next-hop node of the encapsulation node device is another transmission node device, namely the second transmission node device, and the next-hop node of the second transmission node device is the first transmission node device), then when executing step S1B, the first transmission node device receives the forwarded data (second forwarded traffic data) from its previous hop transmission node device (the second transmission node device) as the third forwarded traffic data.
[0038] In this embodiment, Figure 1 Taking the communication network shown as an example, it includes only one transmission node device, namely the first transmission node device. At this time, the first forwarding traffic data forwarded by the encapsulated node device is the third forwarding traffic data received by the first transmission node device when it executes step S1B.
[0039] After receiving the third forwarding traffic data, the first transmission node device checks whether the third forwarding traffic data contains the SIOAM protocol header added by the encapsulation node device. If the SIOAM protocol header is detected, steps S2B-S4B are triggered.
[0040] In step S2B, the first transmission node device determines the flow detection mode under the triggering of the SIOAM protocol header in the third forwarded traffic data.
[0041] Specifically, the network controller can configure the first transmission node device to determine the flow detection mode executed by the first transmission node device when performing steps S2B-S4B.
[0042] In this embodiment, the flow detection modes that the first transmission node device can execute include end-to-end detection mode and hop-by-hop detection mode, that is, the network controller can control the first transmission node device to execute either end-to-end detection mode or hop-by-hop detection mode.
[0043] In this embodiment, when the network controller controls the first transmission node device to execute the end-to-end detection mode, the first transmission node device executes step S3B, which is to process the third forwarding traffic data according to the flow detection mode to obtain the fourth forwarding traffic data. In this step, the third forwarding traffic data is processed in its original form to obtain the fourth forwarding traffic data.
[0044] Specifically, the network controller performs unprocessing of the third forwarding traffic data in end-to-end detection mode, which is equivalent to not processing the third forwarding traffic data at all. The third forwarding traffic data is used as the fourth forwarding traffic data; that is, the fourth forwarding traffic data obtained at this time is the third forwarding traffic data itself. In step S5B, the first transmission node device forwards the fourth forwarding traffic data to the next-hop node. Specifically, the next-hop node of the first transmission node device is another transmission node device (the third transmission node device) or a decapsulation node device. For example, Figure 1 In the communication network shown, the next-hop node of the first transmission node device is the decapsulation node device. Therefore, in step S5B, the first transmission node device forwards the fourth forwarding traffic data to the decapsulation node device.
[0045] Specifically, when the network controller controls the first transmission node device to execute end-to-end detection mode, the effect is as follows: Figure 5 As shown. (Refer to...) Figure 5 Since the first transmission node device processes the third forwarding traffic data in its original form, it is equivalent to not processing the third forwarding traffic data at all, and directly forwarding it as the fourth forwarding traffic data to the next hop node (decapsulation node device). Therefore, the first transmission node device is equivalent to a transparent node.
[0046] In this embodiment, when the network controller controls the first transmission node device to execute the hop-by-hop detection mode, and the first transmission node device executes step S3B, that is, according to the flow-following detection mode, to process the third forwarding traffic data and obtain the fourth forwarding traffic data, the first transmission node device can generate its own corresponding SIOAM node information and push the SIOAM node information into the third forwarding traffic data. The third forwarding traffic data with the SIOAM node information pushed in becomes the fourth forwarding traffic data. That is, the fourth forwarding traffic data includes both the third forwarding traffic data and the SIOAM node information pushed in by the first transmission node device.
[0047] Specifically, the SIOAM node information includes the timestamp of the third-forwarded traffic data entering the first transmission node device, as well as the node ingress and egress interface information of the first transmission node device. When the first transmission node device pushes its corresponding SIOAM node information into the third-forwarded traffic data, it can add the SIOAM node after the SIOAM protocol header in the third-forwarded traffic data. For example, the third-forwarded traffic data may specifically be data under protocols such as TCP, UDP, or Vxlan, and its structure is as follows. Figure 6 As shown, the third forwarding traffic data contains Figure 3 The SIOAM protocol header is shown. After the SIOAM node information is added, as shown... Figure 7 As shown, SIOAMnode list[0] and other information are added after the SIOAM protocol header in the third forwarded traffic data, indicating the SIOAM node information added by the first transmission node device. When the next hop node of the first transmission node device is the third transmission node device or other transmission node devices, other transmission node devices can then add their own SIOAM node information and store it in the SIOAM node list[1] and other positions, thereby realizing the accumulation of SIOAM node information of each transmission node device in the forwarded traffic data.
[0048] In this embodiment, in addition to pushing its own SIOAM node information into the third forwarding traffic data, the first transmission node device also reports its own SIOAM node information along with the SIOAM protocol header to the network controller via Telemetry.
[0049] In this embodiment, when the network controller controls the first transmission node device to execute hop-by-hop detection mode, the first transmission node device processes the received third forwarding traffic data accordingly, causing the third forwarding traffic data to be pushed into its own SIOAM node information to become fourth forwarding traffic data. Therefore, the first transmission node device is not transparent, and its data forwarding process is as follows: Figure 8 As shown. (Refer to...) Figure 8 The fourth forwarding traffic data forwarded by the first transmission node device is pushed into the SIOAM node information (SIOAM MDB) of the first transmission node device relative to the received third forwarding traffic data.
[0050] In this embodiment, when the network controller controls the first transmission node device to execute hop-by-hop detection mode, each node device, including the encapsulation node device, the first transmission node device, and the decapsulation node device, performs processing related to the SIOAM protocol header or SIOAM node information. For example, the encapsulation node device adds the SIOAM protocol header, the first transmission node device adds SIOAM node information, and the decapsulation node device deletes the SIOAM protocol header and SIOAM node information from the data it receives. In this case, refer to... Figure 9Each node device uploads its processed SIOAM protocol header or SIOAM node information to the network controller. For example, the encapsulation node uploads its added SIOAM protocol header to the network controller, the first transmission node uploads its added SIOAM node information to the network controller (since the first transmission node is arbitrary, each transmission node adds its own SIOAM node information, therefore each transmission node uploads its own added SIOAM node information to the network controller), and the decapsulation node uploads its deleted SIOAM node information and other data to the network controller, thus enabling the network controller to obtain the SIOAM protocol header or SIOAM node information processed by each node device.
[0051] In this embodiment, by having the first transmission node device execute steps S1B-S4B, the process of forwarding traffic data by the first transmission node device can be realized by recording the data forwarding process while forwarding, using the added SIOAM node information, thus providing data support for flow detection. Since the first transmission node device is any transmission node device, the execution of steps S1B-S4B by the first transmission node device is actually the execution of steps S1B-S4B by each transmission node device. This allows SIOAM node information to be gradually added to the data packets during the traffic data forwarding process, accumulating SIOAM node information and accurately recording the complete data forwarding process.
[0052] Example 4 In this embodiment, for the... Figure 1 The steps of the flow detection method performed by the decapsulation node device in the communication network shown are explained.
[0053] In this embodiment, the flow detection method performed by the decapsulation node device is as follows: Figure 10 As shown, it includes the following steps: S1C. Receive fourth forwarding traffic data from the first transmission node device; S2C extracts the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data; S3C reports the SIOAM protocol header and all SIOAM node information to the network controller. S4C. Remove the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data to obtain the fifth forwarding traffic data; S5C. Forward the fifth forwarding traffic data.
[0054] In this embodiment, Figure 1Taking the communication network shown as an example, the previous hop of the decapsulation node device is the first transmission node device, and the decapsulation node device is the node device closest to the server host 2 in the communication network. That is, the next hop of the decapsulation node device is the server host 2.
[0055] In step S1C, the first transmission node device sends the fourth forwarding traffic data to the decapsulation node device, and the decapsulation node device receives the fourth forwarding traffic data.
[0056] In step S2C, the decapsulation node device extracts the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data received in step S1C. The SIOAM protocol header is added by the encapsulation node device, and the SIOAM node information is added by each transmission node device that the fourth forwarding traffic data passes through during its forwarding process. For example, Figure 1 In the communication network shown, there is only one transmission node device, namely the first transmission node device. When the decapsulation node device performs step S2C, it can extract the SIOAM protocol header and a SIOAM node information from the fourth forwarding traffic data.
[0057] In step S3C, the decapsulation node device reports the SIOAM protocol header and all SIOAM node information extracted from the fourth forwarding traffic data in step SC2 to the network controller, so that the network controller obtains the SIOAM protocol header and SIOAM node information gradually accumulated by each node device before the decapsulation node device, including the encapsulation node device and the first transmission node device.
[0058] In step S4C, the decapsulation node device removes the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data. The remaining part of the fourth forwarding traffic data after the removal of the SIOAM protocol header and all SIOAM node information becomes the fifth forwarding traffic data.
[0059] Since the fourth forwarding traffic data is obtained by adding the SIOAM protocol header to the original traffic data obtained by the encapsulation node device from the server host 1, and gradually adding the SIOAM node information during the forwarding process of each transmission node device, by executing step S4C, deleting the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data is equivalent to performing the reverse operation of the previous encapsulation node device and each transmission node device, thereby obtaining data that is the same as the original traffic data. That is, the obtained fifth forwarding traffic data is the same as the original traffic data, thereby realizing the recovery of the original traffic data.
[0060] In step S5C, the decapsulation node device forwards the fifth forwarding traffic data to its next hop, which is... Figure 1 Server host 2 in the middle, thus realizing the forwarding of the raw traffic data sent by server host 1 to server host 2.
[0061] In this embodiment, by executing steps S1C-S5C by the decapsulation node device, the original traffic data sent by server host 1 can be forwarded to server host 2, thereby realizing the data forwarding function of the communication network. Moreover, by reporting the SIOAM protocol header and all SIOAM node information to the network controller by the decapsulation node device, the accumulated SIOAM protocol header and all SIOAM node information at each stage of data forwarding can be reported to the network controller.
[0062] Example 5 In this embodiment, for the... Figure 1 The steps of the flow detection method performed by the network controller in the communication network shown are explained.
[0063] In this embodiment, the flow detection method executed by the network controller is as follows: Figure 11 As shown, it includes the following steps: S1D receives SIOAM node information uploaded by each node device; S2D performs data analysis based on the information of each SIOAM node; S3D configures the first transmission node device based on the SIOAM node information.
[0064] The network controller executes step S1D when the encapsulation node device executes step S3A, the first transmission node device executes step S3B, and the decapsulation node device executes step S3C, thereby obtaining the SIOAM node information uploaded by these node devices respectively.
[0065] In step S2D, the network controller performs data analysis based on the information from each SIOAM node. Specifically, when executing step S2D, the network controller can perform the following steps: S201. Perform topology reconstruction based on the information of each SIOAM node to obtain forwarding topology information; S202. Perform latency statistics based on the information of each SIOAM node to obtain the forwarding latency information between each node device; S203. Sample the information of each SIOAM node to obtain multiple sampled information, detect the continuity of each sampled information, and detect packet loss events based on the continuity detection results.
[0066] Step S201 is the topology restoration step. In step S201, since each SIOAM node information contains information such as the node ingress and egress interface information of the node device, as traffic data is forwarded to each node device in sequence, the SIOAM node information obtained by the network controller also accumulates multiple node ingress and egress interface information in sequence. Based on the order of these node ingress and egress interface information, the order in which the traffic data is forwarded by each node device can be determined, thereby obtaining the forwarding topology information and realizing topology restoration.
[0067] In this embodiment, the principle of executing step S201 is as follows: Since each SIOAM node information contains the node ingress and egress interface information of the node device, even if the NTP time synchronization accuracy is low and the order of packet forwarding based on timestamps may be distorted, the network controller can use the node device information contained in each SIOAM node information to incrementally append the node information of the traffic path, thereby directly obtaining the forwarding topology from the packet; moreover, except for the decapsulation node device uploading all SIOAM node information at once, each transmission node device uploads its added SIOAM node information when forwarding traffic data. This allows the network controller to obtain each SIOAM node information in real time. Therefore, the network controller can use its own timestamp to mark the received SIOAM node information. That is, in addition to the timestamp carried by the SIOAM node information itself, the network controller can also determine the forwarding order of each transmission node device based on the timestamp of each SIOAM node information uploaded by each transmission node device in real time, thereby obtaining the forwarding topology information, realizing topology restoration, and compensating for the deficiency of low NTP time synchronization accuracy.
[0068] Step S202 is the latency statistics step. In step S202, the network controller can calculate the forwarding latency of packets between nodes and the end-to-end latency from the encapsulation node to the decapsulation node based on the timestamps contained in the SIOAM node information it receives. Due to the NTP clock synchronization accuracy issue, the upper-layer controller only needs to calculate the absolute value of the timestamp difference between two nodes; microsecond-level latency can be ignored.
[0069] In step S202, when the network controller uses its own timestamp to mark the received SIOAM node information, the network controller can also calculate the forwarding delay of the packet between each node based on its own timestamp. This can avoid large errors in the calculation result of forwarding delay caused by the low accuracy of NTP clock synchronization.
[0070] Specifically, when executing step S202, for any two transmission node devices, such as the SIOAM node information uploaded by the first transmission node device and the SIOAM node information uploaded by the third transmission node device, the network controller can calculate the time difference between the two timestamps corresponding to these two SIOAM node information, thereby determining the delay of traffic data transmission from the first transmission node device to the third transmission node device, that is, the forwarding delay information between the first transmission node device and the third transmission node device.
[0071] In this embodiment, when executing step S202, a duration threshold can be set for network quality alarms, for example, a duration threshold of 50ms. When the forwarding delay between any two adjacent node devices obtained from executing step S202 is greater than 50ms, the network controller can trigger an alarm to achieve flow-based delay statistics.
[0072] Step S203 is the packet loss statistics step. In step S203, the network controller only needs to analyze whether the Sequence IDs in the information reported by the decapsulation nodes (or the SIOAM node information uploaded to the network controller by each node device in real time) are consecutive to determine whether packet loss exists on the forwarding link. If the Sequence IDs are consecutive, the network controller determines that there is no packet loss, i.e., no packet loss event has been detected; if the Sequence IDs are discontinuous, the network controller determines that there is packet loss, i.e., a packet loss event has been detected.
[0073] In this embodiment, when executing step S203, the network controller can process the SIOAM node information by sampling. That is, instead of processing all the SIOAM node information, it samples a portion of the SIOAM node information from all the SIOAM node information. This sampled portion of the SIOAM node information is called sampled information. In step S203, the continuity of the sampled information is detected. This can reduce the amount of data that needs to be processed and reduce the device performance overhead.
[0074] Specifically, the network controller can determine the data traffic volume being forwarded by each transmission node device based on the SIOAM node information. Based on the data traffic volume, it determines the sampling ratio, where the sampling ratio is the proportion of data information the network controller must sample from all SIOAM node information; that is, the larger the data traffic, the larger the sampling ratio, thus sampling more SIOAM node information as sample data. In this embodiment, for low-volume target flows, a smaller sampling ratio of 1:1 (equivalent to packet-by-packet detection) or 10:1 can be used to obtain better detection results. For high-volume continuous flows, a relatively larger sampling ratio can be used to reduce the pressure on the device for encapsulation.
[0075] In this embodiment, when the network controller executes step S303D, it can first configure the flow detection mode of each transmission node device (e.g., the first transmission node device) to end-to-end detection mode, that is, each transmission node device maintains a transparent transmission state. Before the network controller executes step S203 and detects a packet loss event, the network controller configures each transmission node device to maintain the end-to-end detection mode. That is, if the network controller does not detect a packet loss event, then each transmission node device will always maintain the end-to-end detection mode. When the network controller executes step S203 and detects a packet loss event, the network controller configures each transmission node device to switch to hop-by-hop detection mode. In this way, the network controller can control the transmission node devices to operate in end-to-end detection mode by default, thereby reducing the amount of SIOAM node information that the network controller needs to receive and reducing the load on the communication network. After a packet loss event is detected, it switches to hop-by-hop detection mode to receive SIOAM node information from each transmission node device. By analyzing the data reported sequentially by the devices as traffic flows through them, the specific location of the packet loss can be identified, thus enabling fine-grained flow-based detection of the communication network.
[0076] Example 6 As can be seen from the embodiments 1-5, the communication network and the flow-following detection method implemented in these embodiments realize SIOAM from flow-following detection packet encapsulation and detection information reporting, to the controller parsing and restoring the actual forwarding path of the traffic, as well as packet loss alarm and latency alarm location and diagnosis functions. Even when the communication network is time-synchronized by NTP, and the time synchronization accuracy is not high, the effect of flow-following detection fault diagnosis can still be achieved, thereby reducing the necessity of applying more expensive time synchronization technologies such as PTP, and significantly reducing the deployment difficulty of flow-following detection. Specifically, these embodiments can achieve the following effects: Reduce clock synchronization accuracy requirements: By using NTP timestamps and message forwarding information to push forwarding device information, the controller can directly restore the forwarding path and realize delay fault alarms; Simplified in-stream detection head encapsulation: Unnecessary fields in in-stream detection have been removed, resulting in a reduction in the length of the SIOAM detection head; Flexible detection based on sampling: To cope with different traffic scenarios, different sampling values can be set to encapsulate packets with SIOAM, which has less overhead compared to packet-by-packet coloring encapsulation; Applicable to more forwarding scenarios: SIAOM detection directly inserts the detection encapsulation header into the original packet, making it suitable for a wider range of forwarding scenarios. For example, in general network flow detection scenarios, network devices only need to implement NTP clock synchronization to enable detection. SIOAM supports both end-to-end and hop-by-hop detection modes. During use, end-to-end detection can be enabled first to determine the overall link quality, and then switched to hop-by-hop detection mode to locate specific fault points.
[0077] In this embodiment, a computer device can be used, including a memory and a processor. The memory is used to store at least one program, and the processor is used to load at least one program to execute the flow detection method, thereby obtaining the effect of the flow detection method.
[0078] In this embodiment, a computer program product, including a computer program, can be used to implement the flow detection method in the embodiment when the computer program is executed by a processor.
[0079] It should be noted that, unless otherwise specified, when a feature is referred to as "fixed" or "connected" to another feature, it can be directly fixed or connected to the other feature, or indirectly fixed or connected to the other feature. Furthermore, the descriptions of "upper," "lower," "left," and "right" used in this disclosure are only relative to the relative positional relationships of the components of this disclosure in the accompanying drawings. The singular forms "a" and "the" used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. Moreover, unless otherwise defined, all technical and scientific terms used in this embodiment have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this embodiment specification is only for describing specific embodiments and is not intended to limit the embodiments of the invention. The term "and / or" as used in this embodiment includes any combination of one or more of the associated listed items.
[0080] It should be understood that although the terms first, second, third, etc., may be used to describe various elements in this disclosure, these elements should not be limited to these terms. These terms are only used to distinguish elements of the same type from each other. For example, a first element may also be referred to as a second element without departing from the scope of this disclosure, and similarly, a second element may also be referred to as a first element. The use of any and all instances or exemplary language (“e.g.,” “such as,” etc.) provided in this embodiment is intended only to better illustrate embodiments of the invention and, unless otherwise required, does not impose a limitation on the scope of embodiments of the invention.
[0081] It should be recognized that embodiments of the present invention can be implemented or carried out by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable storage medium. The method can be implemented using standard programming techniques—including a non-transitory computer-readable storage medium configured with a computer program, wherein such a storage medium causes the computer to operate in a specific and predefined manner—according to the methods and drawings described in the specific embodiments. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. Furthermore, for this purpose, the program can run on a programmed application-specific integrated circuit (ASIC).
[0082] Furthermore, the procedures described in this embodiment can be performed in any suitable order unless otherwise indicated by this embodiment or otherwise obviously contradict the context. The procedures (or variations and / or combinations thereof) described in this embodiment can be executed under the control of one or more computer systems configured with executable instructions, and can be implemented by hardware or a combination thereof as code (e.g., executable instructions, one or more computer programs, or one or more applications) that commonly executes on one or more processors. A computer program includes a plurality of instructions executable by one or more processors.
[0083] Furthermore, the method can be implemented in any suitable type of computing platform, including but not limited to personal computers, minicomputers, mainframes, workstations, networked or distributed computing environments, standalone or integrated computer platforms, or in communication with charged particle tools or other imaging devices, etc. Aspects of embodiments of the invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, optical read and / or write storage medium, RAM, ROM, etc., such that it is readable by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the processes described herein. Furthermore, the machine-readable code, or portions thereof, can be transmitted via wired or wireless networks. The invention of this embodiment includes these and other different types of non-transitory computer-readable storage media when such media comprises instructions or programs that implement the steps above in conjunction with a microprocessor or other data processor. Embodiments of the invention also include the computer itself when programmed according to the methods and techniques of embodiments of the invention.
[0084] A computer program can be applied to input data to perform the functions of this embodiment, thereby transforming the input data to generate output data stored in non-volatile memory. The output information can also be applied to one or more output devices, such as a display. In a preferred embodiment of the invention, the transformed data represents physical and tangible objects, including a specific visual depiction of physical and tangible objects generated on the display.
[0085] The above are merely preferred embodiments of the present invention. The embodiments of the present invention are not limited to the above-described implementations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the embodiments of the present invention, as long as they achieve the same technical effects, should be included within the scope of protection of the embodiments of the present invention. Within the scope of protection of the embodiments of the present invention, the technical solutions and / or implementation methods can have various modifications and variations.
Claims
1. A flow-fed detection method, applied to encapsulated node equipment, characterized in that, The in-flow detection method includes: Obtain raw traffic data; A SIOAM protocol header is added to the raw traffic data to obtain first forwarded traffic data; the SIOAM protocol header includes the timestamp of the raw traffic data entering the encapsulation node device, and the SIOAM protocol header is used to trigger the first transmission node device to process; Report the SIOAM protocol header to the network controller; The first forwarding traffic data is sent to the first transmission node device.
2. A flow-following detection method, applied to a first transmission node device, characterized in that, The in-flow detection method includes: Receive third forwarding traffic data; the third forwarding traffic data is either the first forwarding traffic data sent by the encapsulated node device, or the second forwarding traffic data sent by the second transmission node device; In response to the SIOAM protocol header in the third forwarded traffic data, the flow detection mode is determined; According to the flow detection mode, the third forwarding traffic data is processed accordingly to obtain the fourth forwarding traffic data; The fourth forwarding traffic data is sent to the next hop node; the next hop node is either the third transmission node device or the decapsulation node device.
3. The in-flow detection method according to claim 2, characterized in that, The step of processing the third forwarding traffic data according to the flow detection mode to obtain the fourth forwarding traffic data includes: When the flow detection mode is end-to-end detection mode, the third forwarding traffic data is processed in its original form to obtain the fourth forwarding traffic data.
4. The in-flow detection method according to claim 2 or 3, characterized in that, The step of processing the third forwarding traffic data according to the flow detection mode to obtain the fourth forwarding traffic data includes: When the flow detection mode is hop-by-hop detection mode, the SIOAM node information corresponding to the first transmission node device is encapsulated into the third forwarding traffic data to obtain the fourth forwarding traffic data; the SIOAM node information includes the timestamp of the third forwarding traffic data entering the first transmission node device, and the node entry and exit information of the first transmission node device. Report the SIOAM protocol header and the SIOAM node information to the network controller.
5. A flow-following detection method, applied to decapsulation node equipment, characterized in that, The in-flow detection method includes: Receive fourth forwarding traffic data from the first transmission node device; Extract the SIOAM protocol header and all SIOAM node information from the fourth forwarding traffic data; Report the SIOAM protocol header and all SIOAM node information to the network controller; The SIOAM protocol header and all SIOAM node information are deleted from the fourth forwarding traffic data to obtain the fifth forwarding traffic data. Forward the fifth forwarding traffic data.
6. A flow-following detection method, applied to a network controller, characterized in that, The in-flow detection method includes: Receive SIOAM node information uploaded by each node device; the node device includes an encapsulation node device, a first transmission node device, and a decapsulation node device; Perform data analysis based on the SIOAM node information described above; Configure the first transmission node device according to the SIOAM node information.
7. The in-flow detection method according to claim 6, characterized in that, The data analysis performed based on the SIOAM node information includes: Based on the SIOAM node information, the topology is reconstructed to obtain the forwarding topology information; Based on the SIOAM node information, latency statistics are performed to obtain the forwarding latency information between the node devices. The SIOAM node information is sampled to obtain multiple sampled information. The continuity of each sampled information is detected. Based on the continuity detection result, packet loss events are detected.
8. The in-flow detection method according to claim 7, characterized in that, The sampling of each SIOAM node information yields multiple sampled information items, including: The data traffic volume is determined based on the SIOAM node information described above; The sampling ratio is determined in a positive correlation with the data flow rate. Based on the sampling ratio, a corresponding number of SIOAM node information are randomly sampled as the sampling information.
9. The in-flow detection method according to claim 7 or 8, characterized in that, The configuration of the first transmission node device based on the SIOAM node information includes: Before detecting the packet loss event, the following detection mode of the first transmission node device is configured as end-to-end detection mode; When the packet loss event is detected, the flow detection mode is configured as a hop-by-hop detection mode.
10. A communication network, characterized in that, The communication network includes: A packaging node device is used to perform the flow detection method according to claim 1. A first transmission node device; the first transmission node device is used to execute the flow detection method according to any one of claims 2-4; A decapsulation node device; the decapsulation node device is used to perform the flow detection method according to claim 5; Network controller; the network controller is used to execute the flow detection method according to any one of claims 6-9; A time synchronization module; the time synchronization module performs time synchronization on the encapsulation node device, the first transmission node device, and the decapsulation node device via NTP or PTP.