Message processing mode, message processing device, electronic equipment, medium and product
By using Vector Packet Processing Node (VPP) technology, which flexibly processes packets based on their physical addresses and interface information, the inflexibility of traditional MAC filtering schemes is solved, enabling refined packet control and efficient processing in complex network environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TP-LINK INT SHENZHEN CO LTD
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-21
AI Technical Summary
Traditional MAC filtering schemes are not very flexible in packet processing and are difficult to adapt to the refined security control requirements of modern network environments, especially in complex network topologies and high-speed network environments where it is difficult to achieve precise control over the direction and type of traffic.
By employing Vector Packet Processing Node (VPP) technology, the system obtains the physical address, input interface, and output interface information of the message to be processed, and combines this with pre-configured message processing rules to achieve flexible processing based on the message transmission direction, including local response, sending, and dropping.
It improves the flexibility and applicability of message processing, reduces processing latency, increases message throughput, and is suitable for complex network topologies and high-speed network environments.
Smart Images

Figure CN121907544A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of message processing technology, and in particular to a message processing method, message processing device, electronic device, computer-readable storage medium, and computer program product. Background Technology
[0002] In related technologies, physical address or Media Access Control (MAC) address filtering is one of the basic security functions of devices such as gateways, routers, and switches. It can be used to allow or deny packets based on their source or destination physical addresses. However, in traditional MAC filtering schemes, when a source physical address is added to the blacklist, all packets originating from that source physical address will be denied, and conversely, when a source physical address is added to the whitelist, all packets originating from that source physical address will be allowed. This processing method is relatively fixed and lacks flexibility, thus limiting its application scenarios. Summary of the Invention
[0003] This application provides a message processing method, a message processing apparatus, an electronic device, a computer-readable storage medium, and a computer program product.
[0004] This application provides a message processing method, the method comprising: When the target vector data packet processing node receives a message to be processed, it obtains the target message information of the message to be processed, wherein the target message information includes a first physical address, a first message input interface and a first message output interface; The message to be processed is processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node, wherein the message processing rules are used to determine the target processing method corresponding to the target message information.
[0005] Thus, in this embodiment, when the target vector data packet processing node receives a message to be processed, it can obtain the first physical address, first message input interface, and first message output interface of the message to be processed. Based on the first physical address, first message input interface, and first message output interface of the message to be processed, and combined with message processing rules corresponding to the target vector data packet processing node for determining the target processing method corresponding to the target message information, at least one of local response processing, sending processing, and discarding processing is performed on the message to be processed. This achieves message processing based on physical address, message input interface, and message output interface. Compared to processing messages through blacklists / whitelists or kernel protocol stacks, message processing constrained by message transmission direction can be achieved based on message input and output interfaces, resulting in greater flexibility and wider applicability. Furthermore, because messages are processed through vector data packet processing nodes, batch and parallel processing of messages can be achieved based on vector data packet processing nodes. Compared to processing messages through kernel protocol stacks, message processing latency is relatively lower and message throughput is higher.
[0006] In some embodiments of this application, the message processing rules include a preset processing method, and a physical address group, a second message input interface, and a second message output interface corresponding to the preset processing method. The preset processing method is one of local response processing, sending processing, and discarding processing. The step of processing the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node includes: When the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface, the message to be processed is processed according to the preset processing method.
[0007] Thus, in this embodiment of the application, when the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface, the message to be processed can be processed according to the preset processing method. Message processing based on the message physical address and message sending / receiving interface can be achieved through the first physical address, the first message input interface, the second message input interface, the first message output interface, and the second message output interface.
[0008] In some embodiments of this application, the method further includes: Obtain physical address configuration data, wherein the physical address configuration data includes a second physical address, a list type and a filtering direction, the list type is a blacklist or a whitelist, the filtering direction is a first direction or a second direction, the first direction includes from a local area network interface to a wide area network interface, and the second direction includes from a local area network interface to a wide area network interface and from a local area network interface to a local area network interface. Create the physical address group based on the second physical address; Based on the physical address group, the list type, and the filtering direction, packet processing rules are generated; The message processing rules are sent to the target vector data packet processing node.
[0009] Thus, in this embodiment of the application, physical address configuration data can be obtained, and the physical address group can be created according to the second physical address. Packet processing rules can be generated according to the physical address group, the list type and the filtering direction, and the packet processing rules can be sent to the target vector data packet processing node, thereby realizing the generation of packet processing rules and the deployment of packet processing rules on the target vector data packet processing node.
[0010] In some embodiments of this application, the message processing rules include multiple rules, each corresponding to a type of filtering direction. The target vector data packet processing node includes a first node and a second node. The first node is capable of sending and discarding received messages, and the second node is capable of local response and discarding received messages. The step of distributing the message processing rules to the target vector data packet processing node includes: The message processing rules corresponding to the first direction are sent to the first node; The message processing rules corresponding to the second direction are sent to the first node and the second node.
[0011] Thus, in this embodiment of the application, the message processing rules corresponding to the first direction can be sent to the first node, and the message processing rules corresponding to the second direction can be sent to both the first node and the second node, thereby realizing message processing based on the message ingress and egress interfaces.
[0012] In some embodiments of this application, the method further includes: In response to the configuration operation of physical address configuration data, the physical address configuration data is obtained.
[0013] Thus, in this embodiment of the application, the physical address configuration data can be obtained in response to the configuration operation of the physical address configuration data, thereby realizing the effective acquisition of the physical address configuration data.
[0014] In some embodiments of this application, the method further includes: The second physical address in the physical address group is compiled into runtime data structure data.
[0015] Thus, in this embodiment of the application, the second physical address in the physical address group can be compiled into runtime data structure data, thereby enabling the second physical address in the physical address group to be processed using runtime data structure data. This reduces the address storage space occupied by the second physical address and improves the processing efficiency of the second physical address, thereby efficiently determining whether the first physical address is the second physical address in the physical address group.
[0016] In some embodiments of this application, the method further includes: In response to the rule deactivation command, the message processing rule is deleted.
[0017] Thus, in this embodiment of the application, the message processing rule can be deleted in response to a rule deactivation command, thereby deactivating the message processing rule.
[0018] This application provides a message processing apparatus, the apparatus comprising: The acquisition module is used to acquire the target message information of the message to be processed when the target vector data packet processing node receives the message to be processed, wherein the target message information includes a first physical address, a first message input interface and a first message output interface; The processing module is used to process the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node, wherein the message processing rules are used to determine the target processing method corresponding to the target message information.
[0019] This application provides an electronic device, including a memory and a processor. The memory stores a computer program, which, when executed by the processor, implements the above-described message processing method.
[0020] This application provides a computer-readable storage medium storing a computer program that, when executed by one or more processors, implements the above-described message processing method.
[0021] This application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the above-described message processing method.
[0022] The control device, electronic device, computer-readable storage medium, and computer program product provided in this application can, when a target vector data packet processing node receives a message to be processed, obtain the first physical address, first message input interface, and first message output interface of the message to be processed, and, based on the first physical address, first message input interface, and first message output interface of the message to be processed, and in conjunction with message processing rules corresponding to the target vector data packet processing node for determining the target processing method corresponding to the target message information, perform at least one of local response processing, sending processing, and discarding processing on the message to be processed. This achieves message processing based on physical address, message input interface, and message output interface. Compared with message processing methods using blacklists / whitelists or kernel protocol stacks, message processing based on message input interface and message output interface can achieve message processing constrained by message transmission direction, thus making message processing more flexible and applicable to a wider range of scenarios. Furthermore, since packets are processed through vector packet processing nodes, batch and parallel processing of packets can be achieved based on vector packet processing nodes. Compared with processing packets through the kernel protocol stack, the packet processing latency is relatively lower and the packet throughput is higher.
[0023] Additional aspects and advantages of embodiments of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of embodiments of this application. Attached Figure Description
[0024] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, wherein: Figure 1 This is a flowchart illustrating a message processing method in certain embodiments of this application; Figure 2 This is a schematic diagram of a message processing apparatus in some embodiments of this application; Figure 3 This is a schematic diagram of an electronic device in some embodiments of this application; Figure 4 This is a flowchart illustrating a message processing method in certain embodiments of this application; Figure 5 This is a flowchart illustrating a message processing method in certain embodiments of this application; Figure 6 This is a flowchart illustrating a message processing method in certain embodiments of this application; Figure 7The diagram illustrates certain application scenarios provided for some embodiments of this application. Detailed Implementation
[0025] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the embodiments of this application, and should not be construed as limiting the embodiments of this application.
[0026] Understandably, physical address (or media access control address) filtering is a fundamental security function of network devices such as gateways, routers, and switches. It controls the passage of data packets based on the source or destination physical address of the data frame, allowing or denying access. Traditional physical address filtering schemes are generally implemented at the data link layer, with relatively limited functionality, supporting only blacklist or whitelist modes based on physical addresses.
[0027] Specifically, traditional physical address filtering schemes cannot distinguish between the direction and type of traffic. For example, when a physical address is blacklisted, all traffic originating from that address, regardless of whether it's destined for the external WAN or communicating with other devices within the internal LAN, will be blocked. In contrast, devices in whitelist mode have full access to both the external WAN and the internal LAN. Understandably, this approach lacks flexibility and struggles to meet the granular security control requirements of modern network environments. For instance, an administrator might need to block an internal device from accessing the external network while allowing it to perform internal file sharing or printing services; traditional physical address filtering schemes cannot achieve this control objective.
[0028] In related technologies, to improve the flexibility of physical address filtering, a physical address filtering scheme based on the Linux kernel network protocol stack and the Internet Protocol (IP) table firewall framework is proposed. This scheme uses the "four tables and five chains" mechanism of the network protocol table to distribute filtering rules containing physical address matching conditions to the predefined key chains in the kernel that correspond to different data packet processing stages. This enables preliminary control over the flow of data packets. For example, filtering rules can be added to the Input chain to control data packets destined for the local machine, and filtering rules can be added to the Forward chain to control data packets transmitted across interfaces.
[0029] However, while the physical address filtering schemes mentioned above can achieve basic targeted filtering, they are difficult to implement for control requirements that are precise down to the interface or path direction, such as "filtering only LAN-to-WAN traffic while allowing LAN-to-LAN traffic".
[0030] In addition, it is understandable that the above physical address filtering scheme implements the physical address filtering function based on five fixed processing chains (PREROUTING, INPUT, FORWARD, OUTPUT, POSTROUTING). However, these chains are based on the protocol stack processing stage of the data packet rather than the network topology location definition, so the processing points are fixed and lack topology awareness.
[0031] Furthermore, because different logical security zones cannot be clearly defined and distinguished, in the above physical address filtering scheme, all LAN interfaces are treated as one whole zone, and all WAN interfaces are treated as another whole zone. However, in a complex enterprise network, there may be multiple subnets of different Virtual Local Area Networks (VLANs) belonging to the LAN zone, but the network protocol table cannot abstract these subnets into a unified "LAN whole zone," thus making it impossible to formulate a unified filtering policy for these subnets. Rules must be configured separately for each specific subnet and interface.
[0032] In summary, the physical address filtering schemes based on network protocol tables described above are difficult to adapt to complex and ever-changing network topologies and business requirements, thus limiting their application in high-end network equipment.
[0033] Based on the issues mentioned above, please refer to Figure 1 This application provides a message processing method, the method including: 01: When the target vector data packet processing node receives the message to be processed, it obtains the target message information of the message to be processed, wherein the target message information includes the first physical address, the first message input interface and the first message output interface; 02: Based on the target message information and the message processing rules corresponding to the target vector data packet processing node, process the message to be processed. The message processing rules are used to determine the target processing method corresponding to the target message information. The target processing method is at least one of local response processing, sending processing, and dropping processing.
[0034] Please see Figure 2This application provides a message processing apparatus 200. The message processing method of this application can be implemented by the message processing apparatus 200. Specifically, the message processing apparatus 200 includes an acquisition module 210 and a processing module 220. The acquisition module 210 is used to acquire target message information of the message to be processed when a target vector data packet processing node receives a message to be processed. The target message information includes a first physical address, a first message input interface, and a first message output interface. The processing module 220 is used to process the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node. The message processing rules are used to determine the target processing method corresponding to the target message information, and the target processing method is at least one of local response processing, sending processing, and discarding processing.
[0035] Please see Figure 3 This application also provides an electronic device 300, which includes a memory 310 and a processor 320. The message processing method of this application can be implemented by the electronic device 300. Specifically, the memory 310 stores a computer program 311, and the processor 320 is used to obtain the target message information of the message to be processed when the target vector data packet processing node receives the message to be processed, and to process the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node. The target message information includes a first physical address, a first message input interface, and a first message output interface. The message processing rules are used to determine the target processing method corresponding to the target message information. The target processing method is at least one of local response processing, sending processing, and discarding processing.
[0036] Specifically, considering that packet (or traffic) processing schemes based on blacklists and whitelists, or the physical address filtering schemes in the aforementioned related technologies, suffer from poor flexibility and are therefore unsuitable for the accuracy and efficiency requirements of packet filtering in high-speed networks and complex topology environments, this application provides a scheme for address filtering based on Vector Packet Processing (VPP). Specifically, when a target vector packet processing node receives a packet to be processed, the electronic device extracts the target packet information of the packet, namely the packet's first physical address, first packet input interface, and first packet output interface. Then, according to the packet processing rules associated with or corresponding to the processing node, it performs at least one of local response processing, transmission processing, or discard processing on the packet. This achieves packet processing based on packet address and packet transmission direction, thereby enabling fine-grained control of packets and improving the flexibility of packet processing.
[0037] In some implementations, vector packet processing can be understood as a high-performance user-space network data plane development framework that uses a node graph to define the packet processing flow. Each node is responsible for a specific network function, such as Ethernet input, IP route lookup, ARP response, etc. Messages (or packets) are passed between these nodes and processed sequentially.
[0038] In some implementations, a target vector packet processing node can be understood as one or more pre-configured vector packet processing (VPP) nodes with certain vector processing capabilities, such as the ability to process packets in batches and in parallel.
[0039] In some implementations, the message to be processed can be understood as a network data packet transmitted in the network that needs to undergo security filtering or direction control, including an Ethernet header, a network layer header, and a data payload. The Ethernet header stores physical address (or media access control address) information.
[0040] In some implementations, the target message information consists of the physical address of the message to be processed, the message input interface, and the message output interface.
[0041] In some implementations, the first physical address can be understood as the source physical address or destination physical address of the message to be processed. It is understood that a physical address or Media Access Control (MAC) address is used to uniquely identify a device; if the first physical address is the source physical address, then the first physical address is used to identify the device that generated the message to be processed.
[0042] In one example, the first physical address is the source physical address of the message to be processed.
[0043] In some implementations, the first message input interface can be understood as the physical or logical interface through which the target message information enters the target processing node. This interface can be a local area network (LAN) interface or a wide area network (WAN) interface, which can identify the source of the message to be processed.
[0044] In some implementations, the first message output interface can be understood as a desired physical or logical interface for receiving messages to be processed. This interface can be a local area network interface or a wide area network interface, and can identify the destination of the messages to be processed.
[0045] In some implementations, message processing rules can be understood as rules that are pre-configured and distributed to the target processing node, and can define the mapping relationship between message information and message processing methods.
[0046] In some implementations, the target vector packet processing node stores message processing rules, and the node can then read these message processing rules to determine the target processing method for the message to be processed.
[0047] In some implementations, the target processing method can be understood as a result determined based on message processing rules and corresponding to the first physical address, the first message input interface, and the first message output interface.
[0048] In some implementations, the target processing method may be one of local response processing, sending processing, and discarding processing.
[0049] In some implementations, local response processing can be understood as inbound (local), that is, the processing method when the destination of the message to be processed is the local machine (i.e., the electronic device itself). It can be understood that when the target processing method is local response processing, the message can be delivered to the application process on the local machine.
[0050] In some implementations, sending processing can be either outbound or forward processing, which can be understood as the processing method when the message to be processed needs to be transmitted across interfaces, such as when the message is transmitted from a local area network interface to a wide area network interface.
[0051] In some implementations, drop processing can be understood as the rejection of pending packets, or as a processing method that does not forward or process local responses to pending packets, but directly discards the packets, in order to filter unauthorized physical address packets or abnormal physical address packets.
[0052] It is worth noting that, in the embodiments of this application, the target vector packet processing node can also be understood as a vector packet processing node capable of performing local response processing, sending processing and dropping processing on received messages, or a vector packet processing node capable of performing local response processing and dropping processing.
[0053] In one example, the target vector packet processing node is an Access Control List (ACL) node connected to a local node and located on the packet input path of the local node. The local node can be an ip4-local node and / or an ip6-local node. The local node can perform local response processing on the packet. The ACL node connected to the local node can determine, based on the packet processing rules, whether the local node is allowed to perform local response processing on the packet to be processed. If allowed (Accept), the packet to be processed is sent to the local node so that the local node can perform local response processing on the packet; otherwise, the packet to be processed is discarded.
[0054] In one example, the target vector packet processing node can be an Access Control List (ACL) node connected to the output node and located on the packet input path of the output node. The output node can be an IP4-output node and / or an IP6-output node. The output node can forward or process the packets to be processed. The ACL node can determine whether to allow forwarding (or outbound processing) of the packets to be processed based on the packet processing rules. If allowed (Accept), the packet to be processed is sent to the output node so that the output node can perform forwarding or outbound processing; if not allowed, the packet to be processed is discarded.
[0055] To more clearly illustrate the message processing method provided in the embodiments of this application, please refer to the following exemplary description: The messages to be processed are transmitted in the network and arrive at the preset target vector packet processing node. It can be understood that the target vector packet processing node has the ability to receive and parse batches of messages.
[0056] Next, the target vector packet processing node can parse the received message, such as extracting the source MAC address (i.e., the first physical address) from the Ethernet header of the message, and obtaining the input interface and output interface (i.e., the first message input port and the first message output port) from the interface association information.
[0057] Next, the target vector packet processing node calls the packet processing rule corresponding to itself (or the pre-stored one in the node), compares the extracted target packet information with the matching conditions in the rule, such as the physical address range, input / output port combination, etc., in order to determine whether the packet matches the packet processing rule.
[0058] Finally, based on the rule matching results, the corresponding target processing method is determined. For example, if the message processing rule defines a condition for satisfying local response processing, and the target message information meets that condition, then the target vector data packet processing node performs local response processing on the message to be processed. Conversely, if the message processing rule defines a condition for satisfying local response processing, but the target message information does not meet that condition, then the target vector data packet processing node discards the message to be processed.
[0059] Thus, in this embodiment, when the target vector data packet processing node receives a message to be processed, it obtains the first physical address, first message input interface, and first message output interface of the message to be processed. Based on these information, and combined with message processing rules corresponding to the target vector data packet processing node for determining the target processing method corresponding to the target message information, at least one of local response processing, sending processing, and discarding processing is performed on the message to be processed. This achieves message processing based on the physical address, message input interface, and message output interface. Compared to processing messages through blacklists / whitelists or kernel protocol stacks, message processing constrained by the message transmission direction can be achieved based on the message input interface and message output interface, resulting in greater flexibility and wider applicability. Furthermore, because messages are processed through a vector data packet processing node, batch and parallel processing of messages can be achieved. Compared to processing messages through the kernel protocol stack, message processing latency is relatively lower and message throughput is higher.
[0060] Please see Figure 4 In some embodiments provided in this application, the message processing rules include a preset processing method, and a physical address group, a second message input interface, and a second message output interface corresponding to the preset processing method. The preset processing method is one of local response processing, sending processing, and discarding processing. Therefore, step 02 includes: 020: When the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface, the message to be processed is processed according to the preset processing method.
[0061] The processing module 220 in this embodiment is further configured to process the message to be processed according to a preset processing method when the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface.
[0062] The processor 320 in this embodiment is further configured to process the message to be processed according to a preset processing method when the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface.
[0063] Specifically, to further realize message processing based on message physical address and message sending / receiving interface, in some embodiments provided in this application, when the first physical address of the message to be processed belongs to the physical address group in the message processing rule, the first message input port of the message to be processed matches the second message input port in the message processing rule, and the first message output port of the message to be processed matches the second message output port in the message processing rule, the message is processed according to the preset processing method in the message processing rule, thereby realizing message processing based on message physical address and message sending / receiving interface.
[0064] In some implementations, a physical address group can be understood as a set consisting of one or more pre-configured physical addresses.
[0065] In some implementations, the second message input port can be understood as an input port that is pre-set in the message processing rules as a matching reference, corresponding to the actual input port of the message to be processed, that is, corresponding to the first message input port, and used to constrain the range of message sources to which the rules apply.
[0066] In some implementations, the second message output port can be understood as an output port that is pre-set in the message processing rules as a matching reference, corresponding to the actual output port of the message to be processed, that is, corresponding to the first message output port, and used to constrain the message destination range to which the rules apply.
[0067] In some implementations, the preset processing method can be understood as a predefined message processing action, which is bound together with the physical address group, the second message input port, and the second message output port, specifically one of local response processing, sending processing, and discarding processing.
[0068] In one example, the packet processing rule is an Access Control List (ACL) rule defined in the Access Control List (ACL) node. This rule may include: the rule action is ACCEPT, the source address type is ACL_ADDRESS_MAC_GROUP, the MAC address group name used for matching is macfilter_white_list, the ingress interface used to match the packet in the rule is "AnyLAN", and the egress interface used to match the packet in the rule is "AnyWAN".
[0069] In this example, ACCEPT indicates that local response processing and sending processing of packets are allowed, ACL_ADDRESS_MAC_GROUP is the identifier of this rule, macfilter_white_list is the name of the physical address group, "AnyWAN" indicates that any LAN interface is a second packet input interface, and "AnyLAN" indicates that any WAN interface is a second packet output interface.
[0070] Furthermore, if the first physical address of the message to be processed belongs to macfilter_white_list, and the first message input interface of the message to be processed is a local area network interface, then the message to be processed will be either processed locally or sent.
[0071] Conversely, if the first physical address of the packet to be processed does not belong to macfilter_white_list, or the first packet input interface of the packet to be processed is not a local area network interface, or the first packet input interface of the packet to be processed is not a wide area network interface, then the packet to be processed will be discarded.
[0072] In some implementations, the physical address group can be empty, meaning that no physical address exists within the physical address group. It is understood that when the physical address group is empty, the first physical address of the packet to be processed does not belong to the physical address group. Therefore, one of the following processing methods—local response processing, sending processing, and discarding processing—other than the preset processing method, is directly used as the target processing method. For example, if the target vector packet processing node is responsible for packet outbound and packet forwarding, and the preset processing method is local response processing or sending processing, and the physical address group can be empty, the target vector packet processing node can discard the packet to be processed.
[0073] For example, if the target vector packet processing node is responsible for incoming packets and the default processing method is to discard them, and the physical address group is empty, the target vector packet processing node can accept the packets to be processed, which is local response processing.
[0074] Thus, in this embodiment of the application, when the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface, the message to be processed can be processed according to a preset processing method. Message processing based on the message physical address and message sending / receiving interface can be realized through the first physical address, the first message input interface, the second message input interface, the first message output interface, and the second message output interface.
[0075] Please see Figure 5 In some embodiments of this application, the message processing method further includes: 03: Obtain physical address configuration data, wherein the physical address configuration data includes a second physical address, a list type and a filtering direction, the list type is a blacklist or a whitelist, the filtering direction is a first direction or a second direction, the first direction includes from LAN interface to WAN interface, and the second direction includes from LAN interface to WAN interface and from LAN interface to LAN interface. 04: Create the physical address group based on the second physical address; 05: Generate packet processing rules based on the physical address group, the list type, and the filtering direction; 06: Send the message processing rules to the target vector data packet processing node.
[0076] The message processing apparatus of this application further includes a data acquisition module, a creation module, a generation module, and a distribution module. The configuration data acquisition module is used to acquire physical address configuration data, wherein the physical address configuration data includes a second physical address, and a list type and filtering direction corresponding to the second physical address. The list type is a blacklist or a whitelist, and the filtering direction is a first direction or a second direction. The first direction includes a path from a local area network (LAN) interface to a wide area network (WAN) interface, and the second direction includes a path from a LAN interface to a WAN interface and a path from a LAN interface to a LAN interface. The creation module is used to create the physical address group based on the second physical address. The generation module is used to generate message processing rules based on the physical address group, the list type, and the filtering direction. The distribution module is used to distribute the message processing rules to the target vector data packet processing node.
[0077] The processor 320 in this embodiment is further configured to acquire physical address configuration data, create the physical address group based on the second physical address, generate packet processing rules based on the physical address group, the list type, and the filtering direction, and distribute the packet processing rules to the target vector data packet processing node. The physical address configuration data includes the second physical address, and includes the list type and filtering direction corresponding to the second physical address. The list type is either a blacklist or a whitelist, and the filtering direction is either a first direction or a second direction. The first direction includes a path from a local area network (LAN) interface to a wide area network (WAN) interface, and the second direction includes a path from a LAN interface to a WAN interface and a path from a LAN interface to a LAN interface.
[0078] Specifically, in order to generate message processing rules and deploy them on the target vector data packet processing node, in some embodiments provided in this application, the electronic device can obtain the physical address configuration data set by the user, classify the physical addresses in the physical address configuration data into physical address groups, and then generate corresponding message processing rules by combining the list type and filtering direction. Finally, the rules are sent to the target vector data packet processing node to provide a rule basis for the targeted filtering of subsequent messages.
[0079] In some implementations, physical address configuration data can be understood as a set of parameters based on user configuration used to implement physical address filtering functionality.
[0080] In some implementations, the second physical address can be understood as a specific physical address configured by the user to implement the physical address filtering function, and can exist in string form.
[0081] In some implementations, the number of second physical addresses may be one or more.
[0082] In some implementations, the list type can be understood as one of the attributes used to define filtering rules, and is divided into blacklists and whitelists. A blacklist means that matching packets are denied passage, while a whitelist means that matching packets are allowed passage.
[0083] In some implementations, the filtering direction can be used to limit the range of traffic transmission paths to which the message processing rules apply. The first direction specifically refers to the traffic path from the Local Area Network (LAN) interface to the Wide Area Network (WAN) interface, while the second direction includes all traffic paths from the LAN interface to the WAN interface and from the LAN interface to the LAN interface.
[0084] In some implementations, a physical address group can be understood as a collection of multiple second physical addresses categorized by list type.
[0085] In one example, an electronic device may create a physical address group called macfilter_black_list and / or a physical address group called macfilter_white_list, where macfilter_black_list is used to store a second physical address configured as a blacklist and macfilter_white_list is used to store a second physical address configured as a whitelist.
[0086] In some implementations, considering the potential conflicts that may arise when configuring both blacklists and whitelists simultaneously, the physical address configuration data may include only one type of second physical address, such as only the second physical address configured as a blacklist, or only the second physical address configured as a whitelist.
[0087] In some implementations, to further enhance the flexibility of message processing, the physical address configuration data includes a second physical address of the blacklist type and a second physical address of the whitelist type.
[0088] Furthermore, in some implementations, when the physical address configuration data includes a second physical address of type blacklist and a second physical address of type whitelist, and a second physical address is configured as both type blacklist and type whitelist, and the second physical address belongs to both the blacklist physical address group and the whitelist physical address group, in order to avoid conflicts in packet processing rules, when generating packet processing rules, only packet processing rules corresponding to the blacklist physical address group or only packet processing rules corresponding to the whitelist physical address group can be generated, thereby avoiding conflicts in rules.
[0089] In some implementations, the generation of message processing rules depends on the group name of the physical address group. Therefore, if the physical address group can be pre-configured, such as with pre-configured group names macfilter_black_list and macfilter_white_list, when a second physical address configured as a whitelist is obtained, message processing rules can be generated based on macfilter_white_list before creating the physical address group corresponding to the second physical address. In other words, in this application's implementation, the electronic device can execute steps 04 and 05 synchronously or asynchronously, and the execution order of these two steps can be arbitrarily designed.
[0090] Furthermore, when the generation of message processing rules depends on the group name of the physical address group, even if the address members within the physical address group change, the rules generated based on the group name of the physical address group do not need to be updated. In other words, the generated message processing rules can be applied to the physical address group after the address members within the group have been updated, thus ensuring the robustness of the message processing rules in application.
[0091] In some implementations, when the list type is a blacklist, the rule generated and sent to the target vector packet processing node can be a single rule. The target vector packet processing node can use this rule to know the physical addresses that are not allowed to perform preset processing methods, such as physical addresses that are not allowed to perform local response processing or sending processing.
[0092] In some implementations, when the list type is a whitelist, two rules can be generated and sent to the target vector packet processing node, with one rule having a higher priority than the other. Assuming these two rules are RA and RB, and RA has a higher priority than RB, then the role of RA is to constrain the physical addresses that are allowed to execute the preset processing method, and the role of RB is to reject all physical addresses (corresponding to the drop operation). Therefore, when the target vector packet processing node processes packets based on RA and RB, it first determines whether the packet matches RA. If it matches, it processes the packet based on the preset processing method corresponding to RA. If it does not match, it determines whether the packet matches RB. Since the role of RB is to reject all physical addresses, the packet meets the RB requirement and is therefore rejected, and thus the drop operation is performed.
[0093] To more clearly illustrate the message processing method provided in the embodiments of this application, please refer to the following exemplary description: First, in response to the user's input and confirmation of physical address configuration data, the electronic device obtains the configured physical address data, namely the second physical address, the list type (blacklist or whitelist), and the filtering direction. In some examples, the electronic device can perform validity checks on the configuration data, such as verifying whether the format of the second physical address is correct.
[0094] Then, the electronic device categorizes and integrates multiple second physical addresses according to the list type in the configuration data, and creates corresponding physical address groups, such as blacklist physical address groups and whitelist physical address groups.
[0095] Then, based on the group name of the physical address group, combined with the processing action corresponding to the list type (e.g., blacklist corresponds to discard processing, whitelist corresponds to allow sending processing and allow local response processing), and combined with the traffic path of the filtering direction constraint, specific packet processing rules are generated, such as "the rule action is ACCEPT, the source address type is ACL_ADDRESS_MAC_GROUP, the MAC address group name used for matching is macfilter_white_list, the ingress interface used for matching packets in the rule is "AnyLAN", and the egress interface used for matching packets in the rule is "AnyWAN". Finally, the generated message processing rules are sent to the target vector packet processing node so that the target vector packet processing node can receive and store the message processing rules. Then, when the node receives a message to be processed, it can determine the target processing method of the message based on the message processing rules and process the message based on the target processing method.
[0096] Thus, in this embodiment of the application, physical address configuration data can be obtained, and a physical address group can be created based on multiple second physical addresses. Based on the physical address group, the list type and filtering direction of the second physical addresses, message processing rules can be generated, and the message processing rules can be sent to the target vector data packet processing node, thereby realizing the generation of message processing rules and the deployment of message processing rules on the target vector data packet processing node.
[0097] Please see Figure 6 In some embodiments provided in this application, the message processing rules include multiple rules, each corresponding to a filtering direction. The target vector data packet processing node includes a first node and a second node. The first node can perform message sending and discarding processing on the received messages, and the second node can perform local response processing and discarding processing on the received messages. Therefore, step 06 includes: 060: Send the message processing rules corresponding to the first direction to the first node; 060: Send the message processing rules corresponding to the second direction to the first and second nodes.
[0098] The delivery module in this application embodiment is also used to deliver the message processing rules corresponding to the first direction to the first node, and to deliver the message processing rules corresponding to the second direction to the first node and the second node.
[0099] The processor 320 in this embodiment is further configured to send message processing rules corresponding to the first direction to the first node, and to send message processing rules corresponding to the second direction to the first node and the second node.
[0100] Specifically, in order to effectively realize message processing based on message ingress and egress interfaces, in some embodiments provided in this application, multiple message processing rules can be classified according to filtering direction. Combined with the different message processing capabilities of the first node and the second node, the rules of the corresponding direction can be sent to the adaptation node respectively. For example, the message processing rules corresponding to the first direction can be sent to the first node, and the message processing rules corresponding to the second direction can be sent to the first node and the second node respectively. This ensures that each node only receives a subset of the rules, thereby achieving collaboration between the data processing rules and the processing node.
[0101] In some implementations, the first node can be understood as a functional node among the target vector packet processing nodes, possessing the ability to send and drop packets. It can be understood that the first node is adapted to the first direction, or in other words, adapted to the traffic path from the Local Area Network (LAN) interface to the Wide Area Network (WAN) interface. It can also be understood that the first node can be responsible for forwarding packets input from the WAN interface to the LAN interface, and can also be responsible for packet outbound processing.
[0102] In some implementations, the second node can be understood as another type of functional node in the target vector packet processing node, possessing the ability to handle local response processing and packet dropping. It can be understood that the second node is adapted to a second direction, or in other words, adapted to traffic paths from a LAN interface to a WAN interface, and from a LAN interface to a LAN interface. It can also be understood that the second node can be responsible for packet inbound, or in other words, it can be responsible for forwarding packets from one LAN interface to another, and can be responsible for sending packets from a LAN interface to a WAN interface.
[0103] In one example, the first node is an Access Control List (ACL) node located on the packet input path of the output node and connectable to it. The output node can be an IP4-output node and / or an IP6-output node. The output node can perform forwarding or outbound processing on the packets to be processed. The ACL node can determine whether to allow forwarding (or outbound processing) of the packets to be processed based on the packet processing rules. If allowed (Accept), the packet to be processed is sent to the output node so that the output node can perform forwarding or outbound processing; if not allowed, the packet to be processed is discarded.
[0104] In one example, the second node is an Access Control List (ACL) node connected to the local node and located in the packet input path of the local node. The local node can be an ip4-local node and / or an ip6-local node. The local node can perform local response processing on the packet. The ACL node connected to the local node can determine, based on the packet processing rules, whether the local node is allowed to perform local response processing on the packet to be processed. If allowed (Accept), the packet to be processed is sent to the local node so that the local node can perform local response processing on the packet; otherwise, the packet to be processed is discarded.
[0105] Thus, in this embodiment of the application, message processing rules corresponding to the first direction can be sent to the first node, and message processing rules corresponding to the second direction can be sent to the first node and the second node, thereby realizing message processing based on message ingress and egress interfaces.
[0106] In some embodiments of this application, the message processing method further includes: responding to a configuration operation of physical address configuration data and obtaining physical address configuration data.
[0107] The message processing apparatus of this application embodiment further includes a response module. The response module is used to respond to configuration operations on physical address configuration data and obtain physical address configuration data.
[0108] The processor 320 in this embodiment is also used to obtain physical address configuration data in response to a configuration operation of physical address configuration data.
[0109] Specifically, in order to effectively obtain physical address configuration data, in some embodiments provided in this application, the electronic device can provide the user with the function of configuring physical address data. Then, the electronic device can respond to the user's operation of configuring physical address data, thereby obtaining physical address configuration data that can be used to generate message processing rules, and thus providing effective data support for subsequent processes such as physical address group creation, message processing rule generation and distribution.
[0110] In some implementations, the electronic device may acquire physical address configuration data in response to a physical address configuration data configuration operation performed by a user on a visual page (Web).
[0111] In some implementations, the electronic device may obtain physical address configuration data in response to a physical address configuration data configuration operation performed by a user through a command line interface (CLI).
[0112] In some implementations, a controller component is deployed in the management control plane. When a user performs a physical address configuration data configuration operation on a visual page or through a command-line interface, the controller component can perform processing such as parsing and verification on the data generated by the user operation to obtain the physical address configuration data.
[0113] In some implementations, the electronic device may acquire physical address configuration data in response to a physical address configuration data configuration operation performed by a user on a preset controller software.
[0114] Thus, in this embodiment of the application, the physical address configuration data can be obtained in response to the configuration operation of the physical address configuration data, thereby realizing the effective acquisition of the physical address configuration data.
[0115] Furthermore, the target page provides users with a unified and convenient configuration entry point, lowering the operational threshold for users and enabling them to complete the input of physical address configuration data through a visual page, thereby ensuring user experience to a certain extent.
[0116] In some embodiments of this application, the message processing method further includes: compiling the second physical address in the physical address group into runtime data structure data.
[0117] The message processing apparatus of this application embodiment further includes a compilation module. The compilation module is used to compile the second physical address in the physical address group to compile the second physical address into runtime data structure data.
[0118] The processor 320 in this embodiment is further configured to perform compilation processing on the second physical address in the physical address group, so as to compile the second physical address into runtime data structure data.
[0119] Specifically, considering that user-configured second physical addresses are typically stored as strings, such as 18-byte strings like "XX:XX:XX:XX:XX:XX", processing efficiency for second physical addresses in this format is low. For example, when determining whether a first physical address is a member of an address group, each of the 18 bytes needs to be compared. Furthermore, string-formatted addresses occupy a large amount of storage space. When a physical address group contains a large number of second physical addresses, it leads to low search efficiency during rule matching, thus affecting the real-time requirements of message processing.
[0120] Based on this, in some embodiments provided in this application, the electronic device can perform compilation processing on the second physical address in the physical address group to convert each second physical address into runtime data structure data, thereby reducing the address storage space occupied by the second physical address and improving the processing efficiency of the second physical address.
[0121] In some implementations, compilation can be understood as a process of converting the format type of the second physical address in the physical address group. This process can convert the original format of the second physical address, which has a slower self-processing efficiency and a larger storage space, into a runtime data structure format that has a faster processing efficiency and a smaller storage space.
[0122] In some implementations, runtime data structure data can be understood as data format that has been compiled and processed to adapt to the operation logic of the target vector data packet processing node, and is convenient for fast comparison and lookup in memory.
[0123] In some implementations, the physical address group is stored using a hash table. It is understood that when storing the physical address group using a hash table, the complexity of finding a physical address within the physical address group can be O(1).
[0124] In some implementations, the runtime data structure data is 6 bytes in length.
[0125] Thus, in this embodiment of the application, the second physical address in the physical address group can be compiled into runtime data structure data, thereby enabling the second physical address in the physical address group to be processed as runtime data structure data, thereby reducing the address storage space occupied by the second physical address and improving the processing efficiency of the second physical address, and thus efficiently determining whether the first physical address is the second physical address in the physical address group.
[0126] In some embodiments of this application, the message processing method further includes: deleting the message processing rule in response to a rule deactivation command.
[0127] The message processing apparatus of this application embodiment further includes a deletion module. The deletion module is used to delete message processing rules in response to a rule deactivation command.
[0128] The processor 320 in this embodiment is also used to delete the message processing rule in response to a rule deactivation command.
[0129] Specifically, considering that users may need to disable the address filtering function, in some embodiments provided in this application, electronic devices can directly delete the message processing rules that have been sent to the target vector data packet processing node by responding to the rule disable command, thereby disabling the address filtering function.
[0130] In some implementations, a rule deactivation command can be understood as a user-triggered command used to delete message processing rules stored in the target vector packet processing node.
[0131] In one example, the aforementioned target page includes a switch control that determines whether the address filtering function is enabled. When the user sets the switch control to disable the address filtering function, an instruction is sent to delete the packet processing rules stored in the target vector packet processing node. Conversely, when the user sets the switch control to enable the address filtering function, steps such as obtaining physical address configuration data are executed to generate packet processing rules and send them to the target vector packet processing node.
[0132] Thus, in this embodiment of the application, a message processing rule can be deleted in response to a rule deactivation command, thereby deactivating the message processing rule.
[0133] Furthermore, for a clearer explanation of the implementation methods of this application, please refer to [link to relevant documentation]. Figure 7 , Figure 7 These are schematic diagrams illustrating application scenarios for certain embodiments of this application. Specifically, such as... Figure 7 As shown, the message processing method provided in this application can be implemented through a management plane and a data plane.
[0134] The management plane comprises two components: CLI / web / controller and the MAC FilterManager. CLI / web / controller provides users with the functionality to configure physical address data. Users can configure and confirm physical address data through CLI / web / controller, such as enabling filtering, setting the filtering direction of the blacklist to "LAN→WAN," etc. Furthermore, users can configure a specific physical address (i.e., a second physical address) to be added to the blacklist or whitelist through the MAC FilterManager. In addition, the MAC FilterManager can convert physical address configuration data (i.e., second physical address, list type, filtering direction, etc.) into packet processing rules (or access control list rules) that can be distributed to target vector packet processing nodes.
[0135] In the data plane, the Physical Address Group Manager is responsible for storing and maintaining physical address groups issued from the management plane, and has the function of determining whether an address belongs to a certain physical address group. The Access Control List node (i.e., the Destination Vector Packet Processing node) is responsible for receiving and storing the packet processing rules issued by the Physical Address Manager, and performing one of the following operations on the received packets: sending, dropping, or local response processing, according to the stored packet processing rules. The "Direction and Node Position Mapping Management" component manages the mapping relationship between the filtering direction and the first and second nodes in the Destination Vector Packet Processing node, enabling the first and second nodes to process packets using packet processing rules adapted to the filtering direction.
[0136] More specifically, in the management plane, users can configure and confirm physical address configuration data. After the user confirms the configuration of the physical address configuration data, the physical address group manager performs physical address group creation and maintenance, as well as packet processing rule generation, based on the physical address configuration data, and distributes the generated packet processing rules to the vector packet processing nodes in the data plane.
[0137] In the data plane, the physical address group manager matches the physical addresses provided by the vector packet processing nodes to determine whether the provided physical addresses belong to physical address groups previously created and maintained by the physical address group manager, and feeds back the matching results to the vector packet processing nodes. The vector packet processing nodes then perform one of the following operations based on the matching results from the physical address group manager: sending, dropping, or local response processing.
[0138] This application also provides a computer-readable storage medium storing a computer program that, when executed by one or more processors, implements the above-described message processing method.
[0139] This application also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the above-described message processing method.
[0140] In this specification, the terms "specifically," "furthermore," "particularly," "understandably," etc., refer to specific features, structures, materials, or characteristics described in connection with embodiments or examples that are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0141] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the function involved, as will be understood by those skilled in the art to which embodiments of this application pertain.
[0142] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A message processing method, characterized in that, The method includes: When the target vector data packet processing node receives a message to be processed, it obtains the target message information of the message to be processed, wherein the target message information includes a first physical address, a first message input interface and a first message output interface; The message to be processed is processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node, wherein the message processing rules are used to determine the target processing method corresponding to the target message information.
2. The message processing method according to claim 1, characterized in that, The message processing rules include a preset processing method, and a physical address group, a second message input interface, and a second message output interface corresponding to the preset processing method. The preset processing method is one of local response processing, sending processing, and discarding processing. The step of processing the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node includes: When the first physical address belongs to the physical address group, the first message input interface matches the second message input interface, and the first message output interface matches the second message output interface, the message to be processed is processed according to the preset processing method.
3. The message processing method according to claim 2, characterized in that, The method further includes: Obtain physical address configuration data, wherein the physical address configuration data includes a second physical address, a list type and a filtering direction, the list type is a blacklist or a whitelist, the filtering direction is a first direction or a second direction, the first direction includes from a local area network interface to a wide area network interface, and the second direction includes from a local area network interface to a wide area network interface and from a local area network interface to a local area network interface. Create the physical address group based on the second physical address; Based on the physical address group, the list type, and the filtering direction, packet processing rules are generated; The message processing rules are sent to the target vector data packet processing node.
4. The message processing method according to claim 3, characterized in that, The message processing rules include multiple rules, each corresponding to a filtering direction. The target vector data packet processing node includes a first node and a second node. The first node can perform message sending and discarding processing on received messages, and the second node can perform local response processing and discarding processing on received messages. The step of distributing the message processing rules to the target vector data packet processing node includes: The message processing rules corresponding to the first direction are sent to the first node; The message processing rules corresponding to the second direction are sent to the first node and the second node.
5. The message processing method according to claim 3, characterized in that, The method further includes: In response to the configuration operation of physical address configuration data, the physical address configuration data is obtained.
6. The method according to claim 3, characterized in that, The method further includes: The second physical address in the physical address group is compiled into runtime data structure data.
7. The method according to claim 1, characterized in that, The method further includes: In response to the rule deactivation command, the message processing rule is deleted.
8. A message processing apparatus, characterized in that, The device includes: The acquisition module is used to acquire the target message information of the message to be processed when the target vector data packet processing node receives the message to be processed, wherein the target message information includes a first physical address, a first message input interface and a first message output interface; The processing module is used to process the message to be processed according to the target message information and the message processing rules corresponding to the target vector data packet processing node, wherein the message processing rules are used to determine the target processing method corresponding to the target message information.
9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by one or more processors, implements the method of any one of claims 1-7.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method described in any one of claims 1-7.