Message forwarding method based on semantic perception, electronic equipment and storage medium
By acquiring business semantic attributes and compiling segment routing IPv6 policies, the problem that SRv6 networks cannot perceive the business connotation of data flows is solved, realizing fine-grained and adaptive data flow forwarding and improving the network's adaptability in complex business scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA ACADEMY OF INFORMATION & COMM
- Filing Date
- 2026-02-02
- Publication Date
- 2026-05-01
AI Technical Summary
The existing SRv6 network cannot deeply perceive the service semantic attributes of data streams, resulting in a disconnect between forwarding strategies and service requirements, making it difficult to achieve fine-grained forwarding that adapts to demand.
By acquiring the business semantic attributes of the target data stream, the segment routing IPv6 policy is compiled based on semantic intent, including a segment sequence composed of semantic function segments, to encapsulate and forward the data stream.
It has enabled the network to leap from 'network feature awareness' to 'business semantic awareness', improving the network's intelligent adaptability to complex business scenarios and providing refined and adaptive forwarding services.
Smart Images

Figure CN121967293A_ABST
Abstract
Description
A semantically aware message forwarding method, electronic device, and storage medium Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a semantically aware message forwarding method, electronic device, and storage medium. Background Technology
[0002] With the development of the Industrial Internet, intelligent manufacturing, fintech, and data element circulation system, the data carried by the network is no longer a simple bit stream, but a data object with clear business semantics, risk level, and process constraints, such as equipment control instructions, settlement transaction data, model inference results, and quality inspection data. These semantic attributes are generally expressed through information models.
[0003] However, existing segment routing over IPv6 (SRv6) packet forwarding methods mostly rely on network layer features such as IP address, 5-tuple, and QoS tags to formulate forwarding policies. They cannot deeply perceive the business semantic attributes and core requirements corresponding to the data flow, resulting in a disconnect between the forwarding policy and the network performance and processing requirements of the business. This makes it difficult to achieve fine-grained forwarding that adapts to demand, and the flexibility and adaptability are insufficient, failing to meet the differentiated forwarding needs under different business scenarios. Summary of the Invention
[0004] This invention provides a semantically aware message forwarding method, electronic device, and storage medium to solve the problem that existing SRv6 networks only support path programmability based on network characteristics, but cannot achieve service semantic awareness and adaptive programmable forwarding, resulting in a disconnect between forwarding strategies and service requirements.
[0005] According to one aspect of the present invention, a semantically aware packet forwarding method is provided, the method comprising: obtaining service semantic attributes corresponding to a target data stream; the service semantic attributes being semantic attributes determined from service objects defined by a preset information model based on the target data stream; determining the corresponding semantic intent based on the service semantic attributes; the semantic intent being used to characterize the network performance and processing requirements of the target data stream; compiling the semantic intent into a segment routing IPv6 policy; the segment routing IPv6 policy comprising a segment sequence consisting of at least one semantic function segment; and encapsulating and forwarding the target data stream according to the segment routing IPv6 policy.
[0006] According to another aspect of the present invention, a semantically aware packet forwarding apparatus is provided, the apparatus comprising: a semantic attribute acquisition module, configured to acquire service semantic attributes corresponding to a target data stream; the service semantic attributes are semantic attributes determined from service objects defined by a preset information model based on the target data stream; a semantic intent determination module, configured to determine the corresponding semantic intent based on the service semantic attributes; the semantic intent is used to characterize the network performance and processing requirements of the target data stream; a policy compilation module, configured to compile the semantic intent into a segment routing IPv6 policy; the segment routing IPv6 policy includes a segment sequence composed of at least one semantic function segment; and a forwarding module, configured to encapsulate and forward the target data stream according to the segment routing IPv6 policy.
[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the semantically aware message forwarding method according to any embodiment of the present invention.
[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the semantically aware message forwarding method according to any embodiment of the present invention.
[0009] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the semantically aware message forwarding method described in any embodiment of the present invention.
[0010] The technical solution of this invention involves obtaining the business semantic attributes corresponding to the target data stream. These business semantic attributes are determined from business objects defined in a preset information model based on the target data stream. Based on the business semantic attributes, the corresponding semantic intent is determined. The semantic intent characterizes the network performance and processing requirements of the target data stream. The semantic intent is compiled into a segment routing IPv6 policy. The segment routing IPv6 policy includes a sequence of segments composed of at least one semantic function segment. The target data stream is then encapsulated and forwarded according to the segment routing IPv6 policy. This technical solution deeply integrates the business semantic attributes derived from the information model with the SRv6 forwarding mechanism, achieving a leap from "network feature awareness" to "business semantic awareness" in the network. This effectively solves the problem that existing SRv6 networks cannot perceive and understand the business connotations of data streams, thus making it difficult to provide refined and adaptive forwarding services. This significantly improves the network's intelligent adaptability to complex business scenarios.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 is a flowchart of a semantically aware packet forwarding method according to Embodiment 1 of the present invention; Figure 2 is a technical architecture diagram of a semantically aware packet forwarding method according to Embodiment 2 of the present invention; Figure 3 is a flowchart of a semantically aware packet forwarding method according to Embodiment 2 of the present invention; Figure 4 is a structural schematic diagram of a semantically aware packet forwarding system according to Embodiment 3 of the present invention; Figure 5 is a structural schematic diagram of a semantically aware packet forwarding device according to Embodiment 4 of the present invention; Figure 6 is a structural schematic diagram of an electronic device implementing the semantically aware packet forwarding method of the present invention. Detailed Implementation
[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0016] Example 1: Existing SRv6 packet forwarding methods largely rely on network layer features such as IP addresses, five-tuples, and QoS tags to formulate forwarding strategies. Network devices cannot perceive the information model objects corresponding to the data and their business semantics, leading to the following problems: ① The network is "semantically insensitive" to different business data and cannot distinguish between data of different values and risk levels, such as control flow, production data flow, settlement flow, and model flow; ② Even if SRv6 has programmable forwarding capabilities, its segment sequence is still mainly statically configured by operations and maintenance or controllers based on topology and bandwidth planning, making it difficult to automatically adjust with changes in business semantics; ③ Although the upper-layer system can identify semantic information such as key equipment, key processes, and high-risk data based on the information model, this information cannot be transmitted to the network forwarding layer, resulting in a "model-network disconnect"; ④ In scenarios such as the Industrial Internet, trusted data spaces, and data element circulation, the security, timeliness, and reliability requirements of data strongly depend on their semantic attributes, and the existing network architecture cannot achieve fine-grained semantic protection.
[0017] Therefore, there is an urgent need for a new network technology that can directly map the business semantics in the information model to SRv6 forwarding behavior, so that the network can truly become a "model-executable infrastructure".
[0018] Figure 1 is a flowchart of a semantically aware packet forwarding method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where the information model is deeply integrated with the segment routing IPv6 (SRv6) programmable forwarding mechanism, thereby realizing network adaptive forwarding and scheduling based on service semantics. This method can be executed by a semantically aware packet forwarding device, which can be implemented in hardware and / or software and can be configured in an electronic device. As shown in Figure 1, the semantically aware packet forwarding method provided in Embodiment 1 specifically includes the following steps: S110, obtaining the service semantic attributes corresponding to the target data stream; the service semantic attributes are semantic attributes determined from the service objects defined by the preset information model according to the target data stream.
[0019] The target data stream can refer to network data traffic that needs to be transmitted in the network and undergo semantic awareness and forwarding optimization. Business semantic attributes can refer to a set of attributes that can characterize the business essence, core needs and characteristics of a business object, such as identifying whether a business object is a control instruction or a transaction record, its process stage, risk level, real-time requirements, etc.
[0020] A pre-built information model can refer to a pre-constructed data model or metadata framework used to standardize and structure the description of real-world business entities (such as equipment, orders, services, etc.), the relationships between them, and related attributes. A business object can refer to a specific instance defined in the pre-built information model, representing an entity with clear business significance (such as a specific machine tool or a production order), and possessing a set of semantic attributes describing its state and characteristics.
[0021] In this embodiment of the invention, for a target data stream to be processed in the network, the target business object associated with the target data stream can be found and determined from a preset information model based on its flow characteristics (such as traffic quintuple, device identifier, message topic, etc.), and the business semantic attributes that can reflect its business connotation and constraints can be extracted from the target object, such as object identifier, data category, process stage, risk level, real-time level, trust compliance level, etc.
[0022] S120. Based on the business semantic attributes, determine the corresponding semantic intent; the semantic intent is used to characterize the network performance and processing requirements of the target data stream.
[0023] Semantic intent can refer to network-side demand guidance generated based on business semantic attributes, used to clearly characterize the network performance and processing requirements of the target data stream. It is a bridge connecting the semantic side and the network side, and its content may include, but is not limited to, specific latency, jitter, packet loss rate targets, as well as whether specific processing actions such as security detection, audit mirroring, and path protection need to be performed.
[0024] In this embodiment of the invention, after obtaining the business semantic attributes corresponding to the target data stream, the multi-dimensional business semantic attributes can be converted into semantic intents that can be recognized and executed by the network side based on the pre-configured mapping logic or algorithm model, such as specific end-to-end performance targets, reliability requirements, security action requirements, and audit action requirements.
[0025] S130. Compile the semantic intent into a segment routing IPv6 policy; the segment routing IPv6 policy includes a sequence of segments consisting of at least one semantic function segment.
[0026] In SRv6, segment routing IPv6 (hereinafter referred to as SRv6) policies can refer to executable rules compiled based on semantic intent, used to guide network nodes to forward target data flows. These rules include an ordered sequence of segments and related mapping relationships. A segment sequence can refer to an ordered list of segment identifiers, used to guide data packets through different network nodes or service functions in a specified order for processing and forwarding. A semantic function segment can refer to a segment identifier in an SRv6 network that is assigned a specific service or processing semantic. This identifier instructs network nodes to perform specific forwarding actions or service functions corresponding to its semantics, such as, but not limited to, low-latency processing segments, high-reliability path segments, security detection segments, audit mirroring segments, and trusted processing segments.
[0027] In this embodiment of the invention, the semantic intent to be realized on the network side can be combined with the current network context, such as real-time topology, link bandwidth, node load, and dynamic resource status information such as the location of available service functions. Through a pre-configured mapping logic or algorithm model, the abstract semantic intent can be deconstructed and mapped into a series of semantic function segments with specific network functions. Then, according to the logical relationship and dependency order of each objective in the semantic intent, as well as the path and resource constraints in the network context, these semantic function segments are arranged into an ordered segment sequence. Finally, the generated segment sequence is bound to a globally unique policy identifier and encapsulated together into a complete policy object that can be recognized, managed, and distributed by the network system, namely the SRv6 policy. It fully defines the precise forwarding and processing path composed of semantic function segments in a specific order that the target data flow must follow in the network to realize the above-mentioned specific semantic intent, as well as the global identifier, version information, and related execution parameters (such as security detection parameters, mirroring policy parameters, etc.) of the path.
[0028] S140. Encapsulate and forward the target data stream according to the segment routing IPv6 policy.
[0029] In this embodiment of the invention, after the semantic intent is compiled into an SRv6 policy, it can be distributed to the network ingress node and the SRv6 control plane. The ingress node matches the flow characteristics of the target data flow with the SRv6 policies configured in the network to determine the SRv6 policy corresponding to the target data flow and obtain the segment sequence contained in the policy. Then, the ingress node encapsulates and modifies the original packet of the target data flow according to the matched SRv6 policy, that is, encapsulates the above segment sequence into the segment routing header of the packet to generate a target packet carrying the semantic policy, and sends the target packet to the network for transmission. Each network node that receives the packet will parse its segment routing header and find the currently needed... The node activates the semantic function segment and executes the specific action corresponding to that semantic function segment. For example, if the current segment is a security detection segment, the node will redirect the target packet to the security detection module for processing; if it is a low-latency processing segment, the node will schedule the target packet to the low-latency queue, and so on. After each semantic function segment's corresponding action is executed, the segment routing header pointer of the target packet is updated to point to the next segment. When all semantic function segments in the segment sequence have been processed, the last network node that executed the semantic function segment will strip the segment routing header of the target packet, restore it to a standard IPv6 packet, and finally route it to its original destination address, thus completing end-to-end network forwarding that conforms to semantic intent.
[0030] The technical solution of this invention deeply integrates the business semantic attributes derived from the information model with the SRv6 forwarding mechanism, realizing the leap from "network feature perception" to "business semantic perception" in the network. This effectively solves the problem that existing SRv6 networks cannot perceive and understand the connotation of data flow services, and therefore cannot provide refined and adaptive forwarding services. It significantly improves the network's intelligent adaptability to complex business scenarios.
[0031] Furthermore, based on the above embodiments of the invention, obtaining the business semantic attributes corresponding to the target data stream includes: determining the target business object mapped to the target data stream in the preset information model based on a preset object binding rule set; extracting business semantic attributes from the target business object; the business semantic attributes include at least one of the following: object identifier, data category, process stage, risk level, real-time level, and trust compliance level.
[0032] The preset object binding rule set can refer to a pre-configured set of logical rules used to associate network data stream feature identifiers (such as 5-tuples, message topics, device identifiers, etc.) with specific business object instances in the information model. The target business object can refer to the entity instance defined in the preset information model that corresponds to the target data stream to be processed in a business sense.
[0033] Object identifiers can refer to unique identification information used to distinguish different target business objects, and can be used to accurately locate the business entities corresponding to the data flow. Data categories can refer to the type of business data corresponding to the target data flow, such as control data, status data, transaction data, model data, log data, etc. Process stages can refer to the specific stage in the entire lifecycle of the business corresponding to the target data flow, such as the raw material warehousing stage, processing stage, and finished product outbound stage in a production process. Risk levels can refer to the risk levels classified based on factors such as the importance and data sensitivity of the target business object, used to indicate the security protection requirements of the data flow. Real-time levels can refer to the real-time levels classified based on the business requirements of the target business object, used to indicate the performance requirements of the data flow, such as forwarding latency and jitter. Trust and compliance levels can refer to the trust and compliance levels classified based on industry standards, corporate policies, etc., used to indicate whether the data flow needs to undergo de-identification, verification, mirroring, or other processing.
[0034] In this embodiment of the invention, for the target data stream to be processed in the network, its flow characteristics can be extracted, such as the traditional five-tuple (source IP, destination IP, source port, destination port, protocol type), or extended identifiers in specific business scenarios, such as MQTT topics, device IDs in industrial protocols, API interface names, business order numbers, etc.; then, these flow characteristics are matched with a pre-configured preset object binding rule set to determine the target business object mapped to the target data stream in the preset information model; next, a set of structures is read and extracted from the model definition corresponding to the target business object. The technical solution of this embodiment achieves accurate mapping between network data streams and business objects and standardized extraction of business semantic attributes through the synergistic effect of a preset object binding rule set and a preset information model. This breaks the traditional disconnect between network forwarding and business needs, and provides accurate and consistent business-level input for subsequent semantic intent determination and differentiated forwarding strategy compilation. It effectively supports intelligent and differentiated packet forwarding based on semantic awareness and improves the network's adaptability to diverse business needs.
[0035] Furthermore, based on the above embodiments of the invention, after obtaining the business semantic attributes, the method further includes: constructing a corresponding semantic description vector based on the business semantic attributes; and generating a corresponding semantic identifier based on the semantic description vector.
[0036] In this context, a semantic description vector can refer to a structured data object that encapsulates all the business semantic attributes required to describe a data stream according to a predetermined order and fields, forming a complete, machine-readable formal expression of the business meaning of that data stream. A semantic identifier can refer to a fixed-length unique identifier generated by performing specific operations (such as encoding or hashing) on the semantic description vector, used to efficiently and unambiguously represent and index a specific set of business semantics in a network system.
[0037] In this embodiment of the invention, after obtaining the business semantic attributes of the target data stream, the following steps may be included: (1) The obtained discrete business semantic attributes (such as object identifier, data category, risk level, etc.) are organized and integrated according to a predefined structured format to form a unified, machine-readable semantic description vector, which can comprehensively and unambiguously describe all the business semantic information carried by the target data stream.
[0038] (2) The semantic description vector obtained above is encoded or hashed to generate a globally unique semantic identifier. Furthermore, in order to support the evolution of the information model and the smooth upgrade of the strategy, this embodiment also introduces parameters such as version number and validity period for each semantic identifier to form a semantic directory entry; at the same time, in order to ensure cross-system semantic consistency, this embodiment can also perform "equivalence merging" on the semantics, that is, establish synonym relationships for entries from different system sources but with equivalent or mappable semantics, and maintain an alias set and mapping rules in the directory to avoid strategy fragmentation.
[0039] The technical solution of this embodiment realizes the digital representation of business semantics by constructing semantic description vectors, which solves the problem that business semantics are difficult to be directly processed by network devices. Then, by generating unique semantic identifiers, it realizes the accurate differentiation of data streams with different business characteristics, reduces the semantic information transmission overhead and matching latency, and supports the consistency management of semantics across systems. It provides a standardized and reusable semantic foundation for the subsequent intelligent recognition of semantic intent and the accurate compilation of SRv6 strategies, thereby improving the overall efficiency and reliability of the semantic awareness-based packet forwarding method.
[0040] Furthermore, based on the above embodiments of the invention, the corresponding semantic intent is determined based on business semantic attributes, including at least one of the following: determining the semantic intent based on a preset semantic policy rule set and semantic description vector; determining the semantic intent based on semantic identifiers and network historical performance data through a preset adaptive learning model; wherein the semantic intent is characterized by at least one of the following parameters: latency target, jitter target, packet loss target, bandwidth level, security action requirements, audit action requirements, and path preference.
[0041] In this embodiment, the preset semantic policy rule set can refer to a predefined set of mapping rules that specify how different combinations of business semantic attributes (or semantic description vectors generated from them) should be transformed into specific semantic intents. Network historical performance data can refer to a set of performance metrics associated with the semantic identifier of the target data stream, generated during its past forwarding in the network. Examples include latency, packet loss rate, bandwidth utilization, and security incident occurrence rate. The preset adaptive learning model can refer to a pre-trained machine learning model (such as a deep neural network or reinforcement learning agent) that can learn and output optimized semantic intent parameters based on the input semantic identifier and related network historical performance data to adapt to dynamically changing network environments.
[0042] Latency targets / jitter targets / packet loss targets refer to the maximum allowable latency, maximum latency jitter, and maximum packet loss rate threshold for end-to-end data flow transmission. These are specific standards for measuring whether network performance meets the required standards. Bandwidth class refers to a qualitative or quantitative description of the network bandwidth resources required by the data flow, such as different service levels like guaranteed bandwidth, priority bandwidth, and best-effort. Security action requirements refer to the set of security processing actions that must be performed on the data flow as specified in the semantic intent, such as intrusion detection, traffic encryption, and access control. Audit action requirements refer to the set of auditing and logging actions that must be performed on the data flow as specified in the semantic intent, such as mirroring all traffic to an auditing platform and recording flow logs at a 1% sampling rate. Path preferences refer to the preferred selection of data flow forwarding path characteristics, such as the lowest latency path, the highest reliability path, physically isolated paths, and the most cost-effective paths.
[0043] In this embodiment of the invention, the business semantic attributes obtained from the information model are converted into semantic intents that the network can understand and execute. This can be achieved in any of the following ways: (1) Rule matching method: The semantic description vector of the target data stream is matched with the pre-configured set of preset semantic policy rules. Based on the matched rule entries, the corresponding network performance and processing requirements are extracted and integrated into a structured semantic intent.
[0044] (2) Adaptive learning method: Collect historical network performance data associated with the semantic identifier of the target data stream, such as the latency, packet loss rate, bandwidth utilization rate, and security event occurrence rate of the target data stream in the past; input the semantic identifier and the corresponding historical network performance data into the preset adaptive learning model, and output the initial parameters of the semantic intent adapted to the current network state; at the same time, the initial parameters can be calibrated by combining real-time network load, link status and other dynamic information, and finally form a structured semantic intent.
[0045] The aforementioned semantic intent can be characterized by an intent profile, which consists of at least one of the following parameters: latency target, jitter target, packet loss target, bandwidth level, security action requirements, audit action requirements, and path preference.
[0046] The technical solution in this embodiment determines semantic intent through two flexible methods: rule matching and adaptive learning. This ensures that the intent complies with business specifications and Service Level Agreement (SLA) requirements, while also adapting to dynamic network changes, thus solving the pain point of transforming abstract business semantics into network requirements. At the same time, by parametrically representing semantic intent, it provides a standardized and identifiable input basis for subsequent compilation of SRv6 strategies. The flexible combination of the two methods also expands the applicability of the solution in different business scenarios, laying a core foundation for semantic-driven intelligent packet forwarding.
[0047] Furthermore, based on the above embodiments of the invention, the semantic intent is compiled into a segment routing IPv6 policy, including: generating a segment sequence according to preset compilation constraints based on the semantic intent, the current network topology and network resource status; wherein, the segment sequence includes at least one of the following semantic function segments: low latency processing segment, high reliability path segment, security detection segment, audit mirror segment, and trusted processing segment; configuring a unique policy identifier for the segment sequence, and establishing a mapping relationship between the semantic intent, the policy identifier and the segment sequence to form a segment routing IPv6 policy.
[0048] The current network topology can refer to the overall description of the connectivity and path reachability of nodes and links in the current network. Network resource status refers to the real-time availability and utilization of various network resources (such as link bandwidth, node processing capacity, queue buffers, current load, and performance metrics). Predefined compilation constraints refer to a set of predefined rules or logical conditions used to ensure that the generated scheme meets specific policy, security, or performance requirements when translating semantic intent into network paths and actions. A segment sequence can refer to a list of IPv6 addresses arranged in a predetermined order. In a segment routing (SRv6) architecture, each address in this list (i.e., the segment identifier SID) indicates the node or location that a data packet needs to reach sequentially or perform a specific function on the forwarding path. A policy identifier refers to a unique identifier assigned to a complete segment routing policy, used to index, manage, and reference the policy in the network control plane and data plane.
[0049] The low-latency processing segment can refer to a semantic function segment used to ensure the low-latency transmission requirements of the target data stream. The high-reliability path segment can refer to a semantic function segment used to ensure the high continuity and low packet loss transmission requirements of the target data stream. The security detection segment can refer to a semantic function segment used to perform security detection processing on the target data stream. The audit mirroring segment can refer to a semantic function segment used to perform mirroring and auditing logging processing on the target data stream. The trusted processing segment can refer to a semantic function segment used to perform trusted verification, de-identification, and other processing on the target data stream.
[0050] In this embodiment of the invention, the specific compilation process of the SRv6 strategy includes: (1) collecting three types of core input data required for strategy compilation: first, semantic intent, which is an abstract description of the network performance and processing requirements of the target data stream; second, the current network topology, which is the connection relationship and reachable path information of each node and link in the network; and third, the network resource status, which is the real-time running data such as link bandwidth, latency, packet loss rate, and node processing capability in the current network.
[0051] (2) Based on the specific requirements of semantic intent, combined with the current network topology and resource status, and according to the preset compilation constraints, suitable semantic function segments are selected from the preset set of semantic function segments, and the segments are generated by combining them in the execution order.
[0052] (3) Assign a unique policy identifier to the generated segment sequence. This identifier is used for network nodes to quickly identify and match the corresponding policy. At the same time, establish a one-to-one mapping relationship between semantic intent, policy identifier, and segment sequence to form a complete SRv6 policy that can be identified, issued, and managed by the network control system. It fully defines the end-to-end behavior of the target data flow in the IPv6 network.
[0053] The technical solution of this embodiment compiles abstract business semantic intent into standardized SRv6 policies, thereby achieving precise alignment between business requirements and network configuration. The generated policies not only meet the differentiated requirements of services for latency, reliability, and security, but also adapt to the current network topology and resource status. At the same time, by establishing unique policy identifiers and mapping relationships, the identification efficiency and traceability of policies are improved, laying a core foundation for the differentiated encapsulation and forwarding of subsequent packets.
[0054] Furthermore, based on the above embodiments of the invention, the preset compilation constraints include at least one of the following: if the semantic intent includes a security action requirement, then the segment sequence includes a security detection segment, and the next hop of the security detection segment is configured as a network node with security detection capability; if the semantic intent includes an audit action requirement, then the segment sequence includes an audit mirror segment, and the mirroring strategy parameters are configured for the audit mirror segment according to the audit strength in the audit action requirement; if the latency target in the semantic intent is lower than a preset latency threshold, then the segment sequence includes a low latency processing segment, and a path that meets the upper latency bound is selected for the segment sequence from the preset candidate path set; if the path preference in the semantic intent is high reliability, then the segment sequence includes a high reliability path segment, and a path combination with path protection or fault detour capability is selected for the segment sequence from the preset candidate path set.
[0055] Among these, network nodes with security detection capabilities can refer to network devices equipped with security modules such as firewalls and intrusion detection systems, capable of performing security detection operations on data flows. Audit strength can refer to parameters characterizing the audit granularity in audit action requirements, such as full mirroring or sampling mirroring. Mirroring policy parameters can refer to specific parameters used to configure audit mirroring operations, such as mirroring sampling rate and destination address of mirrored packets.
[0056] The candidate path set can refer to the set of all available forwarding paths in the network that have been pre-collected and stored. The latency upper bound can refer to the maximum latency limit allowed for low-latency data stream transmission. Path protection can refer to a path guarantee mechanism that automatically switches to a backup path when the primary path fails, through methods such as configuring primary and backup paths. Fault detour capability can refer to the ability of a path to avoid faulty nodes or links and select other available links to complete transmission.
[0057] In this embodiment of the invention, in order to generate an SRv6 policy segment sequence that meets the requirements of services and networks, at least one of the following preset compilation constraints can be adopted: (1) Security constraint: If the semantic intent includes security action requirements, the segment sequence must contain a security detection segment, and the next hop of the security detection segment is configured to be a network node with security detection capability, so as to ensure that the data flow completes the specified security detection operation during the forwarding process.
[0058] (2) Audit constraints: If the semantic intent includes audit action requirements, the segment sequence must include an audit mirror segment, and the mirror strategy parameters for the audit mirror segment should be configured according to the audit intensity in the audit action requirements, such as full mirror, the replication ratio of sampled mirror, sampling rate, etc.
[0059] (3) Delay constraint: If the delay target in the semantic intent is lower than the preset delay threshold, the segment sequence must contain a low-delay processing segment, and a path that satisfies the upper delay limit is selected for the segment sequence from the preset candidate path set.
[0060] (4) Reliability constraint: If the path preference in the semantic intent is high reliability, the segment sequence must contain high reliability path segments, and a path combination with path protection or fault detour capability is selected for the segment sequence from the preset candidate path set.
[0061] Furthermore, based on the above embodiments of the invention, the preset compilation constraints also include one of the following: if the real-time level in the business semantic attribute is a preset level, then the segment sequence includes a low-latency processing segment, and a path that meets the upper limit of latency is selected for the segment sequence from the preset candidate path set; if the risk level in the business semantic attribute is higher than a preset risk threshold, then the segment sequence includes a high-reliability path segment, and a combination of paths with path protection or fault detour capabilities is selected for the segment sequence from the preset candidate path set; if the business semantic attribute includes a risk level, then a path that meets the corresponding isolation requirements is selected for the segment sequence from the preset candidate path set according to the risk level.
[0062] In this embodiment of the invention, the segment sequence configuration can be further optimized by combining business semantic attributes. The corresponding preset compilation constraints also include one of the following: (3) Latency constraint: If the real-time level in the business semantic attribute is a preset level (such as strong real-time level), then the segment sequence must contain a low-latency processing segment, and a path that satisfies the upper limit of latency is selected for the segment sequence in the preset candidate path set.
[0063] (4) Reliability constraint: If the risk level in the business semantic attribute is higher than the preset risk threshold, the segment sequence must contain a highly reliable path segment, and a path combination with path protection or fault detour capability shall be selected for the segment sequence from the preset candidate path set.
[0064] (5) Isolation constraints: If the business semantic attributes include risk level, then select the path that meets the corresponding isolation requirements for the segment sequence from the preset candidate path set according to the risk level. For example, path isolation is performed according to different fault domains, different link groups, and different queues / slices based on the risk level, so as to realize the transmission isolation of data streams with different risk levels.
[0065] This embodiment not only achieves precise transformation of business requirements into network policies by setting various preset compilation constraints, ensuring the rigid implementation of various business requirements such as low latency, high reliability, and security auditing, but also realizes resource isolation of data streams with different risks through risk level isolation constraints, effectively improving the security and independence of data stream transmission. At the same time, it combines real-time network status to select the optimal path, further improving network resource utilization and policy execution efficiency.
[0066] Furthermore, based on the above embodiments of the invention, the encapsulation and forwarding of the target data flow according to the segment routing IPv6 policy includes: at the network entry node of the target data flow, matching the corresponding segment routing IPv6 policy based on the flow characteristics of the target data flow; encapsulating the segment routing header of the target data flow according to a preset semantic injection method to generate a target packet carrying a segment sequence; forwarding the target packet; wherein, when the target packet is forwarded in the network, the network nodes along the way perform corresponding processing actions according to the currently activated semantic function segments in the segment routing header; after all semantic function segments in the segment sequence have been executed, the target packet is forwarded to the destination according to the conventional IPv6 forwarding rules.
[0067] In this context, the network entry node refers to the first network device upon which the target data flow enters the network domain. It is responsible for identifying the data flow, matching policies, and performing initial semantic encapsulation. The preset semantic injection method refers to the specific implementation method of writing segment sequences into the target data flow packets. It is a means of binding business semantic instructions with packets, such as an indirect method of binding the flow with a policy identifier, or an explicit method of directly writing segment sequences.
[0068] The Segment Routing Header (SRH) is an extended header in IPv6 used to carry information such as segment sequence, guiding packets to be forwarded along a specified path and to perform specific operations. It is the key carrier for SRv6 technology to achieve programmable forwarding. A standard IPv6 forwarding rule refers to the standard process by which network devices query the routing table based on their IPv6 destination address to perform next-hop forwarding when a packet does not contain an SRH or when the segment sequence in the SRH has been completed. The currently active semantic function segment (SFS) refers to the SFS pointed to by the segment pointer in the SRH, which is the SFS that the current network node needs to perform processing actions on; it is an element in the segment sequence.
[0069] In this embodiment of the invention, the specific process of applying the compiled SRv6 policy to a specific data stream so that the semantics are propagated with the message in a native SRv6 manner includes: (1) When the target data stream arrives at the network's entry node (such as a border router or gateway), the node extracts the flow characteristics of the data stream (e.g., source IP, destination IP, 5-tuple, or device ID, message topic, etc. in an industrial scenario). Subsequently, the entry node uses its flow characteristics as the key to query the local policy mapping table, thereby matching the unique SRv6 policy pre-compiled for the data stream.
[0070] (2) Based on the matched SRv6 strategy, an SRH is added to the original packets of the target data stream according to the preset semantic injection method. The SRH carries a segment sequence corresponding to the matching strategy. The segment sequence consists of at least one semantic function segment, and each semantic function segment corresponds to a network processing requirement (such as low latency processing, security detection, etc.). This transforms the abstract business semantic requirements into SRv6 forwarding instructions that can be recognized by network nodes, enabling the data stream to be processed differently during transmission.
[0071] (3) The network entry node sends the encapsulated target packet into the network for forwarding. When the packet arrives at a network node, the node parses its SRH, reads the currently active semantic function segment (i.e., the SID pointed to by the current pointer in the segment list), and executes the predetermined action corresponding to the segment. After each node completes the action specified by its segment, it updates the SRH pointer and forwards the packet to the node indicated by the next segment in the segment sequence.
[0072] (4) When all semantic function segments in the segment sequence have been executed, that is, when the segment list in the SRH is exhausted, the network node will remove the SRH extension header. At this time, the packet is restored to a standard IPv6 packet, and the network will forward it to the destination according to its destination IP address and regular IPv6 forwarding rules (such as routing table lookup), thus completing the end-to-end transmission.
[0073] The technical solution of this embodiment achieves precise binding between business requirements and network forwarding actions through semantic-driven SRv6 policy encapsulation and segmented execution mechanism. It can provide differentiated forwarding processing services for different business data streams, effectively improve the transmission quality of high-priority services, and is compatible with the existing IPv6 network architecture, with the advantages of low-cost deployment and flexible expansion.
[0074] Furthermore, based on the above embodiments of the invention, the preset semantic injection method includes any one of the following: binding the target data stream with the policy identifier of the matched segment routing IPv6 policy, and inserting a segment routing header into the packets of the target data stream according to the segment routing IPv6 policy; inserting a segment routing header into the packets of the target data stream according to the segment sequence contained in the matched segment routing IPv6 policy, and setting a flag bit for indicating the processing parameters of the network node.
[0075] Among them, network node processing parameters can refer to the configuration information required for network nodes to execute semantic function segments, such as image sampling rate, security inspection level, etc.
[0076] In this embodiment of the invention, the application of SRv6 policy to the actual forwarding of data flow (i.e. semantic injection) can be achieved by one of the following two preset methods to ensure that semantic intent can drive network behavior: (1) Policy binding method: The network entry node establishes an association between the target data flow and the matched SRv6 policy identifier, and sends the association to the network data plane (such as forwarding chip, forwarding engine), and the network data plane automatically inserts an SRH carrying the segment sequence corresponding to the policy into the packet.
[0077] (2) Explicit encapsulation method: After the network ingress node matches the SRv6 policy, it will extract the compiled segment sequence (SIDList) from the policy. For each packet (or batch of packets) of the target data flow, the ingress node directly constructs and inserts an SRH after the original IPv6 header of the packet, and writes the extracted segment sequence into the segment list field of the header. While constructing the SRH, the ingress node can set a flag bit in the reserved field of the SRH according to the semantic intent corresponding to the SRv6 policy (such as security detection strength, audit sampling rate, low latency priority, etc.) to clearly indicate the specific processing parameters of subsequent network nodes.
[0078] The technical solution of this embodiment complements each other by adopting two preset semantic injection methods. It supports large-scale deployment scenarios where policies and forwarding are decoupled, reducing the operation and maintenance costs of policy iteration. It also supports the precise transmission of node processing parameters through flag bits, improving the execution efficiency and differentiated processing capabilities of semantic function segments. Ultimately, it achieves efficient conversion of semantic intent into packet forwarding actions, ensuring that the semantically aware SRv6 forwarding scheme has flexibility, accuracy, and scalability.
[0079] Furthermore, based on the above embodiments of the invention, the network nodes along the route perform corresponding processing actions according to the currently active semantic function segment in the segment routing header, including at least one of the following: if the currently active semantic function segment is a security detection segment, the target packet is imported into a preset security detection module for detection, and forwarded after the detection is completed; if the currently active semantic function segment is an audit mirror segment, the target packet is copied and sent to a preset audit system; if the currently active semantic function segment is a low-latency processing segment, the target packet is scheduled to a preset low-latency queue; if the currently active semantic function segment is a high-reliability path segment, a preset high-reliability path policy is enabled for the target packet; if the currently active semantic function segment is a trusted processing segment, the target packet is imported into a preset trusted processing module for processing.
[0080] The preset security detection module can refer to a functional module built into the network node that has security detection capabilities such as malicious traffic detection, protocol compliance verification, and access control. The preset audit system can refer to a dedicated audit system pre-designated in the network for receiving mirrored packets and performing log retention, behavior auditing, and compliance verification. The preset low-latency queue can refer to a queue pre-configured in the network node with high forwarding priority, used for transmitting latency-sensitive target packets. The preset high-reliability path policy can refer to a policy pre-configured in the network node to ensure the reliability of packet transmission, such as primary / backup path switching, faulty link rerouting, and multi-path redundant transmission. The preset trusted processing module can refer to a functional module built into the network node that has trusted processing capabilities such as signature verification, data integrity verification, and sensitive information de-identification.
[0081] In this embodiment of the invention, in the semantically aware SRv6 packet forwarding process, the process of the forwarding node performing differentiated processing on packets carrying semantic function segments specifically includes: (1) If the currently activated segment is the security detection segment, the built-in security detection process is triggered, the target packet is imported into the preset security detection module, and detection operations such as malicious traffic detection, protocol compliance verification, and access control are completed; after the detection is passed, the subsequent process continues to be executed.
[0082] (2) If the currently active segment is the audit mirror segment, the message mirroring process is triggered to copy the complete content or key fields of the target message and send the copied message to the preset audit system for log retention, behavior auditing or compliance verification.
[0083] (3) If the low-latency processing segment is currently active, the queue scheduling process is triggered to schedule the target packet from the normal forwarding queue to the preset low-latency queue and process it using the low-latency forwarding priority to reduce the packet forwarding latency.
[0084] (4) If the currently active path segment is a high-reliability path segment, the high-reliability forwarding process is triggered to enable the preset high-reliability path strategy for the target packet, such as operations including but not limited to primary and backup path switching, faulty link detour, and multi-path redundant transmission.
[0085] (5) If the currently active trusted processing segment is the trusted processing segment, the trusted verification process is triggered, the target message is imported into the preset trusted processing module, and trusted operations such as signature verification, data integrity verification, and sensitive information desensitization are completed.
[0086] The technical solution of this embodiment achieves differentiated processing of data streams with different business requirements by parsing and executing the processing actions corresponding to the semantic function segments during message forwarding. This not only ensures the low latency requirements of high real-time services and the transmission reliability of critical services, but also improves the security and compliance of data transmission through security detection, trusted processing, and audit mirroring. At the same time, it simplifies the processing logic of network nodes, improves the utilization rate of network resources, and ultimately achieves precise matching between business semantic requirements and network processing capabilities.
[0087] Furthermore, based on the above embodiments of the invention, the method further includes a policy adaptive update process, comprising: monitoring and collecting policy execution evaluation indicators after the target data flow is forwarded according to the segment routing IPv6 policy; and re-determining the segment routing IPv6 policy when the target data flow meets the preset policy adaptive update conditions; wherein the preset policy adaptive update conditions include any one of the following: the policy execution evaluation indicator does not reach the preset threshold, the network resource status undergoes a preset change, or the service semantic attributes are updated.
[0088] The policy adaptive update process refers to a closed-loop optimization process for already implemented SRv6 policies, involving monitoring their execution effects, determining update conditions, regenerating policies, and smoothly switching over. This process enables dynamic adaptation of policies to business needs and network conditions. Policy execution evaluation metrics refer to core parameters used to quantify the effectiveness of segment routing IPv6 policy execution. These metrics cover network performance, security, and auditing dimensions corresponding to semantic intent, such as latency compliance rate, packet loss rate, jitter, congestion count, security check hit rate, and audit coverage.
[0089] Preset policy adaptive update conditions can refer to a set of pre-configured judgment rules used to automatically trigger the policy optimization process, including at least the following conditions: policy execution evaluation indicators are not met, network resource status changes by a preset, and business semantic attributes are updated.
[0090] In this embodiment of the invention, the above-mentioned semantically aware message forwarding method may also include the following policy adaptive update process: (1) For the target data stream corresponding to the issued SRv6 policy, continuously collect policy execution evaluation indicators after forwarding according to the semantic identifier dimension, such as latency compliance rate, packet loss rate, jitter, congestion count, security check hit rate, audit coverage, etc.
[0091] (2) Detect whether the target data stream meets the preset policy adaptive update conditions. If any of the following conditions are met, the update process is triggered: ① At least one of the policy execution evaluation indicators has not reached the preset threshold, such as the latency compliance rate corresponding to the low latency intention is less than 99.9%; ② The network resource status has changed according to the preset conditions, such as link failure, queue overflow, bandwidth utilization exceeding the threshold, fault domain distribution adjustment, etc.; ③ The business semantic attributes have been updated, such as the risk level of the data stream has been upgraded, the real-time level has been adjusted, the process stage to which the business object belongs has been switched, etc.
[0092] (3) When the update conditions are met, the SRv6 policy determination process described in the previous embodiment is re-executed on the target data stream. That is, based on the updated business semantic attributes or network status, the corresponding semantic intent is re-determined; according to the new semantic intent, the current network topology and resource status, the segment sequence is regenerated according to the preset compilation constraints; a policy identifier is configured for the new segment sequence, and a new "semantic intent-policy identifier-segment sequence" mapping relationship is established to form the updated SRv6 policy. Then, the newly generated SRv6 policy can be distributed to the network entry node and take effect through a preset non-disruptive switching method (such as canary release / rollback mechanism) to replace or update the original policy, thereby realizing the dynamic adjustment and optimization of the target data stream forwarding behavior.
[0093] The technical solution in this embodiment achieves dynamic adaptation of SRv6 policies to service requirements and network conditions by introducing a closed-loop feedback and policy adaptive adjustment mechanism. This solves the pain point that traditional static policies are prone to substandard forwarding performance due to service changes or network failures. At the same time, hierarchical statistical evaluation indicators based on semantic identifiers ensure the accuracy of policy optimization and avoid interference between different service data streams. The uninterrupted switching method effectively ensures the continuity of service data stream forwarding, reduces the impact of policy iteration on network services, and ultimately improves the stability, adaptability, and engineering practicality of the semantically aware packet forwarding method.
[0094] Figure 2 of Embodiment 2 is a technical architecture diagram of a semantically aware packet forwarding method provided in Embodiment 2 of the present invention. Based on this technical architecture diagram, this embodiment provides an implementation method of a semantically aware packet forwarding method, aiming to solve the problem that existing SRv6 networks only support path programmability but not semantic programmability. Through an SRv6 semantically aware forwarding mechanism driven by an information model, the network can automatically generate and execute differentiated SRv6 forwarding and processing strategies according to the service object, process semantics, and risk level, realizing the leap from "network feature awareness" to "service semantic awareness" of the network. As shown in Figure 3, the semantically aware packet forwarding method provided in Embodiment 2 of the present invention specifically includes the following steps: S210, obtaining the semantic description vector corresponding to the target data stream.
[0095] This step is used to extract business semantics from the preset information model and establish a stable mapping relationship between the business semantics and the actual network data flow, providing input conditions for subsequent semantic policy compilation and SRv6 execution.
[0096] Assume the set of data streams to be processed in the network is For any data stream Its basic flow characteristics can be represented by quintuples or equivalent features: in, For data stream The flow characteristics are: SrcIP is the source IP address, DstIP is the destination IP address, SrcPort is the source port number, DstPort is the destination port number, and Proto is the protocol type.
[0097] In addition, in message bus / industrial protocol scenarios, extended keys can also be constructed using Topic, interface name, device identifier, etc. .
[0098] A collection of business object instances is defined on the preset information model side. Each business object instance It should include at least the following semantic attributes: ObjectID, DataClass, Stage, RiskLevel, TimeClass, and TrustClass.
[0099] To map data streams to business objects, the system is configured with a set of preset object binding rules. The rules may include, but are not limited to: ① Binding by system interface / service name: interface name → object type / object instance; ② Binding by device / production line topology: device ID → object instance; ③ Binding by data table / field definition: field / table → object semantics; ④ Binding by message topic: topic → object semantics; ⑤ Binding by session / business number: order number / work order number / batch number → object semantics.
[0100] According to the preset object binding rule set The following mapping relationship can be obtained, which is the data flow Bind to business object : ,in This represents a mapping function.
[0101] Furthermore, the semantic description vector can be constructed as follows: Based on the above stream-object binding process, the following information can be output: ① The binding table of the stream to the object. ② Semantic description vector set .
[0102] In summary, for the target data stream to be processed in the network, the corresponding target business object can be matched from the preset information model based on its flow characteristics (such as traffic quintuple, device identifier, message topic, etc.) through a preset object binding rule set, and the corresponding semantic description vector can be extracted from the object.
[0103] S220. Generate semantic identifiers based on semantic description vectors and establish semantic traceability relationships.
[0104] This step is used to transform the semantic description vector Standardize them into semantic identifiers that are identifiable, transmissible, and statistically significant on the network side, and establish an auditable version and lifecycle management mechanism.
[0105] In this embodiment of the invention, semantic description vectors can be... Using encoding / hash functions Generate semantic tags: To support the evolution of information models and the smooth upgrading of policies, this embodiment introduces parameters such as version number Ver and validity period TTL for each semantic identifier, forming semantic catalog entries: Here, Owner is the identifier of the entity that creates or owns this semantic entry; ObjectType is the type of business object, such as industrial equipment, transaction orders, etc.; CreateTime is the timestamp of the semantic directory entry being created, used for recording and auditing; AuditFlag is a boolean flag used to indicate whether the data stream associated with this SemanticID needs to be strongly audited or logged. For example, a flag of True indicates that all messages under this semantic must be fully mirrored and sent to the auditing system.
[0106] Meanwhile, to ensure semantic consistency across systems, this embodiment also performs "equivalence merging" on semantics, that is, it establishes synonym relationships for entries from different systems that are semantically equivalent or mappable, and maintains alias sets and mapping rules in the directory to avoid strategy fragmentation.
[0107] Thus, through the above semantic identifier generation and version management process, the following information can be output: ① Semantic catalog table (Includes SemanticID, version, and object semantic metadata); ② Semantic tracing relationship This is used for subsequent auditing and diagnosis.
[0108] In summary, the semantic attribute vector of the extracted target data stream can be encoded / hash to generate a unique semantic identifier, SemanticID.
[0109] S230, Generate the intended profile.
[0110] This step is used to convert "semantics" into "network executable intent (intent profile)" to form a unified input for SRv6 compilation.
[0111] In this embodiment of the invention, the data structure of the intent profile P can be represented as: P = (LatencyTarget, JitterTarget, LossTarge, BandwidthClass, PathClass, SecurityAction, AuditAction), where LatencyTarget (latency target) / JitterTarget (jitter target) / LossTarge (packet loss target) represent end-to-end performance targets; BandwidthClass represents bandwidth level; PathClass represents path preference (such as low latency / high reliability / low cost / isolation, etc.); SecurityAction represents security action requirements (such as detection, isolation, encryption, integrity verification, etc.); AuditAction represents audit action requirements (such as mirroring, sampling logging, full logging, etc.).
[0112] The intent profile P can be generated in any of the following ways: (1) Rule matching method: based on the parameter combination of DataClass, RiskLevel, TimeClass, and TrustClass, from the preset semantic strategy rule set. The corresponding intent profile is matched from the data.
[0113] (2) Adaptive learning method: Based on historical SLA compliance rate, link congestion, alarm events and other indicators, the system outputs an intent profile that adapts to the current network status through a preset adaptive learning model. For example, if there is a link congestion alarm, the PathClass priority is automatically increased or detour is enabled.
[0114] To ensure reusability in engineering applications, this embodiment can pre-set industry / scenario template libraries (such as control flow templates, transaction flow templates, model inference flow templates, etc.) and support hierarchical configuration by object type / device type / business line, forming a profile generation mechanism of "template-based + dynamic calibration".
[0115] Thus, the intent profile generation and construction process described above can output the following information: ① Semantic-to-intent mapping table ; ② The scope and version information of the intent profile, used for subsequent policy gray-scale deployment and rollback.
[0116] In summary, for a target data stream, a corresponding intent profile can be generated through rule matching or adaptive learning.
[0117] S240, Compile the intent profile into an SRv6 strategy.
[0118] This step is used to compile semantic intents into a native SRv6 executable forwarding / processing chain, avoiding simply remaining at the control plane external orchestration level.
[0119] In this embodiment of the invention, the SID address space of SRv6 can be divided into the following set of semantic function segments: in, This is a low-latency processing segment; For highly reliable path segments; For safety inspection section; For auditing mirror segments; This is a trusted processing segment.
[0120] For any semantic intent profile P, the policy compiler generates the following segment sequence based on the current network topology (Topo) and network resource state (State) (such as link latency, queue occupancy, packet loss, fault domain, etc.) according to preset compilation constraints: ,in Compile functions for the strategy.
[0121] Specifically, the preset compilation constraints may include, but are not limited to, any of the following: (1) Security constraint: If SecurityAction ≠ empty, then SID_List must contain a security detection segment. (2) Audit constraints: If AuditAction ≠ empty, then SID_List must contain audit mirror segments. And configure mirror strategy parameters according to audit intensity, such as full mirror, sampled mirror replication ratio, sampling rate, etc.; (3) Latency constraint: if TimeClass is strong real-time or LatencyTarget is lower than the preset latency threshold, then SID_List must contain low latency processing segments. And select the path that meets the upper limit of delay from the preset candidate path set; (4) Reliability constraint: If PathClass=high reliability or RiskLevel is higher than the preset risk threshold, then SID_List must contain high reliability path segments. , and select a path combination with protection / bypass capability (such as containing primary and backup sections or fault domain isolation constraints); (5) Isolation constraints (optional): perform path isolation for the semantic requirements of different RiskLevels (such as different fault domains, different link groups, different queues / slices), and the compiler generates SID_List that meets the isolation strategy under the constraint conditions.
[0122] After compilation, an SRv6Policy identifier (PolicyID) is generated, and a semantic policy distribution table is formed. At this point, the following information can be output through the above policy compilation process: ① the mapping relationship between the intent profile and the SRv6 policy (including SID stack mapping); ② the parameter package required for the SRv6 policy to be issued (PolicyID, SID_List, effective scope, version, etc.).
[0123] In summary, based on the intent profile corresponding to the target data stream, an ordered segment sequence can be generated by combining real-time network topology and resource status (such as link latency and bandwidth utilization) according to preset compilation constraints. A unique policy identifier is assigned to this segment sequence, establishing a one-to-one mapping relationship between semantic intent, policy identifier, and segment sequence, thereby forming a complete SRv6 policy that can be recognized, issued, and managed by the network control system.
[0124] S250. At the network entry point, semantic injection and SRv6 encapsulation are performed to generate the target message.
[0125] This step is used to apply semantic policies to specific data streams at the network entry point, enabling semantics to be propagated with packets in a native SRv6 manner.
[0126] In this embodiment of the invention, when the target data stream arrives at the network's ingress node, the node will query based on the stream characteristics of the target data stream. , and Information such as PolicyID and SID_List is matched to the corresponding SRv6 policy. Then, the ingress node adds an SRH to the original packet of the target data stream according to the matched SRv6 policy and any of the following preset semantic injection methods: (1) Policy binding method: The ingress node establishes an association between the target data stream and the matched SRv6 policy identifier, and sends the association to the network data plane, which automatically inserts an SRH carrying the segment sequence corresponding to the policy into the packet.
[0127] (2) Explicit encapsulation method: The entry node directly adds SRH to the original message of the target data stream, writes SID_List into the SRH, and sets relevant flag bits (such as mirror sampling rate, security level, etc.).
[0128] To ensure seamless switching, this embodiment also supports policy gray-scale, which means gradually switching traffic to different versions of the same SemanticID policy in proportion and rolling back to the old version in case of an anomaly.
[0129] In summary, through the above-described network access semantic injection and SRv6 encapsulation process, the output can be: an SRv6 packet sequence carrying SRH (i.e., the target packet) or a flow table entry with a policy already bound.
[0130] S260. Perform SRv6 semantic awareness execution on the target message.
[0131] This step is used to execute the actions corresponding to the semantic function segment during SRv6 forwarding, forming a semantic-driven processing pipeline.
[0132] In this embodiment of the invention, the network ingress node sends the encapsulated target packet into the network for forwarding, and the subsequent SRv6 nodes identify the currently active segment by parsing the SRH in the packet. And perform the corresponding action: If The target packet is then imported into a preset security detection module for detection (such as access control / maliciousness detection / protocol compliance verification), and after the detection is completed, it returns to the main forwarding chain to continue executing the next segment; if If so, the target message is copied and sent to the preset audit system, and semantic traceability tags (such as SemanticID, version, object ID, etc.) can be written; if If so, the target packet will be scheduled to a preset low-latency queue, and a low-latency path / link group will be preferred; if If so, a preset high-reliability path strategy is enabled for the target message, such as primary / backup selection, detour trigger threshold, and fault domain isolation; if The target message will then be imported into a preset trusted processing module for processing, such as signature / verification, integrity verification, desensitization / watermarking, etc.
[0133] Once all semantic function segments in the segment sequence have been executed, i.e., the segment list in the SRH is exhausted, the target packet reverts to a standard IPv6 packet. The network will then forward it to the destination according to its destination IP address and conventional IPv6 forwarding rules (such as routing table lookups), completing the end-to-end transmission. Simultaneously, semantic execution logs / counters can be recorded during packet forwarding for subsequent closed-loop optimization.
[0134] S270, monitor the effect of strategy execution and trigger closed-loop adaptive updates.
[0135] This step is used to form a closed loop of "semantics-network behavior-effects", enabling the strategy to be continuously optimized and adapted to dynamic changes in business / network.
[0136] In this embodiment of the invention, the system can statistically analyze SLA metrics and security / audit execution effectiveness (i.e., policy execution evaluation metrics) according to the SemanticID dimension, including but not limited to delay, packet loss rate, jitter, audit coverage, security hit rate, etc., and establish a semantic-level evaluation vector: When the target data flow is detected to meet any of the following preset policy adaptive update conditions, the SRv6 policy is redefined: ① at least one of the policy execution evaluation indicators has not reached the preset threshold; ② the network resource status has undergone preset changes, such as link failure, queue overflow, bandwidth utilization exceeding the threshold, or fault domain distribution adjustment.
[0137] ③ Business semantic attributes are updated, such as the risk level of data flow being upgraded, the real-time level being adjusted, or the process stage to which the business object belongs being switched.
[0138] After triggering the adaptive update, the system will perform a "profile recalculation → policy recompilation" process on the affected target data stream to generate a new SRv6 policy, and use a canary / rollback mechanism to ensure that the business is not interrupted.
[0139] In addition, this step will also output the updated version. With policy version records, and auditable traceable change chains.
[0140] The semantically aware packet forwarding method provided in this embodiment of the invention has at least the following beneficial effects: (1) It achieves the first native integration of information model semantics and SRv6 forwarding mechanism, enabling the network to have the ability to perceive service and data semantics: This solution maps and embeds semantic elements such as service objects, data types, stage attributes and risk levels in the information model into the segment routing mechanism of SRv6, so that the network no longer relies solely on IP and QoS at the forwarding level, but can directly identify the service meaning and semantic attributes corresponding to the data flow. This mechanism fundamentally solves the problem of existing networks "only recognizing addresses and not understanding services", and upgrades SRv6 from a traditional path-programmable network to a true semantically programmable network.
[0141] (2) A compilation mechanism of "semantics → intent → SRv6 segment sequence" is proposed to realize the computable mapping from business semantics to network behavior: This scheme transforms complex business semantics (such as real-time, security, reliability and compliance requirements) into executable SRv6 forwarding and processing links through the automatic compilation of semantic intent profiles and SRv6 segment sequences. This method transforms the network strategy that originally relied on manual planning or static configuration into an automated compilation process that is computable, verifiable and dynamically updatable, significantly improving the network's adaptability to complex business scenarios.
[0142] (3) Constructing a network adaptive closed loop driven by information model changes to achieve continuous alignment between network and service states: This solution introduces a semantic-level monitoring and closed-loop control mechanism. When the status of service objects, risk levels, or network resource conditions change, it can automatically trigger semantic intent recalculation and SRv6 policy recompilation, and take effect without interruption through gray-scale switching, so that network forwarding behavior can be adjusted synchronously with changes in the information model. This "model change drives network change" mechanism significantly improves the network's agility and stability in the face of dynamic service environments.
[0143] Figure 4 of Embodiment 3 is a schematic diagram of the structure of a semantically aware message forwarding system provided in Embodiment 3 of the present invention. As shown in Figure 4, the system includes an information model and semantic management subsystem 31, a semantic policy control and SRv6 compilation subsystem 32, and an SRv6 semantic execution and closed-loop feedback subsystem 33. The specific functions of each subsystem are described below.
[0144] (1) Information Model and Semantic Management Subsystem 31, used to uniformly model and manage business objects, data objects and their semantic attributes, and to provide computable and traceable semantic input to the network side. It includes at least the following functional modules: ① Information Model Management Module, used to store and manage business object models, data models and process models, support the maintenance of object instances, attribute fields, stage status and risk levels, and provide model version control and change notification functions.
[0145] ② The flow identification and object binding module is used to bind the actual network data flow with object instances in the information model based on features such as interface name, message topic, device identifier, service number or network flow 5-tuple, forming a one-to-one correspondence between data flow and business semantics.
[0146] ③ The semantic description and semantic identifier generation module is used to construct a semantic description vector for the bound data stream and generate a corresponding semantic identifier (SemanticID) based on the semantic description vector. At the same time, it maintains the version number, validity period and object information of the semantic identifier to support subsequent policy compilation and audit traceability.
[0147] (2) Semantic policy control and SRv6 compilation subsystem 32, which is used to convert the information model semantics into network executable SRv6 policies, is the core control module connecting the semantic layer and the network layer. It includes at least the following functional modules: ① Semantic intent generation module, which is used to generate a semantic intent profile containing latency targets, reliability requirements, security actions and audit requirements based on semantic identifiers and their semantic attributes, combined with preset semantic policy rules or adaptive learning models.
[0148] ② The semantic-to-SRv6 compilation module is used to combine the semantic intent profile with the current network topology and resource status to compile and generate the corresponding SRv6 segment sequence (SID stack) and SRv6 Policy, so that the semantic intent is transformed into a forwarding and processing link that can be executed in the network.
[0149] ③ The semantic policy publishing and version management module is used to distribute the generated SRv6 Policy and SID stack to the network entry node and SRv6 control plane, and to perform version management, gray-scale switching and rollback control of semantic policies to ensure business continuity when semantics changes or network fluctuations occur.
[0150] (3) SRv6 semantic execution and closed-loop feedback subsystem 33, deployed on the network data plane and monitoring plane, is used to perform SRv6 forwarding and processing according to semantics and to send the execution effect back to the control layer. It includes at least the following functional modules: ① Ingress semantic injection module, which is used to select the corresponding SRv6 Policy or directly insert SRv6 packet header according to the semantic identifier matched by the data flow when the data flow enters the network, so that the semantics are spread in the network in a native way with the data packet.
[0151] ②SRv6 semantic-aware forwarding nodes are used to parse the semantic function segments in the SRv6 packet header and execute forwarding, queue scheduling, security detection, audit mirroring or trusted processing operations corresponding to the semantic function segment, forming a semantic-driven forwarding and processing pipeline.
[0152] ③ The semantic execution monitoring and auditing module is used to collect data stream metrics such as latency, packet loss, congestion, security detection hit rate, and audit coverage according to the semantic identifier dimension, and generate traceable semantic-level network behavior records.
[0153] ④ The closed-loop optimization and adaptive module is used to trigger semantic intent recalculation and SRv6 policy recompilation when semantic-level SLA is not met, network state changes, or information model changes are detected, so as to achieve continuous adaptive alignment between network and service semantics.
[0154] This invention provides a semantically aware message forwarding system that can form an engineerable, deployable semantically aware network architecture, providing fundamental support for the industrial internet and data element circulation. Specifically, this solution also provides a systematic implementation scheme including information model management, semantic generation, SRv6 compilation, semantic execution, and auditing closed loop, supporting direct deployment in existing SRv6 networks and industrial information systems. This system can provide native-level low-latency, high-reliability, strong security, and auditable network capabilities for scenarios such as industrial control, financial transactions, data element circulation, and artificial intelligence data pipelines, providing critical network infrastructure support for new industrialization and data elementization.
[0155] Figure 5 is a schematic diagram of the structure of a semantically aware packet forwarding device provided in Embodiment 4 of the present invention. As shown in Figure 5, the device includes: a semantic attribute acquisition module 41, used to acquire the business semantic attributes corresponding to the target data stream; the business semantic attributes are semantic attributes determined from the business objects defined by the preset information model according to the target data stream; a semantic intent determination module 42, used to determine the corresponding semantic intent based on the business semantic attributes; the semantic intent is used to characterize the network performance and processing requirements of the target data stream; a policy compilation module 43, used to compile the semantic intent into a segment routing IPv6 policy; the segment routing IPv6 policy includes a segment sequence composed of at least one semantic function segment; and a forwarding module 44, used to encapsulate and forward the target data stream according to the segment routing IPv6 policy.
[0156] Furthermore, based on the above embodiments of the invention, the semantic attribute acquisition module 41 is specifically used to: determine the target business object mapped to the target data stream in the preset information model based on the preset object binding rule set; extract business semantic attributes from the target business object; the business semantic attributes include at least one of the following: object identifier, data category, process stage, risk level, real-time level, and trust compliance level.
[0157] Furthermore, based on the above embodiments of the invention, the device further includes: a semantic description vector construction module, used to construct a corresponding semantic description vector based on the business semantic attributes after obtaining the business semantic attributes; and a semantic identifier generation module, used to generate a corresponding semantic identifier based on the semantic description vector.
[0158] Furthermore, based on the above embodiments of the invention, the semantic intent determination module 42 is specifically used to: determine the semantic intent based on a preset semantic policy rule set and semantic description vector; determine the semantic intent based on semantic identifiers and network historical performance data through a preset adaptive learning model; wherein the semantic intent is characterized by at least one of the following parameters: latency target, jitter target, packet loss target, bandwidth level, security action requirements, audit action requirements, and path preference.
[0159] Furthermore, based on the above embodiments of the invention, the policy compilation module 43 is specifically used to: generate a segment sequence according to preset compilation constraints based on semantic intent, current network topology and network resource status; wherein, the segment sequence includes at least one of the following semantic function segments: low latency processing segment, high reliability path segment, security detection segment, audit mirror segment, and trusted processing segment; configure a unique policy identifier for the segment sequence, and establish a mapping relationship between semantic intent, policy identifier and segment sequence to form a segment routing IPv6 policy.
[0160] Furthermore, based on the above embodiments of the invention, the preset compilation constraints include at least one of the following: if the semantic intent includes a security action requirement, then the segment sequence includes a security detection segment, and the next hop of the security detection segment is configured as a network node with security detection capability; if the semantic intent includes an audit action requirement, then the segment sequence includes an audit mirror segment, and the mirroring strategy parameters are configured for the audit mirror segment according to the audit strength in the audit action requirement; if the latency target in the semantic intent is lower than a preset latency threshold, then the segment sequence includes a low latency processing segment, and a path that meets the upper latency bound is selected for the segment sequence from the preset candidate path set; if the path preference in the semantic intent is high reliability, then the segment sequence includes a high reliability path segment, and a path combination with path protection or fault detour capability is selected for the segment sequence from the preset candidate path set.
[0161] Furthermore, based on the above embodiments of the invention, the preset compilation constraints also include one of the following: if the real-time level in the business semantic attribute is a preset level, then the segment sequence includes a low-latency processing segment, and a path that meets the upper limit of latency is selected for the segment sequence from the preset candidate path set; if the risk level in the business semantic attribute is higher than a preset risk threshold, then the segment sequence includes a high-reliability path segment, and a combination of paths with path protection or fault detour capabilities is selected for the segment sequence from the preset candidate path set; if the business semantic attribute includes a risk level, then a path that meets the corresponding isolation requirements is selected for the segment sequence from the preset candidate path set according to the risk level.
[0162] Furthermore, based on the above embodiments of the invention, the forwarding module 44 is specifically used for: at the network entry node of the target data flow, matching the corresponding segment routing IPv6 policy based on the flow characteristics of the target data flow; encapsulating the segment routing header for the target data flow according to a preset semantic injection method to generate a target packet carrying a segment sequence; forwarding the target packet; wherein, when the target packet is forwarded in the network, the network nodes along the way perform corresponding processing actions according to the currently activated semantic function segments in the segment routing header; after all semantic function segments in the segment sequence have been executed, forwarding the target packet to the destination according to the conventional IPv6 forwarding rules.
[0163] Furthermore, based on the above embodiments of the invention, the preset semantic injection method includes any one of the following: binding the target data stream with the policy identifier of the matched segment routing IPv6 policy, and inserting a segment routing header into the packets of the target data stream according to the segment routing IPv6 policy; inserting a segment routing header into the packets of the target data stream according to the segment sequence contained in the matched segment routing IPv6 policy, and setting a flag bit for indicating the processing parameters of the network node.
[0164] Furthermore, based on the above embodiments of the invention, the network nodes traversed by the forwarding module 44 perform corresponding processing actions according to the currently active semantic function segment in the segment routing header, including at least one of the following: if the currently active semantic function segment is a security detection segment, the target packet is imported into a preset security detection module for detection, and forwarding continues after the detection is completed; if the currently active semantic function segment is an audit mirror segment, the target packet is copied and sent to a preset audit system; if the currently active semantic function segment is a low-latency processing segment, the target packet is scheduled to a preset low-latency queue; if the currently active semantic function segment is a high-reliability path segment, a preset high-reliability path policy is enabled for the target packet; if the currently active semantic function segment is a trusted processing segment, the target packet is imported into a preset trusted processing module for processing.
[0165] Furthermore, based on the above embodiments of the invention, the device further includes a policy adaptive update module, specifically used for: monitoring and collecting policy execution evaluation indicators after the target data flow is forwarded according to the segment routing IPv6 policy; and re-determining the segment routing IPv6 policy when the target data flow meets the preset policy adaptive update conditions; wherein the preset policy adaptive update conditions include any one of the following: the policy execution evaluation indicator does not reach the preset threshold, the network resource status undergoes a preset change, or the service semantic attributes are updated.
[0166] The semantically aware packet forwarding device provided in the embodiments of the present invention can execute the semantically aware packet forwarding method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0167] Figure 6 of Embodiment 5 illustrates a schematic diagram of an electronic device 50 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0168] As shown in Figure 6, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52 and a random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes based on the computer program stored in the ROM 52 or loaded into the RAM 53 from storage unit 58. The RAM 53 can also store various programs and data required for the operation of the electronic device 50. The processor 51, ROM 52, and RAM 53 are interconnected via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.
[0169] Multiple components in electronic device 50 are connected to I / O interface 55, including: input unit 56, such as keyboard, mouse, etc.; output unit 57, such as various types of monitors, speakers, etc.; storage unit 58, such as disk, optical disk, etc.; and communication unit 59, such as network card, modem, wireless transceiver, etc. Communication unit 59 allows electronic device 50 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0170] Processor 51 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 51 performs the various methods and processes described above, such as semantically aware message forwarding methods.
[0171] In some embodiments, the semantic-aware message forwarding method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the semantic-aware message forwarding method described above may be performed. Alternatively, in other embodiments, processor 51 may be configured to perform the semantic-aware message forwarding method by any other suitable means (e.g., by means of firmware).
[0172] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0173] In some embodiments, the semantic-aware message forwarding method can be implemented as a computer program, which is implicitly included in a computer program product. When executed by a processor, the computer program implements the semantic-aware message forwarding method of the present invention. The computer program product can be understood as a software product that primarily implements its solution through a computer program. The computer program used to implement the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer program causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer program can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0174] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0175] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0176] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0177] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0178] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0179] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A message forwarding method based on semantic awareness, characterized in that, The method includes: obtaining business semantic attributes corresponding to a target data stream; the business semantic attributes are semantic attributes determined from business objects defined by a preset information model based on the target data stream; determining a corresponding semantic intent based on the business semantic attributes; the semantic intent is used to characterize the network performance and processing requirements of the target data stream; compiling the semantic intent into a segment routing IPv6 policy; the segment routing IPv6 policy includes a segment sequence composed of at least one semantic function segment; and encapsulating and forwarding the target data stream according to the segment routing IPv6 policy.
2. The method according to claim 1, characterized in that, The step of obtaining the business semantic attributes corresponding to the target data stream includes: determining the target business object that the target data stream is mapped to in the preset information model based on a preset object binding rule set; extracting the business semantic attributes from the target business object; the business semantic attributes include at least one of the following: object identifier, data category, process stage, risk level, real-time level, and trust compliance level.
3. The method according to claim 1, characterized in that, After obtaining the business semantic attributes, the method further includes: constructing a corresponding semantic description vector based on the business semantic attributes; and generating a corresponding semantic identifier based on the semantic description vector.
4. The method according to claim 3, characterized in that, Determining the corresponding semantic intent based on the business semantic attributes includes at least one of the following: determining the semantic intent based on a preset semantic policy rule set and the semantic description vector; Based on the semantic identifier and historical network performance data, the semantic intent is determined by a preset adaptive learning model; wherein the semantic intent is characterized by at least one of the following parameters: latency target, jitter target, packet loss target, bandwidth level, security action requirements, audit action requirements, and path preference.
5. The method according to claim 1, characterized in that, The step of compiling the semantic intent into a segment routing IPv6 policy includes: generating the segment sequence based on the semantic intent, the current network topology, and the network resource status, according to preset compilation constraints; wherein the segment sequence includes at least one of the following semantic function segments: low-latency processing segment, high-reliability path segment, security detection segment, audit mirroring segment, and trusted processing segment; configuring a unique policy identifier for the segment sequence, and establishing a mapping relationship between the semantic intent, the policy identifier, and the segment sequence to form the segment routing IPv6 policy.
6. The method according to claim 5, characterized in that, The preset compilation constraints include at least one of the following: if the semantic intent includes a security action requirement, then the segment sequence includes a security detection segment, and the next hop of the security detection segment is configured to be a network node with security detection capability; if the semantic intent includes an audit action requirement, then the segment sequence includes an audit mirror segment, and the mirroring policy parameters are configured for the audit mirror segment according to the audit strength in the audit action requirement; if the latency target in the semantic intent is lower than a preset latency threshold, then the segment sequence includes a low latency processing segment, and a path that meets the upper latency bound is selected for the segment sequence from a preset candidate path set; if the path preference in the semantic intent is high reliability, then the segment sequence includes a high reliability path segment, and a path combination with path protection or fault detour capability is selected for the segment sequence from a preset candidate path set.
7. The method according to claim 6, characterized in that, The preset compilation constraints also include one of the following: if the real-time level in the business semantic attribute is a preset level, then the segment sequence includes a low-latency processing segment, and a path that meets the upper limit of latency is selected for the segment sequence from the preset candidate path set; if the risk level in the business semantic attribute is higher than a preset risk threshold, then the segment sequence includes a high-reliability path segment, and a path combination with path protection or fault detour capability is selected for the segment sequence from the preset candidate path set; if the business semantic attribute includes a risk level, then a path that meets the corresponding isolation requirements is selected for the segment sequence from the preset candidate path set according to the risk level.
8. The method according to claim 1, characterized in that, The encapsulation and forwarding of the target data flow according to the segment routing IPv6 policy includes: at the network entry node of the target data flow, matching the corresponding segment routing IPv6 policy based on the flow characteristics of the target data flow; encapsulating the segment routing header of the target data flow according to a preset semantic injection method to generate a target packet carrying the segment sequence; and forwarding the target packet. When the target packet is forwarded in the network, the network nodes along the route perform corresponding processing actions according to the currently active semantic function segment in the segment routing header; after all the semantic function segments in the segment sequence have been executed, the target packet is forwarded to the destination according to conventional IPv6 forwarding rules.
9. The method according to claim 8, characterized in that, The preset semantic injection method includes any of the following: binding the target data stream with the policy identifier of the matched segment routing IPv6 policy, and inserting the segment routing header into the packets of the target data stream according to the segment routing IPv6 policy; inserting the segment routing header into the packets of the target data stream according to the segment sequence contained in the matched segment routing IPv6 policy, and setting a flag bit for indicating network node processing parameters.
10. The method according to claim 8, characterized in that, The network nodes along the route perform corresponding processing actions based on the currently active semantic function segment in the segment routing header, including at least one of the following: if the currently active semantic function segment is a security detection segment, the target packet is imported into a preset security detection module for detection, and forwarded after the detection is completed; if the currently active semantic function segment is an audit mirror segment, the target packet is copied and sent to a preset audit system; if the currently active semantic function segment is a low-latency processing segment, the target packet is scheduled to a preset low-latency queue; if the currently active semantic function segment is a high-reliability path segment, a preset high-reliability path policy is enabled for the target packet; if the currently active semantic function segment is a trusted processing segment, the target packet is imported into a preset trusted processing module for processing.
11. The method according to claim 1, characterized in that, The method further includes a policy adaptive update process, comprising: monitoring and collecting policy execution evaluation indicators after the target data flow is forwarded according to the segment routing IPv6 policy; and re-determining the segment routing IPv6 policy when the target data flow meets the preset policy adaptive update conditions; wherein the preset policy adaptive update conditions include any one of the following: the policy execution evaluation indicators do not reach the preset threshold, the network resource status undergoes a preset change, or the service semantic attributes are updated.
12. An electronic device, characterized in that, The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the semantically aware message forwarding method according to any one of claims 1-11.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the semantically aware message forwarding method according to any one of claims 1-11.