Routing transmission method, device, system, equipment, storage medium and product
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2026-08-11
AI Technical Summary
对于复杂的传播场景,可能会出现误判的现象,导致错误拦截合法路由,造成网络中断的现象
Smart Images

Figure CN122554375A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technology, and in particular to a routing transmission method, apparatus, system, device, storage medium, and product. Background Technology
[0002] Border Gateway Protocol (BGP) is a routing protocol between Autonomous Systems (AS). An AS can advertise its own routing information via BGP update messages, and can also learn routing information by receiving BGP update messages from other ASs.
[0003] Security risks such as route hijacking, route leakage, or path hijacking may occur during the propagation of routing information. Currently, these risks can be mitigated through route origin validation (ROV), autonomous system provider authorization (ASPA), and only-to-customer (OTC) authentication methods.
[0004] However, in actual propagation processes, the strategies for disseminating routing information are quite complex. The route verification methods described above are applicable to simple propagation scenarios. In complex scenarios, misjudgments may occur, leading to the incorrect interception of legitimate routes and causing network outages. Summary of the Invention
[0005] This application provides a routing transmission method, apparatus, system, device, storage medium, and product that can enable legitimate routing information to avoid erroneous interception and maintain the continuity of network communication.
[0006] To achieve the above objectives, the embodiments of this application provide the following technical solutions:
[0007] Firstly, a routing transmission method is provided, which can be executed by a network device (hereinafter referred to as the first network device); or, it can be executed by a module applied in the first network device, such as a chip, chip system, or circuit; or, it can be implemented by a logic module or software capable of implementing all or part of the functions of the first network device, without limitation. For ease of description, the following explanation takes execution by the first network device as an example.
[0008] The method includes: receiving routing information from a second network device, the routing information indicating path information for accessing a routing prefix, and the routing information including tagging information indicating exemption from at least one routing verification. A first network device may respond to the tagging information by updating its routing table based on the routing information.
[0009] As can be seen from the above technical solution, after receiving routing information, the first network device can exempt the routing information from at least one routing verification based on the tagging information in the routing information. Thus, with the help of tagging information, routing verification can be exempted as needed, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication. Through tagging information, operators can more autonomously control the propagation path of routing information without being bound by routing verification, thereby achieving a more flexible routing announcement strategy.
[0010] In one alternative implementation, exempting the routing information from at least one route verification means: not performing at least one route verification on the routing information; or performing at least one route verification on the routing information, wherein the result of the route verification is valid, invalid, or not found.
[0011] The above technical solution provides two methods for exempting routing information from at least one route verification: one is not to perform at least one route verification on the routing information, and the other is to perform at least one route verification on the routing information, but regardless of whether the route verification result is legal, illegal, or unknown, the routing table is updated based on the routing information. This improves the flexibility of exempting the first network device from at least one route verification and expands the robustness of this solution.
[0012] In one alternative implementation, the route verification described above may include at least one of: ROV, ASPA, prefix filtering, OTC, or BGP security (sec).
[0013] The above technical solution describes route verification. The first network device can use tagging information to exempt at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec, which can improve the feasibility of this application. Furthermore, network devices can select at least one route verification method from ROV, ASPA, prefix filtering, OTC, or BGP sec as needed for exemption, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication.
[0014] In one alternative implementation, before receiving routing information from the second network device, the first network device may also send capability information (hereinafter referred to as first exemption capability information) to the second network device.
[0015] The first exemption capability information is used to indicate that the exemption capability of the first network device is enabled, and the exemption capability is used to exempt at least one route verification.
[0016] In the above technical solution, when the exemption capability of the first network device is enabled, it can also send capability information to the second network device to indicate that the exemption capability of the first network device is enabled. This ensures that the first network device can exempt itself from route verification when its exemption capability is enabled, thus guaranteeing the feasibility of this solution.
[0017] In one alternative implementation, the first network device may also receive capability information (hereinafter referred to as second exemption capability information) sent by the second network device.
[0018] The second exemption capability information is used to indicate that the exemption capability of the second network device is enabled, and the exemption capability is used to exempt at least one route verification.
[0019] In the above technical solution, when the exemption capability of the second network device is enabled, capability information indicating that the exemption capability of the second network device is enabled can also be sent to the first network device.
[0020] In an alternative implementation, the aforementioned capability information (such as first exemption capability information and second exemption capability information) may be carried in a BGP open message.
[0021] The above technical solution demonstrates that capability information can be carried in BGP open messages. BGP open messages are the first BGP messages sent by network devices after establishing a connection, thus ensuring the timeliness of capability information transmission.
[0022] In one alternative implementation, the routing information can be carried in a BGP update message, and the marking information can be carried in any of the community attribute, OTC attribute, optional transit attribute, or newly added path attribute of the BGP update message.
[0023] The above technical solution explains the carrying of tag information, that is, tag information can be carried in community attributes, OTC attributes, optional transit attributes or newly added path attributes in BGP update, thus improving the compatibility of this solution.
[0024] Secondly, a routing transmission method is provided, which can be executed by a network device (hereinafter referred to as the second network device); or, it can be executed by a module applied in the second network device, such as a chip, chip system, or circuit; or, it can be implemented by a logic module or software capable of implementing all or part of the functions of the second network device, without limitation. For ease of description, the following explanation uses execution by the second network device as an example.
[0025] The method includes sending routing information to a first network device. This routing information indicates path information for accessing a routing prefix, and includes tagging information indicating an exemption from at least one routing verification.
[0026] As can be seen from the above technical solution, the second network device can send routing information carrying tagging information to the first network device. Upon receiving the routing information, the first network device can exempt the routing information from at least one routing verification based on the tagging information within it. Thus, with the help of tagging information, routing verification can be exempted as needed, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication. Furthermore, through tagging information, operators can more autonomously control the propagation path of routing information without being bound by routing verification, enabling more flexible routing announcement strategies.
[0027] In one alternative implementation, exempting the routing information from at least one routing verification means: not performing at least one of the routing verifications on the routing information; or performing at least one routing verification on the routing information, wherein the result of the routing verification is legal, illegal, or unknown.
[0028] The above technical solution provides two methods for exempting routing information from at least one route verification: one is not to perform at least one route verification on the routing information, and the other is to perform at least one route verification on the routing information, but regardless of whether the route verification result is legal, illegal, or unknown, the routing table is updated based on the routing information. This improves the flexibility of exempting the first network device from at least one route verification and expands the robustness of this solution.
[0029] In one alternative implementation, the route verification described above may include at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec verification.
[0030] The above technical solution describes route verification. The first network device can use tagging information to exempt at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec, which can improve the feasibility of this application. Furthermore, network devices can select at least one route verification method from ROV, ASPA, prefix filtering, OTC, or BGP sec as needed for exemption, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication.
[0031] In one optional implementation, sending routing information to the first network device may specifically include: sending routing information carrying tagging information to the first network device when the tagging conditions are met.
[0032] The marking conditions may include at least one of the following: the AS from which the second network device is located does not have a business relationship to the AS where the first network device is located; the identifier of the originating AS in the routing information does not match the routing prefix; or the second network device has modified the path information for accessing the aforementioned routing prefix. The originating AS refers to the AS where the first network device that sent the aforementioned routing information is located.
[0033] The above technical solution further restricts the process of sending routing information to the first network device. Only when the marking conditions are met does the second network device need to include marking information in the routing information and send the marked routing information to the first network device. If the marking conditions are not met, the second network device does not need to include marking information in the routing information. This reduces the overhead of the second network device and lowers signaling consumption.
[0034] In an optional implementation, the method may further include: receiving capability information (i.e., the aforementioned first exemption capability information) sent by the first network device.
[0035] The first exemption capability information is used to indicate that the exemption capability of the first network device is enabled, and the exemption capability is used to exempt at least one route verification.
[0036] In the above technical solution, the second network device can also receive capability information sent by the first network device, indicating that the first network device's exemption capability is enabled. This ensures that the first network device can exempt route verification when the exemption capability is enabled, thus guaranteeing the feasibility of this solution.
[0037] In one alternative implementation, the second network device may also send capability information (i.e., the second exemption capability information described above) to the first network device.
[0038] The second exemption capability information is used to indicate that the exemption capability of the second network device is enabled, and the exemption capability is used to exempt at least one route verification.
[0039] In the above technical solution, when the exemption capability of the second network device is enabled, capability information indicating that the exemption capability of the second network device is enabled can also be sent to the first network device.
[0040] In one alternative implementation, the aforementioned capability information can be carried in a BGP open message.
[0041] The above technical solution demonstrates that capability information can be carried in BGP open messages. BGP open messages are the first BGP messages sent by network devices after establishing a connection, thus ensuring the timeliness of capability information transmission.
[0042] In one alternative implementation, the routing information can be carried in a BGP update message, and the marking information can be carried in any of the community attribute, OTC attribute, optional transit attribute, or newly added path attribute of the BGP update message.
[0043] The above technical solution explains the carrying of tag information, that is, tag information can be carried in community attributes, OTC attributes, optional transit attributes or newly added path attributes in BGP update, thus improving the compatibility of this solution.
[0044] Thirdly, a routing query method is provided, which can be executed by a first network device; or by a module applied in the first network device, such as a chip, chip system, or circuit; or by a logic module or software capable of implementing all or part of the functions of the first network device, without limitation. For ease of description, the following explanation uses execution by the first network device as an example.
[0045] The method includes: receiving query information from a second network device and sending a response message to the second network device.
[0046] The query information is used to indicate the AS where the network device that received the first routing prefix is located, and the response message contains the identifier of the AS where the network device that received the first routing prefix is located.
[0047] Through the above technical solution, the second network device can query the first network device for the identifier of the AS where the router receiving the first routing prefix resides. Thus, when subsequent issues arise where the routing prefix becomes inaccessible, maintenance personnel can quickly locate the fault using the identifier of the AS where the network device receiving the routing prefix resides, effectively improving the speed of fault location. Furthermore, the way the first network device responds to the query information and determines the AS where the network device receiving the routing prefix resides is on-demand querying; that is, it only determines the AS where the network device receiving the routing prefix resides when there is a query requirement. This reduces the communication overhead of the network devices.
[0048] In one alternative implementation, the query information can be carried in a BGP route refresh message.
[0049] The above technical solution describes how query information can be carried in a BGP route refresh message. This improves the feasibility of the proposed solution.
[0050] In one alternative implementation, the BGP route refresh message includes a first identifier, which indicates the type of the first route prefix.
[0051] The first routing prefix can be of type Internet Protocol version 4 (IPv4) or Internet Protocol version 6 (IPv6).
[0052] The above technical solution describes how BGP route refresh messages can also be used to indicate the type of the first route prefix. In this way, the first network device can accurately determine the route prefix to be queried (such as the first route prefix) based on the type of the first route prefix, and determine the identifier of the AS to which the network device receiving that route prefix belongs based on the route prefix to be queried. This can effectively improve the query efficiency of the first network device.
[0053] In one alternative implementation, the first identifier is carried in the address family or sub-address family (or address subfamily) of the BGP route refresh message.
[0054] The above technical solution describes the carrying method of the first identifier, that is, the first identifier can be carried in the address family or in the sub-address family, thus expanding the compatibility of this solution.
[0055] In one alternative implementation, the query information includes a first routing prefix, and at least one of the following: a first length field, the length of the first routing prefix, and the identifier of the AS to which the first network device sending the query information is located.
[0056] The first length field is used to indicate the length of the query information.
[0057] The above technical solution describes the fields contained in the query information. These fields help to determine the AS where the first network device (such as the second network device) that sent the query information is located, so that a response message can be quickly returned to the AS based on the field, thereby improving the speed of sending response messages.
[0058] In one alternative implementation, the response information is carried in a BGP route refresh message.
[0059] The above technical solution describes how response information can be carried in a BGP route refresh message, which can further improve the feasibility of this solution.
[0060] In one alternative implementation, the response information may further include the identifier of the AS where the first network device that sent the query information is located, the identifier of the AS where the first network device that sent the response information is located, or at least one of the second length fields.
[0061] The second length field is used to indicate the length of the response information.
[0062] The above technical solution describes the fields contained in the response information. These fields can not only determine the AS where the first network device that sent the response information (such as the first network device) is located, but also the AS where the network device that sent the query information (such as the second network device) is located. In this way, a response message can be quickly returned to the network device based on this field, thereby improving the response speed of the response message.
[0063] In one alternative implementation, before receiving query information from the second network device, the first network device may also send capability information (hereinafter referred to as first query capability information) to the second network device.
[0064] The first query capability information is used to indicate that the query capability of the first network device is enabled, and the query capability is used to query the AS where the network device that received the first routing prefix is located.
[0065] In the above technical solution, when the query capability of the first network device is enabled, it can also send capability information to the second network device to indicate that the query capability of the first network device is enabled. This ensures that the first network device, when its query capability is enabled, can query the AS where the network device receiving the route prefix to be queried belongs, thus ensuring the feasibility of this solution and improving the query efficiency of the first network device.
[0066] In one alternative implementation, the first network device may also receive capability information (hereinafter referred to as second query capability information) sent by the second network device.
[0067] The second query capability information is used to indicate that the query capability of the second network device is enabled, and the query capability is used to query the AS where the network device that received the first routing prefix is located.
[0068] In the above technical solution, when the query capability of the second network device is enabled, it can also send capability information to the first network device to indicate that the query capability of the second network device is enabled.
[0069] In one alternative implementation, the network device receiving the first routing prefix may include: a third network device and a network device that receives the first routing prefix sent by the third network device.
[0070] The third network device includes the network device that receives the first routing prefix sent by the first network device.
[0071] The above technical solution describes the network devices that receive the first routing prefix, which includes not only the network devices that receive the first routing prefix sent by the second network device, but also the network devices that receive the first routing prefix sent by the first network device. In this way, the comprehensiveness of the network devices that receive the first routing prefix can be guaranteed.
[0072] In one optional implementation, the response message may include a first response message containing an identifier of the AS where the third network device is located. The third network device includes the network device that received the first routing prefix sent by the first network device. Accordingly, sending a response message to the second network device may specifically include sending the first response message to the second network device.
[0073] The above technical solution provides a specific description of the response message, namely, the first network device can send a response message containing the identifier of the AS where the third network device is located to the second network device, namely the first response message. In this way, the feasibility of this application can be effectively improved.
[0074] In an optional implementation, the response message may further include a second response message, which contains the identifier of the AS to which the network device receiving the first routing prefix sent by the third network device resides; correspondingly, the method may further include: sending query information to the third network device and receiving a second response message from the third network device. Sending the response message to the second network device may further include: sending the second response message to the second network device.
[0075] The above technical solution further explains the response message, namely, the first network device can also send query information to the third network device to further query which AS the first routing prefix has been propagated to. In this way, the comprehensiveness of the network devices that received the first routing prefix can be guaranteed.
[0076] Fourthly, a routing query method is provided, which can be executed by a second network device; or by a module applied in the second network device, such as a chip, chip system, or circuit; or by a logic module or software capable of implementing all or part of the functions of the second network device, without limitation. For ease of description, the following explanation uses execution by the second network device as an example.
[0077] The method includes: sending query information to a first network device and receiving a response message from the first network device.
[0078] The query information is used to indicate the AS where the network device that received the first routing prefix is located, and the response message contains the identifier of the AS where the network device that received the first routing prefix is located.
[0079] Through the above technical solution, the second network device can query the first network device for the identifier of the AS where the router receiving the first routing prefix is located. Thus, when a routing prefix becomes inaccessible, maintenance personnel can quickly locate the fault using the identifier of the AS where the network device receiving the routing prefix is located, effectively improving the speed of fault location. Furthermore, the first network device's method of determining the AS where the network device receiving the routing prefix is located in response to the query information is on-demand querying; that is, it only determines the AS when there is a query requirement. This reduces the communication overhead of the network devices.
[0080] In one alternative implementation, the query information is carried in a BGP route refresh message.
[0081] The above technical solution describes how query information can be carried in a BGP route refresh message. This improves the feasibility of the proposed solution.
[0082] In one alternative implementation, the BGP route refresh message includes a first identifier, which indicates the type of the first route prefix.
[0083] The type of the first routing prefix can be either IPv4 or IPv6.
[0084] The above technical solution describes how BGP route refresh messages can also be used to indicate the type of the first route prefix. In this way, the first network device can accurately determine the route prefix to be queried (such as the first route prefix) based on the type of the first route prefix, and determine the identifier of the AS to which the network device receiving that route prefix belongs based on the route prefix to be queried. This can effectively improve the query efficiency of the first network device.
[0085] In one alternative implementation, the first identifier is carried in the address family or sub-address family of the BGP route refresh message.
[0086] The above technical solution describes the carrying method of the first identifier, that is, the first identifier can be carried in the address family or in the sub-address family, thus expanding the compatibility of this solution.
[0087] In one alternative implementation, the query information includes a first routing prefix, and at least one of the following: a first length field, the length of the first routing prefix, and the identifier of the AS to which the first network device sending the query information is located.
[0088] The first length field is used to indicate the length of the query information.
[0089] The above technical solution describes the fields contained in the query information. These fields help to determine the AS where the first network device (such as the second network device) that sent the query information is located, so that a response message can be quickly returned to the AS based on the field, thereby improving the speed of sending response messages.
[0090] In one alternative implementation, the response information is carried in a BGP route refresh message.
[0091] The above technical solution describes how response information can be carried in a BGP route refresh message, which can further improve the feasibility of this solution.
[0092] In one alternative implementation, the response information may further include the identifier of the AS where the first network device that sent the query information is located, the identifier of the AS where the first network device that sent the response information is located, or at least one of the second length fields.
[0093] The second length field is used to indicate the length of the response information.
[0094] The above technical solution describes the fields contained in the response information. These fields can not only determine the AS where the first network device that sent the response information (such as the first network device) is located, but also the AS where the network device that sent the query information (such as the second network device) is located. In this way, a response message can be quickly returned to the network device based on this field, thereby improving the response speed of the response message.
[0095] In one alternative implementation, before sending the query information to the first network device, the second network device may also receive capability information (i.e., the first query capability information mentioned above) sent by the first network device.
[0096] The first query capability information indicates that the query capability of the first network device is enabled. The query capability is used to query the AS to which the network device receiving the first routing prefix belongs.
[0097] In the above technical solution, the second network device can also receive capability information indicating that the query capability of the first network device is enabled. This ensures that the first network device, when its query capability is enabled, can query the AS where the network device receiving the route prefix to be queried belongs, thus ensuring the feasibility of this solution and improving the query efficiency of the first network device.
[0098] In one alternative implementation, the second network device may also send its own capability information (i.e., the second query capability information mentioned above) to the first network device.
[0099] The second query capability information is used to indicate that the query capability of the second network device is enabled, and the query capability is used to query the AS where the network device that received the first routing prefix is located.
[0100] In the above technical solution, when the query capability of the second network device is enabled, it can also send capability information to the first network device to indicate that the query capability of the second network device is enabled.
[0101] In one alternative implementation, the network device receiving the first routing prefix may include: a third network device and a network device that receives the first routing prefix sent by the third network device.
[0102] The third network device includes the network device that receives the first routing prefix sent by the first network device.
[0103] The above technical solution describes the network devices that receive the first routing prefix, which includes not only the network devices that receive the first routing prefix sent by the second network device, but also the network devices that receive the first routing prefix sent by the first network device. In this way, the comprehensiveness of the network devices that receive the first routing prefix can be guaranteed.
[0104] In one optional implementation, the response message may include a first response message containing an identifier of the AS where the third network device is located. The third network device includes the network device that received the first routing prefix sent by the first network device. Accordingly, receiving the response message from the first network device may specifically include: receiving the first response message from the first network device.
[0105] The above technical solution provides a specific description of the response message, namely, the first network device can send a response message containing the identifier of the AS where the third network device is located to the second network device, namely the first response message. In this way, the feasibility of this application can be effectively improved.
[0106] In an optional implementation, the response message may further include a second response message, which contains the identifier of the AS where the network device receiving the first routing prefix sent by the third network device is located; correspondingly, receiving the response message from the first network device may further include receiving the second response message from the first network device.
[0107] The above technical solution further clarifies the response message, namely, the response message may also include the identifier of the AS where the network device that received the first routing prefix sent by the third network device is located. In this way, the comprehensiveness of the network devices that received the first routing prefix can be guaranteed.
[0108] Fifthly, a connection establishment method is provided, which can be executed by a first network device; or by a module applied in the first network device, such as a chip, chip system, or circuit; or by a logic module or software capable of implementing all or part of the functions of the first network device, without limitation. For ease of description, the following explanation uses execution by the first network device as an example.
[0109] The method includes sending a BGP open message carrying role information to a second network device.
[0110] The role information indicates the business role of the AS where the first network device is located. The business role includes any one of mutual transit, partial transit customer, or partial transit provider.
[0111] In the above technical solution, BGP open messages can carry commercial roles such as mutual transit, partial transit customer, and partial transit provider. This expands the range of commercial roles carried by BGP open messages, ensuring the accuracy of commercial role configuration within the AS where the network device resides.
[0112] In one optional implementation, the AS where the first network device is located is called the first AS, and the AS where the second network device is located is called the second AS. If both the second AS and the first AS have a business role of mutual relay, the second AS uses the first AS as its supplier, and the first AS uses the second AS as its supplier. If the second AS has a business role of partially relaying customers, and the first AS has a business role of partially relaying suppliers, the second AS allows access to some of the first AS's neighboring ASes. If both the second AS and the first AS have a business role of partially relaying suppliers, the first AS allows access to some of the second AS's neighboring ASes.
[0113] The above technical solution describes the business roles of the AS where the first network device is located and the AS where the second network device is located, both of which are mutual transit, as well as the cases where one of the business roles of the AS where the first network device is located is a partial transit customer and the other is a partial transit provider. This can further ensure the accuracy of the business role configuration of the AS where the network device is located.
[0114] Sixthly, a connection establishment method is provided, which can be executed by a second network device; or by a module applied in the second network device, such as a chip, chip system, or circuit; or by a logic module or software capable of implementing all or part of the functions of the second network device, without limitation. For ease of description, the following explanation uses execution by the second network device as an example.
[0115] The method includes: receiving a BGP open message carrying role information from a first network device; and establishing a BGP connection with the first network device if the business role of the AS where the second network device is located successfully matches the business role of the AS where the first network device is located.
[0116] The role information is used to indicate the business role of the AS where the first network device is located; the business role includes any one of mutual transit, partial transit customer, or partial transit provider.
[0117] In the above technical solution, BGP open messages can carry commercial roles such as mutual transit, partial transit customer, and partial transit provider. This expands the range of commercial roles carried by BGP open messages, ensuring the accuracy of commercial role configuration within the AS where the network device resides.
[0118] In one optional implementation, the AS where the first network device is located is called the first AS, and the AS where the second network device is located is called the second AS. If both the second AS and the first AS have a business role of mutual relay, the second AS uses the first AS as its supplier, and the first AS uses the second AS as its supplier. If the second AS has a business role of partially relaying customers, and the first AS has a business role of partially relaying suppliers, the second AS allows access to some of the first AS's neighboring ASes. If both the second AS and the first AS have a business role of partially relaying suppliers, the first AS allows access to some of the second AS's neighboring ASes.
[0119] The above technical solution describes the business roles of the AS where the first network device is located and the AS where the second network device is located, both of which are mutual transit, as well as the cases where one of the business roles of the AS where the first network device is located is a partial transit customer and the other is a partial transit provider. This can further ensure the accuracy of the business role configuration of the AS where the network device is located.
[0120] In a seventh aspect, a routing transmission method is provided, which can be executed by a first network device; or, it can be executed by a module applied in the first network device, such as a chip, chip system, or circuit; or, it can be implemented by a logic module or software capable of implementing all or part of the functions of the first network device, without limitation. For ease of description, the following explanation uses execution by the first network device as an example.
[0121] The method includes: receiving routing information from a second network device, the routing information indicating path information for accessing a routing prefix, the routing information including first tagging information, the first tagging information indicating the execution of at least one routing protection mechanism on the routing information. The first network device may respond to the first tagging information and update its routing table based on the routing information.
[0122] The above technical solution allows for the configuration of routing protection mechanisms as needed, utilizing tagging information. This avoids unnecessary routing protection mechanisms from erroneously intercepting routing information, thus maintaining the continuity of network communication.
[0123] In one alternative implementation, the above-mentioned execution of at least one routing protection mechanism on the routing information may specifically include: performing at least one routing verification on the routing information; or, adding second tag information to the routing information, the second tag information being used for routing verification.
[0124] The above technical solution provides two methods for implementing routing protection mechanisms on routing information: one is to perform at least one routing verification on the routing information, and the other is to add a second tag for routing verification to the routing information. This improves the flexibility of the first network device in implementing routing protection mechanisms and expands the compatibility of this solution.
[0125] In one alternative implementation, the route verification described above may include at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec verification.
[0126] The above technical solution describes route verification. The first network device can use tagging information (such as first tagging information) to verify at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec, which can improve the feasibility of this application. Furthermore, network devices can select at least one route verification method from ROV, ASPA, prefix filtering, OTC, or BGP sec as needed, which can avoid unnecessary route verification from erroneously intercepting routing information and maintain the continuity of network communication.
[0127] In one optional implementation, the routing information can be carried in the BGP update message, and the first tagging information can be carried in any of the community attribute, OTC attribute, optional transit attribute, or newly added path attribute of the BGP update message.
[0128] The above technical solution describes how the first tag information can be carried in the community attribute, OTC attribute, optional transit attribute, or newly added path attribute in BGP update, thus improving the compatibility of this solution.
[0129] Eighthly, a routing transmission method is provided, which can be executed by a network device (hereinafter referred to as the second network device); or, it can be executed by a module applied in the second network device, such as a chip, chip system, or circuit; or, it can be implemented by a logic module or software capable of implementing all or part of the functions of the second network device, without limitation. For ease of description, the following explanation uses execution by the second network device as an example.
[0130] The method includes: sending routing information to a first network device, the routing information indicating path information for accessing a routing prefix, the routing information including first tagging information, the first tagging information indicating the execution of at least one routing protection mechanism on the routing information.
[0131] The above technical solution allows for the configuration of routing protection mechanisms as needed, utilizing tagging information. This avoids unnecessary routing protection mechanisms from erroneously intercepting routing information, thus maintaining the continuity of network communication.
[0132] In one alternative implementation, the above-mentioned execution of at least one routing protection mechanism on the routing information includes: performing at least one routing verification on the routing information; or, adding second tag information to the routing information, the second tag information being used for routing verification.
[0133] The above technical solution provides two methods for implementing routing protection mechanisms on routing information: one is to perform at least one routing verification on the routing information, and the other is to add a second tag for routing verification to the routing information. This improves the flexibility of the first network device in implementing routing protection mechanisms and expands the compatibility of this solution.
[0134] In one alternative implementation, the route verification described above may include at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec verification.
[0135] The above technical solution describes route verification. The first network device can use tagging information (such as first tagging information) to verify at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec, which can improve the feasibility of this application. Furthermore, network devices can select at least one route verification method from ROV, ASPA, prefix filtering, OTC, or BGP sec as needed, which can avoid unnecessary route verification from erroneously intercepting routing information and maintain the continuity of network communication.
[0136] In one alternative implementation, the routing information can be carried in the BGP update message, and the marking information can be carried in any of the community attribute, OTC attribute, optional transit attribute, or newly added path attribute of the BGP update message.
[0137] The above technical solution describes how the first tag information can be carried in the community attribute, OTC attribute, optional transit attribute, or newly added path attribute in BGP update, thus improving the compatibility of this solution.
[0138] In a ninth aspect, a routing transmission apparatus is provided, located in a first network device, comprising: modules for performing any of the methods provided in the first aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0139] The device includes a transceiver module and a processing module. The transceiver module receives routing information from a second network device. This routing information indicates path information for accessing a routing prefix, and includes tagging information indicating exemption from at least one routing verification. The processing module responds to the tagging information and updates the routing table of the first network device based on the routing information.
[0140] In a tenth aspect, a routing transmission apparatus is provided, located in a second network device, comprising: a modular functional unit for performing any of the methods provided in the second aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0141] The device includes a transceiver module. The transceiver module is used to send routing information to a first network device. This routing information indicates path information for accessing a routing prefix, and includes tagging information indicating that at least one routing verification is exempted from the routing information.
[0142] In the eleventh aspect, a routing query device is provided, which is located in a first network device and includes: a modular functional unit for performing any of the methods provided in the third aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0143] The device includes a transceiver module and a processing module. The transceiver module is used to receive query information from the second network device and to send response messages to the second network device.
[0144] In a twelfth aspect, a routing query apparatus is provided, located in a second network device, comprising: modules for performing any of the methods provided in the fourth aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0145] The device includes a transceiver module. This transceiver module is used to send query information to a first network device and to receive response messages from the first network device.
[0146] In a thirteenth aspect, a connection establishment apparatus is provided, located in a first network device, comprising: modules for performing any of the methods provided in the fifth aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0147] The device includes a transceiver module and a processing module. The transceiver module is used to send BGP open messages carrying role information to the second network device. The role information indicates the business role of the AS to which the first network device belongs. The business role includes any one of mutual transit, partial transit customer, or partial transit provider.
[0148] In a fourteenth aspect, a connection establishment apparatus is provided, the apparatus being located in a second network device, comprising: modules for performing any of the methods provided in the sixth aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0149] The device includes a transceiver module. The transceiver module and the processing module are used to receive BGP open messages carrying role information from the first network device. The processing module is used to establish a BGP connection with the first network device if the business role of the AS where the second network device is located successfully matches the business role of the AS where the first network device is located.
[0150] In a fifteenth aspect, a routing transmission apparatus is provided, located in a first network device, comprising: modules for performing any of the methods provided in the seventh aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0151] The device includes a transceiver module and a processing module. The transceiver module receives routing information from a second network device. This routing information indicates path information for accessing a routing prefix. The routing information includes first tagging information, which indicates the execution of at least one routing protection mechanism. The processing module responds to the first tagging information and updates the routing table of the first network device based on the routing information.
[0152] In a sixteenth aspect, a routing transmission apparatus is provided, located in a second network device, comprising: modules for performing any of the methods provided in the eighth aspect, wherein the actions performed by each module are implemented by hardware or by hardware executing corresponding software.
[0153] The device includes a transceiver module. The transceiver module is used to send routing information to a first network device. The routing information indicates path information for accessing a routing prefix. The routing information includes first tagging information, which indicates the execution of at least one routing protection mechanism on the routing information.
[0154] In a seventeenth aspect, a communication system is provided, comprising a first network device and a second network device. The first network device is used to execute any one of the methods provided in the first, third, fifth, or seventh aspects, and the second network device is used to execute any one of the primary / standby switching methods provided in the second, fourth, sixth, or eighth aspects.
[0155] Eighteenthly, a network device is provided, including a memory and a processor, the memory for storing program code and the processor for calling the program code to execute any one of the methods provided in the first, second, third, fourth, fifth, sixth, seventh, or eighth aspects.
[0156] Nineteenthly, a computer-readable storage medium is provided, including computer-executable instructions that, when executed on a computer, cause the computer to perform any one of the methods provided in the first, second, third, fourth, fifth, sixth, seventh, or eighth aspects.
[0157] In a twentieth aspect, a computer program product is provided, the computer program product including instructions, which, when executed on a computer, cause the computer to perform any one of the methods provided in the first, second, third, fourth, fifth, sixth, seventh, or eighth aspects.
[0158] It should be noted that the technical effects of any of the implementation methods in aspects nine to twentieth can be found in the technical effects of the corresponding implementation methods in aspects one to eight, and will not be repeated here. Attached Figure Description
[0159] Figure 1 This is a schematic diagram of the legitimate publishing model and route leakage model provided in related technologies;
[0160] Figure 2 This is a schematic diagram illustrating the transmission of routing information provided in related technologies;
[0161] Figure 3 This is a schematic diagram illustrating the interaction between AS and RPKI servers provided in related technologies.
[0162] Figure 4 This is a schematic diagram of ASPA provided in related technologies;
[0163] Figure 5 A system architecture diagram of a communication system provided in this application embodiment;
[0164] Figure 6 This is a schematic diagram of the structure of a routing transmission device provided in an embodiment of this application;
[0165] Figure 7 A schematic diagram of the interaction flow of a routing transmission method provided in an embodiment of this application;
[0166] Figure 8 A schematic diagram of network device interaction provided in an embodiment of this application;
[0167] Figure 9 This is another schematic diagram of network device interaction provided in an embodiment of this application;
[0168] Figure 10 A schematic diagram of the interaction flow of a connection establishment method provided in an embodiment of this application;
[0169] Figure 11 A schematic diagram of the interaction flow of a routing query method provided in an embodiment of this application;
[0170] Figure 12 This is another schematic diagram of network device interaction provided in an embodiment of this application;
[0171] Figure 13 This is a schematic diagram of the structure of a first network device provided in an embodiment of this application;
[0172] Figure 14 This is a schematic diagram of the structure of a second network device provided in an embodiment of this application. Detailed Implementation
[0173] In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.
[0174] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0175] "Used for indication" can include direct and indirect indications, as well as explicit and implicit indications. When describing "indication information used to indicate A" or "indication information of A," it can include whether the indication information directly or indirectly indicates A, but does not necessarily mean that the indication information carries A. The information indicated by a certain piece of information is called the information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as, but not limited to, directly indicating the information to be indicated, such as the information to be indicated itself or its index. It can also indirectly indicate the information to be indicated by indicating other information, where there is a relationship between the other information and the information to be indicated. It can also indicate only a part of the information to be indicated, while the other parts are known or pre-agreed. At the same time, it is possible to identify the common parts of various pieces of information and unify the indication to reduce the indication overhead caused by individually indicating the same information. Furthermore, the specific indication method can also be any existing indication method, such as, but not limited to, the above-mentioned indication methods and their various combinations. Specific details of various indication methods can be found in existing technologies, and will not be elaborated upon here.
[0176] It is understood that the term "embodiment" used throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, throughout the specification, various embodiments do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0177] In this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. The following embodiments of this application do not constitute a limitation on the scope of protection of this application.
[0178] BGP is a routing protocol for communication between ASs (Autonomous Systems). An AS can advertise its own routing information via BGP update messages, and can also learn routing information by receiving BGP update messages from other ASs. Routing information includes route prefixes and path attributes. One type of path attribute is the AS path. During the routing information advertising process (also known as the route advertisement process), the AS path contains the identifier of each AS that received the routing information (hereinafter referred to as the AS identifier). The AS identifier is used to uniquely identify an AS.
[0179] For example, suppose AS1 intends to advertise route information 'a'. AS1 can generate a BGP update message carrying route information 'a' and send it to AS2. After receiving the BGP update message, AS2 sends a BGP update message to AS3. After receiving the BGP update message, AS3 sends a BGP update message to AS4. At this time, the AS Path in the BGP update message received by AS4 contains the AS identifiers of AS1, AS2, and AS3.
[0180] Assume AS1 has an AS identifier of 1, AS2 has an AS identifier of 2, and AS3 has an AS identifier of 3. The AS Path in the BGP update message received by AS4 is [3, 2, 1]. Furthermore, if AS4 intends to continue sending this BGP update message, it can add its own AS identifier to the AS Path of the BGP update message.
[0181] During the route announcement process, security risks such as route hijacking, route leakage, or path hijacking may occur. Route hijacking, path hijacking, and route leakage will be described in detail below.
[0182] Route hijacking occurs when an AS (Autonomous System) advertises a local route prefix to other ASs, misdirecting traffic destined for that route prefix to its own AS, thus hijacking traffic. The originating AS is the first AS to advertise a particular route prefix to other ASs. Route hijacking can also be called origin hijacking.
[0183] Path hijacking: The phenomenon of altering the AS Path in routing information.
[0184] For example, AS4 receives a routing message with AS Path = [3, 2, 1], and AS4 intends to send this routing message to its neighbor AS5. Before sending the routing message to its neighbor AS5, AS4 adds its own AS identifier (let's say AS4) to the AS Path, resulting in AS Path [4, 3, 2, 1], and then changes the AS Path from [4, 3, 2, 1] to [4, 1]. After receiving this routing message, AS5 can choose to access the corresponding routing prefix via the path from AS4 to AS1. However, in reality, there may be no business relationship between AS1 and AS4, meaning that the link from AS4 to AS1 does not exist. This will cause AS5 to be unable to access the corresponding routing prefix. Accessing the routing prefix refers to accessing the network indicated by that routing prefix.
[0185] Route leakage: When ASs send routing information to each other, it is necessary to consider whether the AS sending the routing information (hereinafter referred to as the sending AS) and the AS receiving the routing information (hereinafter referred to as the receiving AS) meet the preset propagation rules (intercommunication rule). If the sending AS and the receiving AS do not meet the preset propagation rules, it is considered that the sending AS and the receiving AS do not have a commercial relationship (or are not considered to have a commercial relationship). In this case, if the sending AS sends routing information to the receiving AS, it will cause route leakage.
[0186] Two Autonomous Systems (AS) can have various business relationships, such as simple and complex ones. Simple business relationships can include provider-to-customer (P2C, where the sending AS is the provider and the receiving AS is the customer), customer-to-provider (C2P, where the sending AS is the customer and the receiving AS is the provider), and peer-to-peer (P2P, where both the sending and receiving ASs are peers). Complex business relationships can include sibling relationships, hybrid relationships, and partial transit customer relationships.
[0187] The commercial role of an AS is relative, and each AS can include multiple commercial roles. For example, if AS1 sends routing information to AS2 and AS2 sends routing information to AS3, AS2's commercial role relative to AS1 can be customer, or it can be described as AS2 being a customer AS of AS1. Relative to AS3, AS2's commercial role can be provider, or it can be described as AS2 being a provider AS of AS3.
[0188] Table 1 below lists the propagation rules for routing information corresponding to the simple business relationships described above. "Pass" indicates that transmission is allowed, and "block" indicates that transmission is not allowed. As shown in Table 1, when an AS receives routing information from its customer AS, it can forward that routing information to its customer AS, peer AS, or provider AS. When an AS receives routing information from its peer AS or provider AS, it can forward that routing information to its customer AS, but it cannot forward the routing information to its peer AS or provider AS.
[0189] Table 1
[0190] rules of propagation to customer to peer to provider from customer pass pass pass from peer pass block block from provider pass block block
[0191] To more clearly illustrate the above propagation rules, the following example illustrates how ASes with the same business role are placed at the same level, and how ASes with the business role of provider are placed above ASes with the business role of customer. Figure 1 The examples show the valley-free and route-leaking models. Figure 1 As shown, AS in tier1 (such as Figure 1 AS11 and AS12 shown are AS in tier 2 (e.g.) Figure 1 The providers shown are AS21, AS22, and AS23. The AS in tier 2 is the AS in tier 3 (e.g., AS21, AS22, and AS23). Figure 1 The provider shown in AS31, AS32 and AS33).
[0192] See Figure 1 The legal distribution model shown in (a) indicates that no route leakage occurred during the transmission of the routing information if the transmission path conforms to any one of the following: uphill distribution model, downhill distribution model, or single-peak distribution model. The uphill distribution model refers to the transmission of routing information from the lower layer to the upper layer, such as... Figure 1The path shown in (a) is ①. The downhill publishing model, where routing information is transmitted from the upper layer to the lower layer, is as follows: Figure 1 Path ② is shown in (a) in the diagram. The single-peak distribution model means that routing information is first transmitted from the lower layer to the upper layer, and then back to the lower layer, as shown in the diagram. Figure 1 The path shown in (a) is either ③ or ④.
[0193] See Figure 1 The routing leakage model shown in (b) indicates that routing information leakage has occurred during transmission when the transmission path conforms to any of the following: valley distribution model, parallel distribution model, or semi-valley distribution model. Specifically, the valley distribution model means that routing information is transmitted from the upper layer to the lower layer, and then back to the upper layer, as shown in (b). Figure 1 Path ⑤ is shown in (b) in the diagram. This is a parallel publishing model, where routing information is transmitted between layers within the same layer, and the AS (Aspect Ratio) of the routing information path is greater than 2, such as... Figure 1 The path shown in (b) is ⑥. The semi-valley publishing model means that routing information is first transmitted from the upper layer to the lower layer (or from the lower layer to the upper layer), and then transmitted between layers within the same layer, such as... Figure 1 The path shown in (b) is ⑦ or ⑧.
[0194] To reduce security risks during the route announcement process, route verification methods have emerged.
[0195] Currently, route hijacking can be prevented through route authentication methods such as ROV or prefix filtering. Route leakage can be prevented through route authentication methods such as OTC or ASPA. Path hijacking can be prevented through route authentication methods such as ASPA or BGP security (sec).
[0196] The above route verification methods will be described one by one below.
[0197] ROV: An AS stores a mapping between AS identifiers and route prefixes. When an AS receives routing information from a neighboring AS, it can match the route prefix in the routing information with the AS identifier of the originating AS based on its stored mapping. If the route prefix in the routing information matches the AS identifier of the originating AS, the routing information is determined to be a valid route. If the route prefix in the routing information does not match the AS identifier of the originating AS, the routing information is determined to be an invalid route.
[0198] Prefix filtering: An AS can store multiple route prefixes. An AS can determine a valid route based on these stored prefixes. Specifically, after receiving routing information from a neighboring AS, an AS can determine whether the route prefix in that information is included in its stored list of route prefixes. If it is included, the route is considered valid. If it is not included, the route is considered invalid.
[0199] OTC: An AS can determine a legitimate route based on the OTC tag carried in the routing information. The OTC tag can be added to the routing information by the sending AS or carried in the routing information by the receiving AS. The following explanation uses the example of the OTC tag being carried in the routing information by the sending AS.
[0200] When a sending AS sends routing information to its customer AS or peer AS, it can carry an OTC tag in the path attributes (such as community attributes) of the routing information, and this OTC tag can contain the AS identifier of the sending AS. Accordingly, the receiving AS (i.e., the customer AS or peer AS of the sending AS) can determine whether the routing information is a legitimate route by using the OTC tag carried in the routing information.
[0201] Specifically, if the sending AS is a provider AS of the receiving AS, the receiving AS can determine that the route is legitimate if the route information carries an OTC tag. If the sending AS is a customer AS of the receiving AS, the receiving AS can determine that the route is illegitimate if the route information carries an OTC tag. If the sending AS is a peer AS of the receiving AS, the receiving AS can determine that the route is illegitimate if the route information carries an OTC tag and the AS identifier carried in the OTC tag is different from the AS identifier of the sending AS; or, if the route information carries an OTC tag and the AS identifier carried in the OTC tag is the same as the AS identifier of the sending AS, the receiving AS can determine that the route is legitimate.
[0202] For example, such as Figure 2As shown, assume AS1 and AS3 are both provider ASs of AS2, AS2 is a customer AS of both AS1 and AS3, and AS1 and AS2 are neighboring ASs, as are AS2 and AS3. Based on this, before sending routing information to AS2, AS1 can include an OTC tag in the path attribute of the routing information, and this OTC tag contains AS1's AS identifier. Then, AS1 can send routing information carrying the OTC tag to AS2. Alternatively, AS1 can send routing information to AS2 without the OTC tag. When AS2 receives the routing information from AS1, it can include the OTC tag in the path attribute of the routing information, and this OTC tag contains AS1's AS identifier.
[0203] Before AS2 sends routing information to AS3, it can determine whether the routing information carries an OTC tag. If the routing information carries an OTC tag, AS2 can determine that the routing information is a valid route; if the routing information does not carry an OTC tag, AS2 can determine that the routing information is an invalid route.
[0204] After AS2 sends routing information to AS3, AS3 can determine whether the routing information carries the OTC mark. If the routing information carries the OTC mark, AS3 can determine that the routing information is an illegal route; if the routing information does not carry the OTC mark, AS3 can determine that the routing information is a legal route.
[0205] BGP sec: During the route information advertisement process, the AS sending the route information (hereinafter referred to as the sending AS) can sign the AS path in the route information using its own private key. The AS receiving the route information (hereinafter referred to as the receiving AS) can verify the signature using the public key corresponding to the sending AS to determine whether the AS path has been tampered with. If the verification fails, it is determined that the sending AS has tampered with the AS path, and the route information is an invalid route. If the verification succeeds, it is determined that the sending AS has not tampered with the AS path, and the route information is a valid route.
[0206] ASPA: An AS can pre-store the business relationships between various ASes (hereinafter referred to as ASPA data). After receiving routing information sent by a neighboring AS, an AS can read the AS Path in the routing information and verify the legitimacy of the AS Path based on its own stored ASPA data.
[0207] The ASPA process will be described in detail below.
[0208] After identifying its own provider AS, an AS can send an ASPA pair consisting of its own AS identifier and the AS identifier of its provider AS to the Resource Public Key Infrastructure (RPKI) server. The format of the ASPA pair is (AS identifier of customer AS, AS identifier of provider AS).
[0209] For example, such as Figure 3 As shown, assume AS200 is a provider AS of AS100 and AS300, with AS identifier 100 for AS100, AS identifier 200 for AS200, and AS identifier 300 for AS300. AS100 can generate its own ASPA pair (100, 200) and send it to the RPKI server, and AS300 can generate its own ASPA pair (300, 200) and send it to the RPKI server. Therefore, the ASPA data stored in the RPKI server can include both (100, 200) and (300, 200).
[0210] An AS can obtain ASPA data from the RPKI server. After receiving routing information sent by a neighboring AS, it uses the corresponding verification algorithm to verify the validity of the AS Path in the routing information based on its own stored ASPA data and the business role of the neighboring AS.
[0211] The aforementioned verification algorithms can include uplink path algorithms and downlink path algorithms. The uplink path algorithm refers to an algorithm that verifies the validity of the AS Path in the routing information based on the uplink path. The downlink path algorithm refers to an algorithm that verifies the validity of the AS Path in the routing information based on the downlink path.
[0212] An uplink path refers to the path indicated by the ASPA data of the provider AS of the AS indicated by the (i+1)th AS identifier, which is the AS indicated by the ith AS identifier. For example, see [link to previous section]. Figure 3 If AS200 is the provider AS of AS100 and AS300, then the paths indicated by ASPA data (100, 200) and (300, 200) are both uplink paths.
[0213] A downlink path refers to the path indicated by the ASPA data of the provider of the AS indicated by the (i-1)th AS identifier, where the AS is the provider of the AS indicated by the ith AS identifier. For example, see [link to example]. Figure 3If AS200 is the provider AS of AS100 and AS300, then the paths indicated by ASPA data (200, 100) and (200, 300) are both downlink paths.
[0214] Specifically, when the neighboring AS's business role is customer, peer, route server (RS)-client, or RS, the AS can use an uplink path algorithm for verification. When the neighboring AS's business role is provider or sibling, the AS can use a downlink path algorithm for verification.
[0215] For example, such as Figure 4 As shown, assume the ASPA data stored by the RPKI server includes (700, 100), (400, 700), (500, 400), and (400, 700). The AS connected to the RPKI server is AS200. AS200 is adjacent to AS100 and AS300 respectively, and AS200 is a provider for both AS100 and AS300. AS200 receives routing information with the route prefix 10.1.1.0 / 24 from AS100, containing the AS path (100, 700, 400), and receives routing information with the route prefix 10.1.1.0 / 24 from AS300, containing the AS path (300, 400, 500). AS200 can verify AS path (100, 700, 400) and AS path (300, 400, 500) based on its stored ASPA data (700, 100), (400, 700), (500, 400), and (400, 700).
[0216] Specifically, AS100 is a customer AS of AS200. AS200 can verify AS path (100, 700, 400) based on ASSPA data using the uplink path algorithm. The presence of (700, 100) and (400, 700) in the ASSPA data indicates that there is no route leakage in ASpath (100, 700, 400), meaning that the routing information sent by AS100 is a legitimate route.
[0217] AS300 is a customer AS of AS200. AS200 can verify ASpath (300, 400, 500) based on ASSPA data using the uplink path algorithm. The ASPA data contains (500, 400) but does not contain (300, 400), indicating that route leakage has occurred in ASpath (300, 400, 500), meaning that the routing information sent by AS300 is an invalid route.
[0218] However, in actual propagation processes, the strategies for disseminating routing information are quite complex. The route verification methods described above can be applied to simple propagation scenarios. For complex propagation scenarios, misjudgments may occur. For example, the route verification methods mentioned above for route leakage (OTC and ASPA) are based on the valley-free principle. When a valley path (such as...) is present... Figure 1 If the path shown in (b) is encountered (⑤), the corresponding routing information will be determined to be an illegal route. In actual propagation scenarios, more than 50% of the valley paths are intentionally configured by staff, which will lead to the erroneous interception of legitimate routes and cause network interruption.
[0219] In view of this, embodiments of this application provide a routing transmission method. A network device (such as the second network device in this embodiment) can receive routing information carrying tagging information sent by a neighboring network device (such as the first network device in this embodiment). The tagging information is used to indicate that at least one routing verification is exempted for the routing information. The network device can respond to the tagging information, that is, exempt the routing information from at least one routing verification, and update the routing table of the first network device based on the routing information.
[0220] As can be seen from the above technical solution, after receiving routing information, the first network device can exempt the routing information from at least one routing verification based on the tagging information in the routing information. Thus, with the help of tagging information, routing verification can be exempted as needed, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication. Furthermore, through tagging information, operators can more autonomously control the propagation path of routing information without being bound by routing verification, thereby achieving a more flexible routing announcement strategy.
[0221] Furthermore, this application embodiment also provides a routing transmission method. A network device (such as the second network device in this application embodiment) can receive routing information carrying tagging information (such as the first tagging information in this application embodiment) sent by a neighboring network device (such as the first network device in this application embodiment). The tagging information is used to indicate the execution of at least one routing protection mechanism (or routing protection policy) on the routing information. The network device can respond to the tagging information, that is, execute at least one routing protection mechanism on the routing information and update the routing table of the first network device based on the routing information.
[0222] As can be seen from the above technical solution, after receiving routing information, the first network device can execute at least one routing protection mechanism based on the tagging information in the routing information. Thus, with the help of the tagging information, the corresponding routing protection mechanism can be executed as needed, ensuring that legitimate routing information avoids erroneous interception and maintaining the continuity of network communication. Furthermore, through the tagging information, operators can more autonomously control the propagation path of routing information without being bound by route verification, thereby achieving a more flexible route announcement strategy.
[0223] The technical solution provided in this application will now be described with reference to the accompanying drawings.
[0224] Figure 5 This is a system architecture diagram of a communication system provided in an embodiment of this application. Figure 5 As shown, this communication system can include multiple network devices, such as... Figure 5 The first network device 501 and the second network device 502 shown are communicatively connected.
[0225] The embodiments of this application do not limit the specific form of the network devices (e.g., the first network device 501 and the second network device 502). For example, the network devices in the embodiments of this application can be routers, route reflectors (RR), controllers, switches, and servers, etc.
[0226] In the embodiments of this application, the first network device 501 and the second network device 502 may be network devices located in the same AS or network devices located in different ASs.
[0227] In this embodiment, the second network device 502 and the first network device 501 can execute the routing transmission method, routing query method, and connection establishment method provided in this embodiment.
[0228] In practice, all of the above-mentioned network devices can be adopted. Figure 6 The shown composition structure, or including Figure 6 The components shown. Figure 6 This is a schematic diagram illustrating the composition of a routing transmission device 600 provided in an embodiment of this application. The routing transmission device 600 can be a network device or a chip or system-on-a-chip within a network device. Figure 6 As shown, the routing transmission device 600 includes a processor 601, a communication interface 602, and a communication line 603.
[0229] Furthermore, the routing transmission device 600 may also include a memory 604. The processor 601, memory 604, and communication interface 602 can be connected via a communication line 603.
[0230] The processor 601 can be a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 601 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.
[0231] Communication interface 602 is used for communication with other devices or other communication networks. Other communication networks can be Ethernet, radio access network (RAN), wireless local area network (WLAN), etc. Communication interface 602 can be a module, circuit, transceiver, or any device capable of enabling communication.
[0232] Communication line 603 is used to transmit information between the components included in the routing transmission device 600.
[0233] Memory 604 is used to store instructions. These instructions can be computer programs.
[0234] The memory 604 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions; it can also be a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.
[0235] It should be noted that the memory 604 can exist independently of the processor 601, or it can be integrated with the processor 601.
[0236] The memory 604 can be used to store instructions, program code, or some data. The memory 604 can be located inside or outside the routing transmission device 600, without restriction.
[0237] Processor 601 is configured to execute instructions stored in memory 604 to implement the methods provided in the following embodiments of this application.
[0238] In one example, processor 601 may include one or more CPUs, for example Figure 6 CPU0 and CPU1 in the CPU.
[0239] As an optional implementation, the routing transmission device 600 includes multiple processors, for example, besides Figure 6 In addition to processor 601, it may also include processor 607.
[0240] Figure 6 The structural composition shown does not constitute a limitation on the routing transmission device, except... Figure 6 In addition to the components shown, the routing transmission device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.
[0241] Furthermore, the actions, terms, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of this application are merely examples, and other names may be used in specific implementations without limitation.
[0242] The following is combined Figure 5,by Figure 5 Taking the first network device and the second network device as examples, and using Scheme A (marking information used to indicate exemption from at least one route verification) and Scheme B (marking information used to indicate execution of at least one route protection mechanism) as examples, the routing transmission method provided in this application embodiment is described.
[0243] Option A: The tagging information is used to indicate that at least one route verification is exempted for the routing information.
[0244] Figure 7 This is a schematic diagram of the interaction flow of a routing transmission method provided in an embodiment of this application, such as... Figure 7 As shown, the method includes:
[0245] S701, the second network device sends routing information to the first network device.
[0246] Routing information indicates the path information for accessing a route prefix. Specifically, routing information includes the route prefix and path attributes. The path attribute may contain the AS path, which is the path information for accessing that route prefix.
[0247] The routing information also includes tagging information. The tagging information is used to indicate that at least one routing verification is exempted from the routing information.
[0248] In embodiments of this application, route verification may include at least one of ROV, ASPA, prefix filtering, OTC, or BGP sec. In one example, marking information may be used to indicate an exemption from one route verification for the route information. For example, taking ROV as an example, the marking information may be used to indicate an exemption from ROV for the route information. In another example, marking information may be used to indicate an exemption from multiple route verifications for the route information. For example, taking ROV and ASPA as examples, the marking information may be used to indicate an exemption from both ROV and ASPA for the route information.
[0249] The aforementioned marking information can be the marking information corresponding to exempted route verification. This application does not limit the specific form of the marking information in its embodiments. In one example, the marking information can be represented using binary characters. For example, taking ROV as an example, the marking information corresponding to ROV can be 10. In another example, the marking information can be represented using decimal characters. For example, continuing with ROV as an example, the marking information corresponding to ROV can be 2. In yet another example, the marking information can be represented using characters. For example, continuing with ROV as an example, the marking information corresponding to ROV can be 'a'.
[0250] This application does not limit the length of the tag information. For example, the length of the tag information can be 2 bits or 4 bits.
[0251] Specifically, the second network device may store tagging information corresponding to each route verification. Based on this, when the second network device intends to exempt at least one route verification (hereinafter referred to as the first route verification) from routing information sent to the first network device, the second network device may, before sending the routing information to the first network device, determine the tagging information corresponding to the first route verification based on the tagging information corresponding to each route verification stored in its own memory, and generate routing information carrying the tagging information corresponding to the first route verification. Then, the second network device may send the routing information carrying the tagging information corresponding to the first route verification to the first network device to indicate that the first route verification is exempted for this routing information.
[0252] For example, let's take the case where the tag information corresponding to ROV that can be stored in the second network device is 2, and the tag information corresponding to prefix filtering is 1. In one embodiment, the second network device intends to send routing information A to the first network device, and exempts routing information A from ROV. The second network device can generate routing information A carrying tag information 2, and send routing information A carrying tag information 2 to the first network device.
[0253] In another embodiment, the second network device intends to send routing information B to the first network device, and exempts routing information B from ROV and prefix filtering. The second network device may generate routing information B carrying tag information 2 and tag information 1, and send routing information B carrying tag information 2 and tag information 1 to the first network device.
[0254] When the tagging information is used to indicate exemption from multiple routing verifications for routing information, and each routing verification corresponds to one tagging information, multiple tagging information needs to be carried in the routing information. In an optional implementation, the second network device may also store tagging information corresponding to any number of routing verifications. Based on this, when the second network device intends to exempt multiple routing verifications for routing information sent to the first network device, it can also achieve exemption from multiple routing verifications by carrying a single tagging information in the routing information, thereby reducing communication overhead.
[0255] The tagging information corresponding to any number of route authentication methods can include: tagging information corresponding to any combination of ROV, ASPA, prefix filtering, OTC, or BGP sec.
[0256] In this embodiment of the application, the tagging information corresponding to any number of route verifications is not limited. For example, the tagging information corresponding to any number of route verifications may include at least one of the following (1) or (2): (1) Tagging information corresponding to multiple route verifications that address different route security risks (route hijacking, path hijacking, and route leakage). For example, tagging information corresponding to multiple route verifications (including ROV and prefix filtering) that address route hijacking, tagging information corresponding to multiple route verifications (including ASPA and OTC) that address route leakage, and tagging information corresponding to multiple route verifications (including ASPA and BGP sec) that address path hijacking. (2) Tagging information corresponding to all route verifications.
[0257] For example, in one embodiment, let's take the tag information corresponding to multiple route verifications (e.g., ROV and prefix filtering) for dealing with route hijacking stored in the second network device as 3. The second network device intends to send route information B to the first network device and exempt route information B from multiple route verifications for dealing with route hijacking. The second network device can generate route information B carrying tag information 3 and send route information B carrying tag information 3 to the first network device to indicate that route information B is exempt from multiple route verifications for dealing with route hijacking.
[0258] In another embodiment, taking the example that all the route verification corresponding tag information that can be stored in the second network device is 0, the second network device intends to send route information C to the first network device and exempt route information C from all route verification. The second network device can generate route information C carrying tag information 0 and send route information C carrying tag information 0 to the first network device to indicate that route information C is exempt from all route verification.
[0259] In one alternative implementation, the tagging information is transitive. That is, after receiving routing information carrying tagging information from the second network device, the first network device can directly send the routing information carrying tagging information to its next-hop device without having to re-add the tagging information.
[0260] For example, such as Figure 8 As shown, taking device 300 as the second network device, device 400 as the first network device, and device 500 as the next-hop device of device 400 as an example. Taking the example that device 300 intends to send routing information A to device 400, exempting routing information A from ROV (Redirection of Vehicles), and the tag information corresponding to ROV is 2. Device 300 can generate routing information A carrying tag information 2 and then send routing information A to device 400. Device 400, upon receiving routing information A, can send routing information A to device 500 without needing to re-add tag information 2.
[0261] In one alternative implementation, exempting the routing information from at least one route verification means: not performing at least one route verification on the routing information; or performing at least one route verification on the routing information, wherein the result of the at least one route verification is legal, illegal, or unknown. The above-mentioned at least one route verification will be referred to as the first route verification in the following description.
[0262] Not performing first route verification on routing information means performing route verification other than the first route verification (hereinafter referred to as second route verification). For example, assuming that all route verifications include ROV, ASPA, prefix filtering, OTC, and BGP sec, and the first route verification includes ROV and ASPA, then not performing first route verification on routing information can be replaced by performing route verification on routing information other than ROV and ASPA, that is, performing prefix filtering, OTC, and BGP sec on routing information.
[0263] Performing a first route verification on routing information, where the result of the first route verification is valid, invalid, or unknown, means performing both first and second route verifications on the routing information, and using the result of the second route verification for subsequent operations such as route information propagation or routing table updates. In other words, the result of the first route verification is not involved in subsequent operations. For example, assuming all route verifications include ROV, ASPA, prefix filtering, OTC, and BGP sec, and the first route verification includes ROV and ASPA, then performing at least one route verification on the routing information, where the result of at least one route verification is valid, invalid, or unknown, can be replaced with: performing ROV, ASPA, prefix filtering, OTC, and BGP sec on the routing information, and using the results of prefix filtering, OTC, and BGP sec verification for subsequent operations. That is, the results of ROV and ASPA verification are not involved in subsequent operations.
[0264] In one alternative implementation, the second network device may send routing information carrying the tagging information to the first network device if the tagging conditions are met.
[0265] The above marking conditions may include at least one of the following: the AS where the second network device is located does not have a business relationship with the AS where the first network device is located; the identifier of the originating AS in the routing information does not match the routing prefix; or the second network device has modified the path information for accessing the above routing prefix.
[0266] Here, the originating AS refers to the AS where the first network device that sends routing information resides. In one example, the rightmost AS in the AS path is the AS identifier of the originating AS. For example, if AS path = (AS300, AS400, AS500), then AS500 is the AS identifier of the originating AS.
[0267] Different marking conditions correspond to different marking information. In one example, if the marking condition includes a lack of commercial relationship between the AS where the second network device resides and the AS where the first network device resides, it indicates that sending routing information from the second network device to the first network device will result in route leakage. Therefore, the corresponding marking information refers to the marking information corresponding to multiple route verifications to address route leakage. As another example, if the marking condition includes a mismatch between the origin AS identifier and the routing prefix in the routing information, it indicates that sending routing information from the second network device to the first network device will result in route hijacking. Therefore, the corresponding marking information refers to the marking information corresponding to multiple route verifications to address route hijacking. Yet another example, if the marking condition includes that the second network device modified the path information accessing the aforementioned routing prefix, it indicates that sending routing information from the second network device to the first network device has resulted in path hijacking. Therefore, the corresponding marking information refers to the marking information corresponding to multiple route verifications to address path hijacking.
[0268] Specifically, taking the example where the marking condition includes a lack of business relationship between the AS where the second network device is located and the AS where the first network device is located, before the second network device intends to send routing information to the first network device, it can first determine the business role of its own AS (hereinafter referred to as the first business role) and the business role of the AS where the first network device is located (hereinafter referred to as the second business role), and determine whether the AS where it is located and the AS where the first network device is located conform to a business relationship based on the first and second business roles. If the business relationship does not conform, it indicates that routing leakage will occur when the second network device sends routing information to the first network device. The second network device can determine the marking information (hereinafter referred to as marking information m) corresponding to the multiple routing verifications required to address the routing leakage, and generate routing information carrying marking information m. Afterwards, the second network device can send the routing information carrying marking information m to the first network device to indicate that the routing information is exempt from the multiple routing verifications required to address the routing leakage.
[0269] For example, such as Figure 9 As shown, assume that the AS where device 100 is located is the provider AS of the AS where device 200 is located, the AS where device 200 is located is the customer AS of the AS where device 100 is located, the AS where device 200 is located is the provider AS of the AS where device 300 is located, the AS where device 300 is located is the customer AS of the AS where device 200 is located, the AS where device 300 is located is the customer AS of the AS where device 400 is located, and the AS where device 400 is located is the provider AS of the AS where device 300 is located.
[0270] Taking device 100 as an example, the routing information of device 100 can be sent to device (device 200) located in its own customer AS. That is, the AS where device 100 is located and the AS where device 200 is located are in accordance with the business relationship. Therefore, when device 100 sends routing information to device 200, it does not need to carry the tag information m.
[0271] Taking device 200 as an example, the routing information received by device 200 from its own provider (device 100) can be sent to device 300 located in its own customer AS. That is, the AS where device 200 is located and the AS where device 300 is located are in accordance with a business relationship. Therefore, after receiving the routing information sent by device 100, device 200 can directly send the routing information to device 300 without carrying the tag information m.
[0272] Taking device 300 as an example, the routing information received by device 300 from its own provider (device 200) cannot be sent to the device (device 400) located in its own provider AS. That is, the AS where device 300 is located does not conform to the business relationship with the AS where device 400 is located. Therefore, after receiving the routing information sent by device 200, device 300 needs to first generate routing information carrying the tag information m, and then send the routing information carrying the tag information m to device 400.
[0273] In one optional implementation, the second network device may carry the aforementioned routing information in the BGP update message. Based on this, the embodiments of this application do not specifically limit the method of carrying the marking information. For example, the marking information may be carried in existing path attributes of the BGP update message, such as the community attribute, the OTC attribute, or the optional transit attribute. Alternatively, a new path attribute may be defined in the BGP update message, and the marking information may be carried using the newly defined path attribute.
[0274] S702, the first network device receives routing information from the second network device.
[0275] S703, the first network device responds to the tagging information and updates its routing table based on the routing information.
[0276] Specifically, after receiving routing information from the second network device, the first network device can parse the routing information. If the routing information carries marker information indicating exemption from at least one routing verification, the first network device can exempt the routing information from at least one routing verification. The first network device can update its own routing table based on the routing prefix and path information in the routing information.
[0277] As described above, exempting routing information from at least one route verification means either not performing at least one route verification on the routing information, or performing at least one route verification on the routing information, where the result of the at least one route verification is valid, invalid, or unknown. Therefore, if the first network device determines that the routing information carries tagging information indicating an exemption from the first route verification, it may not perform the first route verification on the routing information, but instead perform a second route verification on the routing information, and update its own routing table based on the result of the second route verification. Alternatively, the first network device may perform both the first and second route verifications on the routing information. Regardless of whether the result of the first route verification is valid, invalid, or unknown, the first network device updates its own routing table based on the result of the second route verification.
[0278] To avoid the situation where the first network device is unable to exempt the corresponding route verification when it receives routing information carrying tagging information from the second network device while its exemption capability is disabled, in an optional implementation, after performing the above... Figure 7 Prior to the routing transmission method shown, the first network device may also send its own capability information (hereinafter referred to as the first exemption capability information) to the second network device when its exemption capability is enabled. Accordingly, the second network device may send routing information carrying tag information to the first network device upon receiving the first exemption capability information sent by the first network device.
[0279] The first exemption capability information is used to indicate that the exemption capability of the first network device is enabled, and the exemption capability is used to exempt at least one of the above-mentioned routing verifications.
[0280] This application does not specifically limit the method of sending the first exemption capability information. For example, the first exemption capability information can be carried in a BGP open message. Alternatively, the first exemption capability information can be sent as a separate message to the second network device.
[0281] Specifically, taking the example of carrying the first exemption capability information in a BGP open message, the operator can manually enable the exemption capability of the first network device. When the first network device detects that its exemption capability is enabled, it can send a BGP open message carrying the first exemption capability information to its neighboring network device (also known as a neighboring network device, such as a second network device), indicating that its exemption capability is enabled. Upon receiving the BGP open message, the neighboring network device can parse it and, if the BGP open message contains the first exemption capability information, send routing information carrying tagging information to the first network device.
[0282] Through the above technical solution, after receiving routing information, the first network device can exempt itself from at least one routing verification based on the tagging information in the routing information. Thus, with the help of tagging information, routing verification can be exempted as needed, allowing legitimate routing information to avoid erroneous interception and maintaining the continuity of network communication. Through tagging information, operators can more autonomously control the propagation path of routing information without being bound by routing verification, thereby achieving a more flexible routing announcement strategy.
[0283] In one optional implementation, the second network device may send its own capability information (hereinafter referred to as second exemption capability information) to the first network device when its exemption capability is enabled. This enables the first network device to subsequently send routing information carrying tagging information to the second network device upon receiving the second exemption capability information sent by the second network device.
[0284] The second exemption capability information is used to indicate that the exemption capability of the second network device is enabled.
[0285] The specific execution process can be referred to in the above process of the first network device sending the first exemption capability information to the second network device, which will not be repeated here.
[0286] Option B: The tagging information is used to indicate that at least one routing protection mechanism should be implemented for the routing information.
[0287] In this embodiment, in order to distinguish it from the second marking information described later, the above marking information can be referred to as the first marking information, that is: the first marking information is used to indicate the execution of at least one routing protection mechanism on the routing information.
[0288] The difference between this embodiment and the above embodiments is that:
[0289] Performing at least one routing protection mechanism on routing information may include: performing a second routing verification on the routing information; or, adding a second tagging information to the routing information, the second tagging information being used for routing verification.
[0290] The second route verification performed on the routing information may include the following (1) or (2): (1) Performing second route verification on the routing information without performing first route verification on the routing information. For example, assuming that all route verifications include ROV, ASPA, prefix filtering, OTC and BGP sec, and the second route verification includes ROV and ASPA, then performing second route verification on the routing information can be replaced by: performing ROV and ASPA on the routing information, without performing prefix filtering, OTC and BGP sec on the routing information. (2) Performing second route verification and first route verification on the routing information, and using the verification result of the second route verification for subsequent operations, that is, the verification result of the first route verification does not participate in subsequent operations. For example, assuming all route verifications include ROV, ASPA, prefix filtering, OTC, and BGP sec, and the second route verification includes ROV and ASPA, then performing the second route verification on the route information can be replaced by performing ROV, ASPA, prefix filtering, OTC, and BGP sec on the route information. Regardless of whether the verification results of prefix filtering, OTC, and BGP sec are valid, invalid, or unknown, the verification results of ROV and ASPA are used for subsequent operations. That is, the verification results of prefix filtering, OTC, and BGP sec are not involved in subsequent operations.
[0291] Adding a second tag to the routing information for route verification means generating routing information carrying the second tag and sending it to the next-hop device. Upon receiving the routing information carrying the second tag, the next-hop device can perform corresponding route verification using the second tag. For example, the second tag can be an OTC tag. Correspondingly, after receiving the routing information carrying the second tag, the first network device can generate routing information carrying the OTC tag and send it to its neighboring network devices (hereinafter referred to as neighboring network devices). Upon receiving the routing information carrying the OTC tag, the neighboring network devices can perform OTC verification based on the OTC tag.
[0292] The above technical solution, by leveraging tagging information, allows for the on-demand configuration of routing protection mechanisms. Routing protection mechanisms that might erroneously intercept routing information can be left unmarked within the routing information itself. This avoids unnecessary routing protection mechanisms from erroneously intercepting routing information, thus maintaining the continuity of network communication.
[0293] In one optional implementation, before sending routing information to the second network device, the first network device can also inform the other party of its business role in the AS via a BGP open message and establish a BGP connection (or initiate a BGP session). In this case, the first network device and the second network device can be referred to as BGP peers. The following description will use the example of the first network device sending a BGP open message carrying role information to the second network device to illustrate the process of establishing a BGP connection between the first network device and the second network device.
[0294] Figure 10 This is a schematic diagram of the interaction flow of a connection establishment method provided in an embodiment of this application. The method is executed in cooperation between a first network device and a second network device, such as... Figure 10 As shown, the method includes:
[0295] S1001, the first network device sends a BGP open message carrying role information to the second network device.
[0296] The role information indicates the business role of the AS where the first network device is located. This business role can include any one of mutual transit, partial transit customer, or partial transit provider.
[0297] It should be noted that, in addition to the aforementioned mutual transit, partial transit customer, and partial transit provider, the business role of the AS where the first network device carried in the BGP open message is located can also include any one of the five business roles defined in the RFC9234 standard: provider, RS, RS-client, customer, or peer.
[0298] This application does not limit the way role information is carried in BGP open messages. In one example, each business role can correspond to a different tag value. Based on this, the business role of the AS to which the first network device is located can be indicated by carrying the tag value in the BGP open message.
[0299] Optionally, Table 2 is a table showing the correspondence between business roles and tag values. As shown in Table 2, the tag value for provider can be 0, the tag value for RS can be 1, the tag value for RS-client can be 2, the tag value for customer can be 3, the tag value for peer can be 4, the tag value for mutual transit can be 5, the tag value for partial transit customer can be 6, and the tag value for partial transit provider can be 7.
[0300] Table 2
[0301] Tag value Business Role 0 provider 1 RS 2 RS-client 3 customer 4 peer 5 mutual transit 6 partial transit customer 7 partial transit provider
[0302] Taking the indication of business role by a tag value as an example, assuming that the business role of the AS where the first network device is located is mutual transit, after the first network device establishes a transmission control protocol (TCP) connection with the second network device, the first network device can generate a BGP open message carrying a tag value of 5 and send the BGP open message to the second network device.
[0303] The method for establishing a TCP connection between the first and second network devices can be found in relevant technologies, and will not be elaborated here.
[0304] S1002, the second network device receives a BGP open message carrying role information from the first network device.
[0305] S1003, if the business role of the AS where the second network device is located is successfully matched with the business role of the AS where the first network device is located, a BGP connection is established with the first network device.
[0306] Specifically, the second network device can store the correspondence, or matching relationship, between various business roles. For example, the business role matching mutual transit is mutual transit, the business role matching partial transit customer is partial transit provider, the business role matching provider is customer, the business role matching RS is RS-client, and the business role matching peer is peer.
[0307] Based on this, after receiving the BGP open message sent by the first network device, the second network device can parse the BGP open message to obtain the business role of the AS where the first network device is located, which is carried in the BGP open message. The second network device can then match the business role of the AS where the first network device is located with the business role of its own AS. If the business role of the AS where the second network device is located successfully matches the business role of the AS where the first network device is located, the second network device can establish a BGP connection with the first network device.
[0308] For example, suppose the business role of the AS where the second network device is located is a partial transit customer. After obtaining the business role of the AS where the first network device is located, the second network device can determine whether the business role of the AS where the first network device is located is a partial transit provider. If yes, the match is successful, and the second network device can establish a BGP connection with the first network device. If not, the match fails, and the second network device can return a match failure message to the first network device.
[0309] When the business relationship between two ASes is a mutual transit business relationship, both ASes have the business role of mutual transit, and they consider each other to be their providers. For example, let's take the AS where the first network device is located as the first AS and the AS where the second network device is located as the second AS. The business relationship between the first AS and the second AS is a mutual transit business relationship, meaning that the business role of the second AS is mutual transit, and the business role of the first AS is also mutual transit. In this case, the second AS can consider the first AS as its provider, and the first AS can consider the second AS as its provider.
[0310] When the business relationship between two ASes is a partial transit business relationship, the AS acting as a provider in the partial transit business relationship has a partial transit provider business role, and the AS acting as a customer in the partial transit business relationship has a partial transit customer business role. The AS with the business role of partial transit customer can access some of the neighboring ASes of the AS with the business role of partial transit provider. For example, continuing with the AS where the first network device is located as the first AS and the AS where the second network device is located as the second AS, the business relationship between the first AS and the second AS is a partial transit business relationship, and the business role of the second AS is partial transit customer. The first AS also has the business role of partial transit provider. In this case, the first AS is allowed to access some of the neighboring ASes of the second AS. As another example, continuing with the AS where the first network device is located as the first AS and the AS where the second network device is located as the second AS, the business relationship between the first AS and the second AS is a partial transit business relationship, and the business role of the second AS is partial transit provider. The first AS also has the business role of partial transit customer. In this case, the second AS is allowed to access some of the neighboring ASes of the first AS.
[0311] As demonstrated by the above technical solution, when negotiating business roles through BGP open messages, network devices can carry not only the five business roles defined in the RFC9234 standard, but also any one of mutual transit, partial transit customer, or partial transit provider. This expands the range of business roles carried in BGP open messages, ensuring the accuracy of business role configuration within the AS where the network devices reside, and thus enabling this solution to accommodate more diverse business relationships.
[0312] In one optional implementation, after the second network device sends routing information to the first network device, it can also query the AS where the network device that received the routing prefix (hereinafter referred to as the first routing prefix) carried in the routing information is located. The method by which the second network device queries the AS where the network device that received the first routing prefix is located will be described below.
[0313] Figure 11This is a schematic diagram of the interaction flow of a routing query method provided in an embodiment of this application. The method is executed by a first network device and a second network device, such as... Figure 11 As shown, the method includes:
[0314] S1101, the second network device sends a query message to the first network device.
[0315] The query information is used to indicate the AS where the network device that received the first routing prefix is located.
[0316] The embodiments of this application do not limit the number of first routing prefixes. For example, the number of first routing prefixes can be 1, 3, 4, or 5, or even more.
[0317] The network device that receives the first routing prefix may include: the network device that receives the first routing prefix sent by the first network device (hereinafter referred to as the third network device), and the network device that receives the first routing prefix sent by the third network device.
[0318] For example, such as Figure 12 As shown, assume the second network device is device 100, the first network device is device 200, and the third network devices include devices 300, 400, and 500. After receiving the routing information sent by device 100, device 200 sends the routing information to devices 300, 400, and 500 respectively. Therefore, the network devices that receive the first routing prefix can include: devices 300, 400, and 500, as well as the network devices that receive the first routing prefix sent by devices 300, 400, and 500.
[0319] Specifically, the second network device intends to query which ASs its first routing prefix has been propagated to by its neighboring network devices (such as the first network device). The second network device can generate query information carrying the first routing prefix and send the query information to the first network device.
[0320] For example, see [link to previous article] Figure 12 Assume the first route prefix is prefix P1, the first network device is device 100, and the second network device is device 200. Device 200 intends to query which ASs have been propagated to prefix P1 by device 200. Device 200 can generate query information carrying prefix P1 and send the query information to device 100.
[0321] In one alternative implementation, the second network device may carry the above query information in a BGP routerefresh message.
[0322] This application does not limit the method of carrying query information in its embodiments. In one example, the query information can be carried in the address family or sub-address family of the BGP route refresh message. For example, a new address family or sub-address family can be defined in the BGP route refresh message to carry the query information. In another example, the query information can be carried in the type field of the BGP route refresh message. For example, a new field can be defined in the BGP route refresh message to carry the query information.
[0323] To more accurately locate the first routing prefix, the second network device can also send the type of the first routing prefix to the first network device. Accordingly, when the query information is carried in a BGP route refresh message, the BGP route refresh message can also include a first identifier, which is used to indicate the type of the first routing prefix.
[0324] The type of the first routing prefix includes at least one of IPv4 and IPv6.
[0325] This application does not limit the method of carrying the first identifier in its embodiments. In one example, the first identifier can be carried in the address family or sub-address family of the BGP route refresh message. For example, a new address family or sub-address family can be defined in the BGP route refresh message to carry the first identifier. In another example, the first identifier can be carried in a field of the BGP route refresh message. For example, a new field can be defined in the BGP route refresh message to carry the first identifier.
[0326] In one optional implementation, the query information may include a first routing prefix, and may also include at least one of the following: a first length field, the length of the first routing prefix, and the identifier of the AS where the first network device that sent the query information is located.
[0327] The first length field is used to identify the length of the query information.
[0328] For example, consider a BGP route refresh message that carries a type length value (TLV), with the query information carried in the type field of the BGP route refresh message. In this case, the query information can also be referred to as the query TLV. The query TLV may include a first type field of 1 byte length, a reserved field of 1 byte length, a first length field of 2 bytes length, an identifier field of 4 bytes length for the AS to which the first network device sending the query information (e.g., the first network device) belongs, and a prefix list field of variable length.
[0329] The first type field indicates that the information is query information. The prefix list field includes a length field of the first route prefix with a length of 1 byte, and a first route prefix field with a length of an integer byte. The length of the first route prefix field is determined by the first route prefix.
[0330] In this application embodiment, the value of the first type field is not limited. For example, if the value of the first type field is 1, it can indicate that the TLV is a query TLV. Or, if the value of the first type field is 0, it can indicate that the TLV is a query TLV.
[0331] S1102, the first network device receives query information from the second network device.
[0332] S1103, the first network device sends a response message to the second network device.
[0333] S1104, the second network device receives a response message from the first network device.
[0334] The response message includes the identifier of the AS where the network device that received the first routing prefix is located.
[0335] In one alternative implementation, the response message may include the identifier of the AS to which the network device (hereinafter referred to as the third network device) that received the first routing prefix sent by the first network device is located.
[0336] Specifically, after receiving the query information sent by the second network device, the first network device can determine the identifier of the AS where the network device (i.e., the third network device) that received the first routing prefix sent by itself is located, and generate a response message based on the identifier of the AS where the third network device is located, and send the response message to the second network device.
[0337] To ensure a more comprehensive list of network devices that received the first routing prefix, after receiving the query information from the second network device, the first network device can also send the query information to the third network device to determine the identifier of the AS where the network device that received the first routing prefix from the third network device resides. Based on this, the response message can include the identifier of the AS where the third network device resides, as well as the identifier of the AS where the network device that received the first routing prefix from the third network device resides.
[0338] In this embodiment, the number of response messages is not limited. In one example, there may be one response message, meaning the identifier of the AS where the third network device is located and the identifier of the AS where the network device receiving the first routing prefix sent by the third network device is located can be included in the same response message. In another example, there may be multiple response messages, meaning the identifier of the AS where the third network device is located and the identifier of the AS where the network device receiving the first routing prefix sent by the third network device is located can be included in different response messages. For example, taking the network devices receiving the first routing prefix sent by the third network device as including network device A and network device B, the identifier of the AS where the third network device is located can be included in the first response message, and the identifiers of the AS where network device A is located and the AS where network device B is located can be included in the second response message.
[0339] Specifically, taking the example where the identifier of the AS where the third network device is located is included in the first response message, and the identifier of the network device that receives the first routing prefix sent by the third network device is included in the second response message, the first network device, after receiving the query information sent by the second network device, can determine the identifier of the AS where the network device that received the first routing prefix sent by itself (i.e., the third network device) is located, generate a first response message based on the identifier of the AS where the third network device is located, and send the first response message to the second network device.
[0340] The second network device can also send the query information to the third network device. After receiving the query information sent by the first network device, the third network device can determine the identifier of the AS where the network device that received the first routing prefix sent by itself (hereinafter referred to as the fourth network device) is located, generate a second response message based on the identifier of the AS where the fourth network device is located, and send the second response message to the second network device through the first network device.
[0341] For example, see [link to previous article] Figure 12Assume the first routing prefix is prefix P1, the second network device is device 100, the first network device is device 200, and the third network devices include devices 300, 400, and 500. After device 100 sends the query information to device 200, device 200 can generate response message A based on the identifiers of the AS where device 300, device 400, and device 500 reside, and send response message A to device 100.
[0342] Device 200 can also send the query information to devices 300, 400 and 500 respectively.
[0343] Taking device 300 as an example, after receiving the query information, device 300 can determine the identifier of the AS where the network device receiving the first routing prefix sent by device 300 is located, and generate response message B (i.e., the second response message mentioned above) based on the identifier of the AS where the network device receiving the first routing prefix is located. Device 300 can send response message B to device 200, and device 200 can send response message B to device 100. The execution process of devices 400 and 500 can refer to the description of device 300 above, and will not be repeated here. In this way, device 100 can obtain the identifiers of the ASs where all network devices receiving the first routing prefix are located.
[0344] In one alternative implementation, the response information can be carried in a BGP route refresh message.
[0345] This application does not limit the method of carrying the response information. In one example, the response information can be carried in the address family or sub-address family of the BGP route refresh message. For example, a new address family or sub-address family can be defined in the BGP route refresh message to carry the response information. In another example, the response information can be carried in the type field of the BGP route refresh message. For example, a new field can be defined in the BGP route refresh message to carry the response information.
[0346] In an optional implementation, the response information may further include: the identifier of the AS where the first network device that sent the query information is located, the identifier of the AS where the first network device that sent the response information is located, and at least one of the second length fields.
[0347] The second length field is used to indicate the length of the response information.
[0348] For example, if a BGP route refresh message carries a TLV and the response information is carried in the type field of the BGP route refresh message, then the response information can also be called a response TLV. The response TLV may include a second type field of length 1 byte, a reserved field of length 1 byte, a first length field of length 2 bytes, an identifier field of length 4 bytes for the AS where the first network device that sent the query information (such as the first network device) is located, an identifier field of length 4 bytes for the AS where the first network device that sent the response information (such as the second network device) is located, and an AS list field.
[0349] The second type field is used to indicate that the information is a response. The AS list field can include the identifiers of multiple ASs where the network devices that received the first routing prefix are located, and the identifier field of each AS where the network devices that received the first routing prefix are located has a length of 4.
[0350] The value of the second type field is different from the value of the first type field. For example, if the value of the first type field is 1, the value of the second type field can be 2. Or, if the value of the first type field is 0, the value of the second type field can be 1.
[0351] It is understandable that when the AS list field is empty, it means that the number of network devices that received the first route prefix is 0, that is, the first route prefix has not been propagated to other network devices.
[0352] To avoid the situation where the first network device is unable to query the AS of the network device receiving the first routing prefix due to the first network device's query capability being disabled and receiving query information from the second network device, in an optional implementation, when performing the above... Figure 11 Prior to the routing query method shown, the first network device can also send capability information (hereinafter referred to as first query capability information) to the second network device when its query capability is enabled. Correspondingly, the second network device can send query information to the first network device upon receiving the first query capability information sent by the first network device.
[0353] The first query capability information indicates that the query capability of the first network device is enabled. The query capability is used to query the AS to which the network device receiving the first routing prefix belongs.
[0354] This application does not specifically limit the method of sending the first query capability information. For example, the first exemption capability information can be carried in the address family or sub-address family of the BGP open message. Alternatively, the first query capability information can be sent as a separate message.
[0355] In one optional implementation, the second network device can send its own capability information (hereinafter referred to as second query capability information) to the first network device when its query capability is enabled. This allows the first network device to send query information to the second network device upon receiving the second query capability information sent by the second network device.
[0356] The second query capability information is used to indicate that the query capability of the second network device is enabled.
[0357] The specific execution process can be referred to in the above process of the first network device sending the first query capability information to the second network device, which will not be repeated here.
[0358] Through the above technical solution, each network device can determine whether its transmitted routing prefix has been propagated and to which ASs it has been propagated. Thus, when a routing prefix becomes inaccessible, maintenance personnel can quickly locate the fault by using the identifier of the AS where the network device that received the routing prefix resides, effectively improving the speed of fault location. Furthermore, the way the first network device responds to query information to determine the AS where the network device that received the routing prefix resides is an on-demand query; that is, the AS where the network device that received the routing prefix resides is determined only when there is a query request. This reduces the communication overhead of network devices.
[0359] The above mainly describes the solution provided by the embodiments of this application from the perspective of interaction between various devices. Accordingly, the embodiments of this application also provide a routing transmission device, a routing query device, and a connection establishment device. The routing transmission device is used to implement the above... Figure 7 The method shown uses a connection establishment device to achieve the above. Figure 10 The method shown is used by the routing query device to perform the above. Figure 11 The method shown. The routing transmission device, routing query device, and connection establishment device can be the first network device in the above method embodiment, or a component that can be used in the first network device; or, the routing transmission device, routing query device, and connection establishment device can be the second network device in the above method embodiment, or a component that can be used in the second network device.
[0360] It is understood that the routing transmission device, routing query device, and connection establishment device, in order to achieve the above functions, include corresponding hardware structures and / or software modules for performing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0361] This application embodiment can divide the routing transmission device, routing query device, and connection establishment device into functional modules according to the above method embodiments. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be understood that the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0362] For example, taking the routing transmission device as an example. Figure 7 Taking the first network device in the method embodiment shown as an example, Figure 13 A schematic diagram of a first network device is shown, which includes a transceiver module 1301 and a processing module 1302. The transceiver module 1301, also known as a transceiver unit, is used to implement transceiver functions, and may be, for example, a transceiver circuit, a transceiver, a transceiver device, or a communication interface.
[0363] The transceiver module 1301 is used to receive routing information from the second network device. The routing information is used to indicate path information for accessing the routing prefix, and the routing information includes tagging information, which is used to indicate that at least one routing verification is exempted from the routing information.
[0364] Processing module 1302 is used to update the routing table of the first network device based on the routing information in response to the tagging information.
[0365] The transceiver module 1301 can be used to implement the transceiver function of the first network device in the above method embodiment, and the processing module 1302 can be used to implement the processing function of the first network device in the above method embodiment. Therefore, all relevant content of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, and will not be repeated here.
[0366] In this embodiment, the first network device is presented as an integrated functional module. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the first network device can employ... Figure 6 The routing transmission device 600 shown is in the form of this device.
[0367] Since the first network device provided in this application embodiment can execute the above-described routing transmission method, the technical effects it can achieve can be referred to the above-described method embodiment, and will not be repeated here.
[0368] Alternatively, for example, taking the routing transmission device as the second network device in the above method embodiment as an example, Figure 14 A schematic diagram of a second network device is shown, which includes a transceiver module 1401. The transceiver module 1401, also known as a transceiver unit, is used to implement transceiver functions, and may be, for example, a transceiver circuit, a transceiver, a transceiver interface, or a communication interface.
[0369] The transceiver module 1401 is used to send routing information to the first network device. This routing information indicates path information for accessing a routing prefix, and includes tagging information indicating that at least one routing verification is exempted from the routing information.
[0370] The transceiver module 1401 can be used to implement the transceiver function of the second network device in the above method embodiment. Therefore, all relevant content of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, and will not be repeated here.
[0371] In this embodiment, the second network device is presented as an integrated functional module. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the second network device can employ... Figure 6 The routing transmission device 600 shown is in the form of this device.
[0372] Since the second network device provided in this application embodiment can execute the above-described routing transmission method, the technical effects it can achieve can be referred to the above-described method embodiment, and will not be repeated here.
[0373] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of both. When any of the above modules or units are implemented by software, the software exists as computer program instructions and is stored in memory. The processor can be used to execute the program instructions and implement the above method flow. The processor can be built into a SoC (System-on-a-Chip) or ASIC, or it can be a separate semiconductor chip. In addition to the core that executes software instructions for computation or processing, the processor may further include necessary hardware accelerators, such as field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), or logic circuits that implement dedicated logic operations.
[0374] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, microprocessor, digital signal processing (DSP) chip, micro controller unit (MCU), artificial intelligence processor, ASIC, SoC, FPGA, PLD, application-specific digital circuit, hardware accelerator, or non-integrated discrete device, which can run the necessary software or perform the above method flow independently of software.
[0375] Optionally, embodiments of this application also provide a routing transmission device (e.g., the routing transmission device may be a chip or a chip system), the routing transmission device including a processor for implementing the above. Figure 7 The method in the illustrated embodiment. In one possible design, the routing transmission device further includes a memory. This memory stores necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the routing transmission device to perform the above-described... Figure 7 The method illustrated in the method embodiment. Of course, the memory may not be located in the routing transmission device. When the routing transmission device is a chip system, it can be composed of chips or may include chips and other discrete components; this application embodiment does not specifically limit this.
[0376] Optionally, embodiments of this application also provide a routing query device (e.g., the routing query device may be a chip or a chip system), the routing query device including a processor for implementing the above. Figure 11 The method in the illustrated embodiment. In one possible design, the routing query device further includes a memory. This memory stores necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the routing query device to perform the above-described... Figure 11The method illustrated in the method embodiment. Of course, the memory may not be located in the routing lookup device. When the routing lookup device is a chip system, it can be composed of chips or may include chips and other discrete components; this application embodiment does not specifically limit this.
[0377] Optionally, embodiments of this application also provide a connection establishment device (e.g., the routing query device may be a chip or a chip system), the routing query device including a processor for implementing the above. Figure 10 The method in the illustrated embodiment. In one possible design, the connection establishment apparatus further includes a memory. This memory stores necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the connection establishment apparatus to execute the above-described method. Figure 10 The method illustrated in the method embodiment. Of course, the memory may not be included in the connection establishment device. When the connection establishment device is a chip system, it may be composed of chips or may include chips and other discrete devices; this application embodiment does not specifically limit this.
[0378] In one possible implementation, this application also provides a computer-readable storage medium storing a computer program or instructions that, when run on a routing transmission device, enable the routing transmission device to perform the methods described in any of the above method embodiments or any implementation thereof.
[0379] In one possible implementation, this application embodiment also provides a communication system, which includes the first network device and the second network device described in the above method embodiments.
[0380] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0381] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0382] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. A routing transmission method, characterized in that, Applied to a first network device, the method includes: Receive routing information from a second network device, the routing information being used to indicate path information for accessing a routing prefix, the routing information including tagging information, the tagging information being used to indicate exemption from at least one routing verification for the routing information; In response to the tagging information, the routing table of the first network device is updated based on the routing information.
2. The method according to claim 1, characterized in that, The exemption of at least one route verification for the routing information means: At least one of the route verifications is not performed on the route information; or, The routing information is subjected to at least one of the aforementioned routing verifications, and the result of the routing verification is either valid, invalid, or unknown.
3. The method according to claim 1 or 2, characterized in that, The route verification includes at least one of the following: Route origin verification ROV; Autonomous System Supplier Authorization ASPA; Prefix filtering; Only to customers' OTC; or, Border Gateway Protocol (BGP) security.
4. The method according to any one of claims 1-3, characterized in that, Before receiving routing information from the second network device, the method further includes: Send capability information to the second network device; the capability information is used to indicate that the exemption capability of the first network device is enabled, and the exemption capability is used to exempt at least one of the routing verifications.
5. The method according to claim 4, characterized in that, The capability information is carried in the BGP open message.
6. The method according to any one of claims 1-5, characterized in that, The routing information is carried in the BGP update message, and the marking information is carried in any of the following: The community attribute of the BGP update message; The OTC attribute of the BGP update message; The optional transit attributes of the BGP update message; or, The newly added path attribute in the BGP update message.
7. A routing transmission method, characterized in that, Applied to a second network device, the method includes: Send routing information to a first network device, the routing information being used to indicate path information for accessing a routing prefix, the routing information including tagging information, the tagging information being used to indicate exemption from at least one routing verification.
8. The method according to claim 7, characterized in that, The exemption of at least one route verification for the routing information means: At least one of the route verifications is not performed on the route information; or, The routing information is subjected to at least one of the aforementioned routing verifications, and the result of the routing verification is either valid, invalid, or unknown.
9. The method according to claim 7 or 8, characterized in that, The route verification includes at least one of the following: ROV; ASPA; Prefix filtering; OTC; or, BGP is secure.
10. The method according to any one of claims 7-9, characterized in that, Sending routing information to the first network device includes: If the marking conditions are met, the routing information carrying the marking information is sent to the first network device; The marking conditions include at least one of the following: There is no commercial relationship between the Autonomous System (AS) where the second network device is located and the AS where the first network device is located. The identifier of the originating Autonomous System (AS) in the routing information does not match the routing prefix; the originating AS refers to the AS where the first network device sending the routing information is located; or, The second network device modified the path information for accessing the routing prefix.
11. The method according to any one of claims 7-10, characterized in that, The method further includes: The first network device receives capability information sent by the first network device; the capability information is used to indicate that the first network device's exemption capability is enabled, and the exemption capability is used to exempt at least one of the routing verifications.
12. The method according to claim 11, characterized in that, The capability information is carried in the BGP open message.
13. The method according to any one of claims 7-12, characterized in that, The routing information is carried in the BGP update message, and the marking information is carried in any of the following: The community attribute of the BGP update message; The OTC attribute of the BGP update message; The optional transmission attributes of the BGP update message; The newly added path attribute in the BGP update message.
14. A routing query method, characterized in that, Applied to a first network device, the method includes: Receive query information from the second network device regarding the first routing prefix; Based on the received query information, a response message is sent to the second network device; the response message contains the identifier of the AS where the network device that received the first routing prefix is located.
15. The method according to claim 14, characterized in that, The query information is carried in the BGP routerefresh message.
16. The method according to claim 15, characterized in that, The BGP route refresh message includes a first identifier, which indicates the type of the first route prefix.
17. The method according to claim 16, characterized in that, The first identifier is carried in the address family or sub-address family of the BGP routerefresh message.
18. The method according to any one of claims 14-17, characterized in that, The query information includes the first routing prefix, and at least one of the following: A first length field; the first length field is used to indicate the length of the query information; The length of the first routing prefix; The identifier of the AS where the first network device to send the query information is located.
19. The method according to any one of claims 14-18, characterized in that, The response information is carried in the BGProute refresh message.
20. The method according to any one of claims 14-19, characterized in that, The response information also includes at least one of the following: The identifier of the AS where the first network device to send the query information is located; The identifier of the AS to which the first network device to send the response information is located; The second length field indicates the length of the response information.
21. The method according to any one of claims 14-20, characterized in that, Before receiving query information from the second network device, the method further includes: Send capability information to the second network device; the capability information is used to indicate that the query capability of the first network device is enabled; the query capability is used to query the AS where the network device that received the first routing prefix is located.
22. The method according to any one of claims 14-21, characterized in that, The network device that receives the first routing prefix includes: A third network device; the third network device includes a network device that receives the first routing prefix sent by the first network device; and a network device that receives the first routing prefix sent by the third network device.
23. The method according to any one of claims 14-21, characterized in that, The response message includes a first response message, which contains the identifier of the AS where the third network device is located; the third network device includes the network device that received the first routing prefix sent by the first network device; Sending a response message to the second network device includes: Send the first response message to the second network device.
24. The method according to claim 23, characterized in that, The response message also includes a second response message, which contains the identifier of the AS where the network device that received the first routing prefix sent by the third network device is located; The method further includes: Send the query information to the third network device; Receive the second response message from the third network device; Sending a response message to the second network device further includes: Send the second response message to the second network device.
25. A routing query method, characterized in that, Applied to a second network device, the method includes: Send a query message for the first routing prefix to the first network device; Receive a response message from the first network device; the response message contains the identifier of the AS to which the network device that received the first routing prefix is located.
26. The method according to claim 25, characterized in that, The query information is carried in the BGP routerefresh message.
27. The method according to claim 26, characterized in that, The BGP route refresh message includes a first identifier, which indicates the type of the first route prefix.
28. The method according to claim 27, characterized in that, The first identifier is carried in the address family or sub-address family of the BGP routerefresh message.
29. The method according to any one of claims 25-28, characterized in that, The query information includes the first routing prefix, and at least one of the following: A first length field; the first length field is used to indicate the length of the query information; The length of the first routing prefix; The identifier of the AS where the first network device to send the query information is located.
30. The method according to any one of claims 25-29, characterized in that, The response information is carried in the BGProute refresh message.
31. The method according to any one of claims 25-30, characterized in that, The response information also includes at least one of the following: The identifier of the AS where the first network device to send the query information is located; The identifier of the AS to which the first network device to send the response information is located; The second length field indicates the length of the response information.
32. The method according to any one of claims 25-31, characterized in that, Before sending the query information to the first network device, the method further includes: The system receives capability information sent by the first network device; the capability information is used to indicate that the query capability of the first network device is enabled; the query capability is used to query the AS where the network device that received the first routing prefix is located.
33. The method according to any one of claims 25-32, characterized in that, The network device that receives the first routing prefix includes: A third network device; the third network device includes a network device that receives the first routing prefix sent by the first network device; and a network device that receives the first routing prefix sent by the third network device.
34. The method according to any one of claims 25-32, characterized in that, The response message includes a first response message, which contains the identifier of the AS where the third network device is located; the third network device includes the network device that received the first routing prefix sent by the first network device; The receiving of the response message from the first network device includes: Receive the first response message from the first network device.
35. The method according to claim 34, characterized in that, The response message also includes a second response message, which contains the identifier of the AS where the network device that received the first routing prefix sent by the third network device is located; The step of receiving a response message from the first network device further includes: Receive the second response message from the first network device.
36. A connection establishment method, characterized in that, Applied to a first network device, the method includes: Send a BGP open message carrying role information to the second network device; the role information is used to indicate the business role of the AS to which the first network device is located; the business role includes any one of mutual transit, partial transit customer, or partial transit provider.
37. The method according to claim 36, characterized in that, The AS where the first network device is located is the first AS, and the AS where the second network device is located is the second AS; When the business role of the second AS is the mutual transit, and the business role of the first AS is the mutual transit, the second AS will treat the first AS as its supplier, and the first AS will treat the second AS as its supplier. or, When the business role of the second AS is the partial transit customer and the business role of the first AS is the partial transit supplier, the second AS is allowed to access some of the neighboring ASs of the first AS; or, When the business role of the second AS is that of a partial transit supplier and the business role of the first AS is that of a partial transit customer, the first AS is allowed to access some of the neighboring ASs of the second AS.
38. A connection establishment method, characterized in that, Applied to a second network device, the method includes: Receive a BGP open message carrying role information from a first network device; the role information is used to indicate the business role of the AS to which the first network device is located; the business role includes any one of mutual transit, partial transit customer, or partial transit provider; If the business role of the AS where the second network device is located is successfully matched with the business role of the AS where the first network device is located, a BGP connection is established with the first network device.
39. The method according to claim 38, characterized in that, The AS where the first network device is located is the first AS, and the AS where the second network device is located is the second AS; When the business role of the second AS is the mutual transit, and the business role of the first AS is the mutual transit, the second AS will treat the first AS as its supplier, and the first AS will treat the second AS as its supplier. When the business role of the second AS is the partial transit customer and the business role of the first AS is the partial transit supplier, the second AS is allowed to access some of the neighboring ASs of the first AS; When the business role of the second AS is that of a partial transit supplier and the business role of the first AS is that of a partial transit customer, the first AS is allowed to access some of the neighboring ASs of the second AS.
40. A routing transmission method, characterized in that, Applied to a first network device, the method includes: Receive routing information from a second network device, the routing information being used to indicate path information for accessing a routing prefix, the routing information including first tagging information, the first tagging information being used to indicate the execution of at least one routing protection mechanism on the routing information; In response to the first tagging information, the routing table of the first network device is updated based on the routing information.
41. The method according to claim 40, characterized in that, The execution of at least one routing protection mechanism on the routing information includes: Perform at least one route verification on the routing information; or, A second tag is added to the routing information, and the second tag is used for route verification.
42. The method according to claim 41, characterized in that, The route verification includes at least one of the following: Route origin verification ROV; Autonomous System Supplier Authorization ASPA; Prefix filtering; Only for customers' OTC needs; Border Gateway Protocol (BGP) security.
43. The method according to any one of claims 40-42, characterized in that, The routing information is carried in the BGP update message, and the first marking information is carried in any of the following: The community attribute of the BGP update message; The OTC attribute of the BGP update message; The optional transmission attributes of the BGP update message; The newly added path attribute in the BGP update message.
44. A routing transmission method, characterized in that, Applied to a second network device, the method includes: Send routing information to a first network device. The routing information is used to indicate path information for accessing a routing prefix. The routing information includes first tagging information, which is used to indicate the execution of at least one routing protection mechanism on the routing information.
45. The method according to claim 44, characterized in that, The execution of at least one routing protection mechanism on the routing information includes: Perform at least one route verification on the routing information; or, A second tag is added to the routing information, and the second tag is used for route verification.
46. The method according to claim 45, characterized in that, The route verification includes at least one of the following: Route origin verification ROV; Autonomous System Supplier Authorization ASPA; Prefix filtering; Only for customers' OTC needs; Border Gateway Protocol (BGP) security.
47. The method according to any one of claims 44-46, characterized in that, The routing information is carried in the BGP update message, and the first marking information is carried in any of the following: The community attribute of the BGP update message; The OTC attribute of the BGP update message; The optional transmission attributes of the BGP update message; The newly added path attribute in the BGP update message.
48. A routing transmission device, characterized in that, The apparatus is located in a first network device and includes a module for performing the method as described in any one of claims 1-6.
49. A routing transmission device, characterized in that, The apparatus is located in a second network device and includes a module for performing the method as described in any one of claims 7-13.
50. A communication system, characterized in that, The system includes: a first network device and a second network device; The first network device is configured to perform the routing transmission method as described in any one of claims 1-6, or the routing query method as described in any one of claims 14-24, or the connection establishment method as described in any one of claims 36-37, or the routing transmission method as described in any one of claims 40-43; The second network device is configured to perform the routing transmission method as described in any one of claims 7-13, or the routing query method as described in any one of claims 25-35, or the connection establishment method as described in any one of claims 38-39, or the routing transmission method as described in any one of claims 44-47.
51. A network device, characterized in that, The device includes a memory and a processor; the memory is used to store program code; the processor is used to invoke the program code to cause the network device to perform the method as described in any one of claims 1-6, or the method as described in any one of claims 7-13, or the method as described in any one of claims 14-24, or the method as described in any one of claims 25-35, or the method as described in any one of claims 36-37; or the method as described in any one of claims 38-39; or the method as described in any one of claims 40-43, or the method as described in any one of claims 44-47.
52. A computer-readable storage medium, characterized in that, The method includes program code that, when executed on a computer or processor, causes the computer or processor to perform the method as described in any one of claims 1-6, or the method as described in any one of claims 7-13, or the method as described in any one of claims 14-24, or the method as described in any one of claims 25-35, or the method as described in any one of claims 36-37, or the method as described in any one of claims 38-39; or to perform the method as described in any one of claims 40-43, or to perform the method as described in any one of claims 44-47.
53. A computer program product, characterized in that, The computer program product includes instructions that, when executed on a computer, enable the computer to perform the method as described in any one of claims 1-6, or the method as described in any one of claims 7-13, or the method as described in any one of claims 14-24, or the method as described in any one of claims 25-35, or the method as described in any one of claims 36-37, or the method as described in any one of claims 38-39; or to perform the method as described in any one of claims 40-43, or the method as described in any one of claims 44-47.