Data transmission method and apparatus, and device and medium
By combining the SRv6 service chains of two customers in data transmission, deduplication of service nodes, and generating target service chains, the problem of reducing the security of some traffic data packets is solved, and higher data transmission security is achieved.
Patent Information
- Application Number
- PCT/CN2023/134011
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-02
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-08
AI Technical Summary
In the two customer visit scenarios in the security pool, some traffic packets are only redirected to one SRv6 service chain, resulting in reduced transmission security.
By receiving the messages to be transmitted, extracting the source IP and destination IP, determining the corresponding classification strategy and service chain, deduplication of service nodes, merging the service chain, generating the target service chain, and transmitting messages using the target service chain.
It realizes that traffic data packets can pass through all service nodes in the two service chains, improving the security of data transmission.
Smart Images

Figure CN2023134011_08052025_PF_FP_ABST
Abstract
Description
Data transmission method, device, equipment and medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on November 2, 2023, with application number 202311450678.5 and application name “A Data Transmission Method, Device, Equipment and Medium”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of information security technology, and in particular to a data transmission method, apparatus, device and medium. Background Art
[0004] Segment Routing IPv6 (SRv6), based on Internet Protocol Version 6 (IPv6), is a new-generation IP bearer protocol that can simplify and unify traditional complex network protocols. It is the foundation for building intelligent IP networks in the 5G and cloud eras. SRv6 has the advantages of centralized control, stateless intermediate networks, and good scalability. Segment Routing (SR) is a protocol designed for the Software Defined Network (SDN) architecture. It combines the advantages of autonomous device forwarding and centralized programming control to better implement application-driven networks. Service Function Chaining (SFC) is a technology that provides ordered services to the application layer. It is used to connect services on network devices at the logical level to form an orderly service combination.
[0005] Service chaining ensures that packets pass through service nodes sequentially along a specified path by adding service node path information to traffic data packets. When packets are transmitted across a network, they often need to pass through a variety of service nodes to ensure secure, fast, and stable transmission according to pre-planned requirements. These service nodes include well-known firewalls, intrusion prevention systems (IPS), application accelerators, and network address translation (NAT). Traffic data packets must pass through these service nodes in the established order required by business logic to achieve the required services. Based on this, the path orchestration capabilities of SRv6 policies are used to implement service chaining, which can provide different security value-added services and combined services on demand. Different security services together form a security pool for users to select on demand.
[0006] However, currently, in the scenario where two customers visit each other within a security pool, the traffic data packets meet both the source IP-based classification policy and the destination IP-based classification policy, and the two classification policies are redirected to different SRv6 service chains. In this case, some traffic data packets will be redirected to only one of the SRv6 service chains. Since each SRv6 service chain has its own service node, if they are redirected to only one of the SRv6 service chains, they can only be processed by the service nodes of one of the SRv6 service chains, resulting in reduced transmission security.
[0007] Therefore, how to ensure that traffic data packets can pass through all service nodes in the two service chains and improve the security of data transmission is a technical problem that needs to be solved urgently.
[0008] Summary of the Invention
[0009] The present application provides a data transmission method, apparatus, device and medium for improving the security of data transmission.
[0010] In a first aspect, the present application provides a data transmission method, the method comprising:
[0011] Receive a message to be transmitted, and extract the source IP and destination IP contained in the message;
[0012] Determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy;
[0013] De-duplicate the service nodes based on the service nodes included in each service chain;
[0014] Generating a target service chain according to the service nodes after the deduplication operation;
[0015] The message is transmitted using a service node in the target service chain.
[0016] In a possible implementation, after determining the service chain corresponding to each classification strategy and before performing a deduplication operation on the service nodes according to the service nodes included in each service chain, the method further includes:
[0017] Determine whether the last service node included in each service chain is the same;
[0018] If so, the subsequent deduplication operation is performed on the service nodes according to the service nodes included in each service chain.
[0019] In a possible implementation, performing a deduplication operation on the service nodes according to the service nodes included in each service chain includes:
[0020] According to the service nodes included in each service chain, determine the same service nodes;
[0021] The same service node included in the service chain corresponding to the source IP is deleted.
[0022] In a possible implementation, generating a target service chain according to the service nodes after the deduplication operation includes:
[0023] According to the arrangement order of the service nodes in the service chain after the deduplication operation, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
[0024] In a second aspect, the present application provides a data transmission device, the device comprising:
[0025] A receiving module is used to receive the message to be transmitted and extract the source IP and destination IP contained in the message;
[0026] A determination module, configured to determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy;
[0027] A merging module is used to perform a deduplication operation on the service nodes according to the service nodes included in each service chain; and generate a target service chain according to the service nodes after the deduplication operation;
[0028] A transmission module is used to transmit the message using a service node in the target service chain.
[0029] In a possible implementation, the merging module is further configured to determine whether the last service node included in each service chain is the same; if so, perform a subsequent deduplication operation on the service nodes according to the service nodes included in each service chain.
[0030] In a possible implementation, the merging module is specifically configured to determine identical service nodes according to the service nodes included in each service chain; and delete the identical service nodes included in the service chain corresponding to the source IP.
[0031] In a possible implementation, the merging module is specifically used to use the last service node in the service chain corresponding to the destination IP as the last service node in the target service chain according to the arrangement order of the service nodes in the service chain after the deduplication operation; use the first node in the service chain corresponding to the source IP as the first service node in the target service chain; and alternately extract the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP as the intermediate service nodes of the target service chain.
[0032] In a third aspect, the present application provides an electronic device, which includes at least a processor and a memory, and the processor is used to implement the steps of any of the above-mentioned data transmission methods when executing a computer program stored in the memory.
[0033] In a fourth aspect, the present application also provides a computer-readable storage medium, which stores a computer program that can be executed by an electronic device. When the program runs on the electronic device, the electronic device executes the steps of any of the above-mentioned data transmission methods.
[0034] In an embodiment of the present application, a message to be transmitted is received, and the source IP and destination IP contained in the message are extracted, and a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP are determined, thereby determining the service chain corresponding to each classification strategy; based on the service nodes included in each service chain, a deduplication operation is performed on the service nodes; based on the service nodes after the deduplication operation, a target service chain is generated, and the service chains corresponding to the source IP and the destination IP are merged, and the service nodes in the merged target service chain are used to transmit the message, so that it can pass through all the service nodes in the service chains corresponding to the source IP and the destination IP, thereby improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the implementation methods in the embodiments of the present application or related technologies, the following is a brief introduction to the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0036] FIG1 is a schematic diagram of a data transmission process provided by some embodiments of the present application;
[0037] FIG2 is a schematic diagram of a device structure of an SRv6 service chain provided in some embodiments of the present application;
[0038] FIG3 is a schematic diagram of an interaction process between an SRv6 head node and an SF Proxy node provided in some embodiments of the present application;
[0039] FIG4 is a schematic diagram of an interaction process between an SF Proxy node and an SRv6 tail node provided in some embodiments of the present application;
[0040] FIG5 is a schematic diagram of a segment list path of a service chain provided by some embodiments of the present application;
[0041] FIG6 is a schematic diagram of a segment list of a service chain provided by some embodiments of the present application;
[0042] FIG7 is a schematic diagram of an encapsulated message provided in some embodiments of the present application;
[0043] FIG8 is a schematic structural diagram of a data transmission device provided in some embodiments of the present application;
[0044] FIG9 is a schematic structural diagram of an electronic device provided in some embodiments of the present application. DETAILED DESCRIPTION
[0045] To make the purpose, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described in this application are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0046] It should be noted that the brief descriptions of terms in this application are only for the purpose of facilitating the understanding of the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise specified, these terms should be understood according to their ordinary and usual meanings.
[0047] In the specification and claims of this application and the accompanying drawings, the terms "first," "second," "third," etc. are used to distinguish similar or similar objects or entities, and are not necessarily intended to limit a particular order or sequence, unless otherwise noted. It should be understood that the terms used in this manner are interchangeable under appropriate circumstances.
[0048] The terms "comprise," "include," and "have," and any variations thereof, are intended to cover but not exclude inclusion; for example, a product or device comprising a list of components is not necessarily limited to all the components expressly listed but may include other components not expressly listed or inherent to such product or device.
[0049] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functionality associated with that element.
[0050] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
[0051] To improve the security of data transmission, the present application provides a data transmission method, apparatus, device, and medium. The method comprises receiving a message to be transmitted, extracting the source IP address and destination IP address contained in the message, determining a first classification strategy corresponding to the source IP address and a second classification strategy corresponding to the destination IP address, and determining a service chain corresponding to each classification strategy; performing a deduplication operation on the service nodes contained in each service chain; generating a target service chain based on the deduplication-prone service nodes; and transmitting the message using the service nodes in the target service chain.
[0052] Example 1:
[0053] FIG1 is a schematic diagram of a data transmission process provided by an embodiment of the present application. As shown in FIG1 , the process includes the following steps:
[0054] S101: Receive a message to be transmitted, and extract the source IP and destination IP contained in the message;
[0055] The embodiments of the present application are applied to electronic devices, where the electronic devices may be mobile phones, PCs, servers, and other devices.
[0056] SRv6, based on IPv6, is a next-generation IP transport protocol that simplifies and unifies traditional, complex network protocols. It is the foundation for building intelligent IP networks in the 5G and cloud eras. SRv6 offers advantages such as centralized control, stateless intermediate networks, and excellent scalability. SR, designed for SDN architectures, combines the advantages of autonomous device forwarding with centralized programmable control, enabling application-driven networks. SFC is a technology that provides ordered services to the application layer, logically connecting services on network devices to form an organized service portfolio.
[0057] Service chaining ensures that packets traverse service nodes sequentially along a specified path by adding service node path information to traffic packets. As packets travel through the network, they often pass through a variety of service nodes, ensuring secure, fast, and stable transmission according to pre-planned protocols. These service nodes include well-known firewalls, IPS, and NAT. Traffic packets must traverse these service nodes in the order specified by business logic to deliver the desired services. Based on this, service chaining, leveraging the path orchestration capabilities of SRv6 Policy, can provide different value-added security services and combined services on demand. Different security services form a security pool, which users can select based on their needs.
[0058] However, currently, in the scenario where two customers visit each other within a security pool, the traffic data packets meet both the source IP-based classification policy and the destination IP-based classification policy, and the two classification policies are redirected to different SRv6 service chains. In this case, some traffic data packets will be redirected to only one of the SRv6 service chains. Since each SRv6 service chain has its own service node, if they are redirected to only one of the SRv6 service chains, they can only be processed by the service nodes of one of the SRv6 service chains, resulting in reduced transmission security.
[0059] Based on this, an embodiment of the present application provides a data transmission method, which receives a message of a traffic data packet to be transmitted, and extracts the source IP and destination IP contained in the message, wherein the source IP is the sender of the traffic data packet and the destination IP is the receiver of the traffic data packet.
[0060] S102: Determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy.
[0061] Based on the extracted source IP address, a first classification strategy corresponding to the source IP address can be determined. Based on the extracted destination IP address, a second classification strategy corresponding to the destination IP address can be determined. Different classification strategies correspond to different service chains. Based on each determined classification strategy, the corresponding service chain can be determined.
[0062] S103: Deduplication is performed on the service nodes according to the service nodes included in each service chain.
[0063] Each service chain's segment list contains its own service nodes, which are Security Identifiers (SIDs), the nodes that provide security services. Segment lists of different service chains may contain identical SIDs. Therefore, duplicate SIDs in the segment lists of two service chains can be removed. This means that only one of the identical SIDs in each segment list is retained, leaving only one of each type.
[0064] Specifically, the same SID in the segment list corresponding to the source IP address may be deleted, or the same SID in the segment list corresponding to the destination IP address may be deleted.
[0065] S104: Generate a target service chain according to the service nodes after the deduplication operation.
[0066] Generate the target service chain based on the service nodes after the deduplication operation, that is, generate the segment list of the target service chain based on the remaining SIDs.
[0067] In an embodiment of the present application, when two customers in a security pool visit each other through traffic data packets, when the message of the traffic data packet simultaneously satisfies the first classification policy based on the source IP and the second classification policy based on the destination IP, and the two classification policies are redirected to different SRv6 policies, i.e., different service chains, the segment lists of the two service chains are merged to generate the segment list of the target service chain, thereby realizing dynamic merging of service chains, so that the traffic can pass through the security service nodes on the two service chains and meet the requirements of both customers at the same time.
[0068] S105: Using a service node in the target service chain to transmit the message.
[0069] The service node in the target service chain is used, that is, the SID in the segment list of the target service chain is used to transmit the message of the traffic data packet.
[0070] In an embodiment of the present application, a message to be transmitted is received, and the source IP and destination IP contained in the message are extracted, and a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP are determined, thereby determining the service chain corresponding to each classification strategy; based on the service nodes included in each service chain, a deduplication operation is performed on the service nodes; based on the service nodes after the deduplication operation, a target service chain is generated, and the service chains corresponding to the source IP and the destination IP are merged, and the service nodes in the merged target service chain are used to transmit the message, so that it can pass through all the service nodes in the service chains corresponding to the source IP and the destination IP, thereby improving the security of data transmission.
[0071] Example 2:
[0072] To further ensure the security of data transmission, based on the above embodiment, in an embodiment of the present application, after determining the service chain corresponding to each classification strategy, and before performing a deduplication operation on the service nodes included in each service chain, the method further includes:
[0073] Determine whether the last service node included in each service chain is the same;
[0074] If so, the subsequent deduplication operation is performed on the service nodes according to the service nodes included in each service chain.
[0075] In order to further improve the security of data transmission, before merging the service chains corresponding to the source IP and destination IP, that is, before deduplicating the service nodes, it is necessary to first determine whether the last service node contained in each service chain is the same, that is, to determine whether the last SID in the segment list of each service chain is the same.
[0076] If they are the same, then the SIDs can be deduplicated based on the SIDs contained in the segment list of each service chain. If they are different, it means that the service chains corresponding to the source IP and destination IP cannot be merged. In this case, no deduplication is performed, and one of the service chains is selected, and the service node in that service chain is used to transmit the traffic data packet.
[0077] In an embodiment of the present application, before deduplication is performed on the service nodes, it is first determined whether the last service node included in each service chain is the same. If so, deduplication is then performed on the service nodes based on the service nodes included in each service chain, further ensuring the security of data transmission.
[0078] Example 3:
[0079] In order to further improve the efficiency of data transmission while ensuring the security of data transmission, based on the above embodiments, in the embodiment of the present application, the deduplication operation of the service nodes according to the service nodes included in each service chain includes:
[0080] According to the service nodes included in each service chain, determine the same service nodes;
[0081] The same service node included in the service chain corresponding to the source IP is deleted.
[0082] To further improve the security of data transmission, the same SIDs are identified based on the SIDs contained in the segment lists of the service chains corresponding to the source IP and destination IP, and the same SIDs contained in the service chains corresponding to the source IP are deleted.
[0083] Specifically, for example, the path of the service nodes included in segment list 1 of the service chain corresponding to the source IP is SID1->SID3->SID4, that is, the service nodes included in the service chain corresponding to the source IP are SID1, SID3, and SID4. The path of the service nodes included in segment list 2 of the service chain corresponding to the destination IP is SID2->SID3->SID4, that is, the service nodes included in the service chain corresponding to the destination IP are SID2, SID3, and SID4. It is determined that the same service nodes included in the two service chains are SID3 and SID4. SID3 and SID4 included in segment list 1 of the service chain corresponding to the source IP can be deleted.
[0084] In an embodiment of the present application, the identical service nodes are determined based on the service nodes included in each service chain, and the identical service nodes included in the service chain corresponding to the source IP are deleted, thereby further improving the efficiency of data transmission while ensuring the security of data transmission.
[0085] Example 4:
[0086] In order to further ensure the security of data transmission, based on the above embodiments, in an embodiment of the present application, generating a target service chain according to the service nodes after the deduplication operation includes:
[0087] According to the arrangement order of the service nodes in the service chain after the deduplication operation, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
[0088] Based on the order of the deduplicated SIDs in the segment list of the service chain to which they belong, the last SID in segment list 2 of the service chain corresponding to the destination IP address is used as the last SID in the segment list of the target service chain. The first SID in segment list 1 of the service chain corresponding to the source IP address is used as the first SID in the segment list of the target service chain. The remaining SIDs in segment list 1 and segment list 2 are alternately extracted and used as the intermediate SIDs in the segment list of the target service chain.
[0089] Take the example in the above-mentioned embodiment 3 as an example for explanation. The SID after the deduplication operation, that is, the SID remaining after deleting SID3 and SID4 contained in the segment list 1 of the service chain corresponding to the source IP, includes SID1 and SID2 remaining in segment list 1, as well as SID3 and SID4 remaining in segment list 1. The last SID in segment list 2 of the service chain corresponding to the destination IP, that is, SID4, is used as the last SID in the segment list of the target service chain. The first SID in segment list 1 of the service chain corresponding to the source IP, that is, SID1, is used as the first SID in the segment list of the target service chain. The remaining SIDs in segment list 1 and the remaining SIDs in segment list 2 are alternately extracted as the middle SIDs of the segment list of the target service chain, that is, the remaining SID3 in segment list 1 is first extracted, and then the remaining SIDs in segment list 2 are extracted as the middle SIDs in the segment list of the target service chain. The generated segment list of the target service chain includes SID1, SID2, SID3, and SID4, and the segment list path is SID1->SID2->SID3->SID4.
[0090] In an embodiment of the present application, based on the order of service nodes in the service chain after deduplication, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; and the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as intermediate service nodes in the target service chain, thereby merging the service chains corresponding to the source IP and the destination IP to generate a target service chain. Using this target service chain to transmit messages can further improve the efficiency and security of data transmission.
[0091] The data transmission process of the embodiment of the present application is further illustrated below with a specific example.
[0092] Figure 2 is a schematic diagram of the device structure of an SRv6 service chain provided in some embodiments of the present application. As shown in Figure 2, the SRv6 service chain device includes an SRv6 head node, a service function proxy (SF Proxy) node, and an SRv6 tail node. The head node includes a receiving module, a classification and matching module, a merging and processing module, an encapsulation module, and a sending module; the SF Proxy node is a node that provides security services and includes a receiving module, a decapsulation module, a cache module, an encapsulation module, and a sending module; and the tail node includes a receiving module, a decapsulation module, and a sending module.
[0093] Specifically, the receiving module is used to receive the message to be transmitted and extract the source IP and destination IP contained in the message;
[0094] The classification module is used to match classification policies based on the source IP and destination IP addresses of the message. If a unique classification policy is matched, the policy action is executed, redirecting the message to the SRv6 policy service chain and calling the encapsulation module to encapsulate the message. If two classification policies are matched, the first classification policy corresponding to the source IP address and the second classification policy corresponding to the destination IP address are determined, and the service chain corresponding to each classification policy is determined. The merging processing module needs to be called to merge the segment lists of the two service chains to generate the target service chain.
[0095] The merging processing module is specifically used to perform a deduplication operation on the service nodes according to the service nodes included in each service chain; generate a target service chain according to the service nodes after the deduplication operation; and call the encapsulation module to encapsulate the message;
[0096] The encapsulation module is specifically used to encapsulate the IPv6 header and packet header (segment routing header, SRH) in the outer layer of the original packet, where the SRH contains the path information of the segment list of the service chain. The path information of the segment list can come from the classification matching module, the merging processing module or the cache module.
[0097] Decapsulation module: removes the IPv6 header and SRH from the outer layer of the message.
[0098] Cache module: When decapsulating the IPv6 header and SRH, it caches the IPv6 header and SRH for subsequent encapsulation and use.
[0099] Sending module: Sends messages according to the destination IP address of the message.
[0100] FIG3 is a schematic diagram of an interaction process between an SRv6 head node and an SF Proxy node according to some embodiments of the present application. As shown in FIG3 , the process includes the following steps:
[0101] S301: The SRv6 head node receiving module receives the original message from the user network and parses the source IP and destination IP of the message.
[0102] S302: The classification matching module finds that the message matches both the source IP classification policy and the destination IP classification policy, and the SRv6 policy paths redirected by the two classification policies are different. Segment list merging is required.
[0103] S303: The merging processing module performs segment list merging processing. The merging strategy is to merge duplicate SIDs and retain non-duplicate SIDs.
[0104] S304: The encapsulation module encapsulates the IPv6 header and SRH for the original message. The SRv6Policy path information in the SRH information is the result of merging the two segment list paths.
[0105] S305: The sending module sends the message to SF Proxy according to the new destination IP address of the message.
[0106] S306: After receiving the message, the SF Proxy receiving module executes the instruction corresponding to the SF Proxy SID.
[0107] S307: The decapsulation module removes the IPv6 header and SRH from the outer layer of the message.
[0108] S308: The cache module caches the outer IPv6 header and SRH.
[0109] S309: The sending module sends the decapsulated message to SF Proxy.
[0110] S310: SF Proxy receives the message, processes the message, and then sends the message back to SF Proxy.
[0111] S311: The SF Proxy receiving module receives the message.
[0112] S312: The cache module restores the message according to the cache information.
[0113] S313: The encapsulation module re-encapsulates the IPv6 header and SRH in the cached information.
[0114] S314: The sending module sends the message to the node where the next SID is located according to the destination IP address of the message.
[0115] FIG4 is a schematic diagram of the interaction process between an SF Proxy node and an SRv6 tail node according to some embodiments of the present application. As shown in FIG4 , the process includes the following steps:
[0116] S401: After receiving the message, the SF Proxy receiving module executes the instruction corresponding to the SF Proxy SID.
[0117] S402: The decapsulation module removes the outer IPv6 header and SRH from the message.
[0118] S403: The cache module caches the outer IPv6 header and SRH.
[0119] S404: The sending module sends the decapsulated message to the SF.
[0120] S405: SF receives the message, processes the message, and then sends the message back to SF Proxy.
[0121] S406: The SF Proxy receiving module receives the message.
[0122] S407: The cache module attempts to restore the message based on the cache information.
[0123] S408: The encapsulation module re-encapsulates the IPv6 header and SRH in the cached information.
[0124] S409: The sending module sends the message to the SRv6 egress node according to the destination IP address of the message.
[0125] S410: The SRv6 egress receiving module receives the message.
[0126] S411: The decapsulation module decapsulates the message according to the SID instruction.
[0127] S412: The sending module forwards the original message.
[0128] Figure 5 is a schematic diagram of the segment list path of a service chain provided in some embodiments of the present application. As shown in Figure 5, SF1, SF2 and SF3 are SRv6-unaware SFs. In order to implement the service chain, it is necessary to configure the SF Proxy function in SF1 Proxy, SF2 Proxy and SF3 Proxy respectively, and assign SRv6 SIDs to SF1Proxy, SF2 Proxy and SF3 Proxy. There are two classification policies in the SRv6 head node, one is a classification policy based on the source IP, and the other is a classification policy based on the destination IP, and the traffic matches these two policies at the same time. The SRv6 service chain segment list path redirected by the classification policy based on the source IP is SF1 Proxy->SF3 Proxy->SRv6 tail node, and the SRv6 service chain segment list path redirected by the classification policy based on the destination IP is SF2 Proxy->SF3 Proxy->SRv6 tail node.
[0129] Figure 6 is a schematic diagram of a segment list of a service chain provided in some embodiments of the present application. As shown in Figure 6, the segment list of the merged service chain includes Tail SID, SF3 Proxy SID, SF2 Proxy SID and SF3 Proxy SID.
[0130] FIG7 is a schematic diagram of an encapsulated message provided by some embodiments of the present application. As shown in FIG7 , the encapsulated message includes an IPv6 header and an SRH. Specifically, the internal structure of the IPv6 header and SRH is prior art and will not be described in detail here.
[0131] The message encapsulation process includes the following steps:
[0132] S701: After receiving the message, SF1 Proxy executes the instruction corresponding to the SF1 Proxy SID, decapsulates the message, and then sends the original message to SF1 for processing, and caches the decapsulated IPv6 message header and SRH.
[0133] S702: After SF1 processes the message, it sends the message back to SF1 Proxy.
[0134] S703: SF1 Proxy searches the cache information based on the inbound interface information of the packet, then re-adds the IPv6 packet header and SRH information based on the cache information and performs SRv6 encapsulation. At this time, the destination address of the SRv6 packet is SF2 Proxy SID, and the packet is sent to SF2 Proxy.
[0135] S704: After receiving the message, SF2 Proxy executes the instruction corresponding to the SF2 Proxy SID, decapsulates the message, and then sends the original message to SF2 for processing, and caches the decapsulated IPv6 message header and SRH.
[0136] S705: After SF2 processes the message, it sends the message back to SF2 Proxy.
[0137] S706: SF2 Proxy searches the cache information based on the inbound interface information of the packet, then re-adds the IPv6 packet header and SRH information based on the cache information and performs SRv6 encapsulation. At this time, the destination address of the SRv6 packet is SF3 Proxy SID, and the packet is sent to SF3 Proxy.
[0138] S707: After receiving the message, SF3 Proxy executes the instruction corresponding to the SF3 Proxy SID, decapsulates the message, and then sends the original message to SF3 for processing, and caches the decapsulated IPv6 message header and SRH.
[0139] S708: After SF3 processes the message, it sends the message back to SF3 Proxy.
[0140] S709: SF3 Proxy searches the cache for information based on the inbound interface information of the packet. It then re-adds the IPv6 packet header and SRH information based on the cache information and performs SRv6 encapsulation. At this time, the destination address of the SRv6 packet is the Tail SID, and the packet is sent to the SRv6 egress node.
[0141] S710: After receiving the SRv6 message, the SRv6 egress node finds that the destination address of the message is its own SID and SL=0. Therefore, it executes the instructions related to the SID, decapsulates the message, and forwards the original message.
[0142] In an embodiment of the present application, segment list merging is implemented by merging two independent segment list paths into a single segment list path based on SRv6 service chaining. When processing an SRv6 service chain segment list merge, the merged segment list path is encapsulated into a message SRH, so that traffic is forwarded through the merged segment list path.
[0143] Example 5:
[0144] Based on the same technical concept, on the basis of the above embodiments, in the embodiments of the present application, a data transmission device is provided. FIG8 is a schematic structural diagram of a data transmission device provided in some embodiments of the present application. As shown in FIG8 , the device includes:
[0145] The receiving module 801 is used to receive a message to be transmitted and extract the source IP and destination IP contained in the message;
[0146] Determination module 802, used to determine the first classification strategy corresponding to the source IP and the second classification strategy corresponding to the destination IP, and determine the service chain corresponding to each classification strategy;
[0147] The merging module 803 is configured to perform a deduplication operation on the service nodes according to the service nodes included in each service chain; and generate a target service chain according to the deduplication-operated service nodes;
[0148] The transmission module 804 is configured to transmit the message using a service node in the target service chain.
[0149] In a possible implementation, the merging module 803 is further configured to determine whether the last service node included in each service chain is the same; if so, perform a subsequent deduplication operation on the service nodes according to the service nodes included in each service chain.
[0150] In a possible implementation, the merging module 803 is specifically configured to determine identical service nodes according to the service nodes included in each service chain; and delete the identical service nodes included in the service chain corresponding to the source IP.
[0151] In a possible implementation, the merging module 803 is specifically used to use the last service node in the service chain corresponding to the destination IP as the last service node in the target service chain according to the arrangement order of the service nodes in the service chain after the deduplication operation; use the first node in the service chain corresponding to the source IP as the first service node in the target service chain; and alternately extract the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP as the intermediate service nodes of the target service chain.
[0152] The specific manner in which each module performs operations in the device of the embodiment of the present application has been described in detail in the embodiment of the data transmission method and will not be elaborated here.
[0153] In an embodiment of the present application, a message to be transmitted is received, and the source IP and destination IP contained in the message are extracted, and a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP are determined, thereby determining the service chain corresponding to each classification strategy; based on the service nodes included in each service chain, a deduplication operation is performed on the service nodes; based on the service nodes after the deduplication operation, a target service chain is generated, and the service chains corresponding to the source IP and the destination IP are merged, and the service nodes in the merged target service chain are used to transmit the message, so that it can pass through all the service nodes in the service chains corresponding to the source IP and the destination IP, thereby improving the security of data transmission.
[0154] Example 6:
[0155] Based on the same technical concept and on the basis of the above embodiments, an electronic device is provided in an embodiment of the present application.
[0156] FIG9 is a schematic diagram of the structure of an electronic device provided by some embodiments of the present application. As shown in FIG9 , the electronic device includes: a processor 901, a communication interface 902, a memory 903, and a communication bus 904, wherein the processor 901, the communication interface 902, and the memory 903 communicate with each other via the communication bus 904;
[0157] The memory 903 stores a computer program. When the program is executed by the processor 901, the processor 901 performs the following steps:
[0158] Receive a message to be transmitted, and extract the source IP and destination IP contained in the message;
[0159] Determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy;
[0160] De-duplicate the service nodes based on the service nodes included in each service chain;
[0161] Generating a target service chain according to the service nodes after the deduplication operation;
[0162] The message is transmitted using a service node in the target service chain.
[0163] In a possible implementation, the processor 901 is further configured to:
[0164] Determine whether the last service node included in each service chain is the same;
[0165] If so, the subsequent deduplication operation is performed on the service nodes according to the service nodes included in each service chain.
[0166] In a possible implementation, the processor 901 is further configured to:
[0167] According to the service nodes included in each service chain, determine the same service nodes;
[0168] The same service node included in the service chain corresponding to the source IP is deleted.
[0169] In a possible implementation, the processor 901 is further configured to:
[0170] According to the arrangement order of the service nodes in the service chain after the deduplication operation, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
[0171] Since the principle of solving the problem by the above electronic device is similar to that of the data transmission method, the implementation of the above electronic device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0172] The communication bus mentioned in the electronic device mentioned above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. This communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not mean that there is only one bus or only one type of bus.
[0173] The communication interface 902 is used for communication between the electronic device and other devices.
[0174] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Alternatively, the memory may be at least one storage device located away from the processor.
[0175] The above-mentioned processor can be a general-purpose processor, including a central processing unit, a network processor (NP), etc.; it can also be a digital signal processing processor (DSP), an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, etc.
[0176] In an embodiment of the present application, a message to be transmitted is received, and the source IP and destination IP contained in the message are extracted, and the first classification strategy corresponding to the source IP and the second classification strategy corresponding to the destination IP are determined, thereby determining the service chain corresponding to each classification strategy; based on the service nodes contained in each service chain, a deduplication operation is performed on the service nodes; based on the service nodes after the deduplication operation, a target service chain is generated, and the service chains corresponding to the source IP and the destination IP are merged, and the service nodes in the merged target service chain are used to transmit the message, so that it can pass through all the service nodes in the service chains corresponding to the source IP and the destination IP, thereby improving the security of data transmission.
[0177] Example 7:
[0178] Based on the same technical concept and on the basis of the above embodiments, in an embodiment of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program executable by an electronic device. When the program is executed on the electronic device, the electronic device implements the following steps:
[0179] Receive a message to be transmitted, and extract the source IP and destination IP contained in the message;
[0180] Determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy;
[0181] De-duplicate the service nodes based on the service nodes included in each service chain;
[0182] Generating a target service chain according to the service nodes after the deduplication operation;
[0183] The message is transmitted using a service node in the target service chain.
[0184] In a possible implementation, after determining the service chain corresponding to each classification strategy and before performing a deduplication operation on the service nodes according to the service nodes included in each service chain, the method further includes:
[0185] Determine whether the last service node included in each service chain is the same;
[0186] If so, the subsequent deduplication operation is performed on the service nodes according to the service nodes included in each service chain.
[0187] In a possible implementation, performing a deduplication operation on the service nodes according to the service nodes included in each service chain includes:
[0188] According to the service nodes included in each service chain, determine the same service nodes;
[0189] The same service node included in the service chain corresponding to the source IP is deleted.
[0190] In a possible implementation, generating a target service chain according to the service nodes after the deduplication operation includes:
[0191] According to the arrangement order of the service nodes in the service chain after the deduplication operation, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
[0192] The above-mentioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in the electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc., optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid-state drives (SSDs), etc.
[0193] In an embodiment of the present application, a message to be transmitted is received, and the source IP and destination IP contained in the message are extracted, and a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP are determined, thereby determining the service chain corresponding to each classification strategy; based on the service nodes included in each service chain, a deduplication operation is performed on the service nodes; based on the service nodes after the deduplication operation, a target service chain is generated, and the service chains corresponding to the source IP and the destination IP are merged, and the service nodes in the merged target service chain are used to transmit the message, so that it can pass through all the service nodes in the service chains corresponding to the source IP and the destination IP, thereby improving the security of data transmission.
[0194] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0195] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0196] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0197] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0198] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0199] Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if such changes and modifications of the embodiments of the present invention fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A data transmission method, characterized in that: The method comprises: Receive a message to be transmitted, and extract the source IP and destination IP contained in the message; Determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy; De-duplicate the service nodes according to the service nodes included in each service chain; Generate a target service chain according to the service nodes after the deduplication operation; The message is transmitted using a service node in the target service chain.
2. The method according to claim 1, characterized in that: After determining the service chain corresponding to each classification strategy and before performing a deduplication operation on the service nodes according to the service nodes included in each service chain, the method further includes: Determine whether the last service node included in each service chain is the same; If yes, then the subsequent deduplication operation is performed on the service nodes according to the service nodes included in each service chain.
3. The method according to claim 1, characterized in that The deduplication operation on the service nodes according to the service nodes included in each service chain includes: According to the service nodes included in each service chain, determining the same service nodes therein; The same service node included in the service chain corresponding to the source IP is deleted.
4. The method according to claim 1 or 3, characterized in that: The generating a target service chain according to the service nodes after the deduplication operation comprises: According to the arrangement order of the service nodes in the service chain after the deduplication operation, the last service node in the service chain corresponding to the destination IP is used as the last service node in the target service chain; the first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; the service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
5. A data transmission device, characterized in that: The device comprises: A receiving module, used for receiving a message to be transmitted, and extracting a source IP and a destination IP contained in the message; A determination module, used to determine a first classification strategy corresponding to the source IP and a second classification strategy corresponding to the destination IP, and determine a service chain corresponding to each classification strategy; A merging module, used to perform a deduplication operation on the service nodes according to the service nodes included in each service chain; and generate a target service chain according to the service nodes after the deduplication operation; A transmission module is used to transmit the message using a service node in the target service chain.
6. The device according to claim 5, characterized in that The merging module is further used to determine whether the last service node included in each service chain is the same; if so, perform the subsequent deduplication operation on the service nodes according to the service nodes included in each service chain.
7. The device according to claim 5, characterized in that The merging module is specifically used to determine the same service nodes according to the service nodes included in each service chain; and delete the same service nodes included in the service chain corresponding to the source IP.
8. The device according to claim 5, characterized in that The merging module is specifically configured to use the last service node in the service chain corresponding to the destination IP as the last service node in the target service chain according to the arrangement order of the service nodes in the service chain after the deduplication operation; The first node in the service chain corresponding to the source IP is used as the first service node in the target service chain; The service nodes in the service chain corresponding to the destination IP and the service nodes in the service chain corresponding to the source IP are alternately extracted as the intermediate service nodes of the target service chain.
9. An electronic device, characterized in that: The electronic device comprises at least a processor and a memory, and the processor is used to implement the steps of the data transmission method according to any one of claims 1 to 4 when executing a computer program stored in the memory.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device executes the steps of the data transmission method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Data plane learning of bi-directional service chains
CN105191215A
Configuration information checking method and equipment and storage medium
CN116915608A
Data processing method and device, electronic equipment and storage medium
CN116939035A
Message processing method and device, and storage medium
CN116939060A
Distributed service chaining in a network environment
US20150071285A1