Header information transmission device and header information transmission method

The header information transmitting device and method address the challenge of ensuring bidirectional flows pass through the same analyzer by determining consistent interface selection for bidirectional flows using a hash value and reversed header usage information, enabling efficient analysis and control.

WO2025094376A1PCT designated stage expired Publication Date: 2025-05-08NT T INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/039663
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-02
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Existing systems face challenges in ensuring that bidirectional flows pass through the same analyzer, leading to inefficient analysis and control of two-way flows, especially when different routers with varying hash calculation methods and operators are involved.

Method used

A header information transmitting device and method that determine the passing interface for packets based on a hash value from header information and interface set information, using a header calculation unit to reverse header usage information and ensure consistent interface selection for bidirectional flows.

Benefits of technology

This solution allows bidirectional flows to be concentrated on a particular device, even in environments where flows are distributed across multiple devices, ensuring efficient analysis and control of two-way flows by maintaining consistent interface selection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023039663_08052025_PF_FP_ABST
    Figure JP2023039663_08052025_PF_FP_ABST
Patent Text Reader

Abstract

A router (10B) comprises: a header calculation unit (15) that inversely calculates downlink header use information, which is a part of HF information, such that a transmission packet passing interface calculated from a hash value obtained from HF information of transmission header information of a transmission packet in the bidirectional flow and information of the interface set is the same as a reception packet passing interface in the bidirectional flow; and a flow generation unit (14) that transmits, to a header attachment / detachment device (20B), downlink header information (10X) in which flow identification information of the bidirectional flow and downlink header use information calculated by the header calculation unit (15) are associated with each other.
Need to check novelty before this filing date? Find Prior Art

Description

Header information transmitting device and header information transmitting method

[0001] The present invention relates to a header information transmitting device and a header information transmitting method.

[0002] If packets sent from any of the router's multiple interfaces can reach the same device, all flows can be forwarded from one interface, or the load can be distributed across multiple interfaces. When distributing each flow to each link through load distribution, an algorithm is required to decide which interface to assign each flow to.

[0003] To assign a set of packets belonging to the same flow to the same interface, an algorithm is often used that calculates a hash value based on different identification information for each flow and then determines the interface to assign from that hash value. Flow identification information is, for example, a combination of destination IP, source IP, and flow label. Routers determine the interface ID from the flow's hash value using the formula "Interface ID = hash value mod number of interfaces." Note that mod is a modulus function; for example, 10 mod 4 = 2.

[0004] 8 is a configuration diagram of a flow communication system 100z. In the flow communication system 100z, a network is formed that relays between transmitting terminals TC1z to TC3z, such as client terminals that request services, and receiving terminals TS1z to TS3z, such as servers that provide services. Hereinafter, the flow in which an IPv4 packet 71z, such as a request transmitted from a transmitting terminal TC2z, reaches a receiving terminal TS2z is referred to as upstream traffic 70z. The flow in which an IPv4 packet 81z, such as a response transmitted from a receiving terminal TS2z, reaches a transmitting terminal TC2z is referred to as downstream traffic 80z.

[0005] In the upstream traffic 70z, an IPv4 packet 71z flows along a route 70Pz passing through the transmitting terminal TC2z → header attachment / detachment device 20Az → router 10Az → analysis device 31z → router 10Bz → header attachment / detachment device 20Bz → receiving terminal TS2z in this order. The header attachment / detachment device 20Az adds (encapsulates) an IPv6 header 72z to the received IPv4 packet 71z. The header attachment / detachment device 20Bz removes the IPv6 header 72z from the received IPv6 packet, restoring it to an IPv4 packet 71z. In other words, the flow is transferred by IPv6 tunneling in the section "header attachment / detachment device 20Az → router 10Az → analysis device 31z → router 10Bz → header attachment / detachment device 20Bz."

[0006] In the downstream traffic 80z, an IPv4 packet 81z flows along a route 80Pz passing through the receiving terminal TS2z → header attachment / detachment unit 20Bz → router 10Bz → analysis device 32z → router 10Az → header attachment / detachment unit 20Az → transmitting terminal TC2z in this order. The header attachment / detachment unit 20Bz adds (encapsulates) an IPv6 header 82z to the received IPv4 packet 81z. The header attachment / detachment unit 20Az removes the IPv6 header 82z from the received IPv6 packet, restoring it to the IPv4 packet 81z. In other words, the flow is transferred by IPv6 tunneling in the section "header attachment / detachment unit 20Bz → router 10Bz → analysis device 32z → router 10Az → header attachment / detachment unit 20Az."

[0007] The analysis devices 31z and 32z analyze the flows passing through them and acquire statistical information such as traffic volume. When multiple analysis devices 31z and 32z are installed between the routers 10Az and 10Bz, upstream traffic 70z may pass through the analysis device 31z, while downstream traffic 80z may pass through the analysis device 32z. As a result, the upstream and downstream traffic of the same flow may pass through different analysis devices 31z and 32z, resulting in the analysis results being distributed to different devices. In this case, the analysis devices 31z and 32z cannot distinguish between bidirectional flows (identifying upstream and downstream traffic as a set), and therefore cannot properly control the flow if the same policy is applied to both the upstream and downstream traffic based on the bidirectional flow. Application of a policy includes, for example, assigning a Quality of Service (QoS) DSCP (Differentiated Services Code Point) or queuing traffic in a priority queue.

[0008] The reason why the route 70Pz of the upstream traffic 70z and the route 80Pz of the downstream traffic 80z do not match is that the static HA of the router 10Az that determines the route 70Pz is different from the static HA of the router 10Bz that determines the route 80Pz. Therefore, there is a desire to route the upstream traffic 70z and the downstream traffic 80z through the same analysis device 31z. Therefore, Non-Patent Document 1 describes a setting item for a pair of routers provided by a specific vendor to ensure that bidirectional flows flow through the same link. This setting item involves setting "symmetric-hash" on both routers and "complement" on one router.

[0009] Juniper Networks, "Load Balancing on Aggregated Ethernet Interfaces," [online], [Retrieved October 24, 2023], Internet <URL: https: / / www.juniper.net / documentation / us / en / software / junos / high-availability / topics / topic-map / load-balancing-aggregated-ethernet-interfaces.html>, Junos OS, 3-Mar-23

[0010] As explained in Fig. 8, the following methods can be considered to address the problem of bidirectional flows passing through separate analysis devices 31z and 32z. (Method 1) The bidirectional flows pass through separate analysis devices 31z and 32z, and then the analysis results of the unidirectional flows are exchanged between the analysis devices 31z and 32z, thereby creating the analysis results of the bidirectional flows after the fact. (Method 2) A setting item is described for routing bidirectional flows between routers 10Az and 10Bz through the same link so that the bidirectional flows do not pass through separate analysis devices 31z and 32z (Non-Patent Document 1).

[0011] Regarding (Method 1), traffic (passing packets) or flows must be exchanged between the analysis devices 31z and 32z, and this information exchange requires unnecessary CPU resources and communication bandwidth for the exchange. As a result, the processing performance of the analysis devices decreases. For example, because traffic exchange is required for the number of combinations in which two devices are selected from n different devices, throughput decreases during scale-out. Regarding (Method 2), this method cannot be applied if the models used are different between the routers 10Az and 10Bz (if the hash calculation method is different), or if the same policy cannot be set between the routers 10Az and 10Bz, for example, if different operators are used between the routers 10Az and 10Bz.

[0012] Therefore, the main object of the present invention is to concentrate a bidirectional flow through a specific device even in an environment where the bidirectional flow can be distributed to a plurality of devices for communication.

[0013] In order to solve the above problems, the header information transmission device of the present invention has the following features: The header information transmission device of the present invention is characterized by comprising: a header calculation unit that determines a pass-through interface for a packet to be transmitted based on a hash value calculated from field information used for a predetermined hash function in the header information of the packet and information on a set of interfaces going to the same destination as the packet; a header calculation unit that reverse-calculates header usage information that is part of the field information of a transmission header information of a transmission packet of a bidirectional flow so that the pass-through interface for the transmission packet calculated from the hash value calculated from the field information of the transmission header information of the transmission packet of the bidirectional flow and the information on the set of interfaces is the same as the pass-through interface for a reception packet of the bidirectional flow; and a flow generation unit that transmits header information that associates flow identification information of the bidirectional flow with the header usage information reverse-calculated by the header calculation unit to a header attachment / detachment device, and controls the header attachment / detachment device so that the header usage information is used for the transmission header information of the transmission packet that matches the transmitted flow identification information.

[0014] According to the present invention, even in an environment where bidirectional flows can be distributed among a plurality of devices for communication, the bidirectional flows can be concentrated and passed through a specific device.

[0015] FIG. 1 is a configuration diagram of a flow communication system according to the present embodiment. FIG. 2 is a configuration diagram of a router and a header attachment / detachment device according to the present embodiment. FIG. 3 is a hardware configuration diagram of each device constituting the flow communication system according to the present embodiment. FIG. 4 is a packet format diagram showing an example of a notification OT of downstream header information according to the present embodiment. FIG. 5 is a packet format diagram showing an example of a notification DT corresponding to the notification OT of FIG. 4 according to the present embodiment. FIG. 6 is a sequence diagram showing the operation of the flow communication system according to the present embodiment. FIG. 7 is a flowchart showing details of a process in which a router according to the present embodiment obtains downstream header usage information from upstream traffic. FIG. 8 is a configuration diagram of a flow communication system.

[0016] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.

[0017] 1 is a configuration diagram of a flow communication system 100. In the flow communication system 100, a network is formed that relays between sending terminals TC1 to TC3, such as client terminals that request services, and receiving terminals TS1 to TS3, such as servers that provide services. Hereinafter, the flow in which an IPv4 packet 71, such as a request sent by a sending terminal TC2, reaches the receiving terminal TS2 is referred to as upstream traffic 70. The flow in which an IPv4 packet 81, such as a response sent by the receiving terminal TS2, reaches the sending terminal TC2 is referred to as downstream traffic 80.

[0018] In the upstream traffic 70, an IPv4 packet 71 flows along a route 71P passing through the transmitting terminal TC2 → header attachment / detachment device 20A → router 10A → analysis device 31 → router 10B → header attachment / detachment device 20B → receiving terminal TS2 in this order. The header attachment / detachment device 20A adds (encapsulates) an IPv6 header 72 to the received IPv4 packet 71. The header attachment / detachment device 20B removes the IPv6 header 72 from the received IPv6 packet, restoring it to the IPv4 packet 71. In other words, the flow is transferred over the section "header attachment / detachment device 20A → router 10A → analysis device 31 → router 10B → header attachment / detachment device 20B" using an IPv6 tunnel, as exemplified below: IPv4 over IPv6 technology, such as MAP-E (Mapping of Addresses and Ports with Encapsulation), DS-Lite (Dual-Stack Lite), and LW4o6 (Light Weight 4 over 6).・SRv6 (Segment Routing over IPv6) ・All other XX over IPv6 technologies

[0019] In the downstream traffic 80, an IPv4 packet 81 flows in the opposite direction along the same route 71P as the upstream traffic 70. The header attachment / detachment device 20B adds (encapsulates) an IPv6 header 82 to the received IPv4 packet 81. The header attachment / detachment device 20A removes the IPv6 header 82 from the received IPv6 packet, restoring it to the IPv4 packet 81. In other words, the flow is forwarded via IPv6 tunneling in the section "header attachment / detachment device 20B → router 10B → analysis device 31 → router 10A → header attachment / detachment device 20A." The IPv6 headers 72 and 82 are, for example, headers such as MAP-E and DS-Lite. The analysis devices 31 and 32 analyze the flows passing through their own devices and perform policy control, such as fairness control, bandwidth control, and application identification, based on the analysis results.

[0020] Next, the main differences between the flow communication system 100 of FIG. 1 and the flow communication system 100z of FIG. 8 will be described. In the flow communication system 100 of FIG. 1, both upstream traffic 70 and downstream traffic 80, which are bidirectional flows in which the combinations of SIP (Source IPv6 Address) and DIP (Destination IPv6 Address) are interchangeable, pass through the same route 71P so that they can be analyzed by the same analysis device 31. Furthermore, there are multiple interfaces from router 10B to router 10A (with router 10A as the next hop) for load balancing. Therefore, the interface through which router 10B receives upstream traffic 70 (upstream passing interface) and the interface through which router 10B transmits downstream traffic 80 (downstream passing interface) must be the same interface (the interface connected to the analysis device 31).

[0021] Therefore, the router (header information transmitting device) 10B transmits to the header attaching / detaching device 20B downstream header information 10X that associates the flow identification information of the upstream traffic 70 with downstream header usage information (header usage information). This downstream header usage information is information to be included in the IPv6 header 82, and is information that is set so that the downstream transit interface calculated by the router 10B from the IPv6 header 82 is the same as the upstream transit interface.

[0022] The downstream header usage information is, for example, a field established by the IPv6 specifications so that it can be assigned arbitrarily among the fields included in the IPv6 header 82, and for example, the flow label (FlowLabel, 20 bits) in the IPv6 header or the interface ID (= excluding the prefix) in SIP is used. Note that an IPv6 address such as SIP is a combination of a network address (generally the upper 64 bits) and an interface ID (generally the lower 64 bits).

[0023] Here, devices such as routers 10A and 10B basically perform routing table lookups for IP packets using the destination address, so changing the SIP does not generally affect forwarding. On the other hand, changing the SIP may affect forwarding in the following cases: - When a filter such as RPF includes an interface ID. - When strict packet checking is performed, such as when the header attachment / detachment device 20A searches all 128 bits as the tunnel destination to confirm a match. Therefore, it is preferable to use a flow label rather than SIP as the information used for downstream header usage.

[0024] The flow identification information is, for example, a combination of SIP and DIP. In a bidirectional flow, SIP in the upstream traffic 70 is replaced with DIP in the downstream traffic 80. The router 10B transmits downstream header information 10X to the header attachment / detachment device 20B as an IPFIX (IP Flow Information Export) packet, which is standardized as RFC (Request for Comments) 7011. This IPFIX packet contains basic information, such as flow identification information, and optional information, such as downstream header usage information. Meanwhile, the router 10B may use any protocol other than IPFIX, such as Netflow, as a protocol for notifying the flow identification information. The header attachment / detachment device 20B then receives downstream traffic 80 corresponding to the upstream traffic 70 from the receiving terminal TS2. The header attachment / detachment device 20B identifies downstream header usage information associated with the flow identification information of the upstream traffic 70 (= flow identification information of the downstream traffic 80), and forwards the downstream traffic 80 with an IPv6 header 82 containing the downstream header usage information to the router 10B.

[0025] As a result, the router 10B selects the same downstream pass-through interface as the upstream pass-through interface as a result of a hash calculation based on the IPv6 header 82 of the downstream traffic 80. Therefore, the upstream traffic 70 and the downstream traffic 80 pass through the same route 71P, allowing bidirectional flows to be concentrated and passed through the analysis device 31. The analysis device 31 can then identify the upstream traffic 70 and the downstream traffic 80 as a set of bidirectional flows. As a result, the analysis device 31 can perform analysis processing based on bidirectional flows, such as applying the same policy (assigning a QoS DSCP or queuing in a priority queue).

[0026] 2 is a configuration diagram of a router 10B and a header attachment / detachment device 20B. The router 10B has a user interface 11, a routing processing unit 12, a packet communication unit 13, a flow generation unit 14, and a header calculation unit 15. The header attachment / detachment device 20B has a user interface 21, a routing processing unit 22, a packet communication unit 23, a flow processing unit 24, a flow holding unit 26, and a tunnel header control unit 27.

[0027] The user interfaces 11 and 21 are management plane units that accept commands and APIs from users and external systems. The routing processing units 12 and 22 are control plane units that process routing protocols between devices and manage routes. The packet communication units 13 and 23 are user / data plane units that forward packets, send spontaneous packets, and receive self-addressed packets. The flow generation unit 14 generates packets such as IPFIX that notify downstream header usage information associated with flow identification information. The flow processing unit 24 performs processing to store packets generated by the flow generation unit 14 in the flow storage unit 26. The flow storage unit 26 is a data storage area that stores information processed by the flow processing unit 24.

[0028] The header calculation unit 15 creates downstream header usage information by calculating a hash function based on the following information: HA (Hash Algorithm) information is information indicating the algorithm used in the hash function and its initial value (seed). HF (Hash Field) information (field information) is information indicating a set of parameters in the IPv6 header 72 that serve as arguments input to the hash function, and is also called a hash key. LB (Load Balance) information indicates a set of interfaces that are candidates for downstream transit interfaces when determining a downstream transit interface from a hash value, which is the calculation result of the hash function. In other words, the LB information uses router 10A, which is the next hop for downstream traffic 80 to router 10B, as the next hop ID and indicates a set of interfaces for heading to that next hop ID.

[0029] The routers 10A and 10B each determine the transit interface for a packet to be transmitted based on a hash value calculated from the HF information used in a predetermined hash function (different functions may be used for the routers 10A and 10B) in the header information of the packet and information on a set of interfaces leading to the same destination of the packet. Here, the header calculation unit 15 sets part of the HF information as downstream header usage information so that the downstream transit interface calculated from the hash value and LB information of the IPv6 header 82 is the same as the upstream transit interface. The header calculation unit 15 then inputs the remaining HF information (other than the downstream header usage information), the LB information, and the downstream transit interface (=upstream transit interface), and reverse-calculates the downstream header usage information with a hash value that satisfies the relationship between the input data.

[0030] The tunnel header control unit 27 decapsulates the IPv6 header 72 when receiving upstream traffic 70, and generates and encapsulates an IPv6 header 82 when sending downstream traffic 80.

[0031] 3 is a hardware configuration diagram of each device constituting the flow communication system 100. Each device (routers 10A and 10B, header attachment / detachment devices 20A and 20B, and analyzers 31 and 32) of the flow communication system 100 is configured as a computer 900 having a CPU 901, RAM 902, ROM 903, HDD 904, communication I / F 905, input / output I / F 906, and media I / F 907. The communication I / F 905 is connected to an external communication device 915. The input / output I / F 906 is connected to an input / output device 916. The media I / F 907 reads and writes data from a recording medium 917. Furthermore, the CPU 901 controls each unit by executing a program (header information transmission program) loaded into the RAM 902. This program (also called an application, or simply "app") can be distributed via a communication line or recorded on a recording medium 917 such as a USB memory and distributed.

[0032] An example packet of downstream header information 10X will be described below with reference to Figures 4 and 5. Note that the IPFIX set header and template header are omitted in Figures 4 and 5. When the downstream header information 10X is an IPFIX packet, the packet format is defined by an Option Template (OT) and a Data Template (DT) that indicate optional information other than the flow identification information. The OT is a template that defines the data structure of each field included in the DT, and it is the DT that is actually used to notify the downstream header information 10X.

[0033] FIG. 4 is a packet format diagram showing an example of a notification OT of downstream header information 10X. The notification OT consists of six fields. In the fields divided into left and right, such as the first line of the notification OT, "DesignatedFieldID," the left field indicates the type of IE (Information Element) that is the data element (the number in parentheses is the IE ID specified in the standardization specification), and the right field indicates the length of that IE (in bytes). The second and sixth lines of the notification OT, "PEN = 210," indicate the PEN (Private Enterprise Number), which is the identifier of the organization that defined the IE, if the line above is a proprietary IE. For example, PEN = 210 is a number assigned to Nippon Telegraph and Telephone Corporation, the applicant of this application.

[0034] The first line of the notification OT, "DesignatedFieldID," indicates that it is treated as a scope (valid range) and is information for specifying the field value. The IE ID shown in parentheses, "32768," has the most significant bit set to 1, indicating a custom-defined IE. The IE ID, "110," is an arbitrary value within the custom definition and uses a value that does not overlap with other custom-defined IEs. The second bit of the IE ID in the fifth line of the notification OT, set to 1 (expressed as 16384 in decimal), indicates in this example that there is a field designated as downstream header usage information. If "flowLableIPv6" (IE ID=31) is specified in line 5, it is expressed as 32768+16384+31 in decimal.

[0035] FIG. 5 is a packet format diagram showing an example of a notification DT corresponding to the notification OT of FIG. 4. The notification DT is composed of four fields. An arbitrary value (e.g., "1") corresponding to the "DesignatedFieldID" in the first line of FIG. 4 is assigned to the first line of FIG. 5. The SIP of the downstream IPv6 header 82 corresponding to the "sourceIPv6address" in the third line of FIG. 4 is assigned to the second line of FIG. 5. This assigned SIP is obtained by replacing the DIP of the IPv6 header 72. The third line of FIG. 5 is assigned to the DIP of the downstream IPv6 header 82 corresponding to the "destinationIPv6address" in the fourth line of FIG. 4. This assigned DIP is obtained by replacing the SIP of the IPv6 header 72. The fourth line of FIG. 5 is assigned to the downstream header usage information of the downstream IPv6 header 82 corresponding to the "(Designated) flowLabelIPv6" in the fifth line of FIG. 4 (here, the designated value of flowLabelIPv6). This downstream header usage information is the reverse calculation result (e.g., the lowest 16 bits are 0x8416) of the hash value calculated by the header calculation unit 15 as the specified value of the "flowLabelIPv6" field, which is the field for which you want to specify a value. Note that "0x" indicates that the value that follows is a hexadecimal number.

[0036] The tunnel header control unit 27 of the header attachment / detachment device 20B newly generates an IPv6 header 82 to be added to the received downstream traffic 80. If the flow identification information in the IPv6 header 82 matches the flow identification information listed in the second and third lines of Fig. 5, the tunnel header control unit 27 overwrites the "flowLabelIPv6" field in the IPv6 header 82 with the specified value listed in the fourth line of Fig. 5.

[0037] 6 is a sequence diagram showing the operation of the flow communication system 100. In S11, the router 10A determines the analysis device 31 as the forwarding destination of the upstream traffic 70 received from the transmitting terminal TC2, and forwards the packets of the upstream traffic 70 to the analysis device 31. That is, the router 10A determines the forwarding destination from the result of modulo calculation of the hash value calculated from the HF information in the IPv6 header 72 of the received upstream traffic 70 and the number of interfaces (number of links) of the router 10A.

[0038] In S12, when the router 10B receives the upstream traffic 70 forwarded to the analysis device 31 in S11, it obtains downstream header usage information from the received upstream traffic 70 (see FIG. 7 for details). Note that the router 10B may refer to an access list (filter) that indicates, for each flow identification information, whether or not to perform the processing of S12 for the received upstream traffic 70, and may omit the processing of S12 and S13 for flows that match the access list.

[0039] In S13, the router 10B transmits downstream header information 10X, including the downstream header usage information calculated in S12, to the header attachment / detachment device 20B. In the example of FIG. 5, the router 10B creates the downstream header information 10X by the following process: - Inserts the SIP (e.g., 2001:db8:1012:3400:0:c000:0212:0034) of the received IPv6 header 72 into the DIP field of the third line. - Inserts the DIP (e.g., 2001:db8:1fff:1::1) of the received IPv6 header 72 into the SIP field of the second line. - Inserts the reverse calculation result of the hash value (e.g., the lowest 16 bits are 0x8416), which is the downstream header usage information calculated in S12, into the flowLabelIPv6 field of the fourth line. Furthermore, although omitted in FIG. 5, the downstream header information 10X also includes HA information and HF information of the router 10B.

[0040] In S14, the header attachment / detachment device 20B associates the flow identification information included in the downstream header information 10X received in S13 with the downstream header usage information and stores them in the flow storage unit 26. As a result, the processes of S12 to S14 can be omitted for the flow identification information stored in the flow storage unit 26 from the second time onwards.

[0041] That is, the header calculation unit 15 of the router 10B reverse-calculates the downstream header usage information, which is part of the HF information, so that the pass-through interface of the transmitted packet calculated from the hash value obtained from the HF information of the transmitted packet of the bidirectional flow and the information of the interface set is the same as the pass-through interface of the received packet of the bidirectional flow (S12).Then, the flow generation unit 14 of the router 10B transmits downstream header information 10X, which associates the flow identification information of the bidirectional flow with the downstream header usage information reverse-calculated by the header calculation unit 15, to the header attachment / detachment device 20B, and controls the header attachment / detachment device 20B to use the downstream header usage information in the pass-through header information of the transmitted packet that matches the transmitted flow identification information (S13).

[0042] In other words, the header calculation unit 15 of the router 10B calculates generation information for generating transmission header information for transmission packets such that the pass-through interface of the transmission packets of the bidirectional flow is the same as the pass-through interface of the reception packets of the bidirectional flow (S12).Then, the flow generation unit 14 of the router 10B transmits downstream header information 10X, which associates the flow identification information of the bidirectional flow with the generation information calculated by the header calculation unit 15, to the header attachment / detachment device 20B, and controls the header attachment / detachment device 20B to generate transmission header information for transmission packets that matches the transmitted flow identification information from the generation information (S13).

[0043] In S15, the router 10B forwards the upstream traffic 70 received from the analysis device 31 to the header attachment / detachment device 20B. In S16, the header attachment / detachment device 20B forwards the IPv4 packet 71 resulting from removing the IPv6 header 72 from the upstream traffic 70 received in S15 to the receiving terminal TS2. This completes the description of the forwarding process for the upstream traffic 70. Here, the upstream pass-through interface of the router 10B is the interface passed through when the upstream traffic 70 was received in S12.

[0044] In S21, if the flow identification information of the downstream traffic 80 received from the receiving terminal TS2 matches the flow identification information held in the flow holding unit 26, the header attaching / detaching device 20B adds an IPv6 header 82 including corresponding downstream header usage information and forwards the header 82 to the router 10B. The following shows an example of the IPv6 header 82 created by the header attaching / detaching device 20B: SIP=2001:db8:1fff:1::1 (DIP of the IPv6 header 72) DIP-2001:db8:1012:3400:0:c000:0212:0034 (SIP of the IPv6 header 72) Flow label=downstream header usage information calculated in S12 so that the downstream transit interface number of the router 10B is 0 (first link in the NHG, the remainder calculation result for the number of links is 0).

[0045] In S22, the router 10B selects the analysis device 31 as the destination based on the remainder calculation result of the hash value calculated from the HF information in the IPv6 header 82 of the downstream traffic 80 received from S21 and the number of interfaces (number of links) of the router 10B, and forwards the packet to the analysis device 31. Here, the upstream pass-through interface and the downstream pass-through interface match based on the downstream header usage information included in the HF information.

[0046] In S23, the router 10A transfers the downstream traffic 80 received from the analysis device 31 to the header attachment / detachment device 20A. This causes the bidirectional flow to pass through the same analysis device 31. In S31, the analysis device 31 performs analysis processing on the upstream traffic 70 and downstream traffic 80 of the bidirectional flow.

[0047] 7 is a flowchart showing the details of the process (S12) in which the router 10B obtains downstream header usage information from the upstream traffic 70. For the purpose of explaining this flowchart, consider the case in which the following IP addresses are assigned to the devices in FIG. 1: IP address of header attachment / detachment device 20A = 2001:db8:1012:3400:0:c000:0212:0034 (lower 16 bits are 0x0034) IP address of router 10B = 2001:db8:1fff:1::2 IP address of header attachment / detachment device 20B = 2001:db8:1fff:1::1 (lower 16 bits are 0x01)

[0048] Also, the link connected to the analysis device 31 is the first link (first link, selected when the remainder calculation result is 0 within the same NHG) in the output of the router 10B. On the other hand, the link connected to the analysis device 32 is the second link (second link, selected when the remainder calculation result is 1 within the same NHG) in the output of the router 10B.

[0049] At this time, the IPv6 header 72 of the upstream traffic 70 received by the router 10B is as follows: Source IP address: 2001:db8:1012:3400:0:c000:0212:0034 Destination IP address: 2001:db8:1fff:1::1 Flow label: 0 Receiving link: 0 (first link in the NHG (Next Hop Group), remainder calculation result for the number of links is 0)

[0050] In S121, the router 10B acquires, from the flow aggregation information of the received packets, the upstream transit interface for the packet having flow identification information where SIP=header attach / detach device 20A and DIP=header attach / detach device 20B. In S122, the router 10B acquires, from the LB information (Nexthop ID) of the router 10B itself, the number A of links constituting the ECMP (Equal Cost Multi Path) to which the upstream transit interface belongs and the ordinal number B of the link of which the upstream transit interface constitutes the ECMP.

[0051] In S123, router 10B obtains the HA to be used and its initial value from its own HA information, and also obtains its own HF information (field and number of bits used for hashing). Note that if the HA is CRC16 (0xf000), only the lowest 16 bits of each field in the HF information are used in the calculation. The initial value is also set to 0x02.

[0052] An example of HA information is shown below. - Only the lower 16 bits of a 16-bit field are handled, and the value obtained by concatenating each field is used as the input value. - The algorithm is CRC-16 (CRC-16-IBM) (generator polynomial: 0x8005 (left) / 0xA001 (right)) - The seed is 0x0002 (the lower 16 bits of the IP address of router 10B) - The HF information is SIP, DIP, and flow label

[0053] In S124, the router 10B assigns the link ordinal number B (for example, "0") to the final result hash value D (for example, "0x0000") so that the downstream pass-through interface is the same as the upstream pass-through interface. Note that the formula for calculating the interface ID described above is "(link ordinal number B) = (final result hash value D) mod (number of ECMP constituents A)." If (link ordinal number B) < (number of ECMP constituents A), then (link ordinal number B) = (final result hash value D).

[0054] In S125, the router 10B determines whether the HF information set in itself includes a flow label. If the answer is Yes in S125, the downstream header usage information is set to the flow label and the process proceeds to S126. If the answer is No, the downstream header usage information is set to SIP and the process proceeds to S128.

[0055] In S126, the router 10B calculates an intermediate hash value C (e.g., "0x8416") using HF information other than the flow label. The final hash value D is the calculation result obtained by referencing all HF information, including the downstream header usage information (the flow label in S126). The intermediate hash value C is the calculation result obtained by referencing HF information other than the downstream header usage information. S126 may be, for example, the calculation of steps 1 and 2 below. (Step 1) Using a seed (initial value): 0x02 as the initial state of the CRC16, calculate the CRC16 calculation result (0xf000) with SIP (lower 16 bits): 0x01. (Step 2) Using CRC16: 0xf000 as the internal state of the CRC16, calculate the CRC16 calculation result with DIP (lower 16 bits: 0x0034) as the intermediate hash value C (0x8416).

[0056] In S127, the router 10B calculates the flow label value (e.g., "0x8416"), which is the downstream header usage information, based on the final hash value D and the intermediate hash value C. For example, in the case of the parameters assigned in S124, the flow label value (0x8416) is calculated backward from the intermediate hash value C (0x8416) and the final hash value D (0x0000). Note that CRC backward calculation is a well-known technique (e.g., https: / / qiita.com / dearblue / items / 669e2ce2fae57baf1e90).

[0057] In S128, the router 10B calculates an intermediate hash value C using HF information other than SIP, similar to S126. In S129, the router 10B obtains SIP, which is downstream header usage information, based on the final hash value D and the intermediate hash value C, similar to S127.

[0058] [Effects] The router 10B of the present invention is characterized by having: a header calculation unit 15 that determines the pass-through interface of a packet to be sent from a hash value calculated from HF information used for a predetermined hash function in the header information of the packet and information on a set of interfaces going to the same destination of the packet; a header calculation unit 15 that reverse-calculates downstream header usage information, which is part of the HF information, so that the pass-through interface of the sent packet calculated from the hash value calculated from the HF information in the sending header information of the sent packet of the bidirectional flow and the information on the set of interfaces is the same as the pass-through interface of the received packet of the bidirectional flow; and a flow generation unit 14 that transmits downstream header information 10X, which associates flow identification information of the bidirectional flow with the downstream header usage information reverse-calculated by the header calculation unit 15, to the header attachment / detachment device 20B, and controls the header attachment / detachment device 20B so that the downstream header usage information is used in the send header information of the sent packet that matches the transmitted flow identification information.

[0059] This allows the router 10B to concentrate the bidirectional flow to a specific device and pass it through, even in an environment where bidirectional flows can be distributed to multiple devices for communication. Therefore, even if different operators operate adjacent forwarding devices (routers 10A and 10B) or if the forwarding devices (routers 10A and 10B) are not the same model, it is possible to control the bidirectional flow to be sent and received via the same link.

[0060] The router 10B of the present invention is characterized by having: a header calculation unit 15 that determines the pass-through interface of a packet to be sent from a hash value obtained from HF information used for a predetermined hash function in the header information of the packet and information on a set of interfaces going to the same destination of the packet; and calculates generation information for generating transmission header information of a transmission packet such that the pass-through interface of a transmission packet in a bidirectional flow is the same as the pass-through interface of a reception packet in a bidirectional flow; and a flow generation unit 14 that controls the header attachment / detachment device 20B to generate, from the generation information, transmission header information of a transmission packet that matches the transmitted flow identification information by transmitting downstream header information 10X that associates flow identification information of the bidirectional flow with the generation information calculated by the header calculation unit 15 to the header attachment / detachment device 20B.

[0061] As a result, even if the predetermined hash function used by the router 10B is a special hash calculation algorithm that is not implemented in other devices, the router 10B itself can create downstream header usage information based on the special hash calculation algorithm, thereby reducing the additional cost of implementing the special hash calculation algorithm in routers other than the router 10B.

[0062] The present invention is characterized in that the flow generation unit 14 generates an IPFIX packet in which the flow identification information of the bidirectional flow is used as basic information as the downstream header information 10X, and the downstream header usage information calculated inversely by the header calculation unit 15 is used as optional information.

[0063] As a result, the router 10B can reduce development costs and maintain high compatibility by using IPFIX, a standard protocol for notifying flow identification information.

[0064] 10A Router 10B Router (header information transmission device) 11 User interface 12 Routing processing unit 13 Packet communication unit 14 Flow generation unit 15 Header calculation unit 20A, 20B Header attachment / detachment device 21 User interface 22 Routing processing unit 23 Packet communication unit 24 Flow processing unit 26 Flow holding unit 27 Tunnel header control unit 31 Analysis device 32 Analysis device 100 Flow communication system

Claims

1. A header information transmitting device comprising: a header calculation unit that determines a pass-through interface for a packet to be transmitted from a hash value calculated from field information used for a predetermined hash function in the header information of the packet and information on a set of interfaces heading to the same destination of the packet; a header calculation unit that reverse-calculates header usage information that is a part of the field information so that the pass-through interface for the transmitted packet calculated from the hash value calculated from the field information of the transmission header information of the transmitted packet of a bidirectional flow and the information on the set of interfaces is the same as the pass-through interface for the received packet of the bidirectional flow; and a flow generation unit that controls the header attachment / detachment device to use the header usage information for the transmission header information of the transmitted packet that matches the transmitted flow identification information by transmitting the header information that associates the flow identification information of the bidirectional flow with the header usage information reverse-calculated by the header calculation unit.

2. The header information transmission device according to claim 1, wherein the flow generation unit generates an IPFIX (IP Flow Information Export) packet in which the header information is based on flow identification information of the bidirectional flow as basic information and the header usage information calculated by the header calculation unit as optional information.

3. A header information transmitting device comprising: a header calculation unit that determines a pass-through interface for a packet to be transmitted from a hash value calculated from field information used for a predetermined hash function in the header information of the packet and information on a set of interfaces going to the same destination of the packet; and a flow generation unit that controls the header attachment / detachment device to generate, from the generation information, the transmission header information of the transmission packet of a bidirectional flow such that the pass-through interface of the transmission packet of the bidirectional flow is the same as the pass-through interface of a reception packet of the bidirectional flow; and a flow generation unit that controls the header attachment / detachment device to generate, from the generation information, the transmission header information of the transmission packet that matches the transmitted flow identification information by transmitting the header information that associates the flow identification information of the bidirectional flow with the generation information calculated by the header calculation unit.

4. A header information transmission method, characterized in that a header information transmitting device determines a pass-through interface for a packet to be transmitted based on a hash value calculated from field information used for a predetermined hash function in the header information of the packet and information on a set of interfaces heading to the same destination of the packet, the header information transmitting device having a header calculation unit and a flow generation unit, the header calculation unit reverse-calculates header usage information, which is a part of the field information, so that the pass-through interface for the transmitted packet, calculated from the hash value calculated from the field information of the transmission header information of the transmitted packet of a bidirectional flow and the information on the set of interfaces, is the same as the pass-through interface for the received packet of the bidirectional flow, the flow generation unit transmits the header information, which corresponds to the flow identification information of the bidirectional flow and the header usage information reverse-calculated by the header calculation unit, to a header attachment / detachment device, thereby controlling the header attachment / detachment device to use the header usage information for the transmission header information of the transmitted packet that matches the transmitted flow identification information.

Citation Information

Patent Citations

  • Packet transmission method and apparatus thereof

    JP2004254132A

  • Controller, control method, and network system

    JP2016163264A

  • Load distribution system and load distribution method

    WO2019163518A1