Method for taking ACL rules into effect, and electronic device and storage medium

By dividing compatible and incompatible ACL rule groups on network devices and selecting compatible groups to take effect, the functional limitations caused by incompatibility of ACL rules in the prior art are solved, and the multi-rule effect and rapid recovery functions of network devices are realized.

WO2025112685A1PCT designated stage expired Publication Date: 2025-06-05ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/113326
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-30
Filing Date
2024-08-20
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

When existing network devices process ACL rules, because ACL rules in different dimensions may be incompatible, they can only choose one ACL rule to take effect, resulting in the functions of other ACL rules being unable to be used normally, and need to be reset after the device restarts, which is uncertain.

Method used

By determining all candidate ACL rules on the target object that matches the target message and dividing them into compatible and incompatible groups, selecting compatible ACL rules groups for taking effect, ensuring that ACL rules are compatible, so as to achieve as much functions as possible while avoiding logical conflicts in packet processing.

Benefits of technology

It realizes that network equipment can take effect on multiple compatible ACL rules at the same time, enriches application scenarios, and can quickly restore most of the original effective ACL rules after the device restarts, ensuring the reliability and consistency of functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024113326_05062025_PF_FP_ABST
    Figure CN2024113326_05062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a method for taking ACL rules into effect, and an electronic device and a storage medium. The method comprises: determining all candidate ACL rules on a target object, which candidate ACL rules match a target message; determining all target ACL rules from among all the candidate ACL rules, wherein any two of the target ACL rules are compatible with each other; and taking all the target ACL rules into effect on the target object, wherein the target ACL rules are used for guiding the target object to process the target message.
Need to check novelty before this filing date? Find Prior Art

Description

ACL rule validation method, electronic device, and storage medium

[0001] Cross-references

[0002] This application claims priority to a Chinese patent application filed with the Patent Office of China on November 30, 2023, with application number 202311636899.1 and invention name “A method for activating ACL rules, an electronic device and a storage medium”. The entire contents of the application are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication technology, and in particular to a method for validating ACL rules, an electronic device, and a storage medium. Background Art

[0004] Access Control Lists (ACLs) are a common access control technology used in network devices such as routers, switches, and firewalls. To avoid conflicts in message processing logic, related technologies typically prioritize only one ACL rule to take effect. This conservative approach can prevent the proper functioning of many other ACL rules.

[0005] Summary of the Invention

[0006] The purpose of this application is to provide a method for validating ACL rules, an electronic device, and a storage medium.

[0007] In a first aspect, a method for validating ACL rules is provided, comprising: determining all candidate ACL rules on a target object that match a target message; determining all target ACL rules from all the candidate ACL rules; wherein any two of the target ACL rules are compatible with each other; validating all the target ACL rules on the target object; wherein the target ACL rules are used to guide the target object to process the target message.

[0008] In a second aspect, an embodiment of the present application provides an electronic device, comprising: a processor; and a memory configured to store computer-executable instructions, wherein the computer-executable instructions, when executed, cause the processor to execute the method described in the first aspect.

[0009] According to a third aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium is used to store computer-executable instructions, and the computer-executable instructions implement the method described in the first aspect when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0011] FIG1 is a flow chart of a method for validating ACL rules according to an embodiment of the present application.

[0012] FIG2 is a schematic diagram of a process for matching ACL rules to be effective according to an embodiment of the present application.

[0013] FIG3 is a schematic diagram of the structure of an ACL rule validation device according to an embodiment of the present application.

[0014] FIG4 is a schematic structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0015] As mentioned above, with the evolution of network technology, the ACL rules configured on network devices have become increasingly complex, considering more and more dimensions. However, different dimensions have different starting points for the processing logic of data packets. As a result, some incompatible ACL rules may be configured on network devices for the same packet.

[0016] Here, we briefly use ACL rules in the network security dimension as an example. From the perspective of the network device's port, the ACL rule set for the target packet is a permit operation. However, from the perspective of the entire virtual local area network (VLAN), the ACL rule set for the target packet may be a deny operation. For the network device, both the port-level permit and the VLAN-level deny are ACL rules set for the target packet, but the two are clearly incompatible.

[0017] The above example illustrates only one scenario where ACL rules have conflicting processing logic. In practice, the overlapping and mutually exclusive nature of ACL rules is even more complex. There are ACL rules for rate limiting for Quality of Service (QoS), ACL rules for route matching, and so on. To avoid conflicts in message processing logic, current network devices only prioritize one ACL rule. This prevents the normal operation of many other ACL rules, significantly limiting network devices.

[0018] Furthermore, after a network device restarts, the effective ACL rules need to be reset. Typically, the upper layer issues the effective ACL rules to the network device. Therefore, which ACL rules take effect on the network device depends on the order in which they are issued, which is highly uncertain.

[0019] In view of this, the present application aims to propose a technical solution in which a network device can automatically and simultaneously take effect on multiple ACL rules.

[0020] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this specification, not all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this specification.

[0021] An embodiment of the present application provides a method for validating ACL rules, which can be applied to network devices such as routers and layer 3 switches, or a port of a network device, or an entire VLAN. Figure 1 is a flow chart of the validation method of this embodiment, which includes the following steps.

[0022] S102: Determine all candidate ACL rules on the target object that match the target message.

[0023] In this embodiment, the target object may refer to a network device, a port on the network device, a VLAN, etc., which is not specifically limited in this document; all candidate ACL rules that match the target message refer to all ACL rules configured for the target text on the target object, and may not be limited to ACL rules of at least one of the port plane control dimension, QoS plane control dimension, and VLAN plane control dimension.

[0024] Specifically, all configured ACL rules of the target object are stored in the local chip. When the target message is received, a table lookup can be performed in the local chip to find all candidate ACL rules that match the target message.

[0025] S104: Determine all target ACL rules from all candidate ACL rules; any two target ACL rules are compatible with each other.

[0026] Specifically, this embodiment divides all ACL rules into at least one group based on the conflicting relationships among the ACL rules on the target object. Each ACL rule is assigned to a group, and all ACL rules in each group are compatible with each other. That is, all ACL rules in a group can be applied to the target object, thus distinguishing the conflicting relationships by group.

[0027] As an example, all ACL rules on a target object can be categorized into fully compatible and incompatible types. As the name implies, fully compatible ACL rules are compatible with all other ACL rules on the target object; incompatible ACL rules are incompatible with at least one other ACL rule on the target object.

[0028] On the one hand, this embodiment divides all fully compatible ACL rules into a first type group.

[0029] For example, ACL rules such as statistics, mirroring, enabling or disabling Differentiated Services Code Points (DSCP), and QoS rate limiting do not conflict with any other ACL rules. ACL rules of the statistics, mirroring, DSCP, and QoS categories are classified as the first type group.

[0030] If the first type group includes candidate ACL rules that match the target message, all candidate ACL rules corresponding to the first type group are determined as target ACL rules.

[0031] On the other hand, this embodiment divides all non-fully compatible ACL rules into at least two second-type groups. Any two incompatible non-fully compatible ACL rules are divided into different second-type groups, and each ACL rule in a second-type group is incompatible with at least some of the ACL rules in the other second-type groups that conflict with it.

[0032] For example, the ACL rules of Drop and Deny are incompatible with the ACL rules of Permit and Redirect. In this case, Drop and Deny are classified into one second-type group, and Permit and Redirect are classified into another second-type group.

[0033] If both conflicting second-type groups contain candidate ACL rules that match the target message, then all candidate ACL rules corresponding to one of the second-type groups will be determined as the target ACL rules, and the remaining second-type groups will be disregarded. For example, if both the "Drop" and "Deny" second-type groups and the "Permit" and "Redirect" second-type groups contain candidate ACL rules that match the target message, if all candidate ACL rules in the "Drop" and "Deny" second-type groups are used to determine the target ACL rules, then the target ACL rules in the "Permit" and "Redirect" second-type groups will no longer be considered.

[0034] In addition, in some embodiments, among the second-type groups that conflict with each other, the one containing the largest number of candidate ACL rules can be determined as the target second-type group, and all candidate ACL rules in the target second-type group can be determined as target ACL rules, thereby maximizing the number of target ACL rules; or, according to actual needs, group priorities can be configured in advance for each second-type group that conflicts with each other, and the second-type group with the highest group priority among the second-type groups corresponding to the candidate ACL rules can be determined as the target second-type group, and then all candidate ACL rules in the target second-type group can be determined as target ACL rules.

[0035] S106 , all target ACL rules are enabled on the target object; wherein the target ACL rules are used to guide the target object to forward the target message.

[0036] In this embodiment, all target ACL rules are compatible, so all target ACL rules can be applied to the target object simultaneously. It should be understood that once these target ACL rules are applied to the target object, the target object is controlled to process the target packets according to the actions indicated by the target ACL rules. These actions may include, but are not limited to, the aforementioned allow or deny actions, QoS rate limiting, and DSCP enable / disable actions.

[0037] Assuming that target ACL rules for QoS rate limiting, network security, and DSCP are in effect at the same time, the target object can use QoS rate limiting, network security, and DSCP functions simultaneously. Compared with the traditional solution of only taking effect on the best ACL rule, this enriches the application scenarios.

[0038] Based on the method of this embodiment, when the target object receives the target message, it first queries all local ACL rules that match the target message as candidate ACL rules. Then, it finds all compatible target ACL rules among all candidate ACL rules and makes them effective for all target ACL rules, thereby achieving as many ACL rule functions as possible to serve different scenarios while avoiding conflicts in message processing logic. In addition, since the target object is able to implement the ACL rules by itself, when the physical device of the target object is restarted, most of the original effective ACL rules can be quickly restored without waiting for the upper layer to re-issue the ACL rules, and this restoration is deterministic and will not bring unexpected changes to the overall function.

[0039] The method of this embodiment is described in detail below in conjunction with actual application scenarios.

[0040] In this application scenario, the target object is a port, and the ACL rules include: Permit, Drop, Deny, Statistics, Mirror, Redirect, Set DSCP, and QoS rate limit operations.

[0041] As shown in FIG2 , these ACL rules are pre-classified into the following groups.

[0042] Statistics, Mirror, Redirect, Set DSCP, and QoS rate limit operations do not conflict with other ACL rules. Therefore, statistics, Mirror, Redirect, Set DSCP, and QoS rate limit are classified as the first type group.

[0043] Drop and Deny are compatible with each other, and Permit and Redirect are compatible with each other. However, "Drop, Deny" and "Permit, Redirect" are incompatible. Therefore, Drop and Deny are classified into one second type group, and Permit and Redirect are classified into another second type group.

[0044] It should be understood that the above-divided groups can be applied as prior knowledge.

[0045] Afterwards, after the target object receives the target message, it executes the following steps.

[0046] 1. Based on the target message information, the local chip performs an ACL rule lookup to determine all candidate ACL rules applicable to the target message.

[0047] 2. Find all ACL entries related to the port of this target message. Suppose candidate ACL rules 1 / 2 / 3 / 4 are found.

[0048] 3. Match ACL rules 1 / 2 / 3 / 4 with the divided groups.

[0049] Here, it is assumed that ACL rule 1 is in the first type group, ACL rules 2 and 3 are in the second type group of "Drop, Deny", and ACL rule 4 is in the second type group of "Permit, Redirect".

[0050] Note that ACL rule 1 belongs to the first group, indicating that it is one of the following: Statistics, Mirror, Redirect, Set DSCP, and QoS Rate Limit. Similarly, ACL rules 2 and 3 belong to the second group, indicating that they are one of the following: Drop, Deny. This is not detailed here.

[0051] Based on the matching relationship between ACL rules 1 / 2 / 3 / 4 and the current first-type group and second-type group, it can be determined that: ACL rule 1 is compatible with any other ACL rules, so ACL rule 1 is directly determined as the target ACL rule that takes effect subsequently. ACL rules 2 and 3 conflict with ACL rule 4. Because the second-type group of "Drop, Deny" contains two ACL rules related to the target message, while the second-type group of "Permit, Redirect" contains only one ACL rule related to the target message, under the policy of making as many ACL rules as possible effective, ACL rules 2 and 3 are determined as the target ACL rules that take effect subsequently, while ACL rule 4 is directly ignored. Alternatively, if the second-type group of "Permit, Redirect" is pre-set to have a higher group priority than the second-type group of "Drop, Deny", ACL rule 4 can also be determined as the target ACL rule that takes effect subsequently, while ACL rules 2 and 3 are directly ignored.

[0052] 4. On the target object, all the target ACL rules in ACL rules 1 / 2 / 3 / 4 are simultaneously effective.

[0053] It should be noted that the above solution allows the target object to run ACL rules of different dimensions simultaneously. Here, taking the port dimension ACL rules and QoS dimension ACL rules as examples, the following scenarios can be implemented.

[0054] A. ACL rules take effect simultaneously if they do not conflict: Port-level ACL rules, such as permit and statistics, do not conflict with ACL rules in all QoS dimensions, so they can take effect simultaneously.

[0055] B. The QoS ACL rule contains a Drop option, while the port ACL rule contains a Permit option and statistics. If the port ACL rule contains a Permit option, the packet will be either Drop or Permit, and statistics will be taken simultaneously.

[0056] C. If the port-level ACL rule contains the deny option and the QoS-level ACL rule contains the mirror and statistics option, the packet is denied, and the mirror and statistics options are also enabled.

[0057] D. If the port-level ACL rule contains Deny and the QoS-level ACL rule contains Redirect and Set DSCP, then the packet will be either Deny or Redirected, and Set DSCP will be applied at the same time.

[0058] E. If the port-level ACL rule contains a "Deny" action, and the QoS-level ACL rule contains a rate-limiting action such as "Police CIR," both the "Deny" and "Police CIR" actions take effect simultaneously. Alternatively, "Police CIR" can take effect first, followed by "Deny."

[0059] In summary, the method of this embodiment can improve the application scope of ACL rules of network devices, especially in scenarios where multi-dimensional ACL rules intersect, and has a good application effect.

[0060] In addition, another embodiment of the present application proposes an ACL rule validation device, which can be applied to network devices such as routers, three-layer switches, or a port of a network device, or an entire VLAN. Figure 3 is a structural diagram of the validation device 300, including: a rule matching module 310, used to determine all candidate ACL rules that match the target message on the target object. A rule screening module 320, used to determine all target ACL rules from all the candidate ACL rules; wherein any two of the target ACL rules are compatible with each other. A rule validation module 330, used to validate all the target ACL rules on the target object; wherein the target ACL rules are used to guide the target object to process the target message.

[0061] Based on the device of the embodiment of the present application, when the target object receives the target message, it first queries all local ACL rules that match the target message as candidate ACL rules. Then, it finds all compatible target ACL rules among all candidate ACL rules and makes them effective for all target ACL rules, thereby achieving as many functions of ACL rules as possible to serve different scenarios under the premise of avoiding logical conflicts in message processing. In addition, since it is a solution in which the target object takes effect on its own ACL rules, when the physical device of the target object is restarted, most of the original effective ACL rules can be quickly restored without waiting for the upper layer to re-issue the ACL rules, and this restoration is deterministic and will not bring unexpected changes to the overall function.

[0062] Optionally, the rule screening module 320 determines all target ACL rules from all candidate ACL rules, including: determining at least one group corresponding to all candidate ACL rules; the at least one group is obtained by pre-dividing all ACL rules on the target object, one ACL rule corresponds to one group, and all ACL rules in each group are compatible with each other; based on the at least one group, all target ACL rules are determined.

[0063] Optionally, the rule screening module 320 determines all the target ACL rules based on the at least one group, including: if the at least one group includes a first-type group, determining all the candidate ACL rules corresponding to the first-type group as the target ACL rules; wherein each ACL rule in the first-type group is compatible with other ACL rules on the target object. And, if the at least one group includes at least two conflicting second-type groups, based on a preset rule, determining all the candidate ACL rules corresponding to one of the second-type groups as the target ACL rules; wherein each ACL rule in the second-type group is incompatible with at least some of the ACL rules in the other second-type groups with which it is conflicting.

[0064] Optionally, before determining the at least one group corresponding to all the candidate ACL rules, the rule screening module 320 further divides all the ACL rules into the at least one group according to the effective conflict relationship between all the ACL rules on the target object.

[0065] Optionally, dividing all ACL rules into the at least one group based on the effective conflict relationship between all ACL rules on the target object includes: determining all fully compatible ACL rules from all ACL rules on the target object; wherein the fully compatible ACL rules are mutually compatible with other ACL rules on the target object; and dividing all the fully compatible ACL rules into the first type group.

[0066] Optionally, dividing all ACL rules into the at least one group according to the effective conflict relationship between all ACL rules on the target object includes: determining all non-fully compatible ACL rules from all ACL rules on the target object; wherein the non-fully compatible ACL rules are incompatible with at least one other ACL rule on the target object; and dividing all non-fully compatible ACL rules into at least two second-type groups; wherein any two incompatible non-fully compatible ACL rules are divided into different second-type groups.

[0067] Optionally, for non-fully compatible ACL rules whose corresponding operations are drop operation, deny operation, permit operation and redirect operation, the non-fully compatible ACL rules corresponding to the drop operation and the deny operation are divided into one second type group, and the non-fully compatible ACL rules corresponding to the permit operation and the redirect operation are divided into another second type group.

[0068] Optionally, the rule screening module 320 determines all the candidate ACL rules in one of the second-type groups as target ACL rules based on preset rules, including: among all the second-type groups, determining the one containing the largest number of candidate ACL rules as the target second-type group, or determining the second-type group with the highest group priority as the target second-type group; and determining all the candidate ACL rules corresponding to the target second-type group as the target ACL rules.

[0069] Optionally, the target object includes at least one of a port of a communication device and a virtual network, wherein the target object corresponds to an ACL rule of at least one of a port plane control dimension, a quality of service plane control dimension, and a virtual network plane control dimension.

[0070] It should be noted that the ACL rule validation device of this embodiment is the execution subject of the method shown in FIG. 1 , and thus can implement the steps and functions of the method shown in FIG. 1 .

[0071] FIG4 is a schematic diagram of the structure of an electronic device according to an embodiment of the present specification. Referring to FIG4 , at the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include a memory, such as a high-speed random access memory (RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage device. Of course, the electronic device may also include hardware required for other services.

[0072] The processor, network interface, and memory can be interconnected via an internal bus, which can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. These buses can be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG4 shows only one bidirectional arrow, but this does not imply that there is only one bus or only one type of bus.

[0073] The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provide instructions and data to the processor. The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it. Correspondingly, the processor executes the program stored in the memory, and is specifically used to perform the following operations: determine all candidate ACL rules on the target object that match the target message. Determine all target ACL rules from all candidate ACL rules; wherein any two target ACL rules are compatible with each other. All target ACL rules are effective on the target object; wherein the target ACL rules are used to guide the target object to process the target message.

[0074] Based on the electronic device of this embodiment, when the target object receives the target message, it first queries all local ACL rules that match the target message as candidate ACL rules. Then, it finds all compatible target ACL rules among all candidate ACL rules and makes them effective for all target ACL rules, thereby achieving as many functions of ACL rules as possible to serve different scenarios while avoiding conflicts in message processing logic. In addition, since the target object is able to make the ACL rules effective on its own, when the physical device of the target object is restarted, most of the original effective ACL rules can be quickly restored without waiting for the upper layer to re-issue the ACL rules, and this restoration is deterministic and will not bring unexpected changes to the overall function.

[0075] The ACL rule validation method disclosed in the embodiments shown in this specification can be applied to a processor and implemented by the processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or software instructions. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0076] Of course, in addition to software implementation, the electronic device in this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0077] In addition, an embodiment of the present application also proposes a computer-readable storage medium, which stores one or more programs, and the one or more programs include instructions. When the above instructions are executed by a portable electronic device including multiple applications, the portable electronic device can perform the steps of the method shown in Figure 1, including: determining all candidate ACL rules on the target object that match the target message. Determining all target ACL rules from all the candidate ACL rules; wherein any two of the target ACL rules are compatible with each other. Enforcing all the target ACL rules on the target object; wherein the target ACL rules are used to guide the target object to process the target message.

[0078] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0079] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0080] The above are merely examples of the present invention and are not intended to limit this specification. For those skilled in the art, various modifications and variations of this specification are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification shall be included within the scope of the claims of this specification. In addition, all other embodiments obtained by those of ordinary skill in the art without creative effort shall fall within the scope of protection of this document.

Claims

1. A method for validating an access control list (ACL) rule, comprising: Determine all candidate ACL rules on the target object that match the target message; Determine all target ACL rules from all candidate ACL rules; wherein any two target ACL rules are compatible with each other; All the target ACL rules are effective on the target object; wherein the target ACL rules are used to guide the target object to process the target message.

2. The method according to claim 1, Determine all target ACL rules from all candidate ACL rules, including: Determine at least one group corresponding to all the candidate ACL rules; The at least one group is obtained by pre-dividing all ACL rules on the target object, one ACL rule is divided into one group, and all ACL rules in each group are compatible with each other; Based on the at least one group, all the target ACL rules are determined.

3. The method according to claim 2, Based on the at least one group, all the target ACL rules are determined, including: In the case that the at least one group includes a first type group, all the candidate ACL rules corresponding to the first type group are determined as the target ACL rules; wherein each ACL rule in the first type group is compatible with other ACL rules on the target object.

4. The method according to claim 2, Based on the at least one group, all the target ACL rules are determined, including: In the case where the at least one group includes at least two valid conflicting groups of the second type, Based on preset rules, all the candidate ACL rules corresponding to one of the second type groups are determined as the target ACL rules; wherein each ACL rule in the second type group is incompatible with at least some ACL rules in other second type groups that conflict with it.

5. The method according to claim 4, Based on a preset rule, determining all the candidate ACL rules corresponding to one of the second type groups as the target ACL rules includes: Among all the second type groups, the one containing the largest number of the candidate ACL rules is determined as the target second type group, or the second type group with the highest group priority is determined as the target second type group; All the candidate ACL rules corresponding to the target second type group are determined as the target ACL rules.

6. The method according to claim 2, Before determining at least one group corresponding to all the candidate ACL rules, the method further includes: According to the effective conflict relationship between all the ACL rules on the target object, all the ACL rules are divided into the at least one group.

7. The method according to claim 6, According to the effective conflict relationship between all ACL rules on the target object, the all ACL rules are divided into the at least one group, including: Determine all fully compatible ACL rules from all ACL rules on the target object; wherein the fully compatible ACL rules are compatible with other ACL rules on the target object; All the fully compatible ACL rules are divided into a first type group.

8. The method according to claim 6, According to the effective conflict relationship between all ACL rules on the target object, the all ACL rules are divided into the at least one group, including: Determine all non-fully compatible ACL rules from all ACL rules on the target object; wherein the non-fully compatible ACL rules are incompatible with at least one other ACL rule on the target object; All the non-fully compatible ACL rules are divided into at least two second type groups; wherein any two incompatible non-fully compatible ACL rules are divided into different second type groups.

9. The method according to claim 8, For the non-fully compatible ACL rules whose corresponding operations are dropping the drop operation, rejecting the deny operation, allowing the permit operation and redirecting the redirect operation, the non-fully compatible ACL rules corresponding to the drop operation and the deny operation are divided into one second type group, and the non-fully compatible ACL rules corresponding to the permit operation and the redirect operation are divided into another second type group.

10. The method according to any one of claims 1 to 9, The target object includes at least one of a port of a communication device and a virtual network.

11. The method according to claim 10, The target object corresponds to an ACL rule of at least one of a port plane control dimension, a service quality plane control dimension, and a virtual network plane control dimension.

12. An electronic device, comprising a processor; and a memory configured to store computer executable instructions, wherein when the computer executable instructions are executed, the processor performs the method according to any one of claims 1 to 11.

13. A computer-readable storage medium, wherein the computer-readable storage medium is used to store computer-executable instructions, wherein the computer-executable instructions implement the method according to any one of claims 1 to 11 when executed by a processor.

Citation Information

Patent Citations

  • Management method and equipment of ACL regulation

    CN101141304A

  • ACL configuration method, device, equipment and medium

    CN115242493A

  • Access control list validating control method and device, equipment and storage medium

    CN116016387A

  • Method and apparatus for implementing filter rules in a network element

    US20070150614A1