Method and apparatus for solving ipsec elephant flow on basis of dpdk
By initializing multiple CPU cores in the DPDK environment and performing load balancing distribution, the elephant stream is effectively processed in the IPSec link, solving the performance bottleneck problem when a single-core CPU is processing elephant stream, and achieving efficient IPSec elephant stream processing.
Patent Information
- Application Number
- PCT/CN2024/135825
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-12
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-19
AI Technical Summary
The prior art is difficult to effectively deal with CPU performance bottlenecks caused by IPSec elephant streams, especially in a single-core processor environment, which may lead to packet loss and transmission quality degradation.
Using the DPDK-based method, by initializing multiple CPU cores as PMD thread cores and encrypting and decrypting engine working cores, a lock-free ring is established for inter-core communication, and the PMD thread core is periodically polled to detect elephant flow, and load balancing is performed to the encrypting and decrypting engine working cores for parallel processing.
It effectively solves the performance bottleneck when single-core CPUs handle IPSec elephant streams, realizes efficient processing of elephant streams, reduces message loss, improves transmission quality, and is suitable for domestic information innovation environments.
Smart Images

Figure CN2024135825_19062025_PF_FP_ABST
Abstract
Description
A method and device for solving IPSec elephant flow based on DPDK Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a method and device for resolving IPSec elephant flows based on DPDK. Background Art
[0002] With the development of SD-WAN and the increasing security demands of enterprises and government departments, using IPSec to encrypt data in the transmission path has become a basic requirement. More and more organizations are building their own virtual private networks, with IPSec protocol providing tunnel security.
[0003] With the deepening of informatization, the increasing number of cloud-based services, the massive amounts of data used in AI training, and the high-quality transmission of video conferencing and film productions are driving high throughput demands on SD-WAN IPSec access. This data generates large, continuous flows within IPSec links. These flows impose significant bandwidth requirements and pose challenges for the encryption and decryption nodes within IPSec links. Because encryption and decryption consume significant CPU resources, the arrival of these flows can overwhelm a single CPU thread, leading to packet drops. Furthermore, with the development of domestically produced information and communication technologies, more companies and departments are opting for domestic processors to transition away from Intel processors. However, current single-core performance comparisons show that domestic processors are still far behind Intel processors. Currently, domestic servers generally increase their overall computing power by adding more CPU cores. However, using DPDK's RTC model can lead to bottlenecks in processing these flows due to reduced single-core performance.
[0004] To address the issue of IPSec "elephant flows," offloading is commonly used, enhancing hardware capabilities. Intel has introduced barefoot-based programmable switching chips that achieve higher throughput. It has also introduced CPUs with DLB functionality, which can distribute "elephant flows" across multiple CPUs. Similarly, NVIDIA's new generation CX7 series network cards can use hardware encryption and decryption to process packets, then use the RSS function of the inner packets to send them to the various queues of the network card, thereby splitting a single "elephant flow" into multiple flows. These newly available hardware solutions address the issues of "elephant flows" and higher throughput, but they may not be used due to price and cost issues or the special requirements of the information and innovation field. Summary of the Invention
[0005] This application aims to at least partially address one of the technical problems in the related art. To this end, one purpose of this application is to propose a method and apparatus for resolving IPSec elephant flows based on DPDK. This application, based on DPDK technology, implements software-based IPSec elephant flow detection and multi-core IPSec elephant flow encryption and decryption to address the performance bottleneck of single-core processors, which has a wider range of application scenarios.
[0006] One aspect of the present application provides a method for resolving IPSec elephant flows based on DPDK, including:
[0007] Step S100: According to the configuration file, CPU0 and CPU1 are initialized as PMD thread cores, CPU2, CPU3, and CPU4 are initialized as encryption and decryption engine working cores, an unlocked loop is created for communication between the PMD thread cores and the encryption and decryption engine working cores, and a network card send queue and a network card receive queue are established;
[0008] Initializing CPU0 and CPU1 as PMD thread cores means that both CPU0 and CPU1 are implemented as PMD thread cores of DPDK, and perform polling tasks on the network card send queue and the network card receive queue;
[0009] Initializing CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores means that CPU 2, CPU 3, and CPU 4 are implemented as encryption and decryption engine working cores to implement encryption and decryption processing of messages, wherein the first CPU core is CPU 2, which is used to perform message processing of ordinary flows, and CPU 3 and CPU 4 are used to perform message encryption and decryption of elephant flows in parallel;
[0010] Creating a lockless loop for communication between the PMD thread core and the encryption and decryption engine working core means: using the lockless loop of DPDK, during the initialization phase, establishing a communication channel between the PMD thread cores, i.e., CPU0 and CPU1, and the encryption and decryption engine working core, to achieve inter-core message transmission;
[0011] The network card sending queue is used to store messages to be sent to the network;
[0012] The network card receiving queue is used to store messages received from the network;
[0013] Step S200: The PMD thread core regularly performs polling to obtain messages and detects the large flow and the ordinary flow, performs load balancing on the large flow, and distributes the messages to the encryption and decryption engine working core;
[0014] The PMD thread core regularly performs polling to obtain messages and detect large flows and ordinary flows, performs load balancing on large flows, and distributes messages to the encryption and decryption engine working cores in the following specific steps:
[0015] Step S210: calling rte_eth_rx_burst() to read the messages in the network card receive queue, and dividing the messages into fragmented messages and non-fragmented messages according to their sizes;
[0016] The fragmented message means that when the size of the message exceeds the maximum transmission unit of the network link, the message will be divided into m fragments, each fragment is a fragmented message;
[0017] The non-fragmented message means that if the size of the message is less than or equal to the maximum transmission unit of the network link, the entire message can be transmitted in one message without being divided into fragments;
[0018] Step S220: reassemble the fragmented message to obtain a reassembled message;
[0019] The fragmented messages are reassembled by storing the received fragmented messages in a fragment linked list, and if the last fragmented message has not been received, storing the received fragmented messages in the fragment linked list to wait for subsequent fragmented messages, and assembling the fragmented messages that arrive in order according to their position information in the original message to obtain a reassembled message;
[0020] Step S230: Perform sflow sampling on the received non-fragmented messages, which include reassembled messages and messages that do not need to be fragmented. Count the known flow data of the first K transmission flows. If a transmission flow reaches the threshold of the elephant flow, record the five-tuple information of the transmission flow and update the flow table array of the elephant flow.
[0021] The sflow sampling is performed on the received non-fragmented message, and the non-fragmented message includes a reassembled message and a message that does not need to be fragmented. The known flow data of the first K transmission flows are counted. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the flow table array of the elephant flow is updated. It means: for each non-fragmented message, the sflow sampling operation is performed, the known flow data of the first K transmission flows are counted, and for each transmission flow, it is determined whether the threshold of the elephant flow is reached. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the elephant flow data is maintained in the flow table array. If the transmission flow is an elephant flow, its five-tuple information is added to the flow table array;
[0022] The term "elephant flow" refers to the process of continuously transmitting data in a network link, which occupies a large bandwidth, and may also refer to the data in this process.
[0023] Step S240: Compare the received non-fragmented messages with the flow table array of the elephant flow in sequence. If the non-fragmented message belongs to the elephant flow, mark the non-fragmented message as the elephant flow, number it in sequence, and put it into the non-locked loop of the encryption and decryption engine working core CPU3 and CPU4; if it is a normal flow, put the non-fragmented message into the non-locked loop of the encryption and decryption engine working core CPU2;
[0024] Step S300: encrypt and decrypt the message in the encryption and decryption engine working core and send it to CPU1 for sorting, and then send it to the network card sending queue;
[0025] The specific method of encrypting and decrypting the message in the encryption and decryption engine working core and sending it to CPU1 for sorting and then sending it to the network card sending queue is as follows:
[0026] Each encryption and decryption engine working core continuously polls its own unlocked loop to take out non-fragmented messages; queries the IPSec policy to determine whether the non-fragmented message is an outgoing IPSec message or an incoming IPSec message; if it is an outgoing IPSec message, encrypt it according to the outgoing IPSec message; if it is an incoming IPSec message, query the SA, perform anti-replay check on the message, then decrypt it and update the anti-replay window; if it is a normal flow, no encryption and decryption processing is performed, and after routing query, it is sent to CPU1 responsible for sending; sort it according to the number of the non-fragmented message, and then call rte_eth_tx_burst() to send it to the network card sending queue.
[0027] One aspect of the present application provides a DPDK-based device for resolving IPSec elephant flows, including:
[0028] The initialization creation module is used to initialize CPU0 and CPU1 as PMD thread cores according to the configuration file, initialize CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores, create an unlocked loop for communication between the PMD thread cores and the encryption and decryption engine working cores, and establish the network card send queue and network card receive queue;
[0029] The elephant flow detection and distribution module is used by the PMD thread core to perform polling work regularly, obtain messages and detect elephant flows and ordinary flows, load balance the elephant flows, and distribute the messages to the encryption and decryption engine working core;
[0030] The encryption and decryption sending module is used to encrypt and decrypt the messages in the encryption and decryption engine working core and send them to CPU1 for sorting, and then send them to the network card sending queue.
[0031] One aspect of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps in a method for resolving IPSec elephant flows based on DPDK are implemented.
[0032] One aspect of the present application provides a readable storage medium storing a computer program, wherein the computer program is suitable for being loaded by a processor to execute steps in a method for resolving IPSec elephant flows based on DPDK.
[0033] The DPDK-based method proposed in this application for resolving IPSec elephant flows has the following advantages over existing technologies:
[0034] The massive growth of information data and the increasing need for information security are driving high throughput requirements for SD-WAN IPSec access. This data creates a large, continuous flow of traffic across IPSec links. Because encryption and decryption consume significant CPU resources, a single IPSec traffic can easily reach the performance bottleneck of a single CPU core, leading to packet loss.
[0035] This application addresses the bottleneck issue faced by single-core processing of IPSec elephant flows. Building on the DPDK RTC model, it introduces a pipeline model that detects elephant flows and processes them in parallel across multiple cores, thereby resolving the packet loss problem caused by single-core performance bottlenecks. This allows the throughput of a single IPSec elephant flow to increase linearly with the number of CPU cores. In some domestically produced trusted computing environments, single-core processing performance is relatively low, but the total number of CPUs is relatively large. This application can effectively address overall performance issues at a low cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] FIG1 is a flowchart of a method for resolving IPSec elephant flows based on DPDK in the present application;
[0037] Figure 2 is a schematic diagram of the network card RSS and data flow;
[0038] FIG3 is a functional module diagram of a DPDK-based device for resolving IPSec elephant flows of the present application;
[0039] FIG4 is a schematic structural diagram of an electronic device provided by the present application;
[0040] FIG5 is a schematic diagram of the structure of a readable storage medium provided by this application. DETAILED DESCRIPTION
[0041] For a better understanding of the present application, various aspects of the present application will be described in more detail with reference to the accompanying drawings. It should be understood that these detailed descriptions are merely descriptions of exemplary embodiments of the present application and are not intended to limit the scope of the present application in any way. Throughout the specification, the same reference numerals refer to the same elements. The expression "and / or" includes any and all combinations of one or more of the associated listed items.
[0042] In the accompanying drawings, the size, dimensions, and shapes of the elements have been slightly adjusted for ease of illustration. The accompanying drawings are for illustration only and are not drawn strictly to scale. As used herein, the terms "substantially," "approximately," and similar terms are used to indicate approximations, not degrees, and are intended to illustrate inherent deviations in measurements or calculations that would be recognized by a person of ordinary skill in the art. In addition, in this application, the order in which the steps are described does not necessarily represent the order in which these steps would occur in actual operation, unless otherwise specified or inferred from the context.
[0043] It should also be understood that expressions such as "comprises," "including," "having," "includes," and / or "comprising" are open rather than closed expressions in this specification, indicating the presence of the stated features, elements, and / or components, but do not exclude the presence of one or more other features, elements, components, and / or combinations thereof. In addition, when expressions such as "at least one of..." appear after a list of listed features, they modify the entire list of features rather than just the individual elements in the list. In addition, when describing embodiments of the present application, "may" is used to mean "one or more embodiments of the present application." And, the term "exemplary" is intended to refer to an example or illustration.
[0044] Unless otherwise defined, all words used herein (including engineering terms and scientific and technological terms) have the same meaning as commonly understood by those skilled in the art to which this application belongs. It should also be understood that, unless otherwise specified in this application, words defined in commonly used dictionaries should be interpreted as having the same meaning as they do in the context of the relevant technology, and should not be interpreted in an idealized or overly formal sense.
[0045] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0046] Example 1
[0047] As shown in FIG1 , a flowchart of a method for resolving IPSec elephant flows based on DPDK provided by this application includes:
[0048] Step S100: According to the configuration file, CPU0 and CPU1 are initialized as PMD thread cores, CPU2, CPU3, and CPU4 are initialized as encryption and decryption engine working cores, an unlocked loop is created for communication between the PMD thread cores and the encryption and decryption engine working cores, and a network card send queue and a network card receive queue are established;
[0049] Initializing CPU0 and CPU1 as PMD thread cores means that both CPU0 and CPU1 are implemented as PMD thread cores of DPDK, and perform polling tasks on the network card send queue and the network card receive queue;
[0050] Initializing CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores means that CPU 2, CPU 3, and CPU 4 are implemented as encryption and decryption engine working cores to implement encryption and decryption processing of messages, wherein the first CPU core is CPU 2, which is used to perform message processing of ordinary flows, and CPU 3 and CPU 4 are used to perform message encryption and decryption of elephant flows in parallel;
[0051] Creating a lockless loop for communication between the PMD thread core and the encryption and decryption engine working core means: using the lockless loop of DPDK, during the initialization phase, establishing a communication channel between the PMD thread cores, i.e., CPU0 and CPU1, and the encryption and decryption engine working core, to achieve inter-core message transmission;
[0052] The network card sending queue is used to store messages to be sent to the network;
[0053] The network card receiving queue is used to store messages received from the network;
[0054] Step S200: The PMD thread core regularly performs polling to obtain messages and detects the large flow and the ordinary flow, performs load balancing on the large flow, and distributes the messages to the encryption and decryption engine working core;
[0055] The PMD thread core regularly performs polling to obtain messages and detect large flows and ordinary flows, performs load balancing on large flows, and distributes messages to the encryption and decryption engine working cores in the following specific steps:
[0056] Step S210: calling rte_eth_rx_burst() to read the messages in the network card receive queue, and dividing the messages into fragmented messages and non-fragmented messages according to their sizes;
[0057] The fragmented message means that when the size of the message exceeds the maximum transmission unit of the network link, the message will be divided into m fragments, each fragment is a fragmented message;
[0058] The non-fragmented message means that if the size of the message is less than or equal to the maximum transmission unit of the network link, the entire message can be transmitted in one message without being divided into fragments;
[0059] Step S220: reassemble the fragmented message to obtain a reassembled message;
[0060] The fragmented messages are reassembled by storing the received fragmented messages in a fragment linked list, and if the last fragmented message has not been received, storing the received fragmented messages in the fragment linked list to wait for subsequent fragmented messages, and assembling the fragmented messages that arrive in order according to their position information in the original message to obtain a reassembled message;
[0061] Step S230: Perform sflow sampling on the received non-fragmented messages, which include reassembled messages and messages that do not need to be fragmented. Count the known flow data of the first K transmission flows. If a transmission flow reaches the threshold of the elephant flow, record the five-tuple information of the transmission flow and update the flow table array of the elephant flow.
[0062] The non-fragmented message does not need to be reassembled and therefore contains complete message data;
[0063] The sflow sampling is performed on the received non-fragmented message, and the non-fragmented message includes a reassembled message and a message that does not need to be fragmented. The known flow data of the first K transmission flows are counted. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the flow table array of the elephant flow is updated. It means: for each non-fragmented message, the sflow sampling operation is performed, the known flow data of the first K transmission flows are counted, and for each transmission flow, it is determined whether the threshold of the elephant flow is reached. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the elephant flow data is maintained in the flow table array. If the transmission flow is an elephant flow, its five-tuple information is added to the flow table array;
[0064] The term "elephant flow" refers to the process of continuously transmitting data in a network link, which occupies a large bandwidth, and may also refer to the data in this process.
[0065] In contrast, the data transmission process that occupies a smaller bandwidth and takes a shorter time in the network link is called rat flow or normal flow;
[0066] Step S240: Compare the received non-fragmented messages with the flow table array of the elephant flow in sequence. If the non-fragmented message belongs to the elephant flow, mark the non-fragmented message as the elephant flow, number it in sequence, and put it into the non-locked loop of the encryption and decryption engine working core CPU3 and CPU4; if it is a normal flow, put the non-fragmented message into the non-locked loop of the encryption and decryption engine working core CPU2;
[0067] The flow table array of the elephant flow uses continuous memory, and achieves efficient and fast comparison and inspection by trading space for time and comparing continuous memory bits, reducing the CPU cycles executed and reducing the impact of the comparison and inspection of the elephant flow with non-fragmented messages on network throughput performance;
[0068] Step S300: encrypt and decrypt the message in the encryption and decryption engine working core and send it to CPU1 for sorting, and then send it to the network card sending queue;
[0069] The specific method of encrypting and decrypting the message in the encryption and decryption engine working core and sending it to CPU1 for sorting and then sending it to the network card sending queue is as follows:
[0070] Each encryption and decryption engine working core continuously polls its own unlocked loop to take out non-fragmented messages; queries the IPSec policy to determine whether the non-fragmented message is an outgoing IPSec message or an incoming IPSec message; if it is an outgoing IPSec message, encrypt it according to the outgoing IPSec message; if it is an incoming IPSec message, query the SA, perform anti-replay check on the message, then decrypt it and update the anti-replay window; if it is a normal flow, no encryption and decryption processing is performed, and after routing query, it is sent to CPU1 responsible for sending; sort it according to the number of the non-fragmented message, and then call rte_eth_tx_burst() to send it to the network card sending queue.
[0071] Example 2
[0072] RSS is a widely used network driver technology in current network adapters (NICs) to alleviate network throughput bottlenecks caused by overloading a single CPU. However, with the surge in SD-WAN IPSec access data, as shown in Figure 2, the presence of IPSec traffic has once again become a bottleneck for single CPUs. Because the processing power of a single CPU core is already stretched to its limits by processing this IPSec traffic, from a Quality of Service (QoS) perspective, this traffic and concurrently arriving regular traffic will impact each other, potentially resulting in varying degrees of packet loss, further degrading transmission quality. NVIDIA and Intel have introduced specific features in their NICs and processors to address these issues in hardware. However, in some scenarios, either due to hardware cost considerations or the need for self-control in trusted innovation environments, this new hardware solution cannot be used.
[0073] This application is mainly used to solve the performance bottleneck problem faced by IPSec elephant flow. In terms of implementation, it is necessary to achieve accurate elephant flow detection as much as possible, and to achieve efficient IPSec encryption and decryption without wasting CPU resources. Based on the general SDWAN IPSec network access practice, the best embodiment of this application is given:
[0074] Each queue can have two to four encryption and decryption cores. Lower-end processors with lower performance can use more cores. The descriptor depth of the inter-core ring can be 512 or 1024. During polling, the maximum number of inter-core messages that can be read at a time is 32.
[0075] When using elephant flows for sampling detection, the sampling percentage can be set to configurable mode for greater sampling flexibility. A low sampling rate saves CPU resources; a higher sampling rate improves detection accuracy. By default, the sampling rate is set to 2%. When implementing the Top K algorithm, for practical application and efficiency considerations, a hash table + heap approach is used to support matching up to 20 elephant flows. Generally, a maximum of 10 elephant flows can be selected for matching to save search time. Typically, source IP address, destination IP address, source port, destination port, and transport layer protocol are selected as the characteristics of a flow. For flexibility and efficiency, the configuration interface supports manual configuration of elephant flow rules to reduce resource consumption associated with sampling detection.
[0076] When searching for and using SAs, the encryption and decryption engine worker cores must consider inter-core synchronization. SA data structures are created, deleted, and updated using the RCU mechanism. To ensure efficient anti-replay window checking and updating, when the PMD thread core sends the elephant stream to the inter-core rings of the encryption and decryption engine worker cores, it sends N consecutive packets to one ring and then another N consecutive packets to the next ring.
[0077] In order to reduce the difficulty in implementation, when the message needs to be fragmented, it can be implemented by encrypting it first and then fragmenting it.
[0078] Example 3
[0079] As shown in FIG3 , a functional module diagram of a DPDK-based device for resolving IPSec elephant flows provided by this application includes:
[0080] The initialization creation module is used to initialize CPU0 and CPU1 as PMD thread cores according to the configuration file, initialize CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores, create an unlocked loop for communication between the PMD thread cores and the encryption and decryption engine working cores, and establish the network card send queue and network card receive queue;
[0081] The elephant flow detection and distribution module is used by the PMD thread core to perform polling work regularly, obtain messages and detect elephant flows and ordinary flows, load balance the elephant flows, and distribute the messages to the encryption and decryption engine working core;
[0082] The encryption and decryption sending module is used to encrypt and decrypt the messages in the encryption and decryption engine working core and send them to CPU1 for sorting, and then send them to the network card sending queue.
[0083] Example 4
[0084] Figure 4 is a schematic diagram of the structure of an electronic device provided by one embodiment of the present application. As shown in Figure 4, according to another aspect of the present application, an electronic device is also provided. The electronic device may include one or more processors and one or more memories. The memories may store computer-readable code, which, when executed by the one or more processors, may execute the above-described DPDK-based method for resolving IPSec elephant flows.
[0085] The method or system according to the embodiment of the present application can also be implemented with the help of the architecture of the electronic device shown in Figure 4. As shown in Figure 4, the electronic device may include a bus, one or more CPUs, a read-only memory (ROM), a random access memory (RAM), a communication port connected to the network, an input / output component, a hard disk, etc. The storage device in the electronic device, such as a ROM or a hard disk, can store a method for solving IPSec elephant flows based on DPDK provided by the present application. A method for solving IPSec elephant flows based on DPDK may, for example, include: according to the configuration file, initializing CPU0 and CPU1 as PMD thread cores, initializing CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores, creating a lockless loop for communication between the PMD thread core and the encryption and decryption engine working core, establishing a network card send queue and a network card receive queue; the PMD thread core regularly performs polling work, obtains messages and detects elephant flows and ordinary flows, load balances the elephant flows, and distributes the messages to the encryption and decryption engine working cores; encrypts and decrypts the messages in the encryption and decryption engine working cores and sends them to CPU1 for sorting, and then sends them to the network card send queue. Furthermore, the electronic device may also include a user interface. Of course, the architecture shown in FIG4 is merely exemplary. When implementing different devices, one or more components in the electronic device shown in FIG4 may be omitted according to actual needs.
[0086] Example 5
[0087] FIG5 is a schematic diagram of the structure of a readable storage medium provided by an embodiment of the present application. As shown in FIG5 , a readable storage medium according to an embodiment of the present application is shown. Computer-readable instructions are stored on the computer-readable storage medium. When the computer-readable instructions are executed by the processor, a method for resolving IPSec elephant flows based on DPDK according to an embodiment of the present application described with reference to the above figures can be executed. The storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0088] In addition, according to the embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the present application provides a non-temporary machine-readable storage medium, which stores machine-readable instructions, and the machine-readable instructions can be run by a processor to execute instructions corresponding to the method steps provided in the present application, for example: according to the configuration file, CPU0 and CPU1 are initialized as PMD thread cores, CPU 2, CPU 3, and CPU 4 are initialized as encryption and decryption engine working cores, and a lockless loop is created for communication between the PMD thread core and the encryption and decryption engine working core, and a network card sending queue and a network card receiving queue are established; the PMD thread core regularly performs polling work, obtains messages and detects elephant flows and ordinary flows, load balances the elephant flows, and distributes the messages to the encryption and decryption engine working core; the messages in the encryption and decryption engine working core are encrypted and decrypted and sent to CPU1 for sorting, and then sent to the network card sending queue. When the computer program is executed by the central processing unit (CPU), the above functions defined in the method of the present application are executed.
[0089] The methods, apparatuses, and devices of the present application may be implemented in many ways. For example, the methods, apparatuses, and devices of the present application may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present application are not limited to the order specifically described above unless otherwise specified. In addition, in some embodiments, the present application may also be implemented as programs recorded in a recording medium, which include machine-readable instructions for implementing the methods according to the present application. Therefore, the present application also covers recording media that store programs for executing the methods according to the present application.
[0090] In addition, the parts of the above technical solutions provided in the embodiments of the present application that are consistent with the implementation principles of the corresponding technical solutions in the prior art are not described in detail to avoid excessive redundancy.
[0091] The above-described specific embodiments further illustrate the purpose, technical solutions, and beneficial effects of this application. It should be understood that the above description is merely a specific embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this application shall be included within the scope of protection of this application.
Claims
1. A method for solving IPSec elephant flow based on DPDK, characterized in that: include: According to the configuration file, CPU0 and CPU1 are initialized as PMD thread cores, CPU 2, CPU 3, and CPU 4 are initialized as encryption and decryption engine working cores, an unlocked loop is created for communication between the PMD thread cores and the encryption and decryption engine working cores, and the network card sending queue and the network card receiving queue are established; The PMD thread core periodically performs polling to obtain messages and detect the elephant flows and ordinary flows, load balances the elephant flows, and distributes the messages to the encryption and decryption engine working cores; After encrypting and decrypting the message in the working core of the encryption and decryption engine, it is sent to CPU1 for sorting and then sent to the network card sending queue.
2. A method for solving IPSec elephant flow based on DPDK as claimed in claim 1, characterized in that: Initializing CPU0 and CPU1 as PMD thread cores means that both CPU0 and CPU1 are implemented as PMD thread cores of DPDK, and perform polling tasks on the network card sending queue and the network card receiving queue.
3. A method for solving IPSec elephant flow based on DPDK as claimed in claim 2, characterized in that: Initializing CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores means that CPU 2, CPU 3, and CPU 4 are implemented as encryption and decryption engine working cores to implement encryption and decryption processing of messages, wherein the first CPU core is CPU 2, which is used to execute message processing of ordinary flows, and CPU 3 and CPU 4 are used to execute encryption and decryption of messages of elephant flows in parallel.
4. A method for solving IPSec elephant flow based on DPDK as claimed in claim 3, characterized in that: The creation of an unlocked loop for communication between the PMD thread core and the encryption and decryption engine working core refers to: using the unlocked loop of DPDK, in the initialization phase, establishing a communication channel between the PMD thread core, i.e., CPU0 and CPU1, and the encryption and decryption engine working core to realize message transmission between cores.
5. A method for solving IPSec elephant flow based on DPDK as claimed in claim 4, characterized in that: The PMD thread core periodically performs polling work, obtains messages and detects elephant flows and ordinary flows, performs load balancing on elephant flows, and distributes messages to the encryption and decryption engine working cores in the following specific steps: Call rte_eth_rx_burst() to read the packets in the network card receive queue, and divide them into fragmented packets and non-fragmented packets according to the size of the packets; Reassemble the fragmented messages to obtain a reassembled message; Perform sflow sampling on the received non-fragmented messages, which include reassembled messages and messages that do not need to be fragmented, and count the known flow data of the first K transmission flows. If a transmission flow reaches the threshold of the elephant flow, record the five-tuple information of the transmission flow and update the flow table array of the elephant flow. Compare the received non-fragmented messages with the flow table array of the elephant flow in turn. If the non-fragmented message belongs to the elephant flow, mark the non-fragmented message as the elephant flow, number it in sequence, and put the non-fragmented message into the lockless loop of the encryption and decryption engine working cores CPU3 and CPU 4; If it is a normal flow, the non-fragmented message is placed in the unlocked loop of the encryption and decryption engine working core CPU2.
6. A method for solving IPSec elephant flow based on DPDK as claimed in claim 5, characterized in that: The sflow sampling is performed on the received non-fragmented messages, wherein the non-fragmented messages include reassembled messages and messages that do not need to be distributed, and the known flow data of the first K transmission flows are counted. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the flow table array of the elephant flow is updated. It means: for each non-fragmented message, the sflow sampling operation is performed, the known flow data of the first K transmission flows are counted, and for each transmission flow, it is determined whether the threshold of the elephant flow is reached. If a transmission flow reaches the threshold of the elephant flow, the five-tuple information of the transmission flow is recorded, and the elephant flow data is maintained in the flow table array. If the transmission flow is an elephant flow, its five-tuple information is added to the flow table array.
7. A method for solving IPSec elephant flow based on DPDK as claimed in claim 6, characterized in that: The specific method of encrypting and decrypting the message in the encryption and decryption engine working core and sending it to CPU1 for sorting, and then sending it to the network card sending queue is: Each encryption and decryption engine working core continuously polls its own lock-free loop to extract non-fragmented messages; Query the IPSec policy to determine whether the non-fragmented message is an outgoing IPSec message or an incoming IPSec message; If it is an outgoing IPSec message, encrypt the outgoing IPSec message; If it is an incoming IPSec message, query the SA, perform anti-replay check on the message, then decrypt it and update the anti-replay window; If it is a normal flow, no encryption or decryption is performed. After routing query, it is sent to CPU1 responsible for sending. Sort the non-fragmented packets according to their numbers, and then call rte_eth_tx_burst() to send them to the network card send queue.
8. A device for solving IPSec elephant flow based on DPDK, characterized in that: include: Initialization creation module, used to initialize CPU0 and CPU1 as PMD thread cores according to the configuration file, initialize CPU 2, CPU 3, and CPU 4 as encryption and decryption engine working cores, create an unlocked loop for communication between the PMD thread core and the encryption and decryption engine working core, and establish a network card sending queue and a network card receiving queue; The elephant flow detection and distribution module is used for the PMD thread core to perform polling work regularly, obtain messages and detect elephant flows and ordinary flows, load balance the elephant flows, and distribute the messages to the encryption and decryption engine working core; The encryption and decryption sending module is used to encrypt and decrypt the messages in the encryption and decryption engine working core and send them to CPU1 for sorting, and then send them to the network card sending queue.
9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps in the method for resolving IPSec elephant flows based on DPDK as described in any one of claims 1 to 7 are implemented.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and the computer program is suitable for being loaded by a processor to execute the steps in the method for solving IPSec elephant flows based on DPDK as described in any one of claims 1-7.
Citation Information
Patent Citations
Software encryption and decryption performance extension method for IPsec VPN single tunnel
CN111669374A
IPSec message forwarding method and device based on multi-core processor
CN115967751A
Method and system for realizing 5G service data load balancing based on assembly line
CN117177298A
Method and device for solving IPSec elephant flow based on DPDK
CN117857459A
Dynamic load balancing for multi-core computing environments
US20210075730A1
Cited By
Encryption network card bypass transmission architecture based on parallel feature extraction
CN122293615A
A parallel feature extraction based encrypted network card bypass transmission architecture
CN122293615B