Packet forwarding

By introducing the first virtual switch and forwarding hardware in the host machine, messages carrying forwarding path identification information are generated and forwarded, which solves the problem of insufficient processing power of the smart network card in high-performance network scenarios and improves the message processing capability.

WO2025202784A1PCT designated stage Publication Date: 2025-10-02CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Patent Information

Application Number
PCT/IB2025/052177
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2025-02-28
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing smart network cards are unable to meet the needs of packet processing in high-performance network scenarios, especially in network address translation and network function virtualization scenarios, which require software modules to provide large amounts of storage space and processing power.

Method used

By introducing a first virtual switch in the host machine, receiving the initial message sent by the forwarding hardware, and generating a first message carrying forwarding path identification information, the forwarding hardware is used to forward the message, reducing the dependence on the network card memory and processor performance.

Benefits of technology

Without increasing the network card memory or processor performance, the server-side network message processing capabilities are significantly improved to meet the needs of high-performance network scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025052177_02102025_PF_FP_ABST
    Figure IB2025052177_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a packet forwarding method and system, an electronic device, and a storage medium. The method comprises: receiving an initial packet sent by forwarding hardware, wherein the initial packet is a packet satisfying a preset dispersion condition, the preset dispersion condition is used for dispersing a target packet to obtain a packet needing to be processed by a first virtual switch, and the target packet is a packet for which a forwarding path cannot be determined on the basis of a flow table of the forwarding hardware; and generating a first packet corresponding to the initial packet, and sending the first packet to the forwarding hardware, such that the forwarding hardware forwards the first packet on the basis of identification information in the first packet, wherein the identification information is used for representing a forwarding path of the initial packet.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Message forwarding technology field

[0002]

[0001] The present disclosure relates to the field of network technology, and more particularly to message forwarding.

[0003]

[0002] A virtual switch (vswitch) is a software-implemented virtual switch used to forward traffic between virtual machines. It is a core component that provides network virtualization for virtual machines on the cloud and is responsible for forwarding network messages between virtual machines. The vswitch is usually deployed in the server's smart network card. The smart network card is divided into two modules: software and hardware. The software module is a small system on a chip (SoC) on the smart network card, which has processor resources and memory resources and is used to provide complex and variable message processing functions and control paths. The hardware module is usually implemented by a field programmable gate array (FPGA) or an application-specific integrated circuit (ASIC). The hardware module is mainly responsible for message processing services with relatively fixed logic but high performance requirements.

[0004]

[0003] However, in scenarios such as Network Address Translation (NAT), messages can only be processed by the above-mentioned software modules. In addition, in scenarios such as Network Function Virtualization (NFV) and the activation of multiple containers or virtual machines in a host machine, software modules are also required to provide a large amount of storage space for multiple virtual network cards of the containers or virtual machines. Existing smart network cards are difficult to meet the message processing requirements in the above-mentioned application scenarios.

[0005]

[0004] In view of the above problems, the present disclosure provides a message forwarding method, system, electronic device and storage medium to at least solve the technical problem in the related art that network cards are difficult to meet the message processing requirements in high-performance network scenarios.

[0006]

[0005] According to a first aspect of an embodiment of the present disclosure, a message forwarding method is provided, which is applied to a first virtual switch, wherein the first virtual switch runs in a host machine, and the network card of the host machine includes forwarding hardware; the method includes: receiving an initial message sent by the forwarding hardware, wherein the initial message is a message that meets a preset diversion condition, and the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message whose forwarding path cannot be determined based on a flow table of the forwarding hardware; generating a first message corresponding to the initial message, and sending the first message to the forwarding hardware, so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to characterize the forwarding path of the initial message.

[0007]

[0006] According to a second aspect of an embodiment of the present disclosure, a packet forwarding method is provided, which is applied to a network card, the network card being installed in a host machine, the host machine including a first virtual switch, and the network card including conversion hardware, the method comprising: receiving an initial packet from a source node through the conversion hardware; transmitting the initial packet to the first virtual switch through the conversion hardware when the initial packet meets a preset diversion condition; the preset diversion condition is used to divert packets that need to be processed by the first virtual switch from target packets, the target packets being packets for which a forwarding path cannot be determined based on a flow table of the conversion hardware; receiving a first packet generated by the first virtual switch based on the initial packet through the conversion hardware, the first packet carrying identification information for characterizing a forwarding path of the initial packet; and forwarding the first packet through the forwarding hardware according to the identification information.

[0008]

[0007] According to a third aspect of an embodiment of the present disclosure, a message forwarding system is provided, comprising a first virtual switch and a network card; the first virtual switch runs on a host machine, and the network card includes forwarding hardware; the first virtual switch is configured to receive an initial message sent by the forwarding hardware, where the initial message is a message that meets a preset diversion condition, where the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, where the target messages are messages for which a forwarding path cannot be determined based on a flow table of the forwarding hardware; the first virtual switch generates a first message corresponding to the initial message, and sends the first message to the forwarding hardware; the first message carries identification information used to characterize the forwarding path of the initial message; the network card is configured to receive the initial message from a source node through the forwarding hardware; if the initial message meets the preset diversion condition, transmit the initial message to the first virtual switch through the forwarding hardware; receive the first message generated by the first virtual switch based on the initial message through the forwarding hardware; and forward the first message through the forwarding hardware according to the identification information.

[0009]

[0008] According to a fourth aspect of an embodiment of the present disclosure, an electronic device is also provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the message forwarding method of the first or second aspect.

[0010]

[0009] According to a fifth aspect of the embodiments of the present disclosure, a computer-readable storage medium is further provided, in which a computer program is stored, wherein the computer program is configured to execute the message forwarding method of the first aspect or the second aspect when running.

[0011]

[0010] According to a sixth aspect of the embodiments of the present disclosure, a computer program product is also provided, comprising a computer program, wherein the computer program is configured to execute the message forwarding method of the first aspect or the second aspect when running.

[0012]

[0011] In an embodiment of the present disclosure, a first virtual machine switch in a host machine receives an initial message sent by the forwarding hardware of a network card, wherein the initial message is a message that satisfies a preset diversion condition, and the preset diversion condition is used to divert a message that needs to be processed by the first virtual switch from a target message, wherein the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware; a first message corresponding to the initial message is generated, and the first message is sent to the forwarding hardware so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to characterize the forwarding path of the initial message; when facing an application scenario that requires a software module in the network card to provide more on-chip resources, the present disclosure solves the problem of insufficient on-chip resources such as the network card or the data processor in the network card in the application scenario that requires more on-chip resources without improving the memory or processor performance of the network card, significantly improves the server-side network message processing capability, and meets the message processing requirements in high-performance network scenarios.

[0013]

[0012] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiments below. The accompanying drawings are provided for illustration purposes only and are not to be construed as limiting the present disclosure. Like reference numerals are used throughout the accompanying drawings to denote like parts. In the accompanying drawings:

[0014] FIG1 is a schematic diagram of an application environment of an optional message forwarding method according to the related art;

[0015] FIG2 is a flow chart of an optional message forwarding method according to an embodiment of the present disclosure;

[0016]

[0015] FIG3 is a schematic diagram of an application environment of an optional message forwarding method according to an embodiment of the present disclosure;

[0017]

[0016] FIG4 is a schematic diagram of an application environment of another optional message forwarding method according to an embodiment of the present disclosure;

[0017] FIG5 is a schematic diagram of an application environment of yet another optional message forwarding method according to an embodiment of the present disclosure;

[0018]

[0018] FIG6 is a schematic diagram of an application environment of another optional message forwarding method according to an embodiment of the present disclosure;

[0019]

[0019] FIG7 is a schematic diagram of an application environment of an optional message forwarding method according to an embodiment of the present disclosure;

[0020]

[0020] FIG8 is a schematic diagram of the structure of an optional virtual switch according to an embodiment of the present disclosure;

[0021]

[0021] FIG9 is a schematic diagram of an application environment of another optional message forwarding method according to an embodiment of the present disclosure;

[0022]

[0022] FIG10 is a flow chart of another optional message forwarding method according to an embodiment of the present disclosure;

[0023] FIG11 is a schematic structural diagram of an optional message forwarding device according to an embodiment of the present disclosure;

[0024] FIG12 is a schematic structural diagram of another optional message forwarding device according to an embodiment of the present disclosure;

[0025] FIG13 is a schematic structural diagram of an optional message forwarding system according to an embodiment of the present disclosure;

[0026] FIG14 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure;

[0027]

[0027] FIG15 is a schematic diagram of the structure of another electronic device provided in an embodiment of the present disclosure.

[0028] To help those skilled in the art better understand the present invention, the technical solutions in the embodiments of the present invention will be described clearly and completely below with reference to the accompanying drawings. It should be understood that the described embodiments are merely a portion of the embodiments of the present invention, and are not intended to be exhaustive. All other embodiments derived by those skilled in the art based on the embodiments of the present invention without inventive effort should fall within the scope of protection of the present invention.

[0029]

[0029] It should be noted that the terms "first," "second," and the like in the specification and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.

[0030]

[0030] As shown in FIG1 , in related art, a virtual switch v switch is usually deployed in the network card of the host. The network card is divided into two modules: software and hardware. The software module is a small system-on-chip on the smart network card.

[0031] System on Chip (SoC) has processor and memory resources to provide complex and diverse message processing functions and control paths. Hardware modules are typically implemented using field programmable gate arrays (FPGAs) or application-specific integrated circuits (ASICs). Hardware modules (forwarding hardware) are primarily responsible for message processing services with relatively fixed logic but high performance requirements.

[0032] As shown in Figure 1, after a message enters the host machine through the physical network port (PHY), the forwarding hardware first queries the flow table. If the message matches an entry in the flow table, it is directly forwarded to the corresponding virtual machine (VM), such as VM1, according to the forwarding flow entry corresponding to the entry. If the message does not match an entry in the flow table, the message is sent to the virtual machine switch (vswtich) for processing. After processing, the vswitch forwards the message to the corresponding virtual machine via the forwarding hardware. However, messages facing network address translation (NAT) can only be processed by the aforementioned virtual switch. In addition, scenarios such as network function virtualization (NFV) and the activation of multiple containers or virtual machines in the host machine also require a software module (NIC-SOC) to provide a large amount of storage space for the multiple virtual network cards of the containers or virtual machines. Existing network cards are difficult to meet the message processing requirements in these application scenarios.

[0033]

[0032] To solve the above technical problem, as an optional implementation method, as shown in FIG2 , an embodiment of the present disclosure provides a message forwarding method, which is applied to a first virtual switch, wherein the first virtual switch runs in a host machine, and the network card of the host machine includes forwarding hardware. The method includes the following steps.

[0034]

[0033] S202: Receive an initial message sent by the forwarding hardware, where the initial message is a message that meets a preset diversion condition, where the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware.

[0035]

[0034] Specifically, in an embodiment of the present disclosure, as shown in FIG3 , the first virtual machine switch runs in a virtual machine system on a chip (vSOC) of a host machine Host. When a message enters the host machine through a physical network port (PHY), it is first matched against each entry in the flow table in the forwarding hardware. If no entry is matched, the forwarding path of the initial message cannot be determined. At this time, the initial message needs to pass through the virtual switch to determine the forwarding path of the initial message. In the present disclosure, the first virtual switch (Host-vswitch) diverts the initial message that was originally intended to enter the second virtual machine switch (nic-vswitch), that is, the first virtual machine and the second virtual machine jointly bear the task of processing the message that does not match each entry in the flow table.

[0036]

[0035] S204, generating a first message corresponding to the initial message, and sending the first message to the forwarding hardware, so that the forwarding hardware forwards the first message according to the identification information in the first message; the identification information is used to characterize the forwarding path of the initial message.

[0037]

[0036] Specifically, in the embodiment of the present disclosure, the above-mentioned identification information may be, for example, a network card identification of a destination node or a source node and / or an information transceiver queue identification. When the first virtual switch receives the initial message sent by the forwarding hardware, it generates a first message corresponding to the initial message and carrying the identification information. Then, the first message is sent to the virtual machine on the host machine or to a network device outside the host machine through the forwarding hardware.

[0038]

[0037] In an embodiment of the present disclosure, a first virtual machine switch in a host machine receives an initial message sent by forwarding hardware of a network card, where the initial message is a message that meets a preset diversion condition, and the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, where the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware; a first message corresponding to the initial message is generated, and the first message is sent to the forwarding hardware so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to characterize the forwarding path of the initial message; the present disclosure solves the problem of insufficient on-chip resources such as the network card or the data processor in the network card in application scenarios that require more on-chip resources without improving the memory or processor performance of the network card, significantly improves the network message processing capability of the server, and meets the message processing requirements in high-performance network scenarios.

[0039]

[0038] In one or more embodiments, the initial message is a message sent by an external device to the host machine, and the receiving of the initial message sent by the forwarding hardware includes: reading a communication message including the initial message from a virtual queue based on the first network interface of the first virtual switch, the message header of the communication message carries the first network port identifier and the first transceiver message queue identifier corresponding to the destination node of the initial message, and the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0040]

[0039] Specifically, as shown in FIG4 , in an embodiment of the present disclosure, the aforementioned initial message is a message sent from an external device to the host machine, i.e., the initial message is an uplink message type. In the forwarding path process of the initial message, when the initial message is sent to the first virtual machine switch, it needs to carry the network port identifier (port ID) and the transceiver message queue identifier (queue ID) of the destination node's Elastic Network Interface (ENI) so that the first virtual machine switch can know the forwarding destination node of the initial message. In an embodiment of the present disclosure, the first network port identifier and the first transceiver message queue identifier corresponding to the destination node of the initial message are written into a virtual queue Vring by forwarding hardware. The Vring is a data link connecting the driver of a virtual system on chip (vSOC) and the driver of the host machine. The virtual queue Vring can be a message queue in a paravirtualized device (Virtual Input / Output Device). It should be noted that the first network port identifier and the first transceiver message queue identifier can be written into the message header of the communication message, and the message data of the initial message can be written into the payload data of the communication message. The first virtual switch reads the communication message including the initial message from the virtual queue via the first network interface (ENI-A), and then parses the communication message to obtain the first network port identifier and the first transceiver message queue identifier corresponding to the destination node from the header, thereby determining the forwarding path of the initial message.

[0041]

[0040] In one or more embodiments, generating a first message corresponding to the initial message and forwarding the first message to the forwarding hardware includes: determining identification information used to characterize the forwarding path of the initial message based on the initial message; adding the identification information to the initial message to obtain the first message; and forwarding the first message from the second network interface of the first virtual switch to the forwarding hardware.

[0042]

[0041] Specifically, as shown in FIG4 , in an embodiment of the present disclosure, after the first virtual switch obtains an initial message and the first network port identifier and the first transceiver message queue identifier corresponding to the destination node (e.g., VM1) from the virtual queue, the first network port identifier and the first transceiver message queue identifier are added to the initial message to obtain a first message. The first message is then forwarded from the second network interface (ENI-B) of the first virtual switch to the forwarding hardware. The forwarding hardware forwards the first message to the first transceiver message queue corresponding to VM1 based on the first network port identifier and the first transceiver message queue identifier, and VM1 is then able to obtain the first message from the first transceiver message queue.

[0043]

[0042] In one or more embodiments, the initial message is a message sent by the virtual machine in the host machine, and the receiving of the initial message sent by the forwarding hardware includes: reading a communication message including the initial message from a virtual queue based on the second network interface of the first virtual switch, the message header of the communication message carries the second network port identifier and the second transceiver message queue identifier corresponding to the source node of the initial message, and the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0044]

[0043] Specifically, as shown in FIG5 , in the embodiment of the present disclosure, the aforementioned initial message is a message sent by a virtual machine in the host machine, i.e., the initial message is a downlink message type. In the forwarding path process of the initial message, when the initial message is sent to the first virtual machine switch, it needs to carry the network port identifier (port ID) and the transceiver message queue identifier (queue ID) of the elastic network interface card of the source node (e.g., VM1) so that the first virtual machine switch can know which virtual machine the initial message is sent from. In the embodiment of the present disclosure, the second network port identifier and the second transceiver message queue identifier corresponding to the source node are written into the virtual queue Vring by the forwarding hardware. It should be noted that the second network port identifier and the second message transceiver queue identifier can be written into the message header of the communication message, and the message data of the initial message can be written into the payload data of the communication message. The first virtual switch reads the communication message including the initial message from the virtual queue via the second network interface (ENI-B), and then parses the communication message to obtain the second network port identifier and the second message transceiver queue identifier corresponding to the source node from the header, thereby determining the forwarding path of the initial message.

[0045]

[0044] In one or more embodiments, generating a first message corresponding to the initial message and forwarding the first message to the forwarding hardware includes: determining identification information used to characterize the forwarding path of the initial message based on the initial message; adding the identification information to the initial message to obtain the first message; and forwarding the first message from the first network interface of the first virtual switch to the forwarding hardware.

[0046]

[0045] Specifically, as shown in FIG5 , in an embodiment of the present disclosure, after the first virtual switch obtains the initial message and the second network port identifier and the second transceiver message queue identifier corresponding to the source node (e.g., VM1) from the virtual queue, the first virtual switch adds the second network port identifier and the second transceiver message queue identifier to the initial message to obtain a first message. The first message is then forwarded from the first network interface (ENI-A) of the first virtual switch to the forwarding hardware. The forwarding hardware forwards the first message to the second transceiver message queue corresponding to the second transceiver message queue identifier based on the second network port identifier and the second transceiver message queue identifier.

[0047]

[0046] In one or more embodiments, the preset diversion conditions include: not matching the table entries of the flow table of the forwarding hardware, and matching the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the upstream diversion mapping table is used to store the mapping relationship between the network identifier in the host machine message and the identifier of the first virtual switch, and the downstream diversion mapping table is used to store the correspondence between the network card port identifier in the host machine message and the identifier of the first virtual switch; or when the resource utilization rate of the second virtual switch is greater than a preset threshold, it does not match the table entries of the flow table of the forwarding hardware, and matches the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the second virtual switch runs in the network card.

[0048]

[0047] Specifically, as shown in FIG6 , in an embodiment of the present disclosure, a vSOC on a host machine can be started on demand. Since the vSOC itself is a virtual machine, its memory and processor resources are dynamically configurable. Therefore, it is possible to create a vSOC on demand based on load and resource requirements, and to migrate network resources and traffic from the second virtual switch to the first virtual machine switch. The present disclosure dynamically diverts or migrates traffic from the second virtual switch to the first virtual machine switch by setting an upstream traffic diversion mapping table (Vin table) and a downstream traffic diversion mapping table (port table).

[0049]

[0048] It should be noted that there are two cases for traffic diversion or migration from the second virtual switch to the first virtual machine switch. In the first case, when the initial message does not match an entry in the flow table of the forwarding hardware, the message is matched with a mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table. If the initial message is an upstream message, the initial message is matched with the mapping relationship in the upstream diversion mapping table. If the network identifier in the initial message matches the mapping relationship in the upstream diversion mapping table, the initial message is forwarded to the first virtual machine switch for processing; otherwise, the initial message is forwarded to the second virtual machine switch for processing. If the initial message is a downstream message, the initial message is matched with the mapping relationship in the downstream diversion mapping table. If the network card port identifier in the initial message matches the mapping relationship in the downstream diversion mapping table, the initial message is forwarded to the first virtual machine switch for processing; otherwise, the initial message is forwarded to the second virtual machine switch for processing.

[0050]

[0049] In one or more embodiments, the message forwarding method further includes: based on the third network interface of the first virtual switch, sending hardware configuration information to the forwarding hardware; the hardware configuration information includes configuration information corresponding to the flow table, and / or configuration information corresponding to the uplink diversion mapping table and the downlink diversion mapping table; and / or based on the fourth network interface of the first virtual switch, receiving management and configuration information sent by the second virtual switch.

[0051] Specifically, as shown in FIG7 , the first virtual switch sends configuration information corresponding to the flow table and / or configuration information corresponding to the upstream and downstream traffic distribution mapping tables to the forwarding hardware via the third network interface (ENI-C). The elastic network interface (ENI) in the disclosed embodiments is a virtual network interface that provides a network interface and IP address for a cloud server (ECS) instance in a private private network (VPC).

[0052]

[0051] As shown in Figure 8, the first virtual switch uses a dedicated elastic network card, namely ENI-C (configuration channel), to issue hardware configuration. The first virtual switch encapsulates the hardware configuration command containing hardware configuration information into a custom format message, and issues it from ENI-C to the forwarding hardware. After receiving the hardware configuration command, the forwarding hardware parses it according to the agreed custom format to complete the hardware configuration issuance.

[0053] the first virtual switch receives the management and configuration information sent by the second virtual switch through the fourth network interface ENLD and manages and configures the first virtual switch through the second virtual switch in the network card.

[0054]

[0053] In one or more embodiments, the message forwarding method also includes: receiving an initial message to be forwarded to a virtual machine in a second host machine; generating a second message corresponding to the initial message through a first virtual switch, and forwarding the second message to the forwarding hardware of the network card in the second host machine, so that the forwarding hardware of the network card in the second host machine forwards the second message according to the identification information in the second message.

[0055]

[0054] Specifically, in embodiments of the present disclosure, when faced with high-performance network requirements, such as scenarios where a large number of containers are enabled on a host machine to send and receive messages, all of the host machine's resources can be allocated to the first virtual switch, Host-vswitch. Specifically, no virtual machines are running on the current host machine, and only the first virtual switch is running. This enhances the network processing performance of the first virtual switch, thereby enabling the provision of high-performance network services for virtual machines on other hosts. As shown in FIG9 , the first virtual switch receives an initial message to be forwarded to a virtual machine on the first host machine (Host1). The first virtual switch generates a second message corresponding to the initial message, and forwards the second message to the forwarding hardware of the network interface card in the second host machine (Host2). The forwarding hardware of the network interface card in the second host machine forwards the second message based on identification information in the second message.

[0056]

[0055] As an optional implementation, as shown in FIG10, an embodiment of the present disclosure provides a message forwarding method, which is applied to a network card installed in a host machine, the host machine includes a first virtual switch, and the network card includes conversion hardware, including the following steps.

[0057]

[0056] S1002: Receive an initial message from a source node through the conversion hardware.

[0058]

[0057] S1004: If the initial message meets a preset diversion condition, transmit the initial message to the first virtual switch through the conversion hardware; the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target messages are messages for which a forwarding path cannot be determined based on a flow table of the conversion hardware.

[0059]

[0058] S1006: Receive, through the conversion hardware, a first message generated by the first virtual switch based on the initial message, where the first message carries identification information for characterizing a forwarding path of the initial message.

[0060]

[0059] S1008: Forward the first message through the forwarding hardware according to the identification information.

[0061]

[0060] Specifically, in an embodiment of the present disclosure, as shown in FIG3 , the first virtual machine switch runs in a virtual machine system on a chip (vSOC) of a host machine Host. After a message enters the host machine through a physical network port (PHY), the conversion hardware receives an initial message from a source node, and then matches each entry in a flow table in the forwarding hardware. If no entry is matched, the forwarding path of the initial message cannot be determined. At this time, the initial message needs to pass through the virtual switch to determine the forwarding path of the initial message. In the present disclosure, the first virtual switch (Host-vswitch) diverts the initial message that was originally intended to enter the second virtual machine switch (nic-vswitch), that is, the first virtual machine and the second virtual machine share the task of processing messages that do not match each entry in the flow table.

[0062]

[0061] After the first virtual switch receives the initial message sent by the forwarding hardware, it generates a first message corresponding to the initial message and carrying the network card identifier of the destination node or source node and / or the information transceiver queue identifier, and then sends the first message to the virtual machine on the host machine or to a network device outside the host machine through the forwarding hardware.

[0063]

[0062] In the embodiment of the present disclosure, when facing an application scenario that requires a software module in the network card to provide more on-chip resources, the first virtual machine and the second virtual machine jointly share the task of processing messages that are not matched to the entries in the flow table. This can solve the problem of insufficient on-chip resources such as the network card or the data processor in the network card in the application scenario that requires more on-chip resources. Without improving the memory or processor performance of the network card, the server-side network message processing capability can be significantly improved.

[0064]

[0063] In one or more embodiments, the initial message is a message sent by an external device to the host machine, and the initial message is transmitted to the first virtual switch through the conversion hardware, including: writing the first network port identifier and the first transceiver message queue identifier of the destination node into the message header of the communication message of the virtual queue, and writing the message data of the initial message into the payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through the first network interface; the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0065]

[0064] Specifically, as shown in FIG4 , in the embodiment of the present disclosure, the aforementioned initial message is a message sent by an external device to the host machine, that is, the initial message is an uplink message type. In the forwarding path process of the initial message, when the initial message is sent to the first virtual machine switch, it needs to carry the network port identifier (port ID) and the transceiver message queue identifier (queue ID) of the destination node's elastic network interface card (ENIC), so that the first virtual machine switch can know the forwarding destination node of the initial message. In the embodiment of the present disclosure, the first network port identifier and the first transceiver message queue identifier corresponding to the destination node of the initial message are written into the virtual queue Vring by forwarding hardware. The Vring is a data link connecting the virtual system-on-chip (vSOC) driver and the host machine driver. It should be noted that the first network port identifier and the first transceiver message queue identifier can be written into the message header (Header) of the communication message, and the message data of the initial message can be written into the payload data (Payload) of the communication message. The first virtual switch reads the communication message including the initial message from the virtual queue via the first network interface (ENLA), and then parses the communication message to obtain the first network port identifier and the first transceiver message queue identifier corresponding to the destination node from the header, thereby determining the forwarding path of the initial message.

[0066]

[0065] In one or more embodiments, receiving, by the forwarding hardware, a first message generated by the first virtual switch based on the initial message, and forwarding, by the forwarding hardware according to the identification information, the first message includes: obtaining, by the forwarding hardware, from the second network interface of the first virtual switch, a first message carrying identification information for characterizing a forwarding path of the initial message; and forwarding, by the forwarding hardware, the first message to a destination node corresponding to the identification information of the forwarding path.

[0067]

[0066] Specifically, as shown in FIG4 , in an embodiment of the present disclosure, after the first virtual switch obtains the initial message and the first network port identifier and the first transceiver message queue identifier corresponding to the destination node (e.g., VM1) from the virtual queue, the first network port identifier and the first transceiver message queue identifier are added to the initial message to obtain a first message. The first message is then forwarded from the second network interface (ENI-B) of the first virtual switch to the forwarding hardware. The forwarding hardware obtains the first message from the second network interface (ENI-B). The forwarding hardware then forwards the first message to the first transceiver message queue corresponding to VM1 based on the first network port identifier and the first transceiver message queue identifier. VM1 can then obtain the first message from the first transceiver message queue.

[0068]

[0067] In one or more embodiments, the initial message is a message sent by the virtual machine in the host computer, and the initial message is transmitted to the first virtual switch through the conversion hardware, including: writing the second network port identifier and the second transceiver message queue identifier of the source node into the message header of the communication message of the virtual machine queue, and writing the message data of the initial message into the payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through the second network interface; the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0069]

[0068] Specifically, as shown in FIG. 5 , in the embodiment of the present disclosure, the aforementioned initial message is a message sent by a virtual machine in the host machine, i.e., the initial message is a downlink message type. In the forwarding path process of the initial message, when the initial message is sent to the first virtual machine switch, it needs to carry the network port identifier (port ID) and the transceiver message queue identifier (queue ID) of the elastic network interface card of the source node (e.g., VM1) so that the first virtual machine switch can know which virtual machine the initial message is sent from. In the embodiment of the present disclosure, the second network port identifier and the second transceiver message queue identifier corresponding to the source node are written into the virtual queue Vring by the forwarding hardware. It should be noted that the second network port identifier and the second message transceiver queue identifier can be written into the message header of the communication message, and the message data of the initial message can be written into the payload data of the communication message. The first virtual switch reads the communication message including the initial message from the virtual queue via the second network interface (ENI-B), and then parses the communication message to obtain the second network port identifier and the second message transceiver queue identifier corresponding to the source node from the header, thereby determining the forwarding path of the initial message.

[0070]

[0069] In one or more embodiments, receiving, by the forwarding hardware, a first message generated by the first virtual switch based on the initial message, and forwarding, by the forwarding hardware according to the identification information, the first message includes: obtaining, by the forwarding hardware, from the first network interface of the first virtual switch, a first message carrying identification information for characterizing a forwarding path of the initial message; and forwarding, by the forwarding hardware, the first message to a destination node corresponding to the identification information of the forwarding path.

[0071]

[0070] Specifically, as shown in FIG5 , in an embodiment of the present disclosure, after the first virtual switch obtains an initial message and the second network port identifier and the second transceiver message queue identifier corresponding to the source node (e.g., VM1) from the virtual queue, the first virtual switch adds the second network port identifier and the second transceiver message queue identifier to the initial message to obtain a first message. The first message is then forwarded from the first network interface (ENI-A) of the first virtual switch to the forwarding hardware. After receiving the first message from ENI-A, the forwarding hardware forwards the first message to the second transceiver message queue corresponding to the second transceiver message queue identifier based on the second network port identifier and the second transceiver message queue identifier carried in the first message, thereby transmitting the first message to the destination node.

[0072]

[0071] In one or more embodiments, when the initial message meets the preset diversion condition, transmitting the initial message to the first virtual switch through the conversion hardware includes: determining that the initial message does not match an entry in the flow table of the conversion hardware and that the initial message matches a mapping relationship in an upstream diversion mapping table or a downstream diversion mapping table, and transmitting the initial message to the first virtual switch through the conversion hardware; wherein the upstream diversion mapping table is used to store a correspondence between a network identifier in the host message and an identifier of the first virtual machine switch, and the downstream diversion mapping table is used to store a correspondence between a network card port identifier in the host message and an identifier of the first virtual machine switch; or when the resource utilization rate of the second virtual switch is greater than a preset threshold, determining that the initial message does not match an entry in the flow table of the conversion hardware and that the initial message matches a mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table, and transmitting the initial message to the first virtual switch through the conversion hardware; and the second virtual switch runs in the network card.

[0073]

[0072] Specifically, as shown in FIG6 , in an embodiment of the present disclosure, a vSOC on a host machine can be started on demand. Since the vSOC itself is a virtual machine, its memory and processor resources are dynamically configurable. Therefore, it is possible to create a vSOC on demand based on load and resource requirements, and to divert or migrate network resources and traffic from the second virtual switch to the first virtual machine switch. The present disclosure dynamically diverts or migrates traffic from the second virtual switch to the first virtual machine switch by setting an upstream diversion mapping table (Vin table) and a downstream diversion mapping table (port table).

[0074]

[0073] It should be noted that there are two cases for traffic diversion or migration from the second virtual switch to the first virtual machine switch. In the first case, when the initial message does not match an entry in the flow table of the forwarding hardware, the message is matched with a mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table. If the initial message is an upstream message, the initial message is matched with the mapping relationship in the upstream diversion mapping table. If the network identifier in the initial message matches the mapping relationship in the upstream diversion mapping table, the initial message is forwarded to the first virtual machine switch for processing; otherwise, the initial message is forwarded to the second virtual machine switch for processing. If the initial message is a downstream message, the initial message is matched with the mapping relationship in the downstream diversion mapping table. If the network card port identifier in the initial message matches the mapping relationship in the downstream diversion mapping table, the initial message is forwarded to the first virtual machine switch for processing; otherwise, the initial message is forwarded to the second virtual machine switch for processing.

[0075]

[0074] In one or more embodiments, the message forwarding method further includes: receiving hardware configuration information sent from the third network interface of the first virtual switch through the forwarding hardware; the hardware configuration information includes configuration information corresponding to the flow table, and / or configuration information corresponding to the upstream diversion mapping table and the downstream diversion mapping table; and / or, sending management and configuration information corresponding to the first virtual switch to the second virtual switch through the fourth network interface of the first virtual switch.

[0076]

[0075] Specifically, as shown in FIG7 , the first virtual switch sends configuration information corresponding to the flow table and / or configuration information corresponding to the upstream and downstream traffic distribution mapping tables to the forwarding hardware via the third network interface (ENI-C). The elastic network interface (ENI) in the disclosed embodiments is a virtual network interface that provides a network interface and IP address for a cloud server (ECS) instance in a private private network (VPC).

[0077]

[0076] As shown in Figure 8, the first virtual switch uses a dedicated elastic network card, namely ENI-C (configuration channel), to issue hardware configuration. The first virtual switch encapsulates the hardware configuration command containing hardware configuration information into a custom format message, and issues it from ENI-C to the forwarding hardware. After receiving the hardware configuration command, the forwarding hardware parses it according to the agreed message format to complete the hardware configuration issuance.

[0078] the first virtual switch receives the management and configuration information sent by the second virtual switch through the fourth network interface ENLD and manages and configures the first virtual switch through the second virtual switch in the network card.

[0079]

[0078] According to another aspect of the embodiments of the present disclosure, a message forwarding device for implementing the above-mentioned message forwarding method is also provided, as shown in Figure 11, which is applied to a first virtual switch, wherein the first virtual switch runs in a host machine, and the network card of the host machine includes forwarding hardware; the device includes a receiving unit 1102 and a generating forwarding unit 1104.

[0080]

[0079] A receiving unit 1102 is configured to receive an initial message sent by the forwarding hardware, wherein the initial message is a message that meets a preset diversion condition, wherein the preset diversion condition is used to divert messages requiring processing by the first virtual switch from target messages, wherein the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware.

[0080] A generating and forwarding unit 1104 is configured to generate a first message corresponding to the initial message and send the first message to the forwarding hardware, so that the forwarding hardware forwards the first message based on identification information in the first message; the identification information is used to indicate a forwarding path for the initial message.

[0081]

[0081] In one or more embodiments, the initial message is a message sent by an external device to the host machine, and the receiving unit 1102 includes: a first reading module, which is used to read a communication message including the initial message from a virtual queue based on the first network interface of the first virtual switch, wherein the message header of the communication message carries a first network port identifier and a first transceiver message queue identifier corresponding to the destination node of the initial message, and the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0082]

[0082] In one or more embodiments, the generating forwarding unit 1104 includes: a first determining module, used to determine, based on the initial message, identification information used to characterize the forwarding path of the initial message; a first adding module, used to add the identification information to the initial message to obtain the first message; and a first forwarding module, used to forward the first message from the second network interface of the first virtual switch to the forwarding hardware.

[0083]

[0083] In one or more embodiments, the initial message is a message sent by the virtual machine in the host machine, and the receiving unit 1102 includes: a second reading module, which is used to read a communication message including the initial message from a virtual queue based on the second network interface of the first virtual switch, and the message header of the communication message carries a second network port identifier and a second message sending and receiving queue identifier corresponding to the source node of the initial message. The virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0084]

[0084] In one or more embodiments, the generating forwarding unit 1104 includes: a second determining module, used to determine, based on the initial message, identification information used to characterize the forwarding path of the initial message; a second adding module, used to add the identification information to the initial message to obtain the first message; and a second forwarding module, used to forward the first message from the first network interface of the first virtual switch to the forwarding hardware.

[0085]

[0085] In one or more embodiments, the preset diversion conditions include: not matching the table entries in the flow table of the forwarding hardware, and matching the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the upstream diversion mapping table is used to store the mapping relationship between the network identifier in the host machine message and the identifier of the first virtual switch, and the downstream diversion mapping table is used to store the correspondence between the network card port identifier in the host machine message and the identifier of the first virtual switch; or when the resource utilization rate of the second virtual switch is greater than a preset threshold, it does not match the table entries in the flow table of the forwarding hardware, and matches the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the second virtual switch runs in the network card.

[0086]

[0086] In one or more embodiments, the document forwarding device also includes: a configuration sending unit, which is used to send hardware configuration information to the forwarding hardware based on the third network interface of the first virtual switch; the hardware configuration information includes configuration information corresponding to the flow table, and / or configuration information corresponding to the uplink diversion mapping table and the downlink diversion mapping table; and / or a receiving configuration unit, which is used to receive management and configuration information sent by the second virtual switch based on the fourth network interface of the first virtual switch.

[0087]

[0087] According to another aspect of the embodiments of the present disclosure, a message forwarding device for implementing the above-mentioned message forwarding method is also provided, which is applied to a network card, the network card is installed in a host machine, the host machine includes a first virtual switch, and the network card includes conversion hardware. As shown in Figure 12, the device includes the following units.

[0088]

[0088] The first receiving unit 1202 is configured to receive an initial message from a source node through the conversion hardware.

[0089] A transmission unit 1204 is configured to transmit the initial packet to the first virtual switch through the conversion hardware if the initial packet meets a preset diversion condition; the preset diversion condition is configured to divert packets that need to be processed by the first virtual switch from target packets, where the target packets are packets for which a forwarding path cannot be determined based on a flow table of the conversion hardware.

[0089]

[0090] The second receiving unit 1206 is configured to receive, through the conversion hardware, a first message generated by the first virtual switch based on the initial message, where the first message carries identification information for characterizing a forwarding path of the initial message.

[0090]

[0091] The forwarding unit 1208 is configured to forward the first message through the forwarding hardware according to the identification information.

[0091]

[0092] In one or more embodiments, the initial message is a message sent by an external device to the host machine, and the transmission unit 1204 includes: a first writing module, configured to write a first network port identifier and a first message sending and receiving queue identifier of a destination node into a message header of a communication message of a virtual queue, and write message data of the initial message into payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through a first network interface; the virtual queue is a data link for communication between the host machine and a virtual system-on-chip to which the first virtual switch belongs.

[0092]

[0093] In one or more embodiments, the second receiving unit 1206 includes: a first obtaining module configured to obtain, through the forwarding hardware, a first message carrying identification information representing a forwarding path of the initial message from the second network interface of the first virtual switch.

[0093]

[0094] The forwarding unit 1208 includes: a first forwarding module, configured to forward the first message to a destination node corresponding to the identification information of the forwarding path through the forwarding hardware.

[0094]

[0095] In one or more embodiments, the initial message is a message sent by the virtual machine in, and the transmission unit 1204 includes: a second writing module, which is used to write the second network port identifier and the second transceiver message queue identifier of the source node into the message header of the communication message of the virtual machine queue, and write the message data of the initial message into the payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through the second network interface; the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

[0095]

[0096] In one or more embodiments, the second receiving unit 1206 includes: a second acquisition module, configured to enable the forwarding hardware to obtain, from the first network interface of the first virtual switch, a first message carrying identification information representing the forwarding path of the initial message; and the forwarding unit 1208 includes: a second forwarding module, configured to forward, through the forwarding hardware, the first message to a destination node corresponding to the identification information of the forwarding path.

[0096]

[0097] In one or more embodiments, the transmission unit 1204 includes: a first transmission module, configured to determine that the initial message does not match an entry in a flow table of the conversion hardware and that the initial message matches a mapping relationship in an upstream offload mapping table or a downstream offload mapping table, and transmit the initial message to the first virtual switch through the conversion hardware; wherein the upstream offload mapping table is configured to store a correspondence between a network identifier in the host message and an identifier of the first virtual machine switch, and the downstream offload mapping table is configured to store a correspondence between a network card port identifier in the host message and an identifier of the first virtual machine switch; or a second transmission module, configured to determine that the initial message does not match an entry in the flow table of the conversion hardware and that the initial message matches a mapping relationship in the upstream offload mapping table or the downstream offload mapping table when a resource utilization rate of the second virtual switch is greater than a preset threshold, and transmit the initial message to the first virtual switch through the conversion hardware; and the second virtual switch runs in the network card.

[0098] In one or more embodiments, the message forwarding device further includes: a configuration receiving unit, configured to receive, through the forwarding hardware, hardware configuration information sent from the third network interface of the first virtual switch; the hardware configuration information includes configuration information corresponding to the flow table, and / or configuration information corresponding to the upstream diversion mapping table and the downstream diversion mapping table; and / or, a configuration sending unit, configured to send management and configuration information corresponding to the first virtual switch to the second virtual switch through the fourth network interface of the first virtual switch.

[0097]

[0099] According to another aspect of the embodiments of the present disclosure, a message forwarding system for implementing the above-mentioned message forwarding method is also provided. As shown in FIG13 , the system includes a first virtual switch and a network card; the first virtual switch runs on a host machine, and the network card includes forwarding hardware.

[0098]

[0100] The IoT terminal and the first virtual switch are configured to receive an initial message sent by the forwarding hardware, where the initial message is a message that satisfies a preset diversion condition, and the preset diversion condition is configured to divert messages that need to be processed by the first virtual switch from target messages, where the target message is a message whose forwarding path cannot be determined based on a flow table of the forwarding hardware; generate a first message corresponding to the initial message through the first virtual switch, and send the first message to the forwarding hardware; and carry identification information for characterizing the forwarding path of the initial message.

[0099]

[0101] The network card is used to receive an initial message from a source node through the forwarding hardware; when the initial message meets a preset diversion condition, transmit the initial message to the first virtual switch through the forwarding hardware; receive a first message generated by the first virtual switch based on the initial message through the forwarding hardware; and forward the first message through the forwarding hardware according to the identification information.

[0100]

[0102] According to another aspect of an embodiment of the present disclosure, an electronic device for implementing the aforementioned network security management and control method is also provided. This electronic device may be the first virtual switch or network card shown in FIG13 . This embodiment is described using the electronic device as the first virtual switch as an example. As shown in FIG14 , the electronic device includes a memory 1402 and a processor 1404. The memory 1402 stores a computer program, and the processor 1404 is configured to execute the steps of any of the aforementioned method embodiments using the computer program.

[0101]

[0103] Optionally, in this embodiment, the electronic device may be at least one network device among multiple network devices of a computer network.

[0102]

[0104] Optionally, in this embodiment, the processor may be configured to execute the following steps through a computer program:

[0103]

[0105] S11, receiving an initial message sent by the forwarding hardware, where the initial message is a message that meets a preset diversion condition, where the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware;

[0104]

[0106] S12: Generate a first message corresponding to the initial message, and send the first message to the forwarding hardware, so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to represent a forwarding path of the initial message.

[0105]

[0107] Memory 1402 may be used to store software programs and modules, such as program instructions / modules corresponding to the network security management and control methods and apparatuses in the embodiments of the present disclosure. Processor 1404 executes the software programs and modules stored in memory 1402 to perform various functional applications and data processing, thereby implementing the aforementioned message forwarding method. Memory 1402 may include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, memory 1402 may further include memory remotely located from processor 1404, which may be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. Memory 1402 may specifically, but is not limited to, be used to store a Media Access Control Address (MAC) table.

[0106]

[0108] As an example, as shown in FIG14 , the memory 1402 may include, but is not limited to, the receiving unit 1102 and the generating and forwarding unit 1104 in the network security management and control apparatus. Furthermore, the memory 1402 may include, but is not limited to, other module units in the network security management and control apparatus, which will not be described in detail in this example.

[0107]

[0109] Optionally, the transmission device 1406 is configured to receive or send data via a network. Specific examples of the aforementioned network may include wired networks and wireless networks. In one example, the transmission device 1406 includes a network interface controller (NIC), which can be connected to other network devices and a router via a network cable to enable communication with the Internet or a local area network. In another example, the transmission device 1406 is a radio frequency (RF) module configured to communicate with the Internet wirelessly.

[0108]

[0110] In addition, the electronic device further includes a connection bus 1408, which is used to connect various module components in the electronic device.

[0109]

[0111] According to another aspect of an embodiment of the present disclosure, an electronic device for implementing the aforementioned network security management and control method is also provided. This electronic device may be the first virtual switch or network card shown in FIG13 . This embodiment is described using the network card as an example. As shown in FIG15 , the electronic device includes a memory 1502 and a processor 1504. The memory 1502 stores a computer program, and the processor 1504 is configured to execute the steps of any of the aforementioned method embodiments using the computer program.

[0110]

[0112] Optionally, in this embodiment, the electronic device may be at least one network device among multiple network devices of a computer network.

[0111]

[0113] Optionally, in this embodiment, the processor may be configured to execute the following steps through a computer program.

[0112]

[0114] S21: Receive an initial message from a source node through the conversion hardware.

[0113]

[0115] S22: If the initial packet meets a preset diversion condition, transmit the initial packet to the first virtual switch through the conversion hardware; the preset diversion condition is used to divert packets that need to be processed by the first virtual switch from target packets, where the target packets are packets for which a forwarding path cannot be determined based on a flow table of the conversion hardware.

[0114]

[0116] S23. Receive, through the conversion hardware, a first message generated by the first virtual switch based on the initial message, where the first message carries identification information for characterizing a forwarding path of the initial message.

[0115]

[0117] S24: Forward the first message through the forwarding hardware according to the identification information.

[0116]

[0118] Memory 1502 can be used to store software programs and modules, such as program instructions / modules corresponding to the network security management and control methods and apparatuses in the embodiments of the present disclosure. Processor 1504 executes the software programs and modules stored in memory 1502 to perform various functional applications and data processing, thereby implementing the aforementioned message forwarding method. Memory 1502 can include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, memory 1502 can further include memory remotely located from processor 1504, and such remote memory can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. Memory 1502 can be used, but is not limited to, to store flow table entry information.

[0117]

[0119] As an example, as shown in FIG. 15 , the memory 1502 may include, but is not limited to, the first receiving unit 1202, the transmission unit 1204, the second receiving unit 1206, and the forwarding unit 1208 of the network security management and control device. Furthermore, the memory 1502 may include, but is not limited to, other modules and units of the network security management and control device, which are not described in detail in this example.

[0118]

[0120] Optionally, the transmission device 1506 is configured to receive or send data via a network. Specific examples of the network may include wired networks and wireless networks. In one example, the transmission device 1506 includes a network interface controller (NIC), which can be connected to other network devices and a router via a network cable to communicate with the Internet or a local area network. In another example, the transmission device 1506 is a radio frequency (RF) module configured to communicate with the Internet wirelessly.

[0119]

[0121] In addition, the electronic device further includes a connection bus 1508, which is used to connect various module components in the electronic device.

[0120]

[0122] In other embodiments, the electronic device may be a node in a distributed system, wherein the distributed system may be a blockchain system. The blockchain system may be a distributed system formed by connecting multiple nodes via network communication. The nodes may form a peer-to-peer (P2P) network. Any computing device, such as a server or terminal, may become a node in the blockchain system by joining the peer-to-peer network.

[0121]

[0123] In one or more embodiments, the present disclosure further provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the aforementioned network security management and control method. The computer program is configured to execute the steps of any of the aforementioned method embodiments when executed.

[0122]

[0124] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for executing the following steps:

[0123]

[0125] S11, receiving an initial message sent by the forwarding hardware, where the initial message is a message that meets a preset diversion condition, where the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware;

[0124]

[0126] S12: Generate a first message corresponding to the initial message, and send the first message to the forwarding hardware, so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to represent the forwarding path of the initial message. A computer program is further configured to perform the following steps:

[0125]

[0127] S21, receiving an initial message from a source node through the conversion hardware;

[0126]

[0128] S22: If the initial packet meets a preset diversion condition, transmit the initial packet to the first virtual switch through the conversion hardware; the preset diversion condition is used to divert packets that need to be processed by the first virtual switch from target packets, the target packets being packets for which a forwarding path cannot be determined based on a flow table of the conversion hardware;

[0127]

[0129] S23. Receive, through the conversion hardware, a first message generated by the first virtual switch based on the initial message, where the first message carries identification information for characterizing a forwarding path of the initial message;

[0130] S24: Forward the first message through the forwarding hardware according to the identification information.

[0128]

[0131] Optionally, in this embodiment, a person of ordinary skill in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by a program to instruct hardware related to the terminal device. The program may be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0129]

[0132] The serial numbers of the above embodiments of the present disclosure are for description only and do not represent the advantages or disadvantages of the embodiments.

[0130]

[0133] If the integrated units in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in the aforementioned computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the relevant art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for causing one or more computer devices (such as personal computers, servers, or network devices) to execute all or part of the steps of the methods of various embodiments of the present invention.

[0131]

[0134] In the above embodiments of the present invention, the description of each embodiment is given with emphasis. For parts not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0132]

[0135] In the several embodiments provided in this disclosure, it should be understood that the disclosed client can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is merely a logical functional division. In actual implementation, other divisions may be employed. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through interfaces, or indirect coupling or communication connection between units or modules, and may be electrical or otherwise.

[0133]

[0136] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected based on actual needs to achieve the objectives of this embodiment.

[0134]

[0137] In addition, the functional units in various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0135]

[0138] The above are only preferred embodiments of the present invention. It should be noted that those skilled in the art can make several improvements and modifications without departing from the principles of the present invention, and such improvements and modifications should also be considered within the scope of protection of the present invention.

[0136]

[0139] All user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties. The collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and corresponding operation portals shall be provided for users to choose to authorize or refuse.

Claims

Claims 1. A packet forwarding method, applied to a first virtual switch, wherein the first virtual switch runs in a host computer, and the network interface card of the host computer includes forwarding hardware; the method comprising: Receive an initial message sent by the forwarding hardware, where the initial message is a message that meets a preset diversion condition, where the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message for which a forwarding path cannot be determined based on a flow table of the forwarding hardware; generate a first message corresponding to the initial message, and send the first message to the forwarding hardware so that the forwarding hardware forwards the first message according to identification information in the first message; the identification information is used to characterize the forwarding path of the initial message.

2. The method according to claim 1, wherein The initial message is a message sent by an external device to the host machine. The receiving the initial message sent by the forwarding hardware includes: reading a communication message including the initial message from a virtual queue based on a first network interface of the first virtual switch, wherein a message header of the communication message carries a first network port identifier and a first message transmitting and receiving queue identifier corresponding to a destination node of the initial message. The virtual queue is a data link for communication between the host machine and the virtual system-on-chip to which the first virtual switch belongs.

3. The method according to claim 1 or 2, wherein The generating of a first message corresponding to the initial message and forwarding the first message to the forwarding hardware includes: determining, based on the initial message, identification information used to characterize a forwarding path of the initial message; adding the identification information to the initial message to obtain the first message; and forwarding the first message to the forwarding hardware from the second network interface of the first virtual switch.

4. The method according to claim 1, wherein The initial message is a message sent by the virtual machine in the host machine, and the receiving of the initial message sent by the forwarding hardware includes: reading a communication message including the initial message from a virtual queue based on the second network interface of the first virtual switch, wherein the message header of the communication message carries a second network port identifier and a second message sending and receiving queue identifier corresponding to the source node of the initial message, and the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

5. The method according to claim 1 or 4, wherein The generating of a first message corresponding to the initial message and forwarding the first message to the forwarding hardware includes: determining, based on the initial message, identification information used to characterize a forwarding path of the initial message; adding the identification information to the initial message to obtain the first message; and forwarding the first message from the first network interface of the first virtual switch to the forwarding hardware.

6. The method according to claim 1, wherein: The preset diversion conditions include: not matching the table entries of the flow table of the forwarding hardware, and matching the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the upstream diversion mapping table is used to store the mapping relationship between the network identifier in the host machine message and the identifier of the first virtual switch, and the downstream diversion mapping table is used to store the correspondence between the network card port identifier in the host machine message and the identifier of the first virtual switch; or when the resource utilization of the second virtual switch is greater than the preset threshold, it does not match the table entries of the flow table of the forwarding hardware, and matches the mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table; the second virtual switch runs in the network card.

7. The method according to claim 6, further comprising: Based on the third network interface of the first virtual switch, the hardware configuration information is sent to the forwarding hardware; The hardware configuration information includes configuration information corresponding to the flow table, and / or configuration information corresponding to the uplink diversion mapping table and the downlink diversion mapping table; and / or receiving management and configuration information sent by the second virtual switch based on the fourth network interface of the first virtual switch.

8. A packet forwarding method, applied to a network card, wherein the network card is installed in a host machine, the host machine includes a first virtual switch, and the network card includes conversion hardware; the method comprising: receiving an initial message from a source node through the conversion hardware; When the initial message satisfies a preset diversion condition, the initial message is transmitted to the first virtual switch through the conversion hardware; the preset diversion condition is used to divert messages that need to be processed by the first virtual switch from target messages, and the target message is a message whose forwarding path cannot be determined based on the flow table of the conversion hardware; a first message generated by the first virtual switch based on the initial message is received through the conversion hardware, the first message carrying identification information used to characterize the forwarding path of the initial message; and the first message is forwarded through the forwarding hardware according to the identification information.

9. The method according to claim 8, wherein The initial message is a message sent by an external device to the host machine. The initial message is transmitted to the first virtual switch through the conversion hardware, including: writing the first network port identifier and the first message sending and receiving queue identifier of the destination node into the message header of the communication message of the virtual queue, and writing the message data of the initial message into the payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through the first network interface; the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

10. The method according to claim 8 or 9, wherein Receiving a first message generated by the first virtual switch based on the initial message through the forwarding hardware, and forwarding the first message through the forwarding hardware according to the identification information, including: obtaining a first message carrying identification information for characterizing a forwarding path of the initial message from the second network interface of the first virtual switch through the forwarding hardware; forwarding the first message to a destination node corresponding to the identification information of the forwarding path through the forwarding hardware.

11. The method according to claim 8, wherein: The initial message is a message sent by the virtual machine in the host, and the initial message is transmitted to the first virtual switch through the conversion hardware, including: writing the second network port identifier and the second message sending and receiving queue identifier of the source node into the message header of the communication message of the virtual machine queue, and writing the message data of the initial message into the payload data of the communication message, so that the first virtual switch obtains the communication message from the virtual machine queue through the second network interface; the virtual queue is a data link for communication between the host machine and the virtual system on chip to which the first virtual switch belongs.

12. The method according to claim 8 or 11, wherein Receiving, by the forwarding hardware, a first message generated by the first virtual switch based on the initial message, and forwarding the first message by the forwarding hardware according to the identification information, comprising: obtaining, by the forwarding hardware, from a first network interface of the first virtual switch, a first message carrying identification information for characterizing a forwarding path of the initial message; forwarding, by the forwarding hardware, the first message to a destination node corresponding to the identification information of the forwarding path; 7 p.m.

13. The method according to claim 8, wherein: The transmitting the initial message to the first virtual switch through the conversion hardware when the initial message meets the preset diversion condition includes: determining that the initial message does not match an entry in the flow table of the conversion hardware and that the initial message matches a mapping relationship in an upstream diversion mapping table or a downstream diversion mapping table, and transmitting the initial message to the first virtual switch through the conversion hardware; wherein the upstream diversion mapping table is used to store a correspondence between a network identifier in the host message and an identifier of the first virtual machine switch, and the downstream diversion mapping table is used to store a correspondence between a network card port identifier in the host message and an identifier of the first virtual machine switch; or when the resource utilization rate of the second virtual switch is greater than a preset threshold, determining that the initial message does not match an entry in the flow table of the conversion hardware and that the initial message matches a mapping relationship in the upstream diversion mapping table or the downstream diversion mapping table, and transmitting the initial message to the first virtual switch through the conversion hardware; the second virtual switch runs in the network card.

14. The method according to claim 13, further comprising: receiving, through the forwarding hardware, hardware configuration information sent from the third network interface of the first virtual switch; the hardware configuration information including configuration information corresponding to the flow table and / or configuration information corresponding to the upstream flow splitting mapping table and the downstream flow splitting mapping table; and / or sending management and configuration information corresponding to the first virtual switch to the second virtual switch via the fourth network interface of the first virtual switch.

15. A packet forwarding system, comprising a first virtual switch and a network interface card (NIC); the first virtual switch running on a host machine, the network interface card including forwarding hardware; the first virtual switch configured to receive an initial packet sent by the forwarding hardware, the initial packet being a packet that satisfies a preset diversion condition, the preset diversion condition being configured to divert packets requiring processing by the first virtual switch from target packets, the target packets being packets for which a forwarding path cannot be determined based on a flow table of the forwarding hardware; generating a first packet corresponding to the initial packet via the first virtual switch, and sending the first packet to the forwarding hardware; The first message carries identification information for characterizing a forwarding path of the initial message; the network card is configured to receive the initial message from a source node through the forwarding hardware; If the initial message meets a preset diversion condition, transmitting the initial message to the first virtual switch through the forwarding hardware; receiving, through the forwarding hardware, a first message generated by the first virtual switch based on the initial message; The first message is forwarded by the forwarding hardware according to the identification information.

16. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: The processor runs the computer program to implement the method according to any one of claims 1 to 7, or 8 to 14.

17. A computer-readable storage medium having a computer program stored thereon, wherein: The program is executed by a processor to implement the method according to any one of claims 1 to 7, or 8 to 14.

18. A computer program product comprising a computer program, wherein: The computer program is executed by a processor to implement the method according to any one of claims 1 to 7, or 8 to 14.

Citation Information

Patent Citations

  • Intelligent network card, data forwarding method and device and electronic equipment

    CN114793217A

  • Message forwarding control method, DPU and related equipment

    CN116886621A

  • Tunnel encapsulation table resource management method, DPU and related equipment

    CN116996478A

Cited By

  • Virtual switch deployment and test method and device

    CN121239653A