Packet forwarding method and system in service function chain (SFC), and medium and product

By using the SFC routing table entries in the Service Function Chain (SFC) to determine the network address of the next-hop SF through mapping relationships, no additional encapsulation is required. This solves the packet encapsulation overhead and system maintenance cost problems caused by NSH encapsulation, and achieves efficient packet forwarding.

WO2026007569A1PCT designated stage Publication Date: 2026-01-08TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/096354
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-03
Filing Date
2025-05-21
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing technologies require additional encapsulation of the NSH protocol in the Service Function Chain (SFC), which increases message encapsulation overhead. Furthermore, multi-tenant network architectures need to be extended to support the NSH protocol, increasing system maintenance difficulty and implementation costs.

Method used

The Service Function Forwarding Node (SFF) determines the network address of the next-hop SF by receiving the destination network address and sending node information of the target packet and using the mapping relationship in the SFC routing table entries. No additional encapsulation steps, such as NSH encapsulation, are required; the packet is forwarded directly.

Benefits of technology

It reduces message encapsulation overhead, lowers the network infrastructure's dependence on specific protocols, improves system maintainability, and reduces implementation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025096354_08012026_PF_FP_ABST
    Figure CN2025096354_08012026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a packet forwarding method, system and apparatus in a service function chain (SFC), and a computer-readable storage medium, an electronic device and a computer program product, which are applied to the technical field of communications. The method comprises: an SFF receiving a target packet, wherein the target packet carries a destination network address of a corresponding service and sending node information of the target packet; when determining that the target packet hits an SFC routing table entry, on the basis of a first mapping relationship recorded in the SFC routing table entry, the SFF determining a network address of a next-hop SF of the target packet, wherein the SFC routing table entry records a mapping relationship between routing matching information of different services and next-hop SF information, the routing matching information comprises a destination network address of a target service and sending node information of a current packet, and the next-hop SF information is used for determining the next-hop SF to which the current packet is forwarded; and on the basis of the network address of the next-hop SF, the SFF sending the target packet. By means of the packet forwarding solution in an SFC which is provided in the present application, it is not necessary to introduce additional NSH encapsulation.
Need to check novelty before this filing date? Find Prior Art

Description

Method, system, medium and product for forwarding message in service function chain (SFC)

[0001] Priority information

[0002] The present application claims priority from the Chinese patent application No. 202410890977.9 and titled "Method, system, medium and product for forwarding message in service function chain (SFC)", filed on July 03, 2024, with the China Patent Office, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] Embodiments of the present application relate to the field of communication technology, and in particular to a method, system, device, computer readable storage medium, electronic device and computer program product for forwarding message in service function chain (SFC). BACKGROUND

[0004] Service function chain (SFC) is a technology for supporting the quality of service requirement of application layer by organizing and orchestrating service functions in the network, and thus providing ordered service for the application layer. Specifically, SFC connects the services on the network devices, virtualized or cloud native service components in the logical layer, and thus forms an ordered service combination.

[0005] Network service header (NSH) is a network protocol. In the related art, NSH is used in the SFC architecture, and is specifically used to provide a method for encapsulating service link information into the header of a message, so as to correctly guide the message to the next network service function node that should be accessed when forwarding in the network, and thus help the message to be correctly routed in the SFC.

[0006] It can be seen that the message forwarding in the SFC framework provided by the related art relies on the implementation of NSH encapsulation. SUMMARY

[0007] The present application provides a method, device, system, computer readable storage medium, electronic device and computer program product for forwarding message in service function chain (SFC), without introducing additional encapsulation such as NSH encapsulation.

[0008] In a first aspect, the application provides a method for forwarding a message in a service function chain, applied to a service function forwarding node SFF, the method comprising: receiving a target message, wherein the target message carries a destination network address of a corresponding service and sending node information of the target message; determining that the target message hits a SFC routing table item according to the carrying information of the target message, wherein the SFC routing table item records a first mapping relationship between first routing matching information and next hop SF information, the first routing matching information includes the destination network address of the target service and the sending node information of the current message, and the next hop SF information is used to determine a next hop SF to which the current message is forwarded; determining a network address of a next hop service function node SF of the target message based on the SFC routing table item; and sending the target message based on the network address of the next hop SF of the target message.

[0009] In an exemplary embodiment, based on the above scheme, before receiving the target message, the method further comprises: receiving a SFC routing table item issued by a control node; wherein the routing table item about the target service in the SFC routing table item is determined according to a service function path SFP of the target service, and the control node is a software defined network SDN controller.

[0010] In an exemplary embodiment, based on the above scheme, the determining that the target message hits the SFC routing table item according to the carrying information of the target message comprises: searching the SFC routing table item according to the destination network address carried by the target message; if it is determined that the destination network address carried by the target message hits the destination network address about the target service in the SFC routing table item, determining whether the sending node information carried by the target message is included in the first routing matching information about the target service of the SFC routing table item; and if it is determined that the sending node information carried by the target message is included in the routing matching information in the first routing table item about the target service of the SFC routing table item, determining that the target message hits the SFC routing table item about the target service.

[0011] In an exemplary embodiment, based on the above scheme, the determining the network address of the next hop SF of the target message based on the first mapping relationship recorded by the SFC routing table item comprises: determining the target SF information from the SFC routing table item information according to the sending node information carried by the target message and the first mapping relationship; and determining the network address of the next hop SF of the target message according to the target SF information.

[0012] In an example embodiment, based on the above scheme, the next hop SF information in the SFC routing entry is an SF identifier having a second mapping relationship with a tenant identifier in the Overlay network; and the method further includes: determining the network address of the next hop SF of the target packet according to the target SF information, including: searching an instance table according to the target SF information to obtain a target tenant identifier having a second mapping relationship with the target SF information, and obtaining the network address of the SF having a third mapping relationship with the target tenant identifier to obtain the network address of the next hop SF of the target packet; wherein the instance table records the second mapping relationship between the SF identifier and the tenant identifier and records the third mapping relationship between the tenant identifier and the network address of the SF.

[0013] In an example embodiment, based on the above scheme, the sending of the target packet based on the network address of the next hop SF of the target packet includes: searching an Overlay routing entry according to the network address of the next hop SF of the target packet and the target tenant identifier to determine the encapsulation information required for forwarding the target packet to the next hop SF, wherein the Overlay routing entry records a fourth mapping relationship between second route matching information and encapsulation information, and the second route matching information includes the network address of the next hop SF and the tenant identifier; tunnel encapsulating the target packet according to the encapsulation information corresponding to the forwarding of the target packet to the next hop SF; and sending the tunnel encapsulated target packet according to the network address of the next hop SF of the target packet.

[0014] In an example embodiment, based on the above scheme, the method further includes: if it is determined that the target packet does not hit the SFC routing entry according to the carrying information in the target packet, searching the Overlay routing entry according to the destination network address carried by the target packet to determine the encapsulation information corresponding to the forwarding to the destination network address; tunnel encapsulating the target packet according to the encapsulation information corresponding to the destination network address; and sending the tunnel encapsulated target packet to the node corresponding to the destination network address.

[0015] In an example embodiment, based on the above scheme, the target SF information is the network address of the next hop SF of the target packet; and the method further includes: if it is determined that the target packet does not hit the SFC routing entry according to the carrying information of the target packet, sending the target packet according to the destination network address carried by the target packet.

[0016] In a second aspect, the present application provides a system for forwarding a message in a service function chain, comprising: a service function forwarding node (SFF) configured to receive a target message, wherein the target message carries a destination network address of a corresponding service and sending node information of the target message; determine that the target message hits a SFC routing table item according to the carrying information of the target message; determine a network address of a next hop service function node (SF) of the target message based on a first mapping relationship recorded in the SFC routing table item; and send the target message based on the network address of the next hop SF of the target message; wherein the SFC routing table item records a first mapping relationship between first routing matching information of a target service and next hop SF information, the first routing matching information comprises the destination network address of the target service and the sending node information of the current message, and the next hop SF information is used to determine the next hop SF to which the current message is forwarded.

[0017] In an exemplary embodiment, based on the above scheme, the system further comprises: a control node configured to issue a SFC routing table item to the SFF, wherein the routing table item about the target service in the SFC routing table item is determined according to a service function path (SFP) of the target service, and the control node is a software defined network (SDN) controller; and the SFF is further configured to receive the SFC routing table item issued by the control node.

[0018] In an exemplary embodiment, based on the above scheme, the system further comprises: at least one SF, wherein one of the SFs corresponds to one tenant in an overlay.

[0019] In a third aspect, the present application provides a device for forwarding a message in a service function chain, configured in a service function forwarding node (SFF). The device for forwarding a message in a service function chain (SFC) comprises: a receiving module, a determining module and a sending module.

[0020] The receiving module is configured to receive a target packet, wherein the target packet carries a destination network address of a corresponding service and sending node information of the target packet; the determining module is configured to determine that the target packet hits an SFC routing table item according to the carrying information of the target packet, wherein the SFC routing table item records a first mapping relationship between first route matching information of a target service and next hop SF information, the first route matching information includes the destination network address of the target service and the sending node information of the current packet, and the next hop SF information is used to determine a next hop SF to which the current packet is forwarded; the determining module is further configured to determine a network address of a next hop service function node SF of the target packet based on the first mapping relationship recorded by the SFC routing table item; and the packet sending module is configured to send the target packet based on the network address of the next hop SF of the target packet.

[0021] In an exemplary embodiment, based on the above scheme, the receiving module is further configured to receive an SFC routing table item issued by a control node before receiving the target packet, wherein the routing table item about the target service in the SFC routing table item is determined according to a service function path SFP of the target service, and the control node is a software defined network SDN controller.

[0022] In an exemplary embodiment, based on the above scheme, the determining module is further configured to, after the receiving module receives the target packet, search the SFC routing table item according to the destination network address carried by the target packet, determine whether the sending node information carried by the target packet is included in the first route matching information about the target service of the SFC routing table item if it is determined that the destination network address carried by the target packet hits the destination network address about the target service in the SFC routing table item, and determine that the target packet hits the SFC routing table item if it is determined that the sending node information carried by the target packet is included in the first route matching information about the target service of the SFC routing table item.

[0023] In an exemplary embodiment, based on the above scheme, the network address determining module includes a first determining unit and a second determining unit; the first determining unit is configured to determine target SF information from the SFC routing table item according to the sending node information carried by the target packet and the first mapping relationship; and the second determining unit is configured to determine the network address of the next hop SF of the target packet according to the target SF information.

[0024] In an example embodiment, based on the above scheme, the next hop SF information in the SFC routing entry is an SF identifier having a second mapping relationship with a tenant identifier in the Overlay network; the second determining unit is specifically configured to: search an instance table according to the target SF information to obtain a target tenant identifier having a second mapping relationship with the target SF information, and obtain a network address of an SF having a third mapping relationship with the target tenant identifier, to obtain the network address of the next hop SF of the target packet; wherein the instance table records the second mapping relationship between the SF identifier and the tenant identifier, and records the third mapping relationship between the tenant identifier and the network address of the SF.

[0025] In an example embodiment, based on the above scheme, the sending module is specifically configured to: search an Overlay routing entry according to the network address of the next hop SF of the target packet and the target tenant identifier, to determine the encapsulation information required for forwarding the target packet to the next hop SF, wherein the Overlay routing entry records a fourth mapping relationship between second routing matching information and the encapsulation information, and the second routing matching information includes the network address of the next hop SF and the tenant identifier; perform tunnel encapsulation on the target packet according to the encapsulation information corresponding to forwarding the target packet to the next hop SF; and send the target packet after tunnel encapsulation according to the network address of the next hop SF of the target packet.

[0026] In an example embodiment, based on the above scheme, the service function chain SFC packet forwarding device further includes an encapsulation module; wherein the encapsulation module is configured to: if it is determined that the target packet does not hit the SFC routing entry according to the carrying information in the target packet, search the Overlay routing entry according to the destination network address carried by the target packet to determine the encapsulation information corresponding to forwarding to the destination network address; perform tunnel encapsulation on the target packet according to the encapsulation information corresponding to the destination network address; and send the target packet after tunnel encapsulation to the node corresponding to the destination network address.

[0027] In an example embodiment, based on the above scheme, the target SF information is the network address of the next hop SF of the target packet; and the sending module is further configured to: if it is determined that the target packet does not hit the SFC routing entry according to the carrying information in the target packet, send the target packet according to the destination network address carried by the target packet.

[0028] In a fourth aspect, an electronic device is provided, comprising a processor and a memory. The memory is configured to store a computer program, and the processor is configured to invoke and run the computer program stored in the memory to perform the method for forwarding a packet in a service function chain in the first aspect or any of the implementation manners thereof.

[0029] In a fifth aspect, a chip is provided for implementing the method in any of the first aspect or any of the implementation manners thereof. Specifically, the chip comprises a processor configured to invoke and run a computer program from a memory, so that a device installed with the chip performs the method for forwarding a packet in a service function chain in the first aspect or any of the implementation manners thereof.

[0030] In a sixth aspect, a computer readable storage medium is provided for storing a computer program, which causes a computer to perform the method for forwarding a packet in a service function chain in the first aspect or any of the implementation manners thereof.

[0031] In a seventh aspect, a computer program product is provided, comprising computer program instructions, which cause a computer to perform the method for forwarding a packet in a service function chain in the first aspect or any of the implementation manners thereof.

[0032] In an eighth aspect, a computer program is provided, which, when running on a computer, causes the computer to perform the method for forwarding a packet in a service function chain in the first aspect or any of the implementation manners thereof.

[0033] In summary, in the service function chain SFC message forwarding solution provided in the embodiments of the present application, a service function forwarding node (SFF) receives a target message, wherein the target message carries a destination network address of a corresponding service and information about a sending node of the target message. The SFF can determine whether the target message hits a SFC routing table item according to the carried information of the target message. The SFC routing table item records a first mapping relationship between first routing matching information and next-hop SF information, and the first routing matching information includes the destination network address of the target service and the sending node information of the current message. If the SFF determines that the target message hits the SFC routing table item, since the next-hop SF information in the SFC routing table item is used to determine the next-hop SF to which the current message is forwarded, the network address of the next-hop service function node (SF) of the target message can be determined based on the first mapping relationship recorded in the SFC routing table item. Thus, the SFF sends the target message based on the network address of the next-hop SF of the target message, and the forwarding of the target message is implemented. The SFC message forwarding solution provided in the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), and thus does not need to generate additional message encapsulation overhead. For example, after NSH encapsulation in the related art, the size of a data packet can exceed the maximum transmission unit (MTU) value of a link, and this problem can be avoided through the embodiments of the present application. Meanwhile, the existing network architecture service line extension supports an additional encapsulation protocol, such as the NSN protocol in the related art, which reduces the direct dependence of network infrastructure on a specific protocol, and is beneficial to improving the maintainability of the system and reducing the implementation cost. BRIEF DESCRIPTION OF DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.

[0035] FIG. 1 is a structural schematic diagram of a system architecture of a service function chain;

[0036] FIG. 2 is a flow schematic diagram of a service function chain SFC message forwarding method provided in an embodiment of the present application;

[0037] FIG. 3 is a flow schematic diagram of a SFC message forwarding method in an Overlay network provided in an embodiment of the present application;

[0038] FIG. 4 is a structural diagram of a service function chain SFC according to an embodiment of the present application;

[0039] FIG. 5 is an information interaction diagram of a packet forwarding process based on the service function chain SFC shown in FIG. 4;

[0040] FIG. 6 is a structural diagram of a packet forwarding system in the service function chain SFC according to an embodiment of the present application;

[0041] FIG. 7 is a structural diagram of a packet forwarding apparatus in the service function chain SFC according to an embodiment of the present application;

[0042] FIG. 8 is a structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0043] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0044] It should be noted that the terms "first", "second", and the like in the description, claims, and the above drawings of the present application are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in other than the order illustrated or described herein. In the embodiments of the present application, "B corresponding to A" means that B is associated with A. In one implementation, B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server including a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product, or device. In the description of the present application, "a plurality of" means two or more, unless otherwise specified.

[0045] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an integral module or unit that includes the functions of the module or unit

[0046] The value-added service devices (such as firewalls, load balancers, intrusion prevention devices, etc.) in the traditional network are tightly coupled with the network topology and hardware, and they are all dedicated devices and the deployment is complex. When the network is expanded or changed, the network topology needs to be re-planned, which increases the cost of network deployment and maintenance. With the development of network function virtualization (NFV) technology, the network function is decoupled from the hardware, and the forwarding and control are separated, which makes the network control of the data center more flexible and flexible. In the NFV virtualized network, SFC (also known as function chain, service chain, service function chain, etc.) plays a crucial role in realizing the traffic according to the specified order to complete the network service. When the service needs to be adjusted, only the order of the service chain needs to be updated without changing the network configuration, and the agile opening of the network service can be realized.

[0047] FIG. 1 is a schematic diagram of a system architecture 100 of a service function chain SFC. Referring to FIG. 1, the system architecture 100 of the SFC includes a service classification node (SC) (also known as a service classifier), SFFs (such as SFF 1 and SFF 2 in FIG. 1), and SFs (such as SF 1, SF 2, and SF 3 in FIG. 1).

[0048] Among them, the related terms of SFC also include: SFC domain, which is an area containing SFC devices. The related terms of SFC also include: service chain path (SFP), which is a packet path calculated according to service configuration, which defines the specific path of the data packet on this link, including which SFF and the SF connected by the SFF; the SFP not only plans the complete path of the packet from the entrance to the exit, but also accurately locates each SF, ensuring that the packet can be correctly classified, forwarded, and finally delivered to the target according to the requirements of the service chain.

[0049] The service classification node SC is located at the boundary entrance of the SFC domain, inspects the traffic entering the SFC domain, and classifies the traffic (e.g., identifies the application traffic belonging to financial transactions) by checking the metadata of the data packet (e.g., source IP, destination IP, port number, protocol type, etc.). Further, the SC adds a service chain identifier (e.g., using Network Service Header, NSH) on the data packet to specify that the data packet needs to follow a specific SFP.

[0050] The service function forwarding node SFF is a key component in the SFC architecture, responsible for forwarding data packets from one service function node to one or several SFs associated with the SFF according to the requirements of network services, until the entire service chain processing is completed. In simple terms, the SFF is like a bridge connecting various SFs, ensuring that data packets pass through a series of service functions in a predefined order. The SFF can usually be shared with the SC.

[0051] The service function node SF refers to an entity in the network that performs specific services or functions, such as firewalls, load balancers, intrusion detection systems (IDS), wide-area network optimization devices, content filters, etc. Each SF represents a service or function in the network, and they work together to process data flows passing through the network to meet specific security, optimization, inspection, or other business requirements. Among them, the SF providing firewall function can be used to perform deep packet inspection to filter out malicious traffic, such as ensuring that only legitimate financial transaction data packets continue to advance. The SF2 providing encryption service can be used to encrypt sensitive financial information to protect the security and privacy of data during transmission. The SF providing load balancer function intelligently distributes data packets according to the current load of each server, such as ensuring the efficient and stable operation of the financial transaction processing system. The SF providing application delivery controller is used to optimize data packets, such as compression or caching, to improve the response speed of financial applications and user experience. Among them, the node providing specific network services usually runs on a virtual machine or container.

[0052] In the related art, in order to realize the SFC function, the packet is usually encapsulated by NSH, so that each node on the service chain path can pass information to each other. Thus, based on the information passed by each other, the entire data chain can dynamically and flexibly process data. The data packet header of the NSH protocol includes a 64-bit "service path identifier (SPI)" and a 24-bit "service index (SI)". The SPI identifies a unique path of a service link, and the SI identifies each service in the service link. Using the NSH protocol, a network administrator can create a service link and direct data packets to a specific service on the service link. For example, the NSH-based SFC process provided by the related art can include the following steps:

[0053] Step S1, after the traffic reaches the service classification node SC, the SC first classifies according to the packet header, and redirects the classified traffic to the SFC service chain, encapsulates the NSH according to the SPI and SI information obtained by querying, and sends to the SFF;

[0054] Step S2, after the SFF receives the NSH encapsulated packet, the SPI and SI information in the NSH packet header are queried to obtain the next hop SF address, and the NSH is re-encapsulated and sent if the SI is not the last hop SI value, and if the SI is the last hop, the packet is normally encapsulated and the forwarding of the packet in the SFC domain is ended;

[0055] Step S3, after the SF in the SFC domain receives the above-mentioned packet, the NSH encapsulation is removed, the obtained SI value is reduced by 1, and the original data in the encapsulation is processed. After processing, the NSH is re-encapsulated and sent to the SFF, and step S2 is repeated.

[0056] In the related art, according to whether the SF can perceive the NSH encapsulation, the SF is divided into NSH-aware SF and NSH-unaware SF. In the related art, for the NSH-unaware SF, the SFC proxy (Service Proxy) receives the packet from the SFF on behalf of the SF, deletes the NSH encapsulation information, and sends the packet to the SF. At the same time, the packet sent back from the NSH-unaware SF is received, the NSH encapsulation information is added again, and the SFF is sent.

[0057] However, the NSH-based SFC solution provided by the related art has the following technical problems. For example, the NSH needs to be additionally encapsulated, thereby causing additional message encapsulation overhead; for example, after the NSH is encapsulated in the message forwarding process, the packet size may exceed the link MTU value, and the MTU value between links needs to be adjusted or the MTU supported by the link needs to be determined according to the path MTU discovery (PMTUD); for another example, the current multi-tenant network architecture based on software design network (SDN) (including a control plane and a data plane) needs to be extended to support the NSH protocol, and the original SF also needs to be extended to support the NSH protocol, thereby increasing the maintainability difficulty of the system and increasing the implementation cost.

[0058] The message forwarding solution in the service function chain SFC provided by the embodiments of the present application can solve the technical problems in the related art. Specifically, a service function forwarding node SFF receives a target message, wherein the target message carries a destination network address of a corresponding service and sending node information of the target message. The SFF can determine whether the target message hits a SFC routing table item according to the carrying information of the target message. The SFC routing table item includes at least one routing table item about a service, and the routing table item about the target service records a first mapping relationship between routing matching information of the target service and next hop SF information. The routing matching information includes the destination network address of the target service and the sending node information of the current message. If the SFF determines that the target message hits the SFC routing table item, since the next hop SF information in the SFC routing table item is used to determine the next hop SF to which the current message is forwarded, the network address of the next hop SF of the target message can be determined based on the first mapping relationship recorded in the SFC routing table item. Therefore, the SFF sends the target message based on the network address of the next hop SF of the target message, thereby realizing the forwarding of the target message. The message forwarding solution in the SFC provided by the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), thereby not causing additional message encapsulation overhead. At the same time, the existing network architecture service line is extended to support the additional encapsulation protocol, such as the NSN protocol in the related art, thereby reducing the direct dependence of the network infrastructure on a specific protocol, which is conducive to improving the maintainability of the system and reducing the implementation cost.

[0059] The technical solutions of the embodiments of the present application will be described in detail in some embodiments. The following embodiments can be combined with each other, and the same or similar concepts or processes can not be described in detail in some embodiments.

[0060] FIG. 2 is a flow diagram of a method P200 for forwarding a packet in a service function chain (SFC) according to an embodiment of the present disclosure. The method P200 can be performed by a service function forwarder (SFF), such as the SFF 1 or the SFF 2 in FIG. 1, or an electronic device as shown in FIG. 8. The method P200 includes steps S210 to S230.

[0061] In step S210, the SFF receives a target packet. The target packet carries a destination network address of a target service and a sending node information of the target packet.

[0062] To implement a specific service flow, relevant data needs to be transmitted through a series of nodes. In an exemplary embodiment, the last node in a data flow path can be regarded as a destination node or an end node. The above-mentioned target network address is a network address of an end of a service flow, i.e., a network address of a destination node. In an exemplary embodiment, the sending node of the target packet refers to a node that sends the target packet to the SFF.

[0063] For example, a packet delivery path of a service A is assumed to be a virtual machine A, an SFF, an SFA, an SFF, and a virtual machine 2. The SFF receives a packet 1 from the virtual machine 1, and the sending node of the packet 1 is the virtual machine A. The SFF receives a packet 2 from the SFA, and the sending node of the packet 2 is the SFA. Since the packet 1 and the packet 2 both belong to data of the service A, the destination network address in the packet 1 and the packet 2 is the network address of the virtual machine A. If the network address of the virtual machine A is bbb.16.0.0, the packet 1 carries information of bbb.16.0.0, which is information of the virtual machine 1. The packet 2 carries information of bbb.16.0.0, which is information of the SFA.

[0064] In step S220, the SFF determines, according to the carrying information of the target packet, that the target packet hits an SFC routing table item. The SFC routing table item records a first mapping relationship between first routing matching information of a target service and next-hop SF information. The first routing matching information includes a destination network address of the target service and sending node information of a current packet. The next-hop SF information is used to determine a next-hop SF to which the current packet is forwarded.

[0065] As Overlay networks can more flexibly manage resources while maintaining network isolation between tenants, this is particularly useful for cloud service providers in a multi-tenant environment. Overlay networks allow each tenant to have an independent address space by establishing a virtual logical network layer on top of the underlying physical network (Underlay network), even if these address spaces overlap with each other without causing conflicts. This is because Overlay networks use tunneling technology to encapsulate the network packets of tenants, adding additional header information containing tenant-specific identifiers, so that multiple tenants' network traffic can be transmitted on shared physical network infrastructure without confusion. In order to ensure that the data packet is correctly routed to the target tenant's network in the Underlay network, the Overlay network adds the tenant identifier (i.e. Tenant ID) when encapsulating. For example, the forwarding scheme of the message in the SFC provided by the embodiments of the present application can be applied to the overlay network, and in order for the data to be correctly routed, the sending node information of the message can be represented by the tenant identifier (i.e. Tenant ID).

[0066] For example, in the case where the forwarding scheme of the message in the SFC provided by the embodiments of the present application is applied to the overlay network, the SFC routing table entry is shown in Table 1. Wherein the destination network address "Dst" corresponding to different services is different, and the routing table entries about service 1 and service 2 are shown in Table 1.

[0067] Table 1

[0068] Referring to Table 1, the SFC routing table entry can include routing table entries about multiple services, and the routing table entry about the target service records the first mapping relationship between the routing matching information of the target service and the next hop SF information, and the routing matching information includes the destination network address of the target service and the sending node information of the current message. Since the end node of the service can be more than one, the network address of the terminal node can be different, and therefore the destination network address of the target service recorded in the SFC routing table entry can be the network segment of the service destination node.

[0069] In step S230, the SFF determines the network address of the next hop SF of the target message based on the first mapping relationship recorded in the SFC routing table entry.

[0070] If the information carried by the packet x1 includes the destination network address Dst = bbb.16.0.0 of the corresponding service and the sending node information "Tenant ID = 100" sending the packet x1 to the SFF, it can be determined that the packet x1 hits the first row in the SFC routing table shown in Table 1, i.e., the routing table item about service 1. Then, based on the mapping relationship shown in the SFC routing table item, it can be determined that the next hop (NextHop) SF information of the packet x1 is "SF ID = 1".

[0071] In the case where the embodiments of the present application are applied to an Overlay network, the network addresses of different tenants can overlap with each other, and if the network address of the SF is directly used as the next hop SF information in the SFC routing table item, it can cause routing errors. Therefore, as shown in Table 1, the next hop SF information in the SFC is the SF identifier which has a second mapping relationship with the identifier of the next hop tenant network in the overlay network. Specifically, in this case, the embodiments of the present application further set an instance table, which records the second mapping relationship between the SF identifier and the tenant identifier, and also records the third mapping relationship between the tenant identifier and the network address of the SF, as shown in Table 2.

[0072] Table 2

[0073] Referring to Table 2, the mapping relationship between the SF ID and the Tenant ID is recorded in the instance table, and the mapping relationship between the Tenant ID and the VNF Access IP is also recorded. For example, according to the above embodiment, it can be determined that the packet x1 hits the first row in the SFC routing table shown in Table 1, and then based on the SFC routing table item, it can be determined that the next hop SF information of the packet x1 is NextHop SF ID = 1. Further, according to the determined next hop SF information (SF ID = 1), Table 2 is searched, and it can be determined that the tenant identifier having a mapping relationship with SF ID = 1 is Tenant ID = 2, and the VNF Access IP = aaa.168.0.5. Wherein, the VNF Access IP = aaa.168.0.5 is the network address of the next hop SF of the packet x1. Wherein, the virtualization network function (Virtualization Network Functions, VNF) is a software-based application that provides one or more network services. The VNF connects to the network using the virtualization infrastructure provided by the network function virtualization (NFV) architecture and provides programmable and scalable network services. And the NFV draws on the architecture of x86 servers to encapsulate routers, switches, firewalls, load balancing and other different network functions into independent modular software, and realizes diversified network functions on a single hardware device by running different modular software on the hardware device.

[0074] In the case where the SFC message forwarding scheme provided by the embodiments of the present application is applied to an Overlay network, the sending node information of the current message in the SFC routing entry is specifically the identifier of the tenant network sending the current message, and the next-hop SF information is specifically the SF identifier having a second mapping relationship with the identifier of the next-hop tenant network in the Overlay network. Specifically, in combination with the SFC routing table shown in Table 1 and the example table shown in Table 2, the network address of the next-hop SF can be accurately determined, the forwarding of the message in the SFC under the Overlay network is implemented, and no additional encapsulation step (such as NSH encapsulation) is introduced. In another exemplary embodiment, the SFC routing entry is shown in Table 3.

[0075] Table 3

[0076] Referring to Table 3, in the SFC message forwarding scheme provided by the embodiments of the present application, in the case where the SFC message forwarding scheme is not applied to an Overlay network, since there is no phenomenon of overlapping of different SF network addresses, the first routing matching information includes the network segment to which the network address of the service end node (destination network address) belongs and the network address of the message sending node, and the next-hop SF information is directly represented as the network address of the next-hop SF. The network address of the sending node of the exemplary message y1 is cc.0.0.5, and the destination network address of the service corresponding thereto is bbb.16.0.0, so it can be determined that the message y1 hits the first row in the SFC routing entry shown in Table 3, that is, the routing entry about service 3. Further, it can be determined that the network address of the next-hop SF of the message y1 is aaa.168.0.5.

[0077] In the embodiments, the sending node information of the current message in the SFC routing entry is specifically the identifier of the tenant network sending the current message, and the next-hop SF information is specifically the SF identifier having a second mapping relationship with the identifier of the next-hop tenant network in the Overlay network. It can be seen that, by adaptively adjusting the sending node information of the current message and the next-hop SF information in the SFC table, the embodiments of the present application can be applied to an Overlay network or other networks, and have high flexibility.

[0078] In step S240, the target message is sent based on the network address of the next-hop SF of the target message.

[0079] In the exemplary embodiments, in the case that the SFC packet forwarding scheme provided by the embodiments of the present application is not applied to the Overlay network, the target packet can be directly sent according to the network address of the next hop SF. For example, the packet delivery path of service A is assumed to be virtual machine A, SFF, SFA, SFF and virtual machine 2, wherein the SFF receives the packet 1 from the virtual machine 1, determines the network address of the next hop SF (i.e. SFA) to be cc.0.0.4 according to the information carried by the packet 1 and the SFC routing table item, and then the packet 1 can be forwarded to SFA based on the network address.

[0080] FIG. 3 is a flow diagram of a packet forwarding method in a service function chain (SFC) in an Overlay network according to an embodiment of the present application. It can be used as an implementation of step S240. Specifically, in the case that the SFC packet forwarding scheme provided by the embodiments of the present application is applied to the Overlay network, the target packet needs to be tunnel encapsulated and then forwarded.

[0081] Specifically, in step S240-1, the SFF looks up an Overlay routing table item according to the network address of the next hop SF of the target packet and the target tenant identifier, to determine the encapsulation information required for forwarding the target packet to the next hop SF.

[0082] The Overlay routing table item records a fourth mapping relationship between second route matching information and encapsulation information, and the second route matching information includes the network address of the next hop SF and the tenant identifier, which is exemplarily shown in Table 4.

[0083] Table 4

[0084] In step S240-2, the SFF tunnel encapsulates the target packet according to the encapsulation information corresponding to the target packet for forwarding to the next hop SF. In step S240-3, the tunnel encapsulated target packet is sent according to the network address of the next hop SF of the target packet.

[0085] Referring to Table 4, in the Overlay network, the Encapsulation with Tenant ID 100 means that the packet will be added with a specific encapsulation when it is transmitted through the Overlay network, and the encapsulation contains the information of the Tenant ID (tenant identification) being 100. Thus, the packet is routed to the network segment or resource of the tenant definitely, ensuring data isolation and security, and facilitating management and measurement. Specifically, the original packet is embedded in a new packet header containing encapsulation information (Tenant ID), which can be implemented by using technologies such as Virtual eXtensible Local Area Network (VXLAN), Generic Routing Encapsulation (GRE) or other Overlay technologies. Through the tunnel encapsulation manner, multiple independent logical networks can be created on a shared physical infrastructure, and each logical network serves a specific tenant or application. Finally, the target packet after tunnel encapsulation is sent to the network address of the next hop SF determined by the above embodiment.

[0086] In an exemplary embodiment, the method P200 further includes an implementation in which the SFF determines that the target packet does not hit the SFC routing table item.

[0087] Exemplarily, in the case where the packet forwarding scheme in the SFC is applied to the Overlay network, if the SFF determines that the target packet does not hit the SFC routing table item, the Overlay routing table item is searched according to the destination network address carried by the target packet, to determine the encapsulation information corresponding to the destination network address; further, the target packet is tunnel encapsulated according to the encapsulation information corresponding to the destination network address; finally, the target packet after tunnel encapsulation is sent to the node corresponding to the destination network address.

[0088] Exemplarily, in the case where the packet forwarding scheme in the SFC is not applied to the Overlay network, since tunnel encapsulation is not required, in the case where the SFF determines that the target packet does not hit the SFC routing table item, the target packet is directly sent according to the destination network address carried by the target packet.

[0089] In the method P200, the SFF receives a target packet, where the target packet carries a destination network address of a corresponding service and information about a sending node of the target packet. The SFF can determine whether the target packet hits a SFC routing table item according to the information carried by the target packet. The SFC routing table item records a first mapping relationship between first routing matching information of the target service and next-hop SF information, where the first routing matching information includes the destination network address of the target service and the sending node information of the current packet, and the next-hop SF information is used to determine a next-hop SF to which the current packet is forwarded. If the SFF determines that the target packet hits the SFC routing table item, the SFF determines a network address of the next-hop SF of the target packet based on the first mapping relationship recorded by the SFC routing table item. Then, the SFF sends the target packet based on the network address of the next-hop SF of the target packet, thereby implementing the forwarding of the target packet. The method for forwarding a packet in a service function chain provided in the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), thereby not needing to generate an additional packet encapsulation overhead. Meanwhile, the existing network architecture service line extension supports an additional encapsulation protocol, such as the NSN protocol in the related art, which reduces the direct dependence of the network infrastructure on a specific protocol, and is beneficial to improving the maintainability of the system and reducing the implementation cost.

[0090] The above describes the method for forwarding a packet in a service function chain provided in the embodiments of the present application. The following describes the method for forwarding a packet in a service function chain provided in the embodiments of the present application with reference to FIG. 4 and FIG. 5.

[0091] FIG. 4 is a structural schematic diagram of a service function chain 400 provided in an embodiment of the present application. As shown in FIG. 4, a target service is communication between a virtual machine 1 and a virtual machine 2, and needs to sequentially pass through two SFs: SF 44 is a virtual firewall (VFW) and belongs to a tenant network with an ID of 300 (that is, Tenant ID: 300), and an access IP is cc.0.0.5; and SF 46 is a virtual intrusion prevention system (vIPS) and belongs to a tenant network with an ID of 400 (that is, Tenant ID: 400), and an access IP is cc.0.1.5.

[0092] FIG. 5 is an information interaction schematic diagram of a packet forwarding process P500 based on the service function chain 400 shown in FIG. 4. As shown in FIG. 5, the packet forwarding process P500 includes steps S50-S511.

[0093] In step S50, the control node 40 issues the SFC routing table item. In step S51, the SFF 42 receives the SFC routing table item issued by the control node.

[0094] The SFC service is deployed in a software defined network (SDN). The SDN includes a controller (SDN controller) and an SDN routing switching device (such as an SDN ROUTER component). It should be noted that in the embodiments of the present application, the above-mentioned SDN controller is taken as the control node 40 of the SFC, and the SDN routing switching device is issued with the SFC routing table item. Further, the SDN routing switching device performs relevant steps as the role of the SFF 42.

[0095] The SDN controller, as a centralized brain, is responsible for decision making, i.e., determining the transmission path of the data packet in the network (such as determining the SFP about the target service) and how to process the data packet (such as generating the corresponding SFC routing table item based on the SFP about the target service). The SDN controller decouples the control plane (the part responsible for making decisions) and the data plane (the part responsible for actual data forwarding) of the network, making the management of the network more flexible and intelligent. For example, the SDN routing switching device is a network device designed to support the SDN architecture. Since in the SDN architecture, the control plane and the data plane of the routing and switching device are separated, the SDN routing switching device no longer needs to maintain a complex routing table, but is uniformly managed and issued with routing rules by the centralized SDN controller (such as receiving the SFC routing table item issued by the SDN controller in the embodiments of the present application).

[0096] For example, the routing table item about the target service in the SFC routing table item is determined based on the SFP of the target service. Referring to FIG. 4, assuming that the packet path calculated by the configuration of the target service is: virtual machine 1→SFF 42→SF 44→SFF 42→SF 46→SFF 42→virtual machine 2, the SPF represents all SFs and their order that the data packet in the target service needs to pass through. Further, the routing table item about the target service in the SFC routing table item can be generated according to the SPF, as shown in Table 5.

[0097] Table 5

[0098] Referring to Table 5, the destination network address of the target service is "Dst: bbb.16.0.5", i.e., the virtual machine 2. The first row in Table 5 indicates that the sending node of the current packet received by the SFF 42 is the virtual machine 1 (Tenant ID: 100), in which case the next hop of the SFF 42 forwarding the packet is the SF with the SF ID equal to 1, which can be determined as Tenant ID = 300 (i.e., the SF 44) according to Table 6; it can be seen that it is consistent with the packet path "virtual machine 1 → SFF 42 → SF 44". The second row in Table 5 indicates that the sending node of the current packet received by the SFF 42 is the SF 44 (Tenant ID: 300), in which case the next hop of the SFF 42 forwarding the packet is the SF with the SF ID equal to 2, which can be determined as Tenant ID = 400 (i.e., the SF 46) according to Table 6; it can be seen that it is consistent with the packet path "SF 44 → SFF 42 → SF 46". Similarly, the third row in Table 5 indicates that the sending node of the current packet received by the SFF 42 is the SF 46 (Tenant ID: 400), in which case the next hop of the SFF 42 forwarding the packet is the SF with the SF ID equal to 3, which can be determined as Tenant ID = 200 (i.e., the virtual machine 2) according to Table 6; it can be seen that it is consistent with the packet path "SF 46 → SFF 42 → virtual machine 2".

[0099] In the case where the embodiments of the present application are applicable to the Overlay network, as described above, since the network addresses of different tenants can overlap with each other, directly taking the network address of the SF as the next hop SF information in the SFC routing table item can cause routing errors, therefore, the next hop SF information (SF ID) in the SFC shown in Table 5 is the SF identifier which has the second mapping relationship with the identifier (Tenant ID) of the next hop tenant network in the Overlay network. Specifically, in this case, the embodiments of the present application further set an instance table, which records the second mapping relationship between the SF identifier and the tenant identifier and records the third mapping relationship between the tenant identifier and the network address of the SF, as shown in Table 6.

[0100] Table 6

[0101] In the embodiments of the present application, by using the example table shown in Table 6 in cooperation with the SFC routing table item shown in Table 5, the network address of the next hop SF can be determined, and the packet forwarding without additional encapsulation in the SFC can be realized. The SFC routing table item shown in Table 5 is generated by the control node 40 and delivered to the SFF, that is, delivered to the SDN routing switching device acting as the SFF role by the SDN controller; the example table shown in Table 6 can be generated by the control node 40 and further delivered to the SFF, or generated by the SFF, which is not limited in the embodiments of the present application.

[0102] For example, the SDN routing switching device can communicate with the SDN controller through the OpenFlow protocol. OpenFlow is an open protocol that can define how the SDN controller delivers forwarding rules to network devices (such as switches and routers) and collects network state information. Through OpenFlow, the SDN controller can directly insert or modify forwarding rules in the flow table of the data plane device to achieve flexible control of network traffic.

[0103] Referring to FIG. 5, in step S52, the virtual machine 1 sends a packet about the target service to the SFF 42. In step S53, the SFF 42 finds the SFC routing table item according to the destination network address carried by the received packet, and determines that the destination network address carried by the packet is the destination network address of the target service in the SFC routing table item.

[0104] In the exemplary embodiments, the packet sent by the virtual machine 1 to the SFF 42 carries the Tenant ID 100 of itself, the destination (virtual machine 2) network address bbb.16.0.5, and the network address aaa.168.0.5 of the sending node. For example, the above-mentioned carried information can be added to the original packet in the form of a packet header, so that the tenant isolation can be maintained when the packet traverses the network, and can be used to determine whether the SFC routing table item is hit or which specific SFC routing table item is hit, thereby guiding the correct forwarding of the packet.

[0105] For example, the SFC routing table item delivered by the SDN controller can contain only the routing information of one service, or can contain the routing information of multiple services in the same SFC table item, such as the SFC routing table item shown in Table 1, which contains the routing information of the service with the destination network address bbb.16.0.0 / 16, and also contains the routing information of another service with the destination network address aaa.168.0.0 / 16.

[0106] The following provides an implementation of the SFF 42 judging whether the current packet hits the SFC routing table item.

[0107] Exemplarily, the SFF 42 looks up the SFC routing table according to the destination network address carried by the current packet. As described above, the destination network address carried by the current packet is bbb.16.0.5, which is the same as the destination network address segment of the target service in the SFC routing table item as shown in Table 5, and it can be determined that the destination network address carried by the current packet hits the destination network address of the target service in the SFC routing table item.

[0108] In step S54, if the SFF 42 determines that the destination network address carried by the current packet hits the destination network address of the target service in the SFC routing table item, it is further determined whether the sending node information carried by the current packet is contained in the first route matching information of the target service in the SFC routing table item. If it is determined through step S54 that the destination network address carried by the current packet hits the destination network address of the target service in the SFC routing table item, and the sending node information carried by the current packet is contained in the first route matching information of the target service in the SFC routing table item, then steps S55-S58 are executed next. If it is determined through step S54 that the sending node information carried by the current packet is not contained in the first route matching information of the target service in the SFC routing table item, then steps S59-S511 are executed next.

[0109] In step S55, if the SFF 42 determines that the sending node information carried by the current packet is contained in the first route matching information of the target service in the SFC routing table item, it is determined that the current packet hits the routing table item of the target service in the SFC routing table item. Exemplarily, the sending node information carried by the current packet includes the tenant identification Tenant ID 100, and the first row of route matching information in the SFC routing table item as shown in Table 5 contains the destination network address bbb.16.0.5 and the tenant identification Tenant ID 100. It can be seen that the current packet hits the first row of route matching information in the SFC routing table item as shown in Table 5.

[0110] In step S56, the SFF 42 determines the target SF information from the routing table item of the target service in the SFC routing table item according to the sending node information and the first mapping relationship. Exemplarily, the SFF 42 determines that the target SF information is SF ID=1 from the SFC routing table item information as shown in Table 5 according to the sending node information Tenant ID 100 and the first mapping relationship.

[0111] In step S57, the SFF 42 determines the network address of the next-hop SF of the packet according to the target SF information. For example, the SFF 42 looks up the example table shown in Table 6 according to the target SF information SF ID = 1, and determines that the network address of the next-hop SF of the packet is cc.0.0.5 and the tenant identification Tenant ID 300 of the next-hop.

[0112] In step S58, the SFF 42 sends the packet to the next-hop SF based on the network address of the next-hop SF of the packet. For example, the target service is a service in the Overlay network, and therefore the packet needs to be tunnel-encapsulated before being sent to the next-hop. Specifically, the Overlay routing table item (shown in Table 7) is looked up according to the network address (cc.0.0.5) and the tenant identification (Tenant ID 300) of the next-hop SF, and the packet is tunnel-encapsulated according to the encapsulation information obtained from the lookup and sent to the next-hop SF 44.

[0113] Table 7

[0114] Through the above embodiment, the packet is delivered to the SF 44. Next, the SF 44 and the SFC 42 perform information interaction to perform the packet processing procedure as in steps S52 to S55. For example, the SF 44 sends a packet about the target service to the SFF 42, and the packet header carries the destination network address (bbb.16.0.5) of the target service and the tenant identification (Tenant ID: 300) of the SF 44. The SFF 42 looks up the SFC routing table item as in Table 6 according to the destination network address (bbb.16.0.5) carried in the packet from the SF 44, and determines that the destination network address carried in the packet is the destination network address of the target service in the SFC routing table item. Further, the SFF 42 judges that the sending node information (Tenant ID 300) carried in the current packet is contained in the routing matching information about the target service in the SFC routing table item, so that the SFF 42 determines that the packet from the SF 44 hits the routing table item about the target service in the SFC routing table item. Next, the SFC 42 performs the packet processing procedure as in steps S56 to S58: the SFF 42 determines that the target SF information is SF ID = 2 from the routing table item information about the target service according to the sending node information Tenant ID 300 and the first mapping relationship. The SFF 42 looks up the example table shown in Table 6 according to the target SF information (SF ID = 2), and determines that the network address of the next-hop SF of the packet is cc.0.1.5. The SFF 42 sends the packet to the next-hop SF (SF 46) based on the network address of the next-hop SF of the packet.

[0115] After the packet is transmitted to the SF 46, the SF 46 and the SFC 42 interact information to perform the packet processing procedure as steps S52 to S55. For example, the SF 46 sends the packet about the target service to the SFF 42, and the packet header carries the destination network address (bbb.16.0.5) of the target service and the tenant ID (Tenant ID: 400) of the SF 46. The SFF 42 looks up the SFC routing table item as Table 6 according to the destination network address (bbb.16.0.5) carried by the packet from the SF 46, and determines that the destination network address carried by the packet is the destination network address of the target service in the SFC routing table item. However, the SFF 42 further judges that the sending node information (Tenant ID 400) carried by the current packet is not included in the routing matching information about the target service in the SFC routing table item, so that the SFF 42 determines that the packet from the SF 46 does not hit the SFC routing table item, which indicates that the entire service chain about the target service has been traversed. Next, the SFC 42 performs the packet processing procedure as steps S59 to S511: in step S59, the SFF 42 looks up the Overlay routing table item (such as Table 7) according to the destination network address (bbb.16.0.5) carried by the packet to determine the encapsulation information (Encapsulation with Tenant ID 200) corresponding to the destination network address. In step S510, the current packet is tunnel encapsulated according to the encapsulation information corresponding to the destination network address. In step S511, the target packet after tunnel encapsulation is sent to the node (i.e. the virtual machine 2) corresponding to the destination network address, so as to complete the entire SFC packet forwarding process.

[0116] As can be seen from the above embodiments, the priority of looking up the SFC routing table item in the SFF is higher than that of the Overlay routing table item, that is, the SFF first looks up the SFC routing table item to determine whether the SFC routing table item is hit in the packet, and further looks up the Overlay routing table item to tunnel encapsulate the packet. Specifically, when the packet arrives at the SFF, the SFF first looks up the SFC routing table item, if the information carried by the packet hits the SFC routing table item, the network address of the next hop (NextHop) is determined according to the SFC routing table item, and further the Overlay routing table item is looked up for corresponding encapsulation and sent to the next hop node; if the information carried by the packet does not hit the SFC routing table item, the Overlay routing table item is queried for corresponding encapsulation and sent to the next hop node.

[0117] Based on the above embodiments, it can be seen that the embodiments of the present application provide a solution for quickly supporting SFC function under the premise of keeping the existing multi-tenant network architecture (control plane and data plane) unchanged. Specifically, in the Overlay-based multi-tenant network, the current multi-tenant network forwarding plane technology is reused, without introducing additional encapsulation steps (such as NSH encapsulation), the data plane of the virtualized network is programmed by SDN to implement given SFC logic deployment and routing implementation, and the data frame of specific traffic can pass through each network function node in the SFC hop by hop according to the given SFC order and be processed by each network function node, thereby meeting the business requirements for security, performance, and the like.

[0118] Meanwhile, the forwarding solution for messages in the SFC provided by the embodiments of the present application does not need to introduce additional encapsulation steps (such as NSH encapsulation), thereby not needing to generate additional message encapsulation overhead. The existing network architecture business line extension supports additional encapsulation protocols, such as the NSN protocol extended in the related art, which reduces the direct dependence of the network infrastructure on specific protocols, and is conducive to improving the maintainability of the system and reducing the implementation cost.

[0119] The above describes in detail the method embodiment of the present application for forwarding messages in the service function chain SFC with reference to FIGS. 1 to 5, and the following describes in detail the system embodiment 600 of the present application for forwarding messages in the service function chain SFC with reference to FIG. 6.

[0120] FIG. 6 is a structural schematic diagram of the system 600 for forwarding messages in the service function chain SFC according to an embodiment of the present application. Referring to FIG. 6, the system 600 for forwarding messages in the service function chain SFC includes a service function forwarding node SFF 620, such as the SFF 42 in FIGS. 4 and 5.

[0121] The SFF 620 is configured to receive a target message, where the target message carries a destination network address of a corresponding service and sending node information of the target message; the SFF 620 is configured to determine that the target message hits an SFC routing table item according to the carrying information of the target message; the SFF 620 is configured to determine a network address of a next hop service function node SF of the target message based on a first mapping relationship recorded by the SFC routing table item; and the SFF 620 is configured to send the target message based on the network address of the next hop SF of the target message. The SFC routing table item records a first mapping relationship between first routing matching information of a target service and next hop SF information, the first routing matching information includes the destination network address of the target service and the sending node information of the current message, and the next hop SF information is used to determine the next hop SF to which the current message is forwarded.

[0122] In an example embodiment, referring to FIG. 6, the system 600 for forwarding a packet in an SFC further includes a control node 610 configured to issue an SFC routing table item to the SFF 620, wherein the routing table item for a target service in the SFC routing table item is determined according to a service function path (SFP) of the target service, and the control node is a software defined network (SDN) controller, and the SFF 620 is an SDN routing switching device; and the SFF 620 is further configured to receive the SFC routing table item issued by the control node.

[0123] In an example embodiment, referring to FIG. 6, the system 600 for forwarding a packet in an SFC further includes at least one SF, such as SF 630 and SF 632 in FIG. 6. The method for forwarding a packet in an SFC provided by the embodiments of the present application can be applied to an Overlay network, and one SF corresponds to one tenant in the Overlay. The embodiments of the present application provide a solution for quickly supporting SFC functions without changing the existing multi-tenant network architecture (control plane and data plane). Specifically, in a multi-tenant network based on Overlay, the current multi-tenant network forwarding plane technology is reused, and no additional encapsulation step (such as NSH encapsulation) is introduced. The data plane of the virtualized network is programmed by SDN to implement given SFC logic deployment and routing implementation, and the data frame of specific traffic can pass through each network function node in the SFC hop by hop according to the given SFC order and be processed by each network function node, thereby meeting the service requirements for security, performance, and the like.

[0124] In the system 600 for forwarding a packet in an SFC provided by FIG. 6, the SFF 620 receives a target packet, wherein the target packet carries a destination network address of a corresponding service and information about a sending node of the target packet. The SFF can determine whether the target packet hits an SFC routing table item according to the carried information of the target packet. If the SFF determines that the target packet hits the SFC routing table item, the network address of a next-hop SF of the target packet is determined based on a first mapping relationship recorded in the SFC routing table item. The SFF sends the target packet based on the network address of the next-hop SF of the target packet, thereby forwarding the target packet. The solution for forwarding a packet in an SFC provided by the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), thereby not generating additional packet encapsulation overhead. At the same time, the existing network architecture service line extension supports an additional encapsulation protocol, such as the NSN protocol in the related art, which reduces the direct dependence of the network infrastructure on a specific protocol, is conducive to improving the maintainability of the system, and reduces the implementation cost.

[0125] It should be understood that the SFC packet forwarding system embodiments and the SFC packet forwarding method embodiments can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, details are not described here. Specifically, the SFC packet forwarding system shown in FIG. 6 can perform the above-mentioned SFC packet forwarding method embodiments, and the foregoing and other operations and / or functions of each device in the SFC packet forwarding system correspond to the method embodiments.

[0126] The above describes the SFC packet forwarding system embodiments of the application in combination with FIG. 6, and the following describes the SFC packet forwarding device embodiments of the application in combination with FIG. 7.

[0127] FIG. 7 is a structural schematic diagram of a SFC packet forwarding device 700 according to an embodiment of the application. The SFC packet forwarding device 700 is configured in a service function forwarding node SFF, such as the SFF 42 in FIG. 4, or the SFF 620 in FIG. 6, etc. Referring to FIG. 7, the SFC packet forwarding device 700 includes a receiving module 710, a determining module 720, and a sending module 730.

[0128] The receiving module 710 is configured to receive a target packet. The target packet carries a destination network address of a corresponding service and sending node information of the target packet. The determining module 720 is configured to determine that the target packet hits an SFC routing table item according to the carrying information of the target packet. The SFC routing table item records a first mapping relationship between first routing matching information and next hop SF information. The first routing matching information includes the destination network address of the target service and the sending node information of the current packet. The next hop SF information is used to determine a next hop SF to which the current packet is forwarded. The determining module 720 is further configured to determine a network address of a next hop service function node SF of the target packet based on the first mapping relationship recorded in the SFC routing table item. The sending module 730 is configured to send the target packet based on the network address of the next hop SF of the target packet.

[0129] In an exemplary embodiment, based on the above scheme, the receiving module 710 is further configured to receive an SFC routing table item issued by a control node before receiving the target packet. The routing table item about the target service in the SFC routing table item is determined according to a service function path SFP of the target service. The control node is a software defined network SDN controller.

[0130] In an example embodiment, based on the above scheme, the determining module 720 is specifically configured to: after the message receiving module 710 receives the target message, search the SFC routing table item according to the destination network address carried by the target message; if it is determined that the destination network address carried by the target message hits the destination network address of the target service in the SFC routing table item, determine whether the sending node information carried by the target message is included in the first routing matching information of the SFC routing table item about the target service; and if it is determined that the sending node information carried by the target message is included in the first routing matching information of the SFC routing table item about the target service, determine that the target message hits the SFC routing table item.

[0131] In an example embodiment, based on the above scheme, the determining module 720 includes a first determining unit and a second determining unit; the first determining unit is configured to determine the target SF information from the SFC routing table item information according to the sending node information carried by the target message and the first mapping relationship; and the second determining unit is configured to determine the network address of the next hop SF of the target message according to the target SF information.

[0132] In an example embodiment, based on the above scheme, the next hop SF information in the SFC routing table item is an SF identifier having a second mapping relationship with a tenant identifier in the Overlay network; the second determining unit is specifically configured to: search an instance table according to the target SF information to obtain a target tenant identifier having a second mapping relationship with the target SF information, and obtain the network address of the SF having a third mapping relationship with the target tenant identifier, thereby obtaining the network address of the next hop SF of the target message; and the instance table records the second mapping relationship between the SF identifier and the tenant identifier and records the third mapping relationship between the tenant identifier and the network address of the SF.

[0133] In an example embodiment, based on the above scheme, the sending module 730 is specifically configured to: search an Overlay routing table item according to the network address of the next hop SF of the target message and the target tenant identifier to determine the encapsulation information required for forwarding the target message to the next hop SF, wherein the Overlay routing table item records a fourth mapping relationship between second routing matching information and encapsulation information, and the second routing matching information includes the network address of the next hop SF and the tenant identifier; perform tunnel encapsulation on the target message according to the encapsulation information corresponding to forwarding the target message to the next hop SF; and send the target message after the tunnel encapsulation according to the network address of the next hop SF of the target message.

[0134] In an example embodiment, based on the above scheme, the forwarding device 700 for packets in the service function chain SFC further comprises: an encapsulation module; wherein the encapsulation module is configured to: if it is determined according to the carrying information in the target packet that the target packet does not hit the SFC routing table item, search the Overlay routing table item according to the destination network address carried by the target packet to determine the encapsulation information corresponding to the destination network address; perform tunnel encapsulation on the target packet according to the encapsulation information corresponding to the destination network address; and send the target packet after the tunnel encapsulation to the node corresponding to the destination network address.

[0135] In an example embodiment, based on the above scheme, the target SF information is the network address of the next-hop SF of the target packet; and the sending module 730 is further configured to: if it is determined according to the carrying information in the target packet that the target packet does not hit the SFC routing table item, send the target packet according to the destination network address carried by the target packet.

[0136] The forwarding device 700 for packets in the service function chain SFC provided in FIG. 7 is configured in the SFF, and the SFF receives a target packet based on the packet receiving module, wherein the target packet carries the destination network address corresponding to the service and the information about the sending node of the target packet. The SFF determines whether the target packet hits the SFC routing table item according to the carrying information of the target packet through the network address determining module. If the SFF determines that the target packet hits the SFC routing table item, the SFF determines the network address of the next-hop SF of the target packet based on the first mapping relationship recorded in the SFC routing table item. Thus, the SFF sends the target packet based on the network address of the next-hop SF of the target packet through the packet sending module, thereby realizing the forwarding of the target packet. The forwarding scheme for packets in the service function chain SFC provided in the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), thereby not needing to generate additional packet encapsulation overhead. At the same time, the existing network architecture service line extension supports the protocol of additional encapsulation, such as the NSN protocol extended in the related art, which reduces the direct dependence of the network infrastructure on a specific protocol, is conducive to improving the maintainability of the system and reducing the implementation cost.

[0137] The forwarding device 700 for packets in the service function chain SFC provided in FIG. 7 is configured in the SFF, and the SFF receives a target packet based on the packet receiving module, wherein the target packet carries the destination network address corresponding to the service and the information about the sending node of the target packet. The SFF determines whether the target packet hits the SFC routing table item according to the carrying information of the target packet through the network address determining module. If the SFF determines that the target packet hits the SFC routing table item, the SFF determines the network address of the next-hop SF of the target packet based on the first mapping relationship recorded in the SFC routing table item. Thus, the SFF sends the target packet based on the network address of the next-hop SF of the target packet through the packet sending module, thereby realizing the forwarding of the target packet. The forwarding scheme for packets in the service function chain SFC provided in the embodiments of the present application does not need to introduce an additional encapsulation step (such as NSH encapsulation), thereby not needing to generate additional packet encapsulation overhead. At the same time, the existing network architecture service line extension supports the protocol of additional encapsulation, such as the NSN protocol extended in the related art, which reduces the direct dependence of the network infrastructure on a specific protocol, is conducive to improving the maintainability of the system and reducing the implementation cost.

[0138] The device of the embodiments of the present application is described above from the perspective of functional modules in combination with the drawings. It should be understood that the functional modules can be implemented in the form of hardware, or in the form of instructions of software, or in the form of a combination of hardware and software modules. Specifically, the steps of the method embodiments in the embodiments of the present application can be completed by the integrated logic circuit of hardware in the processor and / or instructions of software. The steps of the method disclosed in the embodiments of the present application can be directly embodied as hardware code processing for execution by the processor, or can be executed by a combination of hardware and software modules in the code processing. Alternatively, the software module can be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, and the like. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps in the above method embodiments in combination with the hardware thereof.

[0139] It should be understood that the device for forwarding a packet in an SFC and the method for forwarding a packet in an SFC can correspond to each other, and similar descriptions can be referred to the method embodiments. To avoid repetition, details are not described here. Specifically, the device for forwarding a packet in an SFC shown in FIG. 7 can execute the above-mentioned method embodiments for forwarding a packet in an SFC, and the above-mentioned and other operations and / or functions of each device in the device for forwarding a packet in an SFC correspond to the method embodiments.

[0140] FIG. 8 is a schematic block diagram of an electronic device provided by the embodiments of the present application, and the electronic device in FIG. 8 can be used to execute the above-mentioned method for forwarding a packet in a service function chain SFC. The electronic device can be the above-mentioned service function forwarding node SFF.

[0141] As shown in FIG. 8, the electronic device 800 can include:

[0142] The memory 810 is used to store the computer program 33 and transmit the program code 33 to the processor 820. In other words, the processor 820 can call and run the computer program 830 from the memory 810 to implement the method in the embodiments of the present application.

[0143] For example, the processor 820 can be used to execute the steps in the above-mentioned method according to the instructions in the computer program 830.

[0144] In some embodiments of the present application, the processor 820 can include but is not limited to:

[0145] General processor, Digital Signal Processor (DSP), Application Specific Integrated Circuit (ASIC), Field Programmable Gate Array (FPGA) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc.

[0146] In some embodiments of the present application, the memory 810 includes, but is not limited to:

[0147] volatile memory and / or non-volatile memory. The non-volatile memory can be Read-Only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically EPROM (EEPROM), or flash memory. The volatile memory can be Random Access Memory (RAM), which is used as the external cache. By way of example, and not limitation, many forms of RAM can be used, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0148] In some embodiments of the present application, the computer program 830 can be divided into one or more modules, which are stored in the memory 810 and executed by the processor 820 to complete the forwarding method of the packet in the SFC provided by the present application. The one or more modules can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program 830 in the electronic device.

[0149] As shown in FIG. 8, the electronic device 800 can further include:

[0150] a transceiver 840, which can be connected to the processor 820 or the memory 810.

[0151] The processor 820 can control the transceiver 840 to communicate with other devices, specifically, can send information or data to other devices, or receive information or data sent by other devices. The transceiver 840 can include a transmitter and a receiver. The transceiver 840 can further include an antenna, and the number of antennas can be one or more.

[0152] It should be understood that various components in the electronic device 800 are connected through a bus system, wherein the bus system includes, in addition to a data bus, a power supply bus, a control bus, and a status signal bus.

[0153] According to an aspect of the present application, a computer storage medium is provided, and the computer storage medium stores a computer program. When the computer program is executed by a computer, the computer is enabled to perform the method of the above method embodiments. Alternatively, the embodiments of the present application further provide a computer program product containing instructions. When the instructions are executed by a computer, the computer performs the method of the above method embodiments.

[0154] According to another aspect of the present application, a computer program product or computer program is provided, and the computer program product or computer program includes computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device performs the method of the above method embodiments.

[0155] In other words, when implemented using software, the functions can be implemented in whole or in part using a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the whole or part of the flow or function according to the embodiments of the present application is generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center through wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)), or semiconductor media (for example, solid state disk (SSD)) and the like.

[0156] Those skilled in the art can appreciate that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0157] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above described device embodiments are only schematic, for example, the division of the modules is only a logical function division, and actual implementation can have another division manner, for example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be indirect coupling or communication connection through some interface, device or module, and can be electrical, mechanical or other forms.

[0158] The modules illustrated as separate components may or may not be physically separate, and the components illustrated as modules may or may not be physical modules, i.e., may be located in one place, or may be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application. For example, the functional modules in various embodiments of the present application can be integrated in one processing module, or each module can exist physically separately, or two or more modules can be integrated in one module.

[0159] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for forwarding a packet in a service function chaining (SFC), characterized in that, The method is applied to a service function forwarding node SFF, and the method comprises the following steps: receiving a target message, wherein the target message carries a destination network address of a corresponding service and sending node information of the target message; determining that the target message hits an SFC routing table item according to the carrying information of the target message, wherein the SFC routing table item records a first mapping relationship between first route matching information of a target service and next hop service function node SF information, the first route matching information of the target service comprises the destination network address of the target service and the sending node information of the current message, and the next hop SF information is used to determine a next hop SF to which the current message is forwarded; determining a network address of a next hop SF of the target message based on the first mapping relationship recorded by the SFC routing table item; sending the target message based on the network address of the next hop SF of the target message.

2. The method of claim 1, wherein, Before the step of receiving the target message, the method further comprises the following steps: receiving an SFC routing table item issued by a control node; wherein the routing table item about the target service in the SFC routing table item is determined according to a service function path SFP of the target service, and the control node is a software defined network SDN controller.

3. The method of claim 1, wherein, The step of determining that the target message hits the SFC routing table item according to the carrying information of the target message comprises the following steps: searching for the SFC routing table item according to the destination network address carried by the target message; if it is determined that the destination network address carried by the target message hits the destination network address of the target service in the SFC routing table item, then determining whether the sending node information carried by the target message is contained in the first route matching information of the target service of the SFC routing table item; if it is determined that the sending node information carried by the target message is contained in the first route matching information of the target service in the SFC routing table item, then determining that the target message hits the SFC routing table item.

4. The method of claim 3, wherein, The step of determining the network address of the next hop SF of the target message based on the first mapping relationship recorded by the SFC routing table item comprises the following steps: determining target SF information from the SFC routing table item according to the sending node information carried by the target message and the first mapping relationship; determining the network address of the next hop SF of the target message according to the target SF information.

5. The method of claim 4, wherein, The next hop SF information in the SFC routing table item is SF identification which has a second mapping relationship with tenant identification in an Overlay network; The step of determining the network address of the next hop SF of the target message according to the target SF information comprises the following steps: searching for an instance table according to the target SF information to obtain target tenant identification which has a second mapping relationship with the target SF information, and to obtain the network address of SF which has a third mapping relationship with the target tenant identification, thereby obtaining the network address of the next hop SF of the target message; wherein the instance table records the second mapping relationship between SF identification and tenant identification, and records the third mapping relationship between tenant identification and the network address of SF.

6. The method of claim 5, wherein, sending the target message according to the network address of the next hop SF of the target message, comprises: determining encapsulation information required for forwarding the target message to the next hop SF according to the network address of the next hop SF of the target message and the target tenant identifier, wherein the Overlay routing table item records a fourth mapping relationship between second routing matching information and encapsulation information, and the second routing matching information comprises the network address of the next hop SF and the tenant identifier; performing tunnel encapsulation on the target message according to the encapsulation information corresponding to forwarding the target message to the next hop SF; sending the target message after tunnel encapsulation according to the network address of the next hop SF of the target message.

7. The method of claim 6, wherein, The method further comprises: if it is determined that the target message does not hit the SFC routing table item according to the carrying information of the target message, then searching for the Overlay routing table item according to the destination network address carried by the target message to determine encapsulation information corresponding to forwarding to the destination network address; performing tunnel encapsulation on the target message according to the encapsulation information corresponding to the destination network address; sending the target message after tunnel encapsulation to a node corresponding to the destination network address.

8. The method of claim 4, wherein, The target SF information is the network address of the next hop SF of the target message. The method further comprises: if it is determined that the target message does not hit the SFC routing table item according to the carrying information of the target message, then sending the target message according to the destination network address carried by the target message.

9. A message forwarding system in a Service Function Chain (SFC), characterized in that, The system comprises: a service function forwarding node SFF configured to receive a target message, wherein the target message carries a destination network address of a corresponding service and sending node information of the target message; determine that the target message hits an SFC routing table item according to carrying information of the target message; determine a network address of a next hop service function node SF of the target message based on a first mapping relationship recorded by the SFC routing table item; and send the target message according to the network address of the next hop SF of the target message. The SFC routing table item records a first mapping relationship between first routing matching information of a target service and next hop SF information, the first routing matching information comprises a destination network address of the target service and sending node information of a current message, and the next hop SF information is used to determine a next hop SF to which the current message is forwarded.

10. The system of claim 9, wherein, The system further comprises: a control node configured to issue an SFC routing table item to the SFF, wherein a routing table item about the target service in the SFC routing table item is determined according to a service function path SFP of the target service, and the control node is a software defined network SDN controller; the SFF is further configured to receive the SFC routing table item issued by the control node.

11. The system of claim 9, wherein, The system further comprises: at least one SF, wherein one of the SFs corresponds to one tenant in an overlay.

12. A message forwarding device in a Service Function Chain (SFC), characterized in that, The apparatus is configured in a service function forwarding node SFF, and the apparatus comprises: A receiving module is configured to receive a target packet, wherein the target packet carries a destination network address of a corresponding service and sending node information of the target packet; A determining module is configured to determine that the target packet hits an SFC routing table item according to the carrying information of the target packet, wherein the SFC routing table item records a first mapping relationship between first routing matching information of a target service and next hop service function node (SF) information, the first routing matching information includes the destination network address of the target service and the sending node information of the current packet, and the next hop SF information is used to determine a next hop SF to which the current packet is forwarded; The determining module is further configured to determine a network address of the next hop SF of the target packet based on the first mapping relationship recorded by the SFC routing table item. A sending module is configured to send the target packet based on the network address of the next hop SF of the target packet.

13. An electronic device, comprising: comprising a processor and a memory; the memory is configured to store a computer program; the processor is configured to execute the computer program to implement the method for forwarding a packet in a service function chain (SFC) according to any one of claims 1 to 8.

14. A computer-readable storage medium, characterized in that, for storing a computer program; the computer program enables a computer to execute the method for forwarding a packet in a service function chain (SFC) according to any one of claims 1 to 8.

15. A computer program product, characterised in that, comprising computer program instructions, which enable a computer to execute the method for forwarding a packet in a service function chain (SFC) according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Service function chaining (sfc)-based packet forwarding method, device and system

    CN107925624A

  • Message forwarding method and device based on service function chain

    CN111740900A

  • Implementation of service function chain on basis of software-defined network

    WO2020010557A1