Storage method and apparatus, device, medium, and product

WO2026200148A1PCT designated stage Publication Date: 2026-10-01SANECHIPS TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/147013
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-25
Filing Date
2025-12-30
Publication Date
2026-10-01

Smart Images

  • Figure CN2025147013_01102026_PF_FP_ABST
    Figure CN2025147013_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network communications, and discloses a storage method and apparatus, a device, a medium, and a product. The storage method comprises: acquiring information of a storage space and information of an access control list (S10); on the basis of the information of the storage space and the information of the access control list, selecting or determining a target access control list sharing algorithm model (S20); and on the basis of the target access control list sharing algorithm model, performing entry management on the access control list in the storage space (S30).
Need to check novelty before this filing date? Find Prior Art

Description

Storage methods, devices, equipment, media and products

[0001] Cross-references to related applications

[0002] This application is based on and claims priority to Chinese Patent Application No. 202510359552.X, filed on March 25, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of network communication technology, and in particular to a storage method, apparatus, device, medium and product. Background Technology

[0004] With the continuous advancement of automotive technology and the rapid development of intelligent connected vehicles, automotive network communication systems are becoming increasingly complex. In automotive network communication, Access Control Lists (ACLs) play a crucial role as an important tool for network security management. ACL entries define which systems or devices are authorized to access services on the network, thereby ensuring the security and reliability of in-vehicle communications. However, with the increasing number of sensors, controllers, and actuators in vehicles, and the growing richness of in-vehicle applications and services, the data traffic in automotive network communications is also continuously increasing. This increase in data traffic places higher demands on the capacity of ACL entries.

[0005] In related technologies, ACL tables are mainly stored using ternary content addressable memory (TCAM). The traditional method of storing ACL entries is to divide the TCAM into several blocks of different sizes. Each block can be allocated to an ACL entry. The business key initiates a parallel lookup of multiple blocks of an ACL entry. However, this storage method is inefficient and does not make full use of storage space.

[0006] Therefore, it is necessary to propose a scheme to improve the storage efficiency of ACL in a limited storage space, so as to improve the utilization of storage space. Summary of the Invention

[0007] The main objective of this application is to provide a storage method, apparatus, device, medium, and product.

[0008] To achieve the above objectives, embodiments of this application provide a storage method, the method comprising: acquiring information about a storage space and information about an access control list; selecting a target access control list sharing algorithm model based on the information about the storage space and the access control list; and managing entries of the access control list in the storage space based on the target access control list sharing algorithm model.

[0009] This application embodiment also provides a storage device, the device comprising: an acquisition module configured to acquire information of storage space and information of access control list; a selection module configured to select or determine a target access control list sharing algorithm model based on the information of storage space and access control list; and a management module configured to manage the access control list entries in the storage space based on the target access control list sharing algorithm model.

[0010] This application also provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the storage method described above.

[0011] This application embodiment also provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the storage method described above.

[0012] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the storage method described above.

[0013] This application discloses a storage method, which includes: obtaining information about a storage space and information about an access control list; selecting or determining a target access control list sharing algorithm model based on the information about the storage space and the access control list; and managing the access control list entries in the storage space based on the target access control list sharing algorithm model. Attached Figure Description

[0014] Figure 1 is an exemplary flowchart of a storage method in an embodiment of this application;

[0015] Figure 2 is a schematic diagram of the access control list sharing algorithm management system in an embodiment of this application;

[0016] Figure 3 is a schematic diagram of the access control list structure in an embodiment of this application;

[0017] Figure 4 is a schematic diagram of the storage structure of the three-state content-addressable memory in the embodiment of this application;

[0018] Figure 5 is a schematic diagram of model selection in an embodiment of this application;

[0019] Figure 6 is a schematic diagram of the storage method of different table entry bit widths in TCAM in the embodiments of this application;

[0020] Figure 7 is a schematic diagram of the correspondence between the base address and the index in the embodiments of this application;

[0021] Figure 8 is a schematic diagram of the simultaneous hit selection mode in an embodiment of this application;

[0022] Figure 9 is a schematic diagram of the table entry addition process in an embodiment of this application;

[0023] Figure 10 is a schematic diagram of the table entry deletion process in an embodiment of this application;

[0024] Figure 11 is a schematic diagram of the application process for a three-state content-addressable memory block in an embodiment of this application;

[0025] Figure 12 is a schematic diagram of the fragmentation and defragmentation process in an embodiment of this application;

[0026] Figure 13 is another exemplary flowchart of the storage method in an embodiment of this application;

[0027] Figure 14 is a schematic diagram of the first effect of data entry relocation in an embodiment of this application;

[0028] Figure 15 is a schematic diagram of the second effect of data entry relocation in an embodiment of this application;

[0029] Figure 16 is a schematic diagram of the third effect of data entry relocation in an embodiment of this application;

[0030] Figure 17 is a schematic diagram of the fourth effect of data entry relocation in an embodiment of this application;

[0031] Figure 18 is a schematic diagram of the storage device structure provided in an embodiment of this application.

[0032] The realization of the purpose, functional features and advantages of this application will be described in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0033] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0034] Technical terms used in the embodiments of this application:

[0035] ACL: Access Control List;

[0036] TCAM: Ternary Content Addressable Memory;

[0037] RAM: Random Access Memory;

[0038] Bit: bit;

[0039] Key_mode: entry storage bit width / key value;

[0040] Block: block.

[0041] With the continuous progress of automotive technology and the rapid development of intelligent connected vehicles, automotive network communication systems are becoming increasingly complex. In automotive network communication, access control list (ACL), as an important tool for network security management, plays a crucial role. ACL entries are used to define which systems or devices are authorized to access services on the network, thereby ensuring the security and reliability of in-vehicle communication. However, with the continuous increase in the number of various sensors, controllers and actuators in vehicles, as well as the increasingly abundant in-vehicle applications and services, the data traffic in automotive network communication is also growing continuously. This growth in data traffic puts forward higher requirements for the capacity of ACL entries. ACL is mainly stored by Ternary Content Addressable Memory (TCAM). TCAM is characterized by its support for parallel search and low search delay; its disadvantages are high cost, high power consumption and limited capacity.

[0042] The traditional ACL entry storage method divides TCAM into multiple block spaces of various sizes, and each block can be allocated to an ACL entry, and the service key (Key) initiates parallel search on multiple blocks of one ACL entry. This storage method has low efficiency, especially in large network environments where the number of ACL entries is huge, the traditional storage method can hardly meet the capacity requirement. Therefore, how to increase the capacity of ACL under limited TCAM resources has become an urgent problem to be solved in the field of automotive communication technology.

[0043] Currently, regarding the issue of how to increase ACL capacity, in addition to the direct method of increasing TCAM resource space, the industry has explored a variety of optimization schemes, mainly including: (1) One block can store two ACL entries, and the two ACL tables are written to according to different address directions to achieve resource sharing of one block; (2) Two blocks store one type of ACL entry, and the two ACL tables are written to according to different address directions. By adjusting the size of the block, resource sharing of the block can be achieved. However, these two schemes are not feasible for scenarios where more than three ACL entries share resources; (3) By loading the same ACL rules in multiple ACLs as ACL shared segments separately, the purpose of saving memory space can be achieved. However, the number of ACL shared segments that can be found in scheme (3) is limited, which has strong limitations.

[0044] Taking a TCAM with 16 blocks and each block having a space of 1k×640bit as an example, in practical applications, different services have different requirements for the bit width of ACL entries. For example, service 1 requires a bit width of 160bit, and its maximum resource requirement is 12k×640bit; service 2 increases to a bit width of 320bit, also requiring a maximum resource of 12k×640bit; service 3 is even higher at 640bit, but its maximum resource requirement remains at the level of 12k×640bit. However, when the ACL entries of these three services coexist in the network, the total maximum resource required by them will exceed the existing configuration of 16k×640bit. If the traditional storage method is used to allocate 12k×640bit resources to each service separately, it is obviously impossible to meet the needs of the three services coexisting, resulting in insufficient resource allocation. Therefore, developing an efficient ACL entry storage sharing scheme becomes particularly urgent to ensure that the ACL table can receive reasonable resource allocation under various service scenarios, thereby maintaining the security and stability of automotive network communication.

[0045] This application proposes a solution that, given limited TCAM and cascaded RAM space, provides users with an efficient shared ACL entry storage management method based on existing TCAM storage rules and using an intelligent ACL shared management algorithm. Multiple entries share a single space, and TCAM resource sharing is achieved through dynamic allocation, release, and fragmentation of TCAM blocks.

[0046] Referring to Figure 1, which is an exemplary flowchart of a storage method in an embodiment of this application, the storage method includes:

[0047] Step S10: Obtain information about the storage space and the access control list;

[0048] For example, the information of the storage space includes at least one of the following: the resource size of the tri-state content-addressable memory block, the resource address management method of the tri-state content-addressable memory block, and the cascaded resource size.

[0049] For example, the information in an access control list includes the bit width of the key value for each entry and / or the size of the shared resources that each entry can request.

[0050] Referring to Figure 2, which is a schematic diagram of the access control list sharing algorithm management system in an embodiment of this application, the access control list sharing algorithm management system in this embodiment includes at least one entry information processing unit, one sharing algorithm processing unit, and one storage unit. The storage unit includes at least one TCAM interface and a cascaded RAM interface.

[0051] Referring to Figure 3, which is a schematic diagram of the access control list structure in an embodiment of this application, the ACL table consists of two parts: ACL rules and results. The ACL rules are stored in the TCAM, and the results are stored in the cascaded RAM. The key first searches for the ACL rules stored in the TCAM. When an ACL rule in the TCAM matches, the position of its entry is used as a handle, and the handle is used as an index to search the cascaded RAM again to obtain the result.

[0052] Referring to Figure 4, which is a schematic diagram of the storage structure of the tri-state content addressing memory in the embodiment of this application, as shown in Figure 4, this embodiment of the application takes a TCAM consisting of 16 blocks as an example for illustration. Each block includes 8 TCAM units, and each TCAM unit is 1k(1024)×80bit.

[0053] Step S20: Select a target access control list sharing algorithm model based on the information of the storage space and the access control list;

[0054] For example, the table entry information processing unit in Figure 2 can select a suitable target access control list sharing algorithm model (i.e., ACL sharing algorithm model) to manage ACL tables based on the user's TCAM block resource size, TCAM block resource address management method, cascading resource size, key value bit width of each table entry, and the size of shared resources that each table entry can request.

[0055] For example, the target access control list sharing algorithm model includes at least one of the first access control list sharing algorithm model, the second access control list sharing algorithm model, the third access control list sharing algorithm model, and the fourth access control list sharing algorithm model.

[0056] For example, the steps of selecting a target access control list sharing algorithm model based on the storage space information and the access control list information include:

[0057] Identify whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition;

[0058] If the information of the storage space and the information of the access control list satisfy the first condition and the second condition, the first access control list sharing algorithm model is selected.

[0059] If the information in the storage space and the information in the access control list do not meet the first condition but meet the second condition, the second access control list sharing algorithm model is selected.

[0060] If the information in the storage space and the information in the access control list satisfy the first condition but do not satisfy the second condition, the third access control list sharing algorithm model is selected.

[0061] If the information in the storage space and the information in the access control list do not meet the first and second conditions, the fourth access control list sharing algorithm model is selected.

[0062] For example, the tri-state content-addressable memory block resource address management method includes the configuration range of the base address of the tri-state content-addressable memory block and / or the mode in which multiple blocks simultaneously hit the computation processing.

[0063] For example, the step of identifying whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition includes:

[0064] Based on the bit width of each table entry key value, the size of the shared resources that each table entry can apply for, and the size of the tri-state content addressing memory block resources, it is determined whether the cascaded resource size meets the resource requirements, and whether the configuration range of the base address meets the range requirements.

[0065] If the cascaded resource size meets the resource requirements and the configuration range of the base address meets the range requirements, it is determined that the information of the storage space and the information of the access control list meet the first condition.

[0066] If the size of the cascaded resources does not meet the resource requirements or the configuration range of the base address does not meet the range requirements, it is determined that the information of the storage space and the information of the access control list do not meet the first condition.

[0067] When the multiple blocks simultaneously hit the computation processing mode in the first mode, it is determined that the information of the storage space and the information of the access control list satisfy the second condition;

[0068] If the computation processing mode of the multiple blocks is simultaneously hit is the second mode, it is determined that the information of the storage space and the information of the access control list do not meet the second condition.

[0069] Referring to Figure 5, which is a schematic diagram of model selection in this embodiment, four models are selected based on the following two conditions: First condition: whether the resources of the cascaded RAM are sufficient or whether the range of base_addr is sufficient; Second condition: whether the mode of selecting handle when multiple blocks simultaneously hit is the first mode. If the first condition is not met, the block base address needs to be adjusted to ensure that the order of the base address is the block used by the 640-bit block, the block used by the 320-bit block, and the block used by the 160-bit block; If the second condition is not met, the order of block_id within the table needs to be ensured to be ascending. Based on the first and second conditions, at least one of the first access control list sharing algorithm model, the second access control list sharing algorithm model, the third access control list sharing algorithm model, and the fourth access control list sharing algorithm model is selected to request resources.

[0070] For example, the first mode includes: when different tri-state content-addressable memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressable memory block with the smaller base address, and using the result corresponding to the index calculated using the base address of the selected tri-state content-addressable memory block as the hit result.

[0071] For example, the second mode includes: when different tri-state content-addressable memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressable memory block with the smaller sequence number, and using the result corresponding to the index calculated using the base address of the selected tri-state content-addressable memory block as the hit result.

[0072] Referring to Figure 6, which is a schematic diagram of the storage method of different entry bit widths in TCAM in the embodiments of this application, as shown in Figure 6, for 80-bit, 160-bit, 320-bit, and 640-bit bit widths (key_mode), each row of TCAM0 to TCAM7 is 80 bits, totaling 640 bits. This 640-bit space can store eight 80-bit ACL rules, four 160-bit ACL rules, two 320-bit ACL rules, or one 640-bit ACL rule. For example, when multiple entries in the same block can be matched simultaneously, such as ACL rule 1 and ACL rule 1022, the entry with the smaller position (handle=1) is selected.

[0073] Referring to Figure 7, which is a schematic diagram of the corresponding structure of base address and index in the embodiments of this application, as shown in Figure 7, this application provides two corresponding modes for the base address (base_addr) and handle index of ACL table entries (tcam block). The first mode allocates a cascaded RAM for each table, so the tcam_handle calculated by each table using the base address (base_addr) starts from 0. The second mode shares a cascaded RAM with all tables, and the tcam_handles calculated by base_addr cannot overwrite each other. The advantage of the first mode is a small configuration range for base_addr, but the disadvantage is the need for multiple cascaded RAMs. The advantage of the second mode is that only one cascaded RAM is needed, but the disadvantage is a larger range for base_addr. Furthermore, the calculation formulas for base_addr and the initial tcam_handle within the block include: tcam_handle = base_addr × 1024 × 640 / key_mode, where tcam_handle is the index of the cascaded RAM, base_addr is the base address, and key_mode is the key value.

[0074] Referring to Figure 8, which is a schematic diagram of the simultaneous hit selection mode in an embodiment of this application, the embodiment of this application mainly includes two modes for selecting the handle when multiple TCAM blocks are hit simultaneously. The first mode compares the handle size calculated according to base_addr and selects the smaller handle as the hit result output; the second mode compares the block_id size and calculates the handle based on the base_addr of the smaller block_id as the hit result output.

[0075] Step S30: Based on the target access control list sharing algorithm model, manage the access control list entries in the storage space.

[0076] For example, the shared algorithm processing unit in Figure 2 can, when adding or deleting ACL entries, perform TCAM block allocation, release, fragmentation, entry relocation, address adjustment, and cascaded RAM entry relocation according to the selected ACL shared algorithm model.

[0077] For example, an access control list includes access control list entries to be added and / or access control list entries to be deleted.

[0078] For example, the steps of managing entries of the access control list in the storage space based on the target access control list sharing algorithm model include:

[0079] If the allocated resource storage corresponding to the access control list entry to be added is full, based on the target access control list sharing algorithm model, the storage space is allocated, released, and / or fragmented to obtain a target tri-state content-addressed memory block, and the access control list entry to be added is stored in the target tri-state content-addressed memory block; and / or,

[0080] Based on the target access control list sharing algorithm model, the index corresponding to the access control list entry to be deleted is released in the storage space, and the access control list rules and cascading resources corresponding to the access control list entry to be deleted are deleted.

[0081] For example, based on the target access control list sharing algorithm model, the steps of applying for, releasing, and / or defragmenting the storage space to obtain the target tri-state content-addressable memory block include:

[0082] Based on the target access control list sharing algorithm model, a three-state content-addressable memory block is requested, and a base address is allocated to the requested three-state content-addressable memory block to obtain the target three-state content-addressable memory block;

[0083] In the event that the application for a three-state content-addressable memory block fails, the access control list of the applied three-state content-addressable memory block is defragmented and / or the applied three-state content-addressable memory block is released, and the process returns to the steps of applying for a three-state content-addressable memory block based on the target access control list sharing algorithm model and subsequent steps, until the target three-state content-addressable memory block is obtained.

[0084] If the application for a tri-state content-addressable memory block is successful, an index is allocated to the applied tri-state content-addressable memory block and access control list rules and cascading resources are configured to obtain the target tri-state content-addressable memory block.

[0085] Referring to Figure 9, which is a schematic diagram of the entry addition process in this embodiment of the application, the ACL entry addition process includes: first, determining whether a block needs to be requested based on whether the storage of the resource allocated to the entry is full; if a block needs to be requested, a block is requested from the resource pool and a base_addr is allocated; if the request fails, other entries are fragmented and the block is released, and the block is requested again; after the software allocates the tcam_handle, the hardware ACL rules and cascaded RAM are finally configured.

[0086] Referring to Figure 10, which is a schematic diagram of the entry deletion process in an embodiment of this application, the ACL entry deletion process includes: releasing the software-allocated tcam_handle, and then directly deleting the corresponding data from TCAM and cascaded RAM.

[0087] Referring to Figure 11, which is a flowchart of the application for a three-state content-addressable memory block in an embodiment of this application, as shown in Figure 11, the flowcharts for the application for a three-state content-addressable memory block are as follows: from left to right, the first access control list sharing algorithm model, the second access control list sharing algorithm model, the third access control list sharing algorithm model, and the fourth access control list sharing algorithm model.

[0088] For example, the steps of requesting blocks for a tri-state content-addressable memory based on a first access control list sharing algorithm model include: requesting unused block numbers from the resource pool of the tri-state content-addressable memory in a first order.

[0089] For example, the steps of applying for a tri-state content-addressable memory block based on the second access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a first order, calculating the base address of the block number, and moving the cascade table according to the base address of the block number.

[0090] For example, the steps of applying for a tri-state content addressing memory block based on the third access control list sharing algorithm model and allocating a base address for the applied tri-state content addressing memory block include: applying for unused block numbers from the resource pool of the tri-state content addressing memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the tri-state content addressing memory table according to the base address of the adjusted block numbers.

[0091] For example, the steps of applying for a tri-state content-addressable memory block based on the fourth access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the cascade table and the tri-state content-addressable memory table according to the base address of the adjusted block numbers.

[0092] For example, the first sequence includes: from the first block number (0) of the tri-state content-addressable memory block to the last block number (n) of the tri-state content-addressable memory block.

[0093] For example, the second sequence includes: from the largest requested block number (last_block_id) to the last block number of the tri-state content-addressable memory block, and from the first block number (0) of the tri-state content-addressable memory block to the largest requested block number (last_block_id).

[0094] Referring to Figure 12, which is a schematic diagram of the fragmentation and defragmentation process in an embodiment of this application, as shown in Figure 12, the steps for performing fragmentation and defragmentation on the access control list of the applied tri-state content-addressable memory block include:

[0095] Check the access control list (table) of each of the applied tri-state content addressing memory blocks one by one to determine whether there is an access control list that can release the block;

[0096] If an access control list that can release blocks exists, move the tri-state content-addressable memory entries (tcam entries) and cascaded resources (as_data) corresponding to the access control list that can release blocks one by one to release the tri-state content-addressable memory blocks.

[0097] Identify whether the target access control list sharing algorithm model used during the application phase of the released three-state content-addressable memory block is the first access control list sharing algorithm model or the third access control list sharing algorithm model;

[0098] When the target access control list sharing algorithm model used during the application phase of the released tri-state content-addressable memory block is either the first access control list sharing algorithm model or the third access control list sharing algorithm model, the release tri-state content-addressable memory block relocation cascade table is used, including adjusting the handle and relocating as_data one by one at the block level, and then configuring the base address base_addr of the block.

[0099] For example, ACL entries can be stored based on the results calculated by the ACL sharing algorithm.

[0100] This embodiment, through the above-described scheme, obtains information about the storage space and the access control list; selects or determines a target access control list sharing algorithm model based on the information about the storage space and the access control list; and manages the access control list entries in the storage space based on the target access control list sharing algorithm model. By adaptively selecting the target access control list sharing algorithm model according to the information about the storage space and the access control list, and managing the access control list entries in the storage space using the target access control list sharing algorithm model, the storage efficiency of the access control list can be improved without increasing the storage space, thus increasing the utilization rate of the storage space.

[0101] Referring to Figure 13, which is another exemplary flowchart of a storage method in an embodiment of this application, the method includes:

[0102] Step 1: Obtain the hardware TCAM storage space. This includes 16 blocks, each block being 1024*640 bits in size.

[0103] Step 2: Obtain the address management method of the hardware TCAM resources. The configuration range of the base address is 0 to 63. When multiple blocks hit simultaneously, select mode 2 for calculating the handle (calculate the handle based on the base_addr with the smaller block_id and output it as the hit result).

[0104] Step 3: Obtain the space for the cascaded RAM resources. The cascaded RAM contains only one set of data, i.e., 128k of RAM capacity;

[0105] Step 4: Obtain the bit width (key_mode) and the threshold of shared resources (share_block_num) for all table entries. Table 0 has a bit width of 160 bits and share_block_num = 16; table1 has a bit width of 320 bits and share_block_num = 16; table2 has a bit width of 640 bits and share_block_num = 16.

[0106] Step 5: Obtain the corresponding ACL sharing algorithm model. Based on steps 2-3, the first and second conditions in Figure 5 are not met. Therefore, request the resource model from the shared pool and select the fourth access control list sharing algorithm model.

[0107] Step 6: Obtain the sample operation flow for adding and deleting various table entries. Flow: ① Add an 8k 640-bit entry to table0, ② Add a 16k 160-bit entry to table2, ③ Add an 8k 320-bit entry to table1, ④ Delete a high-priority 8k (entries in block8 and block9) 160-bit entry from table2, ⑤ Add a 4k 320-bit entry to table1;

[0108] Step 7: Storing based on the fourth access control list sharing algorithm model. Referring to Figures 14-17, which are schematic diagrams of the first, second, third, and fourth effects of data entry relocation in this embodiment, respectively, in process ①, all blocks are unused, so blocks are allocated directly starting from block0, and base_addr is calculated. In process ②, since the table 2 entry width is 160 bits, table0 (640 bits) is directly inserted, and then base_addr is calculated. The effect after insertion is shown in Figure 14. In process ③, since table 1 has a width of 320 bits and it is necessary to ensure sufficient base address (the base address order is: 640-bit block, 320-bit block, 160-bit block), the base address of table 2's block needs to be adjusted before inserting table 1's block. The effect after insertion is shown in Figure 15. In process ④, entries in table 2 are deleted, and the ACL entry deletion process in Figure 10 is executed. In process ⑤, since all blocks are used up, a fragmentation and defragmentation process is required. It is determined that table2 can release two blocks, and table2 satisfies the fourth access control list sharing algorithm model in Figure 5. Therefore, the cascaded table needs to be moved, as shown in Figure 16. Next, block allocation is performed. Because table2 uses the fourth access control list sharing algorithm model, the cascaded RAM corresponding to table2 needs to be moved first, followed by the tcam table. The final insertion result is shown in Figure 17.

[0109] This embodiment, through the above-described scheme, selects a suitable ACL sharing algorithm model based on the user's TCAM block resource size, TCAM block resource address management method, cascaded resource size, key width of each table entry, and the amount of shared resources that each table entry can request. When adding or deleting ACL entries, the selected ACL sharing algorithm model is used to allocate, release, defragment, move entries, adjust addresses, and move entries in cascaded RAM, thereby achieving ACL table management and realizing TCAM resource sharing.

[0110] Furthermore, this application embodiment also provides a storage device. Referring to FIG18, FIG18 is a schematic diagram of the structure of the storage device provided in this application embodiment, the device includes:

[0111] Module 10 is configured to retrieve information about the storage space and the access control list.

[0112] The selection module 20 is configured to select or determine the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list;

[0113] Management module 30 is configured to manage entries of the access control list in the storage space based on the target access control list sharing algorithm model.

[0114] This application also provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the storage method described above.

[0115] This application embodiment also provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the storage method described above.

[0116] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the storage method described above.

[0117] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or computing device, etc.) to execute the methods described in the various embodiments of this application.

[0119] The above are only some embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural changes made based on the content of this application’s specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A storage method, comprising: Obtain information about the storage space and the access control list; Select the target access control list sharing algorithm model based on the information of the storage space and the access control list; Based on the target access control list sharing algorithm model, the access control list entries are managed in the storage space.

2. The storage method of claim 1, wherein, The target access control list sharing algorithm model includes at least one of a first access control list sharing algorithm model, a second access control list sharing algorithm model, a third access control list sharing algorithm model, and a fourth access control list sharing algorithm model. The step of selecting the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list includes: Identify whether the information of the storage space and the information of the access control list satisfy the first condition and the second condition; If the information of the storage space and the information of the access control list satisfy the first condition and the second condition, the first access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first condition but meet the second condition, the second access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list satisfy the first condition but do not satisfy the second condition, the third access control list sharing algorithm model is selected. If the information in the storage space and the information in the access control list do not meet the first and second conditions, the fourth access control list sharing algorithm model is selected.

3. The storage method of claim 2, wherein, The information of the storage space includes at least one of the following: the resource size of the tri-state content-addressable memory block, the resource address management method of the tri-state content-addressable memory block, and the cascaded resource size. The information of the access control list includes the bit width of the key value of each entry and / or the shareable resource size that each entry can apply for.

4. The storage method of claim 3, wherein, The tri-state content-addressable memory block resource address management method includes the configuration range of the base address of the tri-state content-addressable memory block and / or the mode of multiple blocks simultaneously hitting the computation processing. The step of identifying whether the information of the storage space and the information of the access control list meet the first condition and the second condition includes: Based on the bit width of each table entry key value, the size of the shared resources that each table entry can apply for, and the size of the tri-state content addressing memory block resources, it is determined whether the cascaded resource size meets the resource requirements, and whether the configuration range of the base address meets the range requirements. If the cascaded resource size meets the resource requirements and the configuration range of the base address meets the range requirements, it is determined that the information of the storage space and the information of the access control list meet the first condition. If the size of the cascaded resources does not meet the resource requirements or the configuration range of the base address does not meet the range requirements, it is determined that the information of the storage space and the information of the access control list do not meet the first condition. When the multiple blocks simultaneously hit the computation processing mode in the first mode, it is determined that the information of the storage space and the information of the access control list satisfy the second condition; If the computation processing mode of the multiple blocks is simultaneously hit is the second mode, it is determined that the information of the storage space and the information of the access control list do not meet the second condition.

5. The storage method of claim 4, wherein, The first mode includes: when different tri-state content-addressed memory blocks simultaneously hit access control list rules, selecting the tri-state content-addressed memory block with the smaller base address, and using the result of the index calculated using the base address of the selected tri-state content-addressed memory block as the hit result; and / or, The second mode includes: when different tri-state content-addressable memory blocks simultaneously hit the access control list rules, selecting the tri-state content-addressable memory block with the smaller sequence number, and using the result corresponding to the index calculated by the base address of the selected tri-state content-addressable memory block as the hit result.

6. The storage method of claim 2, wherein, The access control list includes access control list entries to be added and / or access control list entries to be deleted. The step of managing the access control list entries in the storage space based on the target access control list sharing algorithm model includes: If the allocated resource storage corresponding to the access control list entry to be added is full, based on the target access control list sharing algorithm model, the storage space is allocated, released, and / or fragmented to obtain a target tri-state content-addressed memory block, and the access control list entry to be added is stored in the target tri-state content-addressed memory block; and / or, Based on the target access control list sharing algorithm model, the index corresponding to the access control list entry to be deleted is released in the storage space, and the access control list rules and cascading resources corresponding to the access control list entry to be deleted are deleted.

7. The storage method of claim 6, wherein, The steps of allocating, releasing, and / or defragmenting tri-state content-addressable memory blocks in the storage space based on the target access control list sharing algorithm model to obtain the target tri-state content-addressable memory block include: Based on the target access control list sharing algorithm model, a three-state content-addressable memory block is requested, and a base address is allocated to the requested three-state content-addressable memory block to obtain the target three-state content-addressable memory block; In the event that the application for a three-state content-addressable memory block fails, the access control list of the applied three-state content-addressable memory block is defragmented and / or the applied three-state content-addressable memory block is released, and the process returns to the steps of applying for a three-state content-addressable memory block based on the target access control list sharing algorithm model and subsequent steps, until the target three-state content-addressable memory block is obtained. If the application for a tri-state content-addressable memory block is successful, an index is allocated to the applied tri-state content-addressable memory block and access control list rules and cascading resources are configured to obtain the target tri-state content-addressable memory block.

8. The storage method of claim 7, further comprising at least one of the following: The step of performing a three-state content addressable memory block allocation based on the first access control list sharing algorithm model comprises: Request unused block numbers from the resource pool of the tri-state content-addressable memory in the first order; The steps of applying for a three-state content addressing memory block based on the second access control list sharing algorithm model and allocating a base address for the applied three-state content addressing memory block include: applying for unused block numbers from the resource pool of the three-state content addressing memory in a first order, calculating the base address of the block number, and moving the cascade table according to the base address of the block number; The steps of applying for a three-state content addressing memory block based on the third access control list sharing algorithm model and allocating a base address for the applied three-state content addressing memory block include: applying for unused block numbers from the resource pool of the three-state content addressing memory in a second order, adjusting the block order according to the block numbers, calculating the base address of the adjusted block numbers, and moving the three-state content addressing memory table according to the base address of the adjusted block numbers; The steps of applying for a tri-state content-addressable memory block based on the fourth access control list sharing algorithm model and allocating a base address for the applied tri-state content-addressable memory block include: applying for unused block numbers from the resource pool of the tri-state content-addressable memory in a second order; adjusting the block order according to the block numbers; calculating the base address of the adjusted block numbers; and moving the cascade table and the tri-state content-addressable memory table according to the base address of the adjusted block numbers.

9. The storage method of claim 8, wherein, The first sequence includes: from the first block number of the tri-state content-addressable memory block to the last block number of the tri-state content-addressable memory block; and / or, The second sequence includes: from the largest requested block number to the last block number of the tri-state content-addressable memory block, and from the first block number of the tri-state content-addressable memory block to the largest requested block number.

10. The storage method of claim 7, wherein, The step of performing fragmentation defragmentation on the access control list of the applied tri-state content-addressable memory block includes: Check the access control list of each of the applied tri-state content-addressable memory blocks one by one to determine whether there is an access control list that can release the block; If an access control list that can release blocks exists, move the tri-state content-addressed memory entries and cascaded resources corresponding to the access control list that can release blocks one by one to release the tri-state content-addressed memory blocks. Identify whether the target access control list sharing algorithm model used during the application phase of the released three-state content-addressable memory block is the first access control list sharing algorithm model or the third access control list sharing algorithm model; If the target access control list sharing algorithm model used during the application phase of the released tri-state content-addressable memory block is either the first access control list sharing algorithm model or the third access control list sharing algorithm model, the cascade table is moved according to the released tri-state content-addressable memory block.

11. A storage device, comprising: The acquisition module is configured to retrieve information about the storage space and the access control list. The selection module is configured to select or determine the target access control list sharing algorithm model based on the information of the storage space and the information of the access control list; The management module is configured to manage the access control list entries in the storage space based on the target access control list sharing algorithm model.

12. A network device comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the storage method as described in any one of claims 1 to 10.

13. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the storage method as described in any one of claims 1 to 10.

14. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the storage method as described in any one of claims 1 to 10.