A kind of method and apparatus that is used for the classification of network message high-efficiency dynamic
Technical field
The present invention relates to the network data processing field, be specifically related to a kind of method and apparatus that is used for the classification of network message high-efficiency dynamic.
Background technology
Message classification is the header information according to message, generally is the five-tuple information that agreement, ip, port constitute, and message is divided into the dissimilar different disposal of doing respectively, such as router to the message of different segment to the different sub-network forwarding etc.In express network, software realizes that the efficient of message classification is not high, and therefore a lot of message classification equipment adopt hardware (network processing unit or special chip) to realize.
In order to guarantee rule matching efficiency, generally use TCAM stored messages classifying rules, when each message arrives, can from TCAM, match the classification of message fast.
Application number 200910000608.3 discloses non-rule matching method, device and the network system in a kind of message classification, this method comprises: the keyword of described message and the list item among the Ternary Content Addressable Memory TCAM are mated, described TCAM list item is corresponding with the whole piece rule, and the match is successful for part acquiescence corresponding with non-rule field in the list item of described TCAM; If the match is successful for the keyword of described message and TCAM list item, then, know the non-rule field in the whole piece rule by the non-rule field identification information in the SRAM record corresponding with this TCAM list item; The forward keyword that the keyword of the non-rule field in the described message is corresponding with the non-rule field in the described SRAM record mates, if coupling is all unsuccessful, then judges the success of this message and whole piece rule match.
Application number 200610011455.9 discloses a kind of unified processing method of three-folded content addressable memory message classification, it is characterized in that, comprising: step 1, generation one unified ACL Policy Table, a unified action schedule; Step 2, deposit described unified ACL Policy Table in TCAM, deposit described unified action schedule in memory; Step 3, carry out according to the form structure search key of setting that message is searched, message classification; Wherein said unified ACL Policy Table is made of one group of TCAM clauses and subclauses of depositing message classification information; Described unified action schedule is made of the action corresponding with each described TCAM clauses and subclauses; The form of described TCAM clauses and subclauses is divided into: control information, 2 layers of information, 3 layers of information and 4 layers of information.
Application number 200610011453.X discloses a kind of method that improves the three-folded content addressable memory message classification seek rate, be applicable to the coupling that on the network equipment, realizes based on the access control list ACL of TCAM, it is characterized in that, usage space exchanges time method for and improves TCAM message classification searching speed, specifically can be by buffer memory keyword technology, parallel search technology and/or logic submeter technology realizes.
Application number 200610011466.7 discloses a kind of rule update method of three-folded content addressable memory message classification, it is characterized in that, rule is extended to a plurality of rule entries to be stored in the entry space of memory, when adding new regulation, judge whether last idle entry space that accounts for after the entry space that stores described rule entries can hold the new regulation that will add, be then described last accounted for entry space after the direct described new regulation of storage, otherwise with described memory tighten with remove described last accounted for idle entry space before the entry space, and then store described new regulation; During deletion rule, the entry space that accounts for that directly will store this deleted rule is arranged to idle entry space.
Unified shortcoming is that the update efficiency of TCAM chip is low in these technical schemes, upgrades complicated operation, causes rule to be difficult to realize on-the-fly modifying in real time flexibly, frequently revises in the system of classifying rules at needs, is difficult to meet the demands.
Summary of the invention
The object of the invention provides a kind of equipment and processing method that realizes that hardware message classification rule can dynamic flexible be revised, and when utilizing hardware message classification performance, makes classifying rules real-time update flexibly.
A kind of equipment that is used for the classification of network message high-efficiency dynamic comprises software section and network interface card;
Described software section comprises that network interface card drives and the classifying rules management software;
Described network interface card comprises that network interface, special chip and plate carry internal memory.
A kind of method that is used for the classification of network message high-efficiency dynamic comprises following steps:
When A, driving loading, the rule list that is stored among the network interface card SARM is constructed an identical mirror image in host memory; The hash of rule of correspondence table table storage organization is expanded a management data structures to mirror image simultaneously;
B, when management software need be revised rule, the rule list mirror image in directly revise driving;
After C, modification finish,, amended list item is copied to the position that the network interface card plate carries the sram memory correspondence by driving the memory-mapped that realizes;
After D, network interface card received message, the master control special chip extracted five-tuple information from message, searched in the hash of network interface card sram memory table, to hitting the action that regular message executing rule is formulated.
A kind of optimal technical scheme of the present invention is: described special chip is the network interface card main control chip, moves all message classification processing logics.
Another optimal technical scheme of the present invention is: described plate carries internal memory can adopt the high-speed SRAM internal memory, as QDR etc.
Also a kind of optimal technical scheme of the present invention is: the management data structures of expanding in the described steps A comprises conflict anchor point and conflict queue chain.
Whole system of the present invention has guaranteed very high efficient again when having satisfied the dynamic flexible requirement.
Description of drawings
Fig. 1 is the system configuration of present device
Fig. 2 is the method that the present invention realizes dynamic message classification
Specific embodiments
The technical scheme of present device is the equipment of a software and hardware one, hardware be with special chip for the network interface card that main devices designs, comprise network interface, special chip, plate carry internal memory and constitute; Software is driven by network interface card and the classifying rules management software constitutes.
The function of the every part of system is as follows:
(1) network interface: network message Data Receiving network access card.
(2) special chip: the main control chip of network interface card, move all message classification processing logics.
(3) plate carries internal memory: adopt the high-speed SRAM internal memory, preserve the message classification rule list.
(4) network interface card drives: the administration configuration network interface card, give the table of classification rules in the network interface card, mirror image of structure in host memory.
(5) management software: the instrument of configuration network interface card is configured to the message classification rule in the network interface card hardware.
Implementation method and process are as follows:
(1) the network interface card driving is established mirror image for the rule list in the hardware
Drive when loading the rule list of corresponding stored in network interface card SRAM, identical mirror image of structure in host memory, the hash table storage organization of rule of correspondence table, to mirror-image structure expansion management data,, form the mirror image rule list of expansion such as the anchor point etc. that conflicts.
(2) the rule list mirror image during managing software updates drives
When management software need be revised rule, revise the rule list mirror image in driving earlier.Because the rule list mirror image in the host memory has the managerial structure of expansion, and the operating host internal memory carries fast many of sram memory than the plate of operation network interface card, so management software can be revised the rule list mirror image rapidly.
(3) management software is implemented into the change of mirror image rule list in the hardware rule list
Which list item management software determines finally to have revised in the mirror image rule list, by driving the memory-mapped that realizes, the content of these list items is copied to the correspondence position that the network interface card plate carries sram memory.
(4) after network interface card hardware receives message, carry out rule match.
After network interface card was received message, the master control special chip extracted five-tuple information from message, carried to plate in the hash table of sram internal memory to search, to the action of the message executing rule appointment of hitting rule.