WO2024027194A1 - 报文转发方法、设备、系统及存储介质 - Google Patents

报文转发方法、设备、系统及存储介质 Download PDF

Info

Publication number
WO2024027194A1
WO2024027194A1 PCT/CN2023/087576 CN2023087576W WO2024027194A1 WO 2024027194 A1 WO2024027194 A1 WO 2024027194A1 CN 2023087576 W CN2023087576 W CN 2023087576W WO 2024027194 A1 WO2024027194 A1 WO 2024027194A1
Authority
WO
WIPO (PCT)
Prior art keywords
message
service
resource pool
path
node information
Prior art date
Application number
PCT/CN2023/087576
Other languages
English (en)
French (fr)
Inventor
张亚伟
郝建武
刘持奇
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2024027194A1 publication Critical patent/WO2024027194A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • H04L45/745Address table lookup; Address filtering

Definitions

  • This application relates to the field of communication technology, and in particular to message forwarding methods, equipment, systems and storage media.
  • operators not only provide basic network services, but also provide value-added services such as security services. For example, when forwarding user messages, a resource pool is set up next to the operator's network to implement value-added service processing for users.
  • multiple sub-interfaces are first created between the network device and the resource pool.
  • One sub-interface corresponds to one user.
  • the resource pool allocates an independent virtual system (Vsys) to each sub-interface.
  • Vsys provides value-added services to the corresponding users.
  • the control device arranges different forwarding paths for different users.
  • the forwarding path includes the address of the sub-interface on the network device corresponding to the user, so as to forward the packets of different users to the Vsys corresponding to the sub-interface to achieve multiple Value-added service processing for users.
  • the packet forwarding method in related technologies requires the creation of a large number of sub-interfaces, which makes the configuration of the resource pool complex and difficult to automate. And when arranging forwarding paths, it is necessary to distinguish the addresses of different sub-interfaces, which increases the difficulty of path arrangement.
  • This application provides a message forwarding method, device, system and storage medium to provide users with corresponding value-added services.
  • a message forwarding method includes: obtaining a first message and a second message, wherein the first message includes a first user identification, and the The second message includes a second user identifier, and the first user identifier is different from the second user identifier; the first resource pool is indicated based on the first node information in the first message, and the first node information is used to indicate that the first message corresponds to to the next hop in the forwarding path, the network device sends the first message to the first service device corresponding to the first resource pool, so that the first service device sends the first message to the first resource pool according to the first user identification included in the first message.
  • the network device sends the second message to the first service device corresponding to the first resource pool, so that the first service device determines the second user ID in the first resource pool based on the second user identification included in the second message.
  • the value-added service corresponding to the message is also indicated based on the first node information in the second message, and the first node information is also used to indicate the forwarding path corresponding to the second message.
  • this method does not need to create many sub-interfaces between network equipment and service equipment, and can directly combine the reports of different users based on the first node information included in the packets.
  • the service device Sent to the service device corresponding to the resource pool indicated by the first node information, the service device can map value-added services corresponding to different users according to the user identification carried in the message. Therefore, this method simplifies the deployment of sub-interfaces in the resource pool, and there is no need to distinguish between different sub-interfaces of the same resource pool during path orchestration, which reduces the computational difficulty of path orchestration.
  • the first message and the second message may be obtained by receiving the first message and the second message.
  • the first message also includes a first service chain path
  • the first service chain path includes node information of at least one resource pool through which the first service chain path passes.
  • the second message also includes a second service chain path.
  • the link path includes node information of at least one resource pool that the second service link path passes through, and the node information of at least one resource pool includes first node information.
  • the packet carries the first node information indicating the next hop through the included service link path, so that the network device can send the packet to the first service device corresponding to the first resource pool based on the first resource pool indicated by the first node information. arts.
  • the method of obtaining the first message and the second message may also be: receiving the third message and the fourth message; obtaining the first service chain path corresponding to the third message, and The third message is tunnel-encapsulated to obtain the first message, which includes the first service chain path; the second service chain path corresponding to the fourth message is obtained, and the fourth message is tunnel-encapsulated to obtain the second message, the second message includes a second service chain path; the first service chain path includes node information of at least one resource pool that the first service chain path passes through, and the second service chain path includes at least one resource pool that the second service chain path passes through.
  • the node information of the resource pool, the node information of at least one resource pool includes the first node information.
  • the packets forwarded to the resource pool carry the first node information indicating the next hop through the encapsulated service link path, so that the network device can based on the first node information
  • the indicated first resource pool sends a message to the first service device corresponding to the first resource pool.
  • the third message further includes a first service identifier
  • the fourth message further includes a second service identifier
  • the network device The optional service chain path corresponding to the first service identifier is determined among the optional service chain paths, so that the optional service chain path corresponding to the first service identifier is used as the first service chain path corresponding to the third message; similarly, the network The device determines the optional service chain path corresponding to the second service identifier among the plurality of optional service link paths, and uses the optional service chain path corresponding to the second service identifier as the second service chain path corresponding to the fourth message. Therefore, the corresponding service chain path can be determined among the optional service chain paths through the service identifier carried in the message.
  • the network device before the network device determines the optional service chain paths corresponding to different service identifiers based on the multiple optional service link paths, the network device first receives multiple optional service chain paths sent by the control device.
  • the optional service chain path includes node information of at least one resource pool that any optional service chain path passes through.
  • the optional service chain path is obtained through interaction with the control device. Since the control device has strong computing power, it not only reduces the computing pressure of the network device, but also makes the obtained optional service chain path more accurate.
  • the first service identifier and the second service identifier are application identifiers
  • the first service identifier is carried in the application aware network (APN) identifier included in the first message
  • the second service identifier The identifier is carried in the APN identifier included in the second message.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • the first message and the second message are segment routing based on Internet Protocol version 6 (segment routing IPv6 internet protocol version 6, SRv6) message
  • the first node information is the segment identity (SID) of the first resource pool.
  • SID segment identity
  • the resource pool can be a security resource pool
  • the value-added service can be a security service.
  • a message forwarding method includes: the first service device receives the first message and the second message sent by the network device; The message includes a first user identifier, the second message includes a second user identifier, and the first user identifier is different from the second user identifier; the first service device determines the first user identifier corresponding to the first message in the first resource pool according to the first user identifier. The first value-added service determines the second value-added service corresponding to the second message in the first resource pool according to the second user identifier.
  • the first node information in the first message indicates that the next hop of the network device in the forwarding path of the first message is the first resource pool, and the first node information in the second message indicates the forwarding of the second message.
  • the next hop of the network device in the path is the first resource pool. Therefore, the network device sends the first message and the second message to the first service device corresponding to the first resource pool based on the first node information.
  • the service device of this method When the service device of this method receives different messages including different user identifiers, it can determine the value-added services corresponding to the different messages based on the user identifiers. This enables the same resource pool to provide multi-user value-added services without creating many sub-interfaces between network devices and service devices. Instead, messages from different users can be received directly through the same interface, and the service device can receive messages based on the messages. The user ID carried in the document is used to map the value-added services corresponding to different users. Therefore, this method simplifies the deployment of sub-interfaces in the resource pool, and there is no need to distinguish between different sub-interfaces of the same resource pool during path orchestration, which reduces the computational difficulty of path orchestration.
  • the first service device determines the value-added service corresponding to the first user ID based on the one-to-one correspondence between multiple IDs and multiple value-added services, and uses the value-added service corresponding to the first user ID as The first value-added service corresponding to the first message; similarly, according to the one-to-one correspondence between multiple identifiers and multiple value-added services, the value-added service corresponding to the second user identifier is determined, and the value-added service corresponding to the second user identifier is regarded as The second value-added service corresponding to the second message.
  • the one-to-one correspondence between multiple identifiers and multiple value-added services accurate mapping of value-added services for messages from different users is achieved, making the provided value-added services more accurate.
  • the first service device determines the first value-added service corresponding to the first message in the first resource pool according to the first user identification, it calls the resource corresponding to the first value-added service to apply the first value-added service to the first message.
  • Perform value-added service processing after determining the second value-added service corresponding to the second message in the first resource pool according to the second user identification, call the resources corresponding to the second value-added service to perform value-added service processing on the second message.
  • the first message after performing value-added service processing on the first message, when the second node information in the first message indicates the second resource pool, and the second node information is used to indicate the first message corresponding to the next hop in the forwarding path, the first message is also sent to the second service device corresponding to the second resource pool; similarly, after performing value-added service processing on the second message, when based on the second message
  • the third node information in indicates the third resource pool, and the third node information is used to indicate the next hop in the forwarding path corresponding to the second message
  • the second message is sent to the third service device corresponding to the third resource pool.
  • the first message and the second message are SRv6 messages
  • the first node information is the SID of the first resource pool.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • a message forwarding method includes: obtaining multiple optional service chain paths and sending the multiple optional service chain paths to the network device.
  • any optional service chain path includes node information of at least one resource pool that any optional service chain path passes through, and the plurality of optional service chain paths include a first service link path corresponding to the first message and a second message.
  • the second service link path corresponding to the message the first node information included in the first service link path is used to indicate the next hop of the network device in the forwarding path corresponding to the first message, and the first node information included in the second service link path It is used to indicate the next hop of the network device in the forwarding path corresponding to the second message, and the first node information indicates the first resource pool. Therefore, the network device can forward the first message according to the first service link path among the plurality of optional service chain paths, and forward the second message according to the second service link path among the plurality of optional service chain paths.
  • the resource pool is directly used as a forwarding node for path orchestration. There is no need to distinguish different sub-interfaces of the same resource pool, which reduces the computational difficulty of path orchestration.
  • control device can obtain the SIDs corresponding to multiple resource pools; then the control device can perform path orchestration according to the SIDs corresponding to the multiple resource pools to obtain multiple optional service chain paths, any of which The node information of at least one resource pool included in the optional service chain path is the SID corresponding to at least one resource pool.
  • a message forwarding method includes: the network device obtains a first message and a second message, the first message includes a first user identifier, and the second message includes a second user identifier, The first user identity is different from the second user identity; the network device indicates the first resource pool based on the first node information in the first message, and sends the first message to the first service device corresponding to the first resource pool.
  • the first node The information is used to indicate the next hop in the forwarding path corresponding to the first message; indicating the first resource pool based on the first node information in the second message, and sending the second message to the first service device corresponding to the first resource pool.
  • the first node information is used to indicate the next hop in the forwarding path corresponding to the second message; the first service device receives the first message and the second message sent by the network device; the first service device receives the first message according to the first user
  • the identification determines the first value-added service corresponding to the first message in the first resource pool, and determines the second value-added service corresponding to the second message in the first resource pool according to the second user identifier.
  • the control device obtains multiple optional service chain paths, and any optional service chain path includes node information of at least one resource pool that any optional service chain path passes through.
  • the link path includes a first service link path corresponding to the first message and a second service link path corresponding to the second message.
  • the first node information included in the first service link path is used to indicate the forwarding path corresponding to the first message.
  • the next hop of the network device the first node information included in the second service link path is used to indicate the next hop of the network device in the forwarding path corresponding to the second message, and the first node information indicates the first resource pool;
  • the control device sends
  • the network device sends multiple optional service chain paths, and the multiple optional service chain paths are used by the network device to obtain the first service chain path and the second service chain path.
  • a message forwarding device applied to network equipment, and the device includes:
  • An acquisition module configured to acquire a first message and a second message.
  • the first message includes a first user identifier
  • the second message includes a second user identifier
  • the first user identifier is different from the second user identifier
  • a sending module configured to indicate the first resource pool based on the first node information in the first message, and send the first message to the first service device corresponding to the first resource pool, where the first node information is used to indicate the first message.
  • the next hop in the corresponding forwarding path the first user identity included in the first message is used by the first service device to determine the value-added service corresponding to the first message in the first resource pool; based on the third message in the second message
  • a node information indicates a first resource pool, and a second message is sent to the first service device corresponding to the first resource pool.
  • the first node information is used to indicate the next hop in the forwarding path corresponding to the second message.
  • the second message text included is used by the first service device to determine the value-added service corresponding to the second message in the first resource pool.
  • the first message further includes a first service link path corresponding to the first message, and the first service link path includes node information of at least one resource pool through which the first service link path passes, and the second The message also includes a second service chain path corresponding to the second message.
  • the second service chain path includes node information of at least one resource pool through which the second service link path passes.
  • the node information of at least one resource pool includes the first node information.
  • the acquisition module is configured to receive the third message, obtain the first service link path corresponding to the third message, perform tunnel encapsulation on the third message, and obtain the first message.
  • the message includes the first service chain path; receives the fourth message, obtains the second service chain path corresponding to the fourth message, performs tunnel encapsulation on the fourth message to obtain the second message, and the second message includes the second Service chain path;
  • the first service chain path includes node information of at least one resource pool that the first service chain path passes through, and the second service chain path includes node information of at least one resource pool that the second service chain path passes through, and at least one resource pool
  • the node information includes the first node information.
  • the third message further includes a first service identifier
  • the fourth message further includes a second service identifier
  • An acquisition module configured to determine an optional service chain path corresponding to the first service identifier among multiple optional service chain paths, and use the optional service chain path corresponding to the first service identifier as the first service chain corresponding to the third message. path;
  • An acquisition module configured to determine an optional service chain path corresponding to the second service identifier among multiple optional service chain paths, and use the optional service chain path corresponding to the second service identifier as the second service chain corresponding to the fourth message. path.
  • the device further includes:
  • the receiving module is configured to receive multiple optional service chain paths sent by the first control device, and any optional service chain path includes node information of at least one resource pool through which any optional service chain path passes.
  • the first service identifier and the second service identifier are application identifiers
  • the first service identifier is carried in the APN identifier included in the first message
  • the second service identifier is carried in the APN identifier included in the second message.
  • APN logo
  • the first message and the second message are SRv6 messages
  • the first node information is the SID of the first resource pool.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • a message forwarding device applied to the first service device, and the device includes:
  • a receiving module configured to receive a first message and a second message sent by a network device.
  • the first message includes a first user identifier
  • the second message includes a second user identifier
  • the first node information in the first message Indicate that the next hop of the network device in the forwarding path of the first message is the first resource pool
  • the first node information in the second message indicates that the next hop of the network device in the forwarding path of the second message is the first resource. pool
  • Determining module configured to determine the first value-added service corresponding to the first message in the first resource pool according to the first user identification, and determine the second value-added service corresponding to the second message in the first resource pool according to the second user identification.
  • the determining module is configured to determine the value-added service corresponding to the first user identification according to the one-to-one correspondence between the plurality of identifications and the plurality of value-added services, and assign the value-added service corresponding to the first user identification to As the first value-added service corresponding to the first message; according to the one-to-one correspondence between multiple identifiers and multiple value-added services, determine the value-added service corresponding to the second user identifier, and use the value-added service corresponding to the second user identifier as the second value-added service.
  • the second value-added service corresponding to the message is configured to determine the value-added service corresponding to the first user identification according to the one-to-one correspondence between the plurality of identifications and the plurality of value-added services, and assign the value-added service corresponding to the first user identification to As the first value-added service corresponding to the first message; according to the one-to-one correspondence between multiple identifiers and multiple value-a
  • the device further includes:
  • a sending module configured to indicate the second resource pool based on the second node information in the first message, and send a message to the corresponding node of the second resource pool.
  • the second service device sends the first message, and the second node information is used to indicate the next hop in the forwarding path corresponding to the first message; based on the third node information in the second message, the third resource pool is indicated to the third resource pool.
  • the third service device corresponding to the three resource pools sends the second message, and the third node information is used to indicate the next hop in the forwarding path corresponding to the second message.
  • the device further includes:
  • the processing module is configured to call resources corresponding to the first value-added service to perform value-added service processing on the first message, and call resources corresponding to the second value-added service to perform value-added service processing on the second message.
  • the first message and the second message are SRv6 messages
  • the first node information is the SID of the first resource pool.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • a message forwarding device applied to control equipment, and the device includes:
  • the first acquisition module is used to acquire multiple optional service chain paths.
  • Any optional service chain path includes node information of at least one resource pool that any optional service chain path passes through.
  • the multiple optional service chain paths include the third A first service link path corresponding to a message and a second service link path corresponding to a second message.
  • the first node information included in the first service link path is used to indicate the downstream network device in the forwarding path corresponding to the first message.
  • One hop, the first node information included in the second service link path is used to indicate the next hop of the network device in the forwarding path corresponding to the second message, and the first node information indicates the first resource pool;
  • a sending module configured to send multiple optional service chain paths to the network device.
  • the network device is configured to forward the first message according to the first service link path among the multiple optional service chain paths.
  • the second packet is forwarded along the second service chain path.
  • the device further includes:
  • the second acquisition module is used to obtain the SIDs corresponding to multiple resource pools
  • the first acquisition module is used to arrange paths according to the SIDs corresponding to multiple resource pools, and obtain multiple optional service chain paths.
  • the node information of at least one resource pool included in any optional service chain path is at least one resource pool.
  • the corresponding SIDs respectively.
  • a network device in an eighth aspect, includes: a processor, the processor is coupled to a memory, and at least one program instruction or code is stored in the memory. The at least one program instruction or code is generated by the The processor is loaded and executed, so that the network device implements the message forwarding method described in any one of the first aspect, the second aspect, or the third aspect.
  • processors there are one or more processors and one or more memories.
  • the memory may be integrated with the processor, or the memory may be provided separately from the processor.
  • the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor, or can be set in different On the chip, this application does not limit the type of memory and the arrangement of the memory and the processor.
  • ROM read-only memory
  • a communication device which includes: a transceiver, a memory, and a processor.
  • the transceiver, the memory and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals.
  • the communication device is caused to execute the method in the first aspect or any possible implementation of the first aspect, or to execute the second aspect or any one of the second aspects.
  • method in any possible implementation manner, or perform the third aspect or the method in any possible implementation manner of the third aspect, or perform the fourth aspect or the fourth aspect. method in any possible implementation above.
  • a message forwarding system including a network device, a first service device, and a control device;
  • the network device is configured to perform the method described in the first aspect or any possible implementation of the first aspect
  • the first service device is configured to perform the second aspect or any one of the second aspects.
  • the method described in any possible implementation manner the control device is configured to execute the method described in the third aspect or any possible implementation manner of the third aspect.
  • a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the instruction is loaded and executed by a processor, so that the computer implements the above-mentioned first aspect or any of the first aspects.
  • a method in a possible implementation, or a method in realizing the above second aspect or any possible implementation of the second aspect, or realizing the above third aspect or any possible implementation of the third aspect The method in , or implement the method in the above fourth aspect or any possible implementation of the fourth aspect.
  • a computer program includes: computer program code.
  • the computer program code When the computer program code is run by a computer, it causes the computer to perform the methods in the above aspects. .
  • a chip including a processor, configured to call from a memory and run instructions stored in the memory, so that a communication device equipped with the chip executes the methods in the above aspects.
  • another chip including: an input interface, an output interface, a processor, and a memory, and the input interface, the output interface, the processor, and the memory are connected through an internal connection path, and the The processor is used to execute the code in the memory.
  • the processor is used to execute the methods in the above aspects.
  • Figure 1 is a schematic diagram of the deployment of resource pools in related technologies provided by embodiments of this application;
  • Figure 2 is a schematic diagram of an implementation environment provided by an embodiment of the present application.
  • Figure 3 is an interactive schematic diagram of a message forwarding method provided by an embodiment of the present application.
  • Figure 4 is a schematic diagram of the deployment of another resource pool provided by an embodiment of the present application.
  • Figure 5 is a schematic structural diagram of a resource pool provided by an embodiment of the present application.
  • Figure 6 is a schematic diagram of a message forwarding process provided by an embodiment of the present application.
  • Figure 7 is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application.
  • Figure 8 is a schematic structural diagram of another message forwarding device provided by an embodiment of the present application.
  • Figure 9 is a schematic structural diagram of another message forwarding device provided by an embodiment of the present application.
  • Figure 10 is a schematic structural diagram of a network device provided by an embodiment of the present application.
  • Figure 11 is a schematic structural diagram of another network device provided by an embodiment of the present application.
  • Figure 12 is a schematic structural diagram of a server provided by an embodiment of the present application.
  • FIG. 1 is a schematic diagram of the deployment of resource pools in related technologies provided by embodiments of the present application.
  • multiple sub-interfaces are created between the network device and the resource pool.
  • One sub-interface corresponds to one user.
  • Each sub-interface includes the corresponding endpoint (END).
  • END endpoint
  • Vsys Furthermore, when arranging the path of forwarded packets, use the END. Users are provided with corresponding value-added services. Among them, Vsys refers to multiple independent logical devices divided on a physical device, and network isolation can be achieved between virtual systems.
  • END.X SID is a type of SID and is used to instruct network devices to forward packets from the outbound interface specified by End.X SID.
  • sub-interface 1 corresponds to user 1
  • the SID of sub-interface 1 is END.X SID1
  • sub-interface 1 is connected to Vsys1.
  • the network device receives the first message sent by the user terminal equipment (customer premise equipment, CPE) of user 1.
  • the forwarding path corresponding to the first message includes END.X SID1, and the END.X SID1 indicates the first message.
  • the next hop is sub-interface 1, then the network device sends the message to Vsys1 through sub-interface 1, and then provides user 1 with value-added services corresponding to user 1 through Vsys1.
  • Sub-interface 2 corresponds to user 2, the SID of sub-interface 2 is END.X SID2, and sub-interface 2 is connected to Vsys2. Then the network device receives the second message sent by the CPE of user 2. The forwarding path corresponding to the second message includes END.X SID2. The END.X SID2 indicates that the next hop of the second message is sub-interface 2. Then the network device sends the second message to Vsys2 through sub-interface 2, and then provides user 2 with value-added services corresponding to user 2 through Vsys2. That is to say, in related technologies, when a network device forwards packets of different users, the next hops corresponding to the packets of different users are different, thereby achieving the effect of providing different value-added services to different users.
  • the embodiment of the present application provides a message forwarding method.
  • this method does not need to distinguish between different sub-interfaces when forwarding messages of different users to the resource pool, and directly forwards the corresponding messages to the resource pool.
  • the service device sends the message, and the service device determines the value-added services corresponding to different users in the resource pool through the different user identifiers carried in the message. Therefore, this method does not need to create many sub-interfaces between the network device and the resource pool, and simplifies the configuration of the resource pool.
  • path orchestration for multiple users in the same resource pool, there is no need to orchestrate different forwarding paths for different users based on different sub-interfaces, which reduces the computational difficulty of path orchestration.
  • the implementation environment includes CPE, network equipment, resource pools, first control equipment and second control equipment.
  • the CPE and the network device, the network device and the resource pool, and the first control device and the second control device communicate with each other.
  • the first control device is used to control the CPE and network equipment, for example, deliver an orchestrated forwarding path to the CPE and network equipment.
  • the second control device is used to control the resource pool, for example, deliver a corresponding SID to the resource pool, and a one-to-one correspondence between multiple business identifiers and multiple value-added services.
  • the embodiments of this application do not limit the number of network devices and resource pools.
  • the first control device and the second control device may be deployed on the same physical device, or may be deployed on different physical devices.
  • the network device may be at least one of a provider edge (provider edge, PE) device, a provider (provider, P) device, a network PE device, or a cloud PE device.
  • the resource pool can be a physical device or a cloud device. When the resource pool is a cloud device, the resource pool can also be called a cloud resource pool.
  • Both the first control device and the second control device may be network control engines (network control engines, NCE).
  • the packet forwarding method provided by the embodiment of the present application can be applied in the implementation environment shown in Figure 2. Taking network equipment and resource pools as examples, the packet forwarding method provided by the embodiment of the present application is explained. Among them, one resource pool corresponds to one service device, and the service device is the execution subject corresponding to the resource pool. That is, the resource pool executes the message forwarding method provided by the embodiment of the present application through the corresponding service device. For example, referring to Figure 3, the message forwarding method includes the following steps 301 to 303.
  • Step 301 The network device obtains a first message and a second message.
  • the first message includes a first user identity
  • the second message includes a second user identity
  • the first user identity and the second user identity are different.
  • the network device refers to the previous hop network device that enters the resource pool of the security network in the forwarding path of the first message and the second message.
  • the network device refers to the previous hop network device that enters the resource pool of the security network in the forwarding path of the first message and the second message.
  • a secure network refers to a network that includes resource pools.
  • the first message may carry a first user identification, and the first user identification is used to distinguish different value-added services corresponding to the user corresponding to the first user identification and other users.
  • the operator configures corresponding user IDs for different users and sends the configured user IDs to the CPE used by the corresponding users. Then the CPE can obtain the user IDs of different users and carry the user IDs in the first message. middle.
  • the first message received by the network device may be the first message sent by CPE1, which is the head node on the forwarding path of the first message
  • the second message received by the network device may be the first message sent by CPE2.
  • CPE2 is the head node on the forwarding path of the second packet.
  • CPE1 is the terminal used by user 1
  • CPE2 is the terminal used by user 2.
  • CPE1 can rent value-added services from the operator through CPE1.
  • the operator will arrange packet forwarding paths for different value-added services of CPE1 and deliver them to CPE1.
  • CPE1 can transmit the corresponding message according to the corresponding forwarding path.
  • CPE1 sends the first message to the network device according to the forwarding path, and then the network device receives the first message.
  • CPE1 sends the first message to the network device according to the forwarding path.
  • CPE1 sends the first message to the network device through at least one intermediate node in the forwarding path.
  • the forwarding path is arranged by a control device, which may be the first control device shown in FIG. 2 .
  • the first control device uses multiple resource pools included in the security network as forwarding nodes, performs end-to-end path orchestration for multiple different value-added services, obtains multiple optional service chain paths, and then sends the multiple optional service chain paths to the PCE.
  • optional service chain path Among them, different value-added services correspond to different service identifiers, and one optional service chain path corresponds to one service identifier. This enables the CPE to obtain forwarding paths corresponding to different value-added services.
  • the path orchestration directly uses the resource pool as the forwarding node, instead of using different sub-interfaces connected to the resource pool on the network device as the forwarding node in the related technology, for different users going to the same resource pool, For the first message and the second message, the next hop indicated by the forwarding path corresponding to the first message and the second message is the same and both are the first resource pool.
  • the network device obtains the first packet and the second packet The methods include but are not limited to the following two.
  • Method 1 Receive the first message and the second message.
  • the first message also includes the first service chain path corresponding to the first message.
  • the first service chain path includes node information of at least one resource pool through which the first service chain path passes.
  • the second message also includes the second message corresponding to the first service link path.
  • the second service chain path includes node information of at least one resource pool through which the second service chain path passes, and the node information of at least one resource pool includes the first node information.
  • the first message carries the first node information through the included first service link path
  • the second message carries the first node information through the included second service link path.
  • the first service link path carried in the first message is encapsulated by the head node
  • the second service link path carried in the second message is encapsulated by the head node.
  • the head node CPE1 when sending the first message, performs tunnel encapsulation on the first message, so that the first message can carry the first message according to the tunnel encapsulated message header.
  • the end-to-end service chain path corresponding to the document.
  • the end-to-end service chain path includes an end-to-end forwarding path starting from the CPE, where the forwarding path after entering the resource pool in the end-to-end service chain path is the first service chain path in the embodiment of this application. That is, the end-to-end service chain path includes node information of at least one network device and node information of at least one resource pool, and the first service chain path includes node information of at least one resource pool.
  • the network device identifies the first service link path included in the first message.
  • the network device determines to send the first message to the first service device corresponding to the first resource pool.
  • the network device identifies the second service link path included in the second message.
  • the network device determines to also send the second message to the first service device corresponding to the first resource pool.
  • the first message and the second message may be SRv6 messages.
  • the node information of at least one network device and the node information of at least one resource pool in the end-to-end service chain path are, The SID of at least one network device and the SID of at least one resource pool.
  • the embodiment of this application does not limit the type of SID, which can be END SID or END.X SID.
  • the second control device allocates corresponding SIDs to multiple network devices included in the communication network and multiple resource pools included in the security network, and then the second control device sends multiple network devices to the first control device.
  • the first control device receives the SIDs corresponding to multiple network devices and multiple resource pools sent by the second control device, and performs path orchestration based on the SIDs corresponding to the multiple network devices and multiple resource pools to obtain multiple optional Business chain path.
  • any optional service chain path indicates that the next hop is any resource pool through the SID of the corresponding resource pool.
  • Method two receive the third message, obtain the first service chain path corresponding to the third message, perform tunnel encapsulation on the third message, and obtain the first message.
  • the first message includes the first service chain path; receive the first service chain path corresponding to the third message.
  • four messages obtain the second service chain path corresponding to the fourth message, perform tunnel encapsulation on the fourth message, and obtain the second message, and the second message includes the second service chain path.
  • the first service chain path includes node information of at least one resource pool that the first service chain path passes through
  • the second service chain path includes node information of at least one resource pool that the second service chain path passes through
  • the nodes of at least one resource pool The information includes first node information. Therefore, the first message carries the first node information through the encapsulated first service link path, and the second message carries the first node information through the encapsulated second service link path. It can be understood that the first message is obtained by encapsulating the first service chain path of the third message, then the first service chain path corresponding to the first message and the first service chain path corresponding to the second message are the same.
  • the received third message does not carry the corresponding first service chain path entering the resource pool
  • the received fourth message does not carry the corresponding second service chain path entering the resource pool.
  • the network The device is also the previous hop device for the third message and the fourth message to enter the resource pool. Therefore, after receiving the third message and the fourth message, the network device needs to obtain the third message and the fourth message respectively.
  • the corresponding service chain path entering the resource pool is used to encapsulate the first message corresponding to the third message and the second message corresponding to the fourth message.
  • the embodiment of the present application does not limit the method of obtaining the service chain path entering the resource pool.
  • the third message also carries a first service identifier
  • the fourth message also carries a second service identifier.
  • the first service identifier and the second service identifier are used to distinguish different value-added services.
  • the first service identifier and the second service identifier may be application identifiers or differentiated services code point (DSCP) identifiers.
  • DSCP differentiated services code point
  • the different application identifiers are used to distinguish different applications, and then use different application identifiers to restrict which applications need to enter the value-added service chain; when the first service identifier
  • the second service identifier is a different DSCP identifier
  • the different DSCP identifiers are used to distinguish different quality levels, and then the different DSCP identifiers are used to restrict which quality levels need to enter the value-added service chain.
  • the value-added service chain refers to the service chain on the end-to-end forwarding path that includes the resource pool as the forwarding node.
  • the first service chain path and the second service chain path The need to enter the value-added service chain refers to the need to enter the resource The pool performs corresponding value-added service processing.
  • the third message when CPE1 sends the third message, it also carries the first service identifier in the third message, and when CPE2 sends the fourth message, The second service identifier is also carried in the fourth message.
  • the third packet does not carry the first service chain path
  • the head node CPE1 also tunnel-encapsulates the third packet, but the third packet carries the third packet according to the tunnel-encapsulated packet header.
  • the forwarding path from the corresponding CPE1 to before entering the resource pool does not include the forwarding path of the first service chain after entering the resource pool.
  • the network device needs to identify the first service identifier in the third message, and determine whether the third message needs to enter the value-added service chain based on the identified first service identifier.
  • the first service chain path corresponding to the third packet entering the resource pool is obtained.
  • the third message since the network device is the previous hop network device entering the resource pool, the third message has been transmitted in the communication network and starts to enter the security network from this network device, that is, it enters the value-added service chain. Therefore, the first service link path obtained by the network device includes node information of at least one resource pool and no longer includes node information of the network device in the communication network. For example, the first node information of the first service link path corresponding to the third message is the node information of the first resource pool.
  • the first control device after performing path orchestration to obtain multiple optional service chain paths, the first control device also sends the multiple optional service chain paths to the network device.
  • the network device can obtain the multiple optional service chain paths and the application identifier corresponding to each optional service chain path.
  • the network device can determine the optional service chain path corresponding to the first service identifier among the multiple optional service chain paths, and combine the optional service chain paths corresponding to the first service identifier. The path is used as the first service chain path corresponding to the third message.
  • the network device can determine the optional service link path corresponding to the second service identifier among multiple optional service chain paths, and combine the optional service link paths corresponding to the second service identifier with the The service chain path is used as the second service chain path corresponding to the fourth message.
  • the obtained first message carries the first service chain path
  • the second message carries the second service chain path, so that the forwarding node that subsequently receives the first message, such as the first
  • the service device can forward the first message according to the first service link path corresponding to the first message, so that the forwarding node that subsequently receives the second message, such as the first service device, can forward the first message according to the second message corresponding to the second message.
  • the service chain path forwards the second message.
  • Step 302 The network device indicates the first resource pool based on the first node information in the first message, and sends the first message to the first service device corresponding to the first resource pool; based on the first node information in the second message Instruct the first resource pool to send the second message to the first service device corresponding to the first resource pool.
  • the first node information is used to indicate the next hop of the network device in the forwarding path
  • the first node information in the first message is used to indicate the next hop in the forwarding path corresponding to the first message
  • the second message The first node information in the text is used to indicate the next hop in the forwarding path corresponding to the second message. Therefore, the next hop of the forwarding path for the first packet and the second packet including different user identities is the same as the first resource pool, that is, the forwarding behavior of the network device for different users can be the same, and there is no need to Different users deploy different sub-interfaces.
  • the network device After obtaining the first message and the second message, it can be seen from the above-mentioned methods one and two of obtaining the first message and the second message that the first message and the second message carry the first node information. , and the first node information is used to indicate that the next hop of the network device is the first resource pool. And because the first service device is the execution subject corresponding to the first resource pool, when the next hop indicated by the forwarding path is the first resource pool, the network device can determine to send to the first service device corresponding to the first resource pool.
  • the first user ID and the first application ID may be carried in the first packet.
  • the APN identifier is configured as a first field and a second field, the first field is used to carry the first application identifier, and the second field is used to carry the first service identifier.
  • the APN in the embodiment of this application may be an IPv6-based application-aware network APN6.
  • the APN identifier can be carried in an IPv6 packet header or an IPv6 extension header.
  • the APN identifier is encapsulated in an IPv6 packet header or an IPv6 extension header in the form of a TLV field.
  • this embodiment of the present application since packet forwarding can be realized without distinguishing different sub-interfaces between the network device and the first resource pool, the configuration of the resource pool is simplified.
  • this embodiment of the present application creates a main interface between the network device and the first resource pool, and the network device sends messages carrying different user identities to the first service device corresponding to the first resource pool through the main interface. message.
  • one resource pool corresponds to one SID, instead of one sub-interface of one user on the resource pool corresponding to one SID, which simplifies the SID configuration operation.
  • the SID type of the resource pool can be END SID, which is used to instruct the network device to forward packets by searching the IPv6 routing table.
  • one resource pool can also correspond to multiple SIDs for load sharing. For example, for the total number of users in the same resource pool, the total user load is distributed to multiple SIDs.
  • the first number of users corresponds to the first SID of the resource pool
  • the second number of users corresponds to the second SID of the resource pool.
  • SID, the first quantity and the second quantity are both greater than 1.
  • each SID also corresponds to multiple users, instead of one sub-interface corresponding to one user in the related technology, which can also effectively simplify the deployment of resource pools.
  • Step 303 The first service device receives the first message and the second message sent by the network device, and determines the first value-added service corresponding to the first message in the first resource pool according to the first user identification in the first message. , determining the value-added service corresponding to the first message in the first resource pool according to the first user identifier in the second message.
  • the second control device configures a one-to-one correspondence between multiple identifiers and multiple value-added services for each resource pool, and the second control device sends multiple configured service devices to the service device corresponding to each resource pool.
  • the second control device configures a one-to-one correspondence between multiple identifiers and multiple value-added services for the first resource pool, and sends a one-to-one correspondence between the multiple identifiers and multiple value-added services to the first service device corresponding to the first resource pool.
  • the first service device determines the value-added service corresponding to the first user identifier included in the first message according to the one-to-one correspondence between the multiple identifiers and the multiple value-added services, and compares the value-added service with the first user identifier included in the first message.
  • the value-added service corresponding to the user ID is used as the first value-added service corresponding to the first message.
  • the first service device determines the value-added service corresponding to the second user identifier included in the second message based on the one-to-one correspondence between the multiple identifiers and the multiple value-added services, and compares the value-added service with the second user identifier included in the second message.
  • the value-added service corresponding to the identification is used as the second value-added service corresponding to the second message.
  • the resource pool can also map different value-added services according to different first user IDs and second user IDs.
  • the resource pool can also implement value-added service processing for multiple users without creating multiple sub-interfaces.
  • the first service device determines the first value-added service corresponding to the first message in the first resource pool based on the first user identification, and determines the first value-added service corresponding to the second message in the first resource pool based on the second user identification.
  • the second value-added service realizes the mapping of different value-added services.
  • the first service device can call the resources corresponding to the first value-added service to perform value-added service processing on the first message, and call the resources corresponding to the second value-added service to perform value-added service processing on the second message.
  • the one-to-one correspondence between multiple user identifiers and multiple value-added services may be as shown in Table 1.
  • Table 1 shows three user identifications and the value-added services corresponding to each user identification.
  • the value-added services include firewall (FW), intrusion prevention system (intrusion prevention system, IPS) or web application firewall (web application firewall). WAF) at least one.
  • the value-added service may correspond to the Vsys connected to each sub-interface shown in Figure 1 .
  • the security resource pool corresponding to the cloud security pool may include high-speed business chain orchestration, routers and multiple value added services (VAS). ), among which, high-speed service chain orchestration is used to orchestrate paths for different value-added services, and router is used to support SRv6 forwarding capabilities and provide the ability to identify different users based on APN identities.
  • each VAS includes n (n is a positive integer) FWs, IPSs or WAFs, and the FWs, IPSs or WAFs are used to process the first packet for value-added services.
  • the first service device corresponding to the first resource pool may be a router.
  • the router processes the first message as follows: sending the first message to FW1 in VAS1, and FW1 processes the first message. Perform value-added service processing, and then send the first message to IPS2 in VAS2.
  • IPS2 will perform value-added service processing on the first message.
  • the first message will be forwarded to the next forwarding node according to the service chain path. Forward.
  • the first service device when the first service device performs processing on the first packet based on the corresponding first value-added service is processed, the first service device indicates that the next hop of the forwarding path of the first message is the second node information based on the first service link path included in the first message, and the second node information indicates the second resource pool, Send the first message to the second service device corresponding to the second resource pool.
  • the first service device instructs the forwarding of the second message based on the second service link path included in the second message.
  • the next hop of the path is the third node information
  • the third node information indicates the third resource pool
  • the second message is sent to the third service device corresponding to the third resource pool.
  • the second resource pool and the third resource pool may be the same resource pool or different resource pools.
  • the message forwarding method provided by the embodiments of this application does not require the creation of many sub-interfaces between network devices and service devices when the same resource pool provides value-added services for multiple users, and can directly send messages of different users.
  • the service equipment can map the value-added services corresponding to different users according to the user ID carried in the message. Therefore, this method simplifies the deployment of sub-interfaces in the resource pool, and there is no need to distinguish between different sub-interfaces of the same resource pool during path orchestration, which reduces the computational difficulty of path orchestration.
  • the first message is an SRv6 message
  • the service identifier is an application identifier
  • the user identifier and application identifier are carried in the APN identifier of the first message.
  • FIG. 6 is a schematic diagram of a message forwarding process provided by an embodiment of the present application.
  • the implementation environment includes the cloud network security business orchestration system, NCE-IP, NCE-campus, CPE, cloud security pool, intelligent metropolitan area network and cloud backbone.
  • the network PE device corresponds to the execution subject network device in the embodiment of the present application
  • the NCE-IP corresponds to the first control device in the embodiment of the present application
  • the NCE-campus corresponds to the second control device in the embodiment of the present application
  • cloud security Pool 1 corresponds to the first security resource pool in the embodiment of this application
  • cloud security pool 2 corresponds to the second security resource pool in the embodiment of this application.
  • the cloud network security business orchestration system can be integrated into the operator's business orchestrator, providing administrator and user operation and maintenance interfaces, and is responsible for the end-to-end orchestration of security services.
  • the northbound interface (northbound interface) can refer to a lower-level device connecting to a higher-level interface, through which the lower computer can be read and controlled; on the contrary, the southbound interface (southbound interface) refers to a higher-level device.
  • the high-level connection interface to the lower-level equipment can realize transmission and communication to the upper computer through the southbound interface.
  • the difference between south and north lies in the different positions of the system structure, which is usually agreed to be upper north and lower south.
  • the cloud network security business orchestration system is connected to NCE-IP and NCE-campus in the south direction, which means that the cloud network security business orchestration system is connected downward to NCE-IP and NCE-campus.
  • NCE-IP includes the service chain traffic diversion function and is responsible for the management, control and analysis of the bearer network.
  • NCE-IP adds end-to-end SRv6 policy (Policy) path orchestration for network devices and security resource pools, that is, the security resource pool is used as a forwarding node in the path.
  • Policy SRv6 policy
  • the northbound connection is to the cloud network security business orchestration system, and the southbound connection is to the intelligent metropolitan area network and cloud backbone network equipment.
  • SRv6Policy can realize the end-to-end requirements of the business and is the main mechanism for realizing SRv6 network programming.
  • NCE-campus includes functions such as network management, security management, and resource allocation. Security management is responsible for managing security resource pools.
  • NCE-campus adds the deployment of SID of the security resource pool, template deployment of user identification (USRID) in APN identification (ID), USRID Deployment of corresponding relationships with security services.
  • USRID user identification
  • ID APN identification
  • the northbound connection is to the operator's cloud network security business orchestration system, and the southbound connection is to the security resource pool.
  • NCE-campus deploys storage resource pool (SRP) 1 SID for cloud security pool 1 and deploys SRP2 SID for cloud security pool 2.
  • SRP storage resource pool
  • NCE-IP uses SRP1 SID and SRP2 SID as forwarding nodes for path orchestration, obtains a secure service chain path, and delivers the secure service chain path to CPE and network PE equipment.
  • Security resource pool (also called cloud security pool) is used for security business processing.
  • the security resource pool supports SRv6 SID deployment, SRv6 message forwarding capability, identification of USRID in APNID, and mapping of USRID and security services.
  • the security resource pool is connected to NCE-campus in the north direction, and the security resource pool is managed and controlled by NCE-campus.
  • cloud security pool 1 includes VAS1 and VAS2
  • cloud security pool 2 includes VAS3.
  • the intelligent metropolitan area network includes multiple metro access routers (MER), multiple metro edge routers (MER), and multiple metro core routers (MCR).
  • the cloud The backbone includes multiple PE devices, network PE devices, cloud PE devices, P devices, etc.
  • the CPE generates an SRv6 message, and the SRv6 message includes a payload.
  • CPE carries APNID in SRv6 messages.
  • APNID includes APPID and USRID
  • CPE encapsulates segment routing header (SRH) through SRv6 tunnel.
  • SRH includes MAR2 SID, MER1 SID, and MCR2 SID from bottom to top.
  • network PE SID and network PE VPN SID then MAR2 SID, MER1 SID, MCR2 SID, network PE SID and network PE VPN SID are the node information on the service chain forwarding path.
  • the CPE indicates that the next hop is MAR2 based on the MAR2 SID included in the SRH, and then sends the SRv6 message to MAR2. Then, the SRv6 packets pass through the intelligent metropolitan area network from MAR2, MER1, and MCR2 to reach the network PE equipment. During the transmission process, the SRv6 packets carry the APNID, so that the APN service travels with the packets.
  • the network PE device after receiving the SRv6 message, the network PE device automatically enters the secure service chain by identifying the APPID in the message.
  • the network PE device obtains the secure service chain forwarding path corresponding to the APPID and changes the SRH encapsulated in the SRv6 message to the secure service chain forwarding path, that is, the SRH includes SRP2 SID, SRP1 SID, cloud PE SID, and cloud PE VPN SID.
  • the network PE device indicates that the next hop is cloud security pool 1 based on the SRP2 SID included in the SRH, and then sends the SRv6 message to cloud security pool 1.
  • cloud security pool 1 After receiving the SRv6 message, cloud security pool 1 identifies the USRID in the SRv6 message, maps the corresponding security service based on the USRID, and then performs complete business processing on the SRv6 message based on the mapped security service. After that, cloud security pool 1 indicates that the next hop is cloud security pool 2 based on the SRP1 SID included in the SRH, and then sends the SRv6 message to cloud security pool 2.
  • APNID carries APPID and USRID, and then enters the security service chain according to APPID, and maps the corresponding security service according to USRID, realizing the decoupling of network and security services, effectively solving It solves the complex problem of sub-interface deployment between network devices and resource pools.
  • FIG. 7 is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application.
  • the device is applied to a first network device, and the first network device is the network device shown in FIG. 3 above.
  • the message forwarding device shown in Figure 7 can perform all or part of the operations performed by the network device. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown therein, and the embodiments of the present application are not limited to this.
  • the device includes:
  • Obtaining module 701 is used to obtain a first message and a second message.
  • the first message includes a first user identifier
  • the second message includes a second user identifier
  • the first user identifier is different from the second user identifier;
  • the sending module 702 is configured to indicate the first resource pool based on the first node information in the first message, and send the first message to the first service device corresponding to the first resource pool.
  • the first node information is used to indicate the first message.
  • the next hop in the forwarding path corresponding to the text The first user identity included in the first message is used by the first service device to determine the value-added service corresponding to the first message in the first resource pool; based on the first node information in the second message, the first resource pool is indicated to The first service device corresponding to the first resource pool sends the second message, the first node information is used to indicate the next hop in the forwarding path corresponding to the second message, and the second user identification included in the second message is used for the second message.
  • a service device determines the value-added service corresponding to the second message in the first resource pool.
  • the first message further includes a first service link path corresponding to the first message, and the first service link path includes node information of at least one resource pool through which the first service link path passes, and the second The message also includes a second service chain path corresponding to the second message.
  • the second service chain path includes node information of at least one resource pool through which the second service link path passes.
  • the node information of at least one resource pool includes the first node information.
  • the obtaining module 701 is configured to receive the third message, obtain the first service chain path corresponding to the third message, tunnel encapsulate the third message, and obtain the first message, and the third message.
  • a message includes the first service chain path; receives the fourth message, obtains the second service chain path corresponding to the fourth message, performs tunnel encapsulation on the fourth message, and obtains the second message; the second message includes the Two service chain paths; the first service chain path includes node information of at least one resource pool that the first service chain path passes through, the second service chain path includes node information of at least one resource pool that the second service chain path passes through, and at least one resource The node information of the pool includes first node information.
  • the third message further includes a first service identifier
  • the fourth message further includes a second service identifier
  • the acquisition module 701 is configured to determine an optional service chain path corresponding to the first service identifier among multiple optional service chain paths, and use the optional service chain path corresponding to the first service identifier as the first service corresponding to the third message. chain path;
  • the acquisition module 701 is configured to determine an optional service chain path corresponding to the second service identifier among multiple optional service chain paths, and use the optional service chain path corresponding to the second service identifier as the second service corresponding to the fourth message. chain path.
  • the device further includes:
  • the receiving module is configured to receive multiple optional service chain paths sent by the first control device, and any optional service chain path includes node information of at least one resource pool through which any optional service chain path passes.
  • the first service identifier and the second service identifier are application identifiers
  • the first service identifier is carried in the APN identifier included in the first message
  • the second service identifier is carried in the APN identifier included in the second message.
  • APN logo
  • the first message and the second message are SRv6 messages
  • the first node information is the SID of the first resource pool.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • Figure 8 is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application.
  • the device is applied to a first service device.
  • the first service device is the first service device shown in Figure 3 above.
  • the message forwarding device shown in Figure 8 can perform all or part of the operations performed by the first service device. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown therein, and the embodiments of the present application are not limited to this.
  • the device includes:
  • Receiving module 801 configured to receive a first message and a second message sent by a network device.
  • the first message includes a first user identifier
  • the second message includes a second user identifier
  • the first node in the first message The information indicates that the next hop of the network device in the forwarding path of the first message is the first resource pool
  • the first node information in the second message indicates that the next hop of the network device in the forwarding path of the second message is the first resource pool. resource pool;
  • Determining module 802 configured to determine the first value-added service corresponding to the first message in the first resource pool according to the first user identification, Determine the second value-added service corresponding to the second message in the first resource pool according to the second user identification.
  • the determining module 802 is configured to determine the value-added service corresponding to the first user identification based on the one-to-one correspondence between the multiple identifications and the multiple value-added services, and convert the value-added service corresponding to the first user identification to service as the first value-added service corresponding to the first message; according to the one-to-one correspondence between the multiple identifiers and the multiple value-added services, determine the value-added service corresponding to the second user identifier, and use the value-added service corresponding to the second user identifier as the third value-added service.
  • the second value-added service corresponding to the second message is configured to determine the value-added service corresponding to the first user identification based on the one-to-one correspondence between the multiple identifications and the multiple value-added services, and convert the value-added service corresponding to the first user identification to service as the first value-added service corresponding to the first message; according to the one-to-one correspondence between the multiple identifiers and the multiple
  • the device further includes:
  • a sending module configured to indicate the second resource pool based on the second node information in the first message, and send the first message to the second service device corresponding to the second resource pool, where the second node information is used to indicate the first message.
  • the next hop in the corresponding forwarding path; indicating the third resource pool based on the third node information in the second message, sending the second message to the third service device corresponding to the third resource pool, and the third node information is used Indicates the next hop in the forwarding path corresponding to the second packet.
  • the device further includes:
  • the processing module is configured to call resources corresponding to the first value-added service to perform value-added service processing on the first message, and call resources corresponding to the second value-added service to perform value-added service processing on the second message.
  • the first message and the second message are SRv6 messages
  • the first node information is the SID of the first resource pool.
  • the first user identity is carried in the APN identity included in the first message
  • the second user identity is carried in the APN identity included in the second message.
  • Figure 9 is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application.
  • the device is applied to the first control device.
  • the message forwarding device shown in Figure 9 can perform all or part of the operations performed by the control device. It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown therein, and the embodiments of the present application are not limited to this.
  • the device includes:
  • the first acquisition module 901 is used to acquire multiple optional service chain paths.
  • Any optional service chain path includes node information of at least one resource pool through which any optional service chain path passes.
  • the multiple optional service chain paths include The first service link path corresponding to the first message and the second service link path corresponding to the second message.
  • the first node information included in the first service link path is used to indicate the network device in the forwarding path corresponding to the first message.
  • Next hop the first node information included in the second service link path is used to indicate the next hop of the network device in the forwarding path corresponding to the second message, and the first node information indicates the first resource pool;
  • the sending module 902 is configured to send multiple optional service chain paths to the network device.
  • the network device is configured to forward the first message according to the first service link path among the multiple optional service chain paths.
  • the second service link path in the path forwards the second message.
  • the device further includes:
  • the second acquisition module is used to obtain the SIDs corresponding to multiple resource pools
  • the first acquisition module 901 is used to arrange paths according to the SIDs corresponding to multiple resource pools, and obtain multiple optional service chain paths.
  • the node information of at least one resource pool included in any optional service chain path is at least one resource.
  • the message forwarding device provided by the embodiment of the present application can directly send messages of different users without creating many sub-interfaces between network equipment and service equipment when the same resource pool provides value-added services for multiple users.
  • the service equipment can map the value-added services corresponding to different users according to the user ID carried in the message. Therefore, the device simplifies the deployment of sub-interfaces in the resource pool, and there is no need to distinguish between different sub-interfaces of the same resource pool during path orchestration, which reduces the computational difficulty of path orchestration.
  • Figure 10 shows a schematic structural diagram of a network device 2000 provided by an exemplary embodiment of the present application.
  • the network device 2000 shown in Figure 10 is used to perform operations related to the message forwarding method shown in Figure 3.
  • the network device 2000 is, for example, a switch, a router, etc., and the network device 2000 can be implemented by a general bus architecture.
  • the network device 2000 includes at least one processor 2001, a memory 2003, and at least one communication interface 2004.
  • the processor 2001 is, for example, a general central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processor (Graphics Processing Unit, GPU), Neural network processors (neural-network processing units, NPU), data processing units (Data Processing Unit, DPU), microprocessors or one or more integrated circuits used to implement the solution of this application.
  • the processor 2001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a general array logic (GAL), or any combination thereof.
  • the processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.
  • the network device 2000 also includes a bus.
  • Buses are used to transfer information between components of network device 2000.
  • the bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc.
  • PCI peripheral component interconnect
  • EISA extended industry standard architecture
  • the bus can be divided into address bus, data bus, control bus, etc. For ease of presentation, only one line is used in Figure 10, but it does not mean that there is only one bus or one type of bus.
  • the memory 2003 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, or a random access memory (random access memory, RAM) or a device that can store information and instructions.
  • ROM read-only memory
  • RAM random access memory
  • Other types of dynamic storage devices such as electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disk storage, optical discs Storage (including compressed optical discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or can be used to carry or store desired program code in the form of instructions or data structures and can Any other media accessed by a computer, without limitation.
  • the memory 2003 exists independently, for example, and is connected to the processor 2001 through a bus.
  • the memory 2003 may also be integrated with the processor 2001.
  • the communication interface 2004 uses any device such as a transceiver for communicating with other devices or a communication network.
  • the communication network may be an Ethernet, a radio access network (RAN) or a wireless local area networks (WLAN). )wait.
  • the communication interface 2004 may include a wired communication interface and may also include a wireless communication interface.
  • the communication interface 2004 may be an Ethernet (Ethernet) interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, or an Asynchronous Transfer Mode (ATM) interface, a wireless local area networks (WLAN) interface, a cellular network communication interface or a combination thereof.
  • the Ethernet interface can be an optical interface, an electrical interface, or a combination thereof.
  • the communication interface 2004 can be used for the network device 2000 to communicate with other devices.
  • the processor 2001 may include one or more CPUs, such as CPU0 and CPU1 as shown in FIG. 10 .
  • Each of these processors can be a single-core CPU processor or a multi-core CPU processor.
  • a processor here may refer to one or more devices, circuits, and/or processing cores for processing data (eg, computer program instructions).
  • the network device 2000 may include multiple processors, such as the processor 2001 and the processor 2005 shown in FIG. 10 .
  • processors can be a single-core processor (single-core CPU) or a multi-core processor (multi-core CPU).
  • a processor here may refer to one or more devices, circuits, and/or processing cores for processing data (such as computer program instructions).
  • the network device 2000 may also include an output device and an input device.
  • Output devices communicate with processor 2001 and can display information in a variety of ways.
  • the output device may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector (projector), etc.
  • Input devices communicate with processor 2001 and can receive user input in a variety of ways.
  • the input device may be a mouse, a keyboard, a touch screen device or a sensing device, etc.
  • the memory 2003 is used to store the program code 2010 for executing the solution of the present application
  • the processor 2001 can execute the program code 2010 stored in the memory 2003. That is to say, the network device 2000 can implement the message forwarding method provided by the method embodiment through the processor 2001 and the program code 2010 in the memory 2003.
  • Program code 2010 may include one or more software modules.
  • the processor 2001 itself can also store program codes or instructions for executing the solution of the present application.
  • the network device 2000 in the embodiment of the present application may correspond to the first network device in each of the above method embodiments.
  • the processor 2001 in the network device 2000 reads the instructions in the memory 2003, so that as shown in Figure 10
  • the network device 2000 is capable of performing all or part of the operations performed by network devices.
  • the processor 2001 is used to obtain the first message and the second message, where the first message includes the first user identification, the second message includes the second user identification, and the first user identification and the second user identification Different; based on the first node information in the first message indicating the first resource pool, and the first node information being used to indicate the next hop in the forwarding path corresponding to the first message, the network device sends a request to the first resource pool corresponding to the first node information.
  • the first service device sends the first message; similarly, the first node information in the second message also indicates the first resource pool, and the first node information is also used to indicate the forwarding path corresponding to the second message. In the next hop, the network device sends the second message to the first service device corresponding to the first resource pool.
  • the network device 2000 in the embodiment of the present application may correspond to the first service device in the above method embodiments.
  • the processor 2001 in the network device 2000 reads the instructions in the memory 2003 to make the network device shown in Figure 10 2000 is capable of performing all or part of the operations performed by the first service device.
  • the processor 2001 is configured to receive a first message and a second message sent by a network device.
  • the first message includes a first user identifier
  • the second message includes a second user identifier
  • the first user identifier and the second message The user identifiers are different; the first value-added service corresponding to the first message is determined in the first resource pool according to the first user identifier, and the second value-added service corresponding to the second message is determined in the first resource pool according to the second user identifier.
  • the network device 2000 may also correspond to the message forwarding device shown in the above-mentioned Figures 7-9.
  • Each functional module in the message forwarding device is implemented by the software of the network device 2000.
  • the functional modules included in the message forwarding apparatus are generated by the processor 2001 of the network device 2000 after reading the program code 2010 stored in the memory 2003.
  • Each step of the message forwarding method shown in FIG. 3 is completed through an integrated logic circuit of hardware or instructions in the form of software in the processor of the network device 2000 .
  • the steps of the methods disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware processor for execution, or can be executed by a combination of hardware and software modules in the processor.
  • the software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, the details will not be described here.
  • Figure 11 shows a schematic structural diagram of a network device 2100 provided by another exemplary embodiment of the present application.
  • the network device 2100 shown in Figure 11 is used to perform the steps involved in the message forwarding method shown in Figure 3. All or part of the operation.
  • the network device 2100 is, for example, a switch, a router, etc., and the network device 2100 can be implemented by a general bus architecture.
  • the network device 2100 includes: a main control board 2110 and an interface board 2130.
  • the main control board is also called the main processing unit (MPU) or route processor card.
  • the main control board 2110 is used to control and manage various components in the network device 2100, including route calculation and device management. , equipment maintenance, protocol processing functions.
  • the main control board 2110 includes: a central processing unit 2111 and a memory 2112.
  • the interface board 2130 is also called a line interface unit (line processing unit, LPU), line card (line card) or service board.
  • the interface board 2130 is used to provide various service interfaces and implement data packet forwarding.
  • Business interfaces include but are not limited to Ethernet interfaces, POS (Packet over SONET/SDH) interfaces, etc.
  • Ethernet interfaces are, for example, Flexible Ethernet Clients (FlexE Clients).
  • the interface board 2130 includes: a central processor 2131, a network processor 2132, a forwarding entry memory 2134, and a physical interface card (physical interface card, PIC) 2133.
  • the central processor 2131 on the interface board 2130 is used to control and manage the interface board 2130 and communicate with the central processor 2111 on the main control board 2110 .
  • the network processor 2132 is used to implement packet forwarding processing.
  • the network processor 2132 may be in the form of a forwarding chip.
  • the forwarding chip can be a network processor (NP).
  • the forwarding chip can be implemented through an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • the network processor 2132 is used to forward the received message based on the forwarding table stored in the forwarding table memory 2134.
  • the message is uploaded to the CPU (such as central processor 2131) processing; if the destination address of the message is not the address of the network device 2100, the next hop and outgoing interface corresponding to the destination address are found from the forwarding table according to the destination address, and the message is forwarded to The outbound interface corresponding to the destination address.
  • the processing of uplink packets may include: processing of the packet incoming interface, forwarding table search; and the processing of downlink packets may include: forwarding table search, etc.
  • the central processing unit can also perform the function of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that there is no need for a forwarding chip in the interface board.
  • the physical interface card 2133 is used to implement the docking function of the physical layer.
  • the original traffic enters the interface board 2130 through this, and the processed packets are sent out from the physical interface card 2133.
  • the physical interface card 2133 is also called a daughter card and can be installed on the interface board 2130. It is responsible for converting photoelectric signals into messages and checking the validity of the messages before forwarding them to the network processor 2132 for processing.
  • the central processor 2131 can also perform the functions of the network processor 2132, such as based on a general-purpose CPU. Software forwarding eliminates the need for a network processor 2132 in the physical interface card 2133.
  • the network device 2100 includes multiple interface boards.
  • the network device 2100 also includes an interface board 2140.
  • the interface board 2140 includes: a central processor 2141, a network processor 2142, a forwarding entry memory 2144, and a physical interface card 2143.
  • the functions and implementation methods of each component in the interface board 2140 are the same as or similar to those of the interface board 2130 and will not be described again here.
  • the network device 2100 also includes a switching network board 2120.
  • the switching fabric unit 2120 may also be called a switching fabric unit (switch fabric unit, SFU).
  • SFU switching fabric unit
  • the switching network board 2120 is used to complete data exchange between the interface boards.
  • the interface board 2130 and the interface board 2140 can communicate through the switching network board 2120.
  • the main control board 2110 is coupled with the interface board.
  • the main control board 2110, the interface board 2130, the interface board 2140, and the switching network board 2120 are connected to the system backplane through a system bus to achieve intercommunication.
  • an inter-process communication protocol (IPC) channel is established between the main control board 2110 and the interface board 2130 and the interface board 2140.
  • the main control board 2110 and the interface board 2130 and the interface board 2140 communicate through IPC channels.
  • network device 2100 includes a control plane and a forwarding plane.
  • the control plane includes a main control board 2110 and a central processor 2111.
  • the forwarding plane includes various components that perform forwarding, such as forwarding entry memory 2134, physical interface card 2133, and network processing.
  • the control plane executes functions such as router, generates forwarding tables, processes signaling and protocol messages, configures and maintains the status of network devices.
  • the control plane sends the generated forwarding tables to the forwarding plane.
  • the network processor 2132 is based on the control
  • the forwarding table delivered above looks up the table and forwards the packets received by the physical interface card 2133.
  • the forwarding table delivered by the control plane may be stored in the forwarding table item storage 2134. In some embodiments, the control plane and forwarding plane may be completely separated and not on the same network device.
  • main control boards there may be one or more main control boards, and when there are multiple main control boards, they can include the main main control board and the backup main control board.
  • network equipment can have at least one switching network board, which enables data exchange between multiple interface boards through the switching network board, providing large-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of network equipment with a distributed architecture are greater than those with a centralized architecture.
  • the network device can also be in the form of only one board, that is, there is no switching network board. The functions of the interface board and the main control board are integrated on this board. In this case, the central processor and main control board on the interface board The central processor on the board can be combined into one central processor on this board to perform the superimposed functions of the two.
  • This form of network equipment has low data exchange and processing capabilities (for example, low-end switches or routers, etc. Internet equipment).
  • the specific architecture used depends on the specific networking deployment scenario and is not limited here.
  • the network device 2100 corresponds to the packet forwarding device applied to the network device shown in FIG. 7 above.
  • the acquisition module 701 in the message forwarding device shown in Figure 7 is equivalent to the central processor 2111 or the network processor 2132 in the network device 2100, and the sending module 702 is equivalent to the physical interface card in the network device 2100. 2133.
  • the network device 2100 also corresponds to the packet forwarding device applied to the first service device shown in Figure 8 above.
  • the receiving module 801 in the message forwarding device shown in Figure 8 is equivalent to the physical interface card 2133 in the network device 2100
  • the determining module 802 is equivalent to the central processor 2111 or the network processor in the network device 2100. 2132.
  • FIG 12 is a schematic structural diagram of a server provided by an embodiment of the present application.
  • the server 1300 can be modified due to configuration or performance. The difference is relatively large, and may include one or more processors 1301 and one or more memories 1302, wherein at least one computer program is stored in the one or more memories 1302, and the at least one computer program is composed of the one or more processors 1301. Or multiple processors 1301 are loaded and executed, so that the server implements the message forwarding method provided by each of the above method embodiments.
  • the server 1300 may also have components such as wired or wireless network interfaces, keyboards, and input and output interfaces for input and output.
  • the server 1300 may also include other components for implementing device functions, which will not be described again here.
  • the processing system includes: a network device, a first service device and a control device.
  • the network device and the first service device are the network device 2000 shown in FIG. 10 or the network device 2100 shown in FIG. 11
  • the control device is the server shown in FIG. 12 .
  • the packet forwarding method performed by the network device, the first service device and the control device please refer to the relevant description of the embodiment shown in Figure 3 above, and will not be described again here.
  • An embodiment of the present application also provides a communication device, which includes: a transceiver, a memory, and a processor.
  • the transceiver, the memory and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals.
  • the processor executes the instructions stored in the memory, the processor is caused to execute the method required by the network device.
  • An embodiment of the present application also provides a communication device, which includes: a transceiver, a memory, and a processor.
  • the transceiver, the memory and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals.
  • the processor executes the instructions stored in the memory, the processor is caused to execute the method required to be executed by the first service device.
  • An embodiment of the present application also provides a communication device, which includes: a transceiver, a memory, and a processor.
  • the transceiver, the memory and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals.
  • the processor executes the instructions stored in the memory, the processor is caused to execute the method required to be executed by the control device.
  • processor can be a CPU, or other general-purpose processor, digital signal processing (DSP), application specific integrated circuit (ASIC), field programmable gate array ( field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
  • DSP digital signal processing
  • ASIC application specific integrated circuit
  • FPGA field programmable gate array
  • a general-purpose processor can be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports advanced RISC machines (ARM) architecture.
  • ARM advanced RISC machines
  • the above-mentioned memory may include a read-only memory and a random access memory, and provide instructions and data to the processor.
  • Memory may also include non-volatile random access memory.
  • the memory may also store device type information.
  • the memory may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory.
  • the non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically removable memory. Erase programmable read-only memory (electrically EPROM, EEPROM) or flash memory.
  • Volatile memory may be random access memory (RAM), which is used as an external cache. By way of illustration, but not limitation, many forms of RAM are available.
  • static random access memory static random access memory
  • dynamic random access memory dynamic random access memory
  • DRAM dynamic random access memory
  • SDRAM synchronous dynamic random access memory
  • double data rate synchronous dynamic random access memory double data rate SDRAM, DDR SDRAM
  • enhanced synchronous dynamic random access memory enhanced SDRAM, ESDRAM
  • synchronous link dynamic random access memory direct memory bus random access memory
  • direct rambus RAM direct rambus RAM, DR RAM
  • Embodiments of the present application also provide a computer-readable storage medium. At least one instruction is stored in the storage medium, and the instruction is loaded and executed by the processor, so that the computer implements any of the above message forwarding methods.
  • Embodiments of the present application also provide a computer program (product).
  • the computer program When the computer program is executed by a computer, it can cause the processor or computer to execute corresponding steps and/or processes in the above method embodiments.
  • Embodiments of the present application also provide a chip, including a processor, configured to call and run instructions stored in the memory, so that the communication device installed with the chip executes any of the above message forwarding methods.
  • An embodiment of the present application also provides another chip, including: an input interface, an output interface, a processor, and a memory.
  • the input interface, the output interface, the processor, and the memory are connected through an internal connection path.
  • the processor is used to execute the code in the memory. , when the code is executed, the processor is used to execute any of the above message forwarding methods.
  • a computer program product includes one or more computer instructions.
  • Computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, e.g., computer instructions may be transmitted from a website, computer, server or data center via a wired link (e.g.
  • Coaxial cable, optical fiber, digital subscriber line) or wireless means to transmit to another website, computer, server or data center.
  • Computer-readable storage media can be any available media that can be accessed by a computer or a data storage device such as a server, data center, or other integrated media that contains one or more available media. Available media may be magnetic media (eg, floppy disk, hard disk, magnetic tape), optical media (eg, DVD), or semiconductor media (eg, solid state disk), etc.
  • the program can be stored in a computer-readable storage medium.
  • the storage medium can be read-only memory, magnetic disk or optical disk, etc.
  • the computer program product includes one or more computer program instructions.
  • methods of embodiments of the present application may be described in the context of machine-executable instructions, such as included in a program module executing in a device on a target's real or virtual processor.
  • program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures.
  • the functionality of program modules may be combined or split between the described program modules.
  • Machine-executable instructions for program modules can execute locally or on a distributed device. In a distributed device, program modules can be located in both local and remote storage media.
  • Computer program codes for implementing the methods of embodiments of the present application may be written in one or more programming languages. These computer program codes may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when executed by the computer or other programmable data processing device, the program code causes the flowcharts and/or block diagrams to be displayed. The functions/operations specified in are implemented.
  • the program code may execute entirely on the computer, partly on the computer, as a stand-alone software package, partly on the computer and partly on a remote computer or entirely on the remote computer or server.
  • the computer program code or related data may be carried by any appropriate carrier, so that the device, device or processor can perform the various processes and operations described above.
  • Examples of carriers include signals, computer-readable media, and the like.
  • Examples of signals may include electrical, optical, radio, acoustic, or other forms of propagated signals, such as carrier waves, infrared signals, and the like.
  • a machine-readable medium may be any tangible medium that contains or stores a program for or in connection with an instruction execution system, apparatus, or device.
  • the machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium.
  • Machine-readable media may include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or devices, or any suitable combination thereof. More detailed examples of machine-readable storage media include an electrical connection with one or more wires, laptop computer disk, hard drive, random memory accessor (RAM), read-only memory (ROM), erasable programmable read-only memory Memory (EPROM or flash memory), optical storage device, magnetic storage device, or any suitable combination thereof.
  • the disclosed systems, devices and methods can be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of the modules is only a logical function division. In actual implementation, there may be other division methods.
  • multiple modules or components may be combined or may be Integrated into another system, or some features can be ignored, or not implemented.
  • the coupling or direct coupling or communication connection between each other shown or discussed may be indirect coupling or communication connection through some interfaces, devices or modules, or may be electrical, mechanical or other forms of connection.
  • the modules described as separate components may or may not be physically separated.
  • the components shown as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
  • each functional module in each embodiment of the present application can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.
  • the above integrated modules can be implemented in the form of hardware or software function modules.
  • the integrated module is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium.
  • the technical solution of the present application is essentially or contributes to the existing technology, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium , including several instructions to cause a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application.
  • the aforementioned storage media include: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk and other media that can store program code. .
  • first, second and other words are used to distinguish the same or similar items with basically the same functions and functions. It should be understood that the terms “first”, “second” and “nth” There are no logical or sequential dependencies, and there is no control over quantity or execution. Row order is limited. It should also be understood that, although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, a first image may be referred to as a second image, and similarly, a second image may be referred to as a first image, without departing from the scope of various examples. Both the first image and the second image may be images, and in some cases, may be separate and different images.
  • the size of the sequence number of each process does not mean the order of execution.
  • the execution order of each process should be determined by its function and internal logic, and should not be determined by the execution order of the embodiments of the present application.
  • the implementation process constitutes no limitation.
  • determining B based on A does not mean determining B only based on A, and B can also be determined based on A and/or other information.
  • references throughout this specification to "one embodiment,” “an embodiment,” and “a possible implementation” mean that specific features, structures, or characteristics related to the embodiment or implementation are included herein. In at least one embodiment of the application. Therefore, “in one embodiment” or “in an embodiment” or “a possible implementation” appearing in various places throughout this specification do not necessarily refer to the same embodiment. Furthermore, the particular features, structures or characteristics may be combined in any suitable manner in one or more embodiments.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请公开了一种报文转发方法、设备、系统及存储介质,涉及通信技术领域。网络设备接收包括第一用户标识的第一报文,第一报文中的第一节点信息指示下一跳为第一资源池,向第一资源池对应的服务设备发送第一报文,接收包括第二用户标识的第二报文,第二报文中的第一节点信息也指示下一跳为第一资源池,向第一资源池对应的服务设备发送第二报文;服务设备根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。该方法无需在网络设备和资源池之间创建较多的子接口即可提供对应的增值服务,简化了资源池的部署,降低了路径编排的计算难度。

Description

报文转发方法、设备、系统及存储介质
本申请要求于2022年08月03日提交的申请号为202210927104.1、发明名称为“报文转发方法、装置、设备和存储介质”的中国专利申请的优先权,本申请要求于2022年10月31日提交的申请号为202211352376.X、发明名称为“报文转发方法、设备、系统及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及报文转发方法、设备、系统及存储介质。
背景技术
随着通信技术的发展,运营商除了提供基础网络服务外,还提供例如安全服务等增值服务。例如,在转发用户的报文时,通过在运营商网络旁设置资源池的方式,实现用户的增值业务处理。
相关技术中,先在网络设备与资源池之间创建多个子接口,一个子接口对应一个用户,资源池为每个子接口分配独立的虚拟系统(virtual system,Vsys),Vsys为对应的用户提供增值服务。在转发报文时,控制设备为不同用户编排不同的转发路径,转发路径中包括用户对应的网络设备上的子接口的地址,以将不同用户的报文转发至子接口对应的Vsys,实现多用户的增值服务处理。
但是,相关技术中的报文转发方法,由于需要创建较多的子接口,使得资源池的配置较复杂,自动化难度高。并且在编排转发路径时,需要区分不同子接口的地址,增加了路径编排的难度。
发明内容
本申请提供了一种报文转发方法、设备、系统及存储介质,用于为用户提供对应的增值服务。
第一方面,提供了一种报文转发方法,以网络设备执行该方法为例,该方法包括:获取第一报文和第二报文,其中,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;基于第一报文中的第一节点信息指示第一资源池,且第一节点信息用于指示第一报文对应的转发路径中的下一跳,网络设备向第一资源池对应的第一服务设备发送第一报文,以使第一服务设备根据第一报文包括的第一用户标识在第一资源池中确定第一报文对应的增值服务;同理,基于第二报文中的第一节点信息也指示第一资源池,且第一节点信息也用于指示第二报文对应的转发路径中的下一跳,网络设备向第一资源池对应的第一服务设备发送第二报文,以使第一服务设备根据第二报文包括的第二用户标识在第一资源池中确定第二报文对应的增值服务。
该方法在同一资源池提供多用户的增值服务的情况下,无需在网络设备和服务设备之间创建较多的子接口,可以直接基于报文中均包括的第一节点信息将不同用户的报文 发送给第一节点信息指示的资源池对应的服务设备,服务设备能够根据报文携带的用户标识来映射不同用户对应的增值服务。因此,该方法简化了资源池的子接口部署,并且在路径编排时也无需区分同一资源池的不同的子接口,降低了路径编排的计算难度。
在一种可能的实施方式中,获取第一报文和第二报文的方式可以为,接收第一报文和第二报文。其中,第一报文还包括第一业务链路径,第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二报文还包括第二业务链路径,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。报文通过包括的业务链路径来携带用于指示下一跳的第一节点信息,使得网络设备能够基于第一节点信息指示的第一资源池向第一资源池对应的第一服务设备发送报文。
在一种可能的实施方式中,获取第一报文和第二报文的方式还可以为,接收第三报文和第四报文;获取第三报文对应的第一业务链路径,对第三报文进行隧道封装,得到第一报文,第一报文包括第一业务链路径;获取第四报文对应的第二业务链路径,对第四报文进行隧道封装,得到第二报文,第二报文包括第二业务链路径;第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
通过对接收的报文进行隧道封装的方式,使得向资源池转发的报文通过封装的业务链路径来携带用于指示下一跳的第一节点信息,网络设备由此能够基于第一节点信息指示的第一资源池向第一资源池对应的第一服务设备发送报文。
在一种可能的实施方式中,在接收第三报文和第四报文的情况下,第三报文还包括第一业务标识,第四报文还包括第二业务标识;网络设备在多个可选业务链路径中确定第一业务标识对应的可选业务链路径,以将第一业务标识对应的可选业务链路径作为第三报文对应的第一业务链路径;同理,网络设备在多个可选业务链路径中确定第二业务标识对应的可选业务链路径,将第二业务标识对应的可选业务链路径作为第四报文对应的第二业务链路径。由此,通过报文携带的业务标识能够在可选业务链路径中确定得到对应的业务链路径。
在一种可能的实施方式中,网络设备在基于多个可选业务链路径确定不同业务标识对应的可选业务链路径之前,先接收控制设备发送的多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息。通过与控制设备的交互来获取可选业务链路径,由于控制设备的计算能力较强,在降低网络设备的计算压力的基础上,还使得获取的可选业务链路径更准确。
在一种可能的实施方式中,第一业务标识和第二业务标识为应用标识,第一业务标识携带在第一报文包括的应用感知网络(application aware network,APN)标识中,第二业务标识携带在第二报文包括的APN标识中。第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。通过扩展APN标识携带应用标识或用户标识的方式,使得该方法能够应用于APN网络,且增强了APN网络的转发能力。
在一种可能的实施方式中,第一报文和第二报文为基于互联网协议第6版的段路由 (segment routing IPv6internet protocol version 6,SRv6)报文,第一节点信息为第一资源池的段标识(segment identity,SID)。通过应用SRv6网络中的SID提供了一种报文携带第一节点信息的实现方式,使得携带的第一节点标识能够指示转发路路径的下一跳,且使得该方法能够应用于SRv6网络。其中,资源池可以为安全资源池,增值服务可以为安全服务。
第二方面,提供了一种报文转发方法,以第一服务设备执行该方法为例,该方法包括:第一服务设备接收网络设备发送的第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;第一服务设备根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。其中,第一报文中的第一节点信息指示第一报文的转发路径中网络设备的下一跳为第一资源池,第二报文中的第一节点信息指示第二报文的转发路径中网络设备的下一跳为第一资源池,由此,网络设备会基于第一节点信息向第一资源池对应的第一服务设备发送第一报文和第二报文。
该方法服务设备在接收到包括不同用户标识的不同报文时,能够根据用户标识来确定不同报文对应的增值服务。实现了在同一资源池提供多用户的增值服务的情况下,无需在网络设备和服务设备之间创建较多的子接口,可以直接通过同一个接口接收不同用户的报文,服务设备能够根据报文携带的用户标识来映射不同用户对应的增值服务。因此,该方法简化了资源池的子接口部署,并且在路径编排时也无需区分同一资源池的不同的子接口,降低了路径编排的计算难度。
在一种可能的实施方式中,第一服务设备根据多个标识与多个增值服务的一一对应关系,确定与第一用户标识对应的增值服务,将与第一用户标识对应的增值服务作为第一报文对应的第一增值服务;同理,根据多个标识与多个增值服务的一一对应关系,确定第二用户标识对应的增值服务,将与第二用户标识对应的增值服务作为第二报文对应的第二增值服务。通过多个标识与多个增值服务的一一对应关系实现了对不同用户的报文的增值服务的准确映射,使得提供的增值服务更准确。
在一种可能的实施方式中,第一服务设备根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务之后,调用第一增值服务对应的资源对第一报文进行增值业务处理;根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务之后,调用第二增值服务对应的资源对第二报文进行增值业务处理。由此,实现了对不同用户的报文提供不同的增值服务的效果,满足了为多用户提供对应的增值服务的需求。
在一种可能的实施方式中,在对第一报文进行增值业务处理之后,当第一报文中的第二节点信息指示第二资源池,且第二节点信息用于指示第一报文对应的转发路径中的下一跳时,还向第二资源池对应的第二服务设备发送第一报文;同理,在对第二报文进行增值业务处理之后,当基于第二报文中的第三节点信息指示第三资源池,且第三节点信息用于指示第二报文对应的转发路径中的下一跳时,向第三资源池对应的第三服务设备发送第二报文。实现了报文在不同资源池之间的转发,进而能够提供更丰富的增值服务。
在一种可能的实施方式中,第一报文和第二报文为SRv6报文,第一节点信息为第一资源池的SID。
在一种可能的实施方式中,第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。
第三方面,提供了一种报文转发方法,以控制设备执行该方法为例,该方法包括:获取多个可选业务链路径,向网络设备发送多个可选业务链路径。其中,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息,多个可选业务链路径包括第一报文对应的第一业务链路径和第二报文对应的第二业务链路径,第一业务链路径包括的第一节点信息用于指示第一报文对应的转发路径中网络设备的下一跳,第二业务链路径包括的第一节点信息用于指示第二报文对应的转发路径中网络设备的下一跳,第一节点信息指示第一资源池。由此,网络设备能够根据多个可选业务链路径中的第一业务链路径转发第一报文,根据多个可选业务链路径中的第二业务链路径转发第二报文。
该方法中直接将资源池作为转发节点进行路径编排,无需区分同一资源池的不同的子接口,降低了路径编排的计算难度。
在一种可能的实施方式中,控制设备能够获取多个资源池分别对应的SID;则控制设备可以根据多个资源池分别对应的SID进行路径编排,得到多个可选业务链路径,任一可选业务链路径包括的至少一个资源池的节点信息为至少一个资源池分别对应的SID。
第四方面,提供了一种报文转发方法,该方法包括:网络设备获取第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;网络设备基于第一报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第一报文,第一节点信息用于指示第一报文对应的转发路径中的下一跳;基于第二报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第二报文,第一节点信息用于指示第二报文对应的转发路径中的下一跳;第一服务设备接收网络设备发送的第一报文和第二报文;第一服务设备根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。
在一种可能的实施方式中,控制设备获取多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息,多个可选业务链路径包括第一报文对应的第一业务链路径和第二报文对应的第二业务链路径,第一业务链路径包括的第一节点信息用于指示第一报文对应的转发路径中网络设备的下一跳,第二业务链路径包括的第一节点信息用于指示第二报文对应的转发路径中网络设备的下一跳,第一节点信息指示第一资源池;控制设备向网络设备发送多个可选业务链路径,多个可选业务链路径用于网络设备获取第一业务链路径和第二业务链路径。
第五方面,提供了一种报文转发装置,应用于网络设备,该装置包括:
获取模块,用于获取第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;
发送模块,用于基于第一报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第一报文,第一节点信息用于指示第一报文对应的转发路径中的下一跳,第一报文包括的第一用户标识用于第一服务设备在第一资源池中确定第一报文对应的增值服务;基于第二报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第二报文,第一节点信息用于指示第二报文对应的转发路径中的下一跳,第二报文包括的 第二用户标识用于第一服务设备在第一资源池中确定第二报文对应的增值服务。
在一种可能的实施方式中,第一报文还包括第一报文对应的第一业务链路径,第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二报文还包括第二报文对应的第二业务链路径,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
在一种可能的实施方式中,获取模块,用于接收第三报文,获取第三报文对应的第一业务链路径,对第三报文进行隧道封装,得到第一报文,第一报文包括第一业务链路径;接收第四报文,获取第四报文对应的第二业务链路径,对第四报文进行隧道封装,得到第二报文,第二报文包括第二业务链路径;第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
在一种可能的实施方式中,第三报文还包括第一业务标识,第四报文还包括第二业务标识;
获取模块,用于在多个可选业务链路径中确定第一业务标识对应的可选业务链路径,将第一业务标识对应的可选业务链路径作为第三报文对应的第一业务链路径;
获取模块,用于在多个可选业务链路径中确定第二业务标识对应的可选业务链路径,将第二业务标识对应的可选业务链路径作为第四报文对应的第二业务链路径。
在一种可能的实施方式中,该装置还包括:
接收模块,用于接收第一控制设备发送的多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息。
在一种可能的实施方式中,第一业务标识和第二业务标识为应用标识,第一业务标识携带在第一报文包括的APN标识中,第二业务标识携带在第二报文包括的APN标识中。
在一种可能的实施方式中,第一报文和第二报文为SRv6报文,第一节点信息为第一资源池的SID。
在一种可能的实施方式中,第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。
第六方面,提供了一种报文转发装置,应用于第一服务设备,该装置包括:
接收模块,用于接收网络设备发送的第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一报文中的第一节点信息指示第一报文的转发路径中网络设备的下一跳为第一资源池,第二报文中的第一节点信息指示第二报文的转发路径中网络设备的下一跳为第一资源池;
确定模块,用于根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。
在一种可能的实施方式中,确定模块,用于根据多个标识与多个增值服务的一一对应关系,确定与第一用户标识对应的增值服务,将与第一用户标识对应的增值服务作为第一报文对应的第一增值服务;根据多个标识与多个增值服务的一一对应关系,确定第二用户标识对应的增值服务,将与第二用户标识对应的增值服务作为第二报文对应的第二增值服务。
在一种可能的实施方式中,该装置还包括:
发送模块,用于基于第一报文中的第二节点信息指示第二资源池,向第二资源池对应的 第二服务设备发送第一报文,第二节点信息用于指示第一报文对应的转发路径中的下一跳;基于第二报文中的第三节点信息指示第三资源池,向第三资源池对应的第三服务设备发送第二报文,第三节点信息用于指示第二报文对应的转发路径中的下一跳。
在一种可能的实施方式中,该装置还包括:
处理模块,用于调用第一增值服务对应的资源对第一报文进行增值业务处理,调用第二增值服务对应的资源对第二报文进行增值业务处理。
在一种可能的实施方式中,第一报文和第二报文为SRv6报文,第一节点信息为第一资源池的SID。
在一种可能的实施方式中,第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。
第七方面,提供了一种报文转发装置,应用于控制设备,该装置包括:
第一获取模块,用于获取多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息,多个可选业务链路径包括第一报文对应的第一业务链路径和第二报文对应的第二业务链路径,第一业务链路径包括的第一节点信息用于指示第一报文对应的转发路径中网络设备的下一跳,第二业务链路径包括的第一节点信息用于指示第二报文对应的转发路径中网络设备的下一跳,第一节点信息指示第一资源池;
发送模块,用于向网络设备发送多个可选业务链路径,网络设备用于根据多个可选业务链路径中的第一业务链路径转发第一报文,根据多个可选业务链路径中的第二业务链路径转发第二报文。
在一种可能的实施方式中,该装置还包括:
第二获取模块,用于获取多个资源池分别对应的SID;
第一获取模块,用于根据多个资源池分别对应的SID进行路径编排,得到多个可选业务链路径,任一可选业务链路径包括的至少一个资源池的节点信息为至少一个资源池分别对应的SID。
第八方面,提供了一种网络设备,该网络设备包括:处理器,所述处理器与存储器耦合,所述存储器中存储有至少一条程序指令或代码,所述至少一条程序指令或代码由所述处理器加载并执行,以使所述网络设备实现如上第一方面、第二方面或第三方面任一所述的报文转发方法。
可选地,所述处理器为一个或多个,所述存储器为一个或多个。
可选地,所述存储器可以与所述处理器集成在一起,或者所述存储器与处理器分离设置。
在具体实现过程中,存储器可以为非瞬时性(non-transitory)存储器,例如只读存储器(read only memory,ROM),其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上,本申请对存储器的类型以及存储器与处理器的设置方式不做限定。
第九方面,提供了一种通信装置,该装置包括:收发器、存储器和处理器。其中,该收发器、该存储器和该处理器通过内部连接通路互相通信,该存储器用于存储指令,该处理器用于执行该存储器存储的指令,以控制收发器接收信号,并控制收发器发送信号,并且当该处理器执行该存储器存储的指令时,使得该通信装置执行第一方面或第一方面的任一种可能的实施方式中的方法,或者执行第二方面或第二方面的任一种可能的实施方式中的方法,或者执行第三方面或第三方面的任一种可能的实施方式中的方法,或者执行第四方面或第四方 面的任一种可能的实施方式中的方法。
第十方面,提供了一种报文转发系统,所述报文转发系统包括网络设备、第一服务设备、和控制设备;
所述网络设备用于执行所述第一方面或第一方面的任一种可能的实现方式所述的方法,所述第一服务设备用于执行所述第二方面或第二方面的任一种可能的实现方式所述的方法,所述控制设备用于执行所述第三方面或第三方面的任一种可能的实现方式所述的方法。
第十一方面,提供了一种计算机可读存储介质,所述存储介质中存储有至少一条指令,所述指令由处理器加载并执行,以使计算机实现上述第一方面或第一方面的任一种可能的实施方式中的方法,或者实现上述第二方面或第二方面的任一种可能的实施方式中的方法,或者实现上述第三方面或第三方面的任一种可能的实施方式中的方法,或者实现上述第四方面或第四方面的任一种可能的实施方式中的方法。
第十二方面,提供了一种计算机程序(产品),所述计算机程序(产品)包括:计算机程序代码,当所述计算机程序代码被计算机运行时,使得所述计算机执行上述各方面中的方法。
第十三方面,提供了一种芯片,包括处理器,用于从存储器中调用并运行所述存储器中存储的指令,使得安装有所述芯片的通信设备执行上述各方面中的方法。
第十四方面,提供另一种芯片,包括:输入接口、输出接口、处理器和存储器,所述输入接口、输出接口、所述处理器以及所述存储器之间通过内部连接通路相连,所述处理器用于执行所述存储器中的代码,当所述代码被执行时,所述处理器用于执行上述各方面中的方法。
应当理解的是,本申请的第四方面至第十四五方面技术方案及对应的可能的实施方式所取得的有益效果可以参见上述对第一方面至第三方面及其对应的可能的实施方式的技术效果,此处不再赘述。
附图说明
图1为本申请实施例提供的相关技术中资源池的部署示意图;
图2为本申请实施例提供的一种实施环境的示意图;
图3为本申请实施例提供的一种报文转发方法的交互示意图;
图4为本申请实施例提供的另一种资源池的部署示意图;
图5为本申请实施例提供的一种资源池的结构示意图;
图6为本申请实施例提供的一种报文转发过程的示意图;
图7为本申请实施例提供的一种报文转发装置的结构示意图;
图8为本申请实施例提供的另一种报文转发装置的结构示意图;
图9为本申请实施例提供的又一种报文转发装置的结构示意图;
图10为本申请实施例提供的一种网络设备的结构示意图;
图11为本申请实施例提供的另一种网络设备的结构示意图;
图12为本申请实施例提供的一种服务器的结构示意图。
具体实施方式
为使本申请的目的、技术方案和优点更加清楚,下面将结合附图对本申请实施方式作进 一步地详细描述。
运营商在为用户提供例如安全服务等增值服务时,通常在运营商网络旁设置至少一个资源池,相比于每个资源池为单用户提供对应的增值服务,更希望每个资源池能够为多用户提供对应的增值服务。因此,在对资源池进行部署时,资源池需要具备识别不同用户对应的不同增值服务的能力。相关技术中,采用为不同用户创建不同子接口的方式,实现识别不同用户的不同增值服务的能力。
示例性地,参见图1,图1为本申请实施例提供的相关技术中资源池的部署示意图。如图1所示,网络设备与资源池之间创建有多个子接口,一个子接口对应一个用户,每个子接口包括对应的端点(endpoint,END).X SID,资源池为每个子接口分配独立的Vsys。进而,在对转发的报文进行路径编排时,将每个子接口的END.X SID作为转发路径上的节点,以将不同用户的报文转发至不同子接口对应的Vsys,实现不同Vsys为不同用户提供对应的增值服务。其中,Vsys指的是一台物理设备上划分出的多台相互独立的逻辑设备,虚拟系统之间可以实现网络隔离。END.X SID为SID的一种类型,用于指示网络设备从End.X SID指定的出接口转发报文。
示例性地,子接口1对应用户1,子接口1的SID为END.X SID1,子接口1与Vsys1相连接。则网络设备接收用户1的用户终端设备(customer premise equipment,CPE)发送的第一报文,该第一报文对应的转发路径包括END.X SID1,该END.X SID1指示该第一报文的下一跳为子接口1,则网络设备通过子接口1向Vsys1发送该报文,进而通过Vsys1为用户1提供用户1对应的增值服务。
子接口2对应用户2,子接口2的SID为END.X SID2,子接口2与Vsys2相连接。则网络设备接收用户2的CPE发送的第二报文,该第二报文对应的转发路径包括END.X SID2,该END.X SID2指示该第二报文的下一跳为子接口2,则网络设备通过子接口2向Vsys2发送该第二报文,进而通过Vsys2为用户2提供用户2对应的增值服务。也即在相关技术中,网络设备在转发不同用户的报文时,不同用户的报文对应的下一跳是不同的,由此来实现为不同用户提供不同的增值服务的效果。
但是,在图1所示的资源池的部署方案中,需要在网络设备和资源池之间创建较多的子接口,来实现多用户的增值业务处理,使得资源池的配置较复杂,自动化难度高。并且在路径编排时,由于不同用户对应的子接口不同,因此需要为不同用户编排不同的转发路径,以使不同的转发路径中包括对应的子接口的END.X SID,增加了路径编排的计算难度。
本申请实施例提供了一种报文转发方法,对于为多用户提供增值服务的资源池,该方法在向资源池转发不同用户的报文时,无需区分不同的子接口,直接向资源池对应的服务设备发送,服务设备通过报文中携带的不同用户标识来确定不同用户在该资源池中对应的增值服务。由此,该方法无需在网络设备和资源池之间创建较多的子接口,简化了资源池的配置。并且在路径编排时,对于同一资源池中的多个用户,无需根据不同子接口为不同用户编排不同的转发路径,降低了路径编排的计算难度。
参见图2,图2为本申请实施例提供的一种实施环境的示意图。如图2所示,该实施环境包括CPE、网络设备、资源池、第一控制设备和第二控制设备。其中,CPE与网络设备之间、网络设备与资源池之间、第一控制设备与第二控制设备之间相互通信连接。第一控制设备用于控制CPE和网络设备,例如,向CPE和网络设备下发编排的转发路径。 第二控制设备用于控制资源池,例如,为资源池下发对应的SID,以及多个业务标识与多个增值服务的一一对应关系。
本申请实施例不对网络设备和资源池的数量进行限定。第一控制设备和第二控制设备可以部署于同一个物理设备,也可以部署于不同的物理设备。示例性地,网络设备可以为运营商边缘(provider edge,PE)设备、运营商(provider,P)设备、网PE设备或云PE设备中的至少一种。资源池可以为实体设备或者云化设备,当资源池为云化设备时,资源池还可称为云化资源池。第一控制设备和第二控制设备均可以为网络控制引擎(network control engine,NCE)。
本申请实施例提供的报文转发方法可以应用于图2所示的实施环境中,以网络设备和资源池为例,对本申请实施例提供的报文转发方法进行说明。其中,一个资源池对应一个服务设备,服务设备为资源池对应的执行主体,也即资源池通过对应的服务设备执行本申请实施例提供的报文转发方法。示例性地,参见图3,该报文转发方法包括如下步骤301-步骤303。
步骤301,网络设备获取第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识和第二用户标识不同。
在本申请实施例中,网络设备是指第一报文和第二报文的转发路径中进入安全网络的资源池的前一跳网络设备。例如,图2所示的实施环境中与资源池连接的任一网络设备。安全网络指的是包括资源池的网络。
其中,第一报文可以携带第一用户标识,第一用户标识用于区分第一用户标识所对应的用户与其他用户对应的不同的增值服务。示例性地,运营商为不同用户配置对应的用户标识,并将配置的用户标识发送至对应的用户使用的CPE,进而CPE能够获取到不同用户的用户标识,将用户标识携带在第一报文中。
可选地,网络设备接收的第一报文可以是CPE1发送的第一报文,CPE1为第一报文的转发路径上的头节点,网络设备接收的第二报文可以是CPE2发送的第二报文,CPE2为第二报文的转发路径上的头节点。其中,CPE1为用户1使用的终端,CPE2为用户2使用的终端。
以用户1为例,用户1可以通过CPE1向运营商租赁增值业务,运营商会为CPE1的不同增值业务编排报文的转发路径并下发至CPE1。进而,当用户1通过CPE1请求对应的增值业务时,CPE1能够根据对应的转发路径传输对应的报文。例如,CPE1根据转发路径向网络设备发送第一报文,进而网络设备接收第一报文。其中,CPE1根据转发路径向网络设备发送第一报文可以为,CPE1通过转发路径中的至少一个中间节点向网络设备发送第一报文。
在一种可能的实施方式中,转发路径由控制设备编排得到,控制设备可以为图2所示的第一控制设备。示例性地,第一控制设备将安全网络包括的多个资源池作为转发节点,对多个不同的增值业务进行端到端的路径编排,得到多个可选业务链路径,然后向PCE发送该多个可选业务链路径。其中,不同的增值业务对应不同的业务标识,则一个可选业务链路径对应一个业务标识。由此,使得CPE能够获取到不同增值业务对应的转发路径。
在本申请实施例中,由于路径编排是直接将资源池作为转发节点的,并不是相关技术中将网络设备上连接资源池的不同子接口作为转发节点,因此对于不同用户去往同一资源池的第一报文和第二报文来说,第一报文和第二报文对应的转发路径指示的下一跳相同且均为第一资源池。可选地,由于报文在网络中的传输方式不同,网络设备获取第一报文和第二报文 的方式包括但不限于如下两种。
方式一,接收第一报文和第二报文。第一报文还包括第一报文对应的第一业务链路径,第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二报文还包括第二报文对应的第二业务链路径,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
在该方式一下,第一报文通过包括的第一业务链路径携带第一节点信息,第二报文通过包括的第二业务链路径携带第一节点信息。可选地,第一报文携带的第一业务链路径由头节点封装得到,第二报文携带的第二业务链路径由头节点封装得到。
示例性地,以第一报文为例,头节点CPE1在发送第一报文时,对第一报文进行了隧道封装,使得第一报文能够根据隧道封装的报文头携带第一报文对应的端到端业务链路径。该端到端业务链路径包括CPE开始的端到端的转发路径,其中,端到端业务链路径中进入资源池之后的转发路径为本申请实施例中的第一业务链路径。即端到端业务链路径包括至少一个网络设备的节点信息和至少一个资源池的节点信息,第一业务链路径包括其中的至少一个资源池的节点信息。
因此,网络设备在接收到第一报文后,对第一报文包括的第一业务链路径进行识别,当第一业务链路径中指示网络设备的下一跳的第一节点信息为第一资源池的节点信息,则网络设备确定向第一资源池对应的第一服务设备发送第一报文。同理,网络设备在接收到第二报文后,对第二报文包括的第二业务链路径进行识别,当第二业务链路径中指示网络设备的下一跳的第一节点信息也为第一资源池的节点信息,则网络设备确定也向第一资源池对应的第一服务设备发送第二报文。
可选地,第一报文和第二报文可以为SRv6报文,在SRv6通信场景中,端到端业务链路径中的至少一个网络设备的节点信息和至少一个资源池的节点信息为,至少一个网络设备的SID和至少一个资源池的SID。本申请实施例不对SID的类型进行限定,可以为END SID也可以为END.X SID。
在一种可能的实施方式中,第二控制设备为通信网络包括的多个网络设备和安全网络包括的多个资源池分配对应的SID,然后第二控制设备向第一控制设备发送多个网络设备和多个资源池分别对应的SID。进而,第一控制设备接收第二控制设备发送的多个网络设备和多个资源池分别对应的SID,基于多个网络设备和多个资源池分别对应的SID进行路径编排,得到多个可选业务链路径。其中,任一可选业务链路径通过对应的资源池的SID指示下一跳为任一资源池。
方式二,接收第三报文,获取第三报文对应的第一业务链路径,对第三报文进行隧道封装,得到第一报文,第一报文包括第一业务链路径;接收第四报文,获取第四报文对应的第二业务链路径,对第四报文进行隧道封装,得到第二报文,第二报文包括第二业务链路径。
其中,第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。由此,第一报文通过封装的第一业务链路径携带第一节点信息,第二报文通过封装的第二业务链路径携带第一节点信息。可以理解,第一报文为第三报文封装第一业务链路径后得到的,则第一报文对应的第一业务链路径和第二报文对应的第一业务链路径为同一个第一业务链路径。
在该方式二下,接收的第三报文未携带对应的进入资源池的第一业务链路径,接收的第四报文未携带对应的进入资源池的第二业务链路径,可以理解,网络设备同样为第三报文和第四报文进入资源池的前一跳设备,因此,网络设备在接收到第三报文和第四报文后需要获取第三报文和第四报文分别对应的进入资源池的业务链路径,以封装得到第三报文对应的第一报文和第四报文对应的第二报文。可选地,本申请实施例不对获取进入资源池的业务链路径的方式进行限定。
示例性地,第三报文还携带有第一业务标识,第四报文还携带第二业务标识,第一业务标识和第二业务标识用于区分不同的增值业务。可选地,第一业务标识和第二业务标识可以为应用标识或者差分服务代码点(differentiated services code point,DSCP)标识。其中,当第一业务标识和第二业务标识为不同的应用标识时,不同的应用标识用于区分不同的应用,进而通过不同的应用标识约束哪些应用需要进入增值业务链;当第一业务标识和第二业务标识为不同的DSCP标识时,不同的DSCP标识用于区分不同的质量等级,进而通过不同的DSCP标识约束哪些质量等级需要进入增值业务链。其中,增值业务链指的就是端到端的转发路径上的包括资源池作为转发节点的业务链,例如,第一业务链路径和第二业务链路径,需要进入增值业务链指的是需要进入资源池进行对应的增值服务处理。
在一种可能的实施方式中,以第三报文为例,CPE1在发送第三报文时,还将第一业务标识携带在了第三报文中,CPE2在发送第四报文时,还将第二业务标识携带在了第四报文中。其中,虽然第三报文未携带第一业务链路径,但头节点CPE1对第三报文也进行了隧道封装,只不过第三报文根据隧道封装的报文头携带的是第三报文对应的CPE1开始到进入资源池之前的转发路径,不包括进入资源池后的第一业务链转发路径。因此,网络设备在接收第三报文后,需要识别第三报文中的第一业务标识,并基于识别的第一业务标识确定该第三报文是否需要进入增值业务链,当第一业务标识指示该第三报文需要进入增值业务链时,获取第三报文对应的进入资源池的第一业务链路径。
其中,由于网络设备为进入资源池的前一跳网络设备,则第三报文已经在通信网络中传输完成,从该网络设备开始进入安全网络,即进入增值业务链。从而,由网络设备获取的第一业务链路径包括至少一个资源池的节点信息,不再包括通信网络中的网络设备的节点信息。示例性地,第三报文对应的第一业务链路径的首个节点信息为第一资源池的节点信息。
在本申请实施例中,以第一业务标识和第二业务标识为应用标识为例,第一控制设备在进行路径编排得到多个可选业务链路径后,还向网络设备发送该多个可选业务链路径,网络设备能够获取到该多个可选业务链路径与每条可选业务链路径对应的应用标识。则网络设备获取第一报文包括的第一业务标识后,能够在多个可选业务链路径中确定第一业务标识对应的可选业务链路径,将第一业务标识对应的可选业务链路径作为第三报文对应的第一业务链路径。同样的,网络设备获取第四报文包括的第二业务标识后,能够在多个可选业务链路径中确定第二业务标识对应的可选业务链路径,将第二业务标识对应的可选业务链路径作为第四报文对应的第二业务链路径。
由此,通过上述方式一和方式二,使得获取的第一报文携带第一业务链路径,第二报文携带第二业务链路径,能够使得后续接收第一报文的转发节点例如第一服务设备,能够根据该第一报文对应的第一业务链路径转发第一报文,使得后续接收第二报文的转发节点例如第一服务设备,能够根据该第二报文对应的第二业务链路径转发第二报文。
步骤302,网络设备基于第一报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第一报文;基于第二报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第二报文。
其中,第一节点信息用于指示转发路径中网络设备的下一跳,则第一报文中的第一节点信息用于指示第一报文对应的转发路径中的下一跳,第二报文中的第一节点信息用于指示第二报文对应的转发路径中的下一跳。由此,对于包括不同用户标识的第一报文和第二报文的转发路径的下一跳相同均为第一资源池,也即网络设备对于不同用户的转发行为可以是相同的,无需为不同用户部署不同的子接口。
在获取到第一报文和第二报文之后,通过上述获取第一报文和第二报文的方式一和方式二可知,第一报文和第二报文中携带有第一节点信息,且第一节点信息用于指示网络设备的下一跳为第一资源池。又由于第一服务设备为第一资源池对应的执行主体,则当转发路径指示的下一跳为第一资源池时,网络设备能够确定向第一资源池对应的第一服务设备发送。
可选地,在APN场景中,以第一报文包括第一用户标识和第一业务标识,第一业务标识为第一应用标识为例,第一用户标识和第一应用标识可以携带在第一报文包括的APN标识中。示例性地,将APN标识配置为第一字段和第二字段,第一字段用于携带第一应用标识,第二字段用于携带第一业务标识。本申请实施例中的APN可以为基于IPv6的应用感知网络APN6。APN标识可以携带在IPv6报文头,或者IPv6扩展头中,例如,APN标识以TLV字段的形式封装在IPv6报文头或者IPv6扩展头中。
在本申请实施例中,由于无需区分网络设备与第一资源池之间的不同子接口即可实现报文的转发,因此,简化了资源池的配置。示例性地,如图4所示,本申请实施例在网络设备与第一资源池之间创建一个主接口,网络设备通过该主接口向第一资源池对应的第一服务设备发送携带不同用户标识的报文。在SRv6通信场景中,一个资源池对应一个SID,而不是资源池上的一个用户的一个子接口对应一个SID,简化了SID的配置操作。可选地,资源池的SID类型可以为END SID,用于指示网络设备通过查找IPv6的路由表进行报文转发。
其中,若一个资源池提供增值服务的用户数量较多,则为了进行负载分担,一个资源池也可以对应多个SID。示例性地,对于同一资源池的用户总量,将用户总量负载分担到多个SID,例如,第一数量的用户对应资源池的第一SID,第二数量的用户对应资源池的第二SID,第一数量和第二数量均大于1。在该情况下,虽然一个资源池对应多个SID,但是每个SID同样对应多个用户,并不是相关技术中的一个子接口对应一个用户,同样能够有效简化资源池的部署。
步骤303,第一服务设备接收网络设备发送的第一报文和第二报文,根据第一报文中的第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二报文中的第一用户标识在第一资源池中确定第一报文对应的增值服务。
在本申请实施例中,第二控制设备为每一资源池配置多个标识与多个增值服务的一一对应关系,且第二控制设备向每一资源池对应的服务设备发送配置的多个标识与多个增值服务的一一对应关系。以使得每一资源池对应的服务设备包括在该资源池中的多个标识与多个增值服务的一一对应关系。例如,第二控制设备为第一资源池配置多个标识与多个增值服务的一一对应关系,且向第一资源池对应的第一服务设备发送该多个标识与多个增值服务的一一 对应关系。
可选地,第一服务设备根据多个标识与多个增值服务的一一对应关系,确定与第一报文包括的第一用户标识对应的增值服务,将与第一报文包括的第一用户标识对应的增值服务作为第一报文对应的第一增值服务。同样的,第一服务设备根据多个标识与多个增值服务的一一对应关系,确定与第二报文包括的第二用户标识对应的增值服务,将与第二报文包括的第二用户标识对应的增值服务作为第二报文对应的第二增值服务。
由此,通过配置的多个标识与多个增值服务的一一对应关系,以及随第一报文携带的第一用户标识和随第二报文携带的第二用户标识,在无需创建多个子接口的基础上,资源池也能够根据不同的第一用户标识和第二用户标识映射不同的增值服务。当第一用户标识和第二用户标识为不同的用户标识时,使得在无需创建多个子接口的基础上,资源池也能够实现多用户的增值业务处理。
由此,第一服务设备根据第一用户标识在第一资源池中确定到了第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定到了第二报文对应的第二增值服务,实现了不同增值服务的映射。之后,第一服务设备即可调用第一增值服务对应的资源对第一报文进行增值业务处理,调用第二增值服务对应的资源对第二报文进行增值业务处理。
示例性地,多个用户标识与多个增值服务的一一对应关系可以如表1所示。其中,表1示出了3个用户标识以及每个用户标识对应的增值服务,增值服务包括防火墙(firewall,FW)、入侵防御系统(intrusion prevention system,IPS)或网页应用防火墙(web application firewall,WAF)中的至少一种。在本申请实施例中,增值服务可以与图1所示的每个子接口连接的Vsys对应。
表1
示例性地,参见图5,以资源池为云化安全池为例,云化安全池对应的安全资源池可以包括高速业务链编排、路由器(router)和多个增值服务(value added services,VAS),其中,高速业务链编排用于为不同的增值服务编排路径,router用于支持SRv6转发能力并提供基于APN标识中识别不同用户的能力。可选地,每个VAS包括n(n为正整数)个FW、IPS或WAF,FW、IPS或WAF用于对第一报文进行增值业务处理。
在本申请实施例中,第一资源池对应的第一服务设备可以为router。示例性地,以第一用户标识0x11对应的增值服务FW1-IPS2为例,router对第一报文的处理过程为,将第一报文发送至VAS1中的FW1,由FW1对第一报文进行增值业务处理,然后将第一报文发送至VAS2中的IPS2,由IPS2对第一报文进行增值业务处理,最后基于SRv6转发能力将第一报文按照业务链路径向下一转发节点进行转发。
在一种可能的实施方式中,在第一服务设备在对第一报文基于对应的第一增值服务进行 增值业务处理之后,第一服务设备基于第一报文包括的第一业务链路径指示第一报文的转发路径的下一跳为第二节点信息,该第二节点信息指示第二资源池,向第二资源池对应的第二服务设备发送第一报文。同样的,在第一服务设备在对第二报文基于对应的第一增值服务进行增值业务处理之后,第一服务设备基于第二报文包括的第二业务链路径指示第二报文的转发路径的下一跳为第三节点信息,该第三节点信息指示第三资源池,向第三资源池对应的第三服务设备发送第二报文。其中,第二资源池和第三资源池可以为同一个资源池,也可以为不同的资源池。
本申请实施例提供的报文转发方法,在同一资源池提供多用户的增值服务的情况下,无需在网络设备和服务设备之间创建较多的子接口,可以直接将不同用户的报文发送给资源池对应的服务设备,服务设备能够根据报文携带的用户标识来映射不同用户对应的增值服务。因此,该方法简化了资源池的子接口部署,并且在路径编排时也无需区分同一资源池的不同的子接口,降低了路径编排的计算难度。
接下来,以报文转发方法的实施环境为SRv6+APN6场景,以增值服务为安全服务,资源池为云化安全池为例,以转发第一报文为例,对本申请实施例提供的报文转发方法进行说明。其中,第一报文为SRv6报文,业务标识为应用标识,用户标识和应用标识携带在第一报文的APN标识中。
参见图6,图6为本申请实施例提供的一种报文转发过程的示意图。如图6所示,该实施环境中包括云网安业务编排系统、NCE-IP、NCE-校园(campus)、CPE、云化安全池、智能城域网和云骨干。其中,网PE设备对应本申请实施例中的执行主体网络设备,NCE-IP对应本申请实施例中的第一控制设备,NCE-campus对应本申请实施例中的第二控制设备,云化安全池1对应本申请实施例中的第一安全资源池,云化安全池2对应本申请实施例中的第二安全资源池。
云网安业务编排系统可集成到运营商的业务编排器中,提供管理员和用户运维界面,负责安全业务的端到端编排。通过北向接口对接运营商的业务用户,通过南向接口对接NCE-IP和NCE-campus。北向接口(northbound interface)可以是指一个较低层级的设备向高层级连接接口,通过北向接口可以实现对下位机的读取和控制;相反,南向接口(southbound interface)则是是指一个较高层级向底层级设备的连接接口,通过南向接口可以实现向上位机的传输交流。可以理解,南向北向的区别在于系统结构的不同位置,通常约定为上北下南。例如,从图6所示的结构拓扑来看,云网安业务编排系统南向对接NCE-IP和NCE-campus,指的是云网安业务编排系统向下连接NCE-IP和NCE-campus。
NCE-IP作为网络控制器,包括业务链引流功能,负责承载网络的管控分析。在本申请实施例中,NCE-IP增加了对网络设备和安全资源池的端到端SRv6策略(Policy)路径编排,即将安全资源池作为路径中的转发节点。北向对接云网安业务编排系统,南向对接智能城域网和云骨干各个网络设备。其中,SRv6Policy可以实现业务的端到端需求,是实现SRv6网络编程的主要机制。
NCE-campus作为安全控制器,包括网络管理、安全管理和资源发放等功能,安全管理用于负责管理安全资源池。在本申请实施例中,NCE-campus增加了对安全资源池的SID的部署,APN标识(identification,ID)中用户标识(user identification,USRID)的模板部署、USRID 与安全业务的对应关系的部署。北向对接运营商云网安业务编排系统,南向对接安全资源池。
示例性地,NCE-campus为云化安全池1部署存储资源池(storage resource pool,SRP)1 SID,为云化安全池2部署SRP2 SID。NCE-IP将SRP1 SID和SRP2 SID作为转发节点进行路径编排,得到安全业务链路径,将安全业务链路径下发至CPE和网PE设备。
安全资源池(也称云化安全池),用于进行安全业务处理。在本申请实施例中,安全资源池支持SRv6 SID部署、SRv6报文转发能力、APNID中的USRID的识别、USRID与安全业务的映射。安全资源池北向对接NCE-campus,安全资源池由NCE-campus管控。其中,云化安全池1包括VAS1和VAS2,云化安全池2包括VAS3。
智能城域网包括多个城域接入路由器(metro access router,MER)、多个城域边缘路由器(metro edge router,MER)和多个城域核心路由器(metro core router,MCR)等,云骨干包括多个PE设备、网PE设备、云PE设备和P设备等。
如图6所示,CPE生成SRv6报文,SRv6报文包括负载(payload)。CPE在SRv6报文中携带APNID,APNID包括APPID和USRID,且CPE通过SRv6隧道封装有段路由报文头(segment routing header,SRH),SRH从下到上依次包括MAR2 SID、MER1 SID、MCR2 SID、网PE SID和网PE VPN SID,则MAR2 SID、MER1 SID、MCR2 SID、网PE SID和网PE VPN SID为业务链转发路径上的节点信息。由此,CPE根据SRH包括的MAR2 SID指示下一跳为MAR2,则向MAR2发送该SRv6报文。进而SRv6报文由MAR2、MER1、MCR2穿过智能城域网到达网PE设备,传输过程中,SRv6报文携带APNID,使得APN服务与报文随行。
可选地,网PE设备在接收到SRv6报文后,通过识别报文中的APPID自动进入安全业务链。网PE设备获取该APPID对应的安全业务链转发路径,将SRv6报文封装的SRH更改为安全业务链转发路径,即SRH包括SRP2 SID、SRP1 SID、云PE SID和云PE VPN SID。网PE设备根据SRH包括的SRP2 SID指示下一跳为云化安全池1,则向云化安全池1发送该SRv6报文。
云化安全池1在接收到SRv6报文后,识别SRv6报文中的USRID,根据USRID映射对应的安全服务,进而根据映射的安全服务对SRv6报文进行完全业务处理。之后,云化安全池1根据SRH包括的SRP1 SID指示下一跳为云化安全池2,则向云化安全池2发送该SRv6报文。
由此,在基于SRv6+APN6的安全业务链方案中,通过APNID携带APPID和USRID,进而根据APPID进入安全业务链,根据USRID映射对应的安全服务,实现了网络和安全业务的解耦,有效解决了网络设备和资源池之间子接口部署复杂的问题。
以上介绍了本申请实施例的报文转发方法,与上述方法对应,本申请实施例还提供了报文转发装置。图7是本申请实施例提供的一种报文转发装置的结构示意图,该装置应用于第一网络设备,该第一网络设备为上述图3所示的网络设备。基于图7所示的如下多个模块,该图7所示的报文转发装置能够执行网络设备所执行的全部或部分操作。应理解到,该装置可以包括比所示模块更多的附加模块或者省略其中所示的一部分模块,本申请实施例对此并不进行限制。如图7所示,该装置包括:
获取模块701,用于获取第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;
发送模块702,用于基于第一报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第一报文,第一节点信息用于指示第一报文对应的转发路径中的下一跳, 第一报文包括的第一用户标识用于第一服务设备在第一资源池中确定第一报文对应的增值服务;基于第二报文中的第一节点信息指示第一资源池,向第一资源池对应的第一服务设备发送第二报文,第一节点信息用于指示第二报文对应的转发路径中的下一跳,第二报文包括的第二用户标识用于第一服务设备在第一资源池中确定第二报文对应的增值服务。
在一种可能的实施方式中,第一报文还包括第一报文对应的第一业务链路径,第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二报文还包括第二报文对应的第二业务链路径,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
在一种可能的实施方式中,获取模块701,用于接收第三报文,获取第三报文对应的第一业务链路径,对第三报文进行隧道封装,得到第一报文,第一报文包括第一业务链路径;接收第四报文,获取第四报文对应的第二业务链路径,对第四报文进行隧道封装,得到第二报文,第二报文包括第二业务链路径;第一业务链路径包括第一业务链路径经过的至少一个资源池的节点信息,第二业务链路径包括第二业务链路径经过的至少一个资源池的节点信息,至少一个资源池的节点信息包括第一节点信息。
在一种可能的实施方式中,第三报文还包括第一业务标识,第四报文还包括第二业务标识;
获取模块701,用于在多个可选业务链路径中确定第一业务标识对应的可选业务链路径,将第一业务标识对应的可选业务链路径作为第三报文对应的第一业务链路径;
获取模块701,用于在多个可选业务链路径中确定第二业务标识对应的可选业务链路径,将第二业务标识对应的可选业务链路径作为第四报文对应的第二业务链路径。
在一种可能的实施方式中,该装置还包括:
接收模块,用于接收第一控制设备发送的多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息。
在一种可能的实施方式中,第一业务标识和第二业务标识为应用标识,第一业务标识携带在第一报文包括的APN标识中,第二业务标识携带在第二报文包括的APN标识中。
在一种可能的实施方式中,第一报文和第二报文为SRv6报文,第一节点信息为第一资源池的SID。
在一种可能的实施方式中,第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。
图8是本申请实施例提供的一种报文转发装置的结构示意图,该装置应用于第一服务设备,该第一服务设备为上述图3所示的第一服务设备。基于图8所示的如下多个模块,该图8所示的报文转发装置能够执行第一服务设备所执行的全部或部分操作。应理解到,该装置可以包括比所示模块更多的附加模块或者省略其中所示的一部分模块,本申请实施例对此并不进行限制。如图8所示,该装置包括:
接收模块801,用于接收网络设备发送的第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一报文中的第一节点信息指示第一报文的转发路径中网络设备的下一跳为第一资源池,第二报文中的第一节点信息指示第二报文的转发路径中网络设备的下一跳为第一资源池;
确定模块802,用于根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务, 根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。
在一种可能的实施方式中,确定模块802,用于根据多个标识与多个增值服务的一一对应关系,确定与第一用户标识对应的增值服务,将与第一用户标识对应的增值服务作为第一报文对应的第一增值服务;根据多个标识与多个增值服务的一一对应关系,确定第二用户标识对应的增值服务,将与第二用户标识对应的增值服务作为第二报文对应的第二增值服务。
在一种可能的实施方式中,该装置还包括:
发送模块,用于基于第一报文中的第二节点信息指示第二资源池,向第二资源池对应的第二服务设备发送第一报文,第二节点信息用于指示第一报文对应的转发路径中的下一跳;基于第二报文中的第三节点信息指示第三资源池,向第三资源池对应的第三服务设备发送第二报文,第三节点信息用于指示第二报文对应的转发路径中的下一跳。
在一种可能的实施方式中,该装置还包括:
处理模块,用于调用第一增值服务对应的资源对第一报文进行增值业务处理,调用第二增值服务对应的资源对第二报文进行增值业务处理。
在一种可能的实施方式中,第一报文和第二报文为SRv6报文,第一节点信息为第一资源池的SID。
在一种可能的实施方式中,第一用户标识携带在第一报文包括的APN标识中,第二用户标识携带在第二报文包括的APN标识中。
图9是本申请实施例提供的一种报文转发装置的结构示意图,该装置应用于第一控制设备。基于图9所示的如下多个模块,该图9所示的报文转发装置能够执行控制设备所执行的全部或部分操作。应理解到,该装置可以包括比所示模块更多的附加模块或者省略其中所示的一部分模块,本申请实施例对此并不进行限制。如图9所示,该装置包括:
第一获取模块901,用于获取多个可选业务链路径,任一可选业务链路径包括任一可选业务链路径经过的至少一个资源池的节点信息,多个可选业务链路径包括第一报文对应的第一业务链路径和第二报文对应的第二业务链路径,第一业务链路径包括的第一节点信息用于指示第一报文对应的转发路径中网络设备的下一跳,第二业务链路径包括的第一节点信息用于指示第二报文对应的转发路径中网络设备的下一跳,第一节点信息指示第一资源池;
发送模块902,用于向网络设备发送多个可选业务链路径,网络设备用于根据多个可选业务链路径中的第一业务链路径转发第一报文,根据多个可选业务链路径中的第二业务链路径转发第二报文。
在一种可能的实施方式中,该装置还包括:
第二获取模块,用于获取多个资源池分别对应的SID;
第一获取模块901,用于根据多个资源池分别对应的SID进行路径编排,得到多个可选业务链路径,任一可选业务链路径包括的至少一个资源池的节点信息为至少一个资源池分别对应的SID。
本申请实施例提供的报文转发装置,在同一资源池提供多用户的增值服务的情况下,无需在网络设备和服务设备之间创建较多的子接口,可以直接将不同用户的报文发送给资源池对应的服务设备,服务设备能够根据报文携带的用户标识来映射不同用户对应的增值服务。因此,该装置简化了资源池的子接口部署,并且在路径编排时也无需区分同一资源池的不同的子接口,降低了路径编排的计算难度。
应理解的是,上述图7-9提供的装置在实现其功能时,仅以上述各功能模块的划分进行举例说明,实际应用中,可以根据需要而将上述功能分配由不同的功能模块完成,即将设备的内部结构划分成不同的功能模块,以完成以上描述的全部或者部分功能。另外,上述实施例提供的装置与方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
参见图10,图10示出了本申请一个示例性实施例提供的网络设备2000的结构示意图。图10所示的网络设备2000用于执行上述图3所示的报文转发方法所涉及的操作。该网络设备2000例如是交换机、路由器等,该网络设备2000可以由一般性的总线体系结构来实现。
如图10所示,网络设备2000包括至少一个处理器2001、存储器2003以及至少一个通信接口2004。
处理器2001例如是通用中央处理器(central processing unit,CPU)、数字信号处理器(digital signal processor,DSP)、网络处理器(network processer,NP)、图形处理器(Graphics Processing Unit,GPU)、神经网络处理器(neural-network processing units,NPU)、数据处理单元(Data Processing Unit,DPU)、微处理器或者一个或多个用于实现本申请方案的集成电路。例如,处理器2001包括专用集成电路(application-specific integrated circuit,ASIC),可编程逻辑器件(programmable logic device,PLD)或者其他可编程逻辑器件、晶体管逻辑器件、硬件部件或者其任意组合。PLD例如是复杂可编程逻辑器件(complex programmable logic device,CPLD)、现场可编程逻辑门阵列(field-programmable gate array,FPGA)、通用阵列逻辑(generic array logic,GAL)或其任意组合。其可以实现或执行结合本发明实施例公开内容所描述的各种逻辑方框、模块和电路。处理器也可以是实现计算功能的组合,例如包括一个或多个微处理器组合,DSP和微处理器的组合等等。
可选的,网络设备2000还包括总线。总线用于在网络设备2000的各组件之间传送信息。总线可以是外设部件互连标准(peripheral component interconnect,简称PCI)总线或扩展工业标准结构(extended industry standard architecture,简称EISA)总线等。总线可以分为地址总线、数据总线、控制总线等。为便于表示,图10中仅用一条线表示,但并不表示仅有一根总线或一种类型的总线。
存储器2003例如是只读存储器(read-only memory,ROM)或可存储静态信息和指令的其它类型的静态存储设备,又如是随机存取存储器(random access memory,RAM)或者可存储信息和指令的其它类型的动态存储设备,又如是电可擦可编程只读存储器(electrically erasable programmable read-only Memory,EEPROM)、只读光盘(compact disc read-only memory,CD-ROM)或其它光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其它磁存储设备,或者是能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其它介质,但不限于此。存储器2003例如是独立存在,并通过总线与处理器2001相连接。存储器2003也可以和处理器2001集成在一起。
通信接口2004使用任何收发器一类的装置,用于与其它设备或通信网络通信,通信网络可以为以太网、无线接入网(radio access network,RAN)或无线局域网(wireless local area networks,WLAN)等。通信接口2004可以包括有线通信接口,还可以包括无线通信接口。具体的,通信接口2004可以为以太(Ethernet)接口、快速以太(Fast Ethernet,FE)接口、千兆以太(Gigabit Ethernet,GE)接口,异步传输模式(Asynchronous Transfer Mode,ATM) 接口,无线局域网(wireless local area networks,WLAN)接口,蜂窝网络通信接口或其组合。以太网接口可以是光接口,电接口或其组合。在本申请实施例中,通信接口2004可以用于网络设备2000与其他设备进行通信。
在具体实现中,作为一种实施例,处理器2001可以包括一个或多个CPU,如图10中所示的CPU0和CPU1。这些处理器中的每一个可以是一个单核(single-core CPU)处理器,也可以是一个多核(multi-core CPU)处理器。这里的处理器可以指一个或多个设备、电路、和/或用于处理数据(例如计算机程序指令)的处理核。
在具体实现中,作为一种实施例,网络设备2000可以包括多个处理器,如图10中所示的处理器2001和处理器2005。这些处理器中的每一个可以是一个单核处理器(single-core CPU),也可以是一个多核处理器(multi-core CPU)。这里的处理器可以指一个或多个设备、电路、和/或用于处理数据(如计算机程序指令)的处理核。
在具体实现中,作为一种实施例,网络设备2000还可以包括输出设备和输入设备。输出设备和处理器2001通信,可以以多种方式来显示信息。例如,输出设备可以是液晶显示器(liquid crystal display,LCD)、发光二级管(light emitting diode,LED)显示设备、阴极射线管(cathode ray tube,CRT)显示设备或投影仪(projector)等。输入设备和处理器2001通信,可以以多种方式接收用户的输入。例如,输入设备可以是鼠标、键盘、触摸屏设备或传感设备等。
在一些实施例中,存储器2003用于存储执行本申请方案的程序代码2010,处理器2001可以执行存储器2003中存储的程序代码2010。也即是,网络设备2000可以通过处理器2001以及存储器2003中的程序代码2010,来实现方法实施例提供的报文转发方法。程序代码2010中可以包括一个或多个软件模块。可选地,处理器2001自身也可以存储执行本申请方案的程序代码或指令。
在具体实施例中,本申请实施例的网络设备2000可对应于上述各个方法实施例中的第一网络设备,网络设备2000中的处理器2001读取存储器2003中的指令,使图10所示的网络设备2000能够执行网络设备所执行的全部或部分操作。
具体的,处理器2001用于获取第一报文和第二报文,其中,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;基于第一报文中的第一节点信息指示第一资源池,且第一节点信息用于指示第一报文对应的转发路径中的下一跳,网络设备向第一资源池对应的第一服务设备发送第一报文;同理,基于第二报文中的第一节点信息也指示第一资源池,且第一节点信息也用于指示第二报文对应的转发路径中的下一跳,网络设备向第一资源池对应的第一服务设备发送第二报文。
其他可选的实施方式,为了简洁,在此不再赘述。
又例如,本申请实施例的网络设备2000可对应于上述各个方法实施例中的第一服务设备,网络设备2000中的处理器2001读取存储器2003中的指令,使图10所示的网络设备2000能够执行第一服务设备所执行的全部或部分操作。
具体的,处理器2001用于接收网络设备发送的第一报文和第二报文,第一报文包括第一用户标识,第二报文包括第二用户标识,第一用户标识与第二用户标识不同;根据第一用户标识在第一资源池中确定第一报文对应的第一增值服务,根据第二用户标识在第一资源池中确定第二报文对应的第二增值服务。
其他可选的实施方式,为了简洁,在此不再赘述。
网络设备2000还可以对应于上述图7-9所示的报文转发装置,报文转发装置中的每个功能模块采用网络设备2000的软件实现。换句话说,报文转发装置包括的功能模块为网络设备2000的处理器2001读取存储器2003中存储的程序代码2010后生成的。
其中,图3所示的报文转发方法的各步骤通过网络设备2000的处理器中的硬件的集成逻辑电路或者软件形式的指令完成。结合本申请实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤,为避免重复,这里不再详细描述。
参见图11,图11示出了本申请另一个示例性实施例提供的网络设备2100的结构示意图,图11所示的网络设备2100用于执行上述图3所示的报文转发方法所涉及的全部或部分操作。该网络设备2100例如是交换机、路由器等,该网络设备2100可以由一般性的总线体系结构来实现。
如图11所示,网络设备2100包括:主控板2110和接口板2130。
主控板也称为主处理单元(main processing unit,MPU)或路由处理卡(route processor card),主控板2110用于对网络设备2100中各个组件的控制和管理,包括路由计算、设备管理、设备维护、协议处理功能。主控板2110包括:中央处理器2111和存储器2112。
接口板2130也称为线路接口单元(line processing unit,LPU)、线卡(line card)或业务板。接口板2130用于提供各种业务接口并实现数据包的转发。业务接口包括而不限于以太网接口、POS(Packet over SONET/SDH)接口等,以太网接口例如是灵活以太网业务接口(Flexible Ethernet Clients,FlexE Clients)。接口板2130包括:中央处理器2131、网络处理器2132、转发表项存储器2134和物理接口卡(physical interface card,PIC)2133。
接口板2130上的中央处理器2131用于对接口板2130进行控制管理并与主控板2110上的中央处理器2111进行通信。
网络处理器2132用于实现报文的转发处理。网络处理器2132的形态可以是转发芯片。转发芯片可以是网络处理器(network processor,NP)。在一些实施例中,转发芯片可以通过专用集成电路(application-specific integrated circuit,ASIC)或现场可编程门阵列(field programmable gate array,FPGA)实现。具体而言,网络处理器2132用于基于转发表项存储器2134保存的转发表转发接收到的报文,如果报文的目的地址为网络设备2100的地址,则将该报文上送至CPU(如中央处理器2131)处理;如果报文的目的地址不是网络设备2100的地址,则根据该目的地址从转发表中查找到该目的地址对应的下一跳和出接口,将该报文转发到该目的地址对应的出接口。其中,上行报文的处理可以包括:报文入接口的处理,转发表查找;下行报文的处理可以包括:转发表查找等等。在一些实施例中,中央处理器也可执行转发芯片的功能,比如基于通用CPU实现软件转发,从而接口板中不需要转发芯片。
物理接口卡2133用于实现物理层的对接功能,原始的流量由此进入接口板2130,以及处理后的报文从该物理接口卡2133发出。物理接口卡2133也称为子卡,可安装在接口板2130上,负责将光电信号转换为报文并对报文进行合法性检查后转发给网络处理器2132处理。在一些实施例中,中央处理器2131也可执行网络处理器2132的功能,比如基于通用CPU实现 软件转发,从而物理接口卡2133中不需要网络处理器2132。
可选地,网络设备2100包括多个接口板,例如网络设备2100还包括接口板2140,接口板2140包括:中央处理器2141、网络处理器2142、转发表项存储器2144和物理接口卡2143。接口板2140中各部件的功能和实现方式与接口板2130相同或相似,在此不再赘述。
可选地,网络设备2100还包括交换网板2120。交换网板2120也可以称为交换网板单元(switch fabric unit,SFU)。在网络设备2100有多个接口板的情况下,交换网板2120用于完成各接口板之间的数据交换。例如,接口板2130和接口板2140之间可以通过交换网板2120通信。
主控板2110和接口板耦合。例如。主控板2110、接口板2130和接口板2140,以及交换网板2120之间通过系统总线与系统背板相连实现互通。在一种可能的实现方式中,主控板2110和接口板2130及接口板2140之间建立进程间通信协议(inter-process communication,IPC)通道,主控板2110和接口板2130及接口板2140之间通过IPC通道进行通信。
在逻辑上,网络设备2100包括控制面和转发面,控制面包括主控板2110和中央处理器2111,转发面包括执行转发的各个组件,比如转发表项存储器2134、物理接口卡2133和网络处理器2132。控制面执行路由器、生成转发表、处理信令和协议报文、配置与维护网络设备的状态等功能,控制面将生成的转发表下发给转发面,在转发面,网络处理器2132基于控制面下发的转发表对物理接口卡2133收到的报文查表转发。控制面下发的转发表可以保存在转发表项存储器2134中。在有些实施例中,控制面和转发面可以完全分离,不在同一网络设备上。
值得说明的是,主控板可能有一块或多块,有多块的时候可以包括主用主控板和备用主控板。接口板可能有一块或多块,网络设备的数据处理能力越强,提供的接口板越多。接口板上的物理接口卡也可以有一块或多块。交换网板可能没有,也可能有一块或多块,有多块的时候可以共同实现负荷分担冗余备份。在集中式转发架构下,网络设备可以不需要交换网板,接口板承担整个系统的业务数据的处理功能。在分布式转发架构下,网络设备可以有至少一块交换网板,通过交换网板实现多块接口板之间的数据交换,提供大容量的数据交换和处理能力。所以,分布式架构的网络设备的数据接入和处理能力要大于集中式架构的网络设备。可选地,网络设备的形态也可以是只有一块板卡,即没有交换网板,接口板和主控板的功能集成在该一块板卡上,此时接口板上的中央处理器和主控板上的中央处理器在该一块板卡上可以合并为一个中央处理器,执行两者叠加后的功能,这种形态网络设备的数据交换和处理能力较低(例如,低端交换机或路由器等网络设备)。具体采用哪种架构,取决于具体的组网部署场景,此处不做任何限定。
在具体实施例中,网络设备2100对应于上述图7所示的应用于网络设备的报文转发装置。在一些实施例中,图7所示的报文转发装置中的获取模块701相当于网络设备2100中的中央处理器2111或网络处理器2132,发送模块702相当于网络设备2100中的物理接口卡2133。
在一些实施例中,网络设备2100还对应于上述图8所示的应用于第一服务设备的报文转发装置。在一些实施例中,图8所示的报文转发装置中的接收模块801相当于网络设备2100中的物理接口卡2133,确定模块802相当于网络设备2100中的中央处理器2111或网络处理器2132。
图12是本申请实施例提供的一种服务器的结构示意图,该服务器1300可因配置或性能 不同而产生比较大的差异,可以包括一个或多个处理器1301和一个或多个存储器1302,其中,该一个或多个存储器1302中存储有至少一条计算机程序,该至少一条计算机程序由该一个或多个处理器1301加载并执行,以使该服务器实现上述各个方法实施例提供的报文转发方法。当然,该服务器1300还可以具有有线或无线网络接口、键盘以及输入输出接口等部件,以便进行输入输出,该服务器1300还可以包括其他用于实现设备功能的部件,在此不做赘述。
基于上述图10及图11所示的网络设备与图12所示的服务器,本申请实施例还提供了一种报文转发系统,该处理系统包括:网络设备、第一服务设备和控制设备。例如,网络设备和第一服务设备为图10所示的网络设备2000或图11所示的网络设备2100,控制设备为图12所示的服务器。网络设备、第一服务设备和控制设备所执行的报文转发方法可参见上述图3所示实施例的相关描述,此处不再加以赘述。
本申请实施例还提供了一种通信装置,该装置包括:收发器、存储器和处理器。其中,该收发器、该存储器和该处理器通过内部连接通路互相通信,该存储器用于存储指令,该处理器用于执行该存储器存储的指令,以控制收发器接收信号,并控制收发器发送信号,并且当该处理器执行该存储器存储的指令时,使得该处理器执行网络设备所需执行的方法。
本申请实施例还提供了一种通信装置,该装置包括:收发器、存储器和处理器。其中,该收发器、该存储器和该处理器通过内部连接通路互相通信,该存储器用于存储指令,该处理器用于执行该存储器存储的指令,以控制收发器接收信号,并控制收发器发送信号,并且当该处理器执行该存储器存储的指令时,使得该处理器执行第一服务设备所需执行的方法。
本申请实施例还提供了一种通信装置,该装置包括:收发器、存储器和处理器。其中,该收发器、该存储器和该处理器通过内部连接通路互相通信,该存储器用于存储指令,该处理器用于执行该存储器存储的指令,以控制收发器接收信号,并控制收发器发送信号,并且当该处理器执行该存储器存储的指令时,使得该处理器执行控制设备所需执行的方法。
应理解的是,上述处理器可以是CPU,还可以是其他通用处理器、数字信号处理器(digital signal processing,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现场可编程门阵列(field-programmable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者是任何常规的处理器等。值得说明的是,处理器可以是支持进阶精简指令集机器(advanced RISC machines,ARM)架构的处理器。
进一步地,在一种可选的实施例中,上述存储器可以包括只读存储器和随机存取存储器,并向处理器提供指令和数据。存储器还可以包括非易失性随机存取存储器。例如,存储器还可以存储设备类型的信息。
该存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(read-only memory,ROM)、可编程只读存储器(programmable ROM,PROM)、可擦除可编程只读存储器(erasable PROM,EPROM)、电可擦除可编程只读存储器(electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(random access memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用。例如,静态随机存取存储器(static RAM,SRAM)、动态随机存取存储器(dynamic random access memory,DRAM)、同步动态随机存取存储器(synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(double data rate  SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(direct rambus RAM,DR RAM)。
本申请实施例还提供了一种计算机可读存储介质,存储介质中存储有至少一条指令,指令由处理器加载并执行,以使计算机实现如上任一的报文转发方法。
本申请实施例还提供了一种计算机程序(产品),当计算机程序被计算机执行时,可以使得处理器或计算机执行上述方法实施例中对应的各个步骤和/或流程。
本申请实施例还提供了一种芯片,包括处理器,用于从存储器中调用并运行存储器中存储的指令,使得安装有芯片的通信设备执行如上任一的报文转发方法。
本申请实施例还提供另一种芯片,包括:输入接口、输出接口、处理器和存储器,输入接口、输出接口、处理器以及存储器之间通过内部连接通路相连,处理器用于执行存储器中的代码,当代码被执行时,处理器用于执行如上任一的报文转发方法。
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行计算机程序指令时,全部或部分地产生按照本申请的流程或功能。计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线)或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集成的服务器、数据中心等数据存储设备。可用介质可以是磁性介质,(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质(例如,固态硬盘(solid state disk))等。
本领域普通技术人员可以意识到,结合本文中所公开的实施例中描述的各方法步骤和模块,能够以软件、硬件、固件或者其任意组合来实现,为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地描述了各实施例的步骤及组成。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。本领域普通技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。
本领域普通技术人员可以理解实现上述实施例的全部或部分步骤可以通过硬件来完成,也可以通过程序来指令相关的硬件完成,该程序可以存储于一种计算机可读存储介质中,上述提到的存储介质可以是只读存储器,磁盘或光盘等。
当使用软件实现时,可以全部或部分地以计算机程序产品的形式实现。该计算机程序产品包括一个或多个计算机程序指令。作为示例,本申请实施例的方法可以在机器可执行指令的上下文中被描述,机器可执行指令诸如包括在目标的真实或者虚拟处理器上的器件中执行的程序模块中。一般而言,程序模块包括例程、程序、库、对象、类、组件、数据结构等,其执行特定的任务或者实现特定的抽象数据结构。在各实施例中,程序模块的功能可以在所描述的程序模块之间合并或者分割。用于程序模块的机器可执行指令可以在本地或者分布式设备内执行。在分布式设备中,程序模块可以位于本地和远程存储介质二者中。
用于实现本申请实施例的方法的计算机程序代码可以用一种或多种编程语言编写。这些计算机程序代码可以提供给通用计算机、专用计算机或其他可编程的数据处理装置的处理器,使得程序代码在被计算机或其他可编程的数据处理装置执行的时候,引起在流程图和/或框图中规定的功能/操作被实施。程序代码可以完全在计算机上、部分在计算机上、作为独立的软件包、部分在计算机上且部分在远程计算机上或完全在远程计算机或服务器上执行。
在本申请实施例的上下文中,计算机程序代码或者相关数据可以由任意适当载体承载,以使得设备、装置或者处理器能够执行上文描述的各种处理和操作。载体的示例包括信号、计算机可读介质等等。
信号的示例可以包括电、光、无线电、声音或其它形式的传播信号,诸如载波、红外信号等。
机器可读介质可以是包含或存储用于或有关于指令执行系统、装置或设备的程序的任何有形介质。机器可读介质可以是机器可读信号介质或机器可读存储介质。机器可读介质可以包括但不限于电子的、磁的、光学的、电磁的、红外的或半导体系统、装置或设备,或其任意合适的组合。机器可读存储介质的更详细示例包括带有一根或多根导线的电气连接、便携式计算机磁盘、硬盘、随机存储存取器(RAM)、只读存储器(ROM)、可擦除可编程只读存储器(EPROM或闪存)、光存储设备、磁存储设备,或其任意合适的组合。
所属领域的技术人员可以清楚地了解到,为了描述的方便和简洁,上述描述的系统、设备和模块的具体工作过程,可以参见前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、设备和方法,可以通过其它的方式实现。例如,以上所描述的设备实施例仅仅是示意性的,例如,该模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个模块或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另外,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口、设备或模块的间接耦合或通信连接,也可以是电的,机械的或其它的形式连接。
该作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理模块,即可以位于一个地方,或者也可以分布到多个网络模块上。可以根据实际的需要选择其中的部分或者全部模块来实现本申请实施例方案的目的。
另外,在本申请各个实施例中的各功能模块可以集成在一个处理模块中,也可以是各个模块单独物理存在,也可以是两个或两个以上模块集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。
该集成的模块如果以软件功能模块的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分,或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例中方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(read-only memory,ROM)、随机存取存储器(random access memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
本申请中术语“第一”“第二”等字样用于对作用和功能基本相同的相同项或相似项进行区分,应理解,“第一”、“第二”、“第n”之间不具有逻辑或时序上的依赖关系,也不对数量和执 行顺序进行限定。还应理解,尽管以下描述使用术语第一、第二等来描述各种元素,但这些元素不应受术语的限制。这些术语只是用于将一元素与另一元素区别分开。例如,在不脱离各种示例的范围的情况下,第一图像可以被称为第二图像,并且类似地,第二图像可以被称为第一图像。第一图像和第二图像都可以是图像,并且在某些情况下,可以是单独且不同的图像。
还应理解,在本申请的各个实施例中,各个过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。
本申请中术语“至少一个”的含义是指一个或多个,本申请中术语“多个”的含义是指两个或两个以上,例如,多个第二报文是指两个或两个以上的第二报文。本文中术语“系统”和“网络”经常可互换使用。
应理解,在本文中对各种所述示例的描述中所使用的术语只是为了描述特定示例,而并非旨在进行限制。如在对各种所述示例的描述和所附权利要求书中所使用的那样,单数形式“一个(“a”,“an”)”和“该”旨在也包括复数形式,除非上下文另外明确地指示。
还应理解,本文中所使用的术语“和/或”是指并且涵盖相关联的所列出的项目中的一个或多个项目的任何和全部可能的组合。术语“和/或”,是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本申请中的字符“/”,一般表示前后关联对象是一种“或”的关系。
还应理解,术语“包括”(也称“includes”、“including”、“comprises”和/或“comprising”)当在本说明书中使用时指定存在所陈述的特征、整数、步骤、操作、元素、和/或部件,但是并不排除存在或添加一个或多个其他特征、整数、步骤、操作、元素、部件、和/或其分组。
还应理解,术语“若”和“如果”可被解释为意指“当...时”(“when”或“upon”)或“响应于确定”或“响应于检测到”。类似地,根据上下文,短语“若确定...”或“若检测到[所陈述的条件或事件]”可被解释为意指“在确定...时”或“响应于确定...”或“在检测到[所陈述的条件或事件]时”或“响应于检测到[所陈述的条件或事件]”。
应理解,根据A确定B并不意味着仅仅根据A确定B,还可以根据A和/或其它信息确定B。
还应理解,说明书通篇中提到的“一个实施例”、“一实施例”、“一种可能的实现方式”意味着与实施例或实现方式有关的特定特征、结构或特性包括在本申请的至少一个实施例中。因此,在整个说明书各处出现的“在一个实施例中”或“在一实施例中”、“一种可能的实现方式”未必一定指相同的实施例。此外,这些特定的特征、结构或特性可以任意适合的方式结合在一个或多个实施例中。
以上描述仅为本申请的可选实施例,并不用以限制本申请,凡在本申请的原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (22)

  1. 一种报文转发方法,其特征在于,应用于网络设备,所述方法包括:
    获取第一报文和第二报文,所述第一报文包括第一用户标识,所述第二报文包括第二用户标识,所述第一用户标识与所述第二用户标识不同;
    基于所述第一报文中的第一节点信息指示第一资源池,向所述第一资源池对应的第一服务设备发送所述第一报文,所述第一节点信息用于指示所述第一报文对应的转发路径中的下一跳,所述第一报文包括的所述第一用户标识用于所述第一服务设备在所述第一资源池中确定所述第一报文对应的增值服务;
    基于所述第二报文中的所述第一节点信息指示所述第一资源池,向所述第一资源池对应的第一服务设备发送所述第二报文,所述第一节点信息用于指示所述第二报文对应的转发路径中的下一跳,所述第二报文包括的所述第二用户标识用于所述第一服务设备在所述第一资源池中确定所述第二报文对应的增值服务。
  2. 根据权利要求1所述的方法,其特征在于,所述第一报文还包括所述第一报文对应的第一业务链路径,所述第一业务链路径包括所述第一业务链路径经过的至少一个资源池的节点信息,所述第二报文还包括所述第二报文对应的第二业务链路径,所述第二业务链路径包括所述第二业务链路径经过的至少一个资源池的节点信息,所述至少一个资源池的节点信息包括所述第一节点信息。
  3. 根据权利要求1所述的方法,其特征在于,所述获取第一报文和第二报文,包括:
    接收第三报文,获取所述第三报文对应的第一业务链路径,对所述第三报文进行隧道封装,得到所述第一报文,所述第一报文包括所述第一业务链路径;
    接收第四报文,获取所述第四报文对应的第二业务链路径,对所述第四报文进行隧道封装,得到所述第二报文,所述第二报文包括所述第二业务链路径;
    所述第一业务链路径包括所述第一业务链路径经过的至少一个资源池的节点信息,第二业务链路径包括所述第二业务链路径经过的至少一个资源池的节点信息,所述至少一个资源池的节点信息包括所述第一节点信息。
  4. 根据权利要求3所述的方法,其特征在于,所述第三报文还包括第一业务标识,所述第四报文还包括第二业务标识;
    所述获取所述第三报文对应的第一业务链路径,包括:
    在多个可选业务链路径中确定所述第一业务标识对应的可选业务链路径,将所述第一业务标识对应的可选业务链路径作为所述第三报文对应的第一业务链路径;
    所述获取所述第四报文对应的第二业务链路径,包括:
    在多个可选业务链路径中确定所述第二业务标识对应的可选业务链路径,将所述第二业务标识对应的可选业务链路径作为所述第四报文对应的第二业务链路径。
  5. 根据权利要求4所述的方法,其特征在于,所述在多个可选业务链路径中确定所述第一业务标识对应的可选业务链路径之前,还包括:
    接收控制设备发送的所述多个可选业务链路径,任一可选业务链路径包括所述任一可选业务链路径经过的至少一个资源池的节点信息。
  6. 根据权利要求4或5所述的方法,其特征在于,所述第一业务标识和所述第二业务标识为应用标识,所述第一业务标识携带在所述第一报文包括的应用感知网络APN标识中,所述第二业务标识携带在所述第二报文包括的APN标识中。
  7. 根据权利要求1-6任一所述的方法,其特征在于,所述第一报文和所述第二报文为基于互联网协议第6版的段路由SRv6报文,所述第一节点信息为所述第一资源池的段标识SID。
  8. 根据权利要求1-7任一所述的方法,其特征在于,所述第一用户标识携带在所述第一报文包括的APN标识中,所述第二用户标识携带在所述第二报文包括的APN标识中。
  9. 一种报文转发方法,其特征在于,应用于第一服务设备,所述方法包括:
    接收网络设备发送的第一报文和第二报文,所述第一报文包括第一用户标识,所述第二报文包括第二用户标识,所述第一用户标识与所述第二用户标识不同,所述第一报文中的第一节点信息指示所述第一报文的转发路径中所述网络设备的下一跳为第一资源池,所述第二报文中的所述第一节点信息指示所述第二报文的转发路径中所述网络设备的下一跳为所述第一资源池;
    根据所述第一用户标识在第一资源池中确定所述第一报文对应的第一增值服务,根据所述第二用户标识在所述第一资源池中确定所述第二报文对应的第二增值服务。
  10. 根据权利要求9所述的方法,其特征在于,所述根据所述第一用户标识在第一资源池中确定所述第一报文对应的第一增值服务,根据所述第二用户标识在所述第一资源池中确定所述第二报文对应的第二增值服务,包括:
    根据多个标识与多个增值服务的一一对应关系,确定与所述第一用户标识对应的增值服务,将与所述第一用户标识对应的增值服务作为所述第一报文对应的第一增值服务;
    根据所述多个标识与多个增值服务的一一对应关系,确定所述第二用户标识对应的增值服务,将与所述第二用户标识对应的增值服务作为所述第二报文对应的第二增值服务。
  11. 根据权利要求9或10所述的方法,其特征在于,所述方法还包括:
    基于所述第一报文中的第二节点信息指示第二资源池,向所述第二资源池对应的第二服务设备发送所述第一报文,所述第二节点信息用于指示所述第一报文对应的转发路径中的下一跳;
    基于所述第二报文中的第三节点信息指示第三资源池,向所述第三资源池对应的第三服务设备发送所述第二报文,所述第三节点信息用于指示所述第二报文对应的转发路径中的下一跳。
  12. 根据权利要求9-11任一所述的方法,其特征在于,所述第一服务设备根据所述第一用户标识在第一资源池中确定所述第一报文对应的第一增值服务,根据所述第二用户标识在所述第一资源池中确定所述第二报文对应的第二增值服务之后,还包括:
    调用所述第一增值服务对应的资源对所述第一报文进行增值业务处理,调用所述第二增值服务对应的资源对所述第二报文进行增值业务处理。
  13. 根据权利要求9-12任一所述的方法,其特征在于,所述第一报文和所述第二报文为基于互联网协议第6版的段路由SRv6报文,所述第一节点信息为所述第一资源池的段标识SID。
  14. 根据权利要求9-13任一所述的方法,其特征在于,所述第一用户标识携带在所述第一报文包括的应用感知网络APN标识中,所述第二用户标识携带在所述第二报文包括的APN标识中。
  15. 一种报文转发方法,其特征在于,应用于控制设备,所述方法包括:
    获取多个可选业务链路径,任一可选业务链路径包括所述任一可选业务链路径经过的至少一个资源池的节点信息,所述多个可选业务链路径包括第一报文对应的第一业务链路径和第二报文对应的第二业务链路径,所述第一业务链路径包括的第一节点信息用于指示所述第一报文对应的转发路径中网络设备的下一跳,所述第二业务链路径包括的所述第一节点信息用于指示所述第二报文对应的转发路径中所述网络设备的下一跳,所述第一节点信息指示第一资源池;
    向所述网络设备发送所述多个可选业务链路径,所述网络设备用于根据所述多个可选业务链路径中的第一业务链路径转发所述第一报文,根据所述多个可选业务链路径中的第二业务链路径转发所述第二报文。
  16. 根据权利要求15所述的方法,其特征在于,所述方法还包括:
    获取多个资源池分别对应的段标识SID;
    所述获取多个可选业务链路径,包括:
    根据所述多个资源池分别对应的SID进行路径编排,得到所述多个可选业务链路径,所述任一可选业务链路径包括的至少一个资源池的节点信息为所述至少一个资源池分别对应的SID。
  17. 一种报文转发方法,其特征在于,所述方法包括:
    网络设备获取第一报文和第二报文,所述第一报文包括第一用户标识,所述第二报文包括第二用户标识,所述第一用户标识与所述第二用户标识不同;
    所述网络设备基于所述第一报文中的第一节点信息指示第一资源池,向所述第一资源池对应的第一服务设备发送所述第一报文,所述第一节点信息用于指示所述第一报文对应的转发路径中的下一跳;基于所述第二报文中的所述第一节点信息指示所述第一资源池,向所述第一资源池对应的第一服务设备发送所述第二报文,所述第一节点信息用于指示所述第二报 文对应的转发路径中的下一跳;
    所述第一服务设备接收所述网络设备发送的所述第一报文和所述第二报文;
    所述第一服务设备根据所述第一用户标识在所述第一资源池中确定所述第一报文对应的第一增值服务,根据所述第二用户标识在所述第一资源池中确定所述第二报文对应的第二增值服务。
  18. 根据权利要求17所述的方法,其特征在于,所述方法还包括:
    控制设备获取多个可选业务链路径,任一可选业务链路径包括所述任一可选业务链路径经过的至少一个资源池的节点信息,所述多个可选业务链路径包括所述第一报文对应的第一业务链路径和所述第二报文对应的第二业务链路径,所述第一业务链路径包括的第一节点信息用于指示所述第一报文对应的转发路径中网络设备的下一跳,所述第二业务链路径包括的所述第一节点信息用于指示所述第二报文对应的转发路径中所述网络设备的下一跳,所述第一节点信息指示第一资源池;
    所述控制设备向所述网络设备发送所述多个可选业务链路径,所述多个可选业务链路径用于所述网络设备获取所述第一业务链路径和所述第二业务链路径。
  19. 一种报文转发系统,其特征在于,所述报文转发系统包括网络设备、第一服务设备和控制设备;
    所述网络设备用于执行权利要求1-8任一所述的方法,所述第一服务设备用于执行权利要求9-14任一所述的方法,所述控制设备用于执行权利要求15或16所述的方法。
  20. 一种网络设备,其特征在于,所述网络设备包括:处理器,所述处理器与存储器耦合,所述存储器中存储有至少一条程序指令或代码,所述至少一条程序指令或代码由所述处理器加载并执行,以使所述网络设备实现权利要求1-18中任一所述的报文转发方法。
  21. 一种计算机可读存储介质,其特征在于,所述计算机存储介质中存储有至少一条指令,所述至少一条指令由处理器加载并执行,以使计算机实现如权利要求1-18中任一所述的报文转发方法。
  22. 一种计算机程序产品,其特征在于,所述计算机程序产品包括:计算机程序代码,所述计算机程序代码由计算机加载并执行,以使所述计算机实现权利要求1-18中任一所述的报文转发方法。
PCT/CN2023/087576 2022-08-03 2023-04-11 报文转发方法、设备、系统及存储介质 WO2024027194A1 (zh)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
CN202210927104 2022-08-03
CN202210927104.1 2022-08-03
CN202211352376.X 2022-10-31
CN202211352376.XA CN117527693A (zh) 2022-08-03 2022-10-31 报文转发方法、设备、系统及存储介质

Publications (1)

Publication Number Publication Date
WO2024027194A1 true WO2024027194A1 (zh) 2024-02-08

Family

ID=89761379

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/087576 WO2024027194A1 (zh) 2022-08-03 2023-04-11 报文转发方法、设备、系统及存储介质

Country Status (2)

Country Link
CN (1) CN117527693A (zh)
WO (1) WO2024027194A1 (zh)

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105704167A (zh) * 2014-11-24 2016-06-22 华为技术有限公司 一种业务链处理方法、设备及系统
CN107786437A (zh) * 2016-08-24 2018-03-09 华为技术有限公司 报文转发方法及装置
US20180295053A1 (en) * 2017-04-10 2018-10-11 Cisco Technology, Inc. Service-function chaining using extended service-function chain proxy for service-function offload
CN112491729A (zh) * 2020-09-22 2021-03-12 中兴通讯股份有限公司 一种数据处理方法、装置、存储介质及电子装置
CN113691448A (zh) * 2020-05-18 2021-11-23 华为技术有限公司 SRv6业务链中转发报文的方法、SFF及SF设备
CN114640616A (zh) * 2020-11-30 2022-06-17 华为技术有限公司 一种报文传输、段列表生成、压缩段标识获取方法及装置
CN114697253A (zh) * 2020-12-28 2022-07-01 华为技术有限公司 一种业务链的转发路径确定方法及通信装置

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105704167A (zh) * 2014-11-24 2016-06-22 华为技术有限公司 一种业务链处理方法、设备及系统
CN107786437A (zh) * 2016-08-24 2018-03-09 华为技术有限公司 报文转发方法及装置
US20180295053A1 (en) * 2017-04-10 2018-10-11 Cisco Technology, Inc. Service-function chaining using extended service-function chain proxy for service-function offload
CN113691448A (zh) * 2020-05-18 2021-11-23 华为技术有限公司 SRv6业务链中转发报文的方法、SFF及SF设备
CN112491729A (zh) * 2020-09-22 2021-03-12 中兴通讯股份有限公司 一种数据处理方法、装置、存储介质及电子装置
CN114640616A (zh) * 2020-11-30 2022-06-17 华为技术有限公司 一种报文传输、段列表生成、压缩段标识获取方法及装置
CN114697253A (zh) * 2020-12-28 2022-07-01 华为技术有限公司 一种业务链的转发路径确定方法及通信装置

Also Published As

Publication number Publication date
CN117527693A (zh) 2024-02-06

Similar Documents

Publication Publication Date Title
US11050586B2 (en) Inter-cloud communication method and related device, and inter-cloud communication configuration method and related device
CN112217746B (zh) 云计算系统中报文处理的方法、主机和系统
CN109362085B (zh) 通过openflow数据平面在云计算机中实现epc
CN113132229B (zh) 段标识的确定方法和设备
CN108293022A (zh) 一种报文传输的方法、装置和系统
WO2022001835A1 (zh) 发送报文的方法、装置、网络设备、系统及存储介质
CN114189905A (zh) 一种报文处理方法及相关设备
JP2015032932A (ja) キャリア網における経路制御システム及び方法
US20230156828A1 (en) Session establishment method and apparatus, system, and computer storage medium
WO2021147358A1 (zh) 一种网络接口的建立方法、装置及系统
CN113726915A (zh) 网络系统及其中的报文传输方法和相关装置
WO2023179457A1 (zh) 业务连接的标识方法、装置、系统及存储介质
CN111130978B (zh) 网络流量转发方法、装置、电子设备及机器可读存储介质
WO2024027194A1 (zh) 报文转发方法、设备、系统及存储介质
CN114422297B (zh) 一种多场景虚拟网络流量监控方法、系统、终端及介质
WO2022166465A1 (zh) 一种报文处理方法及相关装置
CN116828024A (zh) 业务连接的标识方法、装置、系统及存储介质
US11743180B2 (en) System and method for routing traffic onto an MPLS network
CN110620999B (zh) 用户面数据处理方法及装置
CN114513485A (zh) 获取映射规则的方法、装置、设备、系统及可读存储介质
US11996993B2 (en) Packet transmission method, apparatus, and system, and storage medium
US20240195731A1 (en) Software defined network controller, network device, method and apparatus of determining resources
WO2023231779A1 (zh) 一种基于alto协议的通信方法以及相关装置
WO2023040729A1 (zh) 报文处理方法、流规范传输方法、设备、系统及存储介质
CN117376240A (zh) 组播业务的回切方法、装置、设备、系统及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23848905

Country of ref document: EP

Kind code of ref document: A1