WO2025256325A1 - 报文处理方法、装置、节点、存储介质及计算机程序产品 - Google Patents
报文处理方法、装置、节点、存储介质及计算机程序产品Info
- Publication number
- WO2025256325A1 WO2025256325A1 PCT/CN2025/094715 CN2025094715W WO2025256325A1 WO 2025256325 A1 WO2025256325 A1 WO 2025256325A1 CN 2025094715 W CN2025094715 W CN 2025094715W WO 2025256325 A1 WO2025256325 A1 WO 2025256325A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network
- message
- arn
- node
- information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/60—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
Definitions
- This disclosure relates to the field of network transmission, and in particular to a message processing method, apparatus, node, storage medium, and computer program product.
- ARN Application Responsive Networking
- the application can call the network path corresponding to the ARN identifier.
- the network boundary device can identify the ARN identifier carried in the packet and forward the packet according to the network path corresponding to the ARN identifier.
- this disclosure provides a message processing method, apparatus, node, storage medium, and computer program product.
- This disclosure provides a message processing method, including:
- the first node receives the first message, which contains the first ARN identifier, and the first node includes the boundary node of the first network;
- the first node performs forwarding-related processing on the first packet on the first interface in association with ARN; or if the first information indicates that the first interface of the first node disables ARN, the first node performs forwarding-related processing on the first packet on the first interface that is not associated with ARN.
- the first message also includes second information, which represents the source of the first message; when the first information represents that the first interface of the first node can use ARN, the first node verifies the second information and the first ARN identifier; after successful verification, the first message is processed for forwarding related to ARN on the first interface.
- the first message also includes second information, which represents the source of the first message; if the first information represents that the first interface of the first node can use ARN, the first node verifies the second information and the first ARN identifier; if the verification fails, the first message is forwarded without ARN association on the first interface.
- the verification of the second information and the first ARN identifier includes:
- the first node uses third information to verify the second information and the first ARN identifier.
- the third information represents the correspondence between the source information of one or more messages and the ARN identifier.
- the method in the above scheme further includes:
- the first node receives the third information sent by the control device
- the first node determines the third information through route learning.
- the second information includes one or more of the following:
- the source address information of the first message
- the port information of the first message is the port information of the first message.
- the forwarding-related processing of the first message associated with ARN includes one of the following:
- the first node sets the first field carrying the first ARN identifier in the first message to the second ARN identifier, thereby obtaining the processed first message.
- the second ARN identifier is associated with the second network, and the processed first message is forwarded to the second network.
- the first node sets the first field carrying the first ARN identifier in the first message to the third ARN identifier, thereby obtaining the processed first message.
- the third ARN identifier is associated with the first network.
- the processed first message is forwarded within the first network in a first manner, wherein the first manner is associated with the third ARN identifier.
- the first node forwards the first message to the second network, where the second network can forward the message in a second manner, the second manner being associated with the second ARN identifier corresponding to the first message;
- the first node forwards the first packet within the first network using a third method, wherein the third method is associated with the first ARN identifier.
- the first node uses the fourth information to set the first field carrying the first ARN identifier in the first message as the second ARN identifier, or sets the first field carrying the first ARN identifier in the first message as the third ARN identifier.
- the fourth information represents the correspondence between one or more ARN identifiers associated with the first network and ARN identifiers associated with the second network.
- the method in the above scheme further includes:
- the first node receives the fourth information sent by the control device
- the first node determines the fourth information through route learning.
- the forwarding-related processing of the first message that is not associated with ARN includes one of the following:
- the first node sets the first field carrying the first ARN identifier in the first message to the fifth information to obtain the processed first message, and forwards the processed first message in the first network in the fourth manner.
- the fourth manner is not associated with ARN, and the fifth information indicates that the first message disables ARN.
- the first node sets the first field carrying the first ARN identifier in the first message to the fifth information to obtain the processed first message, and forwards the processed first message to the second network.
- the fifth information indicates that the first message disables ARN.
- the first node discards the first message.
- This disclosure also provides a message processing apparatus, disposed at a first node, the first node including a boundary node of a first network, comprising:
- a receiving unit is configured to receive a first message, wherein the first message contains a first ARN identifier
- the processing unit is configured to perform forwarding-related processing associated with ARN on the first packet at the first interface when the first information indicates that the first interface of the first node can use ARN, or to perform forwarding-related processing associated with ARN on the first interface when the first information indicates that the first interface of the first node disables ARN.
- This disclosure also provides a node, which includes a boundary node of a first network, comprising:
- a communication interface is used to receive a first message, the first message containing a first ARN identifier
- the processor is configured to perform forwarding-related processing associated with ARN on the first packet at the first interface when the first information indicates that the first interface of the node can use ARN, or to perform forwarding-related processing associated with ARN on the first interface when the first information indicates that the first interface of the node has ARN disabled.
- This disclosure also provides a node, including: a processor and a memory for storing computer programs capable of running on the processor.
- This disclosure also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of any of the above methods.
- This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the above methods.
- the message processing method, apparatus, node, storage medium, and computer program product provided in this disclosure embodiment include a first node receiving a first message, the first message containing a first ARN identifier, and the first node including a boundary node of a first network; when the first information indicates that the first interface of the first node can use ARN, the first message is processed on the first interface in a forwarding manner associated with ARN; or, when the first information indicates that the first interface of the first node disables ARN, the first message is processed on the first interface in a forwarding manner not associated with ARN.
- the solution provided in this disclosure sets first information in a first node at the first network boundary (which can also be understood as the network domain boundary of the first network).
- the first node determines whether to perform forwarding-related processing associated with the ARN on the first message when it receives a first message transmitted across network domains (such as entering or leaving the first network).
- a first message transmitted across network domains such as entering or leaving the first network.
- the forwarding of messages carrying the ARN identifier can be achieved between network domains with different levels of trust by setting whether the interface related to the forwarding of the first message in the first node can use the ARN.
- FIG 1 is a schematic diagram of the structure of an Application-Aware Internet Protocol version 6 (APN6) packet header for a sensing application.
- API6 Application-Aware Internet Protocol version 6
- Figure 2 is a schematic diagram of a network architecture using APN6 technology
- FIG. 3 is a schematic diagram of another network architecture using APN6 technology
- Figure 4 is a schematic diagram of the structure of a message header configured with ARN ID
- Figure 5 is a flowchart illustrating a message processing method according to an embodiment of this disclosure
- Figure 6 is a schematic diagram of a network architecture using ARN technology as an application example of this disclosure.
- Figure 7 is a flowchart illustrating an access control method for ARN ID, an application example of this disclosure.
- Figure 8 is a schematic diagram of a message processing device according to an embodiment of the present disclosure.
- Figure 9 is a schematic diagram of the first node structure in an embodiment of this disclosure.
- networks typically employ a best-effort forwarding model to forward packets (which can also be understood as providing forwarding services).
- a best-effort forwarding model can no longer meet the diverse forwarding service needs of different applications (apps), becoming a major pain point in network development.
- SRv6 Segment Routing SRv6
- G-SRv6 Generalized SRv6
- network slicing SRv6 Segment Routing
- SLA Service Level Agreement
- a network path can include network tunnels and/or network slices.
- MPLS Multi-Protocol Label Switching
- QoS Quality of Service
- MPLS technology can only be applied to a limited trusted domain (also known as an MPLS domain).
- nodes located at the MPLS domain boundary such as routers
- the network within the MPLS domain is not visible to the outside world (also known as a black box).
- MPLS technology can only enable the network to be aware of packets from different applications (also known as the network being aware of applications), but it cannot enable applications to invoke network capabilities (also known as applications being aware of network capabilities or applications being aware of capabilities).
- the network needs to expose its capabilities. Typically, this is achieved through the northbound interface of a controller (which can also be understood as a network controller or control device).
- the application needs to call the controller to access the network capabilities.
- direct application calls to the controller may impact network security. Due to the security mechanisms required by carrier networks, this approach is generally difficult to widely implement.
- APN6 can be used for collaborative applications and network capabilities.
- APN6 defines how application information is carried in IPv6 packets; specifically, an APN6 header can be added to the IPv6 packet, carrying application information.
- the added APN6 header can include APN identifiers (such as APN ID, which may include application-class ID (APP-Group-ID), user-group ID (USER-Group-ID), reserved fields, etc.), intent, APN parameters (APN-Para), and other information.
- the APN6 header can be used to indicate information such as the application (or application group, which can also be understood as the class to which the application belongs) corresponding to the packet, the user (or user group) using the application (or application group), the critical flow in the application (such as action commands in cloud gaming), and relevant parameters of SLA requirements or network performance requirements (such as bandwidth, latency, jitter, packet loss rate, etc.).
- This information can be collectively referred to as APN6 application information or APN6 information.
- multiple applications can be grouped based on grouping rules to obtain multiple application groups. Specifically, the grouping rules for application groups can be set based on the five-tuple information contained in the IPv6 packet, the QinQ information corresponding to the IPv6 packet, etc.
- end-side devices such as terminals
- cloud-side devices such as servers
- end-side devices and cloud-side devices can also be collectively referred to as user equipment
- the end-side or cloud-side devices can set the APN6 application information corresponding to the application in the APN6 header of the IPv6 packet (this can also be understood as filling in APN6 application information or encapsulating application feature information).
- the network can identify the APN6 application information contained in the IPv6 packet, thereby perceiving the application corresponding to the APN6 application information.
- the network can then map the IPv6 packet to the network path corresponding to the perceived application for forwarding (this can also be understood as forwarding the IPv6 packet according to the network path corresponding to the perceived application).
- applications can call the network capabilities corresponding to the APN6 application information by filling the packet with APN6 application information, and the network can also identify the corresponding application based on the APN6 application information carried in the packet.
- applications can access network capabilities without directly calling the controller, which meets the network security requirements of operators.
- the network architecture using APN6 technology can specifically include:
- End-side devices and cloud-side devices such as terminals and servers. End-side devices or cloud-side devices can sense the characteristic information of applications through application sensing programs; then use the sensed characteristic information as APN6 application information to generate IPv6 packets containing APN6 headers, and send the generated IPv6 packets to the APN6 network domain (such as the SRv6 network domain that uses APN6 technology).
- Network edge devices such as nodes at the APN6 network domain boundary (also understood as the edge).
- end-side devices and cloud-side devices lack application awareness (i.e., they cannot perceive the APN6 application information of applications), they cannot generate IPv6 packets containing APN6 headers.
- end-side devices and cloud-side devices can send IPv6 packets without APN6 headers to network edge devices.
- the network edge devices can parse application feature information from the five-tuple information and service information contained in the IPv6 packets (such as the mapping relationship of dual Virtual Local Area Network (VLAN) tags (i.e., the mapping relationship between customer VLAN (C-VLAN) and service provider VLAN (S-VLAN))). They then use the parsed application feature information as APN6 application information to generate IPv6 packets containing APN6 headers and forward the generated IPv6 packets to the network policy enforcement device.
- VLAN Virtual Local Area Network
- Network policy enforcement devices such as nodes in the network path (also called network service path) that provides packet forwarding services in an SRv6 network, specifically including:
- Header node (also understood as the head node for sensing applications): The starting node of the network path.
- the head node is used to maintain the matching relationship between inbound packet traffic (i.e., traffic entering the APN6 network domain) and the network path.
- the head node After receiving an IPv6 packet from the network edge device, the head node can determine the network policy corresponding to the IPv6 packet based on the APN6 application information carried in the IPv6 packet and the correspondence between the APN ID and the network policy (i.e., the routing policy for network forwarding services, also known as the network service policy or routing policy).
- the head node selects a network path for the IPv6 packet according to the network policy (which can also be understood as matching the network path corresponding to the APN6 application information (i.e., the network path that meets the network performance requirements corresponding to the APN6 application information)) and forwards the IPv6 packet to the intermediate node corresponding to the matched network path (which can also be understood as introducing it to the path that meets the requirements).
- the network policy which can also be understood as matching the network path corresponding to the APN6 application information (i.e., the network path that meets the network performance requirements corresponding to the APN6 application information)
- the intermediate node which can also be understood as introducing it to the path that meets the requirements
- the head node can also encapsulate the APN6 application information into the outer (also understood as the outer layer) IPv6 extension header (which can also be understood as path tunnel encapsulation), so that intermediate nodes can obtain the APN6 application information from the outer IPv6 extension header, thereby enabling the further provision of application-aware services in the SRv6 network (which can also be understood as enabling other nodes in the network to be aware of the application information).
- the outer also understood as the outer layer IPv6 extension header
- path tunnel encapsulation which can also be understood as path tunnel encapsulation
- Intermediate nodes also understood as intermediate nodes in the perception application: One or more (or at least one) nodes located between the head node and the tail node in the network path can be called intermediate nodes. Intermediate nodes can obtain the network path matching the IPv6 packet from the head node, and thus, upon receiving the IPv6 packet from the head node, can provide network forwarding services for the application's IPv6 packet according to the matched network path. Simultaneously, intermediate nodes can also provide other value-added network services based on the APN6 application information carried in the IPv6 packet, such as Service Function Chaining (SFC) and In-situ Flow Information Telemetry (IFIT) for the perception application.
- SFC Service Function Chaining
- IFIT In-situ Flow Information Telemetry
- Tail node (also understood as the tail node of application awareness): The terminal node of the network path.
- the tail node can delete (or remove) the APN6 application information and path tunnel encapsulation information contained in the IPv6 packet; at the same time, the tail node can also retain (i.e., not delete) the APN6 application information that already exists in the IPv6 packet before the IPv6 packet enters the path, and continue to transmit the retained APN6 application information with the IPv6 packet;
- the controller can be used to uniformly plan and maintain the mapping relationship between APN IDs, APN IDs and applications (or application groups), and network policies.
- the controller can distribute APN IDs and mapping relationships to network edge devices and network policy enforcement devices. Specifically, the controller can distribute the mapping relationship between applications (or application groups) and APN IDs to network edge devices; simultaneously, the controller can distribute the mapping relationship between APN IDs and network policies to network policy enforcement devices.
- the controller can coordinate the APN IDs corresponding to applications (or application groups) through collaboration with over-the-top (OTT) application management servers and distribute them to end-side devices or cloud-side devices.
- OTT over-the-top
- APN6 APN6 technology enables both application access to network capabilities and network identification of applications, it also suffers from a series of issues related to privacy, security, management, and capacity. Specifically, these include:
- IPv6 header of IPv6 packets carries user information in plaintext, which can easily lead to the leakage of user privacy.
- APN6 application information is only associated with the application, which may lead to problems such as forging or impersonating APN6 application information in IPv6 packets.
- the controller assigns an APN ID corresponding to the application the user has subscribed to.
- the APN ID is fixed and cannot be changed. If the APN ID is leaked (e.g., intercepted by an unauthorized third party), in order to ensure network security, it is necessary to completely update the APN IDs stored in all routers, which is a heavy maintenance burden.
- the extended header of IPv6 packets carries APN6 application information.
- the APN6 application information contained in the extended header (which may include extended headers other than the Hop-By-Hop (HBH) header) cannot be changed during forwarding (e.g., it cannot be inserted, modified, or deleted).
- the APN6 application information may be different in different network domains, which may cause nodes located at the network domain boundary to drop IPv6 packets, violating the best-effort forwarding principle of the Internet.
- APN IDs are uniformly assigned across the entire network
- the encoding methods for application and user information contained in APN6 application information may differ across different network domains. Therefore, when a packet using APN6 technology is transmitted from one network domain to another (i.e., cross-network domain transmission), if the encoding methods for application and user information are the same in both network domains, the boundary node of the receiving network domain can accurately identify the APN6 application information contained in the packet. The boundary node can then receive the packet and forward it within that network domain based on the APN6 application information. However, if the encoding methods for application and user information are different in the two network domains, the boundary node of the receiving network domain cannot accurately identify the APN6 application information contained in the packet. The boundary node can only choose to discard the packet and cannot ignore the APN6 application information contained in the packet and allow the packet to be forwarded within that network domain.
- the boundary node of the metropolitan area network connected to the user network of a home user is a Broadband Remote Access Server (BRAS).
- the BRAS can use the user information stored (or configured) on the BRAS to check the APN6 application information contained in the received user-sent packets. If the APN6 application information in the user-sent packet does not match the user information stored on the BRAS (or the verification fails), the BRAS will discard the packet and will not forward it.
- the APN6 application information contained in the text is consistent with the user information stored on the BRAS (which can also be understood as successful verification).
- the BRAS can forward the packet in the metropolitan area network (MAN) based on the APN6 application information and then pass the packet to the backbone network.
- MAN metropolitan area network
- the boundary nodes of the backbone network usually do not store any user service information, and therefore cannot effectively control and verify the APN6 application information contained in the packet. This may lead to the packet being dropped by the boundary nodes of the backbone network or making it difficult to select a suitable network path for the packet in the backbone network.
- related technologies can achieve cross-domain transmission by building end-to-end network tunnels.
- end-to-end network tunnels With nearly 300 million users in the current fixed network and the diverse destinations of Internet access, hundreds of millions of end-to-end network tunnels need to be built in the network to meet the cross-domain transmission needs of a large number of users. Building end-to-end network tunnels for cross-domain transmission is difficult to achieve.
- ARN technology In related technologies, to avoid the privacy, security, management, capacity, and access control issues inherent in APN6 technology, ARN technology was proposed. ARN technology generates ARN information (which can also be understood as application call interface information, such as ARN ID) applied to the forwarding plane based on control plane routing parameters (such as service type parameters). This enables network capability exposure, allowing applications to access network capabilities. Specifically, when an application generates a packet, it can include an ARN ID in the packet header, allowing the application to call the network capabilities corresponding to that ARN ID. This can also be understood as enabling the application's packet to be forwarded in the network according to the routing policy corresponding to the ARN ID.
- ARN information which can also be understood as application call interface information, such as ARN ID
- control plane routing parameters such as service type parameters
- the network when it receives a packet, it can identify the corresponding application based on the ARN ID in the packet header and forward the packet according to the routing policy matching the ARN ID. For example, when there are multiple network paths and/or multiple slices between the source and destination addresses of a packet, the network can select (or determine) one of the paths and/or slices for forwarding based on the ARN ID contained in the packet.
- ARN ID can be understood as an intermediary layer between applications and the network.
- ARN ID By introducing ARN ID, a bridge is built between the network requirements of applications and the network capabilities of the network. ARN ID simultaneously represents network capability information exposed to the outside world, as well as application information and user information.
- Each ARN ID can be represented by a single number, which can include randomly generated values or values assigned according to a preset order.
- the structure of the ARN ID can be set according to actual needs; that is, there are no restrictions on the structure of the ARN ID. Therefore, it can also be understood as an unstructured number.
- the ARN ID can be set in the Flow Label field; alternatively, the ARN ID can be set in the extended header of the IPv6 packet.
- the ARN ID when the ARN ID is set in the Flow Label field of the IPv6 packet header, as shown in Figure 4, 20 bits of the Flow Label field can be reused to set the ARN ID, and the highest bit (specifically, the 7th bit) of the Traffic Class (TC) field indicates whether the Flow Label field of the packet is escaped to an ARN ID.
- the highest bit of the TC field when the highest bit of the TC field is set to 1, it indicates that the Flow Label field is escaped to an ARN ID; when the highest bit of the TC field is set to 0, it indicates that the Flow Label field is not escaped to an ARN ID.
- the highest bit of the TC field can also be set to 0 to indicate that the Flow Label field is escaped as an ARN ID; and the highest bit of the TC field can be set to 1 to indicate that the Flow Label field is not escaped as an ARN ID.
- the highest bit of the TC field can be set to represent Explicit Congestion Notification (ECN).
- Network service providers can use different ARN IDs to represent different network capabilities exposed to the outside world, so as to provide users with differentiated network services (such as providing low latency, high bandwidth tunnels and/or slicing according to application needs), without having to directly expose segment identifiers (SIDs) and/or binding SIDs (BSIDs), thereby effectively ensuring network security;
- SIDs segment identifiers
- BSIDs binding SIDs
- ARN ID does not explicitly carry application information and user information
- the network when the network receives a message containing ARN ID, the network cannot directly know the application information and user information based on the ARN ID contained in the message. Therefore, ARN technology can avoid the leakage of user privacy.
- the controller can configure ARN IDs individually for each network domain. When a packet enters a network domain, it can carry the corresponding ARN ID for that network domain within the packet. This allows nodes within that network domain to forward packets based on the ARN ID carried in the packet. In other words, the ARN ID for each network domain can be flexibly configured and managed according to actual needs; furthermore, the ARN ID contained in the packet can be changed according to the network domain to invoke the network capabilities of the corresponding network domain.
- the boundary node in network domain A connecting to network domain B can replace the ARN ID corresponding to network domain A in the packet with the ARN ID corresponding to network domain B, and then send (or transmit) the packet to network domain B.
- This allows nodes in network domain B to receive the packet and perform forwarding processing within network domain B based on the ARN ID corresponding to network domain B.
- network domain A can directly send the packet to network domain B.
- the boundary node in network domain B connecting to network domain A upon receiving the packet, can replace the ARN ID corresponding to network domain A in the packet with the ARN ID corresponding to network domain B, and then perform subsequent forwarding processing within network domain B according to the replaced ARN ID.
- This forwarding processing can also be called ARN-associated forwarding processing.
- first information in the first node (which can also be understood as a boundary node) at the first network boundary
- the first node when the first node receives the first message, it can determine whether to perform forwarding-related processing associated with ARN on the first message according to the first information.
- the first node when the first node receives the first message from a network domain with a different level of trust than the first network, or when the first node forwards the first message to a network domain with a different level of trust than the first network, it can realize the forwarding of messages carrying ARN identifiers between network domains with different levels of trust by setting whether the interface related to the forwarding of the first message in the first node can use ARN.
- This disclosure provides a message processing method applied to a first node, the first node including a boundary node of a first network, as shown in Figure 5.
- the method includes:
- Step 501 Receive a first message, the first message containing a first ARN identifier
- Step 502 If the first information indicates that the first interface of the first node can use ARN, perform forwarding-related processing associated with ARN on the first interface for the first packet; or, if the first information indicates that the first interface of the first node disables ARN, perform forwarding-related processing associated with ARN on the first interface for the first packet.
- the first network may specifically include one of a user network, a metropolitan area network, or a backbone network.
- the user network can also be understood as a network used to connect user gateway devices (such as Customer Premise Equipment, CPE) and terminals.
- the terminal can be referred to as User Equipment (UE), terminal device, device, or user, etc., and this disclosure does not limit this terminology.
- the first node includes the boundary node of the first network, specifically including one of the following: CPE, Provider Edge (PE) device (such as Virtual Private Network (VPN) edge router), BRAS, Broadband Network Gateway (BNG), etc.
- the first node can be connected to the second network, that is, the first network and the second network can be connected through the first node.
- the second network can specifically include one of the following: user network, metropolitan area network, backbone network, etc. This disclosure embodiment does not limit the specific implementation of the second network.
- the trust levels of the first network and the second network can be different; specifically, the trust level of the first network can be higher than, equal to, or lower than the trust level of the second network.
- the first message may specifically include an IPv6 message, and the first ARN identifier contained in the first message may specifically include an ARN ID.
- the first ARN identifier may be set in the first field of the first message; that is, the first field of the first message carries the first ARN identifier.
- the first field may include the Flow Label field in the header of the first message.
- the first interface includes the interface connecting the first node to the second network, specifically including an Internet Protocol (IP) interface.
- IP Internet Protocol
- the first interface can also be understood as an outgoing interface or an egress interface.
- the first node can receive the first message from the second network through the first interface.
- the first interface can also be understood as an incoming interface or an ingress interface.
- the first node in step 501, can receive the first message from other nodes in the first network and needs to forward the first message to the second network through the first interface; or, the first node can receive the first message from the second network through the first interface and needs to forward the first message within the first network.
- the first node Upon receiving the first message, the first node needs to determine how to forward the first message, which can also be understood as determining the service type of the forwarding service for the first message.
- the service type of the forwarding service can be determined by one or more of the following: network path, routing policy (which can also be understood as routing policy, specifically including segment routing policy (SR Policy), network tunnel, and/or network slice (one or more can also be understood as at least one).
- the first node can determine how to forward the first packet based on the first information associated with the first interface.
- the first information can be named ⁇ trust_arn ⁇ , or other names as needed. Since the first information is associated with the first interface, it can also be understood as interface-level attribute information.
- the first information characterizes whether the first interface can use an ARN, and whether the first interface can use an ARN is related to the feasibility of the second network associated with the first interface.
- the second network is a trusted domain (which can also be understood as the trustworthiness of the second network being greater than or equal to a trustworthiness threshold)
- the first interface can use an ARN, and in this case, the first node can forward the first packet in a manner associated with the ARN.
- the first interface is prohibited from using an ARN, and in this case, the first node can forward the first packet in a manner not associated with the ARN.
- the value of the first information can be determined by whether the second network is a trusted domain. For example, assuming the value of the first information is true or false, when the second network is a trusted domain, the value of the first information is true, indicating that the first interface can use ARN; when the second network is a non-trusted domain, the value of the first information is false, indicating that the first interface of the first node has ARN disabled. Alternatively, when the second network is a trusted domain, the value of the first information can be false, indicating that the first interface of the first node can use ARN; when the second network is a non-trusted domain, the value of the first information can be true, indicating that the first interface of the first node has ARN disabled.
- the value of the first information can be configured (or set) in the first node.
- the specific implementation method for configuring the value of the first information in the first node can be selected according to actual needs.
- the value of the first information can be configured manually (e.g., manually entering command lines), or configured via a control device.
- the control device can also be called a controller or network controller, and is at least used to generate ARN identifiers and to configure ARN identifiers for nodes in the network.
- the first node can determine how to forward the message based on the configured value of the first information.
- the first node when the first information indicates that the first interface of the first node has disabled ARN, the first node performs forwarding-related processing on the packet that is not associated with ARN, which may include the following two methods:
- the first node directly discards the first packet; based on this, in one embodiment, the forwarding-related processing of the first packet, which is not associated with the ARN, includes:
- the first node discards the first message.
- the first node treats the first packet as (or can be understood as) a packet that does not contain an ARN identifier, and performs forwarding-related processing on the first packet according to the forwarding method for packets that do not contain an ARN identifier (or can be understood as the default forwarding method).
- the forwarding-related processing of the first message that is not associated with the ARN includes:
- the first field carrying the first ARN identifier in the first message is set as the fifth information to obtain the processed first message, and the processed first message is forwarded in the first network in the fourth method.
- the fourth method is not associated with ARN, and the fifth information indicates that the first message disables ARN.
- the value of the fifth information may specifically include 0 or an invalid value.
- the specific value of the fifth information can be set according to actual needs, and this embodiment does not limit it.
- the first node forwards the first packet in the first network according to the default forwarding method (i.e. the fourth method), which can also be understood as providing the first packet with default network services;
- the first field carrying the first ARN identifier in the first message is set as the fifth information to obtain the processed first message, and the processed first message is forwarded to the second network.
- the fifth information indicates that the first message disables ARN.
- the first node does not perform any processing and directly forwards the first message to the second network.
- the first node when the first information indicates that the first interface of the first node has disabled ARN, that is, when the first network is an untrusted domain, the first node can discard the first packet or modify the first ARN identifier contained in the first packet to an invalid value when the second network associated with the first interface is an untrusted domain, thereby preventing the first ARN identifier from being leaked to the untrusted domain and ensuring network security.
- the first node performs forwarding-related processing associated with the ARN on the packet.
- the first node may also verify the ARN identifier contained in the first packet and the source of the first packet, and determine whether to perform forwarding-related processing associated with the ARN based on the verification result.
- the first message further includes second information, the second information representing the source of the first message; if the first information represents that the first interface of the first node can use ARN, the second information and the first ARN identifier are verified; if the verification is successful, the first message is subjected to forwarding-related processing associated with ARN on the first interface; correspondingly, if the verification fails, the first message is subjected to forwarding-related processing not associated with ARN on the first interface.
- the second information may include one or more of the following (one or more may also be understood as at least one):
- the source address information of the first message
- the port information of the first message is the port information of the first message.
- the second information may include the user information of the first packet; that is, the second information can indicate which user the first packet originated from.
- the user information may include a user identifier, access link information of the first packet, etc.
- the first node can determine which access link the first packet was sent to it via, and then determine which user the first packet originated from based on the correspondence between that access link and the user.
- the first node can know the correspondence between the access link and the user in advance.
- the second information may include the source address information (e.g., source IP address information) and/or the port information (e.g., source port information) of the first packet.
- the first node can obtain the correspondence between the source information of one or more messages and the ARN identifier, and match the second information contained in the first message and the first ARN identifier in the obtained correspondence. If a match exists, the verification is determined to be successful; if no match exists, the verification is determined to be unsuccessful.
- verifying the second information and the first ARN identifier includes:
- the second information and the first ARN identifier are verified using the third information, which represents the correspondence between the source information of one or more messages and the ARN identifier.
- the third information can be presented in the form of a mapping table, which can also be called a verification table.
- the third information is associated with the first interface; that is, when the first node connects to multiple networks through multiple interfaces, each interface corresponds to a set of third information, which is used to verify the second information and ARN identifier contained in the message associated with that interface.
- the method by which the first node obtains the third information may include: the first node receiving the third information sent by the control device; manually configuring the third information on the first node; the first node performing route learning using the routing protocols corresponding to all received messages containing ARN identifiers to determine the third information (i.e., determining the third information through route learning); and using the Access Control List (ACL) corresponding to the first node as one of the third information.
- the routing protocol may include Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP), etc. IGP may further include Open Shortest Path First (OSPF) protocol or Intermediate System to Intermediate System (ISIS) protocol, etc.; the routing protocol may be configured by any node that transmits the first message before the first node.
- Border Gateway Protocol BGP
- IGP Interior Gateway Protocol
- IGP may further include Open Shortest Path First (OSPF) protocol or Intermediate System to Intermediate System (ISIS) protocol, etc.
- OSPF Open Shortest Path First
- ISIS Intermediate System to Intermediate System
- step 502 the first node can perform forwarding-related processing on the first packet that is not associated with the ARN.
- the specific implementation of forwarding-related processing that is not associated with the ARN has been detailed above and will not be repeated here.
- step 502 the first node can perform forwarding-related processing on the first packet that is associated with the ARN.
- the forwarding-related processing associated with the ARN can be discussed in the following four cases, depending on whether the first interface is an inbound interface or an outbound interface, and whether the first node needs to reset the ARN identifier contained in the first packet (which can also be understood as performing ARN ID mapping):
- the first node when the first interface is an outgoing interface and the first node needs to reset the ARN identifier contained in the first message, after receiving the first message, the first node can map (or reset or replace) the first ARN identifier associated with the first network contained in the first message to the ARN identifier associated with the second network, and forward the mapped first message to the second network, so that the second network can forward the first message in the second network according to the mapped ARN identifier (or provide the network service corresponding to the mapped ARN identifier for the first message in the second network).
- the forwarding-related processing of the first message associated with the ARN includes:
- the first field carrying the first ARN identifier in the first message is set as the second ARN identifier to obtain the processed first message.
- the second ARN identifier is associated with the second network, and the processed first message is forwarded to the second network.
- the first node can obtain one or more correspondences between first ARN identifiers and second ARN identifiers, so that the first node can use the correspondences and the first ARN identifiers contained in the first message to determine the second ARN identifier corresponding to the first message, and then set the determined second ARN identifier in the first field.
- the fourth information is used to set the first field carrying the first ARN identifier in the first message as the second ARN identifier, or to set the first field carrying the first ARN identifier in the first message as the third ARN identifier.
- the fourth information represents the correspondence between one or more ARN identifiers associated with the first network and ARN identifiers associated with the second network.
- the method by which the first node obtains the fourth information may include: the first node receiving the fourth information sent by the control device, configuring the fourth information on the first node manually, or the first node performing route learning using the routing protocols corresponding to all received messages containing ARN identifiers to determine the fourth information (i.e., determining the fourth information through route learning).
- the first node when the first interface is an outgoing interface and the first node does not need to reset the ARN identifier contained in the first message, the first node can directly forward the received first message to the second network.
- the boundary node of the second network After receiving the first message, the boundary node of the second network can map the first ARN identifier associated with the first network contained in the first message to the ARN identifier associated with the second network, so that the boundary node of the second network can forward the first message in the second network according to the mapped ARN identifier.
- the forwarding-related processing of the first message associated with the ARN includes:
- the first message is forwarded to the second network, where the message can be forwarded in a second manner, the second manner being associated with the second ARN identifier corresponding to the first message;
- the first node when the first interface is an inbound interface and the first node needs to reset the ARN identifier contained in the first message, after receiving the first message from the second network, the first node can map the first ARN identifier associated with the second network contained in the first message to the ARN identifier associated with the first network, and forward the first message within the first network according to the mapped ARN identifier.
- the forwarding-related processing of the first message associated with the ARN includes:
- the first field carrying the first ARN identifier in the first message is set as the third ARN identifier to obtain the processed first message.
- the third ARN identifier is associated with the first network.
- the processed first message is forwarded in the first network according to the first method.
- the first method is associated with the third ARN identifier.
- the first node when the first interface is an inbound interface and the first node does not need to reset the ARN identifier contained in the first packet, after receiving the first packet from the second network, the first node can directly forward the first packet within the first network based on the first ARN identifier associated with the first network contained in the first packet. Specifically, before the boundary node of the second network sends the first packet to the first node, it has already mapped the ARN identifier associated with the second network contained in the first packet to the first ARN identifier associated with the first network.
- the forwarding-related processing of the first message associated with the ARN includes:
- the first message is forwarded within the first network using a third method, wherein the third method is associated with the first ARN identifier.
- the first node can use the third information to verify the source of the first message and the first ARN identifier, and perform forwarding related processing on the first message based on the verification result.
- the third and fourth information can be merged, and the merged information can achieve the functions of the third and fourth information. Therefore, when both the third and fourth information are configured for the first node, the first node can store only the merged information and use it to achieve the functions of the third and fourth information. Since the merged information occupies less storage space, storage resources can be saved. Furthermore, if the first node is configured with both ACL and third information, when performing verification, the first node can prioritize using the ACL to verify the source of the first packet and the first ARN identifier; that is, the ACL has the highest verification priority. For example, when the verification result obtained using the ACL is inconsistent with the verification result obtained using the third information, the verification result corresponding to the ACL can be taken as the standard.
- the message processing method provided in this disclosure includes a first node receiving a first message containing a first ARN identifier, and the first node including a boundary node of a first network. If first information indicates that the first interface of the first node can use ARN, the first message is processed with ARN-related forwarding at the first interface; or, if the first information indicates that the first interface of the first node disables ARN, the first message is processed with non-ARN-related forwarding at the first interface.
- the solution provided in this disclosure sets first information in the first node at the boundary of the first network (which can also be understood as the network domain boundary of the first network), enabling the first node to determine whether to perform ARN-related forwarding processing on the first message when receiving a first message transmitted across network domains (e.g., entering or leaving the first network) based on the first information.
- the forwarding of messages carrying ARN identifiers between network domains with different levels of trust can be achieved by checking whether the interface related to the forwarding of the first message in the first node can use ARN.
- the network architecture includes a controller (i.e., the aforementioned control device), a user network, a metropolitan area network (MAN), and a backbone network.
- the user network is connected to the MAN, and the MAN is connected to the backbone network.
- the CPE of the user network is connected to the BRAS of the MAN, and the MAN boundary node (also understood as a MAN boundary device) of the MAN is connected to the PE of the backbone network.
- the user network, MAN, and backbone network can also be understood as different network domains, and the trust levels between different network domains may differ.
- the ARN ID (i.e., the ARN identifier mentioned above) is mainly used at network boundary nodes (which can also be understood as network boundary service access points, such as PE, BRAS, or BNG).
- network boundary nodes which can also be understood as network boundary service access points, such as PE, BRAS, or BNG.
- the controller receives the order information for a user's subscription to the ARN service (which can also be understood as a subscription request for network services), it can set one or more service types corresponding to the received order information.
- the controller can select a route for that service type in the metropolitan area network connected to the user's network according to the SR Policy, that is, determine the routing strategy for forwarding the packets corresponding to that service type in the metropolitan area network (the routing strategy is associated with the network path of the forwarded packets, and the network path may specifically include network slices and/or network tunnels, etc.).
- the controller can directly determine the correspondence between the service type and the ARN ID (which can also be expressed as a tuple, such as ⁇ service type, ARN ID>) and the correspondence between the ARN ID and the routing strategy (which can also be expressed as a tuple, such as ⁇ ARN ID, routing strategy>). If the routing strategy does not yet have a corresponding ARN ID, the controller can generate an ARN ID corresponding to the routing strategy according to a preset strategy (such as negotiating with the application management server), thereby determining the correspondence between the service type and the ARN ID and the correspondence between the ARN ID and the routing strategy.
- a preset strategy such as negotiating with the application management server
- the controller can...
- the mapping between service types and ARN IDs is distributed to user equipment (such as terminals, servers, CPEs, etc.) so that when user equipment generates a packet, it can determine the corresponding ARN ID based on the service type and mapping, and carry the determined ARN ID in the packet.
- the controller can distribute the mapping between ARN IDs and routing policies to the boundary nodes (such as BRAS) in the metropolitan area network that are connected to the user's network. This allows the BRAS to determine the routing policy (or network forwarding service) for the packet when the user's packet enters the metropolitan area network, based on the ARN ID and mapping contained in the packet.
- the process of the controller distributing the mapping to the boundary nodes can also be understood as performing network-side configuration.
- the controller distributes the mapping between service types and ARN IDs to the terminal and/or server.
- the application on the terminal and/or server can, based on the service type required by the application and the mapping, include the ARN ID corresponding to the service type in the message generated during the application's message generation process.
- the CPE of the user network receives the message sent by the terminal and/or server, the message already carries the ARN ID and can be directly forwarded to the metropolitan area network.
- the controller distributes the mapping between service types and ARN IDs to the CPE.
- the message generated by the terminal and/or server may not carry the ARN ID.
- the CPE After receiving the message from the terminal and/or server, the CPE can classify the message using methods such as ACLs (which can also be understood as flow allocation), thereby determining the required service type of the message. Based on the required service type and the mapping, the CPE includes the ARN ID corresponding to the service type in the message, and can then forward the message to the metropolitan area network.
- ACLs which can also be understood as flow allocation
- this application example provides an access control method for ARN IDs, as shown in Figure 7, which includes the following steps:
- Step 701 The network boundary device (i.e., the first node mentioned above) receives a message containing the ARN ID (i.e., the first ARN identifier mentioned above) (i.e., the first message mentioned above);
- the network boundary device may specifically include one of the following: CPE of the user network, metropolitan area boundary device of the metropolitan area network, BRAS of the metropolitan area network, PE of the backbone network, etc.
- Step 702 The network boundary device forwards packets based on the ARN trust attribute (trust_arn) corresponding to the interface (i.e., the first interface, which may specifically include an IP interface) connected to the neighboring network (i.e., the second network mentioned above); wherein, the forwarding process includes:
- the neighboring network refers to the network adjacent to the network to which the network boundary device belongs.
- the neighboring network of a metropolitan area network includes the user network and the backbone network.
- the interface can also be called an outgoing interface; when the network boundary device receives the packets from the neighboring network and needs to forward them within the network to which the network boundary device belongs, the interface can also be called an incoming interface.
- ⁇ trust_arn ⁇ is an interface-level attribute. It can be configured in advance on the network boundary device based on the trust relationship between the network to which the network boundary device belongs and neighboring networks (which can also be understood as whether the neighboring networks are trusted domains relative to the network to which the network boundary device belongs). The value of ⁇ trust_arn ⁇ can be set to true or false.
- disabling the ARN service means that network boundary devices treat packets as if they did not carry an ARN ID, such as discarding the packet or forwarding it according to the default routing policy.
- the network boundary device can set the value of the field carrying the ARN ID (such as the Flow Label field) in the packet to 0 (which can also be understood as erasing it to 0) or set it to an invalid value (the specific choice can be made according to actual needs). In this way, the network boundary device can forward packets with an ARN ID of 0 or an invalid value as packets without an ARN ID.
- Step 703 The network boundary device verifies the validity of the user information and ARN ID contained in the packet;
- step 704 If the verification is successful, proceed to step 704;
- the validity check can also be called ARN outgoing check or outgoing check; when the interface is an incoming interface, the validity check can also be called ARN incoming check or incoming check.
- network boundary devices can obtain a verification table (i.e., the aforementioned third information) used to verify user identities.
- a verification table used to verify user identities.
- the verification table can be used for outbound verification and/or inbound verification; a verification table used for outbound verification can also be called an outbound verification table, and a verification table used for inbound verification can also be called an inbound verification table.
- the network boundary device can obtain the verification table through one of the following methods: manual configuration, controller distribution, or route learning.
- the specific implementation may include: the controller determines the user's source address information (e.g., source IP) and/or link information based on the user's subscription information, and uses the user's source address information and/or link information as user information (which can also be understood as the user's identification information, i.e., the aforementioned source information).
- the controller can determine the correspondence between the user's user information and the ARN ID corresponding to the service type subscribed to by the user for each user.
- ARN IDs can also be expressed in the form of a tuple, such as ⁇ user information, ARN ID>.
- the controller can then determine the verification table based on the correspondence between the user information and ARN IDs of all users, and distribute the verification table to the network boundary device.
- the network boundary device can determine user information based on the received packets, for example, based on the access link information corresponding to the packets. Simultaneously, the network boundary device can determine the ARN ID contained in the received packets.
- the network boundary device can also be referred to as a user gateway device.
- the network boundary device is a boundary device connecting a metropolitan area network and a backbone network (such as a metropolitan area boundary device or a PE)
- the network boundary device can determine user information and the ARN ID contained in the packets based on the source IP information or port information contained in the packets.
- the network boundary device can also be referred to as a network gateway device.
- the network boundary device can perform a validity check on the packets based on the determined user information, the ARN ID, and the verification table issued by the controller.
- the ARN ID contained in the packets received by the network boundary device may be associated with a neighboring network.
- the network boundary device needs to map (or replace, rewrite, update, etc.) the ARN ID contained in the packet, so that the mapped ARN ID is associated with the network to which the network boundary device belongs. In this way, the network boundary device can forward packets within its own network based on the ARN ID contained in the packet.
- the ARN ID contained in the packets received by the network boundary device is associated with the network to which the network boundary device belongs.
- the network boundary device can map the ARN ID contained in the packet, so that the mapped ARN ID is associated with a neighboring network. In this way, after the network boundary device forwards the packet to the neighboring network, the neighboring network can directly forward the packet within its own network based on the ARN ID contained in the packet.
- the network boundary device can obtain the correspondence between the ARN ID of the network to which it belongs and the ARN ID of the neighboring networks (which can also be understood as a mapping relationship, i.e., the fourth information mentioned above) to map the ARN IDs contained in the packets.
- this correspondence can be presented in the form of a mapping table.
- This mapping table can be used for outbound verification and/or inbound verification.
- the mapping table used for outbound verification can also be called the outbound mapping table; the mapping table used for inbound verification can also be called the inbound mapping table.
- the network boundary device can obtain the mapping table through one of the following methods: manual configuration, controller distribution, or route learning.
- the specific implementation may include: the controller determines the correspondence between the routing policies in the MAN and the backbone network based on the mapping relationship between routing policies in the MAN and the backbone network (which can also be understood as which routing policy should be used to provide network forwarding services for packets forwarded in the MAN using each routing policy).
- the controller determines the correspondence between the ARN IDs allocated to the MAN and the ARN IDs allocated to the backbone network based on the correspondence of all ARN IDs; the controller then determines the mapping table based on the correspondence of all ARN IDs and distributes the mapping table to the boundary device. In this way, flexible access control of the ARN IDs contained in the packets can be achieved during the forwarding of packets between different networks.
- the verification table and mapping table obtained by the network boundary device can be merged (here, when the verification table and mapping table are issued by the controller, the merging can be performed in the controller) to obtain a merged table.
- the network boundary device can perform legality verification on the packet based on the determined user information, ARN ID, and the merged table, and map the ARN ID contained in the packet to the ARN ID associated with the network to which the network boundary device belongs (i.e., the destination ARN ID).
- the merged table can be expressed in the form of triples, such as ⁇ user information, ARN ID, destination ARN ID>, where the ARN ID is associated with the network to which the network boundary device belongs, and the destination ARN ID is associated with the neighboring network.
- the inbound checksum table and inbound mapping table obtained by the network boundary device can be merged, and the outbound checksum table and outbound mapping table can also be merged.
- the inbound checksum table of the user-facing interface of the CPE (which can also be understood as the interface facing the terminal and/or server) can be expressed as ⁇ user information, ARN ID>, and the outbound checksum table can be expressed as ⁇ source IP, ARN ID>;
- the inbound checksum tables and outbound checksum tables of other interfaces of the CPE and other network boundary devices can all be expressed as ⁇ source IP, ARN ID>;
- the inbound mapping table of the user-facing interface of the CPE can be expressed as ⁇ user, ARN ID, destination ARN ID>, and the outbound mapping table can be expressed as ⁇ source IP, ARN ID, destination ARN ID>;
- the inbound mapping tables and outbound mapping tables of other interfaces of the CPE and other network boundary devices can be expressed as ⁇ user information, ARN ID>, and the out
- the network boundary device prioritizes using the ACL to verify the validity of that ARN ID.
- the network boundary device can use the checksum table to verify its validity.
- the network boundary device can use the mapping table to verify its validity. In other words, the network boundary device can verify the validity of the ARN ID according to the priority order: ACL > checksum table > mapping table.
- Step 704 The network boundary device performs forwarding processing associated with the ARN, the forwarding processing associated with the ARN including one of the following:
- the network boundary device determines the routing policy based on the ARN ID contained in the packet and the correspondence between the ARN ID and the routing policy issued by the controller, and forwards the packet according to the determined routing policy; or, the network boundary device maps the ARN ID contained in the packet to an ARN ID associated with the network to which the network boundary device belongs based on the ARN ID contained in the packet and the mapping table, and determines the routing policy based on the mapped ARN ID and the correspondence between the ARN ID and the routing policy issued by the controller, and forwards the packet according to the determined routing policy; wherein, forwarding the packet according to the determined routing policy includes: mapping the packet to the network tunnel and/or network slice corresponding to the routing policy;
- the network boundary device maps the ARN ID contained in the packet to an ARN ID associated with the neighboring network based on the ARN ID contained in the packet and the mapping table, and forwards the packet to the neighboring network; or, the network boundary device directly forwards the packet to the neighboring network.
- the boundary device of the neighboring network can map the ARN ID contained in the packet to an ARN ID associated with the neighboring network based on the ARN ID contained in the packet and the mapping table. This allows the boundary device of the neighboring network to forward packets within the neighboring network based on the ARN ID associated with the neighboring network.
- the solution provided in this application example identifies whether the neighboring network connected to the network boundary device is a trusted or untrusted domain by deploying an IP interface-level attribute ⁇ trust_arn ⁇ on the network boundary device. This enables the network boundary device to forward packets containing ARN IDs based on the value of ⁇ trust_arn ⁇ . In other words, even if the network boundary device is connected to an untrusted domain, it can still forward packets accordingly, thus realizing a basic security framework for building network capabilities that allow untrusted domains to access trusted domains.
- the network boundary device can disable the ARN service as a whole. At this time, if the packets entering or leaving the interface carry ARN information, the network boundary device can erase the ARN ID to 0 or set it to an invalid value, and treat the packet as a packet that does not carry ARN information.
- the network boundary device When the trust_arn value of the IP interface is true, if the ARN ID of the packet received by the network boundary device is invalid, such as the ARN ID being 0 or an invalid value, the network boundary device will treat the packet as a packet that does not carry ARN information (that is, disable the ARN service).
- the user gateway device can match (or query) the ⁇ user, ARN ID> tuple in the checksum table and/or mapping table based on the user information and ARN ID contained in the packet. If a match is found, the user gateway device can map the packet to a network tunnel and/or network slice and forward the packet. Alternatively, it can first map the ARN ID contained in the packet to the destination ARN ID, and then map the packet to a network tunnel and/or network slice and forward the packet. If no match is found, the user gateway device can erase or set the ARN ID contained in the packet to 0 or an invalid value, and treat the packet as a packet without ARN information.
- the network gateway device matches the tuple ⁇ user information (e.g., user or source IP), ARN ID> ⁇ in the checksum table and/or mapping table. If a match is found, the network gateway device can directly map the packet to a network tunnel and/or network slice and forward the packet. Alternatively, it can first map the ARN ID contained in the packet to the destination ARN ID, and then map the packet to a network tunnel and/or network slice and forward the packet.
- the network gateway device erases or resets the ARN ID contained in the packet to 0 or an invalid value, or retains the ARN ID (i.e., does not change the ARN ID contained in the packet), and then maps the packet to a network tunnel and/or network slice and forwards the packet.
- the network boundary device matches the ⁇ user information (such as user or source IP), ARN ID> tuple in the checksum table and/or mapping table. If a match is found, the network boundary device can directly forward the packet to the neighboring network, or first map the ARN ID contained in the packet to the destination ARN ID, and then forward the packet to the neighboring network. If no match is found, the network boundary device can erase or set the ARN ID contained in the packet to 0 or an invalid value, or retain the ARN ID (i.e., do not change the ARN ID contained in the packet), and then forward the packet to the neighboring network.
- the network boundary device can directly forward the packet to the neighboring network, or first map the ARN ID contained in the packet to the destination ARN ID, and then forward the packet to the neighboring network. If no match is found, the network boundary device can erase or set the ARN ID contained in the packet to 0 or an invalid value, or retain the ARN ID (i.e., do not change the ARN ID contained in the packet), and
- ARN ID is a random value and does not carry application privacy information, and can be mapped to network slices and/or tunnels, it can ensure application security. At the same time, ARN can encapsulate internal network privacy information, avoiding the problem of internal network information leakage caused by users directly using SRv6 Policy or BSID.
- the network boundary device when access control is performed on the ARN ID, if the network connected to the interface is in an untrusted domain, the network boundary device can completely ignore the ARN (i.e., disable the ARN service); if the network connected to the interface is in a trusted domain, the network boundary device can not discard the packet when there is no matching item for the ARN ID contained in the packet (which can also be understood as the network boundary device not recognizing the ARN ID contained in the packet), and will map the packet to the default tunnel and/or slice (i.e., provide the packet with the default network forwarding service).
- network boundary devices In terms of device capacity, since network boundary devices only need to store ARN-related information (such as ARN ID, checksum table, mapping table, etc.) of the network to which the network boundary device belongs and the neighboring networks, and do not need to store information of the global network, they occupy less storage space and have lower requirements for device capacity.
- ARN-related information such as ARN ID, checksum table, mapping table, etc.
- this disclosure embodiment also provides a message processing apparatus disposed on a first node, as shown in FIG8, the apparatus comprising:
- the receiving unit 801 is configured to receive a first message, wherein the first message contains a first ARN identifier
- the processing unit 802 is configured to perform forwarding-related processing associated with ARN on the first packet on the first interface when the first information indicates that the first interface of the first node can use ARN, or to perform forwarding-related processing not associated with ARN on the first interface when the first information indicates that the first interface of the first node disables ARN.
- the first message further includes second information, the second information representing the source of the first message; the processing unit 802 is specifically used for:
- the first information indicates that the first interface of the first node can use ARN
- the second information and the first ARN identifier are verified; if the verification is successful, the first message is processed for forwarding related to ARN on the first interface.
- the first message further includes second information, the second information representing the source of the first message; the processing unit 802 is specifically used for:
- the second information and the first ARN identifier are verified; if the verification fails, the first packet is processed on the first interface in a way that is not associated with ARN.
- processing unit 802 is specifically used for:
- the second information and the first ARN identifier are verified using the third information, which represents the correspondence between the source information of one or more messages and the ARN identifier.
- the receiving unit 801 is further configured to receive the third information sent by the control device;
- the processing unit 802 is further configured to determine the third information through route learning.
- processing unit 802 is specifically configured to perform one of the following:
- the first field carrying the first ARN identifier in the first message is set as the second ARN identifier to obtain the processed first message.
- the second ARN identifier is associated with the second network, and the processed first message is forwarded to the second network.
- the first field carrying the first ARN identifier in the first message is set as the third ARN identifier to obtain the processed first message.
- the third ARN identifier is associated with the first network.
- the processed first message is forwarded in the first network according to the first method.
- the first method is associated with the third ARN identifier.
- the first message is forwarded to the second network, where the message can be forwarded in a second manner, the second manner being associated with the second ARN identifier corresponding to the first message;
- the first message is forwarded within the first network using a third method, wherein the third method is associated with the first ARN identifier.
- the first field carrying the first ARN identifier in the first message is set as the second ARN identifier, or the first field carrying the first ARN identifier in the first message is set as the third ARN identifier.
- the fourth information represents the correspondence between one or more ARN identifiers associated with the first network and ARN identifiers associated with the second network.
- the receiving unit 801 is further configured to receive the fourth information sent by the control device;
- the processing unit 802 is further configured to determine the fourth information through route learning.
- processing unit 802 is specifically configured to perform one of the following:
- the first field carrying the first ARN identifier in the first message is set as the fifth information to obtain the processed first message, and the processed first message is forwarded in the first network in the fourth method, wherein the fourth method is not associated with ARN, and the fifth information indicates that the first message disables ARN.
- the processor 902 is used for:
- the first packet is processed with ARN-related forwarding on the first interface; or if the first information indicates that the first interface of the node disables ARN, the first packet is processed with ARN-unrelated forwarding on the first interface.
- the first message further includes second information, the second information representing the source of the first message; the processor 902 is specifically used for:
- the first information indicates that the first interface of the node can use ARN
- the second information and the first ARN identifier are verified; if the verification is successful, the first message is processed for forwarding related to ARN on the first interface.
- the first message further includes second information, the second information representing the source of the first message; the processor 902 is specifically used for:
- the second information and the first ARN identifier are verified; if the verification fails, the first packet is processed on the first interface in a way that is not associated with an ARN.
- the processor 902 is specifically used for:
- the second information and the first ARN identifier are verified using the third information, which represents the correspondence between the source information of one or more messages and the ARN identifier.
- the communication interface 901 is further configured to receive the third information sent by the control device;
- the processor 902 is further configured to determine the third information through routing learning.
- the processor 902 is specifically configured to perform one of the following:
- the first field carrying the first ARN identifier in the first message is set as the second ARN identifier to obtain the processed first message.
- the second ARN identifier is associated with the second network, and the processed first message is forwarded to the second network.
- the first field carrying the first ARN identifier in the first message is set as the third ARN identifier to obtain the processed first message.
- the third ARN identifier is associated with the first network.
- the processed first message is forwarded in the first network according to the first method.
- the first method is associated with the third ARN identifier.
- the first message is forwarded to the second network, where the message can be forwarded in a second manner, the second manner being associated with the second ARN identifier corresponding to the first message;
- the first message is forwarded within the first network using a third method, wherein the third method is associated with the first ARN identifier.
- the processor 902 is specifically used for:
- the first field carrying the first ARN identifier in the first message is set as the second ARN identifier, or the first field carrying the first ARN identifier in the first message is set as the third ARN identifier.
- the fourth information represents the correspondence between one or more ARN identifiers associated with the first network and ARN identifiers associated with the second network.
- the communication interface 901 is further configured to receive the fourth information sent by the control device;
- the processor 902 is further configured to determine the fourth information through routing learning.
- the processor 902 is specifically configured to perform one of the following:
- the first field carrying the first ARN identifier in the first message is set as the fifth information to obtain the processed first message, and the processed first message is forwarded in the first network in the fourth method, wherein the fourth method is not associated with ARN, and the fifth information indicates that the first message disables ARN.
- the first field carrying the first ARN identifier in the first message is set as the fifth information to obtain the processed first message, and the processed first message is forwarded to the second network.
- the fifth information indicates that the first message disables ARN.
- bus system 904. bus system 904 is used to implement communication between these components.
- bus system 904 also includes a power bus, a control bus, and a status signal bus.
- all buses are labeled as bus system 904 in Figure 9.
- the memory 903 in this embodiment is used to store various types of data to support the operation of node 900.
- Examples of such data include any computer program used to operate on node 900.
- the methods disclosed in the above embodiments of this disclosure can be applied to, or implemented by, the processor 902.
- the processor 902 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware in the processor 902 or by instructions in software form.
- the processor 902 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
- DSP digital signal processor
- the processor 902 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure.
- the general-purpose processor may be a microprocessor or any conventional processor, etc.
- the steps of the methods disclosed in the embodiments of this disclosure can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor.
- the software modules may be located in a storage medium, specifically a memory 903.
- the processor 902 reads information from the memory 903 and, in conjunction with its hardware, completes the steps of the aforementioned method.
- node 900 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontroller units (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
- ASICs application-specific integrated circuits
- DSPs digital signal processors
- PLDs programmable logic devices
- CPLDs complex programmable logic devices
- FPGAs field-programmable gate arrays
- general-purpose processors controllers, microcontroller units (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
- the memory (memory 903) in this embodiment of the present disclosure can be volatile memory or non-volatile memory, or both.
- the non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); the magnetic surface memory can be disk storage or magnetic tape storage.
- the volatile memory can be random access memory (RAM), which is used as an external cache.
- RAM Random Access Memory
- SRAM Static Random Access Memory
- SSRAM Synchronous Static Random Access Memory
- DRAM Dynamic Random Access Memory
- SDRAM Synchronous Dynamic Random Access Memory
- DDRSDRAM Double Data Rate Synchronous Dynamic Random Access Memory
- ESDRAM Enhanced Synchronous Dynamic Random Access Memory
- SLDRAM SyncLink Dynamic Random Access Memory
- DRRAM Direct Rambus Random Access Memory
- this disclosure also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a memory 903 storing a computer program, which can be executed by the processor 902 of node 900 to complete the steps described in the aforementioned method.
- the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.
- this disclosure also provides a computer program product, including a computer program that can be executed by a processor 902 of a node 900 to perform the steps described in the foregoing method.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本公开提供了一种报文处理方法、装置、节点、存储介质及计算机程序产品。其中,方法包括:第一节点接收第一报文,所述第一报文包含第一应用响应网络标识,所述第一节点包括第一网络的边界节点;在第一信息表征所述第一节点的第一接口可使用应用响应网络的情况下,在所述第一接口对所述第一报文进行与应用响应网络关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用应用响应网络的情况下,在所述第一接口对所述第一报文进行不与应用响应网络关联的转发相关处理。
Description
相关申请的交叉引用
本公开主张在2024年6月14日在中国提交的中国专利申请号No.202410773425.X的优先权,其全部内容通过引用包含于此。
本公开涉及网络传输领域,尤其涉及一种报文处理方法、装置、节点、存储介质及计算机程序产品。
应用响应网络(Application Responsive Networking,ARN)是一种新型应用和网络协同的技术,通过在应用的报文中携带ARN标识(也可以理解为ARN标签),使得应用能够调用ARN标识对应的网络路径;相应地,网络边界设备接收到报文后,可以识别报文中携带的ARN标识,将报文按照ARN标识对应的网络路径转发。
然而,如何在可信度不相同的网络域之间对携带ARN标识的报文进行转发,目前尚未有有效的解决方案。
为解决相关技术问题,本公开实施例提供一种报文处理方法、装置、节点、存储介质及计算机程序产品。
本公开实施例的技术方案是这样实现的:
本公开实施例提供一种报文处理方法,包括:
第一节点接收第一报文,所述第一报文包含第一ARN标识,所述第一节点包括第一网络的边界节点;
在第一信息表征所述第一节点的第一接口可使用ARN的情况下,所述第一节点在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,所述第一节点在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
上述方案中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;在第一信息表征所述第一节点的第一接口可使用ARN的情况下,所述第一节点校验所述第二信息和第一ARN标识;校验成功后,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理。
上述方案中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;在第一信息表征所述第一节点的第一接口可使用ARN的情况下,所述第一节点校验所述第二信息和第一ARN标识;校验失败后,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
上述方案中,所述校验所述第二信息和第一ARN标识,包括:
所述第一节点利用第三信息,对所述第二信息和第一ARN标识进行校验,所述第三信息表征一个或多个报文的源头信息与ARN标识的对应关系。
上述方案中,所述方法还包括:
所述第一节点接收控制设备发送的所述第三信息;
或者,
所述第一节点通过路由学习,确定所述第三信息。
上述方案中,所述第二信息包括以下一项或多项:
所述第一报文的用户信息;
所述第一报文的源地址信息;
所述第一报文的端口信息。
上述方案中,所述对所述第一报文进行与ARN关联的转发相关处理,包括以下之一:
所述第一节点将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,得到处理后的第一报文,所述第二ARN标识与第二网络关联,将所述处理后的第一报文转发至所述第二网络;
所述第一节点将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,得到处理后的第一报文,所述第三ARN标识与第一网络关联,在所述第一网络内按照第一方式转发所述处理后的第一报文,所述第一方式与所述第三ARN标识关联;
所述第一节点将所述第一报文转发至所述第二网络,在所述第二网络能够按照第二方式转发报文,所述第二方式与所述第一报文对应的第二ARN标识关联;
所述第一节点在所述第一网络内按照第三方式转发所述第一报文,所述第三方式与所述第一ARN标识关联。
上述方案中,所述第一节点利用第四信息,将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,或者,将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,所述第四信息表征一个或多个第一网络关联的ARN标识与第二网络关联的ARN标识的对应关系。
上述方案中,所述方法还包括:
所述第一节点接收控制设备发送的所述第四信息;
或者,
所述第一节点通过路由学习,确定所述第四信息。
上述方案中,所述对所述第一报文进行不与ARN关联的转发相关处理,包括以下之一:
所述第一节点将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并在所述第一网络内按第四方式转发所述处理后的第一报文,所述第四方式不与ARN关联,所述第五信息表征所述第一报文禁用ARN;
所述第一节点将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并将所述处理后的第一报文转发至第二网络,所述第五信息表征所述第一报文禁用ARN;
所述第一节点丢弃所述第一报文。
本公开实施例还提供一种报文处理装置,设置在第一节点,所述第一节点包括第一网络的边界节点,包括:
接收单元,用于接收第一报文,所述第一报文包含第一ARN标识;
处理单元,用于在第一信息表征所述第一节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
本公开实施例还提供一种节点,所述节点包括第一网络的边界节点,包括:
通信接口,用于接收第一报文,所述第一报文包含第一ARN标识;
处理器,用于在第一信息表征所述节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
本公开实施例还提供一种节点,包括:处理器和用于存储能够在处理器上运行的计算机程序的存储器,
其中,所述处理器用于运行所述计算机程序时,执行上述任一方法的步骤。
本公开实施例还提供一种存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现上述任一方法的步骤。
本公开实施例还提供一种计算机程序产品,包括计算机程序,所述计算机程序被处理器执行时实现上述任一方法的步骤。
本公开实施例提供的报文处理方法、装置、节点、存储介质及计算机程序产品,第一节点接收第一报文,所述第一报文包含第一ARN标识,所述第一节点包括第一网络的边界节点;在第一信息表征所述第一节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。本公开实施例提供的方案,通过在第一网络边界(也可以理解为第一网络的网络域边界)的第一节点中设置第一信息,使得第一节点接收到跨网络域传输(比如进入第一网络或者离开第一网络)的第一报文时,能够根据第一信息确定是否对第一报文进行与ARN关联的转发相关处理,如此,当第一节点从与第一网络的可信度不相同的网络接收到第一报文时,或者,当第一节点将第一报文转发至与第一网络的可信度不相同的网络时,可以通过设置第一节点中与第一报文转发相关的接口是否可以使用ARN,来实现在可信度不相同的网络域之间对携带ARN标识的报文进行转发。
图1为一种感知应用的互联网协议第六版网络(Application-Aware Internet Protocol version 6Networking,APN6)报文头部的结构示意图;
图2为一种应用APN6技术的网络架构示意图;
图3为另一种应用APN6技术的网络架构示意图;
图4为一种配置ARN ID的报文头部的结构示意图;
图5为本公开实施例一种报文处理方法的流程示意图;
图6为本公开应用示例一种应用ARN技术的网络架构示意图;
图7为本公开应用示例一种ARN ID的访问控制方法的流程示意图;
图8为本公开实施例一种报文处理装置结构示意图;
图9为本公开实施例第一节点结构示意图。
下面通过附图及实施例对本公开再作进一步详细的说明。
相关技术中,网络通常采用尽力而为(英文可以表达为Best-Effort)的转发模式转发报文(也可以理解为提供转发服务)。然而,随着互联网承载的业务类型增多,尽力而为的转发模式已经难以满足不同应用(英文可以表达为APP)对应的多样化转发服务需求,成为了网络发展的一大痛点。
为了满足多样化的转发服务需求,催生了IPv6段路由(Segment Routing IPv6,SRv6)、通用SRv6(Generalized SRv6,G-SRv6)以及网络切片等技术。然而,上述技术未能解决如何将不同应用映射到对应的网络路径上的问题,也即未能解决如何将不同应用的报文按照对应的网络路径进行转发的问题。这里,与应用对应的网络路径也可以理解为满足应用对应的业务等级协议(Service Level Agreement,SLA)需求的网络路径或隧道路径,网络路径具体可以包括网络隧道和/或网络切片等。
相关技术中,多协议标签交换(Multi-Protocol Label Switching,MPLS)技术使得网络可以根据不同应用的报文特性(比如拥塞(Congestion)或者服务质量(Quality of Service,QoS)要求等)来规定转发的网络路径。然而,MPLS技术只能应用于有限的可信域(也可以称为MPLS域)中(也可以理解为在有限域中运行),此时,位于MPLS域边界的节点(比如路由器等)会将所有从MPLS域外部进入MPLS域的报文丢弃。因此,MPLS域内的网络(也可以理解为位于MPLS域内部的网络)对外不可见(也可以理解为对外可以视为黑盒),也就是说,MPLS技术仅能够实现网络感知不同应用的报文(也可以理解为网络能够感知应用),但是不能够实现应用调用网络能力(也可以理解为应用感知网络能力或者应用感知能力)。
实际应用时,如果不能够实现应用调用网络能力,就难以实现按需调整报文转发的优先级并合理地进行网络资源分配。举个例子来说,在数据快递业务中,网络接收到应用的数据报文后,当网络能够感知应用,而应用不能够调用网络能力时,网络仅能够感知不同应用对应的传输协议,而不能够进一步识别具有相同传输协议的应用的不同优先级需求。在这种情况下,可能会出现网络按照接收到的先后顺序,将具有高优先级需求的应用的报文以较低优先级进行转发(类似于普通的文件传输)的情况。当网络能够感知应用,且应用能够调用网络能力时,不同优先级的应用可以调用不同的网络路径进行报文转发,进而可以实现按需调整报文转发的优先级并合理地进行网络资源分配。
相关技术中,为了实现应用调用网络能力,需要网络对外开放网络能力,通常情况下,可以通过控制器(也可以理解为网络控制器或控制设备)的北向接口实现网络能力开放。此时,应用需要调用控制器,以实现对网络能力的调用。然而,应用直接调用控制器可能对网络安全造成影响,基于运营商网络对安全的机制要求,通常难以广泛应用上述方案。
相关技术中,在SRv6的IPv6+技术体系中,定义了APN6技术,APN6技术可以用于协同应用和网络能力。在APN6技术中,定义了在IPv6报文中携带应用信息的方式;具体地,可以在IPv6报文中增加APN6头部,在APN6头部中携带应用的信息。其中,如图1所示,增加的APN6头部具体可以包含APN标识(比如APN ID,具体可以包含应用-类ID(APP-Group-ID)、用户-组ID(USER-Group-ID)、保留(Reserved)字段等)、意图(Intent)、APN参数(APN-Para)等信息。APN6头部可以用于指示报文对应的应用(或者应用组(也可以理解为应用所属的类))信息、使用该应用(或者应用组)的用户(或者用户组)信息、该应用中的关键流(比如云游戏中的动作指令等)以及SLA需求或网络性能需求的相关参数(比如带宽、时延、抖动、丢包率等)等信息,上述信息也可以统称为APN6应用信息或APN6信息。其中,实际应用时,可以基于分组规则将多个应用进行分组,得到多个应用组。这里,应用组的分组规则具体可以基于IPv6报文包含的五元组信息、IPv6报文对应的QinQ信息等进行设置。
实际应用时,如图2所示,应用APN6技术的网络中,端侧设备(比如终端等)或云侧设备(比如服务器等)(端侧设备和云测设备也可以统称为用户设备)上的应用在生成IPv6报文,并向网络发送IPv6报文。此时,端侧设备或云侧设备可以在IPv6报文的APN6头部设置该应用对应的APN6应用信息(也可以理解为填充APN6应用信息或者封装应用特征信息);网络接收到IPv6报文后,可以识别IPv6报文包含的APN6应用信息,从而感知与APN6应用信息对应的应用,网络进而可以将IPv6报文映射到感知到的应用对应的网络路径上进行转发(也可以理解为按照感知到的应用对应的网络路径转发IPv6报文)。如此,应用可以通过在报文中填充APN6应用信息,调用与APN6应用信息对应的网络能力,网络也可以根据报文中携带的APN6应用信息识别相应的应用。同时,应用不需要直接调用控制器就能够实现调用网络能力,能够满足运营商对网络安全的要求。
实际应用时,如图3所示,应用APN6技术的网络架构具体可以包括:
1)端侧设备、云侧设备:比如终端、服务器等,端侧设备或云侧设备可以通过应用感知程序,感知应用的特征信息;进而利用感知的特征信息作为APN6应用信息,生成包含APN6头部的IPv6报文,并将生成的IPv6报文发送至APN6网络域(比如应用APN6技术的SRv6网络域);
2)网络边缘设备:比如APN6网络域边界(也可以理解为边缘)的节点。当端侧设备、云侧设备不具备应用感知能力(即不能够感知应用的APN6应用信息)时,端侧设备、云侧设备无法生成包含APN6头部的IPv6报文。此时,端侧设备、云侧设备可以将不包含APN6头部的IPv6报文发送至网络边缘设备,网络边缘设备接收到IPv6报文后,可以从IPv6报文包含的五元组信息、业务信息(比如双虚拟局域网(Virtual Local Area Network,VLAN)标签的映射关系(即用户VLAN(Customer VLAN,C-VLAN)和服务商VLAN(Service Provider VLAN,S-VLAN)的映射关系))中解析出应用特征信息,并利用解析出的应用特征信息作为APN6应用信息,生成包含APN6头部的IPv6报文,再将生成的IPv6报文转发至网络策略执行设备;
3)网络策略执行设备:比如SRv6网络中提供报文转发服务的网络路径(也可以称为网络服务路径)中包含的节点,具体可以包括:
头节点(也可以理解为感知应用的头节点):网络路径的起始节点。头节点用于维护入方向(即进入APN6网络域方向)的报文流量与网络路径的匹配关系。头节点从网络边缘设备接收到IPv6报文后,头节点可以根据IPv6报文中携带的APN6应用信息以及APN ID与网络策略(即进行网络转发服务的路由策略,也可以称为网络服务策略或选路策略)的对应关系,确定IPv6报文对应的网络策略,并按照网络策略为IPv6报文选择网络路径(也可以理解为匹配与APN6应用信息对应的网络路径(即满足APN6应用信息对应的网络性能需求的网络路径)),并将IPv6报文转发至匹配的网络路径对应的中间节点(也可以理解为引入到满足需求的路径);同时,头节点还可以将APN6应用信息封装到外侧(也可以理解为外层)IPv6扩展头部中(也可以理解为进行路径隧道封装),以使中间节点能够从外侧IPv6扩展头部中获知APN6应用信息,以实现在SRv6网络中进一步提供感知应用服务(也可以理解为使网络中的其他节点能够感知应用信息);
中间节点(也可以理解为感知应用的中间节点):网络路径中位于头节点与尾节点之间的一个或多个(一个或多个也可以理解为至少一个)节点都可以称为中间节点。中间节点可以从头节点获知为IPv6报文匹配的网络路径,从而在接收到来自头节点的IPv6报文后,可以按照匹配的网络路径为应用的IPv6报文提供网络转发服务;同时,中间节点还可以根据IPv6报文中携带的APN6应用信息提供其他的网络增值服务,比如感知应用的业务功能链(Service Function Chaining,SFC)、感知应用的随流检测(In-situ Flow Information Telemetry,IFIT)等;
尾节点(也可以理解为感知应用的尾节点):网络路径的终结节点。尾节点可以将IPv6报文中包含的APN6应用信息和路径隧道封装信息删除(也可以理解为解除);同时,尾节点也可以保留(即不删除)在IPv6报文进入路径之前就已经存在于IPv6报文中的APN6应用信息,并将保留的APN6应用信息随IPv6报文继续传输;
4)控制器:控制器可以用于对APN ID、APN ID与应用(或者应用组)、网络策略之间的映射关系进行统一规划和维护。在网络边缘设备生成包含APN6头部的IPv6报文的情况下,控制器可以将APN ID以及映射关系下发到网络边缘设备和网络策略执行设备。具体地,控制器可以向网络边缘设备下发应用(或者应用组)和APN ID之间的映射关系;同时,控制器可以向网络策略执行设备下发APN ID和网络策略之间的映射关系。在端侧设备或云侧设备生成包含APN6头部的IPv6报文的情况(也可以理解为应用侧方案的情况)下,控制器可以通过与越过运营商(Over-The-Top,OTT)应用管理服务器之间的协同进行协调应用(或者应用组)对应的APN ID,并分发至端侧设备或云侧设备。
实际应用时,APN6技术虽然同时实现了应用对网络能力的调用以及网络对应用的识别。然而,APN6技术存在隐私、安全、管理、容量等一系列问题。具体包括:
隐私方面,IPv6报文的APN6头部以明文方式携带了用户信息,容易泄露用户隐私;
安全方面,APN6应用信息仅与应用关联,可能存在IPv6报文中伪造APN6应用信息、仿冒APN6应用信息等问题;举例来说,用户购买APN6服务后,控制器为用户分配与用户签约的应用对应的APN ID,APN ID是固定且无法改变的,此时,如果APN ID泄露(比如被非法第三方截取),为保障网络安全,需要全面更新所有路由器内保存的APN ID,维护负担大;
管理方面,存在大量应用,且随时都会产生大量新的应用,如何统一编码(也可以理解为分配)这些应用对应的APN ID,以及对这些应用对应的APN ID进行管理(比如修改、删除等)实际上无法实现;
容量方面,当前存在数亿级数量的应用,存储所有应用的APN ID以及APN ID和网络策略之间的映射关系的数据库占用大量容量,当将APN ID和映射关系下发至网络边界设备时,对网络边界设备的容量存在极大的挑战。
同时,网络对APN6应用信息的访问控制有限,也即网络仅能够有限地控制对APN6应用信息的访问(也可以理解为接入)行为,难以满足网络复杂需求。具体地,IPv6报文的扩展头部携带APN6应用信息,而通常情况下,扩展头部(具体可以包括除逐跳(Hop-By-Hop,HBH)头部之外的扩展头部)包含的APN6应用信息在转发过程中不能被改变(比如不能被插入、修改、删除等),如此,当IPv6报文在不同网络域(也可以理解为管理域)之间传输时,由于不同网络域中APN6应用信息可能不相同,从而可能会导致位于网络域边界的节点丢弃IPv6报文,违反了互联网尽力而为的转发原则。
换句话说,由于APN ID是全网统一分配的,而APN6应用信息中包含的应用信息和用户信息的编码方式可能在不同网络域中不相同。因此,当应用APN6技术的报文从一个网络域传输至另一个网络域时(即跨网络域传输时),如果两个网络域中应用信息和用户信息的编码方式相同,接收报文的网络域的边界节点能够准确识别报文包含的APN6应用信息,边界节点从而可以接收该报文,并根据APN6应用信息在该网络域内转发该报文;如果两个网络域中应用信息和用户信息的编码方式不相同,接收报文的网络域的边界节点不能够准确识别报文包含的APN6应用信息,边界节点只能选择丢弃该报文,而不能够忽略报文包含的APN6应用信息并让报文在该网络域内进行转发。
举例来说,假设与家庭用户的用户网络连接的城域网的边界节点为宽带远程接入服务器(Broadband Remote Access Server,BRAS),BRAS可以利用存储(也可以理解为配置)于BRAS上的用户信息对接收到的用户发送报文中包含的APN6应用信息进行检查,如果用户发送的报文中包含的APN6应用信息与BRAS上存储的用户信息不一致(也可以理解为校验失败),BRAS会丢弃该报文,不再进行转发处理;如果用户发送的报文中包含的APN6应用信息与BRAS上存储的用户信息一致(也可以理解为校验成功),BRAS可以根据APN6应用信息在城域网中转发该报文,并将该报文传递至骨干网,然而,当报文从城域网进入骨干网的网络边界(也可以理解为骨干边缘)时,骨干网的边界节点通常不会存储用户的任何业务信息,也就不能够对该报文包含的APN6应用信息进行有效控制和校验,这样可能就会导致该报文被骨干网的边界结点丢弃或导致难以在骨干网中为该报文选择合适的网络路径。这里,相关技术中可以通过构建端到端的网络隧道的方式实现跨域传输,然而,当前固定网络有近3亿的用户,在互联网访问的目的流向存在多样性的情况下,需要在网络中构建数亿条端到端的网络隧道,才能够满足大量用户的跨域传输需求,构建端到端的网络隧道的方式进行跨域传输是难以实现的。
相关技术中,为了避免APN6技术存在的隐私、安全、管理、容量、访问控制等问题,提出了ARN技术。ARN技术基于控制面的算路参数(比如服务类型(英文可以表达为Color)参数)生成应用于转发面的ARN信息(也可以理解为应用调用接口信息,比如ARN ID)实现网络能力开放,也即实现应用调用网络能力。具体地,应用生成报文时,可以在报文的头部包含ARN ID,使得应用能够调用该ARN ID对应的网络能力,也可以理解为使得应用的报文能够根据ARN ID对应的选路策略在网络中进行转发;同时,网络在接收到报文时,能够根据报文头部包含的ARN ID识别对应的应用,并根据与ARN ID匹配的选路策略对报文进行转发处理,比如当报文对应的源地址和目的地址之间存在多条网络路径和/或多个切片的情况下,网络可以根据报文包含的ARN ID选择(也可以理解为确定)其中一条路径和/或切片进行转发处理。也就是说,ARN ID可以理解为应用与网络之间的中间层,通过引入ARN ID,实现应用的网络需求与网络的网络能力之间的桥接,ARN ID同时表征网络对外开放的网络能力信息,以及应用信息和用户信息。其中,每个ARN ID具体可以由一个数字表征,该数字可以包括随机生成的值或按照预设顺序分配的值,ARN ID的结构可以根据实际需要进行设置,也就是说,对ARN ID的结构不作限定,因此,也可以理解为ARN ID是一个无结构化的数字。
实际应用时,在IPv6报文中,由于IPv6报文头部的流标签(Flow Label)字段被设计为灵活可修改,因此ARN ID可以设置在Flow Label字段;或者,ARN ID可以设置在IPv6报文的扩展头部。示例性地,当ARN ID设置在IPv6报文头部的Flow Label字段时,如图4所示,可以复用Flow Label字段的20比特(bit)以设置ARN ID,并通过流量类型(Traffic Class,TC)字段的最高位(具体可以是第7位)指明报文的Flow Label字段是否转义为ARN ID。示例性地,当TC字段的最高位设置为1时,表示指示Flow Label字段被转义为ARN ID;当TC字段的最高位设置为0时,表示指示Flow Label字段未被转义为ARN ID。当然,也可以将TC字段的最高位设置为0时,表示指示Flow Label字段被转义为ARN ID;TC字段的最高位设置为1时,表示指示Flow Label字段未被转义为ARN ID。这里,相关技术中,TC字段的最高位可以被设置为表征显式拥塞通知(Explicit Congestion Notification,ECN),而在广域网的情况下,由于ECN不开启,因此,上述将TC字段的最高位设置为用于指示报文的Flow Label字段是否转义为ARN ID的方案与相关技术中将TC字段的最高位设置为表征ECN的方案不冲突。
实际应用时,应用ARN技术进行网络传输能够取得以下优势:
1)保障网络安全:网络服务商可以通过不同的ARN ID表征对外开放的不同网络能力,以实现为用户提供差异化的网络服务(比如根据应用需求提供低时延、大带宽的隧道和/或切片),而不需要直接对外开放段识别符(Segment IDentifier,SID)和/或绑定SID(Binding SID,BSID),从而实现有效保障网络安全;
2)保护用户隐私:由于ARN ID不显式携带应用信息和用户信息,如此,当网络接收到包含ARN ID的报文时,网络不能够根据报文包含的ARN ID直接获知应用信息和用户信息,因此,ARN技术能够避免用户隐私的泄露;
3)能够实现对ARN ID灵活控制和管理:控制器可以为每个网络域单独进行ARN ID配置,如此,当报文进入网络域时,可以通过在报文中携带该报文在该网络域下与对应的ARN ID,以使该网络域中的节点可以根据报文携带的该网络域的ARN ID进行该网络域内的报文转发处理。也就是说,每个网络域的ARN ID能够根据实际需要灵活配置和管理;同时,报文包含的ARN ID可以根据网络域进行改变,以实现调用相应的网络域的网络能力。举个例子来说,在跨网络域传输的情况下,假设报文从网络域A传输至网络域B,网络域A中与网络域B连接的边界节点可以将报文包含的与网络域A对应的ARN ID替换为与网络域B对应的ARN ID,并将报文发送(也可以理解为传输或传递)至网络域B,以使网络域B中的节点接收到报文后,能够根据报文包含的与网络域B对应的ARN ID进行网络域B内的转发处理;或者,网络域A直接将报文发送至网路域B,网络域B中与网络域A连接的边界节点接收到报文后,可以将报文包含的与网络域A对应的ARN ID替换为与网络域B对应的ARN ID,并按照替换后的ARN ID进行后续网络域B内的转发处理。上述转发处理也可以称为与ARN关联的转发相关处理。
然而,在应用ARN技术的场景下,如果在可信度不相同的两个网络域之间转发报文,网络域的边界节点如何设置报文中的ARN信息(比如ARN ID)以及如何进行转发相关处理,是目前亟待解决的问题。
基于此,在本公开的各种实施例中,通过在第一网络边界的第一节点(也可以理解为边界节点)中设置第一信息,使得第一节点接收到第一报文时,能够根据第一信息确定是否对第一报文进行与ARN关联的转发相关处理,如此,当第一节点从与第一网络的可信度不相同的网络域接收到第一报文时,或者,当第一节点将第一报文转发至与第一网络的可信度不相同的网络域时,可以通过设置第一节点中与第一报文转发相关的接口是否可以使用ARN,来实现在可信度不相同的网络域之间对携带ARN标识的报文进行转发。
本公开实施例提供了一种报文处理方法,应用于第一节点,所述第一节点包括第一网络的边界节点,如图5所示,该方法包括:
步骤501:接收第一报文,所述第一报文包含第一ARN标识;
步骤502:在第一信息表征所述第一节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
这里,实际应用时,所述第一网络具体可以包括用户网络、城域网、骨干网等中之一,本公开实施例对所述第一网络的具体实现不作限定。其中,用户网络也可以理解为用于连接用户网关设备(比如用户端设备(Customer Premise Equipment,CPE)等)与终端的网络,所述终端可以称为用户设备(User Equipment,UE)、终端设备、设备、或用户等,本公开实施例对此不作限定。
所述第一节点包括所述第一网络的边界节点,具体可以包括CPE、供应商边缘(Provider Edge,PE)设备(比如虚拟专用网(Virtual Private Network,VPN)边缘路由器)、BRAS、宽带网络网关(Broadband Network Gateway,BNG)等中之一,所述第一节点可以与第二网络连接,也就是说,所述第一网络与所述第二网络可以通过所述第一节点连接。其中,所述第二网络具体可以包括用户网络、城域网、骨干网等中之一,本公开实施例对所述第二网络的具体实现不作限定;所述第一网络与第二网络的可信度可以不相同,具体地,所述第一网络的可信度可以高于或者等于或者低于所述第二网络的可信度。
所述第一报文具体可以包括IPv6报文,所述第一报文包含的第一ARN标识具体可以包括ARN ID。所述第一ARN标识具体可以设置在所述第一报文的第一字段,也就是说,所述第一报文的第一字段携带所述第一ARN标识。具体地,所述第一字段具体可以包括所述第一报文的报文头部的Flow Lable字段。
所述第一接口包括所述第一节点与所述第二网络连接的接口,具体可以包括互联网协议(Internet Protocol,IP)接口。当所述第一节点需要将所述第一报文发送至所述第二网络时,所述第一节点的报文可以通过所述第一接口转发至所述第二网络,此时,所述第一接口也可以理解为出向接口或出接口;当所述第一节点从所述第二网络接收到所述第一报文时,所述第一节点可以通过所述第一接口从所述第二网络接收所述第一报文,此时,所述第一接口也可以理解为入向接口或入接口。
实际应用时,步骤501中,所述第一节点可以接收来自所述第一网络中的其他节点的第一报文,并需要将所述第一报文通过第一接口转发至第二网络;或者,所述第一节点可以通过第一接口接收来自第二网络的第一报文,并需要将所述第一报文在所述第一网络内进行转发。
接收到所述第一报文后,所述第一节点需要确定如何对所述第一报文进行转发,也可以理解为确定针对所述第一报文的转发服务的服务类型。其中,转发服务的服务类型具体可以由网络路径、选路策略(也可以理解为路由策略,具体可以包括段路由策略(SR Policy)等)、网络隧道和/或网络切片等中一项或多项(一项或多项也可以理解为至少一项)确定。
具体地,所述第一节点可以根据与所述第一接口关联的第一信息确定如何对所述第一报文进行转发。其中,实际应用时,所述第一信息可以命名为trust_arn,当然也可以根据需要被命名为其他;由于所述第一信息与第一接口关联,因此,所述第一信息也可以理解为接口级属性信息;所述第一信息可以表征所述第一接口是否可以使用ARN,所述第一接口是否可以使用ARN与所述第一接口关联的第二网络的可行度关联。具体地,当所述第二网络为可信域(也可以理解为所述第二网络的可信度大于或等于可信度阈值)时,所述第一接口可以使用ARN,此时,所述第一节点可以按照与ARN关联的方式转发所述第一报文;当所述第二网络为非可信域(也可以理解为所述第二网络的可信度小于可信度阈值)时,所述第一接口禁止使用ARN,此时,所述第一节点可以按照不与ARN关联的方式转发所述第一报文。
基于此,所述第一信息的取值可以由所述第二网络是否为可信域确定,示例性地,假设所述第一信息的取值为正确(true)或者错误(false),当所述第二网络为可信域时,所述第一信息的取值为true,用于表征所述第一接口可使用ARN;当所述第二网络为非可信域时,所述第一信息的取值为false,表征所述第一节点的第一接口禁用ARN。当然,也可以当所述第二网络为可信域时,所述第一信息的取值为false,用于表征所述第一节点的第一接口可使用ARN;当所述第二网络为非可信域时,所述第一信息的取值为true,表征所述第一节点的第一接口禁用ARN。
实际应用时,根据所述第二网络是否为可信域确定所述第一信息的取值后,可以在所述第一节点中配置(也可以理解为设置)所述第一信息的取值。具体地,在所述第一节点中配置所述第一信息的取值的具体实现方式可以根据实际需要进行选择,比如通过人工的方式(比如人工键入命令行)在所述第一节点中配置所述第一信息的取值、通过控制设备在所述第一节点中配置所述第一信息的取值等,本公开实施例对此不作限定。这里,所述控制设备也可以称为控制器或网络控制器,至少用于生成ARN标识,以及用于为网络中的节点配置ARN标识。
在所述第一信息的取值配置完成的情况下,所述第一节点接收到包含ARN标识的报文后,步骤502中,所述第一节点可以根据配置的第一信息的取值,确定如何对该报文进行转发相关处理。
具体地,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,所述第一节点对所述报文进行不与ARN关联的转发相关处理,具体可以包括以下两种方式:
第一种方式,所述第一节点直接丢弃所述第一报文;基于此,在一实施例中,所述对所述第一报文进行不与ARN关联的转发相关处理,包括:
所述第一节点丢弃所述第一报文。
第二种方式,所述第一节点将所述第一报文视为(也可以理解为当作)不包含ARN标识的报文,并按照不包含ARN标识的报文的转发方式(也可以理解为默认转发方式)对所述第一报文进行转发相关处理。
更具体地,在一实施例中,所述对所述第一报文进行不与ARN关联的转发相关处理,包括:
当所述第一接口为入向接口时,将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并在所述第一网络内按第四方式转发所述处理后的第一报文,所述第四方式不与ARN关联,所述第五信息表征所述第一报文禁用ARN;其中,所述第五信息的取值具体可以包括0或者无效值,所述第五信息的具体取值可以根据实际需要进行设置,本公开实施例对此不作限定。
这里,如果所述第一字段设置为第五信息,所述第一节点按照默认的转发方式(即所述第四方式)在所述第一网络中转发所述第一报文,也可以理解为为所述第一报文提供默认的网络服务;
当所述第一接口为出向接口时,将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并将所述处理后的第一报文转发至第二网络,所述第五信息表征所述第一报文禁用ARN;
这里,如果所述第一字段设置为第五信息,所述第一节点不进行任何处理,直接将所述第一报文转发至第二网络。
从上述描述可以看出,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,也即所述第一网络为非可信域的情况下,所述第一节点可以在第一接口关联的第二网路为非可信域的情况下,将第一报文丢弃,或者,将第一报文包含的第一ARN标识修改为无效值,从而避免第一ARN标识泄露给非可信域,能够保障网络安全。
相应地,在所述第一信息表征所述第一节点的第一接口可使用ARN的情况下,所述第一节点对所述报文进行与ARN关联的转发相关处理。同时,为了避免仿冒ARN标识造成的网络安全问题,步骤502之前,所述第一节点还可以对所述第一报文包含的ARN标识以及第一报文的源头进行校验,根据校验结果确定是否进行与ARN关联的转发相关处理。
基于此,在一实施例中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;在第一信息表征所述第一节点的第一接口可使用ARN的情况下,校验所述第二信息和第一ARN标识;校验成功后,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理;相应地,校验失败后,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
其中,在一实施例中,所述第二信息可以包括以下一项或多项(一项或多项也可以理解为至少一项):
所述第一报文的用户信息;
所述第一报文的源地址信息;
所述第一报文的端口信息。
这里,实际应用时,当所述第一报文来自用户网络时,所述第二信息可以包括所述第一报文的用户信息,也就是说,所述第二信息可以表征所述第一报文源自哪个用户。此时,所述用户信息具体可以包括用户标识,所述第一报文的接入链路信息等。其中,当所述用户信息包含所述第一报文的接入链路信息时,所述第一节点可以根据所述第一报文的接入链路信息确定所述第一报文通过哪条接入链路发送至所述第一节点,进而根据该条接入链路与用户的对应关系确定用户第一报文源自哪个用户,这里,所述第一节点可以预先获知所述接入链路与用户的对应关系;当所述第一报文来自城域网或骨干网时,所述第二信息可以包括所述第一报文的源地址信息(比如源IP地址信息)和/或所述第一报文的端口信息(比如源端口信息)。
实际应用时,所述第一节点可以获取一个或多个报文的源头信息与ARN标识的对应关系,将第一报文包含的所述第二信息和第一ARN标识在获取的所述对应关系中进行匹配,当存在匹配项时,确定校验成功;当不存在匹配项时,确定校验失败。
基于此,在一实施例中,所述校验所述第二信息和第一ARN标识,包括:
利用第三信息,对所述第二信息和第一ARN标识进行校验,所述第三信息表征一个或多个报文的源头信息与ARN标识的对应关系。
其中,所述第三信息具体可以通过映射表的形式呈现,此时,所述第三信息也可以称为校验表。所述第三信息与所述第一接口关联,也就是说,当所述第一节点通过多个接口与多个网络连接时,每个接口对应一个第三信息,该第三信息用于校验与该接口关联的报文包含的第二信息和ARN标识。
在一实施例中,所述第一节点获取所述第三信息的方式可以包括:所述第一节点接收控制设备发送的所述第三信息、通过人工的方式在所述第一节点配置所述第三信息、所述第一节点利用接收到的所有包含ARN标识的报文对应路由协议进行路由学习,从而确定所述第三信息(即通过路由学习,确定所述第三信息),以及将第一节点对应的访问控制列表(Access Control List,ACL)作为所述第三信息等中之一。其中,所述路由协议具体可以包括边界网关协议(Border Gateway Protocol,BGP)、或内部网关协议(Interior Gateway Protocol,IGP)等,IGP可以进一步包含开放式最短路径优先(Open Shortest Path First,OSPF)协议、或中间系统到中间系统(Intermediate System to Intermediate System,ISIS)协议等;所述路由协议可以由在所述第一节点之前传输所述第一报文的任何一个节点进行配置。
实际应用时,如果校验失败,步骤502中,所述第一节点可以对所述第一报文进行不与ARN关联的转发相关处理,不与ARN关联的转发相关处理的具体实现方式已在上文详述,这里不再赘述;如果校验成功,步骤502中,所述第一节点可以对所述第一报文进行与ARN关联的转发相关处理,此时,所述与ARN关联的转发相关处理可以根据所述第一接口为入向接口或出向接口,以及所述第一节点是否需要重新设置所述第一报文包含的ARN标识(也可以理解为进行ARN ID映射),分以下四种情况进行讨论:
第一种情况,当所述第一接口为出向接口,且所述第一节点需要重新设置所述第一报文包含的ARN标识时,所述第一节点接收到第一报文后,可以将第一报文包含的与第一网络关联的第一ARN标识,映射(也可以理解为重新设置或替换)为与所述第二网络关联的ARN标识,并将进行映射后的第一报文转发至第二网络,以使所述第二网络能够根据映射后的ARN标识,在第二网络内转发所述第一报文(也可以理解为在所述第二网络内为所述第一报文提供映射后的ARN标识对应的网络服务)。
基于此,在一实施例中,所述对所述第一报文进行与ARN关联的转发相关处理,包括:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,得到处理后的第一报文,所述第二ARN标识与第二网络关联,将所述处理后的第一报文转发至所述第二网络;
其中,所述第一节点可以获取一个或多个第一ARN标识与第二ARN标识的对应关系,以使所述第一节点可以利用所述对应关系和第一报文包含的第一ARN标识,确定第一报文对应的第二ARN标识,进而实现在所述第一字段设置确定的所述第二ARN标识。
基于此,在一实施例中,利用第四信息,将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,或者,将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,所述第四信息表征一个或多个第一网络关联的ARN标识与第二网络关联的ARN标识的对应关系。
其中,在一实施例中,所述第一节点获取所述第四信息的方式可以包括:所述第一节点接收控制设备发送的所述第四信息、通过人工的方式在所述第一节点配置所述第四信息、所述第一节点利用接收到的所有包含ARN标识的报文对应路由协议进行路由学习,从而确定所述第四信息(即通过路由学习,确定所述第四信息)等中之一。
第二种情况,当所述第一接口为出向接口,且所述第一节点不需要重新设置所述第一报文包含的ARN标识时,所述第一节点可以直接将接收到的第一报文转发至第二网络,所述第二网络的边界节点接收到所述第一报文后,可以将第一报文包含的与第一网络关联的第一ARN标识,映射为与所述第二网络关联的ARN标识,以使所述第二网络的边界节点能够根据映射后的ARN标识,在所述第二网络内转发所述第一报文。
基于此,在一实施例中,所述对所述第一报文进行与ARN关联的转发相关处理,包括:
将所述第一报文转发至所述第二网络,在所述第二网络能够按照第二方式转发报文,所述第二方式与所述第一报文对应的第二ARN标识关联;
第三种情况,当所述第一接口为入向接口,且所述第一节点需要重新设置所述第一报文包含的ARN标识时,所述第一节点接收到来自第二网络的第一报文后,可以将第一报文包含的与第二网络关联的第一ARN标识,映射为与所述第一网络关联的ARN标识,并根据映射后的ARN标识,在所述第一网络内转发所述第一报文。
基于此,在一实施例中,所述对所述第一报文进行与ARN关联的转发相关处理,包括:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,得到处理后的第一报文,所述第三ARN标识与第一网络关联,在所述第一网络内按照第一方式转发所述处理后的第一报文,所述第一方式与所述第三ARN标识关联;
第四种情况,当所述第一接口为入向接口,且所述第一节点不需要重新设置所述第一报文包含的ARN标识时,所述第一节点接收到来自第二网络的第一报文后,可以直接根据第一报文包含的与第一网络关联的第一ARN标识,在所述第一网络内转发所述第一报文。其中,所述第二网络的边界节点向所述第一节点发送第一报文之前,已经将所述第一报文中包含的与第二网络关联的ARN标识映射为所述第一网络关联的第一ARN标识。
基于此,在一实施例中,所述对所述第一报文进行与ARN关联的转发相关处理,包括:
在所述第一网络内按照第三方式转发所述第一报文,所述第三方式与所述第一ARN标识关联。
从上述描述可以看出,所述第一节点能够利用所述第三信息对第一报文的源头以及第一ARN标识进行校验,并根据校验结果对所述第一报文进行转发相关处理。
实际应用时,所述第三信息与第四信息可以进行合并,合并后的信息能够实现所述第三信息与第四信息的功能。基于此,当为所述第一节点同时配置了第三信息与第四信息时,所述第一节点可以仅存储合并后的信息,并利用合并后的信息实现所述第三信息与第四信息的功能,由于合并的信息占用的存储空间较小,能够节省存储资源;同时,如果所述第一节点同时配置有ACL和第三信息,所述第一节点在进行校验时,可以优先利用ACL对第一报文的源头以及第一ARN标识进行校验,也即ACL的校验优先级最高。示例性地,当利用ACL进行校验得到的校验结果与利用所述第三信息进行校验得到的校验结果不一致时,可以以ACL对应的校验结果为准。
本公开实施例提供的报文处理方法,第一节点接收第一报文,所述第一报文包含第一ARN标识,所述第一节点包括第一网络的边界节点;在第一信息表征所述第一节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。本公开实施例提供的方案,通过在第一网络边界(也可以理解为第一网络的网络域边界)的第一节点中设置第一信息,使得第一节点接收到跨网络域传输(比如进入第一网络或者离开第一网络)的第一报文时,能够根据第一信息确定是否对第一报文进行与ARN关联的转发相关处理,如此,当第一节点从与第一网络的可信度不相同的网络接收到第一报文时,或者,当第一节点将第一报文转发至与第一网络的可信度不相同的网络时,可以通过在第一节点中与第一报文转发相关的接口是否可以使用ARN,来实现在可信度不相同的网络域之间对携带ARN标识的报文进行转发。
下面结合应用示例对本公开再作进一步详细的描述。
本应用示例提供一种应用ARN技术的网络架构,如图6所示,所述网络架构包括控制器(即上述控制设备)、用户网络、城域网、骨干网。其中,用户网络与城域网连接,城域网与骨干网。示例性地,用户网络的CPE与城域网的BRAS连接,城域网的城域边界节点(也可以理解为城域边界设备)与骨干网的PE连接。其中,用户网络、城域网、骨干网也可以理解为不同的网络域,不同网络域之间的可信度可以不相同。
实际应用时,ARN ID(即上述ARN标识)主要应用于网络边界节点(也可以理解为网络边界业务接入点,比如PE、BRAS、或BNG等)。当控制器收到用户订阅ARN服务的订单信息(也可以理解为针对网络服务的订阅需求)后,可以根据接收到的订单信息设置与订单信息对应的一个或多个服务类型;针对每个服务类型,控制器可以根据SR Policy为该服务类型在与该用户对应的用户网络连接的城域网中进行选路,也即确定城域网中转发该服务类型对应的报文的选路策略(选路策略与转发报文的网络路径关联,网络路径具体可以包括网络切片和/或网络隧道等)。确定服务类型对应的选路策略后,针对该选路策略,如果该选路策略已有对应的ARN ID,控制器可以直接确定服务类型与ARN ID的对应关系(也可以通过二元组的形式表达,比如<服务类型,ARN ID>)以及ARN ID与选路策略的对应关系(也可以通过二元组的形式表达,比如<ARN ID,选路策略>);如果该选路策略尚未有对应的ARN ID,控制器可以按照预设策略(比如与应用管理服务器协商等)生成与该选路策略对应的ARN ID,进而确定服务类型与ARN ID的对应关系以及ARN ID与选路策略的对应关系;确定所述两个对应关系后,控制器可以将服务类型与ARN ID的对应关系下发至用户设备(比如终端、服务器、CPE等),以使用户设备在生成报文时,可以根据报文对应的服务类型以及对应关系,确定报文对应的ARN ID,并在报文中携带确定的ARN ID;同时,控制器可以将ARN ID与选路策略的对应关系下发至城域网中与用户对应的用户网络连接的边界节点(比如BRAS),以使用户的报文进入城域网时,BRAS能够根据报文包含的ARN ID以及对应关系,确定转发该报文的选路策略(也可以理解为确定为该报文提供的网络转发服务),控制器向边界节点下发对应关系的过程也可以理解为进行网络侧配置。
示例性地,假设控制器将服务类型与ARN ID的对应关系下发至终端和/或服务器,终端和/或服务器上的应用可以根据应用所需的服务类型以及所述对应关系,在生成应用对应的报文的过程中,在报文中携带与应用所需的服务类型对应的ARN ID,如此,用户网络的CPE接收到终端和/或服务器发送的报文时,报文已经携带ARN ID,可以直接转发至城域网;假设控制器将服务类型与ARN ID的对应关系下发至CPE,终端和/或服务器生成的报文可以不携带ARN ID,CPE接收到终端和/或服务器发送的报文后,可以利用ACL等方式对报文进行分类(也可以理解为进行流分配),从而,确定报文所需的服务类型,并根据保温所需的服务类型以及所述对应关系,在报文中携带与报文所需的服务类型对应的ARN ID,进而可以将报文转发至城域网。
基于上述网络架构,本应用示例提供了一种ARN ID的访问控制方法,如图7所示,包括以下步骤:
步骤701:网络边界设备(即上述第一节点)接收包含ARN ID(即上述第一ARN标识)的报文(即上述第一报文);
实际应用时,所述网络边界设备具体可以包括用户网络的CPE、城域网的城域边界设备、城域网的BRAS、骨干网的PE等中之一。
步骤702:网络边界设备根据与邻域网络(即上述第二网络)连接的接口(即上述第一接口,具体可以包括IP接口)对应的ARN可信度属性(trust_arn),对报文进行转发处理;其中,所述转发处理包括:
当trust_arn的取值为false时,在报文转发时禁用ARN服务;
当trust_arn的取值为true时,执行步骤703;
这里,所述邻域网络是指与所述网络边界设备所属的网络相邻的网络,示例性地,如图6所示,城域网的邻域网络包括用户网络和骨干网。当网络边界设备需要将接收到的报文转发至邻域网络时,所述接口也可以称为出向接口;当网络边界设备从邻域网络接收到所述报文,并需要在网络边界设备所属的网络内进行转发时,所述接口也可以称为入向接口。
实际应用时,trust_arn为接口级属性,可以通过人工或者控制器下发等之一的方式,根据网络边界设备所属的网络与邻域网络之间的可信度关系(也可以理解为邻域网络相对于网络边界设备所属的网络来说是否为可信域)预先在网络边界设备中进行设置。trust_arn的取值可以被设置为正确(true)或者错误(false)。
实际应用时,所述禁用ARN服务,是指网络边界设备将报文当做不携带ARN ID的报文进行转发处理,比如丢弃报文,或者按照默认选路策略转发报文等。具体地,当trust_arn的取值为false时,网络边界设备接收到包含ARN ID的报文(也可以理解为携带ARN信息的报文)后,可以将报文中携带ARN ID的字段(比如Flow Lable字段等)的取值置为0(也可以理解为擦写为0)或置为无效值(具体可以根据实际需要进行选择)。如此,网络边界设备可以将包含ARN ID为0或无效值的报文,按照不包含ARN ID的报文进行转发处理。
步骤703:网络边界设备对报文包含的用户信息和ARN ID进行合法性校验;
如果校验成功,执行步骤704;
如果校验失败,禁用ARN服务;
这里,当所述接口为出向接口时,所述合法性校验也可以称为ARN出方向校验或者出向校验;当所述接口为入向接口时,所述合法性校验也可以称为ARN入方向校验或者入向校验。
实际应用时,为了避免第三方(比如未订阅ARN服务的用户)在发送的报文中仿冒ARN ID,网络边界设备可以获取用于校验用户身份的校验表(即上述第三信息),如此,网络边界设备接收到用户的报文时,可以利用所述校验表校验报文包含的ARN ID以及报文对应的用户信息,从而避免仿冒。其中,校验表可以用于出向校验和/或入向校验,用于出向校验的校验表也可以称为出向校验表;用于入向校验的校验表也可以称为入向校验表。
实际应用时,所述网络边界设备可以通过人工配置、控制器下发、路由学习等中之一的方式获取所述校验表。示例性地,当所述网络边界设备通过控制器下发的方式获取所述校验表时,具体实现可以包括:控制器根据用户的订阅信息确定用户的源地址信息(比如源IP)和/或链路信息,并将用户的源地址信息和/或链路信息作为用户信息(也可以理解为用户的标识信息,即上述源头信息),从而控制器可以针对每个用户,确定该用户的用户信息与该用户订阅的服务类型对应的ARN ID之间的对应关系,也可以理解为该用户的报文可以包含哪些ARN ID(也可以通过二元组的形式表达,比如<用户信息,ARN ID>);控制器进而可以根据所有用户的用户信息与ARN ID的对应关系,确定所述校验表,并将校验表下发至网络边界设备。
示例性地,假设所述网络边界设备为用户网络的边界设备(比如CPE等)或者与用户网络连接的邻域网络的边界设备(比如BRAS、BNG等),所述网络边界设备可以根据接收到的报文确定用户信息,比如根据报文对应的接入链路信息确定用户信息;同时,网络边界设备可以根据接收到的报文确定报文包含的ARN ID,此时,网络边界设备也可以被称为用户网关设备。或者,假设所述网络边界设备为城域网与骨干网连接的边界设备(比如城域边界设备、PE等),网络边界设备可以根据报文包含的源IP信息或者端口信息确定用户信息,并确定报文包含的ARN ID,此时,网络边界设备也可以被称为网络网关设备。如此,确定用户信息、ARN ID后,网络边界设备可以根据确定的用户信息、ARN ID以及控制器下发的校验表,对报文进行合法性校验。
实际应用时,在进行入向校验时,网络边界设备接收到的报文包含的ARN ID可能与邻域网络关联,此时,网络边界设备需要对报文包含的ARN ID进行映射(也可以理解为替换、重写、更新等),使映射后的ARN ID与网络边界设备所属的网络关联,如此,网络边界设备才能够根据报文包含的ARN ID,在网络边界设备所属的网络内对报文进行转发;相应地,在进行出向校验时,网络边界设备接收到的报文包含的ARN ID与网络边界设备所属的网络关联,网络边界设备可以对报文包含的ARN ID进行映射,使映射后的ARN ID与邻域网络关联,如此,网络边界设备将报文转发至邻域网络后,邻域网络可以直接根据报文包含的ARN ID在邻域网络内进行报文转发。
实际应用时,由于控制器为网络边界设备所属的网络与邻域网络分别进行ARN ID的分配,因此,网络边界设备可以获取网络边界设备所属的网络的ARN ID与邻域网络的ARN ID之间的对应关系(也可以理解为映射关系,也即上述第四信息),以实现对报文包含的ARN ID进行映射。其中,所述对应关系具体可以通过映射表的形式呈现,所述映射表可以用于出向校验和/或入向校验,用于出向校验的映射表也可以称为出向映射表;用于入向校验的映射表也可以称为入向映射表。
实际应用时,所述网络边界设备可以通过人工配置、控制器下发、路由学习等中之一的方式获取所述映射表。示例性地,假设邻域网络为骨干网,网络边界设备所属的网络为城域网,当所述网络边界设备通过控制器下发的方式获取所述映射表时,具体实现可以包括:控制器根据城域网中的选路策略与骨干网中的选路策略的对应关系(也可以理解为在城域网中通过每种选路策略转发的报文在骨干网中分别应当通过哪种选路策略提供网络转发服务),确定控制器为城域网分配的ARN ID与为骨干网分配的ARN ID的对应关系;控制器进而可以根据所有ARN ID的对应关系,确定所述映射表,并将映射表下发至边界设备。如此,能够实现在不同网络之间转发报文的过程中,对报文包含的ARN ID进行灵活地访问控制。
实际应用时,网络边界设备获取的校验表与映射表可以进行合并(这里,当由控制器下发校验表与映射表时,可以在控制器中进行合并),得到合并后的表。此时,网络边界设备可以根据确定的用户信息、ARN ID以及合并后的表,对报文进行合法性校验,并将报文包含的ARN ID映射为与网络边界设备所属的网络关联的ARN ID(也即目的ARN ID)。其中,合并后的表可以通过三元组的形式表达,比如<用户信息,ARN ID,目的ARN ID>,ARN ID与网络边界设备所属的网络关联,目的ARN ID与所述邻域网络关联。
示例性地,网络边界设备获取的入向校验表和入向映射表可以合并,出向校验表和出向映射表也可以合并。如图6所示,CPE的面向用户接口(也可以理解为面向终端和/或服务器的接口)的入向校验表可以表达为<用户信息,ARN ID>、出向校验表可以表达为<源IP,ARN ID>;CPE、其他网络边界设备(包括BRAS、PE、城域网边界设备等)的其他接口的入向校验表和出向校验表均可以表达为<源IP,ARN ID>;CPE的面向用户接口的入向映射表可以表达为<用户,ARN ID,目的ARN ID>、出向映射表可以表达为<源IP,ARN ID,目的ARN ID>;CPE、其他网络边界设备的其他接口的入向映射表和出向映射表均可以表达为<源IP,ARN ID,目的ARN ID>。
实际应用时,当ACL、校验表、映射表均有同一ARN ID(也即一个ARN ID的相关信息同时存在于ACL、校验表、映射表中)时,网络边界设备优先使用ACL对该ARN ID进行合法性校验;当ACL中不包含该ARN ID的相关信息时,网络边界设备可以使用校验表对该ARN ID进行合法性校验;当ACL、校验表中均不包含该ARN ID的相关信息时,网络边界设备可以使用映射表对该ARN ID进行合法性校验。也就是说,网络边界设备可以按照ACL>校验表>映射表的优先级顺序对该ARN ID进行合法性校验。
步骤704:网络边界设备执行与ARN关联的转发处理,所述与ARN关联的转发处理包括以下之一:
如果所述接口为入向接口,网络边界设备根据报文包含的ARN ID以及控制器下发的ARN ID与选路策略的对应关系,确定选路策略,并按照确定的选路策略转发报文;或者,网络边界设备根据报文包含的ARN ID以及所述映射表,将报文包含的ARN ID映射为与网络边界设备所属的网络关联的ARN ID,并根据映射后的ARN ID以及控制器下发的ARN ID与选路策略的对应关系,确定选路策略,并按照确定的选路策略转发报文;其中,按照确定的选路策略转发报文,包括:将报文映射到选路策略对应的网络隧道和/或网络切片;
如果所述接口为出向接口,网络边界设备根据报文包含的ARN ID以及所述映射表,将报文包含的ARN ID映射为与邻域网络关联的ARN ID,并将报文转发至邻域网络;或者,网络边界设备直接将报文转发至邻域网络。
实际应用时,当网络边界设备直接将报文转发至邻域网络时,邻域网络的边界设备可以将根据报文包含的ARN ID以及映射表,将报文包含的ARN ID映射为与邻域网络关联的ARN ID,以使邻域网络的边界设备可以根据与邻域网络关联的ARN ID在邻域网络内进行报文转发。
本公开应用示例提供的方案,通过在网络边界设备部署一个IP接口级属性trust_arn来标识网络边界设备连接的邻域网络为可信域或非可信域,以使网络边界设备能够根据trust_arn的取值对包含ARN ID的报文进行转发处理。也就是说,即使网络边界设备连接非可信域,也可以对报文进行相应的转发处理,也即实现了构建从非可信域调用可信域的网络能力的基本安全框架。
同时,当IP接口的trust_arn取值为false时,网络边界设备可以整体禁用ARN服务,此时,如果进入或离开该接口的报文携带ARN信息,网络边界设备可以将ARN ID擦写为0或置为某个无效值,并将该报文当作不携带ARN信息的报文进行处理;
当IP接口的trust_arn取值为true时,如果网络边界设备收到报文的ARN ID无效,比如ARN ID为0或无效值,网络边界设备将该报文当作不携带ARN信息的报文进行处理(也即禁用ARN服务);
当IP接口的trust_arn为true,且网络边界设备为用户网关设备、IP接口为入向接口时,用户网关设备可以根据报文包含用户信息和ARN ID,在校验表和/或映射表中对<用户,ARN ID>两元组进行匹配(也可以理解为查询),如果存在匹配项,则用户网关设备可以对报文进行网络隧道和/或网络切片的映射并转发报文,或者,可以先将报文包含的ARN ID映射为目的ARN ID,再对报文进行网络隧道和/或网络切片的映射并转发报文;如果不存在匹配项,则用户网关设备可以将报文包含的ARN ID擦写为0或置为某个无效值,并将该报文当作不携带ARN信息的报文进行处理;
当IP接口的trust_arn为true,且网络边界设备为网络网关设备、IP接口为入向接口时,如果报文的ARN ID有效,则网络网关设备在校验表和/或映射表中对<用户信息(比如用户或源IP),ARN ID>两元组进行匹配,如果存在匹配项,则网络网关设备可以直接对报文进行网络隧道和/或网络切片的映射并转发报文,或者,先将报文包含的ARN ID映射为目的ARN ID,再对报文进行网络隧道和/或网络切片的映射并转发报文;如果不存在匹配项,则网络网关设备将报文包含的ARN ID擦写为0或置为某个无效值,或者保留ARN ID(也即不改变报文包含的ARN ID),再对报文进行网络隧道和/或网络切片的映射并转发报文。
当IP接口的trust_arn为true,且IP接口为出向接口时,如果报文的ARN ID有效,则网络边界设备在校验表和/或映射表中对<用户信息(比如用户或源IP),ARN ID>两元组进行匹配,如果存在匹配项,则网络边界设备可以直接将报文转发至邻域网络,或者,先将报文包含的ARN ID映射为目的ARN ID,再将报文转发至邻域网络;如果不存在匹配项,则网络边界设备可以将报文包含的ARN ID擦写为0或置为某个无效值,或者保留ARN ID(也即不改变报文包含的ARN ID),再将报文转发至邻域网络。
如此,本公开应用示例提供的方案存在以下优势:
在应用隐私方面,由于ARN ID是随机值,不携带应用隐私信息,并且可以映射到网络的切片和/或隧道,能够保障应用的安全;同时,ARN可以封装网络内部隐私信息,避免用户直接使用SRv6 Policy或BSID带来的网络内部信息泄露问题;
在业务功能方面,通过在网络边界设备接口定义可信域和非可信域,使得对ARN ID进行访问控制时,当接口连接的网络为非可信域时,网络边界设备可以完全忽略ARN(也即禁用ARN服务);当接口连接的网络为可信域时,网络边界设备可以在报文包含的ARN ID不存在匹配项(也可以理解为网络边界设备不认识报文包含的ARN ID)时,不丢弃报文,并将报文映射到默认隧道和/或切片(也即为报文提供默认的网络转发服务);
在设备容量方面,由于网络边界设备中仅需要存储网络边界设备所属的网络,以及邻域网络的ARN相关信息(比如ARN ID、校验表、映射表等),而不需要存储全局网络的信息,因此,占用的存储空间较小,对设备容量的要求较低。
为了实现本公开实施例的方法,本公开实施例还提供了一种报文处理装置,设置在第一节点上,如图8所示,该装置包括:
接收单元801,用于接收第一报文,所述第一报文包含第一ARN标识;
处理单元802,用于在第一信息表征所述第一节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
其中,在一实施例中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;所述处理单元802,具体用于:
在第一信息表征所述第一节点的第一接口可使用ARN的情况下,校验所述第二信息和第一ARN标识;校验成功后,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理。
在一实施例中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;所述处理单元802,具体用于:
在第一信息表征所述第一节点的第一接口可使用ARN的情况下,校验所述第二信息和第一ARN标识;校验失败后,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
在一实施例中,所述处理单元802,具体用于:
利用第三信息,对所述第二信息和第一ARN标识进行校验,所述第三信息表征一个或多个报文的源头信息与ARN标识的对应关系。
在一实施例中,所述接收单元801,还用于接收控制设备发送的所述第三信息;
或者,
所述处理单元802,还用于通过路由学习,确定所述第三信息。
在一实施例中,所述处理单元802,具体用于执行以下之一:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,得到处理后的第一报文,所述第二ARN标识与第二网络关联,将所述处理后的第一报文转发至所述第二网络;
将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,得到处理后的第一报文,所述第三ARN标识与第一网络关联,在所述第一网络内按照第一方式转发所述处理后的第一报文,所述第一方式与所述第三ARN标识关联;
将所述第一报文转发至所述第二网络,在所述第二网络能够按照第二方式转发报文,所述第二方式与所述第一报文对应的第二ARN标识关联;
在所述第一网络内按照第三方式转发所述第一报文,所述第三方式与所述第一ARN标识关联。
在一实施例中,所述处理单元802,具体用于:
利用第四信息,将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,或者,将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,所述第四信息表征一个或多个第一网络关联的ARN标识与第二网络关联的ARN标识的对应关系。
在一实施例中,所述接收单元801,还用于接收控制设备发送的所述第四信息;
或者,
所述处理单元802,还用于通过路由学习,确定所述第四信息。
在一实施例中,所述处理单元802,具体用于执行以下之一:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并在所述第一网络内按第四方式转发所述处理后的第一报文,所述第四方式不与ARN关联,所述第五信息表征所述第一报文禁用ARN;
将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并将所述处理后的第一报文转发至第二网络,所述第五信息表征所述第一报文禁用ARN;
丢弃所述第一报文。
实际应用时,所述接收单元801可由报文处理装置中的通信接口实现,所述处理单元802可由报文处理装置中的处理器实现。
需要说明的是:上述实施例提供的报文处理装置在进行报文处理时,仅以上述各程序单元的划分进行举例说明,实际应用中,可以根据需要而将上述处理分配由不同的程序单元完成,即将装置的内部结构划分成不同的程序单元,以完成以上描述的全部或者部分处理。另外,上述实施例提供的报文处理装置与报文处理方法实施例属于同一构思,其具体实现过程详见方法实施例,这里不再赘述。
基于上述程序模块的硬件实现,且为了实现本公开实施例的方法,本公开实施例还提供了一种节点,如图9所示,该节点900包括:
通信接口901,能够与其他设备(比如控制设备等)进行信息交互;
处理器902,与所述通信接口901连接,以实现与其他设备进行信息交互,用于运行计算机程序时,执行上述一个或多个技术方案提供的方法;
存储器903,所述计算机程序存储在存储器903上。
具体地,所述通信接口901,用于:
接收第一报文,所述第一报文包含第一ARN标识;
所述处理器902,用于:
在第一信息表征所述节点的第一接口可使用ARN的情况下,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理,或者,在所述第一信息表征所述节点的第一接口禁用ARN的情况下,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
其中,在一实施例中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;所述处理器902,具体用于:
在第一信息表征所述节点的第一接口可使用ARN的情况下,校验所述第二信息和第一ARN标识;校验成功后,在所述第一接口对所述第一报文进行与ARN关联的转发相关处理。
在一实施例中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;所述处理器902,具体用于:
在第一信息表征所述节点的第一接口可使用ARN的情况下,校验所述第二信息和第一ARN标识;校验失败后,在所述第一接口对所述第一报文进行不与ARN关联的转发相关处理。
在一实施例中,所述处理器902,具体用于:
利用第三信息,对所述第二信息和第一ARN标识进行校验,所述第三信息表征一个或多个报文的源头信息与ARN标识的对应关系。
在一实施例中,所述通信接口901,还用于接收控制设备发送的所述第三信息;
或者,
所述处理器902,还用于通过路由学习,确定所述第三信息。
在一实施例中,所述处理器902,具体用于执行以下之一:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,得到处理后的第一报文,所述第二ARN标识与第二网络关联,将所述处理后的第一报文转发至所述第二网络;
将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,得到处理后的第一报文,所述第三ARN标识与第一网络关联,在所述第一网络内按照第一方式转发所述处理后的第一报文,所述第一方式与所述第三ARN标识关联;
将所述第一报文转发至所述第二网络,在所述第二网络能够按照第二方式转发报文,所述第二方式与所述第一报文对应的第二ARN标识关联;
在所述第一网络内按照第三方式转发所述第一报文,所述第三方式与所述第一ARN标识关联。
在一实施例中,所述处理器902,具体用于:
利用第四信息,将所述第一报文中携带所述第一ARN标识的第一字段设置为第二ARN标识,或者,将所述第一报文中携带所述第一ARN标识的第一字段设置为第三ARN标识,所述第四信息表征一个或多个第一网络关联的ARN标识与第二网络关联的ARN标识的对应关系。
在一实施例中,所述通信接口901,还用于接收控制设备发送的所述第四信息;
或者,
所述处理器902,还用于通过路由学习,确定所述第四信息。
在一实施例中,所述处理器902,具体用于执行以下之一:
将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并在所述第一网络内按第四方式转发所述处理后的第一报文,所述第四方式不与ARN关联,所述第五信息表征所述第一报文禁用ARN;
将所述第一报文中携带所述第一ARN标识的第一字段设置为第五信息,得到处理后的第一报文,并将所述处理后的第一报文转发至第二网络,所述第五信息表征所述第一报文禁用ARN;
丢弃所述第一报文。
需要说明的是:所述处理器902和所述通信接口901的具体处理过程可参照上述方法理解。
当然,实际应用时,节点900中的各个组件通过总线系统904耦合在一起。可理解,总线系统904用于实现这些组件之间的连接通信。总线系统904除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图9中将各种总线都标为总线系统904。
本公开实施例中的存储器903用于存储各种类型的数据以支持节点900的操作。这些数据的示例包括:用于在节点900上操作的任何计算机程序。
上述本公开实施例揭示的方法可以应用于所述处理器902,或者由所述处理器902实现。所述处理器902可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过所述处理器902中的硬件的集成逻辑电路或者软件形式的指令完成。上述的所述处理器902可以是通用处理器、数字信号处理器(Digital Signal Processor,DSP),或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。所述处理器902可以实现或者执行本公开实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本公开实施例所公开的方法的步骤,可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于存储介质中,该存储介质位于存储器903,所述处理器902读取存储器903中的信息,结合其硬件完成前述方法的步骤。
在示例性实施例中,节点900可以被一个或多个应用专用集成电路(Application Specific Integrated Circuit,ASIC)、DSP、可编程逻辑器件(Programmable Logic Device,PLD)、复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)、通用处理器、控制器、微控制器(Micro Controller Unit,MCU)、微处理器(Microprocessor)、或者其他电子元件实现,用于执行前述方法。
可以理解,本公开实施例的存储器(存储器903)可以是易失性存储器或者非易失性存储器,也可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read Only Memory,ROM)、可编程只读存储器(Programmable Read-Only Memory,PROM)、可擦除可编程只读存储器(Erasable Programmable Read-Only Memory,EPROM)、电可擦除可编程只读存储器(Electrically Erasable Programmable Read-Only Memory,EEPROM)、磁性随机存取存储器(ferromagnetic random access memory,FRAM)、快闪存储器(Flash Memory)、磁表面存储器、光盘、或只读光盘(Compact Disc Read-Only Memory,CD-ROM);磁表面存储器可以是磁盘存储器或磁带存储器。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(Static Random Access Memory,SRAM)、同步静态随机存取存储器(Synchronous Static Random Access Memory,SSRAM)、动态随机存取存储器(Dynamic Random Access Memory,DRAM)、同步动态随机存取存储器(Synchronous Dynamic Random Access Memory,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate Synchronous Dynamic Random Access Memory,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced Synchronous Dynamic Random Access Memory,ESDRAM)、同步连接动态随机存取存储器(SyncLink Dynamic Random Access Memory,SLDRAM)、直接内存总线随机存取存储器(Direct Rambus Random Access Memory,DRRAM)。本公开实施例描述的存储器旨在包括但不限于这些和任意其它适合类型的存储器。
在示例性实施例中,本公开实施例还提供了一种存储介质,即计算机存储介质,具体为计算机可读存储介质,例如包括存储计算机程序的存储器903,上述计算机程序可由节点900的处理器902执行,以完成前述方法所述步骤。计算机可读存储介质可以是FRAM、ROM、PROM、EPROM、EEPROM、Flash Memory、磁表面存储器、光盘、或CD-ROM等存储器。
在示例性实施例中,本公开实施例还提供了一种计算机程序产品,包括计算机程序,所述计算机程序可由节点900的处理器902执行,以完成前述方法所述步骤。
需要说明的是:“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。
另外,本公开实施例所记载的技术方案之间,在不冲突的情况下,可以任意组合。
以上所述,仅为本公开的较佳实施例而已,并非用于限定本公开的保护范围。
Claims (15)
- 一种报文处理方法,包括:第一节点接收第一报文,所述第一报文包含第一应用响应网络标识,所述第一节点包括第一网络的边界节点;在第一信息表征所述第一节点的第一接口可使用应用响应网络的情况下,所述第一节点在所述第一接口对所述第一报文进行与应用响应网络关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用应用响应网络的情况下,所述第一节点在所述第一接口对所述第一报文进行不与应用响应网络关联的转发相关处理。
- 根据权利要求1所述的方法,其中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;在第一信息表征所述第一节点的第一接口可使用应用响应网络的情况下,所述第一节点校验所述第二信息和第一应用响应网络标识;校验成功后,在所述第一接口对所述第一报文进行与应用响应网络关联的转发相关处理。
- 根据权利要求1所述的方法,其中,所述第一报文还包含第二信息,所述第二信息表征所述第一报文的源头;在第一信息表征所述第一节点的第一接口可使用应用响应网络的情况下,所述第一节点校验所述第二信息和第一应用响应网络标识;校验失败后,在所述第一接口对所述第一报文进行不与应用响应网络关联的转发相关处理。
- 根据权利要求2或3所述的方法,其中,所述校验所述第二信息和第一应用响应网络标识,包括:所述第一节点利用第三信息,对所述第二信息和第一应用响应网络标识进行校验,所述第三信息表征一个或多个报文的源头信息与应用响应网络标识的对应关系。
- 根据权利要求4所述的方法,还包括:所述第一节点接收控制设备发送的所述第三信息;或者,所述第一节点通过路由学习,确定所述第三信息。
- 根据权利要求2或3所述的方法,其中,所述第二信息包括以下一项或多项:所述第一报文的用户信息;所述第一报文的源地址信息;所述第一报文的端口信息。
- 根据权利要求1至3任一项所述的方法,其中,所述对所述第一报文进行与应用响应网络关联的转发相关处理,包括以下之一:所述第一节点将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第二应用响应网络标识,得到处理后的第一报文,所述第二应用响应网络标识与第二网络关联,将所述处理后的第一报文转发至所述第二网络;所述第一节点将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第三应用响应网络标识,得到处理后的第一报文,所述第三应用响应网络标识与第一网络关联,在所述第一网络内按照第一方式转发所述处理后的第一报文,所述第一方式与所述第三应用响应网络标识关联;所述第一节点将所述第一报文转发至所述第二网络,在所述第二网络能够按照第二方式转发报文,所述第二方式与所述第一报文对应的第二应用响应网络标识关联;所述第一节点在所述第一网络内按照第三方式转发所述第一报文,所述第三方式与所述第一应用响应网络标识关联。
- 根据权利要求7所述的方法,其中,所述第一节点利用第四信息,将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第二应用响应网络标识,或者,将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第三应用响应网络标识,所述第四信息表征一个或多个第一网络关联的应用响应网络标识与第二网络关联的应用响应网络标识的对应关系。
- 根据权利要求8所述的方法,还包括:所述第一节点接收控制设备发送的所述第四信息;或者,所述第一节点通过路由学习,确定所述第四信息。
- 根据权利要求1至3任一项所述的方法,其中,所述对所述第一报文进行不与应用响应网络关联的转发相关处理,包括以下之一:所述第一节点将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第五信息,得到处理后的第一报文,并在所述第一网络内按第四方式转发所述处理后的第一报文,所述第四方式不与应用响应网络关联,所述第五信息表征所述第一报文禁用应用响应网络;所述第一节点将所述第一报文中携带所述第一应用响应网络标识的第一字段设置为第五信息,得到处理后的第一报文,并将所述处理后的第一报文转发至第二网络,所述第五信息表征所述第一报文禁用应用响应网络;所述第一节点丢弃所述第一报文。
- 一种报文处理装置,设置在第一节点,所述第一节点包括第一网络的边界节点,包括:接收单元,用于接收第一报文,所述第一报文包含第一应用响应网络标识;处理单元,用于在第一信息表征所述第一节点的第一接口可使用应用响应网络的情况下,在所述第一接口对所述第一报文进行与应用响应网络关联的转发相关处理,或者,在所述第一信息表征所述第一节点的第一接口禁用应用响应网络的情况下,在所述第一接口对所述第一报文进行不与应用响应网络关联的转发相关处理。
- 一种节点,所述节点包括第一网络的边界节点,包括:通信接口,用于接收第一报文,所述第一报文包含第一应用响应网络标识;处理器,用于在第一信息表征所述节点的第一接口可使用应用响应网络的情况下,在所述第一接口对所述第一报文进行与应用响应网络关联的转发相关处理,或者,在所述第一信息表征所述节点的第一接口禁用应用响应网络的情况下,在所述第一接口对所述第一报文进行不与应用响应网络关联的转发相关处理。
- 一种节点,包括:处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行权利要求1至10任一项所述方法的步骤。
- 一种存储介质,其上存储有计算机程序,其中,所述计算机程序被处理器执行时实现权利要求1至10任一项所述方法的步骤。
- 一种计算机程序产品,包括计算机程序,其中,所述计算机程序被处理器执行时实现权利要求1至10任一项所述方法的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202410773425.XA CN118803062B (zh) | 2024-06-14 | 2024-06-14 | 报文处理方法、装置、节点、存储介质及计算机程序产品 |
| CN202410773425.X | 2024-06-14 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025256325A1 true WO2025256325A1 (zh) | 2025-12-18 |
Family
ID=93019153
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2025/094715 Pending WO2025256325A1 (zh) | 2024-06-14 | 2025-05-14 | 报文处理方法、装置、节点、存储介质及计算机程序产品 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN118803062B (zh) |
| WO (1) | WO2025256325A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN118803062B (zh) * | 2024-06-14 | 2026-01-16 | 中国移动通信有限公司研究院 | 报文处理方法、装置、节点、存储介质及计算机程序产品 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112152971A (zh) * | 2019-06-28 | 2020-12-29 | 北京奇虎科技有限公司 | 控制网络使用行为的方法和装置、电子设备和介质 |
| US20220174009A1 (en) * | 2020-11-27 | 2022-06-02 | Huawei Technologies Co., Ltd. | Segment Routing-Based Data Transmission Method and Apparatus |
| CN115776459A (zh) * | 2021-09-06 | 2023-03-10 | 中兴通讯股份有限公司 | 报文处理方法、节点、网络、电子设备和存储介质 |
| WO2024012316A1 (zh) * | 2022-07-11 | 2024-01-18 | 中国移动通信有限公司研究院 | 报文处理方法、装置、网络节点及存储介质 |
| CN118803062A (zh) * | 2024-06-14 | 2024-10-18 | 中国移动通信有限公司研究院 | 报文处理方法、装置、节点、存储介质及计算机程序产品 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN114189905B (zh) * | 2020-09-15 | 2024-06-18 | 华为技术有限公司 | 一种报文处理方法及相关设备 |
| CN116366395A (zh) * | 2021-12-28 | 2023-06-30 | 中国移动通信有限公司研究院 | 一种报文传输的方法及装置 |
| CN117792999A (zh) * | 2022-09-29 | 2024-03-29 | 华为技术有限公司 | 一种报文处理方法、信息处理方法及装置 |
| CN117527681A (zh) * | 2023-10-13 | 2024-02-06 | 上海卫星互联网研究院有限公司 | 一种数据传输方法、装置、网络设备及存储介质 |
-
2024
- 2024-06-14 CN CN202410773425.XA patent/CN118803062B/zh active Active
-
2025
- 2025-05-14 WO PCT/CN2025/094715 patent/WO2025256325A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112152971A (zh) * | 2019-06-28 | 2020-12-29 | 北京奇虎科技有限公司 | 控制网络使用行为的方法和装置、电子设备和介质 |
| US20220174009A1 (en) * | 2020-11-27 | 2022-06-02 | Huawei Technologies Co., Ltd. | Segment Routing-Based Data Transmission Method and Apparatus |
| CN115776459A (zh) * | 2021-09-06 | 2023-03-10 | 中兴通讯股份有限公司 | 报文处理方法、节点、网络、电子设备和存储介质 |
| WO2024012316A1 (zh) * | 2022-07-11 | 2024-01-18 | 中国移动通信有限公司研究院 | 报文处理方法、装置、网络节点及存储介质 |
| CN118803062A (zh) * | 2024-06-14 | 2024-10-18 | 中国移动通信有限公司研究院 | 报文处理方法、装置、节点、存储介质及计算机程序产品 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN118803062A (zh) | 2024-10-18 |
| CN118803062B (zh) | 2026-01-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3759870B1 (en) | Network slicing with smart contracts | |
| US10848461B2 (en) | Unified security policies across virtual private clouds with overlapping IP address blocks | |
| CN109861926B (zh) | 报文的发送、处理方法、装置、节点、处理系统和介质 | |
| US11870641B2 (en) | Enabling enterprise segmentation with 5G slices in a service provider network | |
| US8689316B2 (en) | Routing a packet by a device | |
| WO2019105462A1 (zh) | 报文的发送、处理方法及装置,pe节点,节点 | |
| WO2015057404A1 (en) | Configurable service proxy mapping | |
| CN117501671A (zh) | 使用路由来源授权(ROA)进行边界网关协议(BGP)FlowSpec发起授权 | |
| US12114198B2 (en) | Prioritizing wireless access technologies in an enterprise fabric | |
| WO2025214307A9 (zh) | 一种通信方法及网络设备、存储介质、计算机程序产品 | |
| WO2025180331A1 (zh) | 信息处理方法、装置、设备、存储介质及计算机程序产品 | |
| WO2025256325A1 (zh) | 报文处理方法、装置、节点、存储介质及计算机程序产品 | |
| US9730074B2 (en) | System, methods and apparatuses for providing network access security control | |
| CN105591967B (zh) | 一种数据传输方法和装置 | |
| CN109495370B (zh) | 一种基于vpls的报文传输方法及装置 | |
| CN111464443B (zh) | 基于服务功能链的报文转发方法、装置、设备及存储介质 | |
| CN110602110A (zh) | 一种全网端口隔离方法、装置、设备及存储介质 | |
| CN114884667B (zh) | 一种通信鉴权方法、设备及存储介质 | |
| WO2024002101A1 (zh) | 报文传输方法、装置、相关设备及存储介质 | |
| CN117459476A (zh) | 网络连接方法、装置、设备及存储介质 | |
| CN109768929A (zh) | 一种基于vpws的报文传输方法及装置 | |
| CN102487386B (zh) | 身份位置分离网络的阻断方法和系统 | |
| CN108259292B (zh) | 建立隧道的方法及装置 | |
| US20240372806A1 (en) | Packet Sending Method, Packet Receiving Method, Information Sending Method, and Apparatus | |
| WO2023246501A1 (zh) | 报文校验方法、装置、相关设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 25821004 Country of ref document: EP Kind code of ref document: A1 |