WO2015100650A1 - 一种报文处理方法、装置及系统 - Google Patents

一种报文处理方法、装置及系统 Download PDF

Info

Publication number
WO2015100650A1
WO2015100650A1 PCT/CN2013/091187 CN2013091187W WO2015100650A1 WO 2015100650 A1 WO2015100650 A1 WO 2015100650A1 CN 2013091187 W CN2013091187 W CN 2013091187W WO 2015100650 A1 WO2015100650 A1 WO 2015100650A1
Authority
WO
WIPO (PCT)
Prior art keywords
processing
network element
data packet
indication
context
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2013/091187
Other languages
English (en)
French (fr)
Inventor
谭仕勇
倪慧
蔡慧
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN201910444551.XA priority Critical patent/CN110138618B/zh
Priority to PCT/CN2013/091187 priority patent/WO2015100650A1/zh
Priority to CN201380077723.5A priority patent/CN105340217B/zh
Priority to EP13900610.0A priority patent/EP3079301B1/en
Priority to RU2016131169A priority patent/RU2630178C1/ru
Publication of WO2015100650A1 publication Critical patent/WO2015100650A1/zh
Priority to US15/199,494 priority patent/US10412008B2/en
Anticipated expiration legal-status Critical
Priority to US16/526,518 priority patent/US20190356594A1/en
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0823Configuration setting characterised by the purposes of a change of settings, e.g. optimising configuration for enhancing reliability
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/24Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2483Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks

Definitions

  • the present invention relates to the field of communications, and in particular, to a packet processing method, apparatus, and system. Background technique
  • SDN Software-Defined Network
  • the SDN decouples the control logic and the forwarding function of the network element, and centrally deploys the control logic, so that the control and maintenance of the network can be easily realized by the operation of the control plane device, thereby improving the network management efficiency, and
  • the forwarding plane device is simplified, which is beneficial to the high performance and reusability of the forwarding device.
  • the current SDN concept is being widely applied to data center networks and telecommunication networks.
  • the prior art provides a method for implementing SDN control and forwarding decoupling.
  • the network is composed of a control plane and a forwarding plane device.
  • the control plane controls the forwarding plane device by sending the stream matching information and the corresponding context to implement the user datagram. The processing of the text.
  • the flow matching information is used to determine the service flow to which the message belongs, and the context represents a specific processing function.
  • Each service flow can correspond to or be associated with multiple contexts, and the contexts are independent of each other, so as to achieve relative independence between various types of processing of the stream-sized message, so that parallel processing and processing capability are extended.
  • the forwarding plane device since the forwarding plane device processes all the packets according to the context, the requirements for the forwarding plane device are high, and the load of the forwarding plane device is large, which is not conducive to the improvement of the overall performance of the network. Summary of the invention
  • the embodiment of the present invention provides a packet processing method, which relates to the field of communication, and can implement context processing on a packet by a distributed forwarding plane device, thereby improving load balancing of network packet context processing.
  • a message processing system including:
  • the ingress network element is configured to receive the data packet from the outside of the packet system, and send the data packet to the processing network element according to the ingress flow entry;
  • the ingress flow entry includes the flow description information and the processing network element indication.
  • the processing network element is configured to receive the data packet from the ingress network element, and perform context processing on the data packet according to a context processing indication;
  • the context processing indication is used to indicate a context processing performed on the data packet.
  • the ingress flow entry further includes an encapsulation flow identifier, where the encapsulation flow identifier is used to identify a service flow to which the data packet belongs;
  • the ingress network element is further configured to: add the encapsulated flow identifier to the data packet; the processing network element is configured to obtain the encapsulated flow identifier from the data packet, and obtain the identifier according to the encapsulated flow identifier. Processing a flow entry, and performing context processing on the data packet according to the processing flow entry;
  • the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the ingress flow entry further includes an ingress encapsulation indication, where the ingress encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the Data message;
  • the ingress network element is specifically configured to attach the encapsulated flow identifier to the data packet according to the ingress encapsulation indication.
  • the flow identifier is attached to the processed data packet, where the flow identifier is the encapsulated flow identifier, or when the processing flow entry further includes a new encapsulated flow identifier, The flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes processing a package indication, where the processing encapsulate indication is used to indicate that the flow identifier is attached to the processed Data message;
  • the processing network element is further configured to attach the flow identifier to the processed data packet according to the processing encapsulation indication.
  • the processing network element is further configured to send the processed data packet to the outside of the packet processing system; or when the processing flow entry is The processing network element is further configured to: send the processed data packet to the next processing network element according to the reprocessing network element indication according to the reprocessing network element indication;
  • the reprocessing network element indicates a processing network element for indicating the next processing of the data packet after the processing network element.
  • the ingress flow entry and the processing flow entry are locally configured or sent by a control network element, where the control network element is configured to control the ingress network element and the processing network element to the data Forward or process the message.
  • the processing network element indication includes a context processing indication list, and the context processing indication list includes the context processing indication;
  • the ingress network element is specifically configured to attach the context processing indication list to the data packet, and determine that the next context processing performed on the data packet is the foregoing
  • the processing of the indication indicates the context processing, and sending the data packet to the processing network element according to the correspondence between the context processing indication and the processing network element;
  • the processing network element is specifically configured to obtain the context processing indication list from the data packet, and perform context processing on the data packet according to the context processing indication.
  • the context processing indication list further includes addressing information of the processing network element, where the context processing indication is related to the processing network element Address information corresponding;
  • the ingress network element is specifically configured to send the data packet to the processing network element according to the addressing information of the processing network element corresponding to the context processing indication.
  • processing network element is further configured to send the processed data packet to the outside of the packet processing system when the context processing indication list does not include another context processing indication;
  • the processing network element is further configured to determine that the next context processing performed on the data packet is the context processing indicated by the other context processing indication After the processing network element performs the context processing on the data packet, sending the processed data packet to the other processing network element according to the correspondence between the other context processing indication and the other processing network element. ;
  • the other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element, where the other context processing indication is related to the other processing network The addressing information of the element corresponds to;
  • the processing network element is specifically configured to send the processed data packet to the other processing network element according to the addressing information of the other processing network element corresponding to the other context processing instruction.
  • the ingress flow entry is locally configured or sent by a control network element.
  • the control network element is configured to control forwarding of the data packet by the ingress network element.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication is used to indicate context processing performed on the data packet;
  • the ingress network element is further configured to perform context processing on the data packet according to the ingress context processing indication.
  • an entry network element including:
  • a receiving unit configured to receive a data message
  • a sending unit configured to send, according to the ingress flow entry, the data packet received by the receiving unit to the processing network element, so that the processing network element performs a context processing on the data packet;
  • the ingress flow entry includes flow description information and a processing network element indication, the flow description information is matched with the data packet, and the processing network element indication is used to indicate the next one after the entry network element. Processing the network element of the data packet.
  • the ingress flow entry further includes an encapsulation flow identifier, where the encapsulation flow identifier is used to identify a service flow to which the data packet belongs;
  • the ingress network element further includes a flow identifier encapsulating unit, configured to attach the encapsulation flow identifier to the data packet, so that the processing network element obtains the encapsulation flow identifier from the data packet, according to the The encapsulated flow identifier acquires a processing flow entry, and performs context processing on the data packet according to the processing flow entry.
  • a flow identifier encapsulating unit configured to attach the encapsulation flow identifier to the data packet, so that the processing network element obtains the encapsulation flow identifier from the data packet, according to the The encapsulated flow identifier acquires a processing flow entry, and performs context processing on the data packet according to the processing flow entry.
  • the ingress flow entry further includes an ingress encapsulation indication, where the ingress encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the data Message
  • the flow identifier encapsulating unit is specifically configured to attach the package flow identifier to the data packet according to the ingress encapsulation indication.
  • the ingress flow entry is locally configured or sent by the control network element.
  • the control network element is configured to control forwarding or processing of the data packet by the ingress network element.
  • the processing network element indication includes a context processing indication list, and the context processing indication list includes the context processing indication;
  • the ingress network element further includes a processing indication adding unit, configured to attach the context processing indication list to the data packet;
  • the sending unit is specifically configured to determine that the next context processing performed on the data packet is the context processing indicated by the context processing indication, and according to the corresponding relationship between the context processing indication and the processing network element, The data message is sent to the processing network element.
  • the context processing indication list further includes addressing information of the processing network element, where the context processing indication is related to the processing network element Address information corresponding;
  • the sending unit is configured to send the data packet to the processing network element according to the addressing information of the processing network element corresponding to the context processing indication.
  • the ingress flow entry is locally configured or sent by a control network element; where the control network element is used Controlling, by the ingress network element, forwarding of the data packet.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication is used to indicate context processing performed on the data packet; the ingress network element further includes: a processing unit;
  • the processing unit is configured to process the data according to the ingress context processing indication
  • a processing network element including: The receiving unit is configured to receive a data message;
  • the processing unit is configured to perform context processing on the data packet received by the receiving unit according to the context processing indication
  • the context processing indication is used to indicate a context processing performed on the data packet.
  • the processing unit is configured to obtain an encapsulated flow identifier from the data packet, and obtain a processing flow entry according to the encapsulated flow identifier, according to the processing flow.
  • An entry performing context processing on the data packet;
  • the encapsulated flow identifier is used to identify the service flow to which the data packet belongs, and the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the unit is further configured to attach the flow identifier to the processed data packet, where the flow identifier is the encapsulated flow identifier, or When the processing flow entry further includes a new encapsulated flow identifier, the flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes: processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed Data message;
  • the processing unit is specifically configured to add the flow identifier to the processed data packet according to the processing encapsulation indication.
  • the processing network element further includes: a sending unit; when the processing flow entry is not The transmitting unit sends the data packet processed by the processing unit to the outside when the re-processing network element indication is included; or
  • the sending unit sends the data processed by the processing unit to the next processing network according to the reprocessing network element indication.
  • the reprocessing network element indicates a processing network element for indicating the next processing of the data packet after the processing network element.
  • the processing flow entry is locally configured or sent by the control network element.
  • the control network element is configured to control forwarding or processing of the data packet by the processing network element.
  • the processing unit is specifically configured to obtain a context processing indication list from the data packet, where the context processing indication list includes the context processing indication, according to the Context processing indicates context processing on the data message, the context processing indication list including the context processing indication.
  • the processing network element further includes: a sending unit;
  • the sending unit sends the data message processed by the processing unit to the outside;
  • the sending unit determines that the next context processing performed on the data packet is the context processing indicated by the other context processing indication, After performing the context processing on the data packet, the processing unit sends the data processed by the processing unit to the other processing network element according to the correspondence between the other context processing indication and the other processing network element. ;
  • the other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element, where the other context processing indication is related to the other processing network The addressing information of the element corresponds to;
  • the sending unit is specifically configured to process the corresponding location according to the other context processing
  • the addressing information of the other processing network element is sent to the other processing network element after the data processed by the processing unit is sent.
  • the fourth aspect provides a packet processing method, including:
  • the ingress network element receives the data packet, where the ingress network element stores an ingress flow entry, the ingress flow entry includes flow description information and a processing network element indication, and the flow description information matches the data packet
  • the processing network element indicates a processing network element for indicating the next processing of the data packet after the ingress network element;
  • the ingress network element sends the data packet to the processing network element according to the ingress flow entry, so that the processing network element performs context processing on the data packet.
  • the ingress flow entry further includes an encapsulation flow identifier, where the encapsulation flow identifier is used to identify a service flow to which the data packet belongs; the method further includes:
  • the ingress network element adds the encapsulated flow identifier to the data packet, so that the processing network element obtains the encapsulated flow identifier from the data packet, and obtains a processing flow entry according to the encapsulated flow identifier. And performing context processing on the data packet according to the processing flow entry.
  • the ingress flow entry further includes an ingress encapsulation indication, where the ingress encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the data
  • the packet includes: the ingress network element attaching the encapsulated flow identifier to the data packet:
  • the ingress network element attaches the encapsulated flow identifier to the data packet according to the ingress encapsulation indication.
  • the ingress flow entry is locally configured or sent by the control network element.
  • the control network element is configured to control forwarding or processing of the data packet by the ingress network element.
  • the processing network element indication includes a context processing indication list, where the context processing indication list includes the context processing indication;
  • the method further includes: the ingress network element attaching the context processing indication list to the data message;
  • Sending, by the ingress network element, the data packet to the processing network element according to the ingress flow entry includes:
  • the ingress network element determines that the next context processing performed on the data packet is the context processing indicated by the context processing indication, and sends the data according to the correspondence between the context processing indication and the processing network element. The message is sent to the processing network element.
  • the context processing indication list further includes addressing information of the processing network element, where the context processing indication is related to the processing network element Address information corresponding;
  • sending, according to the correspondence between the context processing indication and the processing network element, sending the data packet to the processing network element includes:
  • the ingress network element sends the data packet to the processing network element according to the addressing information of the processing network element corresponding to the context processing indication.
  • the ingress flow entry is locally configured or sent by a control network element; where the control network element is used Controlling, by the ingress network element, forwarding of the data packet.
  • the ingress flow entry further includes an ingress context processing indication, where the ingress context processing indication is used to indicate context processing on the data packet; the method further includes:
  • the ingress network element performs context processing on the data packet according to the ingress context processing indication.
  • the fifth aspect provides a packet processing method, including:
  • the performing context processing on the data packet according to the context processing indication includes:
  • the encapsulated flow identifier is used to identify the service flow to which the data packet belongs, and the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the method further includes: adding, by the network element, the flow identifier to the processed data packet; where the flow identifier is the package The flow identifier, or when the processing flow entry further includes a new encapsulated flow identifier, the flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes: processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed
  • the method further includes: the processing network element appending the flow identifier to the processed data packet according to the processing encapsulation indication.
  • the method further includes:
  • the processing network element sends the processed data packet to the outside;
  • the processing network element sends the processed data packet to the next processing network element according to the reprocessing network element indication;
  • the reprocessing network element indicates a processing network element for indicating the next processing of the data packet after the processing network element.
  • the processing flow entry is locally configured or sent by a control network element.
  • the control network element is configured to control forwarding or processing of the data packet by the processing network element.
  • the performing context processing on the data packet according to the context processing indication includes:
  • the processing network element obtains a context processing indication list from the data packet, where the context processing indication list includes the context processing indication, and performs context processing on the data packet according to the context processing indication.
  • the method further includes:
  • the processing network element sends the processed data packet outward;
  • the processing network element determines that the next context processing performed on the data packet is the context processing indicated by the other context processing indication, After the processing network element performs the context processing on the data packet, the processed data packet is sent to the other processing network element according to the correspondence between the other context processing indication and the other processing network element;
  • the other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element, where the other context processing indication is related to the other processing network
  • the addressing information of the meta-corresponding information; the sending the processed data packet to the other processing network element includes: The processing network element sends the processed data packet to the other processing network element according to the addressing information of the other processing network element corresponding to the other context processing.
  • the packet processing method, device, and system provided by the foregoing technical solution can perform context processing on the packet by the distributed forwarding device, and then improve the network packet by forwarding the packet to different network elements for context processing. Load balancing of context processing.
  • FIG. 1 is a schematic structural diagram of a communication system according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of a packet processing method according to an embodiment of the present invention
  • FIG. 3 is a schematic flowchart of another packet processing method according to an embodiment of the present invention
  • FIG. 5 is a schematic flowchart of a packet processing method according to another embodiment of the present invention
  • FIG. 6 is a schematic flowchart of a packet processing method according to still another embodiment of the present invention
  • FIG. 7 is a schematic flowchart of a packet processing method according to another embodiment of the present invention
  • FIG. 8 is a schematic flowchart of a packet processing method according to another embodiment of the present invention
  • FIG. 9 is a schematic flowchart of a packet processing method according to another embodiment of the present invention
  • FIG. 10 is a schematic flowchart of a packet processing method according to another embodiment of the present invention.
  • FIG. 1 is a schematic flow chart of a packet processing method according to still another embodiment of the present invention.
  • FIG. 1 is a schematic structural diagram of an ingress network element according to an embodiment of the present invention
  • FIG. 1 is a schematic structural diagram of a processing network element according to an embodiment of the present invention
  • FIG. 15 is a schematic structural diagram of a processing network element according to another embodiment of the present invention.
  • SDN Software-Defined Network
  • the method includes: an ingress network element 1 and at least one processing network element (2- l ⁇ 2-k).
  • the ingress network element 1 is configured to receive a data packet from the outside of the packet system, and send the data packet to the processing network element 2-1 according to the ingress flow entry (of course, the processing network element herein may be any one, Here, taking 2-1 as an example); the ingress flow entry includes flow description information and a processing network element indication, the flow description information is matched with the data packet, and the processing network element indication is used to indicate The next processing element after the entry network element 1 processes the network element 2-1.
  • the processing network element 2-1 is configured to receive the data packet from the ingress network element 1, and perform context processing on the data packet according to a context processing indication.
  • the context processing indication is used to indicate a context processing performed on the data packet.
  • the packet processing system provided by the embodiment of the present invention can perform context processing on the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the context processing of the network packet. Load balancing.
  • the ingress flow entry further includes an encapsulated flow identifier, where the encapsulated flow identifier is used to identify a service flow to which the data packet belongs;
  • the ingress network element 1 is further configured to: add the encapsulated flow identifier to the data packet; the processing network element 2-1 is configured to obtain the encapsulated flow identifier from the data packet, and obtain the identifier according to the encapsulated flow identifier. Processing a flow entry, and performing context processing on the data packet according to the processing flow entry;
  • the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the ingress flow entry further includes an ingress encapsulation indication; where The port encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the data packet.
  • the ingress network element 1 is specifically configured to attach the encapsulation flow identifier to the datagram according to the ingress encapsulation indication. Text.
  • the processing network element 2 - 1 is further configured to: when the processed data packet does not include the encapsulated flow identifier, attach the flow identifier to the processed data packet;
  • the flow identifier is the encapsulated flow identifier, or when the processing flow entry further includes a new encapsulated flow identifier, the flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes: processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed data packet;
  • the processing network element 2 - 1 is further configured to attach the flow identifier to the processed data packet according to the processing encapsulation indication.
  • the processing network element 1-1 is further configured to send the processed data packet to the outside of the packet processing system;
  • processing network element 2-1 is further configured to send the processed data packet to the next one according to the reprocessing network element indication.
  • Processing network element 2 - 2 is further configured to send the processed data packet to the next one according to the reprocessing network element indication.
  • the reprocessing network element indication is used to indicate a processing network element that processes the data message after the processing network element 2-1.
  • the system further includes a control network element 3, where the ingress flow entry and the processing flow entry are locally configured or sent by the control network element 3, where the control network element 3 is used to control The ingress network element 1 and the processing network element 2-1 forward or process the data packet.
  • the processing network element indication includes a context processing indication list, where the context processing indication list includes the context processing indication;
  • the ingress network element 1 is specifically configured to add the context processing indication list to the data packet, and determine that the next context processing performed on the data packet is the context indicated by the context processing indication. Processing, according to the context Corresponding relationship between the processing indication and the processing network element 2-1, sending the data packet to the processing network element 2-1;
  • the processing network element 2-1 is specifically configured to obtain the context processing indication list from the data packet, and perform context processing on the data packet according to the context processing indication.
  • the context processing indication list further includes addressing information of the processing network element 2-1, where the context processing indication corresponds to addressing information of the processing network element 2-1;
  • the ingress network element 1 is specifically configured to send the data packet to the processing network element 2-1 according to the addressing information of the processing network element 2-1 corresponding to the context processing indication. .
  • the processing network element 2-1 is further configured to send the processed data packet to the outside of the processing system; or ,
  • the processing network element 2-1 is further configured to determine that the next context processing performed on the data packet is indicated by the other context processing indication Context processing, after the processing network element performs context processing on the data packet, sending the processed data packet to the other according to the correspondence between the other context processing indication and other processing network elements Processing network element 2-2;
  • the other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element 2-2, where the other context processing indication corresponds to the addressing information of the other processing network element 2-2;
  • the processing network element 2-1 is specifically configured to: according to the addressing information of the other processing network element 2-2 corresponding to the other context processing instruction, send the processed data packet to the Other processing network element 2-2.
  • the ingress flow entry is locally configured or is sent by the control NE 2
  • the control network element 2 is configured to control forwarding of the data packet by the ingress network element.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication is used to indicate context processing performed on the data packet;
  • the ingress network element 1 is further configured to perform context processing on the data packet according to the ingress context processing indication.
  • the packet processing system provided by the embodiment of the present invention can perform context processing on the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the context processing of the network packet.
  • An embodiment of the present invention provides a packet processing method, which is implemented by the foregoing packet processing system. As shown in FIG. 2, the following steps are included on the ingress network element side:
  • the ingress network element receives the data packet, where the ingress network element receives the data packet from the outside of the packet system, where the ingress network element stores the ingress flow entry, and the ingress flow entry includes the flow.
  • the description information and the processing network element indicate that the flow description information is matched with the data packet, and the processing network element indicates a processing network element for indicating the next processing of the data packet after the ingress network element ;
  • the ingress network element sends the data packet to the processing network element according to the ingress flow entry, so that the processing network element performs context processing on the data packet.
  • the flow description information may be information including a packet feature. When the data packet meets the packet feature information included in the flow description information, the data packet is considered to match the flow description information.
  • the flow description information may include: MAC (Media Access Control) address, destination MAC address, source IP (Internet Protocol) address, destination IP address, source port number, destination port number, MPLS Label ( Mul t i-protocol label switching Label , ToS ( ty e of service tag type), ToS ( ty e of service, service type), IPv6 flow lable (Internet Protocol Vers ion 6 flow lable, Internet Protocol version 6 stream identification), GRE a combination of one or more message feature fields, such as a key (generic route encapsulation key), a GTP TE ID (GPRS Tunneling Protocol Tunnel End Point ID), It is used to determine whether the message belongs to the service flow of this processing.
  • An embodiment of the present invention provides another packet processing method, which is implemented by the foregoing packet processing system. Referring to FIG. 3, the processing network element side includes the following steps:
  • the processing network element receives the data packet.
  • the processing network element performs context processing on the data packet according to a context processing indication, where the context processing indication is used to indicate a context processing performed on the data packet.
  • the packet processing method provided by the embodiment of the present invention can perform context processing on the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the context processing of the network packet. Load balancing. Specifically, as shown in FIG. 4, a packet processing method provided by an embodiment of the present invention is implemented by the foregoing packet processing system, and includes the following steps:
  • the ingress flow entry sent by the ingress network element or received by the control network element.
  • the control network element is configured to control the forwarding or processing of the data packet by the ingress network element and the processing network element.
  • the entry flow entry includes: flow description information, a processing network element indication, an encapsulated flow identifier, and a package indication.
  • the flow description information is matched with the data packet, and the processing network element indicates a processing network element for indicating the next processed data message after the entry network element.
  • the flow description information may include: a source MAC (Media Access Control) address, a destination MAC address, a source IP (Internet Protocol) address, a destination IP address, a source port number, a destination port number, and an MPLS Label.
  • the ingress network element receives the data from the outside of the system. In the step 302, the ingress network element only has the function of transmitting and receiving data packets, and the function is that the ingress network element and the processing network element are separately deployed.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication
  • the method further includes: the ingress network element performs context processing on the data packet according to the ingress context processing indication.
  • the ingress network element includes the context processing capability of the packet, that is, the inbound network element and the processing network element are deployed in a unified manner, and the ingress network element function includes a function of processing the network element.
  • the ingress network element attaches the encapsulated flow identifier to the data packet according to the ingress encapsulation indication.
  • the encapsulation index according to the ingress encapsulation indication in the present invention will require additional information, such as an encapsulation flow identifier, to be added to the packet, and the encapsulation flow identifier is used to identify the service flow to which the data packet belongs.
  • the specific encapsulation method can be used, such as GRE (generic route encapsulation), GTP (GPRS Tunnelling Protocol), VLAN (Virtual Local Area Network), MPLS (VLAN).
  • the protocol encapsulation method such as Mul t i-Pro toco 1 Label Swi tching, or other standard or custom format, is not limited by the present invention.
  • the ingress network element sends data according to the ingress flow entry to the processing network element.
  • the processing network element indicates the processing network element for indicating the next processing data packet after the ingress network element, and therefore the specific network element includes the ingress network element sending the data packet to the processing network element according to the processing network element indication.
  • the processing network element indicates that the forwarding information may be processed for processing a MAC address, an IP address, a domain name, or a custom identifier of the network element.
  • the processing network element receives the data packet from the ingress network element, obtains the encapsulated flow identifier from the data packet, obtains the processing flow entry according to the encapsulated flow identifier, and performs context processing on the data according to the processing flow entry.
  • the processing flow entry includes a matching flow identifier and a context processing indication, and the matching flow identifier matches the encapsulated flow identifier.
  • the method further includes: when the processed data packet does not include the encapsulated flow identifier, attaching the flow identifier to the processed data packet; wherein the flow identifier is an encapsulated flow identifier, or when the flow table is processed When the entry also includes a new encapsulated flow identifier, the flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed data packet; and the processed data packet encapsulation process is specifically processing the network element according to the processing The encapsulation indication appends the flow identifier to the processed data message.
  • the processing network element sends the processed data packet outward; or, when the processing flow entry further includes the re-processing network element indication, the processing network element is further processed according to the The processing network element indicates that the processed data packet is sent to the next processing network element.
  • the reprocessing network element indicates a processing network element for indicating the next processing data message after processing the network element.
  • step 305 the process of encapsulating the processed data packet is processed by the processing network element. Therefore, in step 306, the processing of the data packet sent by the network element to the outside of the packet processing system or the processing of the network element is performed.
  • the processing network element indicates that the processed data packet is sent to the next processing network element, and the processed data packet is appended with the flow identifier.
  • the packet processing method provided by the embodiment of the present invention can perform context processing on the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the context processing of the network packet. Load balancing.
  • a packet processing method is implemented by the foregoing packet processing system, and includes the following steps:
  • the ingress network element is configured locally or receives the ingress flow entry sent by the control NE.
  • the control network element is configured to control the ingress network element and the processing network element to the data packet. Forwarding or processing.
  • the entry flow entry includes: flow description information, and processing network element indication.
  • the flow description information is matched with the data packet, and the processing network element indicates a processing network element for indicating the next processed data message after the entry network element.
  • the flow description information may include: a source MAC (Media Access Control) address, a destination MAC address, a source IP (Internet Protocol) address, a destination IP address, a source port number, a destination port number, and an MPLS Label.
  • the processing network element indication includes a context processing indication list, and the context processing indication list includes a context processing indication. 402.
  • the ingress network element receives the data.
  • the ingress network element only has the function of transmitting and receiving data packets, and the function is that the ingress network element and the processing network element are separately deployed.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication
  • the method further includes: the ingress network element performs context processing on the data packet according to the ingress context processing indication.
  • the ingress network element includes the context processing capability of the packet, that is, the inbound network element and the processing network element are deployed in a unified manner, and the ingress network element function includes a function of processing the network element.
  • the ingress network element adds a context processing indication list to the data packet, and determines that the next context processing performed on the data packet is the context processing indicated by the context processing indication, and sends the information according to the context processing indication and the processing network element. Data is processed to the network element.
  • the context processing indication list further includes processing addressing information of the network element, where the context processing indication corresponds to the addressing information of the processing network element.
  • sending the data packet to the processing network element is specifically: the ingress network element sends the data packet to the processing according to the addressing information of the processing network element corresponding to the context processing indication.
  • the processing network element receives the data packet from the ingress network element, obtains a context processing indication list from the data packet, and performs context processing on the data packet according to the context processing indication.
  • the processing network element sends the processed data packet outward.
  • the processing network element determines that the next context processing performed on the data packet is the context processing indicated by the other context processing indication, and the processing network element performs context on the data packet. After the processing, the processed data packet is sent to other processing network elements according to the correspondence between the other context processing instructions and other processing network elements.
  • context processing indicates context processing on the data message.
  • the context processing indication list further includes addressing information of other processing network elements, and other context processing indications correspond to addressing information of the other processing network elements.
  • step 406 according to the correspondence between the other context processing indications and the other processing network elements, the processing of the processed data packets to the other processing network elements is specifically, and the processing network elements are addressed according to other processing network elements corresponding to other context processing instructions.
  • the information is sent to the other processing network element.
  • the packet processing method provided by the embodiment of the present invention can perform context processing on the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the context processing of the network packet. Load balancing.
  • the ingress network element and the processing network element are separately deployed (that is, the ingress network element does not include the context processing capability of the authentication element).
  • the entry network element and the three processing networks are used as follows.
  • the processing of the element is taken as an example, in which the ingress network element completes the flow matching, and the three processing network elements perform the virus firewall, DPI (Deep Packet Inspection) deep analysis and QoS (Quality of Service). , quality of service) control functions, including the following steps:
  • the control network element sends the ingress flow entry to the forwarding surface entry NE through the flow entry installation message.
  • the ingress flow entry is composed of the flow description information, the encapsulation flow identifier FID1, and the processing network element indication, where the processing network element indicates that the forwarding information FWD infol is taken as an example.
  • the flow description information in this embodiment is described by taking a flow matching rule ( ⁇ ow match rule) as an example.
  • the ingress flow entry is sent by the control network element.
  • the ingress flow entry can also be configured locally.
  • the flow matching rule can use one or more packet characteristics such as the source and destination MAC addresses, the source and destination IP addresses, the source and destination port numbers, the MPLS Label, the ToS, the IPv6 flow lable, the GRE key, and the GTP TE ID.
  • the forwarding information includes information for determining a processing network element to be forwarded, such as processing a MAC address, an IP address, a domain name, or a custom identifier of the network element. Take the following entry flow entry as an example:
  • the control network element sends the processing flow entry to the one or more forwarding plane processing network elements by processing the flow entry installation message.
  • the control network element sends the processing flow entry as an example.
  • the processing flow entry can also be configured locally.
  • the processing flow entry includes a matching flow identifier and a context processing indication.
  • the processing flow entry further includes the encapsulated flow identifier and the forwarding information, where the forwarding information is Reprocess the network element indication.
  • the processing flow entry sent to processing NE 1 is as follows:
  • the ingress network element After the data packet arrives at the ingress network element, the ingress network element matches the data packet with the flow matching rule of each ingress flow entry. According to the entry that matches the data The flow entry, the ingress network element attaches the corresponding encapsulated flow identifier to the data packet.
  • the suffix can be implemented in a plurality of manners, for example, the MPLS label, the GRE key, the GTP TEID, and the like, and the corresponding protocol encapsulation is performed on the packet, which is not limited by the present invention.
  • the MPLS label is used as an example.
  • the ingress NE performs MPLS encapsulation on the data and adds the MPLS packet header with the label FID1.
  • the ingress network element sends the encapsulated packet to the processing network element 1 whose IP address is ipl for context processing according to the forwarding information.
  • the ingress flow entry may further include an encapsulation indication.
  • the ingress network element specifically attaches the encapsulation flow identifier to the data packet according to the ingress encapsulation indication.
  • the processing network element 1 searches for a processing flow entry with the same matching flow identifier according to the encapsulated flow identifier of the data packet (in this example, MPLS lable).
  • the local context processing corresponding to CID1 is performed on the MPLS-encapsulated data packet according to the content of the processing flow entry. For example, if the context processing instruction corresponding to CID1 is to perform Trojan virus filtering, the processing network element 1 performs 4 ⁇ text execution. Trojan virus detection and filtering capabilities.
  • the FID2 is configured as an MPLS label to perform MPLS encapsulation on the packet, and the encapsulated packet is sent to the processing network element 1 whose IP address is ip2 for context processing according to the forwarding information.
  • the context indication may also include multiple context processing.
  • the processing network element 2 searches for the processing flow entry corresponding to the FID2 according to the encapsulated flow identifier of the data packet, and performs local context processing corresponding to the CID3 according to the content of the processing flow entry, for example, the context processing corresponding to the CID3. If the P2P deep packet parsing is performed, the processing network element 2 performs P2P service identification on the packet, and optionally adds the P2P service identification result to the packet in the form of metadata. The processing network element 1 sends the packet to the processing network element 3 whose IP address is ip3 according to the forwarding information to perform the next context processing.
  • the processing network element 3 searches for the processing flow entry corresponding to the FID3 according to the encapsulated flow identifier of the data packet, and performs local context processing corresponding to CID1 and CID4 for the MPLS encapsulated packet according to the processing flow entry corresponding to the FID3.
  • CID1 corresponds to the maximum bandwidth of 2Mbps control
  • CID4 corresponds to the highest priority forwarding.
  • the processing flow entry does not carry the forwarding information and the encapsulation flow identifier. Therefore, the processing network element 3 directly forwards the processed packet to the external network according to the normal layer 2 layer 3 rule. It should be noted that the specific content may change after the data packet of FIG. 6 is processed by the context of different processing network elements.
  • the control network element can control the forwarding of the information, so that the same processing NE can appear multiple times during the processing and each time is different.
  • the message can implement different context processing procedures, which are not limited by the present invention.
  • the forwarding plane network element jointly completes various processing specified by the control network element for the service flow.
  • the packet By importing the flow identifier, the packet only needs to perform a packet matching on the ingress network element.
  • the subsequent processing network element can obtain the flow information to which the packet belongs.
  • the metadata enables the processing network elements of each distributed deployment to share the processing specific Information.
  • the ingress network element includes a context processing function (that is, the inbound network element and the processing network element are deployed in a unified manner).
  • a context processing function that is, the inbound network element and the processing network element are deployed in a unified manner.
  • the example uses the ingress network element and the two processing network elements as an example.
  • the ingress network element performs flow matching and admission control, and the two processing network elements respectively perform QoS control function and charging function on the packet, including the following steps:
  • the control network element sends the ingress flow entry to the ingress surface entry NE through the ingress flow entry installation message.
  • the ingress flow entry is sent by the control network element.
  • the ingress flow entry can also be configured locally.
  • the ingress flow entry is composed of the flow description information, the ingress context processing indication, the encapsulation flow identifier FID1, and the processing network element indication, wherein the processing network element indicates that the forwarding information FWD infol is taken as an example.
  • the flow description information is a flow matching rule ( Ow match rule) is an example.
  • the ingress flow entry is sent by the control network element as an example.
  • the ingress flow entry may also be configured locally.
  • the ingress context processing indicates that the ingress context processing indication may be the ingress network element local context processing list Local CID list1, which includes multiple context processing.
  • the flow matching rule is as described in the foregoing embodiment, and may be combined with a packet feature field (such as an IP quintuple, a GTP TEID, etc.) to determine whether the packet belongs to the service flow.
  • the forwarding information includes information for determining the next network element, such as a MAC address, an IP address, a domain name, or a custom identifier of the network element. This example takes the following entry flow entry as an example:
  • the control network element sends the processing flow entry to the two forwarding plane processing network elements for processing the service flow by processing the flow entry installation message.
  • the control network element sends the processing flow entry as an example.
  • the processing flow entry can also be configured locally.
  • the processing flow entry is indicated by the matching flow identifier and the context processing.
  • the processing flow entry further includes the encapsulated flow identifier and the forwarding information, where the forwarding information is Reprocess the network element indication.
  • the processing flow entry sent to processing NE 1 is as follows:
  • ⁇ Flow entry> : ⁇ FID2, [CID 2, CID 3], NO-FID ⁇
  • N0-FID is used as the processing encapsulation indication, and is used to process the indication processing network element 1 without continuing to perform flow identification encapsulation on the data message.
  • the processing of the encapsulation indication may also be represented by using a specific FID value or not carrying the FID field, which is not limited by the present invention.
  • the ingress network element After the data packet arrives at the ingress network element, the ingress network element performs flow entry matching.
  • the inbound flow entry contains a local context processing list. Therefore, the ingress network element needs to perform the flow table according to the ingress flow entry matched by the data packet.
  • the context processing corresponding to the item's local context list For example, if the context corresponding to the CID2 of the ingress network element is to perform user IP admission control on the data, the ingress network element determines whether the packet is permitted to pass according to the source and destination IP addresses of the data packet. For the data packet processed by the context, the ingress network element attaches the corresponding encapsulated flow identifier to the data packet.
  • the GTP protocol encapsulation is used as an example.
  • the ingress NE performs GTP loading on the data, and the TEID (Tunnel Endpoint ID) is the GTP-U header of FID1.
  • the ingress network element sends the encapsulated data packet to the processing network element 1 with the network element identifier id1 for context processing according to the forwarding information.
  • the network element address corresponding to the network element identifier can be obtained by the local network element or the DNS (Domain Name System). 604.
  • the processing network element 1 searches for the FID1 corresponding according to the encapsulated flow identifier of the data packet.
  • the local context processing corresponding to CID1 and CID4 is performed on the data after the GTP encapsulation is released, for example, CID1 corresponds to the maximum bandwidth 2 Mbps control, and CID4 corresponds to the highest priority forwarding.
  • the processing NE 1 performs GTP encapsulation on the user, and adds a GTP-U packet header with the TEID FID2.
  • the processing network element 1 sends the encapsulated data packet to the processing network element 2 with the network element identifier i d2 for context processing according to the forwarding information.
  • the processing network element 2 searches for the processing flow entry corresponding to the FID2 according to the encapsulated flow identifier of the data packet, and performs the local context corresponding to the CID2 and the CID3 for releasing the GTP encapsulated data packet according to the processing flow entry corresponding to the FID2. Processing, such as CID2 corresponding to online charging, CID3 corresponding to offline CDR generation. After the two accounting contexts are processed, the processing packet of the flow entry is forwarded to the external network, and the processing flow entry does not include the reprocessing network. Yuan indication.
  • the embodiment of the present invention further provides an implementation manner of an openflow (open flow, referred to as OF) protocol, which implements an extension of the openfl ow protocol to control an entry flow entry of the network element to each forwarder and processing thereof.
  • OF open flow
  • the processing of the flow entry in this case, under the openf 1 ow protocol, the control network element in the above embodiment is replaced by the 0F control network element, and the function of the above-mentioned entry network element and the processing network element is implemented by the 0F forwarder, referring to FIG. 8
  • the specific process is as follows:
  • the 701, 0F control network element sends the ingress flow entry to the 0F forwarder 1 through the Flow_mod message.
  • the flow_mod message sent to the 0F repeater 1 is the same as the ingress flow entry, and is composed of the flow description information, the encapsulated flow identifier FID1, and the processing network element indication.
  • the processing network element indicates that the forwarding information FWD infol is taken as an example. The information is described in the column "flow match rule". Referring to the foregoing implementation, in the embodiment, the function of processing the network element or the ingress network element is implemented by using the forwarder, and the corresponding processing network element is used to indicate the next one after the OFDM repeater 1 in this embodiment.
  • An OFDM repeater that processes the data packet, where the IF control network element sends the ingress flow entry in the 701.
  • the ingress flow entry may also be configured locally.
  • the flow matching information is as described in the foregoing embodiment, and may be combined with a feature field (such as an IP quintuple, a GTP TEID, etc.) to determine whether the packet belongs to the service flow.
  • the encapsulated flow identifier FID1 is provided as a parameter of the Push_Tag action, and the forwarding information is forwarded. Provided as a parameter to the Output action.
  • This example takes the following flow entry as an example:
  • the OF control network element sends the processing flow entry to the two 0F forwarders used to process the service flow by using a Flow_mod message.
  • the process of sending a processing flow entry by using the 0F control network element in the step 702 is taken as an example.
  • the Flow_mod message sent to other OFDM repeaters other than the 0F repeater 1 is the same as the processing flow entry, including the matching flow identifier and the context processing indication.
  • the Flow-mod message in the context processing also includes the encapsulation flow identifier and the forwarding information, where the forwarding information is an indication of the reprocessing network element.
  • the flow entry sent to the 0F forwarder 1 is as follows:
  • Push_Tag/Pop_Tag indicates encapsulation and decapsulation of the message.
  • the MPLS label is used as the MPLS label to encapsulate the FID as an MPLS label.
  • the Pop_Tag is used to remove the MPLS label from the packet.
  • the same FID package may also use GRE, GTP or other protocol forms, which are not limited by the present invention.
  • the Output action is to send the message out of the corresponding port.
  • the encapsulation indication may also be represented by using a specific FID value or not carrying the FID field, which is not limited by the present invention.
  • the 0F forwarder 1 executes the flow table. The entry is matched, and the corresponding encapsulated flow identifier is added to the data packet by performing a Push_Tag (FID1) operation.
  • FID1 Push_Tag
  • the MPLS protocol encapsulation is used as an example.
  • the OF forwarder 1 adds the MPLS header whose MPLS label is FID1 to the packet, and sends the data packet to the OF through the port 1 according to the forwarding information (the parameter of the output action). 1 performs context processing.
  • the OF forwarder 2 performs flow entry matching according to the MPLS domain of the data packet, and performs local context processing corresponding to CID1 on the data packet according to the processing flow entry corresponding to the FID1, for example, the CID1 corresponds to the IPv4 text reorganization context operation.
  • the 0F forwarder 2 sends the data packet of the IPv4 packet reassembly to its own port 1 to the 0F forwarder 3 for context processing.
  • the 705, 0F forwarder 3 performs flow table matching on the data packet according to the MPLS label of the data packet, and performs local context processing corresponding to CID1 and CID2 on the data packet according to the processing flow entry corresponding to the FID1, for example, the maximum bandwidth corresponding to CID1.
  • Limit (2Mbps) context operation CID2 corresponds to offline charging context operation.
  • the 0F repeater 3 removes the FID information (in this example, the MPLS label) included in the data packet according to the Pop_Tag action, and passes the data through its own port 2 according to the Output action.
  • the message is forwarded to the external network.
  • the 0F forwarder 1 may also perform partial context processing before forwarding the message to other processing network elements. For example, in step 701, the flow rule is sent:
  • the specific deployment of the ingress NE and the processing NE is taken as an example.
  • the entry network element and the two processing network elements are taken as an example, wherein the ingress network element completes the flow matching, and the two processing network elements respectively perform QoS/billing control and GTP encapsulation on the 4 ⁇ text/ Decapsulation function.
  • Each network element determines, according to the processing network element addressing information carried in the context list, the next processing network element, including the following steps: 801.
  • the control network element sends the ingress flow entry to the forwarding plane entry NE through the ingress flow entry installation message.
  • the control network element sends the ingress flow entry as an example.
  • the ingress flow entry may also be configured locally.
  • the ingress flow entry includes: the flow description information, and the processing network element indication processing network element indication includes the context processing indication list CID. List, the context processing indication list includes a context processing indication, and processes addressing information of the network element.
  • the flow description information is exemplified by the flow matching rule (f 1 ow match rule). The description of the above embodiments is not repeated here, and is used to determine whether the packet belongs to the service flow.
  • the context processing indication list CID list includes a context processing indication of all context processing that the forwarding plane needs to perform on the packet, and addressing information (such as an IP address, an identifier, or a domain name, etc.) of the processing network element corresponding to each context processing indication. Take the following flow table entry as an example:
  • each forwarding plane network element determines the next network element according to the NID in the context processing indication list C ID list.
  • the NID uses the IP address, and other identification types such as a domain name, a custom identifier, etc. may be used. The invention is not limited.
  • the ingress network element After the data packet arrives at the ingress network element, the ingress network element performs flow entry matching. The ingress network element adds the corresponding context processing indication list in the flow table entry matching the data to the packet, and sends the packet to the processing network element corresponding to the NIDI according to the order of forwarding the network element list.
  • the specific packet encapsulation format can be in the form of a custom cell. The present invention is not limited. A possible packet format is as follows:
  • ⁇ interim_packet>: ⁇ [NIDl, CIDl] , [NID2, (CID3, CID4) ] , [NI D 3 , C I D5 ] , [user packet] ⁇
  • the processing network element 1 performs a GTP decapsulation operation on the message according to the context processing instruction corresponding to the CID1.
  • the next context processing in the list indicates that the context processing corresponding to the CID3 does not belong to the ingress network element, so the ingress network element sends the remaining context processing indication list and the data packet after the decapsulation processing is completed to the next context processing.
  • a possible message format is as follows:
  • ⁇ inter im_packet>: ⁇ [NID2, (CID3, CID4) ] , [NID3, CID5] , [user packet] ⁇
  • the processing network element 1 performs each context processing on the message sequence according to the context processing list carried in the data packet, until the context corresponding to the next context processing indication in the list does not belong to the local network element processing.
  • the processing network element 2 performs control of the maximum bandwidth of 2 Mbps on the packet according to the context corresponding to the CID3, and performs offline charging according to the context processing corresponding to the CID4 for the data packet controlled by the bandwidth. Since the next context processing in the context processing indication list indicates that the context processing corresponding to CID5 does not belong to the processing network element 2, the processing network element 2 sends the remaining context processing indication list and the data packet after completing the offline charging to the next.
  • a processing network element corresponding to a context processing identifies a processing network element corresponding to the NIDI.
  • the specific packet encapsulation format can be in the form of a custom cell. The present invention is not limited.
  • a possible packet format is as follows:
  • ⁇ inter im_packet>: ⁇ [NID1, CID5] , [user packet] ⁇
  • the processing network element 1 performs the GTP encapsulation context processing corresponding to the CID5 according to the context processing indication list carried in the foregoing message, and encapsulates the GTP-U packet header specified by the context processing instruction into the data packet. On the message. After the above-mentioned encapsulation context processing is completed, since the context processing in the context processing indication list has all been executed, the processing network element 2 directly forwards the processed message to the external network. Through the processing of the above ingress network element and multiple processing network elements, a series of context processing specified by the control network element is completed, and finally sent to the external network. It should be noted that, in FIG.
  • the user packet is used to refer to the to-be-processed message, and the CID list is used to indicate the context processing indication, and the NE list is used to process the list of the network element.
  • the ingress network element includes a context processing function (that is, the inbound network element and the processing network element are deployed in a unified manner).
  • the example uses the ingress network element and the two processing network elements as an example.
  • the ingress network element performs flow matching and GTP decapsulation, and the two processing network elements respectively perform QoS/billing control and GTP encapsulation functions on the packet.
  • the determining, by the network element, the next processing network element according to the CID list includes the following steps: 901:
  • the control network element sends the ingress flow entry to the forwarding surface entry network element by using the ingress flow entry installation message.
  • the control network element sends the ingress flow entry as an example.
  • the ingress flow entry may also be configured locally.
  • the ingress flow entry includes: the flow description information, and the processing network element indication processing network element indication includes the context processing indication list CID. List, the context processing indication list includes a context processing indication, and processes addressing information of the network element.
  • the flow description information is exemplified by the flow matching rule (f 1 ow match rule ). For details, refer to the following description of the embodiments.
  • ⁇ Flow entry> : ⁇ flow match rule, [CID1, CID3, CID4, CID5] ⁇
  • CID1 corresponds to GTP decapsulation
  • CID3 corresponds to 2Mbps bandwidth control
  • CID4 corresponds to offline charging
  • each forwarding plane network element determines the next network element according to the CID, so the CID is the addressing information of the processing network element.
  • the possible implementation manners include: the CID part field is to process the network element identification information (such as the IP address, the domain name, the name identifier, and the like); or each forwarding network element can map the CID to the corresponding network according to the local configuration information or the calculation rule.
  • the present invention is not limited to the method of forwarding the NEs of the forwarding planes to the corresponding processing network elements by using the relay network elements that can map the CIDs to the network element identifiers.
  • the ingress network element After the data packet arrives at the ingress network element, the ingress network element performs flow entry matching. The ingress flow entry is also included in the ingress flow entry.
  • the ingress context processing indication the ingress context processing indication may be included in the context processing indication list, in which case the ingress network element performs local executable process processing in the order of the context processing indication list until the context processing indicates the next context in the list The processing corresponding to the context processing does not belong to the local network element.
  • the ingress network element performs a GTP decapsulation operation on the context according to the context corresponding to the CID1.
  • the next context processing in the list indicates that the context processing corresponding to the CID3 does not belong to the ingress network element, so the ingress network element attaches the remaining context processing indication list to the decapsulated data packet, and sends the processing network element corresponding to the CID2.
  • the specific packet encapsulation format can be in the form of a custom cell. The present invention is not limited. A possible packet format is as follows:
  • inter im_packet>: ⁇ [CID3, CID4, CID5] , [user packet] ⁇
  • the processing network element performs sequential processing on each context according to the sequence of the context processing indication list carried in the data packet, until the next context processing in the context processing indication list indicates that the corresponding context processing does not belong to the local network element processing.
  • the processing network element 1 performs a maximum bandwidth control of 2 Mbps on the packet according to the context corresponding to the CID3, and performs offline charging according to the context corresponding to the CID4. Since the next context processing in the context processing indication list indicates that the context processing corresponding to the CID5 does not belong to the processing network element 1, the processing network element 1 forwards the data message including the remaining context processing indication list to the processing corresponding to the CID5.
  • the specific packet encapsulation format can be in the form of a self-defined cell. The present invention is not limited. A possible packet format is as follows:
  • the processing network element 1 performs the GTP encapsulation context processing corresponding to the CID5 according to the context processing indication list carried in the message, and encapsulates the GTP-U packet header specified by the context processing into the data packet.
  • the processing network element 2 directly forwards the processed 4 ⁇ text to the external network.
  • the data 4 completes a series of context processing specified by the control network element, and is finally sent to the external network.
  • each network element determines a next address according to the CID, so according to different CID lists,
  • the packet may be repeatedly processed through a certain processing network element, and the present invention is not limited.
  • the embodiment of the present invention further provides an implementation manner of an openflow (referred to as OF) protocol, which implements an extension of the openflow protocol to control an ingress flow entry and a processing flow entry of each forwarding device by the network element.
  • OF openflow
  • the control network element in the above embodiment is replaced by the OF control network element, and the function of the ingress network element and the processing network element is implemented by the OF forwarder. Referring to FIG. 11, the specific process is as follows:
  • the 1001, 0F control network element sends the ingress flow entry to the 0F forwarder 1 through the Flow_mod message.
  • a flow entry consists of a flow description rule, a context identifier list, and a context identifier list.
  • the list of context identifiers optionally also includes a repeater identification that performs each context.
  • the Flow_mod message sent to the 0F repeater 1 is the same as the ingress flow entry: the flow description information, the processing network element indication processing network element indication includes a context processing indication list CID list, the context processing indication list includes a context processing indication, and the 0F repeater Addressing information.
  • the corresponding processing network element is used to indicate the next OFDM forwarder that processes the data packet after the OFDM repeater 1 in the embodiment, where the sending of the ingress flow entry by the OFDM control network element in step 1001 is taken as an example.
  • the ingress flow entry can also be configured locally.
  • the flow description information in the embodiment is described by using a ⁇ ow match rule as an example to determine whether the packet belongs to the service flow.
  • the context processing indication list is provided as a parameter to the Push_CID action. This example takes the following flow entry as an example:
  • ⁇ F 1 ow_mod>: ⁇ of -match (n-Tuple) , ofp_ instruct ions [push _cid ( [NIDI, CID1] , [NID2, CID1, CID3] ) , Output (2) ] ⁇
  • the port number of the network element is used as the NID.
  • the same NID can be represented by the network element IP address, MAC address, domain name, etc., or the forwarder obtains the addressing information according to part or all of the CID mapping.
  • the invention is not limited.
  • the 0F forwarder 1 After the data packet reaches the 0F forwarder 1, the 0F forwarder 1 performs flow entry matching, and performs the operation by using ush.cid ([NIDI, CID1], [NID2, CID1, CID3]). A corresponding context processing indication list is attached to the message. The additional manner can be implemented by using a custom cell, which is not limited by the present invention.
  • 0F forwarder 1 root According to the addressing information (parameter of the Output action) or the first context processing instruction identifier NID of the corresponding OF forwarder, the data message is sent to the OF forwarder 2 through the corresponding port for context processing.
  • the OF forwarder 2 processes the indication list according to the context carried by the packet. For parsing, the 0F forwarder 2 performs DPI parsing on the data packet, and optionally adds the parsing result to the report in the form of metadata. In the text.
  • the 0F forwarder 1 deletes the executed context processing indication from the context processing indication list carried in the data packet, and sends the packet to the OFDM repeater 3 corresponding to the NID2 for context according to the addressing information in the subsequent context processing indication. deal with.
  • the context processing indication list does not include a separate transponder identifier
  • the 0F repeater 1 may also map the addressing information of the next processor according to the identifier of the subsequent CID, which is not limited by the present invention.
  • the 1004, 0F forwarder 3 performs context processing corresponding to CID1 and CID3 according to the context processing indication list carried in the message, such as CID1 corresponding to maximum bandwidth limitation (2 Mbps) context operation, CID3 corresponding forwarding (port 1) context processing.
  • the 0F forwarder 3 deletes the foregoing context processing indication from the context processing indication list carried in the data packet, and completes the maximum bandwidth limitation and forwarding operation, and forwards the processed data packet to the external network.
  • the 0F repeater 1 can also perform partial context processing before forwarding data packets to other 0F forwarders.
  • the Flow_mod message is sent:
  • ⁇ F 1 ow_mod>: ⁇ of -match (n-Tuple) , ofp_ instruct ions [Con t ext (CID1) , push.cid ( [NIDI, CID1] , [NID2, CID1, CID3] ) , Output (2 ]] ⁇
  • the OF forwarder 1 performs the context processing corresponding to CID0 on the received data message
  • the CID list is added and forwarded to the processed data message.
  • the p_instruction is used to indicate actions performed by the repeater, such as context processing or flow identifier encapsulation, forwarding, and the like.
  • an embodiment of the present invention provides an ingress network element, which is used to implement the foregoing method, where the ingress network element includes:
  • the receiving unit 1 1 is configured to receive a data packet
  • the sending unit 1 2 is configured to send, according to the ingress flow entry, the data packet received by the receiving unit 1 1 to the processing network element, so that the processing network The element performs context processing on the data packet;
  • the ingress flow entry includes flow description information and a processing network element indication, the flow description information is matched with the data packet, and the processing network element indication is used to indicate the next one after the entry network element. Processing the network element of the data packet.
  • the ingress flow entry further includes an encapsulated flow identifier, where the encapsulated flow identifier is used to identify a service flow to which the data packet belongs;
  • the ingress network element further includes a flow identifier encapsulating unit 13 for appending the encapsulation flow identifier to the data packet, so that the processing network element obtains the encapsulation flow identifier from the data packet. Obtaining a processing flow entry according to the encapsulated flow identifier, and performing context processing on the data packet according to the processing flow entry.
  • the ingress flow entry further includes an ingress encapsulation indication, where the ingress encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the data packet;
  • the flow identifier encapsulating unit 13 is specifically configured to attach the encapsulated flow identifier to the data packet according to the ingress encapsulation indication.
  • the ingress flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding or processing of the data packet by the ingress network element.
  • the processing network element indication includes a context processing indication list, where the context processing indication list includes the context processing indication;
  • the ingress network element further includes a processing indication adding unit 14 for appending the context processing indication list to the data message;
  • the sending unit 12 is specifically configured to determine that the next context processing performed on the data packet is the context processing indicated by the context processing indication, and according to the correspondence between the context processing indication and the processing network element, Sending the data packet to the processing network element.
  • the context processing indication list further includes addressing information of the processing network element, where the context processing indication corresponds to addressing information of the processing network element;
  • the sending unit 1 2 is specifically configured to send the data packet to the processing network element according to the addressing information of the processing network element corresponding to the context processing indication.
  • the ingress flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding of the data packet by the ingress network element.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication is used to indicate a context processing performed on the data packet; the ingress network element further includes: a processing unit 15 The processing unit 15 is configured to perform context processing on the data packet according to the ingress context processing indication.
  • the ingress network element provided by the embodiment of the present invention can implement the context processing of the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the load of the network packet context processing. Balance.
  • an embodiment of the present invention provides a processing network element, which is used to implement the foregoing packet processing method, and includes:
  • the receiving unit 2 1 is configured to receive a data message
  • the processing unit 1 1 is configured to perform context processing on the data packet received by the receiving unit 2 1 according to the context processing indication;
  • the context processing indication is used to indicate context processing performed on the data packet.
  • the processing unit 22 is configured to obtain an encapsulated flow identifier from the data packet, obtain a processing flow entry according to the encapsulated flow identifier, and perform the data packet according to the processing flow entry. Context processing
  • the encapsulated flow identifier is used to identify the service flow to which the data packet belongs, and the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the processing unit 22 is further configured to: add the flow identifier to the processed data packet; where the flow identifier is the encapsulated flow identifier, or when the processing flow entry further includes a new encapsulated flow identifier The flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes: processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed data packet;
  • the processing unit 2 2 is specifically configured to attach the flow identifier to the processed data packet according to the processing package indication.
  • the processing network element further includes: a sending unit 2 3;
  • the sending unit 2 3 sends the data packet processed by the processing unit 22;
  • the sending unit 23 sends the data packet processed by the processing unit 22 to the next one according to the reprocessing network element indication.
  • the reprocessing network element indicates a processing network element for indicating the next processing of the data packet after the processing network element.
  • the processing flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding or processing of the data packet by the processing network element.
  • the processing unit 2 2 is specifically configured to obtain a context processing indication list from the data packet, where the context processing indication list includes the context processing indication, and perform context processing on the data packet according to the context processing indication.
  • the processing network element further includes: a sending unit 2 3;
  • the sending unit 2 3 sends the data message processed by the processing unit 22 outward;
  • the sending unit 23 determines that the next context processing performed on the data packet is the context processing indicated by the other context processing indication, After the processing unit 22 performs context processing on the data packet, sending, according to the correspondence between the other context processing instructions and other processing network elements, the data packet processed by the processing unit 2 2 to the Other processing network elements;
  • the other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element, where the other context processing indication corresponds to the addressing information of the other processing network element;
  • the sending unit is configured to send the data packet processed by the processing unit to the other processing network element according to the addressing information of the other processing network element corresponding to the other context processing indication.
  • the processing network element provided by the embodiment of the present invention can process the context of the packet through the distributed forwarding plane device by performing context processing on the data packet forwarded by the ingress network element in different processing network elements, thereby improving the network. Load balancing of message context processing.
  • an embodiment of the present invention provides an ingress network element, which is used to implement the foregoing packet processing method.
  • the ingress network element may be implemented by using a packet processing server, and includes: a communication unit 31 and a memory 32. And a bus 3 3 , wherein the communication unit 31 and the memory 32 are connected and communicate with each other through a bus 33 for storing data processed by the communication unit 31;
  • the communication unit 31 may be a network card or a transceiver circuit that transmits and receives a full-duplex working mode;
  • the bus 33 may be an I SA (Industry Standard Architecture) bus, a PCI (Peripheral Component) bus, or an EISA (Extended Industry Standard Architecture) bus.
  • the bus 33 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 14, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 32 is for storing executable program code including computer operating instructions.
  • Memory 32 may include high speed RAM memory and may also include non-volatile memory, such as at least one disk memory.
  • the communication unit 3 1 is configured to receive the data packet, and send the data packet received by the communication unit 31 to the processing network element according to the ingress flow entry, so that the processing network element pairs the data packet Context processing;
  • the ingress flow entry includes flow description information and a processing network element indication, the flow description information is matched with the data packet, and the processing network element indication is used to indicate the next one after the entry network element. Processing the network element of the data packet.
  • the ingress flow entry further includes an encapsulated flow identifier, where the encapsulated flow identifier is used to identify a service flow to which the data packet belongs;
  • the ingress network element further includes: a processor 34 connected to the bus, the processor 34 may be a central processing unit (CPU), or an application specific integrated circuit (Application Specific Integrated Circuit, referred to as ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.
  • a processor 34 may be a central processing unit (CPU), or an application specific integrated circuit (Application Specific Integrated Circuit, referred to as ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.
  • the processor 34 is configured to add the encapsulated flow identifier to the data packet, so that the processing network element obtains the encapsulated flow identifier from the data packet, and obtains a processing flow entry according to the encapsulated flow identifier. And performing context processing on the data packet according to the processing flow entry.
  • the ingress flow entry further includes an ingress encapsulation indication, where the ingress encapsulation indication is used to indicate that the encapsulation flow identifier is attached to the data packet;
  • the processor 34 is specifically configured to attach the encapsulated flow identifier to the data packet according to the ingress encapsulation indication.
  • the ingress flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding or processing of the data packet by the ingress network element.
  • the processing network element indication includes a context processing indication list, where the context processing indication list includes the context processing indication;
  • the processor 34 is configured to append the context processing indication list to the data message,
  • the communication unit 31 is configured to determine that the next context processing performed on the data packet is the context processing indicated by the context processing indication, and send the data according to the correspondence between the context processing indication and the processing network element. The message is sent to the processing network element.
  • the context processing indication list further includes addressing information of the processing network element, where the context processing indication corresponds to addressing information of the processing network element;
  • the communication unit 3 is specifically configured to send the data packet to the processing network element according to the addressing information of the processing network element corresponding to the context processing indication.
  • the ingress flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding of the data packet by the ingress network element.
  • the ingress flow entry further includes an ingress context processing indication; the ingress context processing indication is used to indicate a context processing performed on the data packet;
  • the processor 34 is configured to process the indication according to the ingress context
  • the ingress network element provided by the embodiment of the present invention can implement the context processing of the packet by the distributed forwarding plane device by forwarding the packet to different network elements, thereby improving the load of the network packet context processing. Balance.
  • an embodiment of the present invention provides a processing network element, which is used to implement the foregoing packet processing method.
  • the processing network element may be implemented by using a message processing server, and includes: a processor 4 1 and a communication unit 42.
  • the storage unit 43 is configured to store the program code processed by the processor 41;
  • the communication unit 42 may be a network card or a transceiver circuit that transmits and receives a full-duplex operation mode;
  • the bus 44 may be an ISA (Industry Standard Architecture, industry) Standard architecture) Bus, PCI (Peripheral Component) bus or EISA (Extended Industry Standard Architecture) bus.
  • the bus 44 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 15, but it does not mean that there is only one bus or one type of bus. among them:
  • the memory 43 is for storing executable program code including computer operating instructions.
  • the memory 43 may contain a high speed RAM memory and may also include a non-volatile memory such as at least one disk memory.
  • the processor 41 may be a Central Processing Unit (CPU), or an Application Specific Integrated Circuit (ASIC), or one or more configured to implement the embodiments of the present invention. integrated circuit.
  • CPU Central Processing Unit
  • ASIC Application Specific Integrated Circuit
  • the communication unit 42 is configured to receive a data message
  • the processor 4 1 is configured to perform context processing on the data packet received by the communication unit 42 according to a context processing indication
  • the context processing indication is used to indicate a context processing performed on the data packet.
  • the processor 4 is configured to obtain an encapsulated flow identifier from the data packet, obtain a processing flow entry according to the encapsulated flow identifier, and use the data flow entry according to the processing flow entry.
  • Context processing ;
  • the encapsulated flow identifier is used to identify the service flow to which the data packet belongs, and the processing flow entry includes a matching flow identifier and the context processing indication, where the matching flow identifier matches the encapsulated flow identifier.
  • the processor 41 is further configured to attach a flow identifier to the processed data packet;
  • the flow identifier is the encapsulated flow identifier, or when the processing flow entry further includes a new encapsulated flow identifier, the flow identifier is the new encapsulated flow identifier.
  • the processing flow entry further includes: processing the encapsulation indication; the processing encapsulation indication is used to indicate that the flow identifier is attached to the processed data packet;
  • the processor 4 is specifically configured to attach the flow identifier to the processed data packet according to the processing encapsulation indication.
  • the communication unit 42 sends the data packet processed by the processor 4 1 to the outside of the packet processing system;
  • the communication unit 42 sends the data packet processed by the processor 4 1 to the next according to the reprocessing network element indication.
  • the reprocessing network element indicates a processing network element for indicating the next processing of the data packet after the processing network element.
  • the processing flow entry is locally configured or sent by a control network element, where the control network element is configured to control forwarding or processing of the data packet by the processing network element.
  • the processor 41 is configured to obtain a context processing indication list from the data packet, and perform context processing on the data packet according to the context processing indication, where the context processing indication list includes the context processing Instructions.
  • the communication unit 42 sends the data message processed by the processor 4 1 to the outside;
  • the communication unit 42 determines that the next context processing performed on the data packet is the context processing indicated by the other context processing indication, After performing the context processing on the data packet, the processor 4 1 sends the data processed by the processor 4 1 to the data according to the correspondence between the other context processing instructions and other processing network elements.
  • the other processing network element; The other context processing indicates context processing performed on the data packet.
  • the context processing indication list further includes addressing information of the other processing network element, where the other context processing indication corresponds to the addressing information of the other processing network element;
  • the communication unit 42 is configured to send the data message processed by the processor to the other processing network element according to the addressing information of the other processing network element that is instructed by the other context processing.
  • the processing network element provided by the embodiment of the present invention can implement the context processing of the packet by the distributed forwarding plane device by forwarding the packet to different network elements for context processing, thereby improving the load of the network packet context processing. Balance.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a computer.
  • the computer readable medium may include RAM (Random Access Memory), ROM (Read Only Memory), EEPR0M (Electrical ly Erasable Programmable Read Only Memory) Read only memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, disk storage media or other magnetic storage device, or can be used to carry or store the desired form of instructions or data structures.
  • Program code and any other medium that can be accessed by a computer may suitably be a computer readable medium.
  • the software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, DSL (Digital Subscriber Line), or wireless technologies such as infrared, radio, and oscillating waves.
  • Disks and discs as used in the present invention include CD (Compact Disc), laser disc, optical disc, DVD disc (Digital Versatile Disc), floppy disk and Blu-ray disc, wherein the disc is usually magnetically copied data, and The disc uses a laser to optically replicate the data. Combinations of the above should also be included within the scope of the computer readable media.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明公开一种报文处理方法、装置及系统,涉及通信领域,能够实现通过分布式的转发面设备对报文的上下文处理,进而提高网络报文上下文处理的负载均衡性。该方法包括:入口网元接收控制网元发送的流表项;所述入口网元接收报文;所述入口网元对所述报文按照所述流表项进行匹配,获取本次执行上下文处理的报文;所述入口网元将所述报文转发至处理网元,以便所述处理网元对所述报文进行上下文处理,或者对所述用户进行上下文处理后转发至处理网元进行上下文处理。本发明的实施例用用于报文上下文处理。

Description

一种报文处理方法、 装置及系统 技术领域 本发明涉及通信领域, 尤其涉及一种报文处理方法、 装置及系 统。 背景技术
在目前的通信网络中,存在着众多复杂的网络设备,如路由器、 网管、 交换机、 防火墙和各类服务器等。 这些设备分别支持各类的 网络协议, 从而实现网元间的互联互通。 由于每台设备都具有自 己 独立的控制模块,因此这种分布式的控制模块部署使得网络的部署 和管理非常复杂, 为了实施某个控制参数修改或控制模块的升级, 网络操作员必须对每台设备进行单独的操作。 为解决网元的部署灵活性和可管理性,业界提出了软件定义网 络 ( Software-Defined Network, 简称 SDN ) 的概念。 SDN 通过将 网元的控制逻辑和转发功能解耦, 并将控制逻辑进行集中部署, 使 得对网络的控制和维护工作能够简单的通过对控制面设备的操作 实现, 从而提高网络的管理效率, 并使得转发面设备更为简单化, 有利于实现转发设备的高性能和可重用性。 目前 SDN思想正在被广 泛应用到数据中心网络和电信网络中。 现有技术提供一种 SDN控制和转发解耦的实现方法,网络由控 制面和转发面设备组成,控制面通过下发流匹配信息和对应的上下 文对转发面设备进行控制, 实现对用户数据报文的处理。 其中流匹 配信息用于确定报文所属的业务流, 上下文表示特定的处理功能。 每个业务流可以对应或关联多个上下文, 这些上下文之间相互独 立, 从而实现对流粒度报文的各类处理间的相对独立性, 使得并行 处理、 处理能力扩展。 在现有技术中,由于转发面设备对所有报文按照上下文进行处 理, 因此对于转发面设备要求较高, 转发面设备负载较大不利于网 络整体性能的提升。 发明内容
本发明的实施实例提供一种报文处理方法, 涉及通信领域, 能 够实现通过分布式的转发面设备分别对报文进行上下文处理, 进而 提高网络报文上下文处理的负载均衡性。
第一方面, 提供一种报文处理系统, 包括:
入口网元, 用于从所述报文系统外部接收数据报文, 根据入口 流表项, 发送所述数据报文至处理网元; 所述入口流表项包括流描 述信息和处理网元指示, 所述流描述信息与所述数据报文匹配, 所 述处理网元指示用于指示在所述入口网元后的下一个处理所述数据 才艮文的处理网元;
所述处理网元, 用于从所述入口网元接收所述数据报文, 根据 上下文处理指示, 对所述数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。
结合第一方面, 在第一种可能的实现方式中,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用 于标识所述数据报文所属的业务流;
所述入口网元还用于将所述封装流标识附加至所述数据报文; 所述处理网元具体用于从所述数据报文获取所述封装流标识, 根据所述封装流标识获取处理流表项, 根据所述处理流表项, 对所 述数据报文进行上下文处理;
其中, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配流标识与所述封装流标识匹配。
结合第一种可能的实现方式, 在第二种可能的实现方式中, 所述入口流表项还包括入口封装指示; 其中, 所述入口封装指 示用于指示将所述封装流标识附加至所述数据报文;
所述入口网元具体用于根据所述入口封装指示将所述封装流标 识附加至所述数据报文。
结合第一种或第二种可能的实现方式, 在第三种可能的实现方 式中, 流标识时, 将流标识附加至处理后的所述数据报文; 其中所述流标 识为所述封装流标识, 或者当所述处理流表项还包括新的封装流标 识时, 所述流标识为所述新的封装流标识。
结合第三种可能的实现方式, 在第四种可能的实现方式中, 所述处理流表项还包括处理封装指示; 所述处理封装指示用于 指示将所述流标识附加至处理后的所述数据报文;
所述处理网元还用于根据所述处理封装指示将所述流标识附加 至处理后的所述数据报文。
结合第一种可能的实现方式至第四种可能的实现方式中任—— 种可能的实现方式, 在第五种可能的实现方式中,
当所述处理流表项不包括再处理网元指示时, 所述处理网元还 用于发送处理后的所述数据报文至所述报文处理系统外部; 或者 当所述处理流表项还包括所述再处理网元指示时, 所述处理网 元还用于根据所述再处理网元指示, 发送处理后的所述数据报文至 下一个处理网元;
其中所述再处理网元指示用于指示在所述处理网元后的下一个 处理所述数据报文的处理网元。
结合第一种可能的实现方式至第五种可能的实现方式中任—— 种可能的实现方式, 在第六种可能的实现方式中,
所述入口流表项和所述处理流表项是本地配置的或者是控制网 元发送的; 其中, 所述控制网元用于控制所述入口网元和所述处理 网元对所述数据报文的转发或处理。
结合第一方面, 在第七种可能的实现方式中,
所述处理网元指示包括上下文处理指示列表, 所述上下文处理 指示列表包括所述上下文处理指示;
所述入口网元具体用于将所述上下文处理指示列表附加至所述 数据报文, 确定对所述数据报文进行的下一个上下文处理为所述上 下文处理指示所指示的上下文处理, 根据所述上下文处理指示和所 述处理网元的对应关系, 发送所述数据报文至所述处理网元;
所述处理网元具体用于从所述数据报文获取所述上下文处理指 示列表, 根据所述上下文处理指示对所述数据报文进行上下文处理。
结合第七种可能的实现方式, 在第八种可能的实现方式中, 所述上下文处理指示列表还包括所述处理网元的寻址信息, 所 述上下文处理指示与所述处理网元的寻址信息对应;
所述入口网元具体用于, 根据与所述上下文处理指示对应的所 述处理网元的寻址信息, 发送所述数据报文至所述处理网元。
结合第七种或第八种可能的实现方式, 在第九种可能的实现方 式中,
当所述上下文处理指示列表不包括其他上下文处理指示时, 所 述处理网元还用于发送处理后的所述数据报文至所述报文处理系统 外部; 或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述处理网元还用于确定对所述数据报文进行的下一个上下文 处理为所述其他上下文处理指示所指示的上下文处理, 在所述处理 网元对所述数据报文进行上下文处理之后, 根据所述其他上下文处 理指示和其他处理网元的对应关系, 发送处理后的所述数据报文至 所述其他处理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
结合第九种可能的实现方式, 在第十种可能的实现方式中, 所 述上下文处理指示列表还包括所述其他处理网元的寻址信息, 所述 其他上下文处理指示与所述其他处理网元的寻址信息对应;
所述处理网元具体用于, 根据所述其他上下文处理指示对应的 所述其他处理网元的寻址信息, 发送处理后的所述数据报文至所述 其他处理网元。
结合第七种至第十种可能的实现方式, 在第十一种可能的实现 方式中, 所述入口流表项是本地配置的或者是控制网元发送的; 其 中, 所述控制网元用于控制所述入口网元对所述数据报文的转发。
结合第一方面或者第一方面中任意一种可能的实现方式, 在第 十二种可能的实现方式中,
所述入口流表项还包括入口上下文处理指示; 所述入口上下文 处理指示用于指示对所述数据报文进行的上下文处理;
所述入口网元还用于根据所述入口上下文处理指示, 对所述数 据报文进行上下文处理。
第二方面, 提供一种入口网元, 包括:
接收单元, 用于接收数据报文;
发送单元, 用于根据入口流表项, 发送所述接收单元接收的所 述数据报文至处理网元, 以使所述处理网元对所述数据报文进行上 下文处理;
其中, 所述入口流表项包括流描述信息和处理网元指示, 所述 流描述信息与所述数据报文匹配, 所述处理网元指示用于指示在所 述入口网元后的下一个处理所述数据报文的处理网元。
结合第二方面, 在第一种可能的实现方式中,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用 于标识所述数据报文所属的业务流;
所述入口网元还包括流标识封装单元, 用于将所述封装流标识 附加至所述数据报文, 以使所述处理网元从所述数据报文获取所述 封装流标识, 根据所述封装流标识获取处理流表项, 并根据所述处 理流表项对所述数据报文进行上下文处理。
结合第一种可能的实现方式, 在第二种可能的实现方式中, 所述入口流表项还包括入口封装指示, 所述入口封装指示用于 指示将所述封装流标识附加至所述数据报文;
所述流标识封装单元具体用于根据所述入口封装指示将所述封 装流标识附加至所述数据报文。
结合第一种或第二种可能的实现方式, 在第三种可能的实现方 式中,
所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口 网元对所述数据报文的转发或处 理。
结合第二方面, 在第四种可能的实现方式中,
所述处理网元指示包括上下文处理指示列表, 所述上下文处理 指示列表包括所述上下文处理指示;
所述入口网元还包括处理指示附加单元, 用于将所述上下文处 理指示列表附加至所述数据报文;
所述发送单元具体用于确定对所述数据报文进行的下一个上下 文处理为所述上下文处理指示所指示的上下文处理, 根据所述上下 文处理指示和所述处理网元的对应关系, 发送所述数据报文至所述 处理网元。
结合第四种可能的实现方式, 在第五种可能的实现方式中, 所述上下文处理指示列表还包括所述处理网元的寻址信息, 所 述上下文处理指示与所述处理网元的寻址信息对应;
所述发送单元具体用于根据与所述上下文处理指示对应的所述 处理网元的寻址信息, 发送所述数据报文至所述处理网元。
结合第四种或第五种可能的实现方式, 在第六种可能的实现方 式中, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发。
结合第二方面或第二方面中任意一种可能的实现方式, 在第七 种可能的实现方式中,
所述入口流表项还包括入口上下文处理指示; 所述入口上下文 处理指示用于指示对所述数据报文进行的上下文处理; 所述入口网 元还包括: 处理单元;
处理单元用于根据所述入口上下文处理指示, 对所述数据
Figure imgf000008_0001
第三方面, 提供一种处理网元, 包括: 接收单元用于接收数据报文;
处理单元用于根据上下文处理指示, 对所述接收单元接收的所 述数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。
结合第三方面, 在第一种可能的实现方式中, 所述处理单元具 体用于从所述数据报文获取封装流标识, 根据所述封装流标识获取 处理流表项, 根据所述处理流表项, 对所述数据报文进行上下文处 理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配 流标识与所述封装流标识匹配。
结合第一种可能的实现方式, 在第二种可能的实现方式中, 单元还用于将流标识附加至处理后的所述数据报文; 其中所述流标 识为所述封装流标识, 或者当所述处理流表项还包括新的封装流标 识时, 所述流标识为所述新的封装流标识。
结合第二种可能的实现方式, 在第三种可能的实现方式中, 所述处理流表项还包括处理封装指示; 所述处理封装指示用于 指示将所述流标识附加至处理后的所述数据报文;
所述处理单元具体用于根据所述处理封装指示将所述流标识附 加至处理后的所述数据报文。
结合第一种至第三种可能的实现方式中任意一种可能的实现方 式, 在第四种可能的实现方式中, 所述处理网元还包括: 发送单元; 当所述处理流表项不包括再处理网元指示时, 所述发送单元向 外发送所述处理单元处理后的所述数据报文; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述发送单 元根据所述再处理网元指示, 发送所述处理单元处理后的所述数据 才艮文至下一个处理网元; 其中, 所述再处理网元指示用于指示在所述处理网元后的下一 个处理所述数据报文的处理网元。
结合第一种至第四种可能的实现方式中任意一种可能的实现方 式, 在第五种可能的实现方式中,
所述处理流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述处理网元对所述数据报文的转发或处 理。
结合第三方面, 在第六种可能的实现方式中, 所述处理单元具 体用于从所述数据报文获取上下文处理指示列表, 所述上下文处理 指示列表包括所述上下文处理指示, 根据所述上下文处理指示对所 述数据报文进行上下文处理, 所述上下文处理指示列表包括所述上 下文处理指示。
结合第六种可能的实现方式, 在第七种可能的实现方式中, 所 述处理网元还包括: 发送单元;
当所述上下文处理指示列表不包括其他上下文处理指示时, 所 述发送单元向外发送所述处理单元处理后的所述数据报文;
或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述发送单元确定对所述数据报文进行的下一个上下文处理为 所述其他上下文处理指示所指示的上下文处理, 在所述处理单元对 所述数据报文进行上下文处理之后, 根据所述其他上下文处理指示 和其他处理网元的对应关系, 发送所述处理单元处理后的所述数据 才艮文至所述其他处理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
结合第七种可能的实现方式, 在第八种可能的实现方式中, 所 述上下文处理指示列表还包括所述其他处理网元的寻址信息, 所述 其他上下文处理指示与所述其他处理网元的寻址信息对应;
所述发送单元具体用于根据所述其他上下文处理指示对应的所 述其他处理网元的寻址信息, 发送所述处理单元处理后的所述数据 才艮文至所述其他处理网元。 第四方面, 提供一种报文处理方法, 包括:
入口网元接收数据报文; 其中, 所述入口网元存有入口流表项, 所述入口流表项包括流描述信息和处理网元指示, 所述流描述信息 与所述数据报文匹配, 所述处理网元指示用于指示在所述入口网元 后的下一个处理所述数据报文的处理网元;
所述入口网元根据入口流表项, 发送所述数据报文至所述处理 网元, 以使所述处理网元对所述数据报文进行上下文处理。
结合第四方面, 在第一种可能的实现方式中,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用 于标识所述数据报文所属的业务流; 所述方法还包括:
所述入口网元将所述封装流标识附加至所述数据报文, 以使所 述处理网元从所述数据报文获取所述封装流标识, 根据所述封装流 标识获取处理流表项, 并根据所述处理流表项对所述数据报文进行 上下文处理。
结合第一种可能的实现方式, 在第二种可能的实现方式中, 所述入口流表项还包括入口封装指示, 所述入口封装指示用于 指示将所述封装流标识附加至所述数据报文; 所述入口网元将所述 封装流标识附加至所述数据报文包括:
所述入口网元根据所述入口封装指示将所述封装流标识附加至 所述数据报文。
结合第一种或第二种可能的实现方式, 在第三种可能的实现方 式中,
所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口 网元对所述数据报文的转发或处 理。
结合第四方面, 在第四种可能的实现方式中, 所述处理网元指示包括上下文处理指示列表, 所述上下文处理 指示列表包括所述上下文处理指示;
所述方法还包括: 所述入口网元将所述上下文处理指示列表附 加至所述数据报文;
所述入口网元根据入口流表项, 发送所述数据报文至处理网元 包括:
所述入口网元确定对所述数据报文进行的下一个上下文处理为 所述上下文处理指示所指示的上下文处理, 根据所述上下文处理指 示和所述处理网元的对应关系, 发送所述数据报文至所述处理网元。
结合第四种可能的实现方式, 在第五种可能的实现方式中, 所述上下文处理指示列表还包括所述处理网元的寻址信息, 所 述上下文处理指示与所述处理网元的寻址信息对应;
所述根据所述上下文处理指示和所述处理网元的对应关系, 发 送所述数据报文至所述处理网元包括:
所述入口网元根据与所述上下文处理指示对应的所述处理网元 的寻址信息, 发送所述数据报文至所述处理网元。
结合第四种或第五种可能的实现方式, 在第六种可能的实现方 式中, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发。
结合第四方面或第四方面中任意一种可能的实现方式, 在第七 种可能的实现方式中,
所述入口流表项还包括入口上下文处理指示, 所述入口上下文 处理指示用于指示对所述数据报文进行的上下文处理; 所述方法还 包括:
所述入口网元根据所述入口上下文处理指示, 对所述数据报文 进行上下文处理。 第五方面, 提供一种报文处理方法, 包括:
处理网元接收数据报文; 根据上下文处理指示, 对所述数据报文进行上下文处理; 其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。
结合第五方面, 在第一种可能的实现方式中, 所述根据上下文 处理指示, 对所述数据报文进行上下文处理包括:
所述处理网元从所述数据报文获取封装流标识, 根据所述封装 流标识获取处理流表项, 根据所述处理流表项, 对所述数据报文进 行上下文处理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配 流标识与所述封装流标识匹配。
结合第一种可能的实现方式, 在第二种可能的实现方式中, 所 述方法还包括: 网元将流标识附加至处理后的所述数据报文; 其中所述流标识为所 述封装流标识, 或者当所述处理流表项还包括新的封装流标识时, 所述流标识为所述新的封装流标识。
结合第二种可能的实现方式, 在第三种可能的实现方式中, 所述处理流表项还包括处理封装指示; 所述处理封装指示用于 指示将所述流标识附加至处理后的所述数据报文; 所述方法还包括: 所述处理网元根据所述处理封装指示将所述流标识附加至处理 后的所述数据报文。
结合第一种至第三种可能的实现方式中任意一种可能的实现方 式, 在第四种可能的实现方式中, 所述方法还包括:
当所述处理流表项不包括再处理网元指示时, 所述处理网元向 外发送处理后的所述数据报文; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述处理网 元根据所述再处理网元指示, 发送处理后的所述数据报文至下一个 处理网元; 其中, 所述再处理网元指示用于指示在所述处理网元后的下一 个处理所述数据报文的处理网元。
结合第一种至第四种可能的实现方式中任意一种可能的实现方 式, 在第五种可能的实现方式中,
所述所述处理流表项是本地配置的或者是控制网元发送的; 其 中, 所述控制网元用于控制所述处理网元对所述数据报文的转发或 处理。
结合第五方面, 在第六种可能的实现方式中, 所述根据上下文 处理指示, 对所述数据报文进行上下文处理包括:
所述处理网元从所述数据报文获取上下文处理指示列表, 所述 上下文处理指示列表包括所述上下文处理指示, 根据所述上下文处 理指示对所述数据报文进行上下文处理。
结合第六种可能的实现方式, 在第七种可能的实现方式中, 所 述方法还包括:
当所述上下文处理指示列表不包括其他上下文处理指示时, 所 述处理网元向外发送处理后的所述数据报文;
或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述处理网元确定对所述数据报文进行的下一个上下文处理为 所述其他上下文处理指示所指示的上下文处理, 在所述处理网元对 所述数据报文进行上下文处理之后, 根据所述其他上下文处理指示 和其他处理网元的对应关系, 发送处理后的所述数据报文至所述其 他处理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
结合第七种可能的实现方式, 在第八种可能的实现方式中, 所 述上下文处理指示列表还包括所述其他处理网元的寻址信息, 所述 其他上下文处理指示与所述其他处理网元的寻址信息对应; 所述发 送处理后的所述数据报文至所述其他处理网元包括: 所述处理网元根据所述其他上下文处理指示对应的所述其他处 理网元的寻址信息, 发送处理后的所述数据报文至所述其他处理网 元。 上述技术方案提供的报文处理方法、 装置及系统, 通过将报文 转发至不同的网元进行上下文处理,能够实现通过分布式的转发面 设备分别对报文进行上下文处理,进而提高网络报文上下文处理的 负载均衡性。
附图说明 实施例或现有技术描述中所需要使用的附图作简单地介绍, 显而易见地, 下面描述中的附图仅仅是本发明的一些实施例。
图 1为本发明的实施例提供的一种通信系统的结构示意图;
图 2为本发明的实施例提供的一种报文处理方法的流程示意图; 图 3为本发明的实施例提供的另一种报文处理方法的流程示意图; 图 4为本发明的另一实施例提供的一种报文处理方法的流程示意图; 图 5为本发明的又一实施例提供的一种报文处理方法的流程示意图; 图 6为本发明的再一实施例提供的一种报文处理方法的流程示意图; 图 7为本发明的另一实施例提供的一种报文处理方法的流程示意图; 图 8为本发明的又一实施例提供的一种报文处理方法的流程示意图; 图 9为本发明的再一实施例提供的一种报文处理方法的流程示意图; 图 1 0 为本发明的另一实施例提供的一种报文处理方法的流程示意 图;
图 1 1 为本发明的又一实施例提供的一种报文处理方法的流程示意 图;
图 1 2为本发明的实施例提供的一种入口网元的结构示意图; 图 1 3为本发明的实施例提供的一种处理网元的结构示意图; 图 1 4为本发明的另一实施例提供的一种入口网元的结构示意图; 图 1 5为本发明的另一实施例提供的一种处理网元的结构示意图。 具体实施方式 下面将结合本发明实施例中的附图, 对本发明实施例中的技术方案 进行清楚、 完整地描述, 显然, 所描述的实施例仅仅是本发明一部分实 施例, 而不是全部的实施例。 本发明的实施例应用于软件定义网络 ( Software-Defined Network, 简称 SDN ), 提供了一种报文处理系统, 参照图 1所示, 包括: 入口网元 1和至少一个处理网元 ( 2-l〜2-k )。
入口网元 1, 用于从所述报文系统外部接收数据报文, 根据入 口流表项, 发送所述数据报文至处理网元 2-1 ( 当然这里的处理网 元可以为任意一个, 此处以 2-1为例); 所述入口流表项包括流描述 信息和处理网元指示, 所述流描述信息与所述数据报文匹配, 所述 处理网元指示用于指示在所述入口网元 1 后的下一个处理所述数据 才艮文的处理网元 2-1。
所述处理网元 2-1, 用于从所述入口网元 1接收所述数据报文, 根据上下文处理指示, 对所述数据报文进行上下文处理。
其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。
本发明的实施例提供的报文处理系统通过将报文转发至不同的 网元进行上下文处理, 能够实现通过分布式的转发面设备分别对报 文进行上下文处理, 进而提高网络报文上下文处理的负载均衡性。
具体在本发明的实施例提供的一种实现方式中可选的, 入口流 表项还包括封装流标识; 其中, 封装流标识用于标识数据报文所属 的业务流;
入口网元 1还用于将所述封装流标识附加至所述数据报文; 处理网元 2-1 具体用于从所述数据报文获取所述封装流标识, 根据所述封装流标识获取处理流表项, 根据所述处理流表项, 对所 述数据报文进行上下文处理;
其中, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配流标识与所述封装流标识匹配。
可选的, 所述入口流表项还包括入口封装指示; 其中, 所述入 口封装指示用于指示将所述封装流标识附加至所述数据报文; 对应的, 所述入口网元 1 具体用于根据所述入口封装指示将所 述封装流标识附加至所述数据报文。
可选的, 所述处理网元 2 - 1 还用于当处理后的所述数据报文未 包含所述封装流标识时, 将流标识附加至处理后的所述数据报文; 其中所述流标识为所述封装流标识, 或者当所述处理流表项还包括 新的封装流标识时, 所述流标识为所述新的封装流标识。
可选的, 所述处理流表项还包括处理封装指示; 所述处理封装 指示用于指示将所述流标识附加至处理后的所述数据报文;
对应的, 处理网元 2 - 1 还用于根据所述处理封装指示将所述流 标识附加至处理后的所述数据报文。
可选的, 当所述处理流表项不包括再处理网元指示时, 所述处 理网元 1 - 1 还用于发送处理后的所述数据报文至所述报文处理系统 外部; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述处理网 元 2 - 1 还用于根据所述再处理网元指示, 发送处理后的所述数据报 文至下一个处理网元 2 - 2 ;
其中所述再处理网元指示用于指示在所述处理网元 2 - 1 后的下 一个处理所述数据报文的处理网元。
可选的, 该系统还包括控制网元 3 , 所述入口流表项和所述处 理流表项是本地配置的或者是控制网元 3 发送的; 其中, 所述控制 网元 3用于控制所述入口网元 1 和所述处理网元 2 - 1对所述数据报 文的转发或处理。
具体在本发明的实施例提供的另一种实现方式中, 可选的, 所 述处理网元指示包括上下文处理指示列表, 所述上下文处理指示列 表包括所述上下文处理指示;
对应的, 所述入口网元 1 具体用于将所述上下文处理指示列表 附加至所述数据报文, 确定对所述数据报文进行的下一个上下文处 理为所述上下文处理指示所指示的上下文处理, 根据所述上下文处 理指示和所述处理网元 2-1 的对应关系, 发送所述数据报文至所述 处理网元 2-1;
对应的, 所述处理网元 2-1 具体用于从所述数据报文获取所述 上下文处理指示列表, 根据所述上下文处理指示对所述数据报文进 行上下文处理。
可选的, 所述上下文处理指示列表还包括所述处理网元 2-1 的 寻址信息, 所述上下文处理指示与所述处理网元 2-1 的寻址信息对 应;
对应的, 所述入口网元 1 具体用于, 根据与所述上下文处理指 示对应的所述处理网元 2-1 的寻址信息, 发送所述数据报文至所述 处理网元 2-1。
可选的, 当所述上下文处理指示列表不包括其他上下文处理指 示时, 所述处理网元 2-1 还用于发送处理后的所述数据报文至所述 才艮文处理系统外部; 或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述处理网元 2-1 还用于确定对所述数据报文进行的下一个上 下文处理为所述其他上下文处理指示所指示的上下文处理, 在所述 处理网元对所述数据报文进行上下文处理之后, 根据所述其他上下 文处理指示和其他处理网元的对应关系, 发送处理后的所述数据报 文至所述其他处理网元 2-2;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
可选的,所述上下文处理指示列表还包括所述其他处理网元 2-2 的寻址信息, 所述其他上下文处理指示与所述其他处理网元 2-2 的 寻址信息对应;
对应的, 所述处理网元 2-1 具体用于, 根据所述其他上下文处 理指示对应的所述其他处理网元 2-2 的寻址信息, 发送处理后的所 述数据报文至所述其他处理网元 2-2。
可选的, 所述入口流表项是本地配置的或者是控制网元 2 发送 的; 其中, 所述控制网元 2 用于控制所述入口网元对所述数据报文 的转发。
在上述的两种实现方式中, 可选的, 所述入口流表项还包括入 口上下文处理指示; 所述入口上下文处理指示用于指示对所述数据 报文进行的上下文处理; 对应的, 所述入口网元 1 还用于根据所述入口上下文处理指 示, 对所述数据报文进行上下文处理。
本发明的实施例提供的报文处理系统通过将报文转发至不同的 网元进行上下文处理, 能够实现通过分布式的转发面设备分别对报 文进行上下文处理, 进而提高网络报文上下文处理的负载均衡性。 本发明的实施例提供一种报文处理方法,通过上述报文处理系 统实现, 参照 2所示, 在入口网元侧包括以下步骤:
101、 入口网元接收数据报文; 其中、 步骤 101 中入口网元从报文系统外部接收数据报文, 其 中, 所述入口网元存有入口流表项, 所述入口流表项包括流描述信 息和处理网元指示, 所述流描述信息与所述数据报文匹配, 所述处 理网元指示用于指示在所述入口 网元后的下一个处理所述数据报 文的处理网元;
102、 入口网元根据入口流表项, 发送所述数据报文至所述处 理网元, 以使所述处理网元对所述数据报文进行上下文处理。 流描述信息可以是一种包括报文特征的信息, 当数据报文符合 流描述信息中包括的报文特征信息时,认为该数据报文与流描述信 息匹配。 例如, 流描述信息可以包括: MAC ( Media Access Control, 介质访问控制 ) 地址、 目的 MAC地址, 源 IP ( Internet Protocol , 网络协议)地址、 目的 IP地址, 源端口号、 目的端口号, MPLS Label ( mul t i-protocol label switching Label , 多十办议标签交换标 记 ), ToS( ty e of service,业务类型 ), IPv6 flow lable (Internet Protocol Vers ion 6 flow lable,互联网协议版本 6流标识), GRE key ( generic route encapsulation key , 通用路由封装密钥 ), GTP TE I D (GPRS Tunnel ling Protocol Tunnel end point ID, 通 用分组无线服务隧道协议隧道端点标识符)等一个或多个报文特征 域的组合, 用于确定报文是否属于本次处理的业务流。 本发明的实施例提供另一种报文处理方法,通过上述报文处理 系统实现, 参照 3所示, 在处理网元侧包括以下步骤:
201、 处理网元接收数据报文;
从入口网元
202、 所述处理网元根据上下文处理指示, 对所述数据报文进 行上下文处理; 其中,所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。 本发明的实施例提供的报文处理方法,通过将报文转发至不同 的网元进行上下文处理,能够实现通过分布式的转发面设备分别对 报文进行上下文处理, 进而提高网络报文上下文处理的负载均衡 性。 具体的参照图 4所示,本发明的实施例提供的一种报文处理方 法, 通过上述报文处理系统实现, 包括以下步骤:
301、 入口网元本地配置的或者接收控制网元发送的入口流表 项。 其中,控制网元用于控制入口网元和处理网元对数据报文的转 发或处理。 其中, 入口流表项包括: 流描述信息、 处理网元指示、 封装流标识和封装指示。 流描述信息与数据报文匹配, 处理网元指 示用于指示在入口 网元后的下一个处理数据报文的处理网元。 例 如, 流描述信息可以包括: 源 MAC ( Media Access Control, 介质 访问控制 ) 地址、 目 的 MAC地址, 源 IP ( Internet Protocol , 网 络协议)地址、 目的 IP地址, 源端口号、 目 的端口号, MPLS Label ( mul t i-protocol label switching Label , 多十办议标签交换标 记 ), ToS( ty e of service,业务类型 ), IPv6 flow lable (Internet Protocol Vers ion 6 flow lable,互联网协议版本 6流标识), GRE key ( generic route encapsulation key , 通用路由封装密钥 ), GTP TE I D (GPRS Tunnel ling Protocol Tunnel end point ID, 通 用分组无线服务隧道协议隧道端点标识符)等一个或多个报文特征 域的组合, 用于确定报文是否属于本次处理的业务流。 302、 入口网元从才艮文系统外部接收数据才艮文。 通过步骤 302入口网元仅对数据报文具备收发功能,在功能上 入口网元与处理网元的分离部署的, 进一步可选的, 入口流表项还 包括入口上下文处理指示;入口上下文处理指示用于指示对数据报 文进行的上下文处理; 在步骤 302 中还包括, 入口网元根据入口上 下文处理指示, 对数据报文进行上下文处理。 此时入口网元包括报 文的上下文处理能力, 即此时入口网元与处理网元的合一部署的, 在入口网元功能上是包括一个处理网元的功能的。
303、 入口网元根据入口封装指示将封装流标识附加至数据报 文。 本发明中根据入口封装指示进行的封装指将需要附加的信息, 如封装流标识添加到报文上, 所述封装流标识用于标识所述数据报 文所属的业务流。 具体封装的方式可以釆用如 GRE ( generic route encapsulation, 通用路由封装), GTP ( GPRS Tunnelling Protocol, 通用分组无线月良务 P遂道十办议), VLAN ( Vir tualLocalAreaNetwork, 虚拟局域网 ), MPLS ( Mul t i-Pro toco 1 Label Swi tching, 多协议标签 交换) 等协议封装方式, 或釆用其它标准或自定义格式, 本发明不 做限定。
304、 入口网元根据入口流表项, 发送数据 4艮文至处理网元。 步骤 304 中,由于处理网元指示用于指示在入口网元后的下一 个处理数据报文的处理网元, 因此 304具体包括入口网元根据处理 网元指示, 发送数据报文至处理网元, 该处理网元指示可以为处理 网元的 MAC地址、 IP地址、 域名或自定义标识等转发信息。
305、 处理网元从入口网元接收数据报文, 从数据报文获取封装 流标识, 根据封装流标识获取处理流表项, 根据处理流表项, 对数 据^艮文进行上下文处理。 其中, 处理流表项包括匹配流标识和上下文处理指示, 匹配流 标识与封装流标识匹配。 可选的, 在步骤 305 中还包括: 当处理后的数据报文未包含封 装流标识时, 将流标识附加至处理后的数据报文; 其中流标识为封 装流标识, 或者当处理流表项还包括新的封装流标识时, 流标识为 新的封装流标识。
可选的, 处理流表项还包括处理封装指示; 处理封装指示用于 指示将流标识附加至处理后的所述数据报文; 上述处理后的数据报 文封装过程具体为处理网元根据处理封装指示将流标识附加至处理 后的数据报文。
306、 当处理流表项不包括再处理网元指示时, 处理网元向外发 送处理后的数据报文; 或者, 当处理流表项还包括再处理网元指示 时, 处理网元根据再处理网元指示, 发送处理后的数据报文至下一 个处理网元。 其中再处理网元指示用于指示在处理网元后的下一个处理数 据报文的处理网元。
具体的由于步骤 305 中包含处理网元的对处理后的数据报文的 封装过程, 因此步骤 306 中无论是处理网元发送处理后的数据报文 至报文处理系统外部或者处理网元根据再处理网元指示, 发送处理 后的数据报文至下一个处理网元, 处理后的数据报文均是附加有流 标识的。 本发明的实施例提供的报文处理方法,通过将报文转发至不同 的网元进行上下文处理,能够实现通过分布式的转发面设备分别对 报文进行上下文处理, 进而提高网络报文上下文处理的负载均衡 性。
具体的参照图 5所示,本发明的实施例提供的一种报文处理方 法, 通过上述报文处理系统实现, 包括以下步骤:
4 01、入口网元本地配置或者接收控制网元发送的入口流表项。 其中,控制网元用于控制入口网元和处理网元对所述数据报文 的转发或处理。 其中, 入口流表项包括: 流描述信息、 处理网元指 示。 流描述信息与数据报文匹配, 处理网元指示用于指示在入口网 元后的下一个处理数据报文的处理网元。 例如, 流描述信息可以包 括: 源 MAC ( Media Access Control , 介质访问控制 ) 地址、 目的 MAC地址, 源 IP ( Internet Protocol , 网络协议) 地址、 目 的 IP 地址, 源端口号、 目的端口号, MPLS Label ( mul t i-protocol label switching Label, 多十办议标签交换标记 ), ToS ( type of service, 业务类型 ), IPv6 flow lab le (Internet Protocol Version 6 flow lable,互联网协议版本 6 流标识), GRE key ( generic route encapsulation key , 通用 路由封装密钥 ), GTP TEID (GPRS Tunnelling Protocol Tunnel end point ID, 通用分组无线月良务 隧道协议隧道端点标识符)等一个或多个报文特征域的组合, 用于 确定报文是否属于本次处理的业务流。处理网元指示包括上下文处 理指示列表, 上下文处理指示列表包括上下文处理指示。 402、 入口网元接收数据才艮文。 通过步骤 402入口网元仅对数据报文具备收发功能,在功能上 入口网元与处理网元的分离部署的, 进一步可选的, 入口流表项还 包括入口上下文处理指示;入口上下文处理指示用于指示对数据报 文进行的上下文处理; 在步骤 402 中还包括, 入口网元根据入口上 下文处理指示, 对数据报文进行上下文处理。 此时入口网元包括报 文的上下文处理能力, 即此时入口网元与处理网元的合一部署的, 在入口网元功能上是包括一个处理网元的功能的。
403、 入口网元将上下文处理指示列表附加至数据报文, 确定 对数据报文进行的下一个上下文处理为上下文处理指示所指示的 上下文处理, 根据上下文处理指示和处理网元的对应关系, 发送数 据才艮文至处理网元。
可选的, 上下文处理指示列表还包括处理网元的寻址信息, 上 下文处理指示与处理网元的寻址信息对应。
步骤 403 中根据上下文处理指示和处理网元的对应关系, 发送 数据报文至处理网元具体为: 入口网元根据与上下文处理指示对应 的处理网元的寻址信息, 发送数据报文至处理网元。 404、 处理网元从入口网元接收数据报文, 从数据报文获取上 下文处理指示列表,根据上下文处理指示对数据报文进行上下文处 理。
405、 当上下文处理指示列表不包括其他上下文处理指示时, 处 理网元向外发送处理后的数据报文。
406、 当上下文处理指示列表还包括其他上下文处理指示时, 处 理网元确定对数据报文进行的下一个上下文处理为其他上下文处理 指示所指示的上下文处理, 在处理网元对数据报文进行上下文处理 之后, 根据其他上下文处理指示和其他处理网元的对应关系, 发送 处理后的数据报文至其他处理网元。
其中, 其他上下文处理指示对数据报文进行的上下文处理。 可选的, 上下文处理指示列表还包括其他处理网元的寻址信息, 其他上下文处理指示与所述其他处理网元的寻址信息对应。
在步骤 406 中根据其他上下文处理指示和其他处理网元的对应 关系, 发送处理后的数据报文至其他处理网元具体为, 处理网元根 据其他上下文处理指示对应的其他处理网元的寻址信息, 发送处理 后的数据报文至所述其他处理网元。 本发明的实施例提供的报文处理方法,通过将报文转发至不同 的网元进行上下文处理,能够实现通过分布式的转发面设备分别对 报文进行上下文处理, 进而提高网络报文上下文处理的负载均衡 性。
具体的以入口网元和处理网元分开部署( 即入口网元不包括对 才艮文的上下文处理能力 ) 为例, 参照图 6所示, 以 ^艮文经过入口网 元和三个处理网元的处理为例, 其中入口网元完成流匹配, 三个处 理网元分另' J对才艮文执行病毒防火墙、 DPI (Deep Packet Inspect ion, 深层报文检测)解析和 QoS ( Quality of Service, 服务质量) 控 制功能, 包括以下步骤:
501、 控制网元将入口流表项通过流表项安装消息下发到转发 面入口网元上。 入口流表项由流描述信息、 封装流标识 FID1 及处 理网元指示组成, 其中处理网元指示以转发信息 FWD infol为例, 该实施例中流描述信息以流匹配规则 ( Π ow match rule ) 为例进 行说明。 其中步骤 501 中以控制网元发送入口流表项为例, 当然入 口流表项亦可本地配置。 其中, 流匹配规则可以釆用如源、 目的 MAC 地址, 源、 目 的 IP地址, 源、 目的端口号, MPLS Label, ToS, IPv6 flow lable, GRE key, GTP TE I D等一个或多个报文特征域的组合, 用于确定报 文是否属于本次处理的同一业务流。转发信息包括用于确定待转发 的处理网元的信息, 如处理网元的 MAC 地址、 I P 地址、 域名或自 定义标识等。 以下述入口流表项为例:
<F 1 ow ent ry> : = {flow match rule, FID1 , Fwd infol (IP=ipl) }
502、 控制网元将处理流表项通过处理流表项安装消息下发到 一个或多个转发面处理网元上。其中步骤 502 中以控制网元发送处 理流表项为例 , 当然处理流表项亦可本地配置。 处理流表项包括匹配流标识、 上下文处理指示, 当需要处理网 元具备将数据报文转发至其他处理网元进行上下文处理时处理流 表项还包括封装流标识及转发信息,这里转发信息为再处理网元指 示。 例如: 发送给处理网元 1 的处理流表项如下:
<Flow entry> : = {FID1, [CID 1] , FID2, Fwd info2 (IP=ip2) } 发送给处理网元 2的处理流表项如下:
<Flow entry> : = {FID2, [CID 3], FID3, Fwd info3 (IP=ip3) } 发送给处理网元 3的处理流表项如下:
<Flow entry> : = {FID3, [CID 1, CID 4] }
503、 当数据报文到达入口网元后, 入口网元将数据报文与各 入口流表项的流匹配规则进行匹配。根据能匹配该数据 4艮文的入口 流表项, 入口网元将对应的封装流标识附加到数据报文上。 所述附 加可以釆用多种方式实现, 如将流标识作为 MPLS label、 GRE Key, GTP TEID 等, 对报文进行对应的协议封装, 本发明不做限定。 本 例中以 MPLS label 为例, 入口网元对数据 ^艮文执行 MPLS封装, 添 加 label为 FID1 的 MPLS报文头。入口网元根据转发信息将封装后 的才艮文发送到 IP地址为 ipl 的处理网元 1进行上下文处理。 其中入口流表项中还可以包括封装指示,步骤 503 中入口网元 具体根据入口封装指示将封装流标识附加至数据报文。
504、 处理网元 1根据数据报文的封装流标识 (本例中即 MPLS lable ), 查找具有相同匹配流标识的处理流表项。 并才艮据处理流表 项的内容对解除 MPLS封装的数据报文执行 CID1对应的本地上下文 处理, 例如, CID1 对应的上下文处理指示为执行木马病毒过滤, 则处理网元 1对 4艮文执行木马病毒检测和过滤功能。处理网元完成 本地上下文指示对应的上下文处理后, 将 FID2 作为 MPLS label 对报文执行 MPLS封装,并根据转发信息将封装报文发送到 IP地址 为 ip2 的处理网元 1进行上下文处理, 当然这里的上下文指示也可 以可以包括多个上下文处理。
505、 处理网元 2根据数据报文的封装流标识, 查找 FID2对应 的处理流表项, 并根据处理流表项的内容对报文执行 CID3对应的 本地上下文处理, 例如, CID3 对应的上下文处理指示为 P2P 深层 报文解析, 则处理网元 2 对报文执行 P2P 业务识别, 并可选地将 P2P业务识别的结果以元数据的形式附加到报文上。 处理网元 1根 据转发信息将报文发送到 IP地址为 ip3 的处理网元 3进行下一步 上下文处理。
506、 处理网元 3根据数据报文的封装流标识, 查找 FID3对应 的处理流表项, 根据 FID3对应的处理流表项, 对解除 MPLS封装的 报文执行 CID1 和 CID4对应的本地上下文处理, 如 CID1对应最大 带宽 2Mbps 控制、 CID4对应最高优先级转发。 完成上述 QoS控制 后, 由于处理流表项没有携带转发信息和封装流标识, 因此处理网 元 3直接将处理完成的报文按照正常的层 2层 3规则转发到外部网 络中。 需要注意的是,图 6数据报文在通过不同处理网元的上下文处 理后, 具体内容可能会发生变化。 在本实施例或其它实施例中, 各 个处理网元之间没有直接的关联关系,控制网元通过转发信息的控 制,可以使同一个处理网元在处理过程中多次出现并且每次针对不 同报文可以实现不同的上下文处理流程, 本发明不做限定。 通过以上入口网元和多个处理网元的上下文处理过程,转发面 网元共同完成了控制网元对该业务流指定的各种处理。通过引入流 标识, 使得报文只需要在入口网元执行一次报文匹配, 后续处理网 元就可以获取该报文所属的流信息,元数据使得各分布部署的处理 网元间可以共享处理特定的信息。 可选的, 以入口网元包括上下文处理功能为例( 即入口网元和 处理网元合一部署), 参照图 7 所示, 以 ^艮文经过入口网元和两个 处理网元为例, 其中入口网元完成流匹配和准入控制, 两个处理网 元分别对报文执行 QoS控制功能和计费功能, 包括以下步骤:
601、 控制网元将入口流表项通过入口流表项安装消息下发到 转发面入口网元上。其中步骤 601 中以控制网元发送入口流表项为 例 , 当然入口流表项亦可本地配置。 入口流表项由流描述信息、 入口上下文处理指示、 封装流标识 FID1 及处理网元指示组成, 其中处理网元指示以转发信息 FWD infol 为例, 该实施例中流描述信息以流匹配规则 ( Π ow match rule )为例进行说明。 其中步骤 601 中以控制网元发送入口流表项 为例, 当然入口流表项亦可本地配置。 入口上下文处理指示, 该入 口上下文处理指示可以为入口网元本地上下文处理列表 Local CID listl, 该列表中包含多个上下文处理。 其中的流匹配规则如上一实施例所述, 可以釆用报文特征域 (如 IP五元组、 GTP TEID等) 组合, 用于确定报文是否属于该业 务流。转发信息包括用于确定下一网元的信息,如网元的 MAC地址、 I P地址、 域名或自定义标识等。 本实施例以如下入口流表项为例:
<F 1 ow en t r y > : = {flow match rule, [CID 2] , FID1 , Fwd infol (ID=idl) } 602、 控制网元将处理流表项通过处理流表项安装消息下发到 用于处理该业务流的两个转发面处理网元上。其中步骤 602 中以控 制网元发送处理流表项为例, 当然处理流表项亦可本地配置。 处理流表项由匹配流标识、 上下文处理指示, 当需要处理网元 具备将数据报文转发至其他处理网元进行上下文处理时处理流表 项还包括封装流标识及转发信息, 这里转发信息为再处理网元指 示。 例如: 发送给处理网元 1 的处理流表项如下:
<Flow entry> : = {FID1, [CID 1, CID 4], FID2, Fwd info2 (ID=id2) } 发送给处理网元 2的处理流表项如下:
<Flow entry> : = {FID2, [CID 2, CID 3], NO-FID} 其中 N0-FID作为处理封装指示, 用于处理指示处理网元 1 不 需要对数据报文继续执行流标识封装。 在本实施例或其它实施例 中,处理封装指示也可以釆用特定 FID值或不携带 FID字段等方式 来表示, 本发明不做限定。
603、 当数据报文到达入口网元后, 入口网元执行流表项匹配。 由于本例中入口网元与处理网元合一部署,入口流表项中还包含有 本地上下文处理列表, 因此入口网元需要根据该数据报文所匹配的 入口流表项, 执行该流表项的本地上下文列表对应的上下文处理。 如入口网元的 CID2对应的上下文为对数据 ^艮文执行用户 IP准入控 制, 则入口网元根据数据报文的源、 目的 IP地址判断该报文是否 准许通过。 对通过上下文处理的数据报文, 入口网元将对应的封装 流标识附加到数据报文上。 本例中以釆用 GTP协议封装为例, 入口 网元对数据才艮文执行 GTP 装, 添力口 TEID ( Tunnel Endpoint ID P遂 道端点标识符) 为 FID1 的 GTP-U报文头。 入口网元根据转发信息 将封装后的数据报文发送到网元标识为 idl的处理网元 1进行上下 文处理。 人口网元可选地可以通过本地酉己置或 DNS ( Domain Name System, 域名系统) 等方式获得该网元标识对应的网元地址。 604、 处理网元 1根据数据报文的封装流标识, 查找 FID1对应 的处理流表项, 根据 FID1对应的处理流表项, 对解除 GTP封装后 的数据 4艮文执行 CID1和 CID4对应的本地上下文处理, 如 CID1对 应最大带宽 2Mbps控制、 CID4对应最高优先级转发。 完成上述 QoS 控制后, 处理网元 1 对用户执行 GTP封装, 附加 TEID 为 FID2 的 GTP-U报文头。 处理网元 1根据转发信息将封装后的数据报文发送 到网元标识为 i d2 的处理网元 2进行上下文处理。
605、 处理网元 2根据数据报文的封装流标识, 查找 FID2对应 的处理流表项, 根据 FID2对应的处理流表项, 对解除 GTP封装后 的数据报文执行 CID2和 CID3对应的本地上下文处理, 如 CID2对 应在线计费、 CID3 对应离线话单生成。 完成上述两项计费上下文 处理后, 由于流表项的处理封装指示为 N0_FID, 因此处理网元 1 直接将处理完成的报文转发到外部网络中,此时处理流表项不包括 再处理网元指示。 可选的, 本发明的实施例还提供了一种通过 openflow (开放 流, 简称 OF ) 协议的实现方式, 通过对 openfl ow协议的扩展实现 控制网元对各转发器上入口流表项及处理流表项的处理, 此时在 openf 1 ow协议下, 以 0F控制网元替代上述实施例中的控制网元, 以 0F转发器实现上述的入口网元及处理网元的功能, 参照图 8所 示, 具体的流程如下:
701、 0F控制网元通过 Flow_mod消息将入口流表项下发到 0F 转发器 1。 下发到 0F转发器 1 的 Flow_mod消息与入口流表项相同 由流描述信息、 封装流标识 FID1 及处理网元指示组成, 其中处理 网元指示以转发信息 FWD infol 为例, 该实施例中流描述信息以流 匹酉己规贝 'J ( flow match rule ) 为 列进行说明。 参照、上述实施列, 在本实施例中由于釆用转发器实现处理网元或入口网元的功能,相 应的处理网元指示在本实施例中用于指示在 0F转发器 1后的下一 个处理所述数据报文的 0F转发器,其中步骤 701 中以 0F控制网元 发送入口流表项为例 , 当然入口流表项亦可本地配置。 其中的流匹配信息如前述实施例所述, 可以釆用 4艮文特征域 (如 IP五元组、 GTP TEID等) 组合, 用于确定报文是否属于该业 务流。 封装流标识 FID1作为 Push_Tag动作的参数提供, 转发信息 作为 Output动作的参数提供。 本实施例以如下流表项为例:
<F 1 ow_mod>: = {of -match (n-Tuple) , ofp_ instruct ions [push -tag (FID1) , Output (2) ] }
702、 OF 控制网元将处理流表项通过 Flow_mod 消息下发到用 于处理该业务流的两个 0F转发器上。其中步骤 702 中以 0F控制网 元发送处理流表项为例, 当然处理流表项亦可本地配置。
下发到 0F转发器 1之外其他 0F转发器的 Flow_mod消息与处 理流表项相同包括匹配流标识、 上下文处理指示, 当需要其他 0F 转发器具备将数据报文转发至另外的 0F转发器进行上下文处理时 Flow-mod 消息还包括封装流标识及转发信息, 这里转发信息为再 处理网元指示。 例如:
发送给 0F转发器 1 的流表项如下:
<F 1 ow_mod> : = {of p_match (FID1) , of _ ins truct ions [Context [CID1] , Output (1) ] } 发送给 OF转发器 3的流表项如下:
<F 1 ow_mod> : = {of - ma tch (FID1) , of p. ins truct ions [Context [C ID1 , C I D2 ], Pop.Tag (),
Output (2) ] } 其中 Con t ex t表示执行相应上下文处理的动作。
Push_Tag/Pop_Tag 表示对报文执行封装和解封装。 本例中以 MPLS标签为例, 即 Push— Tag动作为将 FID作为 MPLS标签封装到 报文上, Pop_Tag 动作为将 MPLS 标签从报文去除。 同样 FID 的封 装也可以釆用 GRE、 GTP或其它协议形式, 本发明不做限定。 Output 动作为将报文从相应的端口发送出去。 在本实施例或 其它实施例中,封装指示也可以釆用特定 FID值或不携带 FID字段 等方式来表示, 本发明不做限定。
703、 当数据报文到达 0F转发器 1 后, 0F转发器 1 执行流表 项匹配, 并通过执行 Push_Tag (FID1)操作, 将对应的封装流标识 增加到数据报文上。 本例中以釆用 MPLS协议封装为例, OF转发器 1 将 MPLS 标签为 FID1 的 MPLS 头添加到报文, 并根据转发信息 ( Output动作的参数) 将数据报文通过端口 1发送到 OF转发器 1 进行上下文处理。
704、 OF转发器 2 根据数据报文的 MPLS域进行流表项匹配, 根据 FID1对应的处理流表项,对数据报文执行 CID1对应的本地上 下文处理, 如 CID1 对应 IPv4 文重组上下文操作。 0F 转发器 2 将完成 IPv4报文重组的数据报文通过自 己的端口 1发送到 0F转发 器 3进行上下文处理。
705、 0F转发器 3根据数据报文的 MPLS标签对数据报文执行 流表匹配, 根据 FID1 对应的处理流表项, 对数据报文执行 CID1 和 CID2对应的本地上下文处理,如 CID1对应最大带宽限制( 2Mbps ) 上下文操作、 CID2对应离线计费上下文操作。 0F转发器 3在完成 上述最大带宽限制和离线计费操作后,根据 Pop_Tag动作将数据报 文所包含的 FID信息 (本例中即 MPLS标签) 去除, 并根据 Output 动作通过自 己的端口 2将数据报文转发到外部网络中。 本实施例中, 通过下发不同的流规则, 0F 转发器 1 也可以在 转发报文到其它处理网元之前执行部分上下文处理, 如步骤 701 中, 下发流规则:
<F 1 ow_mod>: = {of -match (n-Tuple) , ofp_ instruct ions [Con t ext (CID1) , ush. tag (FID1) , Output (2) ] } 则 OF转发器 1在执行完 CID1对应的上下文处理后,再对处理 后报文执行流标识封装及转发。
可选的, 具体的以入口网元和处理网元分开部署为例, 参照图
9所示, 以 ^艮文经过入口网元和两个处理网元为例, 其中, 入口网 元完成流匹配,两个处理网元分别对 4艮文执行 QoS/计费控制和 GTP 封装 /解封装功能。 各网元根据上下文列表中携带的处理网元寻址 信息确定下一处理网元, 包括以下步骤: 801、 控制网元将入口流表项通过入口流表项安装消息下发到 转发面入口网元上。
其中步骤 801 中以控制网元发送入口流表项为例, 当然入口流 表项亦可本地配置, 入口流表项包括: 流描述信息、 处理网元指示 处理网元指示包括上下文处理指示列表 CID list, 上下文处理指 示列表包括上下文处理指示, 处理网元的寻址信息。
流描述信息以流匹配规则 ( f 1 ow match rule ) 为例, 参照以 上各实施例的描述这里不再赘述, 用于确定报文是否属于该业务 流。 上下文处理指示列表 CID list 包括转发面需要对该报文执行 的所有上下文处理的上下文处理指示,及各上下文处理指示所对应 的处理网元的寻址信息 (如 IP地址、 标识或域名等)。 以如下流表 项为例:
<F 1 ow en t r y > : = {flow match rule,
[NIDI, CID1] , [NID2, (CID3, CID4) ] , [NID3, CID5] } 本实施例中以如下具体上下文处理为例: CID1 对应 GTP 解封 装、 CID3对应 2Mbps带宽控制、 CID4对应离线计费、 CID5对应 GTP 封装 ( src_ ip=ipl, dst_ip=ip2, TEID=0x0004 )。 本实施例中,各转发面网元根据上下文处理指示列表 C ID list 中的 N I D确定下一网元, 本例中 N I D釆用 I P地址, 同样可以釆用 其他标识类型如域名、 自定义标识等, 本发明不做限定。
802、 当数据报文到达入口网元后, 入口网元执行流表项匹配。 入口 网元将匹配该数据 4艮文的流表项中对应的上下文处理指示列 表添加到报文上, 并根据转发网元列表的顺序,将报文发送到 NIDI 对应的处理网元。 具体的报文封装格式可以釆用 自定义信元的形 式, 本发明不做限定, 一种可能的报文格式如下:
<interim_packet>: ={[NIDl, CIDl] , [NID2, (CID3, CID4) ] , [NI D 3 , C I D5 ] , [user packet]}
803、 处理网元 1 按照上述数据报文中上下文处理指示列表, 按照列表顺序, 对其中的报文执行自 己能够处理的上下文处理指 示,直至上下文处理指示列表中下一个上下文处理指示对应的上下 文处理不属于本网元处理为止。
本实施例中, 处理网元 1根据 CID1对应的上下文处理指示对 报文执行 GTP 解封装操作。 由于列表中的下一个上下文处理指示 CID3 对应的上下文处理不属于入口网元, 因此入口网元将剩余的 上下文处理指示列表及完成解封装处理后的数据报文,发送到下一 个上下文处理对应的处理网元标识 N I D2对应的处理网元。 一种可 能的报文格式如下:
<inter im_packet>: = { [NID2, (CID3, CID4) ] , [NID3, CID5] , [user packet] }
804、处理网元 1按照上述数据报文中携带的上下文处理列表, 对报文顺序执行各上下文处理,直至列表中下一个上下文处理指示 对应的上下文不属于本网元处理为止。 本实施例中, 处理网元 2根据 CID3对应的上下文处理对报文 执行最大带宽 2Mbps 的控制, 并对通过带宽控制的数据报文根据 CID4 对应的上下文处理执行离线计费。 由于上下文处理指示列表 中的下一个上下文处理指示 CID5对应的上下文处理不属于处理网 元 2, 因此处理网元 2将剩余的上下文处理指示列表及完成离线计 费后的数据报文, 发送到下一个上下文处理对应的处理网元标识 NIDI 对应的处理网元。 具体的报文封装格式可以釆用 自定义信元 的形式, 本发明不做限定, 一种可能的报文格式如下:
< inter im_packet>: ={[NID1, CID5] , [user packet]}
805、处理网元 1根据上述消息中携带的上下文处理指示列表, 对其中的数据 4艮文 user packet执行 CID5对应的 GTP封装上下文 处理, 即将该上下文处理指示指定的 GTP-U 报文头封装到该报文 上。 完成上述封装上下文处理后, 由于上下文处理指示列表中的上 下文处理已经全部执行完毕, 因此处理网元 2直接将处理完成的报 文转发到外部网络中。 通过以上入口网元和多个处理网元的处理, 4艮文完成控制网元 指定的一系列上下文处理, 并最终被发送到外部网络中。 需要注意的是, 图 9 中统一釆用 user packet指代待处理的报 文, 釆用 CID list表示上下文处理指示, 釆用 NE list表示处理 网元列表。但在通过不同处理网元的上下文处理后,如步骤中所述, 具体 user packet和 CID list, NE 1 i s t 的内容可能会发生变化。 可选的, 以入口网元包括上下文处理功能为例( 即入口网元和 处理网元合一部署), 参照图 10所示, 以 ^艮文经过入口网元和两个 处理网元为例, 其中, 入口网元完成流匹配及 GTP解封装, 两个 处理网元分别对报文执行 QoS/计费控制和 GTP 封装功能。 各网元 根据 CID列表确定下一处理网元, 包括以下步骤: 901、 控制网元将入口流表项通过入口流表项安装消息下发到 转发面入口网元上。
其中步骤 801 中以控制网元发送入口流表项为例, 当然入口流 表项亦可本地配置, 入口流表项包括: 流描述信息、 处理网元指示 处理网元指示包括上下文处理指示列表 CID list, 上下文处理指 示列表包括上下文处理指示, 处理网元的寻址信息。 流描述信息以流匹配规则 ( f 1 ow match rule ) 为例, 参照以 上各实施例的描述这里不再赘述, 以如下流表项为例:
<Flow entry> : = {flow match rule, [CID1, CID3, CID4, CID5] } 本实施例中以如下具体上下文处理为例: CID1 对应 GTP 解封 装、 CID3对应 2Mbps带宽控制、 CID4对应离线计费、 CID5对应 GTP 封装 ( src_ ip=ipl, dst_ip=ip2, TEID=0x0002 )。 本实施例中, 各转发面网元根据 CID确定下一网元, 因此 CID 为处理网元的寻址信息。 几种可能的实现方式包括: CID部分字段 为处理网元标识信息 (如 IP地址、 域名、 名称标识等); 或各转发 网元可以根据本地配置信息或计算规则,将 CID映射为对应的网元 标识信息;或各转发面网元通过能够将 CID映射为网元标识的中继 网元转发到对应处理网元等方式, 本发明不做限定。
902、 当数据报文到达入口网元后, 入口网元执行流表项匹配。 由于本例中入口网元与处理网元合一部署, 因此入口流表项还包括 入口上下文处理指示,该入口上下文处理指示可以包含在上下文处 理指示列表中, 此时入口网元按照上下文处理指示列表的顺序, 对 执行本地可可执行的上下文处理,直至上下文处理指示列表中下一 个上下文处理指示对应的上下文处理不属于本网元为止。 本实施例中, 入口网元根据 CID1 对应的上下文处理对 ^艮文执 行 GTP解封装操作。 由于列表中的下一个上下文处理指示 CID3对 应的上下文处理不属于入口网元, 因此入口网元将剩余的上下文处 理指示列表附加到解封装后的数据报文上, 发送到 CID2对应的处 理网元 1。 具体的报文封装格式可以釆用 自定义信元的形式, 本发 明不做限定, 一种可能的报文格式如下:
< inter im_packet>: ={[CID3, CID4, CID5] , [user packet] }
903、 处理网元 1 按照数据报文中携带的上下文处理指示列表 的顺序, 对各上下文执行顺序处理, 直至上下文处理指示列表中下 一个上下文处理指示对应的上下文处理不属于本网元处理为止。 本实施例中, 处理网元 1根据 CID3对应的上下文处理对报文 执行最大带宽 2Mbps 的控制, 并对通过带宽控制的报文根据 CID4 对应的上下文执行离线计费。由于上下文处理指示列表中的下一个 上下文处理指示 CID5 对应的上下文处理不属于处理网元 1, 因此 处理网元 1将包含有剩余的上下文处理指示列表的数据报文,继续 转发到 CID5对应的处理网元。 具体的报文封装格式可以釆用 自定 义信元的形式, 本发明不做限定, 一种可能的报文格式如下:
< inter im_packet>: ={ [ CID5] , [user packet]}
904、处理网元 1根据上述消息中携带的上下文处理指示列表, 执行 CID5对应的 GTP封装上下文处理,将上下文处理指定的 GTP-U 报文头封装到该数据报文上。 完成上述封装上下文处理后, 由于上 下文列表中的上下文已经全部执行完毕, 因此处理网元 2直接将处 理完成的 4艮文转发到外部网络中。 通过以上入口网元和多个处理网元的处理,数据 4艮文完成控制 网元指定的一系列上下文处理, 并最终被发送到外部网络中。 本实 施例中,各网元根据 CID确定下一地址,因此根据不同的 CID列表, 报文可能会重复经过某一个处理网元, 本发明不做限定。 可选的, 本发明的实施例还提供了一种通过 openflow ( 简称 OF ) 协议的实现方式, 通过对 openflow协议的扩展实现控制网元 对各转发器上入口流表项及处理流表项的处理, 此时在 openflow 协议下, 以 OF控制网元替代上述实施例中的控制网元, 以 OF转发 器实现上述的入口网元及处理网元的功能, 参照图 11, 具体的流 程如下:
1001、 0F控制网元通过 Flow— mod消息将入口流表项下发到 0F 转发器 1。 流表项由流描述信息 flow match rule, 上下文标识列 表组成。其中上下文标识列表可选地还包括执行各上下文的转发器 标识。
下发到 0F转发器 1 的 Flow_mod消息与入口流表项相同包括: 流描述信息、处理网元指示处理网元指示包括上下文处理指示列表 CID list, 上下文处理指示列表包括上下文处理指示, 0F 转发器 的寻址信息。 相应的处理网元指示在本实施例中用于指示在 0F转 发器 1后的下一个处理所述数据报文的 0F转发器, 其中步骤 1001 中以 0F控制网元发送入口流表项为例, 当然入口流表项亦可本地 配置。 该实施例中流描述信息以流匹配规则 ( Π ow match rule ) 为 例进行说明, 用于确定报文是否属于该业务流。 上下文处理指示列 表作为 Push_CID动作的参数提供。 本实施例以如下流表项为例:
<F 1 ow_mod>: = {of -match (n-Tuple) , ofp_ instruct ions [push _cid ( [NIDI, CID1] , [NID2, CID1, CID3] ) , Output (2) ] } 本实施例中, 釆用网元所在端口号作为 NID, 同样 NID可以釆 用网元 IP地址、 MAC地址、 域名等表示, 或由转发器根据 CID 的 部分或全部映射获得寻址信息。 本发明不做限定。
1002、 当数据报文到达 0F转发器 1后, 0F转发器 1执行流表 项匹配, 并通过执行 ush.cid ( [NIDI, CID1] , [NID2, CID1, CID3] ) 操作, 将该报文相应的上下文处理指示列表附加到报文上。 附加方 式可以釆用 自定义信元来实现, 本发明不做限定。 0F 转发器 1 根 据寻址信息 ( Output 动作的参数) 或第一个上下文处理指示对应 的 OF转发器的标识 NID, 将数据报文通过对应的端口发送到 OF转 发器 2进行上下文处理。
1003、 OF 转发器 2 根据报文携带的上下文处理指示列表, 对 解析, 则 0F转发器 2对数据报文执行 DPI解析, 并可选地将解析 结果以 metadata (元数据) 的方式附加到报文上。 0F转发器 1将 已执行的上下文处理指示从数据报文携带的上下文处理指示列表 中删除, 并根据后续上下文处理指示中的寻址信息, 将报文发送到 NID2对应的 0F转发器 3进行上下文处理。 此处, 当上下文处理指示列表中不包含单独的转发器标识时, 0F转发器 1 也可以根据后续 CID 的标识映射出下一处理器的寻址 信息, 本发明不做限定。
1004、 0F转发器 3根据报文携带的上下文处理指示列表, 对 报文执行 CID1 和 CID3对应的上下文处理, 如 CID1对应最大带宽 限制 ( 2Mbps ) 上下文操作、 CID3对应转发 (端口 1 ) 上下文处理。 0F 转发器 3 将上述上下文处理指示从数据报文携带的上下文处理 指示列表中删除, 并完成上述最大带宽限制和转发操作, 将处理完 成的数据报文转发到外部网络中。
本实施例中, 通过下发不同的流规则, 0F 转发器 1 也可以在 转发数据报文到其它 0F转发器之前执行部分上下文处理。 如步骤 1001 中, 下发 Flow— mod消息:
<F 1 ow_mod>: = {of -match (n-Tuple) , ofp_ instruct ions [Con t ext (CID1) , push.cid ( [NIDI, CID1] , [NID2, CID1, CID3] ) , Output (2) ] } 则 OF转发器 1在对接收的数据报文执行完 CID0对应的上下文 处理后, 再对处理后数据报文附加 CID列表及转发。 对于上述基于 0F的方案, 使用 of p_ instruct ion指示转发器 执行的动作, 如上下文处理或流标识封装解封装, 转发等。 同样也 可以釆用 openf low 的动作列表或逻辑端口 /虚端口机制实现上述 处理, 本文不再赘述。 本发明的实施例提供的报文处理方法,通过将报文转发至不同 的网元进行上下文处理, 能够实现通过分布式的转发面设备对报文 的上下文处理, 进而提高网络报文上下文处理的负载均衡性。 参照图 1 2 所示, 本发明的实施例提供一种入口网元, 用于实 现上述的 4艮文处理方法, 该入口网元, 包括:
接收单元 1 1 , 用于接收数据报文; 发送单元 1 2 , 用于根据入口流表项, 发送所述接收单元 1 1 接 收的所述数据报文至处理网元, 以使所述处理网元对所述数据报文 进行上下文处理;
其中, 所述入口流表项包括流描述信息和处理网元指示, 所述 流描述信息与所述数据报文匹配, 所述处理网元指示用于指示在所 述入口网元后的下一个处理所述数据报文的处理网元。
可选的, 所述入口流表项还包括封装流标识; 其中, 所述封装 流标识用于标识所述数据报文所属的业务流;
所述入口网元还包括流标识封装单元 1 3 , 用于将所述封装流标 识附加至所述数据报文, 以使所述处理网元从所述数据报文获取所 述封装流标识, 根据所述封装流标识获取处理流表项, 并根据所述 处理流表项对所述数据报文进行上下文处理。 可选的, 所述入口流表项还包括入口封装指示, 所述入口封装 指示用于指示将所述封装流标识附加至所述数据报文;
所述流标识封装单元 1 3 具体用于根据所述入口封装指示将所 述封装流标识附加至所述数据报文。
可选的, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发 或处理。
可选的, 所述处理网元指示包括上下文处理指示列表, 所述上 下文处理指示列表包括所述上下文处理指示; 所述入口网元还包括处理指示附加单元 1 4 , 用于将所述上下文 处理指示列表附加至所述数据报文;
所述发送单元 1 2 具体用于确定对所述数据报文进行的下一个 上下文处理为所述上下文处理指示所指示的上下文处理, 根据所述 上下文处理指示和所述处理网元的对应关系, 发送所述数据报文至 所述处理网元。
可选的, 所述上下文处理指示列表还包括所述处理网元的寻址 信息, 所述上下文处理指示与所述处理网元的寻址信息对应;
所述发送单元 1 2 具体用于根据与所述上下文处理指示对应的 所述处理网元的寻址信息, 发送所述数据报文至所述处理网元。
可选的, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发。
进一步可选的, 所述入口流表项还包括入口上下文处理指示; 所述入口上下文处理指示用于指示对所述数据报文进行的上下文处 理; 所述入口网元还包括: 处理单元 1 5 ; 所述处理单元 1 5用于根据所述入口上下文处理指示,对所述数 据报文进行上下文处理。
本发明的实施例提供的入口网元,通过将报文转发至不同的网 元进行上下文处理, 能够实现通过分布式的转发面设备对报文的上 下文处理, 进而提高网络报文上下文处理的负载均衡性。 参照图 1 3所示, 本发明的实施例提供一种处理网元, 用于实现 上述的报文处理方法, 包括:
接收单元 2 1用于接收数据报文;
处理单元 1 1 用于根据上下文处理指示, 对所述接收单元 2 1 接 收的所述数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。 可选的, 所述处理单元 22具体用于从所述数据报文获取封装流 标识, 根据所述封装流标识获取处理流表项, 根据所述处理流表项, 对所述数据报文进行上下文处理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配 流标识与所述封装流标识匹配。 所述处理单元 22还用于将流标识附加至处理后的所述数据报文; 其 中所述流标识为所述封装流标识, 或者当所述处理流表项还包括新 的封装流标识时, 所述流标识为所述新的封装流标识。
可选的, 所述处理流表项还包括处理封装指示; 所述处理封装 指示用于指示将所述流标识附加至处理后的所述数据报文;
所述处理单元 2 2 具体用于根据所述处理封装指示将所述流标 识附加至处理后的所述数据报文。
可选的, 处理网元还包括: 发送单元 2 3 ;
当所述处理流表项不包括再处理网元指示时, 所述发送单元 2 3 向外发送所述处理单元 22处理后的所述数据报文; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述发送单 元 2 3根据所述再处理网元指示, 发送所述处理单元 22 处理后的所 述数据报文至下一个处理网元;
其中, 所述再处理网元指示用于指示在所述处理网元后的下一 个处理所述数据报文的处理网元。
可选的, 所述处理流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述处理网元对所述数据报文的转发 或处理。
可选的,
所述处理单元 2 2 具体用于从所述数据报文获取上下文处理指 示列表, 所述上下文处理指示列表包括所述上下文处理指示, 根据 所述上下文处理指示对所述数据报文进行上下文处理。 可选的, 所述处理网元还包括: 发送单元 2 3 ;
当所述上下文处理指示列表不包括其他上下文处理指示时, 所 述发送单元 2 3向外发送所述处理单元 22处理后的所述数据报文; 或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述发送单元 2 3确定对所述数据报文进行的下一个上下文处理 为所述其他上下文处理指示所指示的上下文处理, 在所述处理单元 22对所述数据报文进行上下文处理之后, 根据所述其他上下文处理 指示和其他处理网元的对应关系, 发送所述处理单元 2 2处理后的所 述数据报文至所述其他处理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
可选的, 所述上下文处理指示列表还包括所述其他处理网元的 寻址信息, 所述其他上下文处理指示与所述其他处理网元的寻址信 息对应;
所述发送单元 2 3 具体用于根据所述其他上下文处理指示对应 的所述其他处理网元的寻址信息, 发送所述处理单元处理后的所述 数据报文至所述其他处理网元。 本发明的实施例提供的处理网元,通过将入口网元转发的数据 报文在不同的处理网元进行上下文处理, 能够实现通过分布式的转 发面设备对报文的上下文处理, 进而提高网络报文上下文处理的负 载均衡性。
参照图 1 4所示, 本发明的实施例提供一种入口网元, 用于实现 上述的报文处理方法, 该入口网元可以釆用报文处理服务器实现, 包括: 通信单元 31、 存储器 32及总线 3 3 , 其中通信单元 31、 存储 器 32通过总线 3 3连接并实现相互通信,所述存储器 32用于存储所 述通信单元 31处理的数据;
该通信单元 31 可以为收发全双工的工作方式的网卡或者收发 电路; 该总线 33可以是 I SA ( Industry Standard Architecture , 工业标 准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标 准体系结构) 总线等。 该总线 33可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 14中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中:
存储器 32 用于存储可执行程序代码, 该程序代码包括计算机 操作指令。 存储器 32可能包含高速 RAM存储器, 也可能还包括非 易失性存储器 ( non-volatile memory ) , 例如至少一个磁盘存储器。
通信单元 3 1 , 用于接收数据报文; 根据入口流表项, 发送所述 通信单元 3 1接收的所述数据报文至处理网元, 以使所述处理网元对 所述数据报文进行上下文处理;
其中, 所述入口流表项包括流描述信息和处理网元指示, 所述 流描述信息与所述数据报文匹配, 所述处理网元指示用于指示在所 述入口网元后的下一个处理所述数据报文的处理网元。
可选的, 所述入口流表项还包括封装流标识; 其中, 所述封装 流标识用于标识所述数据报文所属的业务流;
所述入口网元还包括: 与所述总线连接的处理器 34 , 处理器 34可能是一个中央处理器( Central Processing Unit , 简 称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。
处理器 34 用于将所述封装流标识附加至所述数据报文, 以使 所述处理网元从所述数据报文获取所述封装流标识, 根据所述封装 流标识获取处理流表项, 并根据所述处理流表项对所述数据报文进 行上下文处理。
可选的, 所述入口流表项还包括入口封装指示, 所述入口封装 指示用于指示将所述封装流标识附加至所述数据报文;
处理器 34 具体用于根据所述入口封装指示将所述封装流标识 附加至所述数据报文。 可选的, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发 或处理。
可选的, 所述处理网元指示包括上下文处理指示列表, 所述上 下文处理指示列表包括所述上下文处理指示;
处理器 34 用于将所述上下文处理指示列表附加至所述数据报 文,
通信单元 31 用于确定对所述数据报文进行的下一个上下文处 理为所述上下文处理指示所指示的上下文处理, 根据所述上下文处 理指示和所述处理网元的对应关系, 发送所述数据报文至所述处理 网元。
可选的, 所述上下文处理指示列表还包括所述处理网元的寻址 信息, 所述上下文处理指示与所述处理网元的寻址信息对应;
所述通信单元 3 1 具体用于根据与所述上下文处理指示对应的 所述处理网元的寻址信息, 发送所述数据报文至所述处理网元。
可选的, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述入口网元对所述数据报文的转发。 进一步可选的, 所述入口流表项还包括入口上下文处理指示; 所述入口上下文处理指示用于指示对所述数据报文进行的上下文处 理;
处理器 34用于根据所述入口上下文处理指示, 对所述数据
Figure imgf000043_0001
本发明的实施例提供的入口网元,通过将报文转发至不同的网 元进行上下文处理, 能够实现通过分布式的转发面设备对报文的上 下文处理, 进而提高网络报文上下文处理的负载均衡性。 参照图 1 5 , 本发明的实施例提供一种处理网元, 用于实现上述 的报文处理方法, 该处理网元可以釆用报文处理服务器实现, 包括: 处理器 4 1、通信单元 42、存储器 4 3及总线 44 , 其中所述处理器 4 1、 通信单元 42及存储器 4 3通过总线 44连接并实现相互通信,所述存 储器 4 3用于存储所述处理器 4 1处理的程序代码; 该通信单元 4 2 可以为收发全双工的工作方式的网卡或者收发 电路; 该总线 44可以是 ISA ( Industry Standard Architecture , 工业标 准体系结构) 总线、 PCI ( Peripheral Component , 外部设备互连) 总线或 EISA ( Extended Industry Standard Architecture , 扩展工业标 准体系结构) 总线等。 该总线 44可以分为地址总线、 数据总线、 控 制总线等。 为便于表示, 图 15 中仅用一条粗线表示, 但并不表示仅 有一根总线或一种类型的总线。 其中:
存储器 43 用于存储可执行程序代码, 该程序代码包括计算机 操作指令。 存储器 43可能包含高速 RAM存储器, 也可能还包括非 易失性存储器 ( non-volatile memory ) , 例如至少一个磁盘存储器。
处理器 41可能是一个中央处理器( Central Processing Unit , 简 称为 CPU ) , 或者是特定集成电路 ( Application Specific Integrated Circuit , 简称为 ASIC ) , 或者是被配置成实施本发明实施例的一个 或多个集成电路。
所述通信单元 4 2用于接收数据报文;
处理器 4 1 用于根据上下文处理指示, 对所述通信单元 4 2接收 的所述数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上 下文处理。
可选的, 所述处理器 4 1具体用于从所述数据报文获取封装流标 识, 根据所述封装流标识获取处理流表项, 根据所述处理流表项, 对所述数据报文进行上下文处理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配 流标识与所述封装流标识匹配。 所述处理器 4 1还用于将流标识附加至处理后的所述数据报文; 其中 所述流标识为所述封装流标识, 或者当所述处理流表项还包括新的 封装流标识时, 所述流标识为所述新的封装流标识。
可选的, 所述处理流表项还包括处理封装指示; 所述处理封装 指示用于指示将所述流标识附加至处理后的所述数据报文;
所述处理器 4 1 具体用于根据所述处理封装指示将所述流标识 附加至处理后的所述数据报文。
当所述处理流表项不包括再处理网元指示时, 通信单元 4 2向外 发送所述处理器 4 1 处理后的所述数据报文至所述报文处理系统外 部; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述通信单 元 4 2根据所述再处理网元指示, 发送所述处理器 4 1 处理后的所述 数据报文至下一个处理网元;
其中, 所述再处理网元指示用于指示在所述处理网元后的下一 个处理所述数据报文的处理网元。
可选的, 所述处理流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用于控制所述处理网元对所述数据报文的转发 或处理。
可选的, 所述处理器 4 1具体用于从所述数据报文获取上下文处 理指示列表, 根据上下文处理指示对所述数据报文进行上下文处理, 所述上下文处理指示列表包括所述上下文处理指示。
当所述上下文处理指示列表不包括其他上下文处理指示时, 所 述通信单元 4 2向外发送所述处理器 4 1处理后的所述数据报文;
或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示 时, 所述通信单元 4 2确定对所述数据报文进行的下一个上下文处理 为所述其他上下文处理指示所指示的上下文处理, 在所述处理器 4 1 对所述数据报文进行上下文处理之后, 根据所述其他上下文处理指 示和其他处理网元的对应关系, 发送所述处理器 4 1处理后的所述数 据才艮文至所述其他处理网元; 其中, 所述其他上下文处理指示对所述数据报文进行的上下文 处理。
可选的, 所述上下文处理指示列表还包括所述其他处理网元的 寻址信息, 所述其他上下文处理指示与所述其他处理网元的寻址信 息对应;
所述通信单元 42 用于根据所述其他上下文处理指示对应的所 述其他处理网元的寻址信息, 发送所述处理器处理后的所述数据报 文至所述其他处理网元。
本发明的实施例提供的处理网元, 通过将报文转发至不同的网 元进行上下文处理, 能够实现通过分布式的转发面设备对报文的上 下文处理, 进而提高网络报文上下文处理的负载均衡性。
通过以上的实施方式的描述, 所属领域的技术人员可以清楚地 了解到本发明可以用硬件实现, 或固件实现, 或它们的组合方式来 实现。 当使用软件实现时, 可以将上述功能存储在计算机可读介质 中或作为计算机可读介质上的一个或多个指令或代码进行传输。 计 算机可读介质包括计算机存储介质和通信介质, 其中通信介质包括 便于从一个地方向另一个地方传送计算机程序的任何介质。 存储介 质可以是计算机能够存取的任何可用介质。 以此为例但不限于: 计 算机可读介质可以包括 RAM ( Random Access Memory, 随机存储器)、 R0M( Read Only Memory,只读内存)、 EEPR0M( Electrical ly Erasable Programmable Read Only Memory , 电可擦可编程只读存储器 )、 CD-ROM ( Compact Disc Read Only Memory, 即只读光盘 ) 或其他光 盘存储、 磁盘存储介质或者其他磁存储设备、 或者能够用于携带或 存储具有指令或数据结构形式的期望的程序代码并能够由计算机存 取的任何其他介质。 此外。 任何连接可以适当的成为计算机可读介 质。例如,如果软件是使用同轴电缆、光纤光缆、双绞线、 DSL( Digital Subscriber Line, 数字用户专线) 或者诸如红外线、 无线电和啟波 之类的无线技术从网站、 服务器或者其他远程源传输的, 那么同轴 电缆、 光纤光缆、 双绞线、 DSL 或者诸如红外线、 无线和微波之类 的无线技术包括在所属介质的定影中。 如本发明所使用的盘和碟包 括 CD ( Compact Disc, 压缩光碟)、 激光碟、 光碟、 DVD碟 ( Digital Versatile Disc, 数字通用光)、 软盘和蓝光光碟, 其中盘通常磁性 的复制数据, 而碟则用激光来光学的复制数据。 上面的组合也应当 包括在计算机可读介质的保护范围之内。
以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围 并不局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技 术范围内, 可轻易想到变化或替换, 都应涵盖在本发明的保护范围 之内。 因此, 本发明的保护范围应所述以权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种报文处理系统, 其特征在于, 包括:
入口网元, 用于从所述报文系统外部接收数据报文, 根据入口流 表项, 发送所述数据报文至处理网元; 所述入口流表项包括流描述信 息和处理网元指示, 所述流描述信息与所述数据报文匹配, 所述处理 网元指示用于指示在所述入口网元后的下一个处理所述数据报文的 处理网元;
所述处理网元, 用于从所述入口网元接收所述数据报文, 根据上 下文处理指示, 对所述数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上下 文处理。
2、 根据权利要求 1所述的系统, 其特征在于,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用于 标识所述数据报文所属的业务流;
所述入口网元还用于将所述封装流标识附加至所述数据报文; 所述处理网元具体用于从所述数据报文获取所述封装流标识, 根 据所述封装流标识获取处理流表项, 根据所述处理流表项, 对所述数 据报文进行上下文处理;
其中, 所述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配流标识与所述封装流标识匹配。
3、 根据权利要求 2所述的系统, 其特征在于,
所述入口流表项还包括入口封装指示; 其中, 所述入口封装指示 用于指示将所述封装流标识附加至所述数据报文;
所述入口 网元具体用于根据所述入口封装指示将所述封装流标 识附加至所述数据报文。
4、 根据权利要求 2或 3所述的系统, 其特征在于, 流标识时, 将流标识附加至处理后的所述数据报文; 其中所述流标识 为所述封装流标识, 或者当所述处理流表项还包括新的封装流标识 时, 所述流标识为所述新的封装流标识。
5、 根据权利要求 4所述的系统, 其特征在于,
所述处理流表项还包括处理封装指示; 所述处理封装指示用于指 示将所述流标识附加至处理后的所述数据报文;
所述处理网元还用于根据所述处理封装指示将所述流标识附加 至处理后的所述数据报文。
6、 根据权利要求 2- 5任一所述的系统, 其特征在于,
当所述处理流表项不包括再处理网元指示时, 所述处理网元还用 于发送处理后的所述数据报文至所述报文处理系统外部; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述处理网元 还用于根据所述再处理网元指示, 发送处理后的所述数据报文至下一 个处理网元;
其中所述再处理网元指示用于指示在所述处理网元后的下一个 处理所述数据报文的处理网元。
7、 根据权利要求 2- 6任一所述的系统, 其特征在于,
所述入口流表项和所述处理流表项是本地配置的或者是控制网 元发送的; 其中, 所述控制网元用于控制所述入口网元和所述处理网 元对所述数据报文的转发或处理。
8、 根据权利要求 1所述的系统, 其特征在于,
所述处理网元指示包括上下文处理指示列表, 所述上下文处理指 示列表包括所述上下文处理指示;
所述入口 网元具体用于将所述上下文处理指示列表附加至所述 数据报文, 确定对所述数据报文进行的下一个上下文处理为所述上下 文处理指示所指示的上下文处理, 根据所述上下文处理指示和所述处 理网元的对应关系, 发送所述数据报文至所述处理网元;
所述处理网元具体用于从所述数据报文获取所述上下文处理指 示列表, 根据所述上下文处理指示对所述数据报文进行上下文处理。
9、 根据权利要求 8所述的系统, 其特征在于,
所述上下文处理指示列表还包括所述处理网元的寻址信息, 所述 上下文处理指示与所述处理网元的寻址信息对应;
所述入口网元具体用于, 根据与所述上下文处理指示对应的所述 处理网元的寻址信息, 发送所述数据报文至所述处理网元。
1 0、 根据权利要求 8或 9所述的系统, 其特征在于,
当所述上下文处理指示列表不包括其他上下文处理指示时, 所述 处理网元还用于发送处理后的所述数据报文至所述报文处理系统外 部; 或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示时, 所述处理网元还用于确定对所述数据报文进行的下一个上下文处理 为所述其他上下文处理指示所指示的上下文处理, 在所述处理网元对 所述数据报文进行上下文处理之后, 根据所述其他上下文处理指示和 其他处理网元的对应关系, 发送处理后的所述数据报文至所述其他处 理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文处 理。
1 1、 根据权利要求 1 0 所述的系统, 其特征在于, 所述上下文处 理指示列表还包括所述其他处理网元的寻址信息, 所述其他上下文处 理指示与所述其他处理网元的寻址信息对应;
所述处理网元具体用于, 根据所述其他上下文处理指示对应的所 述其他处理网元的寻址信息, 发送处理后的所述数据报文至所述其他 处理网元。
1 2、 根据权利要求 8 - 1 1 任一所述的系统, 其特征在于, 所述入 口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元 用于控制所述入口网元对所述数据报文的转发。
1 3、 根据权利要求 1 - 1 2任一所述的系统, 其特征在于, 所述入口流表项还包括入口上下文处理指示; 所述入口上下文处 理指示用于指示对所述数据报文进行的上下文处理;
所述入口网元还用于根据所述入口上下文处理指示, 对所述数据 才艮文进行上下文处理。 1 4、 一种入口网元, 其特征在于, 包括:
接收单元, 用于接收数据报文;
发送单元, 用于根据入口流表项, 发送所述接收单元接收的所述 数据报文至处理网元, 以使所述处理网元对所述数据报文进行上下文 处理;
其中, 所述入口流表项包括流描述信息和处理网元指示, 所述流 描述信息与所述数据报文匹配, 所述处理网元指示用于指示在所述入 口网元后的下一个处理所述数据报文的处理网元。
1 5、 根据权利要求 1 4所述的入口网元, 其特征在于,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用于 标识所述数据报文所属的业务流;
所述入口网元还包括流标识封装单元, 用于将所述封装流标识附 加至所述数据报文, 以使所述处理网元从所述数据报文获取所述封装 流标识, 根据所述封装流标识获取处理流表项, 并根据所述处理流表 项对所述数据报文进行上下文处理。
1 6、 根据权利要求 1 5所述的入口网元, 其特征在于,
所述入口流表项还包括入口封装指示, 所述入口封装指示用于指 示将所述封装流标识附加至所述数据报文;
所述流标识封装单元具体用于根据所述入口封装指示将所述封 装流标识附加至所述数据报文。
1 7、 根据权利要求 1 5 - 1 6任一所述的入口网元, 其特征在于, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所 述控制网元用于控制所述入口网元对所述数据报文的转发或处理。
1 8、 根据权利要求 1 4所述的入口网元, 其特征在于,
所述处理网元指示包括上下文处理指示列表, 所述上下文处理指 示列表包括所述上下文处理指示;
所述入口网元还包括处理指示附加单元, 用于将所述上下文处理 指示列表附加至所述数据报文;
所述发送单元具体用于确定对所述数据报文进行的下一个上下 文处理为所述上下文处理指示所指示的上下文处理, 根据所述上下文 处理指示和所述处理网元的对应关系, 发送所述数据报文至所述处理 网元。
1 9、 根据权利要求 1 8所述的入口网元, 其特征在于,
所述上下文处理指示列表还包括所述处理网元的寻址信息, 所述 上下文处理指示与所述处理网元的寻址信息对应;
所述发送单元具体用于根据与所述上下文处理指示对应的所述 处理网元的寻址信息, 发送所述数据报文至所述处理网元。
2 0、 根据权利要求 1 8或 1 9所述的入口网元, 其特征在于, 所述 入口流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网 元用于控制所述入口网元对所述数据报文的转发。
2 1、 根据权利要求 1 4 - 2 0任一所述的入口网元, 其特征在于, 所述入口流表项还包括入口上下文处理指示; 所述入口上下文处 理指示用于指示对所述数据报文进行的上下文处理; 所述入口网元还 包括: 处理单元;
所述处理单元用于根据所述入口上下文处理指示, 对所述数据报 文进行上下文处理。
1 1、 一种处理网元, 其特征在于, 包括:
接收单元用于接收数据报文;
处理单元用于根据上下文处理指示, 对所述接收单元接收的所述 数据报文进行上下文处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上下 文处理。
2 3、 根据权利要求 1 1 所述的处理网元, 其特征在于, 所述处理 单元具体用于从所述数据报文获取封装流标识, 根据所述封装流标识 获取处理流表项, 根据所述处理流表项, 对所述数据报文进行上下文 处理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所 述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配流标 识与所述封装流标识匹配。
24、 根据权利要求 2 3所述的处理网元, 其特征在于, 元还用于将流标识附加至处理后的所述数据报文; 其中所述流标识为 所述封装流标识, 或者当所述处理流表项还包括新的封装流标识时, 所述流标识为所述新的封装流标识。
25、 根据权利要求 24所述的处理网元, 其特征在于,
所述处理流表项还包括处理封装指示; 所述处理封装指示用于指 示将所述流标识附加至处理后的所述数据报文;
所述处理单元具体用于根据所述处理封装指示将所述流标识附 加至处理后的所述数据报文。
26、 根据权利要求 2 3- 25任一所述的处理网元, 其特征在于, 所 述处理网元还包括: 发送单元;
当所述处理流表项不包括再处理网元指示时, 所述发送单元向外 发送所述处理单元处理后的所述数据报文; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述发送单元 根据所述再处理网元指示, 发送所述处理单元处理后的所述数据报文 至下一个处理网元;
其中, 所述再处理网元指示用于指示在所述处理网元后的下一个 处理所述数据报文的处理网元。
27、 根据权利要求 2 3-26任一所述的处理网元, 其特征在于, 所述处理流表项是本地配置的或者是控制网元发送的; 其中, 所 述控制网元用于控制所述处理网元对所述数据报文的转发或处理。
28、 根据权利要求 11 所述的处理网元, 其特征在于, 所述处理 单元具体用于从所述数据报文获取上下文处理指示列表, 所述上下文 处理指示列表包括所述上下文处理指示, 根据所述上下文处理指示对 所述数据报文进行上下文处理。
29、 根据权利要求 28 所述的处理网元, 其特征在于, 所述处理 网元还包括: 发送单元; 当所述上下文处理指示列表不包括其他上下文处理指示时, 所述 发送单元向外发送所述处理单元处理后的所述数据报文;
或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示时, 所述发送单元确定对所述数据报文进行的下一个上下文处理为所述 其他上下文处理指示所指示的上下文处理, 在所述处理单元对所述数 据报文进行上下文处理之后, 根据所述其他上下文处理指示和其他处 理网元的对应关系, 发送所述处理单元处理后的所述数据报文至所述 其他处理网元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文处 理。
30、 根据权利要求 29 所述的处理网元, 其特征在于, 所述上下 文处理指示列表还包括所述其他处理网元的寻址信息, 所述其他上下 文处理指示与所述其他处理网元的寻址信息对应;
所述发送单元具体用于根据所述其他上下文处理指示对应的所 述其他处理网元的寻址信息, 发送所述处理单元处理后的所述数据报 文至所述其他处理网元。
31、 一种报文处理方法, 其特征在于, 包括:
入口网元接收数据报文; 其中, 所述入口网元存有入口流表项, 所述入口流表项包括流描述信息和处理网元指示, 所述流描述信息与 所述数据报文匹配, 所述处理网元指示用于指示在所述入口网元后的 下一个处理所述数据报文的处理网元;
所述入口网元根据入口流表项, 发送所述数据报文至所述处理网 元, 以使所述处理网元对所述数据报文进行上下文处理。
32、 根据权利要求 31所述的方法, 其特征在于,
所述入口流表项还包括封装流标识; 其中, 所述封装流标识用于 标识所述数据报文所属的业务流; 所述方法还包括:
所述入口网元将所述封装流标识附加至所述数据报文, 以使所述 处理网元从所述数据报文获取所述封装流标识, 根据所述封装流标识 获取处理流表项, 并根据所述处理流表项对所述数据报文进行上下文 处理。
33、 根据权利要求 32所述的方法, 其特征在于,
所述入口流表项还包括入口封装指示, 所述入口封装指示用于指 示将所述封装流标识附加至所述数据报文;
所述入口网元将所述封装流标识附加至所述数据报文包括: 所述入口 网元根据所述入口封装指示将所述封装流标识附加至 所述数据报文。
34、 根据权利要求 32 - 3 3任一所述的方法, 其特征在于, 所述入口流表项是本地配置的或者是控制网元发送的; 其中, 所 述控制网元用于控制所述入口网元对所述数据报文的转发或处理。
35、 根据权利要求 31所述的方法, 其特征在于,
所述处理网元指示包括上下文处理指示列表, 所述上下文处理指 示列表包括所述上下文处理指示;
所述方法还包括: 所述入口网元将所述上下文处理指示列表附加 至所述数据报文;
所述入口网元根据入口流表项, 发送所述数据 4艮文至处理网元包 括:
所述入口 网元确定对所述数据报文进行的下一个上下文处理为 所述上下文处理指示所指示的上下文处理, 根据所述上下文处理指示 和所述处理网元的对应关系, 发送所述数据报文至所述处理网元。
36、 根据权利要求 35所述的方法, 其特征在于,
所述上下文处理指示列表还包括所述处理网元的寻址信息, 所述 上下文处理指示与所述处理网元的寻址信息对应;
所述根据所述上下文处理指示和所述处理网元的对应关系, 发送 所述数据报文至所述处理网元包括:
所述入口 网元根据与所述上下文处理指示对应的所述处理网元 的寻址信息, 发送所述数据报文至所述处理网元。
37、 根据权利要求 35或 36所述的方法, 其特征在于, 所述入口 流表项是本地配置的或者是控制网元发送的; 其中, 所述控制网元用 于控制所述入口网元对所述数据报文的转发。
38、 根据权利要求 31 - 37任一所述的方法, 其特征在于, 所述入口流表项还包括入口上下文处理指示, 所述入口上下文处 理指示用于指示对所述数据报文进行的上下文处理;
所述方法还包括:
所述入口网元根据所述入口上下文处理指示, 对所述数据报文进 行上下文处理。
39、 一种报文处理方法, 其特征在于, 包括:
处理网元接收数据报文;
所述处理网元根据上下文处理指示, 对所述数据报文进行上下文 处理;
其中, 所述上下文处理指示用于指示对所述数据报文进行的上下 文处理。
40、 根据权利要求 39 所述的方法, 其特征在于, 所述根据上下 文处理指示, 对所述数据报文进行上下文处理包括:
所述处理网元从所述数据报文获取封装流标识, 根据所述封装流 标识获取处理流表项, 根据所述处理流表项, 对所述数据报文进行上 下文处理;
其中, 所述封装流标识用于标识所述数据报文所属的业务流, 所 述处理流表项包括匹配流标识和所述上下文处理指示, 所述匹配流标 识与所述封装流标识匹配。
41、 根据权利要求 4 0 所述的方法, 其特征在于, 所述方法还包 括: 元将流标识附加至处理后的所述数据报文; 其中所述流标识为所述封 装流标识, 或者当所述处理流表项还包括新的封装流标识时, 所述流 标识为所述新的封装流标识。
42、 根据权利要求 4 1所述的方法, 其特征在于, 所述处理流表项还包括处理封装指示; 所述处理封装指示用于指 示将所述流标识附加至处理后的所述数据报文; 所述方法还包括: 所述处理网元根据所述处理封装指示将所述流标识附加至处理 后的所述数据报文。
4 3、 根据权利要求 40-42任一所述的方法, 其特征在于, 所述方 法还包括:
当所述处理流表项不包括再处理网元指示时, 所述处理网元向外 发送处理后的所述数据报文; 或者
当所述处理流表项还包括所述再处理网元指示时, 所述处理网元 根据所述再处理网元指示, 发送处理后的所述数据报文至下一个处理 网元;
其中, 所述再处理网元指示用于指示在所述处理网元后的下一个 处理所述数据报文的处理网元。
44、 根据权利要求 4 0-4 3任一所述的方法, 其特征在于, 所述所述处理流表项是本地配置的或者是控制网元发送的; 其 中, 所述控制网元用于控制所述处理网元对所述数据报文的转发或处 理。
45、 根据权利要求 39 所述的方法, 其特征在于, 所述根据上下 文处理指示, 对所述数据报文进行上下文处理包括:
所述处理网元从所述数据报文获取上下文处理指示列表, 所述上 下文处理指示列表包括所述上下文处理指示, 根据所述上下文处理指 示对所述数据报文进行上下文处理。
46、 根据权利要求 45 所述的方法, 其特征在于, 所述方法还包 括:
当所述上下文处理指示列表不包括其他上下文处理指示时, 所述 处理网元向外发送处理后的所述数据报文;
或者,
当所述上下文处理指示列表还包括所述其他上下文处理指示时, 所述处理网元确定对所述数据报文进行的下一个上下文处理为所述 其他上下文处理指示所指示的上下文处理, 在所述处理网元对所述数 据报文进行上下文处理之后, 根据所述其他上下文处理指示和其他处 元;
其中, 所述其他上下文处理指示对所述数据报文进行的上下文处
47、 根据权利要求 46 所述的方法, 其特征在于, 所述上下文处 理指示列表还包括所述其他处理网元的寻址信息, 所述其他上下文处 理指示与所述其他处理网元的寻址信息对应; 所述发送处理后的所述 数据报文至所述其他处理网元包括:
所述处理网元根据所述其他上下文处理指示对应的所述其他处 理网元的寻址信息,
元。
PCT/CN2013/091187 2013-12-31 2013-12-31 一种报文处理方法、装置及系统 Ceased WO2015100650A1 (zh)

Priority Applications (7)

Application Number Priority Date Filing Date Title
CN201910444551.XA CN110138618B (zh) 2013-12-31 2013-12-31 一种报文处理方法、装置及系统
PCT/CN2013/091187 WO2015100650A1 (zh) 2013-12-31 2013-12-31 一种报文处理方法、装置及系统
CN201380077723.5A CN105340217B (zh) 2013-12-31 2013-12-31 一种报文处理方法、装置及系统
EP13900610.0A EP3079301B1 (en) 2013-12-31 2013-12-31 Packet processing method, apparatus and system
RU2016131169A RU2630178C1 (ru) 2013-12-31 2013-12-31 Способ, устройство и система обработки пакетов
US15/199,494 US10412008B2 (en) 2013-12-31 2016-06-30 Packet processing method, apparatus, and system
US16/526,518 US20190356594A1 (en) 2013-12-31 2019-07-30 Packet Processing Method, Apparatus, and System

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2013/091187 WO2015100650A1 (zh) 2013-12-31 2013-12-31 一种报文处理方法、装置及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/199,494 Continuation US10412008B2 (en) 2013-12-31 2016-06-30 Packet processing method, apparatus, and system

Publications (1)

Publication Number Publication Date
WO2015100650A1 true WO2015100650A1 (zh) 2015-07-09

Family

ID=53492992

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/091187 Ceased WO2015100650A1 (zh) 2013-12-31 2013-12-31 一种报文处理方法、装置及系统

Country Status (5)

Country Link
US (2) US10412008B2 (zh)
EP (1) EP3079301B1 (zh)
CN (2) CN110138618B (zh)
RU (1) RU2630178C1 (zh)
WO (1) WO2015100650A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018176272A1 (zh) * 2017-03-29 2018-10-04 华为技术有限公司 处理报文的方法和装置
CN109302540A (zh) * 2017-07-25 2019-02-01 中兴通讯股份有限公司 一种融合通讯业务的受理方法、装置及设备

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108366436B (zh) 2012-06-29 2023-05-16 华为技术有限公司 信息处理方法、转发面设备和控制面设备
US10033693B2 (en) 2013-10-01 2018-07-24 Nicira, Inc. Distributed identity-based firewalls
US10324746B2 (en) 2015-11-03 2019-06-18 Nicira, Inc. Extended context delivery for context-based authorization
CN108024222B (zh) * 2016-11-01 2020-12-08 中国电信股份有限公司 流量话单生成方法和装置
US10802858B2 (en) * 2016-12-22 2020-10-13 Nicira, Inc. Collecting and processing contextual attributes on a host
CN110768810B (zh) * 2018-07-25 2021-03-30 华为技术有限公司 确定报文流描述的方法、装置和系统
US10986150B2 (en) 2019-03-01 2021-04-20 Netskope, Inc. Load balancing in a dynamic scalable services mesh
CN111953604B (zh) 2019-05-17 2023-07-18 华为技术有限公司 一种为业务流提供业务服务的方法和装置
CN110932968B (zh) * 2019-11-18 2021-05-14 华南理工大学 一种流量转发方法及装置
US11539718B2 (en) 2020-01-10 2022-12-27 Vmware, Inc. Efficiently performing intrusion detection
US11394650B2 (en) * 2020-04-14 2022-07-19 Charter Communications Operating, Llc Modificationless packet prioritization for frame generation
CN111988271B (zh) * 2020-06-30 2021-11-16 联想(北京)有限公司 一种通信流处理方法及装置
US11108728B1 (en) 2020-07-24 2021-08-31 Vmware, Inc. Fast distribution of port identifiers for rule processing
CN115720351A (zh) * 2021-08-23 2023-02-28 中兴通讯股份有限公司 信令采集监测系统、方法、网络设备和存储介质
CN117692490A (zh) * 2022-09-05 2024-03-12 中国移动通信有限公司研究院 一种信息处理方法、装置、设备及可读存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101009662A (zh) * 2007-01-31 2007-08-01 杭州华为三康技术有限公司 基于负载均衡技术的报文处理方法、系统及设备
CN102404179A (zh) * 2010-09-19 2012-04-04 杭州华三通信技术有限公司 一种报文处理的方法和装置
CN103152251A (zh) * 2013-02-27 2013-06-12 杭州华三通信技术有限公司 一种报文处理方法及装置

Family Cites Families (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FI100443B (fi) 1995-04-10 1997-11-28 Nokia Telecommunications Oy Liikenteen väylöitys tietoliikenneverkon solmussa
US8161156B2 (en) * 2009-12-30 2012-04-17 Verizon Patent And Licensing, Inc. Feature delivery packets for peer-to-peer based feature network
EP2596604A4 (en) * 2010-07-23 2016-06-08 Nec Corp COMMUNICATION SYSTEM, KNOT, DEVICE FOR COLLECTING STATISTICAL INFORMATION, METHOD FOR COLLECTING STATISTICAL INFORMATION AND PROGRAM
US9083657B2 (en) 2011-02-17 2015-07-14 Nec Corporation Flow communication system
EP2795515A4 (en) * 2011-12-22 2015-09-02 Intel Corp STILL AVAILABLE EMBEDDED THEFT REACTION SYSTEM
US8971338B2 (en) * 2012-01-09 2015-03-03 Telefonaktiebolaget L M Ericsson (Publ) Expanding network functionalities for openflow based split-architecture networks
US8923296B2 (en) * 2012-02-23 2014-12-30 Big Switch Networks, Inc. System and methods for managing network packet forwarding with a controller
US9215490B2 (en) * 2012-07-19 2015-12-15 Samsung Electronics Co., Ltd. Apparatus, system, and method for controlling content playback
CN102857416B (zh) * 2012-09-18 2016-09-28 中兴通讯股份有限公司 一种实现虚拟网络的方法、控制器和虚拟网络
US8953592B2 (en) * 2012-09-28 2015-02-10 Juniper Networks, Inc. Network address translation for application of subscriber-aware services
CN102938739B (zh) * 2012-11-26 2016-08-24 华为技术有限公司 深度报文检查方法与装置
CN103067295A (zh) * 2013-01-04 2013-04-24 华为技术有限公司 业务传输的方法、装置与系统
US9413667B2 (en) * 2013-02-15 2016-08-09 Telefonaktiebolaget Lm Ericsson (Publ) Methods and network nodes for traffic steering based on per-flow policies
CN103428031B (zh) * 2013-08-05 2016-04-13 浙江大学 一种基于软件定义网络的域间链路快速故障恢复方法
US9755960B2 (en) * 2013-09-30 2017-09-05 Juniper Networks, Inc. Session-aware service chaining within computer networks
US9363180B2 (en) * 2013-11-04 2016-06-07 Telefonkatiebolaget L M Ericsson (Publ) Service chaining in a cloud environment using Software Defined Networking

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101009662A (zh) * 2007-01-31 2007-08-01 杭州华为三康技术有限公司 基于负载均衡技术的报文处理方法、系统及设备
CN102404179A (zh) * 2010-09-19 2012-04-04 杭州华三通信技术有限公司 一种报文处理的方法和装置
CN103152251A (zh) * 2013-02-27 2013-06-12 杭州华三通信技术有限公司 一种报文处理方法及装置

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018176272A1 (zh) * 2017-03-29 2018-10-04 华为技术有限公司 处理报文的方法和装置
CN109302540A (zh) * 2017-07-25 2019-02-01 中兴通讯股份有限公司 一种融合通讯业务的受理方法、装置及设备

Also Published As

Publication number Publication date
CN110138618B (zh) 2021-10-26
CN105340217B (zh) 2019-05-28
EP3079301A4 (en) 2016-12-07
RU2630178C1 (ru) 2017-09-05
CN110138618A (zh) 2019-08-16
US20160315864A1 (en) 2016-10-27
EP3079301B1 (en) 2018-05-02
US20190356594A1 (en) 2019-11-21
CN105340217A (zh) 2016-02-17
US10412008B2 (en) 2019-09-10
EP3079301A1 (en) 2016-10-12

Similar Documents

Publication Publication Date Title
CN110138618B (zh) 一种报文处理方法、装置及系统
EP3958521B1 (en) Method and apparatus for providing service for service flow
EP4037267B1 (en) Method, apparatus and system for sending message
CN104322022B (zh) 多租户系统、交换机、控制器和分组传输方法
CN106921572B (zh) 一种传播QoS策略的方法、装置及系统
CN105830406A (zh) 用于支持软件定义网络中的灵活查找关键字的方法、设备和系统
WO2014176740A1 (zh) 流分类器、业务路由触发器、报文处理的方法和系统
US11522795B1 (en) End to end application identification and analytics of tunnel encapsulated traffic in the underlay
CN112019433A (zh) 一种报文转发方法和装置
WO2017198131A1 (zh) 用于重定向数据流的方法和系统、网络设备和控制设备
WO2023088145A1 (zh) 一种报文处理方法、装置及设备
CN108712338A (zh) 报文处理方法及装置
CN105591967B (zh) 一种数据传输方法和装置
CN114422415A (zh) 在分段路由中的出口节点处理流
WO2020135479A1 (zh) IPv4-in-IPv6 DS Lite数据流转发方法、系统、终端及介质
WO2024124260A2 (en) Ipv6 domain level segment routing using srh
WO2024108985A1 (zh) 一种随流检测方法、电子设备和存储介质
CN111770049B (zh) 全局缓存变量及报文信息存储方法及装置
CN105009542B (zh) 一种处理报文的方法和装置
CN116389340A (zh) 数据传输方法、装置和网络设备、系统及存储介质
CN115333896A (zh) 报文转发的方法、设备和系统
CN118802411A (zh) 算力信息传递方法、装置、设备及存储介质
CN118802413A (zh) 报文处理方法、装置、电子设备及可读存储介质
WO2023231438A1 (zh) 报文发送的方法、网络设备及系统
WO2024179256A1 (zh) 一种evpn的报文传输方法、装置、设备及介质

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201380077723.5

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13900610

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

REEP Request for entry into the european phase

Ref document number: 2013900610

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2013900610

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2016131169

Country of ref document: RU

Kind code of ref document: A