Traffic Classifier, Service Routing Trigger, and Packet Processing Method and System
Claim Score by NHIP
Abstract
A packet processing method includes: a traffic classifier receives a first packet; the traffic classifier determines, in policy information in the traffic classifier and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address, which matches the first filtering rule, of a first service routing trigger. The traffic classifier sends a second packet to the first service routing trigger. Where the policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule. Where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet. Where the second packet is formed by adding the first service identifier to the first packet.

Term
Projected expiry 30 July 2033.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 5 independent, 15 dependent
- 1A packet processing system, comprising:a controller;a traffic classifier;and a first service routing trigger;wherein the controller is configured to send first policy information to the traffic classifier;wherein the first policy information comprises a filtering rule, an address that corresponds to the filtering rule and that is of a service routing trigger, and a service identifier corresponding to the filtering rule, wherein the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet;wherein the controller is further configured to send second policy information to the first service routing trigger, wherein the second policy information comprises the service identifier and a service node sequence corresponding to the service identifier;wherein the traffic classifier is configured to receive the first policy information sent by the controller;wherein the traffic classifier is further configured to receive a first packet, wherein the traffic classifier is further configured to determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of the first service routing trigger, and wherein the traffic classifier is further configured to send a second packet to the first service routing trigger, wherein the second packet comprises the first service identifier;and wherein the first service routing trigger is configured to determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier, and wherein the first service routing trigger is further configured successively trigger one or more service nodes in the first service node sequence to process the second packet.
- 5A packet processing system, comprising:a controller;a traffic classifier;a first service routing trigger;and a second service routing trigger;wherein the controller is configured to send first policy information to the traffic classifier, wherein the first policy information comprises a filtering rule, an address that corresponds to the filtering rule and that is of a service routing trigger, and a service identifier corresponding to the filtering rule, wherein the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet;wherein the controller is further configured to send second policy information to the first service routing trigger, wherein the second policy information comprises the service identifier, and a first part that is triggered by the first service routing trigger and is of a service node sequence corresponding to the service identifier;wherein the controller is further configured to send third policy information to the second service routing trigger, wherein the third policy information comprises the service identifier, and a second part that is triggered by the second service routing trigger and is of the service node sequence corresponding to the service identifier;wherein the traffic classifier is configured to receive the first policy information sent by the controller;wherein the traffic classifier is further configured to receive a first packet;wherein the traffic classifier is further configured to determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, an address that matches the first filtering rule and is of the first service routing trigger, and an address that matches the first filtering rule and is of the second service routing trigger;wherein the traffic classifier is further configured to send a second packet to the first service routing trigger, wherein the second packet comprises the first service identifier;wherein the first service routing trigger is configured to determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier;wherein the first service routing trigger is further configured to, after successively triggering one or more service nodes in the first service node sequence to process a second packet, send the processed second packet to the second service routing trigger;wherein the second service routing trigger is configured to determine, in the third policy information and according to the first service identifier carried in the processed second packet, a second service node sequence that matches the first service identifier;and wherein the second service routing trigger is further configured to successively trigger one or more service nodes in the second service node sequence to process the second packet.
- 9Broadest claimClaim Score 71, broad(NHIP)A packet processing method, comprising:receiving, by a service routing trigger, a first packet, wherein the first packet carries a first service identifier;determining, by the service routing trigger, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier;and successively triggering, by the service routing trigger and according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
- 14A packet processing method, comprising:receiving, by a first service routing trigger, a first packet, wherein the first packet carries a first service identifier;determining, by the first service routing trigger, in first policy information stored in the first service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a second service routing trigger;forwarding, by the first service routing trigger, the first packet to the second service routing trigger processed after successively triggering, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet;determining, by the second service routing trigger, in second policy information stored in the second service routing trigger and according to the first service identifier, a second service node sequence that matches the first service identifier;and successively triggering, by the second service routing trigger, according to the second service node sequence, one or more service nodes in the second service node sequence to process the first packet.
- 16A service routing trigger, comprising:a receiving unit, a processing unit;and a triggering unit;wherein the receiving unit is configured to receive a first packet, wherein the first packet carries a first service identifier;wherein the processing unit is configured to determine, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a service node in the first service node sequence;and wherein the triggering unit is configured to successively trigger, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
Independent claims5
281 paragraphs in 5 sections, as filed
0001This application is a continuation of International Application No. PCT/CN2013/075003, filed on Apr. 28, 2013, which is hereby incorporated by reference in its entirety.
TECHNICAL FIELD
0002The present disclosure relates to the communications field, in particular, to a packet processing method, device, and system.
BACKGROUND
0003On a data center network, service processing based on open system interconnection (OSI) layer 4 to layer 7 usually needs to be performed on a packet. For example, service processing generally includes: providing firewall processing, network address translation (NAT), home control, and the like. Different service processing may need to be provided for different packets, and multiple service processing may need to be provided for a packet, for example, firewall processing and NAT processing may need to be performed on some packets, and firewall processing and home control processing may be expected for some other packets. In this case, how to implement service processing on a packet is an issue to be resolved.
SUMMARY
0004An objective of embodiments of the present disclosure is to provide a traffic classifier, a service routing trigger, and a packet processing method and system, so as to resolve a problem of service processing on a packet.
0005To achieve the foregoing objective, the embodiments of the present disclosure use the following technical solutions.
0006According to a first aspect, an embodiment of the present disclosure provides a packet processing system, including a controller, a traffic classifier, and a first service routing trigger, where
0007the controller is configured to send first policy information to the traffic classifier, where the first policy information includes: a filtering rule, an address that is corresponding to the filtering rule and is of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet;
0008the controller is further configured to send second policy information to the first service routing trigger, where the second policy information includes the service identifier, and a service node sequence that is corresponding to the service identifier;
0009the traffic classifier is configured to receive the first policy information sent by the controller;
0010the traffic classifier is further configured to: receive a first packet; determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of the first service routing trigger; and send a second packet to the first service routing trigger, where the second packet includes the first service identifier; and
0011the first service routing trigger is configured to: determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier; and successively trigger one or more service nodes in the first service node sequence to process the second packet.
0012In some implementations, the first policy information further includes a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier.
0013In some implementations, the traffic classifier is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address that matches the first filtering rule and the first tenant identifier and is of the first service routing trigger; and send the second packet to the first service routing trigger.
0014In some implementations, the second policy information further includes an address of a next-hop node of the service node sequence corresponding to the service identifier.
0015According to a second aspect, an embodiment of the present disclosure provides a packet processing system, including a controller, a traffic classifier, a first service routing trigger, and a second service routing trigger, where
0016the controller is configured to send first policy information to the traffic classifier, where the first policy information includes: a filtering rule, an address that is corresponding to the filtering rule and is of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet;
0017the controller is further configured to send second policy information to the first service routing trigger, where the second policy information includes: the service identifier, and a part that is triggered by the first service routing trigger and is of a service node sequence corresponding to the service identifier;
0018the controller is further configured to send third policy information to the second service routing trigger, where the third policy information includes: the service identifier, and a part that is triggered by the second service routing trigger and is of the service node sequence corresponding to the service identifier;
0019the traffic classifier is configured to receive the first policy information sent by the controller;
0020the traffic classifier is further configured to: receive a first packet; determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, an address that matches the first filtering rule and is of the first service routing trigger, and an address that matches the first filtering rule and is of the second service routing trigger; and send a second packet to the first service routing trigger, where the second packet includes the first service identifier;
0021the first service routing trigger is configured to: determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier; and after successively triggering one or more service nodes in the first service node sequence to process the second packet, send the processed second packet to the second service routing trigger; and
0022the second service routing trigger is configured to: determine, in the third policy information and according to the first service identifier carried in the processed second packet, a second service node sequence that matches the first service identifier; and successively trigger one or more service nodes in the second service node sequence to process the second packet.
0023In some implementations, the first policy information further includes a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier.
0024In some implementations, the traffic classifier is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and the address that matches the first filtering rule and is of the first service routing trigger; and send the second packet to the first service routing trigger.
0025In some implementations, the second policy information further includes an address of a next-hop node of the service node sequence corresponding to the service identifier.
0026According to a third aspect, an embodiment of the present disclosure provides a packet processing method, including:
0027receiving, by a traffic classifier, a first packet;
0028determining, by the traffic classifier, in policy information stored in the traffic classifier and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of a first service routing trigger, where the policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet; and
0029sending, by the traffic classifier, a second packet to the first service routing trigger, where
0030the second packet is formed by adding the first service identifier to the first packet.
0031In some implementations, the policy information further includes a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier; and
0000the step of determining the first service identifier by the traffic classifier is specifically: determining, by the traffic classifier, in the policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and the address of the first service routing trigger.
0032In some implementations, before the receiving, by the traffic classifier, the first packet, the method further includes: receiving, by the traffic classifier, the policy information sent by a controller.
0033According to a fourth aspect, an embodiment of the present disclosure provides a packet processing method, including:
0034receiving, by a service routing trigger, a first packet, where the first packet carries a first service identifier;
0035determining, by the service routing trigger, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier; and
0036successively triggering, by the service routing trigger, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
0037In some implementations, before the receiving, by the service routing trigger, the first packet sent by a traffic classifier, further including: receiving, by the service routing trigger, the policy information sent by a controller.
0038In some implementations, the policy information includes the service identifier, and a service node sequence that matches the service identifier, and the service identifier is used to represent a sequence of a service node that processes a packet.
0039In some implementations, the policy information further includes an address of a service node in the service node sequence.
0040In some implementations, the policy information further includes an address of a next-hop node of the service node sequence corresponding to the service identifier; and
0041the method further includes: after a last service node in the first service node sequence has processed the first packet, sending, by the service routing trigger, the processed first packet to a next-hop node of the service node sequence.
0042According to a fifth aspect, an embodiment of the present disclosure provides a packet processing method, including:
0043receiving, by a first service routing trigger, a first packet, where the first packet carries a first service identifier;
0044determining, by the first service routing trigger, in first policy information stored in the first service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a second service routing trigger;
0045forwarding, by the first service routing trigger, the first packet to the second service routing trigger after successively triggering, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet;
0046determining, by the second service routing trigger, in second policy information in the second service routing trigger and according to the first service identifier, a second service node sequence that matches the first service identifier; and
0047successively triggering, by the second service routing trigger, according to the second service node sequence, one or more service nodes in the second service node sequence to process the first packet.
0048In some implementations, before the receiving, by the first service routing trigger and the second service routing trigger, the first packet, the method further includes: receiving, by the first service routing trigger, the first policy information sent by a controller, and receiving, by the second service routing trigger, the second policy information sent by the controller.
0049According to a sixth aspect, an embodiment of the present disclosure provides a traffic classifier, including a receiving unit, a storage unit, a processing unit, and a sending unit, where
0050the receiving unit is configured to receive a first packet;
0051the storage unit is configured to store policy information;
0052the processing unit is configured to: determine in the policy information stored in the storage unit and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of a first service routing trigger; and trigger the sending unit to send a second packet to the first service routing trigger, where the second packet is formed by adding the first service identifier to the first packet; and
0053the sending unit is configured to send the second packet to the first service routing trigger.
0054In some implementations, the receiving unit is further configured to receive the policy information sent by a controller.
0055In some implementations, the policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet.
0056In some implementations, the policy information further includes a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier; and
0057the processing unit is specifically configured to:
0058determine, in the policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address that matches the first filtering rule and the first tenant identifier and is of the first service routing trigger; and trigger the sending unit to send the second packet to the first service routing trigger.
0059According to a seventh aspect, an embodiment of the present disclosure provides a service routing trigger, including a receiving unit, a processing unit, and a triggering unit, where
0060the receiving unit is configured to receive a first packet, where the first packet carries a first service identifier;
0061the processing unit determines, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a service node in the first service node sequence; and
0062the triggering unit is configured to successively trigger, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
0063In some implementations, the receiving unit is further configured to receive the policy information sent by a controller.
0064In some implementations, the policy information includes a service identifier, and a service node sequence that matches the service identifier, and the service identifier is used to represent a sequence of a service node that processes a packet.
0065In some implementations, the policy information further includes an address of a service node in the service node sequence.
0066In some implementations, the policy information further includes an address of a next-hop node of the service node sequence.
0067In the technical solutions of the embodiments of the present disclosure, a controller sends first policy information to a traffic classifier and sends second policy information to a service routing trigger, and the traffic classifier and the service routing trigger process packets according to received policy information, which implements unified management of the traffic classifier and the service routing trigger by the controller. Further, the traffic classifier adds, according to the first policy information, a service identifier to a packet that is identified as a packet on which service processing needs to be performed, and sends, to the service routing trigger, the packet to which the service identifier is added; and the service routing trigger controls and triggers a service node in a service node sequence corresponding to the service identifier to process the packet, and normally forwards a processed packet according to a routing table, which implements service processing on the packet. In addition, a service node only needs to perform service processing on a packet according to control and triggering of the service routing trigger, and therefore, a mechanism in the present disclosure is compatible with service nodes with various different service capabilities.
BRIEF DESCRIPTION OF THE DRAWINGS
0068To describe the technical solutions in the embodiments of the present disclosure more clearly, the following briefly introduces the accompanying drawings required for describing the embodiments. Apparently, the accompanying drawings in the following description show merely some embodiments of the present disclosure, and a person of ordinary skill in the art may still derive other drawings in these accompanying drawings without creative efforts.
0069<figref idref="DRAWINGS">FIG. 1(</figref><i>a</i>) and <figref idref="DRAWINGS">FIG. 1(</figref><i>b</i>) are diagrams of a packet processing system according to
0070Embodiment 1 of the present disclosure;
0071<figref idref="DRAWINGS">FIG. 2(</figref><i>a</i>) to <figref idref="DRAWINGS">FIG. 2(</figref><i>c</i>) are schematic diagrams of a first policy information table in a packet processing system according to Embodiment 1 of the present disclosure;
0072<figref idref="DRAWINGS">FIG. 3</figref> is a schematic diagram of a packet processing method according to
0073Embodiment 3 of the present disclosure;
0074<figref idref="DRAWINGS">FIG. 4</figref> is a flowchart of a packet processing method according to Embodiment 4 of the present disclosure;
0075<figref idref="DRAWINGS">FIG. 5</figref> is a schematic structural diagram of a traffic classifier according to Embodiment 6 of the present disclosure;
0076<figref idref="DRAWINGS">FIG. 6</figref> is a schematic structural diagram of a service routing trigger according to Embodiment 7 of the present disclosure;
0077<figref idref="DRAWINGS">FIG. 7</figref> is a schematic structural diagram of a traffic classifier according to Embodiment 8 of the present disclosure;
0078<figref idref="DRAWINGS">FIG. 8</figref> is a schematic structural diagram of a service routing trigger according to Embodiment 9 of the present disclosure;
0079<figref idref="DRAWINGS">FIG. 9</figref> is a schematic diagram of a scenario in which technical solutions in Embodiment 10 of the present disclosure are applied in the mobile broadband field; and
0080<figref idref="DRAWINGS">FIG. 10</figref> is a schematic diagram of a scenario in which technical solutions in Embodiment 11 of the present disclosure are applied in a multi-tenant data center.
DETAILED DESCRIPTION OF ILLUSTRATIVE EMBODIMENTS
0081The following clearly describes the technical solutions in the embodiments of the present disclosure with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are merely a part rather than all of the embodiments of the present disclosure. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
0082In the embodiments of the present disclosure, a user access device may be a gateway GPRS (General Packet Radio Service) support node (GGSN)/a PDN (packet data network) gateway (P-GW) in the mobile broadband access field, a broadband network gateway (BNG) in the fixed access field, or a top of rack (ToR) switch in data center application.
0083The service node mentioned in the embodiments of the present disclosure may be a physical entity device, for example, a network device such as a router, a switch, or a server, or may be a logical functional entity or an application, for example, a firewall, or an NAT (Network Address Translation) device; and the service node may also be a service node instance. The service node mentioned in the embodiments of the present disclosure may be applied in a value-added service or a special service.
0084The traffic classifier mentioned in the embodiments of the present disclosure may be a physical entity device, for example, a network device such as a router, a switch, or a server, or may be a logical functional entity or an application providing a service classification function; and the traffic classifier may also be a service instance providing a service classification function.
0085The service routing trigger mentioned in the embodiments of the present disclosure may be a physical entity device, for example, a network device such as a router, a switch, or a server, or may be a logical functional entity or an application providing a function of triggering service routing; and the service routing trigger may also be a service instance providing a function of triggering service routing.
0086The controller mentioned in the embodiments of the present disclosure may be a physical entity device, for example, a network device such as a router, a switch, or a server, or may be a logical functional entity or an application providing a control function; and the controller may also be a service instance providing a control function.
0087The address mentioned in the embodiments of the present disclosure may be an Internet Protocol (IP) address or a media access control (MAC) address of the service routing trigger.
Embodiment 1
0088As shown in <figref idref="DRAWINGS">FIG. 1</figref>, a packet processing system includes a controller <b>12</b>, a traffic classifier <b>14</b>, and a service routing trigger <b>18</b>.
0089The controller <b>12</b> is configured to send first policy information to the traffic classifier <b>14</b>. The first policy information includes: a filtering rule, an address that matches the first filtering rule and is of a service routing trigger, and a service identifier corresponding to the filtering rule. The filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet.
0090The controller <b>12</b> is further configured to send second policy information to the service routing trigger <b>18</b>, where the second policy information includes the service identifier, and a service node sequence that is corresponding to the service identifier.
0091The traffic classifier <b>14</b> is configured to receive the first policy information sent by the controller <b>12</b>.
0092The traffic classifier <b>14</b> is further configured to: receive a first packet; determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of the service routing trigger <b>18</b>; and send a second packet to the service routing trigger <b>18</b>, where the second packet includes the first service identifier.
0093The service routing trigger <b>18</b> is configured to: determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier and processes the second packet; and successively trigger one or more service nodes in the first service node sequence to process the second packet.
0094Optionally, the second policy information may further include an address of a service node in the service node sequence corresponding to the service identifier.
0095Optionally, the second policy information may further include an address of a next-hop node of the service node sequence corresponding to the service identifier. Correspondingly, the service routing trigger <b>18</b> is configured to: determine, in the second policy information and according to the first service identifier carried in the second packet, an address of a next-hop node of the first service node sequence that matches the first service identifier; and forward, to the next-hop node of the first service node sequence, the second packet processed by a service node in the first service node sequence.
0096Specifically, when joining a network, multiple service nodes (<b>16</b>-<b>1</b>, <b>16</b>-<b>2</b>, . . . , and <b>16</b>-<i>n</i>) need to register with the controller <b>12</b> and report types and capabilities of the service nodes (<b>16</b>-<b>1</b>, <b>16</b>-<b>2</b>, . . . , and <b>16</b>-<i>n</i>). The service node may be an application in OSI layer 3 to layer 7, for example, a firewall, or an NAT (Network Address Translation) device; the service node may be a service node instance; or the service node may be a network device such as a router, a switch, or a server. Optionally, the service node may further report address information of a local service routing trigger <b>18</b> corresponding to the service node. An address that is corresponding to the service node and is of the service routing trigger <b>18</b> may be an Internet Protocol (IP) address or a media access control (MAC) address of the service routing trigger.
0097When joining the network, the traffic classifier <b>14</b> needs to register with the controller <b>12</b> and report an address of the traffic classifier <b>14</b>, where the address of the traffic classifier <b>14</b> may be an IP address or a MAC address. Optionally, the traffic classifier <b>14</b> may be an application in OSI layer 3 to layer 7; the traffic classifier <b>14</b> may be an application instance; or the traffic classifier <b>14</b> may be a network device such as a router, a switch, or a server.
0098When joining the network, the service routing trigger <b>18</b> needs to register with the controller <b>12</b> and report service node information of the service routing trigger <b>18</b> and an address of the service routing trigger <b>18</b>, where the address of the service routing trigger <b>18</b> may be an IP address or a MAC address. Optionally, the service routing trigger <b>18</b> may be an application in OSI layer 3 to layer 7; the service routing trigger <b>18</b> may be an application instance; or the service routing trigger <b>18</b> may be a network device such as a router, a switch, or a server. There may be one or multiple service routing triggers <b>18</b>. When the packet processing system includes multiple service routing triggers, the multiple service routing triggers may be corresponding to one or multiple service node sequences, that is, each service routing trigger is corresponding to one service node sequence. Optionally, one service routing trigger may also be corresponding to multiple service node sequences or corresponding to all service node sequences.
0099Optionally, the controller <b>12</b> may be an application in OSI layer 3 to layer 7; or the controller <b>12</b> may be an application instance; or the controller <b>12</b> may be a network device such as a router, a switch, or a server. There may be one or multiple controllers <b>12</b>.
0100Packets with a same service ID are processed by same one or more service nodes, and orders of the processing by the one or more service nodes are the same. Packets with different service IDs are processed by same one or more service nodes, and orders of the processing by the one or more service nodes are different; or packets with different service IDs are processed by different service nodes. For example, a packet whose service ID is 1 is first processed by a first service node <b>16</b>-<b>1</b>, and then processed by a second service node <b>16</b>-<b>2</b>; however, a packet whose service ID is 2 is first processed by the second service node <b>16</b>-<b>2</b>, and then processed by the first service node <b>16</b>-<b>1</b>. Optionally, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, for example, first processing by using a firewall and then processing by using a NAT device on both packets, the two packets are processed by different service nodes. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>1</b> and then processed by a NAT device <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>2</b> and then processed by a NAT device <b>2</b>. This helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0101Optionally, the first filtering rule may include one or multiple of a source address, a destination address, a source port, a destination port, and a protocol number that are of the first packet. For example, a first packet flow corresponding to the first packet may be identified by using 5-tuple information (a source address, a destination address, a source port, a destination port, and a protocol number) of the first packet. Optionally, the first filtering rule may be the 5-tuple information of the first packet, or may be a value calculated by using an algorithm according to the 5-tuple information of the first packet, for example, a value calculated by using a hash algorithm. When the traffic classifier <b>14</b> receives the first packet, if the filtering rule in the first policy information is 5-tuple information, the traffic classifier <b>14</b> acquires the 5-tuple information of the first packet from the first packet, so as to obtain the first filtering rule. If the filtering rule in the first policy information is a value obtained by means of processing based on the 5-tuple information by using a specific algorithm, the traffic classifier <b>14</b> acquires the 5-tuple information of the first packet from the first packet, and performs calculation by using the specific algorithm on the 5-tuple information of the first packet to obtain the value, where the obtained value is the first filtering rule.
0102The second packet is formed by adding the first service identifier to the first packet. For example, the second packet may be formed by adding the first service identifier to a header of the first packet, or may be formed by adding the first service identifier to a payload of the first packet.
0103By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0000<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="6"><colspec colname="1" colwidth="49pt" align="center" /><colspec colname="2" colwidth="42pt" align="center" /><colspec colname="3" colwidth="21pt" align="center" /><colspec colname="4" colwidth="35pt" align="center" /><colspec colname="5" colwidth="35pt" align="center" /><colspec colname="6" colwidth="35pt" align="center" /><thead><row><entry namest="1" nameend="6" rowsep="1">TABLE 1</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row><row><entry>Destination</entry><entry>Source MAC</entry><entry /><entry /><entry /><entry /></row><row><entry>MAC address</entry><entry>address</entry><entry>Type</entry><entry>VLAN ID</entry><entry>ServiceID</entry><entry>IP packet</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry /></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="1"><colspec colname="1" colwidth="217pt" align="center" /><tbody valign="top"><row><entry></entry></row><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0104The service routing trigger <b>18</b> receives the second packet, and determines, in the second policy information delivered by the controller <b>12</b> and according to the first service identifier, the first service node sequence that matches the first service identifier and processes the second packet. The service routing trigger <b>18</b> successively triggers and controls, according to an order of service nodes in the first service node sequence, all service nodes that start from the first service node <b>16</b>-<b>1</b> in the first service node sequence to process the second packet.
0105Optionally, the second policy information further includes an address of a service node in the first service node sequence.
0106Optionally, the second policy information further includes an address of a next-hop node of the service node sequence corresponding to the service identifier; then, the service routing trigger <b>18</b> determines, in the second policy information delivered by the controller <b>12</b> and according to the first service identifier, the address of the next-hop node of the first service node sequence, and sends, to the next-hop node of the first service node sequence, a second packet processed after the service routing trigger <b>18</b> controls all the service nodes in the first service node sequence to complete processing the second packet.
0107The first service node <b>16</b>-<b>1</b> is configured to receive and process the second packet sent by the service routing trigger <b>18</b>. After completing processing the second packet, the first service node <b>16</b>-<b>1</b> sends the processed second packet to the service routing trigger <b>18</b>; the service routing trigger <b>18</b> triggers, according to the order of service nodes in the first service node sequence, the second service node <b>16</b>-<b>2</b> after the first service node <b>16</b>-<b>1</b> to process the second packet; the service routing trigger <b>18</b> forwards the second packet to the next-hop node of the first service node sequence after a last service node <b>16</b>-<i>n </i>in the first service node sequence completes processing the second packet.
0108Optionally, when triggering the first service node <b>16</b>-<b>1</b>, the service routing trigger <b>18</b> may send together, to the first service node <b>16</b>-<b>1</b>, addresses of service nodes after the first service node <b>16</b>-<b>1</b> in the first service node sequence and the address of the next-hop node of the first service node sequence; and instructs the first service node <b>16</b>-<b>1</b> to send the processed second packet to the second service node <b>16</b>-<b>2</b> in the first service node sequence. The second service node <b>16</b>-<b>2</b> receives the second packet that is processed and then sent by the first service node <b>16</b>-<b>1</b>. After the second service node <b>16</b>-<b>2</b> processes the second packet, if it is determined that the second service node <b>16</b>-<b>2</b> is the last service node in the first service node sequence, the second service node <b>16</b>-<b>2</b> forwards the processed second packet to the next-hop node of the first service node sequence. Optionally, in the second policy information delivered by the controller <b>12</b>, an address of the last service node in the service node sequence is set to a special address, for example, 0.0.0.0, where 0.0.0.0 is used to indicate that the service node is a last service node that processes the second packet, in the service node sequence. A special next-hop with the special address may be any unreachable address, as long as it can indicate that the service node is the last service node that processes the second packet, which is not limited in this embodiment of the present disclosure thereto.
0109Optionally, the first service nodes (<b>16</b>-<b>1</b>, <b>16</b>-<b>2</b>, . . . , and <b>16</b>-<i>n</i>) may be logical functional entities. It should be noted that a service node generally has a reachable address, where the address of the service node may be an IP address or a MAC address. Whether a first service node is a physical entity or a logical entity is not limited in this embodiment of the present disclosure, as long as the first service node has a reachable address. In addition, a service node providing a firewall function may be used as an example for illustration to help understand a service node instance. Generally, a firewall function may be installed on many servers, in this way, the servers on which a firewall function is installed can all provide service processing of the firewall function, and the servers on which a firewall function is installed have different addresses. In this way, each server on which a firewall function is installed may be called a service node, that is, each service node instance includes a reachable address and can independently process at least one type of service. In specific implementation of this embodiment of the present disclosure, the service routing trigger <b>18</b> selects service nodes that process the first packet and an order based on which the first packet is processed. If the first service node <b>16</b>-<b>1</b> has another backup node, the service routing trigger <b>18</b> may select, according to processing capabilities and service load conditions of the first service node <b>16</b>-<b>1</b> and the backup node of the first service node <b>16</b>-<b>1</b>, an appropriate service node to process the packet.
0110Optionally, as shown in <figref idref="DRAWINGS">FIG. 2(</figref><i>a</i>), when there is only one service routing trigger or only one service routing trigger group in the packet processing system, the service routing trigger or the service routing trigger group receives the second policy information delivered by the controller, where the second policy information includes all service identifiers (service identifier <b>1</b>, service identifier <b>2</b>, . . . , and service identifier n) and a service node sequence corresponding to each service identifier. Each service node sequence may include multiple same service nodes with different processing orders. For example, a service node sequence <b>1</b> corresponding to the service identifier <b>1</b> includes a first service node and a second service node, and an order based on which the service node sequence <b>1</b> processes a packet is that the packet is first processed by the first service node, and then forwarded to and processed by the second service node; a service node sequence <b>2</b> corresponding to the service identifier <b>2</b> includes a first service node and a second service node, and an order based on which the service node sequence <b>2</b> processes a packet is that the packet is first processed by the second service node, and then forwarded to and processed by the first service node. Each service node sequence may include different quantities of service nodes, for example, a service node sequence <b>3</b> corresponding to a service identifier <b>3</b> includes a first service node, a second service node, and a third service node.
0111When there is only one service routing trigger in the packet processing system, the traffic classifier adds the first service identifier of the first packet to the first packet, and then forwards the first packet to the service routing trigger; the service routing trigger searches the second policy information to acquire the first service node sequence corresponding to the first service identifier; and the service routing trigger successively triggers one or more service nodes in the first service node sequence to process the first packet.
0112When there is only one service routing trigger group that includes multiple service routing triggers in the packet processing system, the service routing trigger group has a virtual address. The traffic classifier adds the first service identifier of the first packet to the first packet, and then forwards the first packet to the virtual address of service routing trigger group; a service routing trigger specified according to load balancing and the like in the service routing trigger group searches the second policy information to acquire the first service node sequence corresponding to the first service identifier; and the service routing trigger successively triggers one or more service nodes in the first service node sequence to process the first packet.
0113Optionally, as shown in <figref idref="DRAWINGS">FIG. 2(</figref><i>b</i>), when there are multiple service routing triggers in the packet processing system, and each service routing trigger is corresponding to one service identifier, the service routing trigger receives the second policy information delivered by the controller, where the second policy information includes a service identifier (for example, the service identifier <b>1</b>) and a service node sequence corresponding to the service identifier.
0114Optionally, the first policy information may further include a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier. Correspondingly, the traffic classifier <b>14</b> is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address, which matches the first filtering rule, of the first service routing trigger; and send the second packet to the service routing trigger <b>18</b>.
0115Optionally, as shown in <figref idref="DRAWINGS">FIG. 2(</figref><i>c</i>), when the packet processing system is applied in a multi-tenant service scenario, the first policy information includes a service identifier, a tenant identifier, a service node sequence corresponding to the service identifier and the tenant identifier, and an address that is corresponding to the service identifier and the tenant identifier and is of a service routing trigger. Correspondingly, the traffic classifier is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address that matches the first filtering rule and is of the first service routing trigger; and send the second packet to the first service routing trigger.
0116According to the packet processing system provided in this embodiment of the present disclosure, a controller sends first policy information to a traffic classifier and sends second policy information to a service routing trigger, and the traffic classifier and the service routing trigger process packets according to received policy information, which implements unified management of the traffic classifier and the service routing trigger by the controller. Further, the traffic classifier adds, according to the first policy information, a service identifier to a packet that is identified as a packet on which service processing needs to be performed, and sends, to the service routing trigger, the packet to which the service identifier is added; and the service routing trigger controls and triggers a service node in a service node sequence corresponding to the service identifier to process the packet, and normally forwards a processed packet according to a routing table, which implements service processing on the packet. In addition, a service node only needs to perform service processing on a packet according to control and triggering of the service routing trigger, and therefore, a mechanism in the present disclosure is compatible with service nodes with various different service capabilities.
Embodiment 2
0117A packet processing system may also include multiple service routing triggers. In this case, a packet processing system includes a controller, a traffic classifier, a first service routing trigger, and a second service routing trigger.
0118The controller is configured to send first policy information to the traffic classifier, where the first policy information includes: a filtering rule, an address that is corresponding to the filtering rule and is of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet.
0119The controller is further configured to send second policy information to the first service routing trigger, where the second policy information includes: the service identifier, and a part, which is triggered by the first service routing trigger, of a service node sequence corresponding to the service identifier.
0120The controller is further configured to send third policy information to the second service routing trigger, where the third policy information includes: the service identifier, and a part that is triggered by the second service routing trigger and is of the service node sequence corresponding to the service identifier.
0121The traffic classifier is configured to receive the first policy information sent by the controller.
0122The traffic classifier is further configured to: receive a first packet; determine, in the first policy information and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, an address that matches the first filtering rule and is of the first service routing trigger, and an address that matches the first filtering rule and is of the second service routing trigger; and send a second packet to the first service routing trigger, where the second packet includes the first service identifier.
0123The first service routing trigger is configured to: determine, in the second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier; and send, to the second service routing trigger, a second packet processed after successively triggering one or more service nodes in the first service node sequence to process the second packet.
0124The second service routing trigger is configured to: determine, in the third policy information and according to the first service identifier carried in the processed second packet, a second service node sequence that matches the first service identifier; and successively trigger one or more service nodes in the second service node sequence to process the second packet.
0125Optionally, the first policy information may further include a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier.
0126Optionally, the traffic classifier is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and the address that matches the first filtering rule and is of the first service routing trigger; and send the second packet to the first service routing trigger.
0127Optionally, the second policy information may further include an address of a next-hop node of the service node sequence corresponding to the service identifier.
0128According to the packet processing system provided in this embodiment of the present disclosure, a controller sends first policy information to a traffic classifier and sends second policy information to a service routing trigger, and the traffic classifier and the service routing trigger process packets according to received policy information, which implements unified management of the traffic classifier and the service routing trigger by the controller. Further, the traffic classifier adds, according to the first policy information, a service identifier to a packet that is identified as a packet on which service processing needs to be performed, and sends, to the service routing trigger, the packet to which the service identifier is added; and the service routing trigger controls and triggers a service node in a service node sequence corresponding to the service identifier to process the packet, and normally forwards a processed packet according to a routing table, which implements service processing on the packet. In addition, a service node only needs to perform service processing on a packet according to control and triggering of the service routing trigger, and therefore, a mechanism in the present disclosure is compatible with service nodes with various different service capabilities.
Embodiment 3
0129As shown in <figref idref="DRAWINGS">FIG. 3</figref>, this embodiment of the present disclosure provides a packet processing method, where the method includes the following steps:
0130<b>304</b>. A traffic classifier receives a first packet.
0131The first packet may be an IP packet or an Ethernet packet, and the first packet may be sent from a user-side device, or may be sent from a network-side device, which is not limited in this embodiment of the present disclosure.
0132<b>306</b>. The traffic classifier determines, in policy information stored in the traffic classifier and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and of a first service routing trigger, where the policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to represent a sequence of a service node that processes the packet.
0133The first filtering rule may include one or multiple of: a source address, a destination address, a source port, a destination port, and a protocol number that are of the first packet. For example, a first packet flow corresponding to the first packet may be identified by using 5-tuple information (a source address, a destination address, a source port, a destination port, and a protocol number) of the first packet. Optionally, the first filtering rule may be the 5-tuple information of the first packet, or may be a value calculated by using an algorithm according to the 5-tuple information of the first packet, for example, a value calculated by using a hash algorithm. When the traffic classifier receives the first packet, if the filtering rule in the policy information is 5-tuple information, the traffic classifier acquires the 5-tuple information from the first packet, so as to obtain the first filtering rule. If the filtering rule in the policy information is a value obtained by means of processing based on the 5-tuple information by using a specific algorithm, the traffic classifier acquires the 5-tuple information of the first packet from the first packet, and performs calculation by using the specific algorithm on the 5-tuple information of the first packet to obtain the value, where the obtained value is the first filtering rule.
0134<b>308</b>. The traffic classifier sends a second packet to the first service routing trigger, so that the first service routing trigger determines, in second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier and processes the second packet, and successively triggers one or more service nodes in the first service node sequence to process the second packet, where the second packet is formed by adding the first service identifier to the first packet.
0135For example, the second packet may be formed by adding the first service identifier to a header of the first packet, or may be formed by adding the first service identifier to a payload of the first packet.
0136By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN for short) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to as LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0137Optionally, before the receiving a first packet, the packet processing method further includes the following step: <b>302</b>. The traffic classifier receives first policy information sent by a controller.
0138Packets with a same service identifier (ID) are processed by a same service node, and an order of the processing by the service node is the same. Packets with different service IDs are processed by a same service node, and an order of the processing by the service node is different; or packets with different service IDs are processed by different service nodes. Further, in specific implementation of this embodiment of the present disclosure, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, the packet flow is processed by different service nodes. In this way, load balancing may be implemented for packet processing. For example, the two different packets are first processed by a firewall, and then processed by a NAT device, but are processed by different service nodes. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>1</b> and then processed by a NAT device instance <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>2</b> and then processed by a NAT device <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0139Optionally, the first policy information may further include a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier. The step that the traffic classifier determines the first service identifier is specifically that: the traffic classifier determines, in the policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and the address of the first service routing trigger.
0140Optionally, when the packet processing method is applied in a scenario with a multi-tenant service, the policy information includes a service identifier, a tenant identifier, a service node sequence corresponding to the service identifier and the tenant identifier, and an address that is corresponding to the service identifier and the tenant identifier and is of a service routing trigger.
0141According to the packet processing method provided in this embodiment of the present disclosure, a traffic classifier receives policy information sent by a controller; the traffic classifier adds a service identifier to a classified packet on which service processing needs to be performed, and sends, to a service routing trigger, the packet that carries the service identifier; the service routing trigger controls and triggers a service node to process the packet; and after processing the packet to which the service identifier is added, the service node may forward a processed packet to a next service node under control of the service routing trigger or normally forward the processed packet according to a routing table, which implements service processing on a packet flow. In addition, a service node only needs to perform service processing on a packet according to control and triggering of the service routing trigger, and therefore, a mechanism in the present disclosure is compatible with service nodes with various different service capabilities.
Embodiment 4
0142As shown in <figref idref="DRAWINGS">FIG. 4</figref>, this embodiment of the present disclosure provides a packet processing method, where the method includes the following steps:
0143S<b>404</b>. A service routing trigger receives a first packet, where the first packet carries a first service identifier.
0144S<b>406</b>. The service routing trigger determines, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier.
0145S<b>408</b>. The service routing trigger successively triggers, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
0146Optionally, before the service routing trigger receives the first packet sent by a traffic classifier, the method further includes the following step:
0147S<b>402</b>. The service routing trigger receives the policy information sent by a controller.
0148Optionally, the policy information includes a service identifier and a service node sequence that matches the service identifier and processes a packet, and the service identifier is used to represent a sequence of a service node that processes a packet.
0149Optionally, the policy information may further include an address of a service node in the service node sequence corresponding to the service identifier.
0150Optionally, the policy information may further include an address of a next-hop node of the service node sequence corresponding to the service identifier. Correspondingly, the method may further include the following step: The service routing trigger receives the second packet that is sent by the traffic classifier after having been processed by a last service node in the first service node sequence; and sends the processed second packet to a next-hop node of the service node sequence.
0151Packets with a same service ID are processed by a same service node, and an order of the processing by the service node is the same. Packets with different service IDs are processed by a same service node, and an order of the processing by the service node is different; or packets with different service IDs are processed by different service nodes. For example, a packet whose service ID is 1 is first processed by a first service node <b>26</b>-<b>1</b>, and then processed by a second service node instance <b>28</b>; however, a packet whose service ID is 2 is first processed by the second service node instance <b>28</b>, and then processed by the first service node <b>26</b>-<b>1</b>. Optionally, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, for example, first processing by using a firewall and then processing by using a NAT device on both packets, the two packets are processed by different service nodes. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>1</b> and then processed by a NAT device <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>2</b> and then processed by a NAT device <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0152A service node may be a logical functional entity. It should be noted that a service node generally has a reachable address, where the address of the service node may be an IP address or a MAC address. Whether a service node is a physical entity or a logical entity is not limited in this embodiment of the present disclosure, as long as the service node has a reachable address. In addition, a service node instance providing a firewall function may be used as an example for illustration to help understand the service node instance. Generally, a firewall function may be installed on many servers. In this way, servers on which a firewall function is installed can provide service processing of the firewall function, and multiple servers on which a firewall function is installed have different addresses. In this way, each server on which a firewall function is installed may be called a service node instance, that is, each service node instance has a reachable address and can independently process at least one service. In specific implementation of this embodiment of the present disclosure, the service routing trigger determines to select service nodes that process the packet and an order based on which the packet is processed. For example, the service routing trigger may select, according to processing capabilities and service load conditions of service node instances, an appropriate service node instance to process the packet.
0153According to the packet processing method provided in this embodiment of the present disclosure, a service routing trigger receives a first packet that carries a first service identifier, and acquires, according to the first service identifier and policy information that is stored in the service routing trigger, a first service node sequence that matches the first service identifier and processes the first packet, an address of a first service node in the first service node sequence, and an address of a next-hop node of the first service node sequence, which implements service processing on a packet flow.
Embodiment 5
0154A packet processing method includes:
0155receiving, by a first service routing trigger, a first packet, where the first packet carries a first service identifier;
0156determining, by the first service routing trigger, in first policy information stored in the first service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a second service routing trigger;
0157forwarding, by the first service routing trigger, the first packet to the second service routing trigger after successively triggering, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet;
0158determining, by the second service routing trigger, in second policy information stored in the second service routing trigger and according to the first service identifier, a second service node sequence that matches the first service identifier; and
0159successively triggering, by the second service routing trigger, according to the second service node sequence, one or more service nodes in the second service node sequence to process the first packet.
0160Optionally, before the receiving, by the first service routing trigger and the second service routing trigger, the first packets, the method further includes: receiving, by the first service routing trigger, the first policy information sent by a controller, and receiving, by the second service routing trigger, the second policy information sent by the controller.
0161According to the packet processing method provided in this embodiment of the present disclosure, a service routing trigger receives a first packet that carries a first service identifier, and acquires, according to the first service identifier and policy information that is stored in the service routing trigger, a first service node sequence that matches the first service identifier and processes the first packet, an address of a first service node in the first service node sequence, and an address of a next-hop node of the first service node sequence, which implements service processing on a packet flow.
Embodiment 6
0162This embodiment of the present disclosure provides a traffic classifier. As shown in <figref idref="DRAWINGS">FIG. 5</figref>, <figref idref="DRAWINGS">FIG. 5</figref> is a schematic diagram of an apparatus of a traffic classifier according to this embodiment of the present disclosure.
0163The traffic classifier includes an input circuit <b>51</b>, a processor <b>52</b>, an output circuit <b>53</b>, and a memory <b>54</b>.
0164The input circuit <b>51</b> is configured to receive a first packet.
0165The first packet may be an IP packet or an Ethernet packet, and the first packet may be sent from a user-side device, or may be sent from a network-side device, which is not limited in this embodiment of the present disclosure.
0166The processor <b>52</b> is configured to: determine in policy information stored in the memory <b>54</b> and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule, of a first service routing trigger; and trigger the output circuit <b>53</b> to send a second packet to the first service routing trigger, where the second packet is formed by adding the first service identifier to the first packet.
0167The first filtering rule may include one or multiple of: a source address, a destination address, a source port, a destination port, and a protocol number that are of the first packet. For example, a first packet flow corresponding to the first packet may be identified by using 5-tuple information (a source address, a destination address, a source port, a destination port, and a protocol number) of the first packet. Optionally, the first filtering rule may be the 5-tuple information of the first packet, or may be a value calculated by using an algorithm according to the 5-tuple information of the first packet, for example, a value calculated by using a hash algorithm. When the input circuit <b>51</b> receives the first packet, if a filtering rule in the policy information is 5-tuple information, the processor <b>52</b> acquires the 5-tuple information from the first packet, so as to obtain the first filtering rule. If the filtering rule in the policy information is a value obtained by using a specific algorithm based on the 5-tuple information, the processor <b>52</b> acquires the 5-tuple information of the first packet from the first packet, and performs calculation by using the specific algorithm on the 5-tuple information of the first packet to obtain the value, where the obtained value is the first filtering rule.
0168The output circuit <b>53</b> is configured to send the second packet to the first service routing trigger, so that the first service routing trigger determines, in second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier and processes the second packet, and successively triggers one or more service nodes in the first service node sequence to process the second packet.
0169The memory <b>54</b> is configured to store the policy information.
0170The second packet is formed by adding the first service identifier to the first packet. For example, the second packet may be formed by adding the first service identifier to a header of the first packet, or may be formed by adding the first service identifier to a payload of the first packet.
0171By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to as LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0172Optionally, the input circuit <b>51</b> is further configured to receive first policy information sent by a controller, where the first policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to identify a sequence of a service node that processes the packet.
0173Optionally, the first policy information may further include a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier. Correspondingly, the processor <b>52</b> is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address that matches the first filtering rule and the first tenant identifier and is of the first service routing trigger; and trigger the output circuit <b>53</b> to send the second packet to the first service routing trigger.
0174Optionally, the controller may allocate a service processing policy based on a packet flow. The controller delivers the first policy information to the traffic classifier according to a service processing policy corresponding to a packet flow. The first policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to identify a sequence of a service node that processes the packet. Packets with a same service identifier (ID) are processed by a same service node, and an order of the processing by the service node is the same. Packets with different service IDs are processed by a same service node, and an order of the processing by the service node is different; or packets with different service IDs are processed by different service nodes. Further, in specific implementation of this embodiment of the present disclosure, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, the packet flow is processed by different service node or service node instances. In this way, load balancing may be implemented for packet processing. For example, the two different packets are first processed by a firewall, and then processed by a NAT device, but are processed by different service nodes. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>1</b> and then processed by a NAT device <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>2</b> and then processed by a NAT device <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0175According to the traffic classifier provided in this embodiment of the present disclosure, a service identifier is added to a received packet according to policy information, so that a service routing trigger controls and triggers, according to the service identifier, a service node in a service node sequence corresponding to the service identifier to process the packet to which the service identifier is added, which implements service processing on the packet.
Embodiment 7
0176As shown in <figref idref="DRAWINGS">FIG. 6</figref>, this embodiment of the present disclosure provides a service routing trigger, including an input circuit <b>61</b>, a processor <b>62</b>, and a trigger <b>63</b>.
0177The input circuit <b>61</b> is configured to receive a first packet, where the first packet carries a first service identifier.
0178For example, the first service identifier that matches the first packet may be carried in a header of the first packet, or the first service identifier may be carried in a payload of the first packet.
0179By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to as LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0180The processor <b>62</b> is configured to determine, in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier, and an address of a service node in the first service node sequence.
0181The triggering unit <b>63</b> is configured to successively trigger, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
0182Optionally, the service routing trigger may further include a memory <b>64</b>, where the memory <b>64</b> is configured to store the policy information.
0183Optionally, the input circuit <b>61</b> is configured to receive the policy information sent by a controller.
0184Optionally, the policy information may include: a service identifier, a service node sequence that matches the service identifier and processes a packet, and an address of a service node in the service node sequence, and the service identifier is used to represent a sequence of a service node that processes the packet.
0185Optionally, the policy information further includes an address of a next-hop node of the service node sequence.
0186In specific implementation of this embodiment of the present disclosure, the controller may allocate a service processing policy based on a packet flow. The controller delivers policy information to a service node instance (or a service node) according to a service processing policy corresponding to a packet flow. Packets with a same service ID are processed by a same service node instance (or a service node), and an order of the processing by the service node instance (or a service node) is the same. For example, a packet whose service ID=1 is first processed by a first service node <b>16</b>, and then processed by a second service node <b>18</b>; however, a packet whose service ID=2 is first processed by the second service node <b>18</b>, and then processed by the first service node <b>16</b>. Optionally, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, for example, first processing by using a firewall and then processing by using an NAT device on both packets, the two packets are processed by different service nodes (or service node instances). In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>1</b> and then processed by a NAT device instance <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>2</b> and then processed by a NAT device instance <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0187A first service node may be a logical functional entity. It should be noted that a service node instance generally has a reachable address, for example, a reachable IP address or MAC address. In this way, whether a first service node is a physical entity or a logical entity is not limited in this embodiment of the present disclosure, as long as the first service node has a reachable address. In addition, a service node instance providing a firewall function may be used as an example for illustration to help understand the service node instance. Generally, a firewall function may be installed on many servers, for example, a virtual machine VM. In this way, servers on which a firewall function is installed can all provide service processing of the firewall function, and the servers on which a firewall function is installed have different addresses. In this way, each server on which a firewall function is installed may be called a service node instance, that is, each service node instance includes a reachable address and can independently process at least one service. In specific implementation of this embodiment of the present disclosure, the controller determines to select the first service node to process the packet flow. For example, the controller may select, according to processing capabilities and service load conditions of service node instances, an appropriate service node instance to process the packet flow.
0188Optionally, the trigger <b>63</b> is further configured to send, to the controller, a packet for requesting to acquire the policy information. Correspondingly, the input circuit <b>61</b> is further configured to receive the policy information sent by the controller according to a packet, sent by the trigger <b>63</b>, for requesting to acquire the policy information.
0189According to the service routing trigger provided in this embodiment of the present disclosure, a packet that carries a service identifier is received, and a service node in a service node sequence corresponding to the service identifier is controlled and triggered to process the packet, which implements service processing on a packet flow.
Embodiment 8
0190As shown in <figref idref="DRAWINGS">FIG. 7</figref>, this embodiment of the present disclosure provides a traffic classifier, including a receiving unit <b>71</b>, a processing unit <b>72</b>, a sending unit <b>73</b>, and a storage unit <b>74</b>.
0191The receiving unit <b>71</b> is configured to receive a first packet.
0192The first packet may be an IP packet or an Ethernet packet, and the first packet may be sent from a user-side device, or may be sent from a network-side device, which is not limited in this embodiment of the present disclosure.
0193The processing unit <b>72</b> is configured to: determine in policy information stored in the storage unit <b>74</b> and according to a first filtering rule that matches the first packet, a first service identifier that matches the first filtering rule, and an address that matches the first filtering rule and is of a first service routing trigger; and trigger the sending unit <b>73</b> to send a second packet to the first service routing trigger, where the second packet is formed by adding the first service identifier to the first packet.
0194The first filtering rule may include one or multiple of: a source address, a destination address, a source port, a destination port, and a protocol number that are of the first packet. For example, a first packet flow corresponding to the first packet may be identified by using 5-tuple information (a source address, a destination address, a source port, a destination port, and a protocol number) of the first packet. Optionally, the first filtering rule may be the 5-tuple information of the first packet, or may be a value calculated by using an algorithm according to the 5-tuple information of the first packet, for example, a value calculated by using a hash algorithm. When the receiving unit <b>71</b> receives the first packet, if a filtering rule in the policy information is 5-tuple information, the processing unit <b>72</b> acquires the 5-tuple information from the first packet, so as to obtain the first filtering rule. If the filtering rule in the policy information is a value obtained by using a specific algorithm based on the 5-tuple information, the processing unit <b>72</b> acquires the 5-tuple information of the first packet from the first packet, and performs calculation by using the specific algorithm on the 5-tuple information of the first packet to obtain the value, where the obtained value is the first filtering rule.
0195The sending unit <b>73</b> is configured to send the second packet to the first service routing trigger, so that the first service routing trigger determines, in second policy information and according to the first service identifier carried in the second packet, a first service node sequence that matches the first service identifier and processes the second packet, and successively triggers one or more service nodes in the first service node sequence to process the second packet.
0196The storage unit <b>74</b> is configured to store the policy information.
0197The second packet is formed by adding the first service identifier to the first packet. For example, the second packet may be formed by adding the first service identifier to a header of the first packet, or may be formed by adding the first service identifier to a payload of the first packet.
0198By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to as LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0199Optionally, the receiving unit <b>71</b> is further configured to receive first policy information sent by a controller.
0200Optionally, the first policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to identify a sequence of a service node that processes the packet.
0201Optionally, the first policy information may further include a tenant identifier, and the service identifier is corresponding to the filtering rule and the tenant identifier. Correspondingly, the processing unit <b>72</b> is specifically configured to: determine, in the first policy information and according to a first tenant identifier corresponding to the first filtering rule and the first packet, the first service identifier that matches the first filtering rule and the first tenant identifier, and an address, that matches the first filtering rule and the first tenant identifier and is of the first service routing trigger; and trigger the sending unit <b>73</b> to send the second packet to the first service routing trigger.
0202Optionally, the controller may allocate a service processing policy based on a packet flow. The controller delivers the first policy information to the traffic classifier according to a service processing policy corresponding to a packet flow. The first policy information includes: a filtering rule, an address of a service routing trigger, and a service identifier corresponding to the filtering rule, where the filtering rule is used to identify a packet, and the service identifier is used to identify a sequence of a service node that processes the packet. Packets with a same service identifier (ID) are processed by a same service node, and an order of the processing by the service node is the same. Packets with different service IDs are processed by a same service node, and an order of the processing by the service node is different; or packets with different service IDs are processed by different service nodes. Further, in specific implementation of this embodiment of the present disclosure, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, the packet flow is processed by different service node instances. In this way, load balancing may be implemented for packet processing. For example, the two different packets are first processed by a firewall, and then processed by a NAT device, but are processed by different service nodes. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>1</b> and then processed by a NAT device <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall <b>2</b> and then processed by a NAT device <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b> and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, which helps to implement load balancing.
0203According to the traffic classifier provided in this embodiment of the present disclosure, a service identifier is added to a received packet according to policy information, so that a service routing trigger controls and triggers, according to the service identifier, a service node in a service node sequence corresponding to the service identifier to process the packet to which the service identifier is added, which implements service processing on the packet.
Embodiment 9
0204As shown in <figref idref="DRAWINGS">FIG. 8</figref>, this embodiment of the present disclosure provides a service routing trigger, including a receiving unit <b>81</b>, a processing unit <b>82</b>, and a triggering unit <b>83</b>.
0205The receiving unit <b>81</b> is configured to receive a first packet, where the first packet carries a first service identifier.
0206For example, the first service identifier that matches the first packet may be carried in a header of the first packet, or the first service identifier may be carried in a payload of the first packet.
0207By using an example in which the first packet is an Ethernet packet, the first service identifier may be added to a new header option of the first packet, or may be added to an IP header of the Ethernet packet; or an existing field in the header of the first packet may be reused, that is, a meaning of the existing field is changed to indicate that the first packet carries the first service identifier. For example, a VLAN identifier (also referred to as VLAN ID) of a virtual local area network (VLAN) or of a QINQ (IEEE 802.1Q in IEEE 802.1Q, also referred to as Stacked VLAN or Double VLAN), or a label (also referred to as LABEL) in Multiprotocol Label Switching (MPLS) may be reused, or a part or all of a source MAC address may be escaped for reuse. A format of the new header option of the first packet is shown in Table 1: A type field is added between the source MAC address and the VLAN ID to indicate whether the first packet carries a service identifier and the first service identifier. For example, it may be defined as follows: When a type value is 0, it indicates that the first packet does not carry a service identifier, and in this case, a value of the service ID is 0; and when a type value is 1, it indicates that the first packet carries a service identifier, and in this case, the value of the service ID is the first service identifier carried in the first packet.
0208The processing unit <b>82</b> is configured to determine in policy information stored in the service routing trigger and according to the first service identifier, a first service node sequence that matches the first service identifier and processes the first packet, and an address of a service node in the first service node sequence.
0209The triggering unit <b>83</b> is configured to successively trigger, according to the first service node sequence, one or more service nodes in the first service node sequence to process the first packet.
0210Optionally, the service routing trigger may further include a storage unit <b>84</b>, where the storage unit <b>84</b> is configured to store the policy information.
0211Optionally, the receiving unit <b>81</b> is configured to receive the policy information sent by a controller.
0212Optionally, the policy information may include: a service identifier, a service node sequence that matches the service identifier and processes a packet, and an address of a service node in the service node sequence, and the service identifier is used to represent a sequence of a service node that processes the packet.
0213Optionally, the policy information further includes an address of a next-hop node of the service node sequence.
0214In specific implementation of this embodiment of the present disclosure, the controller may allocate a service processing policy based on a packet flow. The controller delivers policy information to a service node instance according to a service processing policy corresponding to a packet flow. Packets with a same service ID are processed by a same service node, and orders of the processing by the service node instance is the same. For example, a packet whose service ID=1 is first processed by a first service node <b>16</b>, and then processed by a second service node instance <b>18</b>; however, a packet whose service ID=2 is first processed by the second service node instance <b>18</b>, and then processed by the first service node <b>16</b>. Optionally, if two different service IDs are allocated to two different packets in a same packet flow, it means that although service processing that needs to be performed on the two different packets is the same, for example, first processing by using a firewall and then processing by using a NAT device on both packets, the two packets are processed by different service node instances. In this way, load balancing may be implemented for packet processing. Optionally, packets in a packet flow may be classified to implement load balancing of processing on a same packet flow. For example, a same source address and a same destination address are used to identify a same packet flow. To implement load balancing of processing on packets in the same packet flow, the packets in the same packet flow may be classified according to protocol numbers. It is assumed that a service ID is allocated to packets, of which protocol numbers are greater than 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>1</b> and then processed by a NAT device instance <b>1</b>. Another service ID is allocated to packets, of which protocol numbers are less than or equal to 50, in the same packet flow, where the service ID is used to identify that the packets are first processed by a firewall instance <b>2</b> and then processed by a NAT device instance <b>2</b>. In this way, it helps to implement load balancing of processing on a same packet flow. Optionally, if same service processing, for example, first processing by a NAT device, and then processing by a firewall, needs to be performed on different packet flows, for example, a packet flow <b>1</b>and a packet flow <b>2</b>, a same service ID may be allocated to packets in the packet flow <b>1</b> and packets in the packet flow <b>2</b>. Certainly, different service IDs may also be allocated to the packets in the packet flow <b>1</b> and the packets in the packet flow <b>2</b>, wich helps to implement load balancing.
0215A first service node may be a logical functional entity. It should be noted that a service node instance generally has a reachable address, for example, a reachable IP address or MAC address. In this way, whether a first service node is a physical entity or a logical entity is not limited in this embodiment of the present disclosure, as long as the first service node has a reachable address. In addition, a service node instance providing a firewall function may be used as an example for illustration to help understand the service node instance. Generally, a firewall function may be installed on many servers, for example, a virtual machine VM. In this way, servers on which a firewall function is installed can all provide service processing of the firewall function, and the servers on which a firewall function is installed have different addresses. In this way, each server on which a firewall function is installed may be called a service node instance, that is, each service node instance includes a reachable address and can independently process at least one service. In specific implementation of this embodiment of the present disclosure, the controller determines to select the first service node to process the packet flow. For example, the controller may select, according to processing capabilities and service load conditions of service node instances, an appropriate service node instance to process the packet flow.
0216The receiving unit <b>81</b> further configured to receive the policy information sent by the controller.
0217According to the service routing trigger provided in this embodiment of the present disclosure, a packet that carries a service identifier is received, and a service node in a service node sequence corresponding to the service identifier is controlled and triggered to process the packet, which implements service processing on a packet flow.
Embodiment 10
0218A scenario in which technical solutions in this embodiment of the present disclosure are applied in the mobile broadband field is shown in <figref idref="DRAWINGS">FIG. 9</figref>. <figref idref="DRAWINGS">FIG. 9</figref> provides an example in which technical solutions in this embodiment of the present disclosure are applied in mobile broadband access. A function of a traffic classifier is deployed on a mobile broadband user access device, for example, on a GGSN/P-GW, and two service routing triggers to which different value-added services are connected are separately deployed. A service routing trigger <b>1</b> and an access device are on a same local area network, and a service routing trigger <b>2</b> is deployed in a centralized metropolitan area data center. A service node sequence for a packet flow for uplink Web access requires processing by three service nodes: an application cache acceleration node, a firewall, and NAT address translation.
0219A service node sequence <b>10</b> includes: a service node <b>1</b> that processes application cache acceleration, a service node <b>2</b> that performs firewall processing, and a service node <b>3</b> that performs NAT address translation processing on a packet. An order based on which service nodes in the service node sequence <b>10</b> process a packet is: the service node <b>1</b>-> the service node <b>2</b>-> the service node <b>3</b>. An address of the service node <b>1</b>, an address of the service node <b>2</b>, an address of the service node <b>3</b>, and the service node sequence <b>10</b> may be prestored in a controller, or be prestored in a policy database that can be accessed by the controller.
0220The controller performs a policy decision according to the service node sequence <b>10</b>, subscription information, and relevant physical deployment information of a service node in the service node sequence. Physical deployment information of the service node sequence <b>10</b> provided is shown in Table 2:
0000<tables id="TABLE-US-00002" num="00002"><table frame="none" colsep="0" rowsep="0" pgwide="1"><tgroup align="left" colsep="0" rowsep="0" cols="6"><colspec colname="1" colwidth="42pt" align="left" /><colspec colname="2" colwidth="42pt" align="center" /><colspec colname="3" colwidth="42pt" align="center" /><colspec colname="4" colwidth="42pt" align="left" /><colspec colname="5" colwidth="42pt" align="left" /><colspec colname="6" colwidth="49pt" align="left" /><thead><row><entry namest="1" nameend="6" rowsep="1">TABLE 2</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row><row><entry /><entry /><entry /><entry /><entry>First</entry><entry>Second</entry></row><row><entry /><entry /><entry /><entry /><entry>service</entry><entry>service</entry></row><row><entry>Service</entry><entry /><entry /><entry>Traffic</entry><entry>routing</entry><entry>routing</entry></row><row><entry>node</entry><entry>Service</entry><entry /><entry>classifier</entry><entry>trigger and</entry><entry>trigger and</entry></row><row><entry>sequence</entry><entry>identifier</entry><entry>Subscriber</entry><entry>and rule</entry><entry>service</entry><entry>service</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry>Service node</entry><entry>10</entry><entry>All</entry><entry>Traffic</entry><entry>Service</entry><entry>Service</entry></row><row><entry>sequence 10</entry><entry /><entry /><entry>classifier 1</entry><entry>routing</entry><entry>routing</entry></row><row><entry /><entry /><entry /><entry>and Web</entry><entry>trigger 1</entry><entry>trigger 2</entry></row><row><entry /><entry /><entry /><entry>access</entry><entry>Service</entry><entry>Service</entry></row><row><entry /><entry /><entry /><entry>filtering rule</entry><entry>sequence</entry><entry>sequence (a</entry></row><row><entry /><entry /><entry /><entry /><entry>(application</entry><entry>firewall, NAT</entry></row><row><entry /><entry /><entry /><entry /><entry>caching and</entry><entry>address</entry></row><row><entry /><entry /><entry /><entry /><entry>acceleration)</entry><entry>translation)</entry></row><row><entry /><entry /><entry /><entry /><entry>Next service</entry><entry>Service chain</entry></row><row><entry /><entry /><entry /><entry /><entry>routing</entry><entry>ends</entry></row><row><entry /><entry /><entry /><entry /><entry>trigger:</entry></row><row><entry /><entry /><entry /><entry /><entry>service</entry></row><row><entry /><entry /><entry /><entry /><entry>routing</entry></row><row><entry /><entry /><entry /><entry /><entry>trigger 2</entry></row><row><entry namest="1" nameend="6" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0221The controller delivers first policy information to the traffic classifier, the controller delivers second policy information to the service routing trigger <b>1</b>, and the controller delivers third policy information to the service routing trigger <b>2</b>.
0222The first policy information includes: subscription information of a service node sequence, a flow filtering rule of the service node sequence, a service identifier corresponding to the service node sequence, and address information of a next-hop service node of the service node sequence. An entry that is corresponding to the service node sequence <b>10</b> and is in the first policy information includes:
0223subscription information of the service node sequence <b>10</b>: all subscribers;
0224a flow filtering rule “Web access filtering rule” of the service node sequence <b>10</b>, and the service identifier: <b>10</b>; and
0225address information of a next-hop service node instance: address information of the service routing trigger <b>1</b>.
0226The second policy information delivered by the controller to the service routing trigger <b>1</b> includes: a service identifier, a service node sequence corresponding to the service identifier, an address of a node in the service node sequence corresponding to the service identifier, and address information of a next-hop service node of the service node sequence. An entry that is corresponding to the service node sequence <b>10</b> and is in the second policy information includes:
0227a service identifier: <b>10</b>;
0228value-added service node sequence information corresponding to the service routing trigger <b>1</b>: a first value-added service: application cache caching and acceleration, and an IP address or MAC address of a value-added service node of the application caching and acceleration; and
0229address information of a next-hop service node: address information of the service routing trigger <b>2</b>.
0230The third policy information delivered by the controller to the service routing trigger <b>2</b> includes: a service identifier, a service node sequence corresponding to the service identifier, an address of a node in the service node sequence corresponding to the service identifier, and a service chain end identifier. An entry that is corresponding to the service node sequence <b>10</b> and is in the third policy information includes:
0231a service identifier: <b>10</b>;
0232value-added service node sequence information corresponding to the service routing trigger 2:
0233a first value-added service: a firewall, and an IP address or MAC address of a value-added service node of the firewall;
0234a second value-added service: NAT address translation, and an IP address or MAC address of a value-added service node of the NAT address translation; and
0235a service chain end identifier.
0236The traffic classifier <b>1</b> performs classification on received user service packets according to the flow filtering rule “Web access filtering rule” in the first policy information and information that a subscriber subscribes to the service node sequence <b>10</b>. If it is determined that a first packet, after being filtered by the traffic classifier <b>1</b>, needs to be processed by the service node sequence <b>10</b> corresponding to the service identifier <b>10</b>, the service identifier <b>10</b> is encapsulated into the first packet, and a first packet into which the service identifier <b>10</b> is encapsulated is sent to a next-hop service routing trigger <b>1</b>. Optionally, the service identifier <b>10</b> may be encapsulated into a source MAC address field in the first packet.
0237The service routing trigger <b>1</b> receives the first packet that carries the service identifier <b>10</b>, and determines, in the second policy information and according to the service identifier <b>10</b>, the service node sequence <b>10</b> corresponding to the service identifier <b>10</b>, and an address of the service routing trigger <b>2</b>; then, after the service routing trigger <b>1</b> triggers the service node <b>1</b> that is corresponding to the service routing trigger <b>1</b> and is in the service node sequence <b>10</b> to process the first packet, the service routing trigger <b>1</b> sends, to the service routing trigger <b>2</b>, a first packet processed by a node in the service node sequence <b>10</b>.
0238If the service node <b>1</b> supports a manner of transparent Ethernet networking, a user service packet whose source MAC address carries the service identifier <b>10</b> is sent to the service node <b>1</b> for processing of application caching and acceleration.
0239The service routing trigger <b>1</b> acquires the service identifier <b>10</b> from the source MAC address field of the service packet returned by the service node <b>1</b>, and sends the user service packet whose source MAC address carries the service identifier <b>10</b> to the service routing trigger <b>2</b> by using a pre-established VxLAN tunnel.
0240The service routing trigger <b>2</b> receives the user service packet whose source MAC address carries the service identifier <b>10</b>, and determines, in the third policy information and according to the service identifier <b>10</b>, that the service node sequence <b>10</b> corresponding to the service identifier <b>10</b> is the service node <b>2</b> (a firewall)-> the service node <b>3</b> (NAT address translation) in a service node sequence corresponding to the service routing trigger <b>2</b>.
0241If the service node <b>2</b> supports the manner of transparent Ethernet networking, a service packet whose source MAC address carries the service identifier <b>10</b> is sent to the service node <b>2</b> for firewall processing.
0242When returned from the service node <b>2</b> to the service routing trigger <b>2</b>, the service packet carries the service identifier <b>10</b>, and the service routing trigger <b>2</b> sends, to the service node <b>3</b>, according to an address of a next service node <b>3</b> in the service node sequence <b>10</b>, the service packet that carries the service identifier <b>10</b> for NAT address translation address processing.
0243A NAT address translation service performed by the service node <b>3</b> belongs to a non-transparent value-added service. The NAT address translation service performed by the service node <b>3</b> changes a source IP address of a service packet, and after a value-added service of NAT address translation has been processed, a processed service packet is directly sent to the Internet network.
Embodiment 11
0244As shown in <figref idref="DRAWINGS">FIG. 10</figref>, technical solutions in this embodiment of the present disclosure may also be applied in a multi-tenant data center scenario. In an application scenario of a public cloud data center, one physical data center is rented to multiple tenants for use, and there may be many tenants, for example, on a data center network that applies a VxLAN (virtual extensible local area network) technology for multi-tenant separation, a quantity of tenants may be more than 16,000,000. When hosts or virtual machines between different subnets of a same tenant interwork with each other, a value-added service node such as a firewall is needed for processing, and different tenants may require different value-added service nodes of firewalls for processing. However, an existing value-added service node device, for example, a device such as a firewall, may not support a latest multi-tenant separation technology (for example, VxLAN) for tenant service separation, or it is difficult for a single physical device to support more than 16,000,000 virtual service node instances. Assuming that an existing value-added service device allows to mark 4K virtual value-added service instances by using a VLAN (Virtual Local Area Network), it may be avoided, by using this technical solution, that a value-added service device needs to be upgraded to support the VxLAN multi-tenant separation technology.
0245As shown in <figref idref="DRAWINGS">FIG. 11</figref>, a service routing trigger is deployed on an aggregation switch or a core switch, and a traffic classifier functional entity is deployed on a ToR (Top Of Rack) switch or a vSwitch (virtual switch) in a server. It is assumed that a firewall value-added service is needed for processing when hosts or virtual machines between different subnets of a same tenant interwork with each other, and each service node device in <figref idref="DRAWINGS">FIG. 11</figref> has a function of processing of a firewall value-added service, and further allows to mark 4K virtual value-added service instances by using a VLAN. If ten service node devices are connected to a service routing trigger instance, by using 40K as a unit, service flows, for which interworking of subnets is needed, of different 40K tenants may be directed to different service routing triggers under control of a controller. When sending a packet to a service node, the service routing trigger may add a VLAN mark to the packet according to a VLAN identifier delivered by the controller, so as to perform multi-instance differentiation processing. The following uses a subnet interworking service flow of a tenant <b>100</b> as an example to describe a specific implementation process.
0246A service node sequence <b>100</b> (firewalls) may be prestored in the controller, or prestored in advance in a policy database that can be accessed by the controller.
0247The controller performs a policy decision according to information about the service node sequence <b>100</b>, subscription information, and physical deployment information of a service node in a service node sequence. Physical deployment information of the service node sequence <b>100</b> provided is shown in Table 3:
0000<tables id="TABLE-US-00003" num="00003"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="5"><colspec colname="1" colwidth="35pt" align="left" /><colspec colname="2" colwidth="35pt" align="center" /><colspec colname="3" colwidth="35pt" align="left" /><colspec colname="4" colwidth="49pt" align="left" /><colspec colname="5" colwidth="63pt" align="left" /><thead><row><entry namest="1" nameend="5" rowsep="1">TABLE 3</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row><row><entry>Service</entry><entry /><entry /><entry>Traffic</entry><entry>First service</entry></row><row><entry>node</entry><entry>Service</entry><entry /><entry>classifier</entry><entry>routing trigger</entry></row><row><entry>sequence</entry><entry>identifier</entry><entry>Subscriber</entry><entry>and rule</entry><entry>and service</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry>Service</entry><entry>100</entry><entry>Tenant</entry><entry>All traffic</entry><entry>Service</entry></row><row><entry>node</entry><entry /><entry>100</entry><entry>classifiers and</entry><entry>routing trigger 1</entry></row><row><entry>sequence</entry><entry /><entry /><entry>subnet</entry><entry>Service</entry></row><row><entry>100</entry><entry /><entry /><entry>interworking</entry><entry>sequence (firewall:</entry></row><row><entry /><entry /><entry /><entry>filtering rule of</entry><entry>service node 1,</entry></row><row><entry /><entry /><entry /><entry>a tenant 100</entry><entry>VLAN identifier</entry></row><row><entry /><entry /><entry /><entry /><entry>101 of a</entry></row><row><entry /><entry /><entry /><entry /><entry>corresponding</entry></row><row><entry /><entry /><entry /><entry /><entry>tenant)</entry></row><row><entry /><entry /><entry /><entry /><entry>Service node</entry></row><row><entry /><entry /><entry /><entry /><entry>sequence ends</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0248The controller delivers first policy information to a traffic classifier, and the controller delivers second policy information to a service routing trigger.
0249The first policy information that is related to the service node sequence <b>100</b> and is delivered by the controller to the traffic classifier includes:
0250a flow filtering rule of a service chain <b>10</b>: “subnet interworking filtering rule of the tenant <b>100</b>”;
0251a service identifier: <b>100</b>;
0252a tenant identifier: <b>100</b>; and
0253address information of a next-hop service node instance: address information of the service routing trigger <b>1</b>.
0254The second policy information delivered by the controller to the service routing trigger <b>1</b> includes:
0255a service identifier: <b>100</b>;
0256a tenant identifier: <b>100</b>; and
0257value-added service node sequence information corresponding to the service routing trigger <b>1</b>:
0258a first value-added service: firewall and subnet interworking routing processing, an IP address or MAC address of the service node <b>1</b>, and the VLAN identifier <b>101</b> of a corresponding tenant; and
0259a service node sequence end identifier.
0260The traffic classifier performs classification according to the flow filtering rule “subnet interworking filtering rule of the tenant <b>100</b>”, which is in the first policy information, of the service routing sequence <b>100</b>; encapsulates the service identifier <b>100</b> into a source MAC address field of a user service packet that is classified by the traffic classifier and belongs to the service node sequence <b>100</b>; performs encapsulation of a VxLAN tunnel on a user service packet into which the service identifier <b>100</b> is encapsulated; encapsulates the tenant identifier <b>100</b> into a VxLAN tenant identifier of the VxLAN tunnel; and finally, sends, to the service routing trigger <b>1</b>, a user service packet into which the service identifier <b>100</b> and the tenant identifier <b>100</b> are encapsulated.
0261The service routing trigger <b>1</b> receives the user service packet whose source MAC address carries the service identifier <b>100</b> and whose VxLAN tenant identifier carries the tenant identifier <b>100</b>; performs service triggering control according to a value-added service sequence (a firewall), which is in the service routing trigger <b>1</b>, of a service node sequence corresponding to the service identifier <b>100</b> in the second policy information; decapsulates the VxLAN tunnel; adds the VLAN identifier <b>101</b> to an Ethernet packet that is transmitted in the tunnel and whose source MAC address carries the service identifier <b>100</b>; and sends the Ethernet packet to the service node <b>1</b>.
0262After completing firewall value-added service processing, the source MAC address of the service packet returned by the service node <b>1</b> to the service routing trigger <b>1</b> carries the service identifier <b>100</b>, and a VLAN identifier field carries the VLAN identifier <b>101</b>. It is determined, according to the second policy information, that the service node sequence ends; then, according to a correspondence between the tenant identifier <b>100</b> and the VLAN identifier <b>101</b> in the second policy information, the VLAN identifier field is removed, the VxLAN tunnel is encapsulated, the tenant identifier <b>100</b> is encapsulated into the VxLAN tenant identifier of the VxLAN tunnel ID, and then routing and forwarding to another subnet of the tenant are performed.
0263According to the technical solutions in embodiments of the present disclosure, on-demand tandem connection of a value-added service in a service node sequence may be resolved, and there is no additional function requirement on the value-added service, which facilitates access by using a third-party value-added service interface. When the technical solutions in the embodiments of the present disclosure are applied, a service node in a service chain may be a third-party service node, which helps to inherit and reuse existing service node investments. The service node may be decoupled from bottom-layer network control, and the service node only needs to focus on specific service implementation, which makes it possible for more software vendors to enter the service field, enriches a service product chain, enhances competitive strength, and stimulates production of value-added service products with good quality and low price.
0264The embodiments of the present disclosure further provide a service chain technical solution in which a basic network supports multiple tenants. A problem of on-demand tandem connection of a value-added service in a service chain when a bottom-layer network supports multiple tenants may be resolved, so that service chain technical solutions are deployable and implementable in a network scenario of supporting multiple tenants. In addition, a value-added service does not need to support a latest multi-tenant technology, for example, a VxLAN (Virtual eXtensible Local Area Network) technology, so that an existing value-added service device, or a value-added service device that supports multiple instances may be still applied when the latest multi-tenant technology is supported, and avoids requirements for upgrade and reconstruction of a value-added service device when the latest multi-tenant technology is supported.
0265A person of ordinary skill in the art may understand that all or a part of the steps of the method embodiments may be implemented by a program instructing relevant hardware. The program may be stored in a computer readable storage medium. When the program runs, the steps of the method embodiments are performed. The foregoing storage medium includes any medium that can store program code, such as a ROM, a RAM, a magnetic disk, or an optical disc.
0266The foregoing descriptions are merely specific implementation manners of the present disclosure, but are not intended to limit the protection scope of the present disclosure. Any variation or replacement readily figured out by a person skilled in the art within the technical scope disclosed in the present disclosure shall fall within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure shall be subject to the protection scope of the claims.
Contents5
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US11310202B2 | Cited by | United States of America | – | Applicant | – |
| US10826835B2 | Cited by | United States of America | – | Search report | – |
| US10382596B2 | Cited by | United States of America | – | Applicant | – |
| US10439931B2 | Cited by | United States of America | – | Search report | – |
| US12132764B2 | Cited by | United States of America | – | Applicant | – |
| US11088990B2 | Cited by | United States of America | – | Applicant | – |
| US12301629B2 | Cited by | United States of America | – | Search report | – |
| US11258761B2 | Cited by | United States of America | – | Applicant | – |
| US2017250917A1 | Cited by | United States of America | – | Search report | – |
| US2019245791A1 | Cited by | United States of America | – | Search report | – |
| US2017250902A1 | Cited by | United States of America | – | Search report | – |
| US10652155B2 | Cited by | United States of America | – | Search report | – |
| US2017250917A1 | Cited by | United States of America | – | Search report | – |
| CN107872392A | Cited by | China | – | Search report | – |
| US2022078113A1 | Cited by | United States of America | – | Search report | – |
| US2017104671A1 | Cited by | United States of America | – | Search report | – |
| US2023318973A1 | Cited by | United States of America | – | Search report | – |
| EP3726789A4 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US11082542B2 | Cited by | United States of America | – | Applicant | – |
| US10944722B2 | Cited by | United States of America | – | Applicant | – |
| US11128600B2 | Cited by | United States of America | – | Applicant | – |
| US10547692B2 | Cited by | United States of America | – | Search report | – |
| US11706138B2 | Cited by | United States of America | – | Search report | – |
| US2017104671A1 | Cited by | United States of America | – | Pre-grant | – |
| US2017250917A1 | Cited by | United States of America | – | Pre-grant | – |
| US2017230467A1 | Cited by | United States of America | – | Pre-grant | – |
| US2022217182A1 | Cited by | United States of America | – | Search report | – |
| US11444868B2 | Cited by | United States of America | – | Search report | – |
| US11374857B2 | Cited by | United States of America | – | Search report | – |
| US12284008B2 | Cited by | United States of America | – | Applicant | – |
| US12289235B2 | Cited by | United States of America | – | Search report | – |
| US11425095B2 | Cited by | United States of America | – | Applicant | – |
| US2021168071A1 | Cited by | United States of America | – | Search report | – |
| US12058108B2 | Cited by | United States of America | – | Applicant | – |
| US2015215172A1 | Cited by | United States of America | – | Pre-grant | – |
| US2016119253A1 | Cited by | United States of America | – | Pre-grant | – |
| US11923920B2 | Cited by | United States of America | – | Search report | – |
| US11277338B2 | Cited by | United States of America | – | Search report | – |
| US11979322B2 | Cited by | United States of America | – | Applicant | – |
| CN109922005A | Cited by | China | – | Search report | – |
| US11005707B2 | Cited by | United States of America | – | Search report | – |
| US11082400B2 | Cited by | United States of America | – | Applicant | – |
| US11005815B2 | Cited by | United States of America | – | Applicant | – |
| US9614739B2 | Cited by | United States of America | – | Search report | – |
| US12184698B2 | Cited by | United States of America | – | Applicant | – |
| US2016269286A1 | Cited by | United States of America | – | Pre-grant | – |
| US11171920B2 | Cited by | United States of America | – | Applicant | – |
| US11122085B2 | Cited by | United States of America | – | Search report | – |
| US11115382B2 | Cited by | United States of America | – | Applicant | – |
| US2011161494A1 | Cites | United States of America | Y | Pre-grant | 1-8, 21-25 |
| US2011161494A1 | Cites | United States of America | Y | Search report | 1-8, 21-25 |
| US2012230325A1 | Cites | United States of America | A | Search report | – |
| US2014003433A1 | Cites | United States of America | Y | Search report | 1-8 |
| US2014003433A1 | Cites | United States of America | Y | Pre-grant | 1-8 |
| US2014314094A1 | Cites | United States of America | A | Search report | – |
| US7561580B1 | Cites | United States of America | Y | Search report | 1-8, 21-25 |
11 members in 4 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 2013075003 | China | W |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| WO2014176740A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN104380658A | China | A | |
| US2016050141A1 | United States of America | A1 | |
| EP2993821A1 | European Patent Office (EPO) | A1 | |
| EP2993821A4 | European Patent Office (EPO) | A4 | |
| CN104380658B | China | B | |
| CN108632098A | China | A | |
| EP2993821B1 | European Patent Office (EPO) | B1 | |
| US10735309B2 | United States of America | B2 | |
| US2020344153A1 | United States of America | A1 | |
| CN108632098B | China | B |
120 transactions on the USPTO file
Allowed after 3 non-final rejections, 3 final rejections and 3 RCEs.
- Non-final rejections
- 3
- Final rejections
- 3
- RCEs
- 3
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Reasons for AllowanceEX.R | EX.R | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| After Final Consideration Program Amendment too ExtensiveAFNE | AFNE | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Mail Interview Summary - Applicant Initiated - TelephonicMEXAT | MEXAT | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| PILOT- Request for After Final Consideration ProgramRAFC | RAFC | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Incoming Letter Pertaining to the DrawingsLTDR | LTDR | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Oath or Declaration Filed (Including Supplemental)C602 | C602 | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalADVISORY ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE AFTER FINAL ACTION FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalADVISORY ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalFINAL REJECTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalRESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINERSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNON FINAL ACTION MAILEDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalDOCKETED NEW CASE - READY FOR EXAMINATIONSTPP | STPP | |
| AssignmentAS | AS |
Numbers
- Publication
- 20160050141
- Application
- 14924499
Titles
- English
- Traffic Classifier, Service Routing Trigger, and Packet Processing Method and System
Patent term adjustment
- A delay
- +147 daysthe office missed an examination deadline
- Applicant delay
- −54 days
- Net adjustment
- 93 days
Classification
- CPC, 4
- H04L41/5054
- H04L45/22
- H04L45/306
- H04L43/028
- IPC, 3
- H04L45 24
- H04L12 707
- H04L12 26