Movatterモバイル変換


[0]ホーム

URL:


CN106936719A - A kind of IP messages strategy matching method - Google Patents

A kind of IP messages strategy matching method
Download PDF

Info

Publication number
CN106936719A
CN106936719ACN201710348137.XACN201710348137ACN106936719ACN 106936719 ACN106936719 ACN 106936719ACN 201710348137 ACN201710348137 ACN 201710348137ACN 106936719 ACN106936719 ACN 106936719A
Authority
CN
China
Prior art keywords
strategy
messages
parameters
matched
address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201710348137.XA
Other languages
Chinese (zh)
Inventor
王子彤
姜凯
梁智豪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Jinan Inspur Hi Tech Investment and Development Co Ltd
Original Assignee
Jinan Inspur Hi Tech Investment and Development Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Jinan Inspur Hi Tech Investment and Development Co LtdfiledCriticalJinan Inspur Hi Tech Investment and Development Co Ltd
Priority to CN201710348137.XApriorityCriticalpatent/CN106936719A/en
Publication of CN106936719ApublicationCriticalpatent/CN106936719A/en
Pendinglegal-statusCriticalCurrent

Links

Classifications

Landscapes

Abstract

The present invention discloses a kind of IP messages strategy matching method, it is related to network data processing field, host computer sets the parameters of IP message strategies, and distributing policy is to slave computer memory module, the storage address for obtaining strategy by the transformation calculations of parameters is stored, and parameters are parsed when IP messages are reached, and policy store address to be matched is obtained according to identical transformation calculations, it is compared with the strategy in slave computer memory module and is matched, obtains IP message strategies.

Description

A kind of IP messages strategy matching method
Technical field
The present invention discloses a kind of IP messages strategy matching method, is related to network data processing field.
Background technology
In network exchange or routing device, one or more Policy Table is often maintain, to Match IP message strategy,The IP messages of access arrangement are forwarded, are abandoned, a series for the treatment of such as encryption and decryption.Because contents in table may be thousands of tens of thousands ofEven more many, message strategy matching speed is with efficiency just into the key point of influence network service speed.When need set certainWhen a certain parameter meets the matching strategy of all messages of ad hoc rules under the conditions of individual, generally require to add many rules, abilityAll may cover, therefore tactful bar number can increase in Policy Table, and matching efficiency can equally decrease.The present invention is disclosedA kind of IP messages strategy matching method, host computer distributing policy to policy store module, by the transformation calculations of certain wayGo out every specific storage address of strategy, the policy store address of matching can be quickly found out by same procedure when message is reached,Efficiently complete strategy matching.Tactful each parameter can be set to " all " simultaneously, the bit value whole zero setting of correspondence parameter, Ran HouzaiCarry out Transformation Matching so that all legal IP messages can be rapidly completed matching, can rule of simplification setting procedure, it is completeRule setting function, while rate matched is ensured, saves storage resource.
IP message structures IP agreement is network layer protocol, and the data structure of Internet is commonly referred to as IP messages.
The content of the invention
The present invention provides a kind of IP messages strategy matching method, with highly versatile, be easy to implement the features such as, with wideApplication prospect.
Concrete scheme proposed by the present invention is:
A kind of IP messages strategy matching method:
Host computer sets the parameters of IP message strategies, and distributing policy is to slave computer memory module, by parametersThe storage address that transformation calculations obtain strategy is stored, and parameters are parsed when IP messages are reached, and is counted according to identical conversionCalculation obtains policy store address to be matched, is compared with the strategy in slave computer memory module and matched, and obtains IP message plansSlightly.
If the parameters of the parsing IP messages, obtain in policy store address to be matched according to identical transformation calculationsIt is sky to hold, then IP messages are processed according to default processing method, address contents reading is otherwise stored the policies into, with slave computerStrategy in memory module is compared matching, obtains IP message strategies.
The parameters of the IP messages strategy are set to meet the particular value of network message general rule or by itemsParameter is respectively set to be owned, and represents that corresponding strategy is all suitable for all network messages for meeting parameter current.
The parameter that host computer sets IP message strategies is all, and by parameter whole bit value zero setting, distributing policy is arrived downPosition machine memory module, the new storage address of strategy is obtained by the transformation calculations of parameter, and IP messages parse parameters when reaching,Policy store address to be matched is obtained according to identical transformation calculations, is compared with the new storage address of strategy in memory moduleMatching, obtains IP message strategies.
If IP messages do not have to the policy store address to be matched reached with the new storage address of strategy in memory moduleThere is matching, then checked whether that parameter setting is all, if in the presence of, by the corresponding parameter whole bit value zero setting of IP messages,Matched again.
The parameters of the IP messages strategy include:Source IP address, source subnet mask, purpose IP address, purpose subnetMask, protocol type, source port number, destination slogan.
Usefulness of the present invention is:
The present invention provides a kind of IP messages strategy matching method, and host computer sets the parameters of IP message strategies, and issues planSlave computer memory module is slightly arrived, the storage address for obtaining strategy by the transformation calculations of parameters is stored, when IP messagesParameters are parsed during arrival, policy store address to be matched is obtained according to identical transformation calculations, with slave computer memory moduleIn strategy be compared matching, obtain IP message strategies;
Compared with prior art, the present invention can obtain every specific storage address of strategy by transformation calculations mode, work as messageThe policy store address of matching can be quickly found out during arrival by same procedure, strategy matching is efficiently completed.While can be tactful eachParameter is set to " all ", the bit value whole zero setting of correspondence parameter, Transformation Matching is then carried out again so that all legalIP messages can be rapidly completed matching, can rule of simplification setting procedure, complete rule setting function, in the same of guarantee rate matchedWhen, save storage resource.
Brief description of the drawings
Fig. 1 is the inventive method schematic flow sheet;
Fig. 2 is that parameter is set to all rear the inventive method schematic flow sheets.
Specific embodiment
A kind of IP messages strategy matching method of present invention offer, the parameters of host computer setting IP message strategies, and underHair strategy obtains tactful storage address and is stored to slave computer memory module, by the transformation calculations of parameters, works as IPMessage parses parameters when reaching, and policy store address to be matched is obtained according to identical transformation calculations, is stored with slave computerStrategy in module is compared matching, obtains IP message strategies.
With reference to accompanying drawing, specific explanations explanation is carried out to the present invention.And specific embodiment described herein is only used to solveThe present invention is released, is not intended to limit the present invention.
With reference to Fig. 1, the technology specifically comprises the steps of:
(1)Every parameters of IP message strategies are set by upper computer software, slave computer strategy is issued to after being provided withMemory module is stored, and storage address is made ad hoc fashion conversion and obtained by each parameter;
(2)When network IP messages are reached, outgoing packet parameters are parsed, obtain possible by identical particular transform modePolicy store address;
(3)If this address content is sky, illustrate without corresponding strategy, IP messages are processed according to default processing method;It is noThen, this address content is read, is compared and matches with parameter and strategy in policy store module, obtain IP message strategies;
Above-mentioned particular transform mode can be realized using hash conversion;
The parameters of above-mentioned IP messages, can also be by parameter in addition to it may be configured as meeting the particular value of network message general rule" all " are respectively set to, represent that this strategy is all suitable for all network messages for meeting parameter current;Such as can be by source port" 21 " are set to, be may be alternatively provided as " all ", represented from " 1 " to any value " 65535 ";
As shown in Fig. 2 when a certain parameter is set to " all ", by parameter whole bit value zero setting, such as by source port 16Data whole zero setting(16’b0), then carry out step(1)Particular transform, obtain new policy store address;
When IP messages are reached, first by the step(2)And(3)Particular transform is carried out to each parameter to obtain storage address and openBeginning is matched, if not matching, parameter setting has been checked whether for " all ", if in the presence of the ginseng for being set as " all "Number, then by the corresponding parameter whole bit value zero setting of IP messages, then by the step(2)And(3)Matched, completed current IPThe matching process of message.
The parameters of above-mentioned IP messages strategy can include:Source IP address, source subnet mask, purpose IP address, purposeSubnet mask, protocol type, source port number, destination slogan etc..
Can rule of simplification setting procedure, complete rule setting function, in the same of guarantee rate matched using the inventive methodWhen, save storage resource.

Claims (6)

CN201710348137.XA2017-05-172017-05-17A kind of IP messages strategy matching methodPendingCN106936719A (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201710348137.XACN106936719A (en)2017-05-172017-05-17A kind of IP messages strategy matching method

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201710348137.XACN106936719A (en)2017-05-172017-05-17A kind of IP messages strategy matching method

Publications (1)

Publication NumberPublication Date
CN106936719Atrue CN106936719A (en)2017-07-07

Family

ID=59430195

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201710348137.XAPendingCN106936719A (en)2017-05-172017-05-17A kind of IP messages strategy matching method

Country Status (1)

CountryLink
CN (1)CN106936719A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN107707485A (en)*2017-10-232018-02-16济南浪潮高新科技投资发展有限公司A kind of range type IP message strategy matching circuits and method
CN108449445A (en)*2018-04-132018-08-24济南浪潮高新科技投资发展有限公司A kind of range type message match circuit and method
CN108650181A (en)*2018-04-202018-10-12济南浪潮高新科技投资发展有限公司A kind of IP packet strategy matching circuit and method

Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN102111331A (en)*2010-12-172011-06-29曙光信息产业(北京)有限公司Matching method based on hash table and adopting mask five-element rule
US20140090014A1 (en)*2005-11-222014-03-27Fortinet, Inc.Policy-based content filtering
CN104184842A (en)*2013-05-242014-12-03中兴通讯股份有限公司Message forwarding method and device
CN104579970A (en)*2013-10-292015-04-29国家计算机网络与信息安全管理中心 A policy matching method and device for IPv6 packets

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20140090014A1 (en)*2005-11-222014-03-27Fortinet, Inc.Policy-based content filtering
CN102111331A (en)*2010-12-172011-06-29曙光信息产业(北京)有限公司Matching method based on hash table and adopting mask five-element rule
CN104184842A (en)*2013-05-242014-12-03中兴通讯股份有限公司Message forwarding method and device
CN104579970A (en)*2013-10-292015-04-29国家计算机网络与信息安全管理中心 A policy matching method and device for IPv6 packets

Cited By (3)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN107707485A (en)*2017-10-232018-02-16济南浪潮高新科技投资发展有限公司A kind of range type IP message strategy matching circuits and method
CN108449445A (en)*2018-04-132018-08-24济南浪潮高新科技投资发展有限公司A kind of range type message match circuit and method
CN108650181A (en)*2018-04-202018-10-12济南浪潮高新科技投资发展有限公司A kind of IP packet strategy matching circuit and method

Similar Documents

PublicationPublication DateTitle
CN103685467B (en)A kind of Internet of Things interconnects platform and its communication means
CN109639579B (en)Multicast message processing method and device, storage medium and processor
Bando et al.FlashTrie: beyond 100-Gb/s IP route lookup using hash-based prefix-compressed trie
CN112449751B (en)Data transmission method, switch and station
CN106657637A (en)Handheld device capable of providing data tethering services while maintaining suite of handheld service functions
CN102065021B (en)IPSecVPN (Internet Protocol Security Virtual Private Network) realizing system and method based on NetFPGA (Net Field Programmable Gate Array)
JP6395867B2 (en) OpenFlow communication method and system, control unit, and service gateway
CN104270475A (en)System and method for achieving intercommunication between IPv4 network and IPv6 network based on NAT64
CN117378172A (en) Throughput of a single VPN connection using multiple processing cores
CN106936719A (en)A kind of IP messages strategy matching method
CN101908996B (en) Method for accessing private network, data transmission method, device and system
CN110061921B (en)Cloud platform data packet distribution method and system
US20130294450A1 (en)Optimized trie-based address lookup
CN106487769B (en)Method and device for realizing Access Control List (ACL)
CN110276602A (en) IoT-oriented block chain hierarchical consensus method, system and electronic equipment
CN109309570A (en)Quantum key method used in SSL VPN and relevant device and storage medium
Touch et al.The RNA metaprotocol
CN107919973B (en) Method and apparatus for configuring network device parameters
US20150256459A1 (en)Packet processing method and apparatus
CN115865802B (en) Traffic mirroring method, device, virtual machine platform and storage medium of virtual instance
CN102420740B (en)Method and system for managing keys of routing protocol
CN101977189A (en)Trusted authentication and safe access control method of MPLS network
EP4618520A1 (en)Data packet transmission method, switch, and storage medium
CN118175084A (en)Topology restoration method based on communication protocol and related equipment
WO2014190843A1 (en)Input parameter generation method and device

Legal Events

DateCodeTitleDescription
PB01Publication
PB01Publication
SE01Entry into force of request for substantive examination
SE01Entry into force of request for substantive examination
RJ01Rejection of invention patent application after publication
RJ01Rejection of invention patent application after publication

Application publication date:20170707


[8]ページ先頭

©2009-2025 Movatter.jp