IP Library › Granted Patent US 12,500,932
Granted Patent B2
US 12,500,932 · App. 18/568,817 · Granted Dec 16, 2025

Network transport layer data processing method, and device and storage medium

Inventor: Tian Guo (Shenzhen, CN)
Assignee: ZTE CORPORATION
H04L63/166G06F8/62H04L63/0485
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,932
App. No.
18/568,817
Granted
Dec 16, 2025
Kind
B2
Abstract

The embodiments of the present application relate to the field of communications. Disclosed are a network transport layer data processing method, and a device and a storage medium. The network transport layer data processing method in the present application is applied to an extended Berkeley packet filter (eBPF) program that runs in a kernel. The method comprises: acquiring a network transport layer data packet that needs to be distributed; parsing the network transport layer data packet, and determining a network transport layer data processing mode that needs to be performed on the network transport layer data packet; and processing the network transport layer data packet according to the network transport layer data processing mode.

Claims (65)

1 . A network transport layer data processing method, applied to an extended Berkeley packet filter (eBPF) program that runs in a kernel, and comprising:

acquiring a network transport layer data packet that needs to be distributed;

parsing the network transport layer data packet, and determining a network transport layer data processing mode that needs to be performed on the network transport layer data packet; and

processing the network transport layer data packet according to the network transport layer data processing mode;

wherein parsing the network transport layer data packet, and determining the network transport layer data processing mode that needs to be performed on the network transport layer data packet comprise:

parsing the network transport layer data packet, and extracting a protocol header of the network transport layer data packet;

judging whether the network transport layer data packet needs to be encrypted or decrypted according to the protocol header and pre-configured encryption-decryption conditions, the encryption-decryption conditions being provided by a management program that runs on a user plane;

determining, under the condition that the network transport layer data packet needs to be encrypted, that the network transport layer data processing mode that needs to be performed on the network transport layer data is an encryption processing mode; and

determining, under the condition that the network transport layer data packet needs to be decrypted, that the network transport layer data processing mode that needs to be performed on the network transport layer data is a decryption processing mode.

2 . The network transport layer data processing method according to claim 1 , wherein the network transport layer data processing mode is the encryption processing mode; andprocessing the network transport layer data packet according to the network transport layer data processing mode comprises: selecting a target encryption rule from pre-configured encryption rules, the encryption rules being provided by the management program; performing encryption processing on a load part of the network transport layer data packet according to the target encryption rule; updating the protocol header according to the encrypted load part to obtain the encrypted network transport layer data packet; and handing over the encrypted network transport layer data packet to the kernel, and distributing the encrypted network transport layer data packet through the kernel.

3 . The network transport layer data processing method according to claim 1 , wherein the network transport layer data processing mode is the decryption processing mode; and processing the network transport layer data packet according to the network transport layer data processing mode comprises: selecting a target decryption rule from pre-configured decryption rules, the decryption rules being provided by the management program; performing decryption processing on a load part of the network transport layer data packet according to the target decryption rule; updating the protocol header according to the decrypted load part to obtain the decrypted network transport layer data packet; and handing over the decrypted network transport layer data packet to the kernel, and distributing the decrypted network transport layer data packet through the kernel.

4 . The network transport layer data processing method according to claim 1 , further comprising:

receiving a configuration information update instruction issued by the management program that runs on the user plane; and

updating pre-configured configuration information according to the configuration information update instruction, the configuration information comprising any one or more of the encryption-decryption conditions, the encryption rules, and the decryption rules.

5 . A network transport layer data processing method, applied to a management program that runs on a user plane, and comprising:

monitoring, after the management program is started, whether an operation instruction for an eBPF program that runs in a kernel and/or statistical data for a network transport layer data packet processing process collected by the eBPF program are/is received;

processing the eBPF program according to the operation instruction under the condition that the operation instruction for the eBPF program is received; and

processing the statistical data under the condition that the statistical data for the network transport layer data packet processing process collected by the eBPF program is received, the eBPF program is used to parse the network transport layer data packet. determine a network transport layer data processing mode that needs to be performed on the network transport layer data packet: and process the network transport layer data packet according to the network transport layer data processing mode; wherein program is used to parse the network transport layer data packet, determine a network transport layer data processing mode that needs to be performed on the network transport layer data packet comprise:

parsing the network transport layer data packet, and extracting a protocol header of the network transport layer data packet;

judging whether the network transport layer data packet needs to be encrypted or decrypted according to the protocol header and pre-configured encryption-decryption conditions, the encryption-decryption conditions being provided by a management program that runs on a user plane;

determining, under the condition that the network transport layer data packet needs to be encrypted, that the network transport layer data processing mode that needs to be performed on the network transport layer data is an encryption processing mode; and

determining, under the condition that the network transport layer data packet needs to be decrypted, that the network transport layer data processing mode that needs to be performed on the network transport layer data is a decryption processing mode.

6 . The network transport layer data processing method according to claim 5 , wherein the operation instruction is a configuration information update instruction, or an eBPF program replacement instruction, or an eBPF program uninstalling instruction; and

processing the eBPF program according to the operation instruction under the condition that the operation instruction for the eBPF program is received comprises:

extracting, when the operation instruction is the configuration information update instruction, extract configuration information that needs to be updated from the configuration information update instruction, and updating a configuration information mapping table corresponding to the eBPF program according to the extracted configuration information that needs to be updated;

extracting, when the operation instruction is the eBPF program replacement instruction, a replacement eBPF program from the eBPF program replacement instruction, registering the replacement eBPF program in a kernel, and uninstalling the eBPF program that runs in the kernel after the replacement eBPF program is registered in the kernel; and

uninstalling the eBPF program that runs in the kernel when the operation instruction is the eBPF program uninstalling instruction.

7 . The network transport layer data processing method according to claim 5 , wherein processing the statistical data under the condition that the statistical data for the network transport layer data packet processing process collected by the eBPF program is received comprises:

storing the statistical data in a preset storage area and/or displaying the statistical data in a preset form.

8 . The network transport layer data processing method according to claim 5 , wherein before monitoring, after the management program is started, whether the operation instruction for the eBPF program that runs in the kernel and/or the statistical data for the network transport layer data packet processing process collected by the eBPF program are/is received, the method further comprises:

reading configuration information from a preset address, the configuration information comprising any one or more of encryption-decryption conditions, encryption rules, and decryption rules;

checking integrity of the eBPF program that needs to be registered into the kernel and the configuration information;

registering, under the condition that the eBPF program and the configuration information are complete, the eBPF program into the kernel, such that the eBPF program runs in the kernel; and

configuring the configuration information into the configuration information mapping table corresponding to the eBPF program.

9 . A network transport layer data processing device, comprising: a management program that runs on a user plane, an eBPF program that runs in a kernel, at least one processor, and a memory, in communication connection with the at least one processor, wherein

the management program is used for loading the eBPF program into the kernel of an environment located, such that the eBPF program runs in the kernel, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so as to enable the at least one processor to execute the network transport layer data processing method according to claim 1 .

10 . A computer-readable storage medium, storing a computer program, and the computer program, when executed by a processor, implementing the network transport layer data processing method according to claim 1 .

11 . The network transport layer data processing method according to claim 1 , further comprising:

receiving a configuration information update instruction issued by the management program that runs on the user plane; and

updating pre-configured configuration information according to the configuration information update instruction, the configuration information comprising any one or more of the encryption-decryption conditions, the encryption rules, and the decryption rules.

12 . The network transport layer data processing method according to claim 2 , further comprising:

receiving a configuration information update instruction issued by the management program that runs on the user plane; and

updating pre-configured configuration information according to the configuration information update instruction, the configuration information comprising any one or more of the encryption-decryption conditions, the encryption rules, and the decryption rules.

13 . The network transport layer data processing method according to claim 3 , further comprising:

receiving a configuration information update instruction issued by the management program that runs on the user plane; and

updating pre-configured configuration information according to the configuration information update instruction, the configuration information comprising any one or more of the encryption-decryption conditions, the encryption rules, and the decryption rules.

14 . The network transport layer data processing method according to claim 1 , further comprising:

receiving a data packet with illegal content sent by an upper layer application;

fixing a data in the data packet with illegal content; and

sending the data to the kernel.

15 . The network transport layer data processing method according to claim 6 , wherein processing the statistical data under the condition that the statistical data for the network transport layer data packet processing process collected by the eBPF program is received comprises:

storing the statistical data in a preset storage area and/or displaying the statistical data in a preset form.

16 . The network transport layer data processing method according to any one of claim 6 , wherein before monitoring, after the management program is started, whether the operation instruction for the eBPF program that runs in the kernel and/or the statistical data for the network transport layer data packet processing process collected by the eBPF program are/is received, the method further comprises:

reading configuration information from a preset address, the configuration information comprising any one or more of encryption-decryption conditions, encryption rules, and decryption rules;

checking integrity of the eBPF program that needs to be registered into the kernel and the configuration information;

registering, under the condition that the eBPF program and the configuration information are complete, the eBPF program into the kernel, such that the eBPF program runs in the kernel; and

configuring the configuration information into the configuration information mapping table corresponding to the eBPF program.

17 . The network transport layer data processing method according to any one of claim 7 , wherein before monitoring, after the management program is started, whether the operation instruction for the eBPF program that runs in the kernel and/or the statistical data for the network transport layer data packet processing process collected by the eBPF program are/is received, the method further comprises:

reading configuration information from a preset address, the configuration information comprising any one or more of encryption-decryption conditions, encryption rules, and decryption rules;

checking integrity of the eBPF program that needs to be registered into the kernel and the configuration information;

registering, under the condition that the eBPF program and the configuration information are complete, the eBPF program into the kernel, such that the eBPF program runs in the kernel; and

configuring the configuration information into the configuration information mapping table corresponding to the eBPF program.

18 . A network transport layer data processing device, comprising: a management program that runs on a user plane, an eBPF program that runs in a kernel, at least one processor, and a memory, in communication connection with the at least one processor, wherein

the management program is used for loading the eBPF program into the kernel of an environment located, such that the eBPF program runs in the kernel, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so as to enable the at least one processor to execute the network transport layer data processing method according to claim 5 .

19 . A computer-readable storage medium, storing a computer program, and the computer program, when executed by a processor, implementing the network transport layer data processing method according to claim 5 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2023
From: GUO, TIAN
To: ZTE CORPORATION
Reel/Frame 065821/0372 →
Priority Claims (1)
CN 202110655627.0 · Jun 11, 2021 · national
Continuity (1)
Related Publication 20240275816A1 · Aug 15, 2024
References Cited (20)
US 20070156919A1 · Potti · 2007 [cited by examiner]
US 20080273462A1 · Klish · 2008 [cited by examiner]
US 20180288198A1 · Pope · 2018 [cited by examiner]
US 20190173841A1 · Wang · 2019 [cited by examiner]
US 20190385057A1 · Litichever · 2019 [cited by examiner]
US 20210058989A1 · Simsek · 2021 [cited by examiner]
US 20220321532A1 · Du · 2022 [cited by examiner]
CN 110352400A · 2019 [cited by applicant]
CN 111580931A · 2020 [cited by applicant]
CN 111818041A · 2020 [cited by applicant]
CN 112817597A · 2021 [cited by applicant]
CN 112860484A · 2021 [cited by applicant]
JP 2009009477A · 2009 [cited by applicant]
JP 2010021887A · 2010 [cited by applicant]
Chandranmenon et al., “Trading packet headers for packet processing”, IEEE/ACM Transactions on Networking, vol. 4, Issue: 2, Apr. 1996. [cited by examiner]
Bu et al. , “Encrypted Network Traffic Classification Using Deep and Parallel Network-in-Network Models,” in IEEE Access, vol. 8, pp. 132950-132959, (Year: 2020). [cited by examiner]
Tran Viet-Hoang et al.:“Beyond socket options: Towards fully extensible Linux transport stacks”, Computer Communications, Elsevier Science Publishers BV , Amsterdam , NL, vol. 162 , Aug. 17, 2020 (Aug. 17, 2020) , pp. 1… [cited by applicant]
The extended European search report of the corresponding EP Patent Application No. 22819245.6 dated May 7, 2025. [cited by applicant]
(ISA/237) Written Opinion of the International Searching Authority dated Jun. 24, 2022. [cited by applicant]
International search report of the corresponding PCT Application No. PCT/CN2022/090383 mailed on Jun. 24, 2022 along with English translation thereof. [cited by applicant]