Virtual local area network configuration method and device based on Ethernet gateway controller, equipment and medium

By collecting multi-dimensional vehicle status data in real time through the Ethernet gateway controller and optimizing VLAN configuration using reinforcement learning strategies and security protocols, the configuration problem of the vehicle network in a dynamic environment is solved, intelligent decision-making and safe execution are achieved, and network resource utilization and system reliability are improved.

CN120750765APending Publication Date: 2025-10-03SHANGHAI QINGJIAN AUTOMOTIVE TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510975792.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Existing in-vehicle virtual LAN configuration solutions are unable to respond quickly to dynamic driving environments, remote upgrades, and network security threats, and the configuration policy library lacks real-time optimization capabilities, resulting in network jitter and insufficient security, making it difficult to meet the real-time, reliability, and security requirements of smart cars.

Method used

Multi-dimensional vehicle status data is collected in real time through the Ethernet gateway controller, and the optimal VLAN configuration template is selected using reinforcement learning strategy. The configuration plan with time and space constraints is generated in combination with the real-time network topology. The configuration instruction sequence is issued through the security protocol, and the configuration effect is evaluated in real time. The rollback operation is triggered in case of abnormality, forming a closed-loop control system of perception-decision-execution-verification.

Benefits of technology

It realizes precise triggering, intelligent decision-making and safe execution of vehicle networks in complex dynamic environments, improving network resource utilization, safety response speed and system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750765A_ABST
    Figure CN120750765A_ABST
Patent Text Reader

Abstract

The invention relates to a virtual local area network configuration method and device based on an Ethernet gateway controller, equipment and a medium. The method comprises the following steps: acquiring vehicle multi-dimensional state data and calculating a network reconstruction demand degree through an Ethernet gateway controller, and generating a reconstruction trigger signal when the demand degree exceeds a threshold value; responding to the signal, dynamically selecting an optimal VLAN configuration template from a preset library by adopting a reinforcement learning strategy, and generating a configuration scheme with space-time constraint in combination with network topology; the risk level is analyzed and evaluated based on the scheme and the entropy value of the network topology, a configuration instruction sequence for risk optimization is generated, and the configuration instruction sequence is reliably issued to target equipment through a security protocol; a sensing-decision-execution-verification closed-loop control system is formed by verifying the configuration effect through the nodes and triggering a rollback mechanism when the configuration is abnormal, accurate triggering, intelligent decision, safe execution and reliable recovery of configuration of the vehicle-mounted network in a complex dynamic environment are achieved, and the network resource utilization rate, the safe response speed and the system reliability are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of vehicle control, and in particular relates to a virtual local area network configuration method, device, equipment and medium based on an Ethernet gateway controller. Background Art

[0002] With the rapid development of intelligent connected vehicles, in-vehicle network architecture is undergoing a major transformation from traditional buses to Ethernet. Automotive Ethernet, with its high bandwidth and low latency, is gradually becoming the backbone network supporting core functions such as advanced driver assistance systems and intelligent cockpits. In this evolution, virtual local area network (VLAN) technology, as a key means of isolating functional domains and improving network resource utilization, has been widely adopted in in-vehicle network design.

[0003] Current in-vehicle VLAN configuration primarily relies on a static, predefined model, where switch port parameters are fixed using specialized tools during the vehicle manufacturing phase. This model has gradually exposed significant flaws in dynamic driving environments: when the vehicle enters autonomous driving mode, the surge in sensor data streams leads to an imbalance in existing bandwidth allocation; during remote upgrades, critical communication links are susceptible to interference from unnecessary traffic; and when encountering network security threats, affected areas cannot be quickly isolated. While some solutions attempt to trigger configuration updates through diagnostic interfaces, their response speed and autonomous decision-making capabilities are still limited by external intervention mechanisms.

[0004] While dynamic VLAN technology, which has emerged in recent years, can adjust configurations based on network status, it still faces bottlenecks in practical applications: First, the triggering mechanism relies on simple threshold judgments, which lacks the accuracy of coordinated responses to multi-dimensional state changes; second, the template selection of the configuration policy library lacks real-time optimization capabilities, making it difficult to adapt to complex driving scenarios; third, the configuration verification process has a single point of failure risk, and the reliability of abnormal rollback needs to be improved. In particular, during high-speed driving or sudden safety incidents, network jitter caused by decision delays and execution risks in existing solutions has become a key factor restricting the functional safety of smart cars.

[0005] Therefore, there is an urgent need for an on-board VLAN management solution that can autonomously perceive the vehicle's operating status, intelligently decide on network configuration, and safely perform dynamic adjustments to meet the triple stringent requirements of smart cars for network real-time, reliability, and security. Summary of the Invention

[0006] Based on this, it is necessary to provide a virtual local area network configuration method, device, equipment and medium based on an Ethernet gateway controller to address the above technical problems.

[0007] In a first aspect, the present application provides a method for configuring a virtual local area network based on an Ethernet gateway controller, comprising: Collect multi-dimensional vehicle status data through the Ethernet gateway controller, calculate the network reconstruction demand based on the multi-dimensional vehicle status data, and generate a dynamic reconstruction trigger signal when the network reconstruction demand exceeds a threshold; In response to the dynamic reconstruction trigger signal, a reinforcement learning strategy is used to select the optimal VLAN configuration template from the configuration policy library, and a VLAN configuration scheme with temporal and spatial constraints is generated based on the real-time network topology. Based on the VLAN configuration scheme and the network topology entropy value analysis of the real-time network topology, a risk-optimized configuration instruction sequence is generated and issued to the target network device through a security protocol for execution; The configuration effect of the configuration instruction sequence is evaluated by the verification node to obtain an evaluation result; when the evaluation result is abnormal, a network configuration rollback operation based on the network configuration snapshot stored before the configuration is executed is triggered.

[0008] In a second aspect, the present application further provides a virtual local area network configuration device based on an Ethernet gateway controller, for implementing the method described in the first aspect, the device comprising: Data acquisition module, used to collect multi-dimensional vehicle status data through Ethernet gateway controller; A demand assessment module is used to calculate the network reconfiguration demand based on multi-dimensional vehicle status data and generate a dynamic reconfiguration trigger signal when the network reconfiguration demand exceeds a threshold; A configuration scheme generation module is used to respond to a dynamic reconstruction trigger signal, select the optimal VLAN configuration template from the configuration strategy library using a reinforcement learning strategy, and generate a VLAN configuration scheme with time and space constraints based on the real-time network topology; The instruction sequence generation and issuance module is used to analyze the network topology entropy value based on the VLAN configuration scheme and the real-time network topology, generate risk-optimized configuration instruction sequences, and issue and execute the configuration instruction sequences to the target network devices through the security protocol; The configuration effect evaluation module is used to evaluate the configuration effect of the configuration instruction sequence through the verification node and obtain the evaluation result; The rollback trigger module is used to trigger a network configuration rollback operation based on the network configuration snapshot stored before the configuration is executed when the evaluation result is abnormal.

[0009] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements a virtual local area network configuration method based on an Ethernet gateway controller as in the first aspect.

[0010] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a virtual local area network configuration method based on an Ethernet gateway controller as in the first aspect.

[0011] The above-mentioned virtual local area network configuration method, device, equipment and medium based on the Ethernet gateway controller collects vehicle multi-dimensional status data in real time through the Ethernet gateway controller and calculates the network reconstruction demand, and generates a reconstruction trigger signal when the demand exceeds the threshold; after responding to this signal, a reinforcement learning strategy is used to dynamically select the optimal VLAN configuration template from the preset library, and a configuration scheme with time and space constraints is generated in combination with the real-time network topology; then, based on the entropy value analysis of the scheme and the network topology, the risk level is evaluated, and a risk-optimized configuration instruction sequence is generated, which is reliably issued to the target device through the security protocol; finally, the configuration effect is verified through the node, and a rollback mechanism is triggered in the event of an abnormality, forming a closed-loop control system of perception-decision-execution-verification, realizing accurate triggering, intelligent decision-making, safe execution and reliable recovery of the vehicle network configuration in a complex dynamic environment, significantly improving network resource utilization, security response speed and system reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0013] Figure 1 A flow chart of a method for configuring a virtual local area network based on an Ethernet gateway controller provided by the present invention; Figure 2 A schematic diagram of a flow chart of generating a configuration instruction sequence in an optional embodiment of the present invention; Figure 3 This is a structural diagram of a virtual local area network configuration device based on an Ethernet gateway controller provided by the present invention. DETAILED DESCRIPTION

[0014] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0015] refer to Figure 1 , which presents a flow chart of a virtual local area network configuration method based on an Ethernet gateway controller provided by the present application, the method comprising the following steps: S1. Collect multi-dimensional vehicle status data through the Ethernet gateway controller, calculate the network reconstruction demand based on the multi-dimensional vehicle status data, and generate a dynamic reconstruction trigger signal when the network reconstruction demand is greater than a threshold.

[0016] Specifically, the Ethernet gateway controller collects multi-dimensional vehicle status data in real time through interfaces such as the vehicle's CAN bus, LIN bus, and in-vehicle Ethernet. This includes data from the powertrain, braking system, intelligent driving system, and electronic stability control system. For example, powertrain data includes engine / motor speed, torque, and throttle position; braking system data includes brake pressure and brake pedal travel; intelligent driving system data includes camera images, radar distance information, and lidar point cloud data; and electronic stability system data includes acceleration, steering angle, and wheel speed.

[0017] The formula for calculating network reconstruction requirement can be used:

[0018] Where w i It is the weight of each data dimension, which is preset according to its impact on the network configuration. For example, the weight of the intelligent driving system data can be set higher; f i (Data Change Rate i ,Data stability i ) is a function of data change rate and stability, used to measure the impact of this data dimension on network reconfiguration requirements. When the reconfiguration requirement exceeds a set threshold (this threshold can be determined through experiments and simulations to balance the timeliness and stability of network reconfiguration), the Ethernet gateway controller generates a dynamic reconfiguration trigger signal.

[0019] S2. In response to the dynamic reconstruction trigger signal, a reinforcement learning strategy is used to select the optimal VLAN configuration template from the configuration strategy library, and a VLAN configuration scheme with time and space constraints is generated in combination with the real-time network topology.

[0020] Specifically, reinforcement learning is based on a Markov decision process and maintains a state-action value function Q(s,a), where s represents the vehicle state (including speed, driving mode, network load, etc.) and a represents the action of selecting a VLAN configuration template from the configuration policy library. Through interactive learning with the environment, a strategy for selecting the optimal configuration template under different states is derived, i.e., a strategy that maximizes cumulative reward. The reward function can be: reward = a⋅network bandwidth utilization + b⋅data transmission latency + c⋅network security index. Here, a, b, and c are weight coefficients that can be determined based on actual needs.

[0021] At the same time, the Ethernet gateway controller uses network discovery protocols (such as the Link Layer Discovery Protocol) to obtain real-time network topology information, including the IP addresses, MAC addresses, port status, and connection relationships of network devices. It combines the selected VLAN configuration template with the real-time network topology to generate a VLAN configuration plan with temporal and spatial constraints.

[0022] Among them, the time constraint can be: the VLAN configuration takes effect within a specific time window, for example, in autonomous driving mode, the configuration is effective from the time the vehicle starts to the time it stops; the spatial constraint can be: the VLAN configuration is adjusted based on the vehicle location information (obtained via GPS), for example, enabling a specific sensor data transmission channel at high speeds.

[0023] S3: Based on the network topology entropy analysis of the VLAN configuration scheme and the real-time network topology, a risk-optimized configuration instruction sequence is generated, and the configuration instruction sequence is sent to the target network device through a security protocol for execution.

[0024] Specifically, network topology entropy reflects network complexity and uncertainty. Its calculation takes into account factors such as the number of network nodes, the complexity of connectivity, and the distribution of data traffic. This entropy is derived using, for example, a graph-theoretic entropy formula. Based on this analysis, a risk-optimized configuration instruction sequence is generated, optimizing instruction order and parameters to minimize the impact of the configuration process on network stability.

[0025] After the configuration command sequence is generated, it is encrypted and encapsulated using a security protocol to ensure tamper-proof and leak-proof transmission. The Ethernet gateway controller issues the command sequence to the target network device according to predefined rules. The network device receives and executes the command sequence, updating the VLAN configuration. Security protocols can utilize a combination of certificate-based authentication and data encryption transmission technologies, such as the TLS (Transport Layer Security) protocol, to ensure secure and reliable delivery of configuration commands.

[0026] S4. Evaluate the configuration effect of the configuration instruction sequence through the verification node to obtain an evaluation result; when the evaluation result is abnormal, trigger a network configuration rollback operation based on the network configuration snapshot stored before the configuration is executed.

[0027] Specifically, the verification node continuously monitors network performance indicators and device status at a preset sampling frequency, such as once per second. Network performance indicators include data transmission latency, packet loss rate, and bandwidth utilization; device status includes network device port status, CPU and memory usage, etc. The monitored data is compared with historical data before configuration to determine the effectiveness of the configuration. For example, if data transmission latency and packet loss rate are reduced after configuration, the configuration is effective; otherwise, it is an anomaly.

[0028] Among them, network performance indicators include data that can be calculated through ICMP request response time, packet loss rate can be counted by the number of data packets, and bandwidth utilization can be counted based on network interface traffic; the network device port status can be up / down.

[0029] If the assessment results are abnormal, a rollback operation based on the pre-configuration network configuration snapshot is triggered. The network configuration snapshot is stored on the non-volatile storage media of the network device and contains information such as the pre-configuration VLAN table, port configuration, and routing table. The rollback operation reads the snapshot file and restores the original configuration in the reverse order of the configuration. During the rollback, the network status is monitored in real time to ensure reliable operation and network stability. Rollback information, such as the time and reason, is also recorded to facilitate subsequent analysis and optimization of the VLAN configuration policy.

[0030] The above-mentioned virtual LAN configuration method based on Ethernet gateway controller collects vehicle multi-dimensional status data in real time through the Ethernet gateway controller and calculates the network reconstruction demand, and generates a reconstruction trigger signal when the demand exceeds the threshold; after responding to this signal, a reinforcement learning strategy is used to dynamically select the optimal VLAN configuration template from the preset library, and a configuration scheme with time and space constraints is generated in combination with the real-time network topology; then, based on the entropy value analysis of the scheme and the network topology, the risk level is evaluated, and a risk-optimized configuration instruction sequence is generated, which is reliably issued to the target device through the security protocol; finally, the configuration effect is verified through the node, and a rollback mechanism is triggered in the event of an abnormality, forming a closed-loop control system of perception-decision-execution-verification, realizing accurate triggering, intelligent decision-making, safe execution and reliable recovery of the vehicle network configuration in a complex dynamic environment, significantly improving network resource utilization, security response speed and system reliability.

[0031] In an optional embodiment, collecting multi-dimensional vehicle status data through an Ethernet gateway controller and calculating the network reconfiguration requirement based on the multi-dimensional vehicle status data include the following steps: S11. Based on the vehicle sensor network, collect multi-dimensional vehicle status data through the Ethernet gateway controller; wherein the multi-dimensional vehicle status data includes: driving mode, system events, security threat level, network load variance, and power status.

[0032] S12. Calculate the state change rate of each dimension in the multi-dimensional vehicle state data.

[0033] S13. Calculate the network reconstruction demand degree using the entropy model based on the state change rate. The expression of the network reconstruction demand degree is:

[0034] Where n is the total number of dimensions of multidimensional vehicle state data, ΔS i represents the state change rate of the i-th dimension, ω iis the weight coefficient of the i-th dimension, satisfying ∑ω i =1.

[0035] Specifically, the Ethernet gateway controller uses the on-board sensor network to collect multi-dimensional vehicle status data in all directions, which can cover driving mode, system events, security threat level, network load variance, power status, etc.

[0036] Among them, driving modes can include normal driving, automatic driving, sports mode, etc.; system events can include door switches, light control, wiper action, etc.; the security threat level can be evaluated based on the vehicle intrusion detection system and divided into three levels: low, medium, and high; the network load variance can reflect the degree of fluctuation of network traffic, which can be calculated by counting the network data packet transmission rate; the power status can include parameters such as battery voltage, current, and charging status.

[0037] For the driving mode dimension, taking the driving mode as an example, when the vehicle switches from normal driving mode to automatic driving mode, the state change rate of the driving mode dimension is 1 (indicating a complete change) within a unit time (such as 1 second); if the driving mode remains unchanged for a period of time (such as 10 seconds), the state change rate of this dimension is 0.

[0038] For the system event dimension, statistics are collected to show the changes in the number of occurrences of various system events per unit time. For example, if the door switch event changes from 0 times per minute to 2 times per minute, then its state change rate is 2 times / minute.

[0039] For the security threat level dimension, if it takes 5 seconds for the security threat level to rise from low (assuming a quantitative value of 1) to high (assuming a quantitative value of 3), the state change rate is 0.4 quantitative units / second.

[0040] For the network load variance dimension, the state change rate can be obtained by calculating the difference in network load variance between two adjacent statistical periods (for example, a period of 1 second) and dividing it by the time interval.

[0041] For the power state dimension, the instantaneous change rate of battery voltage, current and other parameters can be analyzed. For example, if the battery voltage changes from 12.5V to 12.8V in 0.1 seconds, the state change rate is 3V / second.

[0042] This embodiment collects multi-dimensional vehicle status data and uses an entropy model to calculate the network reconstruction demand. It can accurately evaluate the vehicle network status in real time, predict potential risks in advance, provide a decision-making basis for network optimization, improve the scientificity and accuracy of network demand forecasting, and ensure the stable operation of key functions such as intelligent driving.

[0043] In an optional embodiment, the dynamic adjustment of the weight coefficient includes the following steps: S131. Calculate the security sensitivity weight corresponding to the security threat level based on historical network security logs; The calculation formula for security sensitivity weight is:

[0044] Among them, N attack is the attack event count, t response is the response time, T total is the total running time, α and β are preset coefficients.

[0045] Specifically, the attack event count is the number of network attack events obtained from historical network security logs, the total operating time is the accumulated operating time of the vehicle network system, and the response time is the time it takes for the system to detect the attack and take effective defense measures each time an attack event occurs. The two coefficients α and β are used to balance the impact of the frequency of attack events and the response time on the security sensitivity weight, and can be adjusted according to the actual vehicle network security strategy.

[0046] S132. Adjust the corresponding driving mode weight according to the current driving mode; wherein, when the driving mode is automatic driving, the corresponding driving mode weight is greater than the driving mode weights corresponding to other driving modes.

[0047] Specifically, when the driving mode is set to autonomous driving, the corresponding driving mode weight is greater than the corresponding weights for other driving modes (such as manual driving and assisted driving). Because autonomous driving mode increases vehicle reliance on the network, the rationality of network configuration directly affects vehicle safety and functional implementation. In autonomous driving mode, the weight can be set to 1.5 times or higher than that of other modes. The specific value can be determined based on actual testing and safety requirements.

[0048] S133. Adjust the network load weight corresponding to the network load variance based on the network monitoring data, so that the network load weight is negatively correlated with the bandwidth utilization.

[0049] Specifically, when bandwidth utilization is low, the network load weight can be appropriately increased so that the network can better cope with sudden traffic changes; when bandwidth utilization is high, the network load weight can be reduced to avoid network congestion caused by network load fluctuations. The specific adjustment formula can be:

[0050] Among them, ω load_base is the basic value of the network load weight; bandwidth utilization and maximum bandwidth utilization are used to measure the current network traffic situation; δ is the adjustment coefficient, which is used to control the sensitivity of the network load weight to changes in bandwidth utilization.

[0051] S134, normalize the weights corresponding to each dimension in the preliminarily obtained multi-dimensional vehicle state data so that ∑ω i =1, and get the weight coefficient.

[0052] Specifically, the normalization formula is:

[0053] Where n is the total number of dimensions of multidimensional vehicle state data, ω i is the weight obtained by preliminary calculation of each dimension, ω′ i is the normalized weight coefficient. The normalization process ensures that the sum of all weight coefficients is 1, so that the weight of each dimension can play a reasonable role in the subsequent network reconstruction demand calculation.

[0054] This embodiment dynamically adjusts the weight coefficients to flexibly adjust the importance of data in each dimension based on the vehicle's real-time operating status and historical data, ensuring rapid response under different driving scenarios and security threats, optimizing network resource allocation, and improving network efficiency and reliability.

[0055] In an optional embodiment, a reinforcement learning strategy is used to select an optimal VLAN configuration template from a configuration strategy library, including the following steps: S21. Construct a state-action value function. The expression of the state-action value function is:

[0056] Among them, the state s t Indicates the current network situation, action a t Represents configuration template selection, t represents the time, λ is the learning rate, and γ is the discount factor.

[0057] S22. Design the immediate reward function r in the state-action value function t ; Immediate reward function r t The expression is:

[0058] Where ΔB t is the bandwidth gain at time t, ΔL t is the delay reduction at time t, ΔT t is the configuration time at time t, and k1, k2, and k3 are preset coefficients.

[0059] S23, based on the state-action value function and the immediate reward function, select action a through the ε-greedy strategy t ,The state-action value function is updated until convergence, and the optimal configuration template is selected as the optimal VLAN configuration template.

[0060] Specifically, network status includes parameters such as network load, data transmission latency, and security threat level. Configuration template selection refers to selecting a specific VLAN configuration template from the configuration policy library. Bandwidth gain refers to the increase in available network bandwidth after implementing the new configuration template. Latency reduction refers to the reduction in data transmission latency after implementing the new configuration template. Configuration duration refers to the time from selecting the configuration template to completing the network configuration adjustment.

[0061] Select action a through the ε-greedy strategy t The steps are: randomly select a configuration template with probability ε to explore new configuration strategies; select the configuration template with the largest value function in the current state with probability 1-ε to use the known optimal strategy; update the state-action value function until convergence. The specific steps are as follows: 1) Initialize all Q(s,a) values ​​to 0; 2) At each time t, observe the current network situation s t ; 3) Select action a according to the ε-greedy strategy t ; 4) Execute action a t , get reward r t and observe new network trends t+1 ; 5) According to the update formula of the above state-action value function, update Q(s t ,a t ).

[0062] Repeat the above steps until the Q(s,a) value converges, that is, the value of each state-action pair tends to be stable. At this time, the corresponding configuration template selected is the optimal VLAN configuration template.

[0063] This embodiment uses a reinforcement learning strategy to select the optimal VLAN configuration template, which can effectively evaluate the configuration effect under different network situations, balance network performance and resource allocation efficiency, improve system response speed and adaptability, and ensure that the vehicle network is always in the best state.

[0064] refer to Figure 2 In an optional embodiment, generating a risk-optimized configuration instruction sequence based on a VLAN configuration scheme and a network topology entropy analysis of a real-time network topology includes the following steps: S311 . Calculate the connectivity of each network node in the real-time network topology according to the VLAN membership in the VLAN configuration scheme.

[0065] Specifically, the connectivity of a network node refers to the complexity of the connections between a node and other nodes in the network. In VLAN configuration, connectivity not only considers the number of physical connections a node has but also the impact of VLAN membership on data transmission. By calculating connectivity, we can assess the importance and potential risks of each node in the network.

[0066] The connectivity CD of network nodes i The calculation formula can be:

[0067] Where N is the total number of other nodes directly connected to node i in the network. ij is the physical link weight between node i and node j, which is used to measure the importance of the link. ij is the link bandwidth between nodes i and j, which measures the transmission capacity of the link. VLAN_WT(i,j) represents the weight of the VLANs to which nodes i and j belong. VLAN_Max represents the maximum weight of all VLANs in the network.

[0068] Link weights can be set based on factors such as link type, usage, and reliability. For example, the link weight between core switches is set to 1.0, the link weight between edge devices (such as cameras and sensors) and access switches is set to 0.8, and the wireless link weight between mobile terminals and access points is set to 0.5.

[0069] For a 1000 Mbps (1 Gbps) link, the link bandwidth can be set to 1000, and for a 100 Mbps link, the link bandwidth can be set to 100.

[0070] VLAN weights can be set based on VLAN functionality and priority. For example, a VLAN related to autonomous driving could have a weight of 1.5, a VLAN related to the smart cockpit could have a weight of 1.2, and a VLAN related to the entertainment system could have a weight of 1.0.

[0071] S312. Based on the connectivity of each network node, the network topology entropy value is calculated according to the Shannon entropy standard formula. The expression of the network topology entropy value is:

[0072] Among them, p i is the ratio of node i’s connectivity to the total connectivity of the network.

[0073] Specifically, the network topology entropy is used to quantify the complexity and uncertainty of the network topology structure. Where N is the total number of nodes in the network, p iIs the ratio of node i’s connectivity to the total connectivity of the network. When calculating specifically, first calculate the sum of the connectivity of all nodes in the network to get the total connectivity, and then calculate the ratio of each node’s connectivity to the total connectivity, that is, p i Finally, all p i Substitute the above formula to calculate the network topology entropy value ζ. For example, in a small network with 5 nodes, the connectivity of each node is 3, 2, 2, 1, 1, and the total connectivity is 3+2+2+1+1=9. Then the p of each node is i They are 93, 92, 92, 91, and 91 respectively. Substituting them into the formula, we can obtain the network topology entropy value ζ.

[0074] S313. Based on preset rules, the configuration risk level is divided according to the network topology entropy value.

[0075] Specifically, the preset rules can be derived from historical configuration data and network operation experience. For example, a value of ζ less than 1.5 is considered low risk, indicating a relatively simple network topology and minimal impact of configuration operations on network stability. A value between ζ 1.5 and 2.5 is considered medium risk, indicating a complex network topology and requiring caution in configuration operations. A value greater than ζ 2.5 is considered high risk, indicating a complex network topology and potential significant impact of configuration operations on network stability, requiring more stringent risk control measures.

[0076] S314: Optimize the sequence of configuration operations in the VLAN configuration solution according to the configuration risk level to generate a risk-optimized configuration instruction sequence.

[0077] Specifically, for low-risk configuration operations, the execution order can be arranged relatively flexibly; for medium-risk configuration operations, priority should be given to executing them during periods of low network traffic, and sufficient testing and verification should be ensured before execution; for high-risk configuration operations, in addition to selecting the appropriate execution time, detailed emergency plans and rollback plans can also be developed to ensure that the network configuration can be quickly restored in the event of an abnormal situation. For example, in a solution that includes multiple VLAN configuration operations, if an operation involves modifying the VLAN configuration of a core switch and the corresponding risk level is high, it should be scheduled for execution during the night when the network is off-peak, and the current network configuration should be backed up before execution. The network status should be monitored in real time during execution, and a rollback operation should be initiated immediately when an abnormality is detected to restore the backed-up configuration status.

[0078] This embodiment analyzes the network topology entropy value based on the VLAN configuration scheme and the real-time network topology to accurately assess network configuration risks, optimize the configuration instruction sequence, reduce the impact of configuration operations on network stability, and improve the efficiency and reliability of vehicle network configuration.

[0079] In an optional embodiment, sending an execution configuration instruction sequence to a target network device through a security protocol includes the following steps: S321. Generate primary channel transmission data and auxiliary channel transmission data based on the configuration instruction sequence; wherein the primary channel transmission data is the encrypted configuration instruction sequence, and the auxiliary channel transmission data is the encrypted configuration summary information, and the configuration summary information is obtained by processing the configuration instruction sequence using the HMAC-SHA256 algorithm.

[0080] Specifically, the Ethernet gateway controller generates main channel transmission data and auxiliary channel transmission data based on the configuration instruction sequence, where the main channel transmission data is the encrypted configuration instruction sequence. The encryption process adopts a symmetric encryption algorithm such as AES, and uses a pre-shared key to encrypt the configuration instruction sequence to ensure the confidentiality of the data during transmission. The auxiliary channel transmission data is the encrypted configuration summary information, which is obtained by processing the configuration instruction sequence through the HMAC-SHA256 algorithm. Specifically, the HMAC-SHA256 algorithm uses a pre-negotiated key and a configuration instruction sequence as input to generate a summary information with a fixed length. The summary information can uniquely identify the configuration instruction sequence and is used to verify the integrity and authenticity of the configuration instruction sequence. The encrypted configuration summary information is also encrypted using a symmetric encryption algorithm to ensure its security during transmission.

[0081] S322: Send the primary channel transmission data to the target network device through the primary channel, and send the secondary channel transmission data to the target network device through the secondary channel.

[0082] Specifically, the Ethernet gateway controller sends data to the target network device via the primary channel and simultaneously sends data to the target network device via the secondary channel. The primary and secondary channels can be physically distinct communication links or logically separate communication channels, such as using different ports, protocols, or VLAN tags, to ensure redundancy and reliability of data transmission. During the transmission process, the Ethernet gateway controller records the transmission timestamp and related status information for subsequent verification and tracking.

[0083] S323: Receive a dual-channel verification result returned by the target network device, where the dual-channel verification result is generated by the target network device according to a preset dual-channel consistency verification rule.

[0084] Specifically, after the target network device receives the data transmitted through the primary channel and the data transmitted through the secondary channel, it verifies the data according to the preset dual-channel consistency verification rules. First, the target device uses the same symmetric encryption algorithm and pre-shared key to decrypt the data transmitted through the primary channel to obtain the configuration instruction sequence. At the same time, the data transmitted through the secondary channel is decrypted to obtain the configuration summary information before encryption. Then, the target device uses the HMAC-SHA256 algorithm to recalculate the summary information of the decrypted configuration instruction sequence and compares it with the received configuration summary information. If the two are consistent, it indicates that the configuration instruction sequence has not been tampered with during transmission and its integrity has been verified; if they are inconsistent, it indicates that the configuration instruction sequence may have been tampered with or damaged during transmission and the verification fails.

[0085] S324: When the dual-channel verification result indicates that the verification is passed, a configuration execution instruction is sent to the target network device to activate the configuration instruction sequence.

[0086] Specifically, upon receiving the configuration execution command, the target device immediately executes the verified configuration command sequence to update the VLAN configuration. During execution, the target device records the configuration execution timestamp, status information, and results for subsequent auditing and troubleshooting. If the dual-channel verification result indicates a failure, the Ethernet gateway controller records the verification failure and takes appropriate action based on pre-defined security policies, such as reissuing the configuration command sequence, triggering an alarm, or ignoring the configuration request.

[0087] This embodiment transmits data through a dual-channel security protocol to improve the security and reliability of configuration instruction transmission, prevent information leakage and tampering, ensure that the target device executes the correct configuration instructions, and ensure the safe and stable operation of the vehicle network.

[0088] In an optional embodiment, evaluating the configuration effect of the configuration instruction sequence by a verification node includes the following steps: S41. Based on the execution result of the risk-optimized configuration instruction sequence, generate a configuration verification data packet, where the configuration verification data packet includes a configuration identifier, a configuration hash value, and a timestamp.

[0089] Specifically, after the risk-optimized configuration instruction sequence is executed, the system evaluates its configuration effect. Based on the execution results, a configuration verification data packet is generated. The configuration verification data packet contains a configuration identifier that is used to uniquely identify this configuration operation, facilitating accurate identification and association of relevant verification information during the verification process. The configuration hash value is obtained by performing a hash operation on the configuration instruction sequence. For example, using the SHA-256 algorithm, the configuration instruction sequence is treated as an input message to generate a fixed-length hash value. This hash value is unique and tamper-proof, ensuring the integrity of the configuration instruction sequence. The timestamp records the specific time of configuration execution and is used for timing analysis and version control in the subsequent verification process to prevent confusion or expiration of verification results.

[0090] S42. Broadcast a verification request to all slave nodes through the master node of the verification network, where the verification request includes a configuration verification data packet.

[0091] Specifically, the master node broadcasts a verification request to all slave nodes via a network communication protocol. This verification request includes the generated configuration verification data packet, ensuring that each slave node receives consistent and accurate verification evidence. This broadcast process can utilize a connection-oriented protocol such as TCP to ensure packet order and integrity, while also incorporating a retry mechanism to mitigate packet loss during network transmission.

[0092] S43. Perform local verification on each slave node based on the configuration verification data packet, and generate a local verification result with an additional digital signature by checking the consistency between the actual network configuration and the target configuration.

[0093] Specifically, after receiving the verification request, each slave node performs local verification based on the configuration verification data packet. The slave node checks the consistency of the actual network configuration with the target configuration, which involves a detailed check of the network configuration of this node, including VLAN settings, port configuration, routing rules, etc., and compares them item by item with the target configuration defined in the configuration instruction sequence. If there are inconsistencies, the slave node will record the specific differences. After completing the consistency check, the slave node will attach a digital signature to the local verification result. The digital signature process can use the private key of the slave node to encrypt the verification result to ensure the authenticity and non-repudiation of the result. In this way, when the master node receives the verification result, it can be decrypted and verified by the corresponding public key to confirm that the result is indeed from the slave node and has not been tampered with.

[0094] S44. The master node collects the local verification results of the slave nodes and counts the number of identical verification results.

[0095] Specifically, the master node is responsible for collecting the local verification results returned by all slave nodes, organizing and counting these results. A key step is counting the number of identical verification results. The master node records each verification result and its occurrence count, which helps to subsequently determine the reliability of the verification results. For example, if the majority of slave nodes return verification results indicating that the configuration is qualified, it can be preliminarily assumed that the execution of the configuration instruction sequence is successful. The master node also chronologically sorts and analyzes the verification results to ensure that the collected results are up-to-date and relevant to the current configuration operation.

[0096] S45. When the number of identical verification results reaches 2f+1, the identical verification result is determined as the global verification result; where f is the maximum tolerated number of Byzantine nodes.

[0097] Specifically, f represents the maximum number of Byzantine nodes tolerated. The Byzantine problem refers to the situation in which some nodes in a distributed system may return incorrect or inconsistent information due to failures, malicious behavior, or software errors. Byzantine fault tolerance requires that the system be able to reach a correct consensus even in the presence of f Byzantine nodes. The formula 2f+1 is the theoretical requirement for Byzantine fault tolerance. This means that if 2f+1 out of at least 3f+1 nodes return the same result, the result of at least one honest node is guaranteed to be included, thus ensuring the correctness of the global verification result.

[0098] S46. If the global verification result is passed, the configuration effect is determined to be qualified; if not, the configuration effect is determined to be unqualified.

[0099] Specifically, if the global verification result is passed, it indicates that the execution of the configuration instruction sequence has achieved the expected results, the network configuration is correct and stable, and the configuration effect is satisfactory. Conversely, if the global verification result is failed, it indicates that there may be errors in the configuration process or the expected configuration status has not been achieved, and the configuration effect is judged to be unsatisfactory. The verification result is recorded and used for subsequent troubleshooting, system maintenance, or reconfiguration decisions.

[0100] The distributed verification method proposed in this embodiment efficiently and reliably evaluates the effectiveness of the configuration instruction sequence. By broadcasting verification requests, local verification, and statistical results, it ensures that the configuration effect meets expectations, detects and handles problems in a timely manner, and ensures the stable operation of the vehicle network.

[0101] The aforementioned Ethernet gateway controller-based virtual local area network configuration method collects multi-dimensional status data such as driving patterns and system events in real time through the vehicle sensor network and Ethernet gateway controller. It dynamically calculates the network reconstruction demand based on an entropy model and generates a trigger signal. It uses a reinforcement learning algorithm combined with real-time network status to adaptively select the optimal VLAN template from a preset policy library to generate a configuration plan with time and space constraints. It then quantifies the configuration risk level through topological entropy analysis and dynamically optimizes the configuration operation sequence. It uses a dual-channel encrypted transmission mechanism to ensure the secure issuance of instructions, implements multi-node collaborative verification based on Byzantine fault-tolerant consensus through distributed nodes, and triggers a rollback mechanism in the event of anomalies. This forms a complete closed loop from status perception, intelligent decision-making, risk control, secure execution, and trusted recovery, significantly improving the resource allocation accuracy, real-time threat response, configuration operation security, and system failure resilience of the vehicle network in dynamic and complex environments.

[0102] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0103] Based on the same inventive concept, embodiments of the present application also provide an apparatus for implementing the aforementioned Ethernet gateway controller-based virtual local area network configuration method. The solution provided by this apparatus is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the Ethernet gateway controller-based virtual local area network configuration apparatus provided below can be found in the aforementioned limitations of the Ethernet gateway controller-based virtual local area network configuration method, and will not be further elaborated here.

[0104] In an exemplary embodiment, Figure 3 As shown, a virtual local area network configuration device 30 based on an Ethernet gateway controller is provided, which is used to implement the steps in the above-mentioned method embodiments. The device includes: The data acquisition module 31 is used to collect multi-dimensional vehicle status data through the Ethernet gateway controller; a demand assessment module 32 for calculating a network reconfiguration demand based on multi-dimensional vehicle status data and generating a dynamic reconfiguration trigger signal when the network reconfiguration demand is greater than a threshold; A configuration scheme generating module 33 is configured to respond to a dynamic reconstruction trigger signal, select an optimal VLAN configuration template from a configuration strategy library using a reinforcement learning strategy, and generate a VLAN configuration scheme including time and space constraints in combination with the real-time network topology; The instruction sequence generation and issuance module 34 is used to generate a risk-optimized configuration instruction sequence based on the VLAN configuration scheme and the network topology entropy value analysis of the real-time network topology, and issue the execution configuration instruction sequence to the target network device through the security protocol; The configuration effect evaluation module 35 is used to evaluate the configuration effect of the configuration instruction sequence through the verification node to obtain an evaluation result; The rollback triggering module 36 is configured to trigger a network configuration rollback operation based on a network configuration snapshot stored before the configuration is executed when the evaluation result is abnormal.

[0105] An embodiment of the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0106] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0107] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are merely illustrative, wherein the components described as separate parts may or may not be physically separated, and the parts displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the disclosed solution. A person of ordinary skill in the art can understand and implement it without expending creative work.

[0108] The above-described embodiments merely represent several implementation methods of the embodiments of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the concept of the embodiments of the present application, and these modifications and improvements fall within the scope of protection of the embodiments of the present application.

Claims

1. A virtual local area network configuration method based on an Ethernet gateway controller, characterized in that: The method comprises: Collecting multi-dimensional vehicle status data through an Ethernet gateway controller, calculating a network reconfiguration requirement based on the multi-dimensional vehicle status data, and generating a dynamic reconfiguration trigger signal when the network reconfiguration requirement is greater than a threshold; In response to the dynamic reconstruction trigger signal, a reinforcement learning strategy is used to select an optimal VLAN configuration template from a configuration strategy library, and a VLAN configuration scheme including time and space constraints is generated in combination with the real-time network topology; Generate a risk-optimized configuration instruction sequence based on the VLAN configuration scheme and the network topology entropy value analysis of the real-time network topology, and issue the configuration instruction sequence to the target network device through a security protocol for execution; The configuration effect of the configuration instruction sequence is evaluated by a verification node to obtain an evaluation result; when the evaluation result is abnormal, a network configuration rollback operation based on a network configuration snapshot stored before the configuration is executed is triggered.

2. The method according to claim 1, characterized in that The collecting of multi-dimensional vehicle status data through the Ethernet gateway controller and calculating the network reconfiguration requirement based on the multi-dimensional vehicle status data include: Based on the vehicle sensor network, the Ethernet gateway controller collects the multi-dimensional vehicle status data; wherein the multi-dimensional vehicle status data includes: driving mode, system events, security threat level, network load variance, and power supply status; Calculating the state change rate of each dimension in the multi-dimensional vehicle state data; According to the state change rate, the network reconstruction demand is calculated using an entropy model; the expression of the network reconstruction demand is: ; Where n is the total number of dimensions of the multi-dimensional vehicle state data, ΔS i represents the state change rate of the i-th dimension, ω i is the weight coefficient of the i-th dimension, satisfying ∑ω i =1.

3. The method according to claim 2, characterized in that The dynamic adjustment of the weight coefficient includes: Based on historical network security logs, the security sensitivity weight corresponding to the security threat level is calculated; the calculation formula of the security sensitivity weight is: ; Among them, N attack is the attack event count, t response is the response time, T total is the total running time, α and β are preset coefficients; Adjusting the corresponding driving mode weight according to the current driving mode; wherein, when the driving mode is automatic driving, the corresponding driving mode weight is greater than the driving mode weights corresponding to other driving modes; Adjusting the network load weight corresponding to the network load variance based on network monitoring data so that the network load weight is negatively correlated with bandwidth utilization; The weights corresponding to each dimension in the initially obtained multi-dimensional vehicle state data are normalized so that ∑ω i =1, and obtain the weight coefficient.

4. The method according to claim 1, wherein The method of selecting the optimal VLAN configuration template from the configuration policy library using a reinforcement learning strategy includes: Construct a state-action value function, the expression of which is: ; Among them, the state s t Indicates the current network situation, action a t represents the configuration template selection, t represents the time, λ represents the learning rate, and γ represents the discount factor; Design the immediate reward function r in the state-action value function t ; The immediate reward function r t The expression is: ; Where ΔB t is the bandwidth gain at time t, ΔL t is the delay reduction at time t, ΔT t is the configuration time at time t, k1, k2, k3 are preset coefficients; Based on the state-action value function and the immediate reward function, action a is selected through the ϵ-greedy strategy t , updating the state-action value function until convergence, and obtaining the optimal configuration template selection as the optimal VLAN configuration template.

5. The method according to claim 1, wherein The network topology entropy analysis based on the VLAN configuration scheme and the real-time network topology to generate a risk-optimized configuration instruction sequence includes: Calculating the connectivity of each network node in the real-time network topology according to the VLAN membership in the VLAN configuration scheme; Based on the connectivity of each network node, the network topology entropy value is calculated according to the Shannon entropy standard formula; the expression of the network topology entropy value is: ; Among them, p i is the proportion of node i’s connectivity to the total connectivity of the network; Based on preset rules, the configuration risk level is divided according to the network topology entropy value; According to the configuration risk level, the configuration operations in the VLAN configuration scheme are sequence optimized to generate the risk-optimized configuration instruction sequence.

6. The method according to claim 1, characterized in that The step of sending the configuration instruction sequence to the target network device through a security protocol for execution includes: Based on the configuration instruction sequence, primary channel transmission data and auxiliary channel transmission data are generated; wherein the primary channel transmission data is an encrypted configuration instruction sequence, and the auxiliary channel transmission data is an encrypted configuration summary information, and the configuration summary information is obtained by processing the configuration instruction sequence using the HMAC-SHA256 algorithm; Sending the primary channel transmission data to the target network device through the primary channel, and sending the auxiliary channel transmission data to the target network device through the auxiliary channel; Receiving a dual-channel verification result returned by the target network device, wherein the dual-channel verification result is generated by the target network device according to a preset dual-channel consistency verification rule; When the dual-channel verification result indicates that the verification is passed, a configuration execution instruction is sent to the target network device to activate the configuration instruction sequence.

7. The method according to any one of claims 1 to 6, characterized in that The evaluating the configuration effect of the configuration instruction sequence by the verification node includes: generating a configuration verification data packet based on the execution result of the risk-optimized configuration instruction sequence, the configuration verification data packet including a configuration identifier, a configuration hash value, and a timestamp; Broadcasting a verification request to all slave nodes through a master node of the verification network, wherein the verification request includes the configuration verification data packet; Performing local verification on each slave node based on the configuration verification data packet, and generating a local verification result with an additional digital signature by checking the consistency between the actual network configuration and the target configuration; Collecting the local verification results of the slave nodes through the master node, and counting the number of identical verification results; When the number of identical verification results reaches 2f+1, the identical verification result is determined as the global verification result; wherein f is the maximum tolerated number of Byzantine nodes; If the global verification result is passed, the configuration effect is determined to be qualified; if not, it is determined to be unqualified.

8. A virtual local area network configuration device based on an Ethernet gateway controller, used to implement the method according to any one of claims 1 to 7, characterized in that: The device comprises: Data acquisition module, used to collect multi-dimensional vehicle status data through Ethernet gateway controller; a demand assessment module, configured to calculate a network reconfiguration demand based on the multi-dimensional vehicle status data, and generate a dynamic reconfiguration trigger signal when the network reconfiguration demand is greater than a threshold; A configuration scheme generating module is configured to respond to the dynamic reconstruction trigger signal, select an optimal VLAN configuration template from a configuration strategy library using a reinforcement learning strategy, and generate a VLAN configuration scheme containing time and space constraints in combination with the real-time network topology; An instruction sequence generation and issuance module is used to generate a risk-optimized configuration instruction sequence based on the VLAN configuration scheme and the network topology entropy value analysis of the real-time network topology, and issue the configuration instruction sequence to the target network device through a security protocol for execution; A configuration effect evaluation module is used to evaluate the configuration effect of the configuration instruction sequence through a verification node to obtain an evaluation result; The rollback triggering module is used to trigger a network configuration rollback operation based on a network configuration snapshot stored before the configuration is executed when the evaluation result is abnormal.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Automobile gateway CAN upgrade security rollback decision management method and system

    CN121070408A

  • Automotive Gateway CAN Upgrade Security Rollback Decision Management Method and System

    CN121070408B

  • Power grid safety supervision system and safety supervision method

    CN121097964A