An anti-spoofing transmission method, device and equipment for Ethernet data and a medium

CN122741114APending Publication Date: 2026-09-11CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610766750.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0003]但是传统技术在实现以太网数据防欺骗校验时,通常采用单项字段比对的模式,仅基于发送端的物理地址(如MAC地址)作为核心依据完成合法性判断,校验逻辑与校验要素较为单一

Benefits of technology

[0016]The embodiments of this application include at least the following beneficial effects: This application provides a method, apparatus, device, and medium for preventing spoofing of Ethernet data transmission. After receiving an Ethernet data frame transmitted by a sending end, this scheme first extracts a verification data segment within the frame, consisting of a first verification value and a target sequence number. The first verification value is generated jointly by the target sequence number, the physical address of the sending end, and a first transmission key agreed upon by both parties. A second verification value is calculated based on the extracted target sequence number, the physical address of the sending end, and a locally stored second transmission key agreed upon by both parties. The calculated second verification value is then compared with the first verification value within the frame. If the verifications do not match, the abnormal Ethernet data frame is discarded; if they match, the Ethernet data frame is transmitted as a normal data frame to the application protocol layer. This application no longer uses the easily spoofed MAC address as the sole criterion for judgment. Instead, it combines the target sequence number, the physical address of the sending end, and the exclusive transmission key of both parties to generate the verification value. This allows for cross-comparison between the first verification value at the time of transmission and the second verification value at the time of reception, constructing a multi-factor linkage verification mechanism. This application utilizes a transmission key known only to the sender and receiver, which raises the threshold for data forgery. Furthermore, it forms multiple verification constraints based on the sequence number and physical address, effectively identifying abnormal data frames such as address forgery, content tampering, or replay, preventing illegal data transmission to upper-layer applications. This ensures the integrity and security of Ethernet data transmission, reduces the probability of upper-layer vehicle applications malfunctioning or experiencing command errors due to false data, and meets the actual transmission needs for data anti-spoofing transmission during vehicle device interconnection and business data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122741114A_ABST
    Figure CN122741114A_ABST
Patent Text Reader

Abstract

The application discloses an anti-fraud transmission method, device and equipment of Ethernet data and a medium, and belongs to the technical field of data transmission. The method comprises the following steps: after receiving an Ethernet data frame transmitted by a sending end, a first check value and a target serial number in the frame are extracted, the first check value being generated by the target serial number, a physical address of the sending end and a first transmission key agreed by both parties; the target serial number, the physical address of the sending end and a second key agreed by both parties are used by the receiving end to generate a second check value, and then the first check value when the data frame is transmitted is cross-compared with the second check value when the data frame is received, so that the abnormality of the Ethernet data frame is checked. Based on the transmission key exclusive to the sending and receiving parties, the difficulty of forgery is improved, and multiple constraints are formed by the serial number and the physical address, so that abnormal data frames such as address forgery, data tampering or frame replay can be identified, and the anti-fraud transmission of data in the process of vehicle-mounted device interconnection and service data transmission is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data transmission technology, and in particular to a method, apparatus, device and medium for preventing spoofing during Ethernet data transmission. Background Technology

[0002] Ethernet communication is the mainstream communication method for data interaction between various network terminals and interconnected devices, and it is widely used in scenarios such as vehicle-mounted equipment interconnection and business data transmission. When Ethernet data frames are forwarded and transmitted through the network link, the legitimacy of the data frames needs to be verified, so as to intercept tampered or forged deceptive data frames, thereby ensuring the authenticity and validity of the interactive data.

[0003] However, traditional technologies typically employ a single-field comparison model when implementing Ethernet data anti-spoofing verification. They rely solely on the sender's physical address (such as the MAC address) as the core basis for legitimacy judgment, resulting in relatively simple verification logic and verification elements.

[0004] Because traditional verification methods rely solely on publicly available and easily spoofed physical addresses for verification, their protective capabilities are relatively weak. If an attacker can forge a physical address, they can tamper with the valid data within the frame. Thus, abnormal data frames that have been forged, tampered with, or replayed can successfully pass through the traditional verification process, making it impossible for the receiving end to identify such deceptive data. The illegal data will then be transmitted normally to the application protocol layer. Therefore, traditional technologies cannot guarantee the integrity and security of Ethernet data transmission and may also cause upper-layer applications to experience operational failures or command errors based on false data. They cannot meet the anti-spoofing transmission requirements of Ethernet data during the interconnection of in-vehicle devices and the transmission of business data. Summary of the Invention

[0005] The main purpose of this application is to propose a method, apparatus, device and medium for preventing spoofing of Ethernet data transmission. By using three types of information—serial number, sender physical address and exclusive transmission keys of both parties—a multi-factor linkage verification mechanism is constructed, which can prevent illegal data transmission to upper-layer applications and ensure the integrity and security of Ethernet data transmission.

[0006] To achieve the above objectives, one aspect of this application proposes a method for preventing spoofing during Ethernet data transmission, the method comprising: Upon receiving an Ethernet data frame sent by the sending end, a checksum segment is extracted from the Ethernet data frame; wherein the checksum segment includes: a first checksum and a target sequence number generated by the sending end; wherein the first checksum is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; A second verification value is calculated based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; If the second check value is not equal to the first check value, the Ethernet data frame is determined to be invalid and is then discarded. If the second check value is equal to the first check value, the Ethernet data frame is determined to be valid, and then the non-check data segment in the Ethernet data frame is transmitted to the application protocol layer.

[0007] Furthermore, in some embodiments, the process of generating the first verification value includes: At the end of the physical address, extract the first address byte data corresponding to the preset number of bytes; The target sequence number, the first address byte data, and the first transmission key are concatenated sequentially to generate a first data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the first data block is processed byte by byte until all bytes in the first data block have been processed. Then, the value of the operation register is used as the first check value.

[0008] Furthermore, in some embodiments, calculating the second check value based on the target sequence number, the physical address, and the locally stored second transmission key includes: At the end of the physical address, extract the second address byte data corresponding to the preset number of bytes; The target sequence number, the second address byte data, and the second transmission key are concatenated sequentially to generate a second data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the second data block is processed byte by byte until all bytes in the second data block have been processed. Then, the value of the operation register is used as the second check value.

[0009] Furthermore, in some embodiments, the process of generating the target sequence number includes: When a data frame transmission command is detected from the sending end, the current sequence number generated by the sending end is obtained; The sum of the preset numerical increment and the current serial number is used as the target serial number.

[0010] Furthermore, in some embodiments, the process of generating the Ethernet data frame includes: Obtain the application data that the sending end is currently transmitting; The target sequence number is concatenated with the first verification value to generate the verification data segment. The verification data segment is concatenated with the application data segment to generate the Ethernet data frame.

[0011] Furthermore, in some embodiments, before calculating the second check value, the method further includes: Extract the historical sequence number stored locally; wherein, the historical sequence number is the sequence number corresponding to the last received valid Ethernet data frame; The serial number difference between the target serial number and the historical serial number is compared with a preset difference threshold. If the difference in serial numbers is less than the preset difference threshold, then the calculation operation of the second verification value is performed; If the sequence number difference is not less than the preset difference threshold, the Ethernet data frame is directly determined to be invalid and then discarded.

[0012] Furthermore, in some embodiments, the step of performing byte-by-byte operations on the second data block based on the preset initial value until all bytes in the second data block have been processed, and then using the value of the operation register as the second check value, includes: Repeat the following register operations until all bytes in the second data block have been processed, and use the updated target value of the operation register as the second check value: Extract the current byte from the second data block, perform an XOR operation between the current value of the arithmetic register and the current byte, and determine the updated value to be processed from the arithmetic register. Perform a shift operation on the value to be processed after the arithmetic register is updated, and output the target value after the arithmetic register is updated. When it is determined that all bytes in the second data block have not been processed, the updated target value of the operation register is used as the current value of the operation register for the next execution of the register operation.

[0013] To achieve the above objectives, another aspect of this application proposes an anti-spoofing transmission device for Ethernet data, the device comprising: The verification data segment extraction module is used to extract the verification data segment from the Ethernet data frame when receiving the Ethernet data frame sent by the sending end; wherein the verification data segment includes: a first verification value and a target sequence number generated by the sending end; wherein the first verification value is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; The verification value calculation module is used to calculate a second verification value based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; The check value comparison module is used to determine that the Ethernet data frame is invalid and then discard the Ethernet data frame when the second check value is not equal to the first check value. The verification value comparison module is further configured to determine that the Ethernet data frame is valid when the second verification value is equal to the first verification value, and then transmit the non-verification data segment in the Ethernet data frame to the application protocol layer.

[0014] To achieve the above objectives, another aspect of this application provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned method for preventing spoofing during Ethernet data transmission.

[0015] To achieve the above objectives, another aspect of the embodiments of this application proposes a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned method for preventing spoofing transmission of Ethernet data.

[0016] The embodiments of this application include at least the following beneficial effects: This application provides a method, apparatus, device, and medium for preventing spoofing of Ethernet data transmission. After receiving an Ethernet data frame transmitted by a sending end, this scheme first extracts a verification data segment within the frame, consisting of a first verification value and a target sequence number. The first verification value is generated jointly by the target sequence number, the physical address of the sending end, and a first transmission key agreed upon by both parties. A second verification value is calculated based on the extracted target sequence number, the physical address of the sending end, and a locally stored second transmission key agreed upon by both parties. The calculated second verification value is then compared with the first verification value within the frame. If the verifications do not match, the abnormal Ethernet data frame is discarded; if they match, the Ethernet data frame is transmitted as a normal data frame to the application protocol layer. This application no longer uses the easily spoofed MAC address as the sole criterion for judgment. Instead, it combines the target sequence number, the physical address of the sending end, and the exclusive transmission key of both parties to generate the verification value. This allows for cross-comparison between the first verification value at the time of transmission and the second verification value at the time of reception, constructing a multi-factor linkage verification mechanism. This application utilizes a transmission key known only to the sender and receiver, which raises the threshold for data forgery. Furthermore, it forms multiple verification constraints based on the sequence number and physical address, effectively identifying abnormal data frames such as address forgery, content tampering, or replay, preventing illegal data transmission to upper-layer applications. This ensures the integrity and security of Ethernet data transmission, reduces the probability of upper-layer vehicle applications malfunctioning or experiencing command errors due to false data, and meets the actual transmission needs for data anti-spoofing transmission during vehicle device interconnection and business data transmission. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating an anti-spoofing transmission method for Ethernet data provided in an embodiment of this application; Figure 2 This is a schematic diagram of the Ethernet data frame verification process between the sending end and the receiving end provided in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of an anti-spoofing transmission device for Ethernet data provided in an embodiment of this application; Figure 4 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit it. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0019] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”

[0020] As used in this application, the terms "several", "each", etc., "several" include one, two or more, "each" refers to each of the corresponding plurality, and "any" refers to any one of the plurality.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0022] In the field of automotive Ethernet data transmission, service commands, status data, and control messages between automotive devices all rely on Ethernet frames for interaction. The validity of data transmission directly determines the operational safety of the automotive control system. However, traditional technologies for Ethernet data anti-spoofing verification rely solely on the sender's physical address (MAC address) as the sole verification criterion for legitimacy determination. This results in a single verification dimension and simple verification logic. Since the physical address is a publicly resolvable fixed field, attackers can easily spoof or forge it, thereby tampering with valid service data within the frame. Forged illegal data frames can then easily pass through traditional verification processes, leading to an extremely low protection threshold.

[0023] Relying solely on a single public field for verification, lacking dynamic timing constraints and private key verification mechanisms, traditional verification methods cannot identify deception behaviors such as address forgery, data tampering, or frame replay. Illegal data frames will be transmitted normally to the application protocol layer, causing the upper-layer application in the vehicle to receive false data, resulting in problems such as instruction execution errors or device malfunctions. This cannot meet the requirements for secure and reliable anti-spoofing transmission of Ethernet data in vehicle scenarios.

[0024] In view of this, this application provides a method, apparatus, device, and medium for preventing spoofing of Ethernet data transmission. This scheme employs a joint verification mechanism using three elements: serial number, physical address, and dedicated key. The receiving end replicates the sender's verification value generation logic, performing a bidirectional comparison between the first verification value at the time of transmission and the second verification value at the time of reception, thereby determining the validity of the data frame. The serial number helps avoid replay attacks, the private transmission key raises the threshold for forgery, and the physical address further identifies the device, thus overcoming the shortcomings of traditional single physical address verification. This effectively intercepts various spoofed data frames, ensuring the integrity and security of in-vehicle Ethernet data transmission.

[0025] Figure 1 This is an optional flowchart of an Ethernet data anti-spoofing transmission method provided in an embodiment of this application. Figure 1 The method may include, but is not limited to, steps S1 to S3: Step S1: Upon receiving an Ethernet data frame sent by the sending end, extract the check data segment from the Ethernet data frame; wherein the check data segment includes: a first check value and a target sequence number generated by the sending end; wherein the first check value is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; In a vehicle-mounted scenario, terminal devices exchange service data in real time via Ethernet links. Each time the sending end generates a valid service data frame, it simultaneously encapsulates a verification data segment, which serves as the basis for legitimacy verification at the receiving end. This verification data segment is a fixed field within the Ethernet data frame, distinguishing it from the non-verification data segment carrying the service content. The target sequence number can be a dynamically updated time-series identifier, and the first verification value is a unique verification identifier generated by fusing the sequence number, physical address, and transmission key. It can be understood that this first verification value uniquely corresponds to the Ethernet data frame being sent.

[0026] Step S2: Calculate the second verification value based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; Indicatively, both the sending and receiving ends can store the same dedicated transmission key in advance. The sending end uses the first transmission key to generate the first check value, and the receiving end calls the local second transmission key replication operation logic. Combining the parsed target sequence number and the physical address of the sending end, the receiving end independently calculates the second check value, thereby ensuring that the benchmark for the check operation at both ends is consistent, providing a reliable basis for subsequent cross-comparison.

[0027] Step S3: If the second check value is not equal to the first check value, the Ethernet data frame is determined to be invalid, and then the Ethernet data frame is discarded. If the second check value is equal to the first check value, the Ethernet data frame is determined to be valid, and then the non-check data segment in the Ethernet data frame is transmitted to the application protocol layer.

[0028] To illustrate, when a data frame is subjected to tampering, forgery, or replay attacks, at least one of the corresponding byte data of the sequence number or physical address within the frame will be abnormal, causing a deviation between the second check value calculated by the receiver and the first check value encapsulated by the sender. In this case, the data frame is directly determined to be an illegal deception frame and is actively discarded and intercepted to prevent illegal data from flowing into the upper layer application.

[0029] Only when the sequence number and physical address within the frame are valid, and the checksums calculated by both the sending and receiving ends match completely, is the current data frame considered a valid frame that was originally transmitted by the sending end and has not been tampered with. In this case, the business data carried within the frame can be allowed to be uploaded to the vehicle application protocol layer to complete the business interaction.

[0030] Steps S1 to S3 as illustrated in this application's embodiments replace the traditional single physical address verification mode by constructing a joint verification mechanism among the serial number, physical address, and key. This allows for time-series replay protection based on each newly generated serial number, raises the forgery threshold based on the private key, and locks the legitimate identity of the device based on the physical address. This enables multi-dimensional interception of deceptive behaviors such as address forgery, data tampering, or frame replay. Through two-way same-source computation and bidirectional verification comparison, this invention can accurately determine the validity of data frames, solving the problem of weak protection and vulnerability to attacks caused by traditional Ethernet verification methods. It effectively avoids malfunctions of in-vehicle equipment caused by false data, comprehensively improving the security and reliability of in-vehicle Ethernet data transmission.

[0031] In some embodiments, the present invention can also calculate a first checksum before transmitting the Ethernet data frame upon detecting a data frame transmission command issued by the transmitting end, i.e., before transmitting the Ethernet data frame. This first checksum, along with the target sequence number generated by the transmitting end, is then inserted as a checksum data segment into the Ethernet data frame to be transmitted. The process of generating the first checksum specifically includes: At the end of the physical address, extract the first address byte data corresponding to the preset number of bytes; The target sequence number, the first address byte data, and the first transmission key are concatenated sequentially to generate a first data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the first data block is processed byte by byte until all bytes in the first data block have been processed. Then, the value of the operation register is used as the first check value.

[0032] Understandably, the first verification value is the result of a trusted computation on the sender's local end, and the data source is all original data from the sender's local end, free from network transmission interference. Optionally, the sender first reads its own physical address, extracts a fixed number of bytes at the end as the first address byte data to ensure the uniqueness of the device identification; then, it sequentially concatenates the dynamically updated target sequence number and the exclusive first transmission key with the first address byte data to form a first data block with a fixed structure and unique content. By initializing a computation register with a fixed preset initial value, it performs byte-by-byte iterative computation on the complete first data block, and after traversing all bytes, locks the final register value as the first verification value for encapsulated transmission.

[0033] In this embodiment of the invention, a verification data block is generated by concatenating a dynamic target sequence number, device-specific address bytes, and a private transmission key. A first verification value is then generated through byte-by-byte iterative calculations using a fixed initial value, ensuring that the verification value of each frame of data possesses uniqueness, dynamism, and privacy. Simultaneously, based on local raw data calculations, the authenticity of the verification benchmark is guaranteed from the sending end, preventing tampering of the source data. This provides an accurate and reliable comparison basis for the receiving end's secondary verification, thereby enhancing the anti-spoofing capability of Ethernet data from the transmission source.

[0034] For step S2, in some embodiments, calculating the second verification value based on the target sequence number, the physical address, and the locally stored second transmission key includes: At the end of the physical address, extract the second address byte data corresponding to the preset number of bytes; The target sequence number, the second address byte data, and the second transmission key are concatenated sequentially to generate a second data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the second data block is processed byte by byte until all bytes in the second data block have been processed. Then, the value of the operation register is used as the second check value.

[0035] To illustrate, the second verification value is the comparison result of the replication operation at the receiving end, which is completely identical to the operation logic at the sending end, but the data source has security differences. The receiving end parses the physical address of the sending end from the received Ethernet data frame, and extracts the same preset number of bytes at the end as the second address byte data. This data is transmitted through the network link and is at risk of being tampered with or corrupted. Then, it reuses the splicing rules, preset initial values, and byte-by-byte operation logic that are completely consistent with those at the sending end, combines the parsed target sequence number and the locally pre-stored second transmission key to generate a second data block, and iteratively calculates to obtain the second verification value, thus achieving a replication with the same caliber as the verification logic at the sending end.

[0036] In this embodiment of the invention, the following advantages or beneficial effects are achieved: Traditional technologies lack a same-source replication verification mechanism at both the sending and receiving ends, and the receiving end only performs simple field matching, failing to identify data tampering during transmission. This invention, by distinguishing between the locally trusted first address byte data at the sending end and the second address byte data obtained through transmission parsing, can cover the risk of data anomalies in the transmission link. Simultaneously, it employs data concatenation rules, register initial values, and byte-by-byte operation logic completely consistent with those at the sending end, ensuring complete uniformity of the verification benchmark at both ends. By generating a second verification value through same-source replication operations, accurate bidirectional comparison is achieved, effectively identifying tampering of physical addresses, sequence numbers, or data content during transmission, thus solving the problems of traditional verification methods being unable to adapt to link transmission interference and having weak tampering detection capabilities.

[0037] In some embodiments, the present invention can complete the calculation process of the second check value through byte-by-byte iterative operation logic, as follows: At the end of the physical address, extract the second address byte data corresponding to the preset number of bytes; The target sequence number, the second address byte data, and the second transmission key are concatenated sequentially to generate a second data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the second data block is processed byte by byte until all bytes in the second data block have been processed. Then, the value of the operation register is used as the second check value.

[0038] Specifically, the iterative calculation process for the second check value is as follows: Repeat the following register operations until all bytes in the second data block have been processed, and use the updated target value of the operation register as the second check value: Extract the current byte from the second data block, perform an XOR operation between the current value of the arithmetic register and the current byte, and determine the updated value to be processed from the arithmetic register. Perform a shift operation on the value to be processed after the arithmetic register is updated, and output the target value after the arithmetic register is updated. When it is determined that all bytes in the second data block have not been processed, the updated target value of the operation register is used as the current value of the operation register for the next execution of the register operation.

[0039] Indicatively, the initial value of the arithmetic register is preset. During the traversal, single-byte data of the second data block is extracted one by one. First, the register value and byte data are merged and updated through XOR operation to obtain the intermediate value to be processed. Then, the value is updated to the latest register target value through shift operation to complete the second iteration of the value.

[0040] After a single-byte operation is completed, if there are still unprocessed bytes, the target value of the current register is used as the current value for the next round of operation. This process is repeated until all bytes have been processed, and the final stable value of the register is the second check value.

[0041] In this embodiment of the invention, the following advantages or beneficial effects are achieved: Traditional verification operations often employ fixed hash algorithms with publicly available and fixed iterative logic, making them easy to crack and forge. In contrast, this invention uses a byte-by-byte XOR and shift-based iterative loop operation logic. Based on a preset initial value, it dynamically updates the register value byte by byte, with each byte participating in a dual iterative operation. This strongly binds the final verification value to all bytes of the data block, the order of operations, and the initial value. Therefore, the operation logic of this invention is not only rich in layers but also highly random, significantly increasing the difficulty for attackers to reverse engineer and forge verification values. Simultaneously, it replicates the sending end's operation process, ensuring the accuracy of the matching verification results at both ends, further strengthening the anti-spoofing protection capability of the data frame.

[0042] In some embodiments, the calculation process for the first check value at the sending end is the same as the calculation logic for the second check value at the receiving end.

[0043] Optionally, the present invention can use the CRC16 algorithm to calculate the first check value and the second check value respectively. It is understood that CRC16 (Cyclic Redundancy Check 16-bit) refers to a 16-bit cyclic redundancy check, which is an error checking algorithm in the cyclic redundancy check system.

[0044] Indicatively, in this embodiment of the invention, a combination of a 2-byte target sequence number, a 4-byte end-byte data of the sender's physical address, and a 2-byte transmission key predetermined by both the sender and receiver is used to form an 8-byte operational data block, namely the first data block or the second data block, to adapt to the byte-by-byte iterative operation mechanism of the CRC16 algorithm.

[0045] In practical vehicle-mounted Ethernet transmission scenarios, the 6-byte physical address of the sending end can be set as 00:1A:2B:3C:4D:5E. The last 4 bytes of this physical address are extracted as valid address verification data. Simultaneously, a 2-byte target sequence number and a 2-byte transmission key agreed upon by both ends are configured. These three types of data are then sequentially concatenated to form a complete computational data block. Based on the 8-byte first data block, the sending end performs byte-by-byte XOR and shift iteration operations using a pre-set initial value's arithmetic register, outputting a unique first verification value. Subsequently, the 2-byte target sequence number and the 2-byte first verification value are concatenated to form a 4-byte verification data segment. This verification data segment is placed at the front end of the service data, encapsulated to generate a complete Ethernet data frame, and then transmitted.

[0046] Correspondingly, after capturing an Ethernet data frame, the receiving end first parses and obtains the 4-byte checksum data segment carried in the frame header. It then extracts a 2-byte target sequence number for timing legitimacy verification. By comparing this with locally stored historical valid sequence numbers, if the sequence number difference is within a preset reasonable threshold range, it determines that the current data frame has no replay risk and no timing anomaly risk, and then initiates the calculation and verification process for the second checksum. The receiving end reuses the same concatenation rules as the sending end, reassembling the parsed 2-byte target sequence number, the 4-byte data at the end of the sending end's physical address, and the locally pre-stored 2-byte transmission key into an 8-byte second data block. Furthermore, the receiving end can replicate the same CRC16 algorithm logic, iteratively calculating the second checksum byte by byte to independently obtain it. By comparing the consistency of the first and second checksums bidirectionally, it accurately determines whether the data frame has been tampered with or forged. Finally, it strips the front-end checksum field from the Ethernet data frame that has passed both checks, transmitting the clean business data to the application protocol layer, completing secure and compliant data interaction.

[0047] In some embodiments, the transmitting end of the present invention may also have a built-in sequence number counting mechanism to continuously maintain the current sequence number locally under normal conditions. Each time a data frame transmission command is triggered, the sequence number update logic is initiated. Therefore, the process of generating the target sequence number before the Ethernet data frame is transmitted includes: When a data frame transmission command is detected from the sending end, the current sequence number generated by the sending end is obtained; The target sequence number is the sum of the preset numerical increment and the current sequence number. Optionally, the preset numerical increment can be set to 1.

[0048] Specifically, the present invention can retrieve the latest current sequence number, superimpose a fixed numerical increment preset by the system, and generate a brand new target sequence number, thereby achieving a dynamic update effect of one sequence number per frame and increasing frame by frame, ensuring that data frames transmitted at different times correspond to different unique sequence numbers.

[0049] In this embodiment of the invention, the following advantages or beneficial effects are achieved: Traditional technologies mostly use fixed identifiers and do not have an orderly incremental update mechanism, making it impossible to distinguish the transmission sequence of data frames. Attackers can directly reuse historical legitimate frames to carry out replay attacks, which are difficult to detect. The present invention uses an ordered incremental superposition method to generate target sequence numbers, realizing dynamic and orderly iteration of sequence numbers. This ensures that each frame of data has a unique time sequence identifier, providing the receiving end with a way to distinguish between new and old data. This also provides a time sequence basis for intercepting replay frames, avoiding the risk of Ethernet data replay attacks.

[0050] In some embodiments, after the sending end completes the target sequence number generation and the first check value calculation, it can also generate an Ethernet data frame based on the updated target sequence number and the calculated first check value. The specific process includes: Obtain the application data that the sending end is currently transmitting; The target sequence number is concatenated with the first verification value to generate the verification data segment. The verification data segment is concatenated with the application data segment to generate the Ethernet data frame.

[0051] Specifically, the sending end first retrieves the vehicle service application data that needs to be uploaded, and prioritizes concatenating the dynamic target sequence number with the first verification value of the security verification identifier to form an independent verification data segment. The verification data segment can be used as the header verification area of ​​the data frame. Then, the verification data segment is placed at the beginning and the service application data is placed at the end to complete the concatenation of the overall frame structure and generate a complete Ethernet data frame, realizing the layered encapsulation of verification information and service data.

[0052] In this embodiment of the invention, the verification data segment can be fixed at the beginning region, and the service data can be placed at the end, making it easier for the receiving end to quickly extract the verification information and extract the service data. Furthermore, this invention can bind and encapsulate dynamic sequence numbers with verification values, ensuring a one-to-one correspondence between the verification information and the current frame's service data, avoiding mismatches between verification information and service data, and further improving the accuracy and reliability of data frame verification.

[0053] In some embodiments, the receiving end can also filter and intercept abnormal frames by sequence number before calculating the second check value. The specific process is as follows: Extract the historical sequence number stored locally; wherein, the historical sequence number is the sequence number corresponding to the last received valid Ethernet data frame; The serial number difference between the target serial number and the historical serial number is compared with a preset difference threshold. If the difference in serial numbers is less than the preset difference threshold, then the calculation operation of the second verification value is performed; If the sequence number difference is not less than the preset difference threshold, the Ethernet data frame is directly determined to be invalid and then discarded.

[0054] Understandably, the receiving end continuously stores the historical sequence number corresponding to the previous valid data frame locally as a timing judgment benchmark. Therefore, after parsing the data frame and obtaining the target sequence number, timing verification is performed first. The difference between the old and new sequence numbers is calculated, and a preset difference threshold is used to determine whether the data frame timing is compliant. Only data frames with normal timing differences and conforming to a frame-by-frame increasing pattern will proceed to the subsequent checksum comparison process. For abnormal frames with excessively large timing jumps, i.e., those exceeding the normal increment range, they are directly intercepted and discarded in advance.

[0055] For example, the sending end updates the sequence number by a preset increment of 1 for each data frame sent, and the receiving end sets the preset difference threshold to 5. Assuming the historical sequence number stored locally at the receiving end is 100, and the target sequence number parsed from the Ethernet data frame is 102, the calculated sequence number difference is 2. This value is less than the preset difference threshold of 5, so the current data frame is considered to have normal timing, and the calculation of the second check value continues. If an attacker reuses an old data frame to launch a replay attack, the parsed target sequence number is 85, and the calculated sequence number difference is 15. This value is greater than the preset difference threshold of 5, so the data frame is considered to have abnormal timing, is directly marked as an invalid frame, and is discarded. If the sending end experiences a short-term disconnection and then recovers after transmitting multiple consecutive frames, the parsed target sequence number is 104, and the sequence number difference is 4, still meeting the threshold requirement, allowing normal entry into the next verification stage. Therefore, through the above calculation and comparison method, this embodiment of the invention can accurately distinguish between normal transmission frames and timing-skipped frames, achieving pre-interception of abnormal data frames.

[0056] In this embodiment of the invention, the following advantages or beneficial effects are achieved: Traditional technologies lack a pre-sequence number timing screening mechanism, requiring all data frames to undergo full verification calculations. This not only results in low verification efficiency but also fails to intercept abnormal replay frames or skip-forged frames in advance. This invention implements the comparison logic by adding a sequence number difference. Utilizing the ordered incrementing characteristic of the sequence number, it identifies illegal frames with timing anomalies in advance, intercepting old replay frames and abnormal skip-forged frames. This eliminates the need for subsequent complex verification value calculations, reducing the device's computing power consumption. Simultaneously, it forms the first layer of security protection, creating a double-layer protection with subsequent verification value comparisons, significantly improving the anti-spoofing effect.

[0057] For step S3, in some embodiments, when the second check value is completely consistent with the first check value, the present invention can determine that the current Ethernet data frame is a valid frame that was originally transmitted by the sending end and has not been tampered with. Then, the check data segment at the front end of the frame can be stripped, and the remaining non-check service data can be transmitted to the application protocol layer to ensure that normal service interaction continues.

[0058] If a data frame is tampered with, forged by an attacker, or replayed using a historical data frame during network transmission, the content of the data block will be altered, ultimately causing a discrepancy between the second checksum calculated by the receiver and the first checksum carried in the frame.

[0059] Understandably, this step, based on the pre-sequence verification of the sequence number, constructs a verification value comparison mechanism based on the same source operation. The design of uniformly encapsulating the verification data segment in the front end of the data frame also facilitates the receiving end to quickly locate and extract the verification information, thereby improving the overall processing efficiency.

[0060] In this embodiment of the invention, the following advantages or beneficial effects are achieved: Traditional Ethernet transmission verification methods rely solely on simple field matching for judgment, failing to identify deep deception behaviors such as data tampering and frame forgery. Abnormal data can easily flow into the application layer, causing equipment malfunctions. This application generates two sets of verification values ​​through same-source operations at both the sending and receiving ends and performs consistency comparison. Relying on the strong binding characteristics of CRC16's byte-by-byte iterative operation, any modification to any byte in the data block will cause a mismatch in the verification value, accurately identifying various attack behaviors in the transmission link, such as data tampering, address forgery, and historical frame replay. Simultaneously, through differentiated frame handling logic, invalid frames are directly intercepted and discarded, while valid frames are forwarded normally, strengthening the security defense line from the end of the transmission link, further improving the integrity, authenticity, and operational stability of Ethernet data transmission, and fully meeting the usage requirements of anti-spoofing Ethernet data transmission in scenarios such as automotive and industrial interconnection.

[0061] To clearly illustrate the complete interaction logic of this invention, please refer to [link / reference]. Figure 2 , Figure 2The document demonstrates the checksum generation and frame encapsulation process on the sending side, as well as the frame parsing and dual verification process on the receiving side, fully reproducing the entire link execution process of Ethernet data anti-spoofing transmission.

[0062] Specifically, the sending end is a communication node with Ethernet data transmission capability, and its execution process is as follows: When the upper-layer application generates service data to be transmitted, it triggers the Ethernet data frame transmission process. The sequence number counting module maintained locally at the sending end adds a preset increment to the current sequence number, such as adding the current sequence number to 1, to generate a unique target sequence number, ensuring that the timing identifier of each frame of data is dynamically updated.

[0063] According to the preset format, the target sequence number, the last byte of the sender's physical address, and the transmission key predetermined by both the sender and receiver are sequentially concatenated to generate a fixed-length computational data block.

[0064] Based on the preset initial value and the CRC16 algorithm, a cyclic iterative operation of byte-by-byte XOR and shift is performed on the data block to obtain the first CRC check value on the sending side.

[0065] The target sequence number and the first CRC check value are concatenated into a standardized check data segment, which is then inserted into the front end of the business data and encapsulated into a complete Ethernet data frame.

[0066] The hardware driver interface is invoked to send the encapsulated Ethernet data frame to the receiving end via the Ethernet link.

[0067] Furthermore, the receiving end is a communication node with Ethernet data reception capability, and its execution process is as follows: The Ethernet driver interface is used to capture Ethernet data frames transmitted by the sending end.

[0068] Extract the source MAC address from the Ethernet frame, parse the frame header field to obtain the source physical address of the sender, and extract the last fixed bytes of data as address verification data.

[0069] Extract the check data segment from the front end of the data frame and separate the target sequence number and the first CRC check value.

[0070] Retrieve historical valid sequence numbers from local storage, calculate the difference between the current target sequence number and the historical sequence number. If the difference is within a preset reasonable threshold range, the data frame timing is determined to be normal, with no risk of replay or timing abnormality.

[0071] The system reuses the same data splicing rules and operation logic as the sending end, combines the target sequence number, the source MAC address end data, and the locally stored transmission key to generate a source data block and calculate the second CRC check value. This second CRC check value is then compared with the first CRC check value from the sending end. If the second CRC check value matches the first CRC check value exactly, the data frame is determined to be untampered and the verification passes. The front-end verification data segment is then stripped, and the clean business data is transmitted to the upper application protocol layer to complete the data interaction.

[0072] It is understood that the Ethernet data anti-spoofing transmission method of the present invention is implemented by a communication node unit with Ethernet transceiver function, such as an in-vehicle ECU, industrial control equipment or in-vehicle gateway, which has the dual role of both a sender and a receiver.

[0073] When acting as the sender, execute Figure 2 The checksum generation, frame encapsulation, and data transmission process on the left side, when executed by the receiving end, is as follows: Figure 2 The frame parsing, double verification, and data forwarding process on the right enables the verification of the legitimacy of Ethernet data frames and the interception of spoofing.

[0074] Indicatively, the execution entity of this invention can function as a single node, performing only the sending or receiving process; or it can function as a bidirectional communication node, simultaneously performing bidirectional verification processes for sending and receiving, adapting to the secure transmission requirements of bidirectional data interaction scenarios such as vehicle Ethernet and industrial equipment interconnection.

[0075] In summary, the Ethernet data anti-spoofing transmission method proposed in this application has multiple technical advantages compared to the traditional single MAC address verification technology.

[0076] This invention constructs a multi-layered protection system consisting of sequence number timing pre-verification, three-element joint verification, and same-source iterative operation comparison. It solves the problem that traditional schemes cannot resist replay attacks by using ordered incremental target sequence numbers, and solves the defect that traditional public verification rules are easily forged by using the private exclusive keys of the sender and receiver. Furthermore, by distinguishing between local original address bytes and transmission parsing address bytes, it can cover the risk of tampering in link transmission.

[0077] Meanwhile, this invention increases the difficulty of cracking the verification value through byte-by-byte iterative operation logic. The solution of this invention does not require additional hardware modification. It can achieve all-round anti-spoofing protection by only optimizing the software algorithm. It can effectively adapt to transmission scenarios with high security requirements such as vehicle Ethernet and industrial equipment interconnection, and greatly improve the integrity, security and reliability of Ethernet data transmission.

[0078] Please see Figure 3This application also provides an Ethernet data anti-spoofing transmission device, which can implement the above-described Ethernet data anti-spoofing transmission method. The device includes: The verification data segment extraction module is used to extract the verification data segment from the Ethernet data frame when receiving the Ethernet data frame sent by the sending end; wherein the verification data segment includes: a first verification value and a target sequence number generated by the sending end; wherein the first verification value is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; The verification value calculation module is used to calculate a second verification value based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; The check value comparison module is used to determine that the Ethernet data frame is invalid and then discard the Ethernet data frame when the second check value is not equal to the first check value. The verification value comparison module is further configured to determine that the Ethernet data frame is valid when the second verification value is equal to the first verification value, and then transmit the non-verification data segment in the Ethernet data frame to the application protocol layer.

[0079] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0080] It should be noted that the device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0081] Those skilled in the art will clearly understand that, for convenience and simplicity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0082] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned method for preventing spoofing Ethernet data transmission. This electronic device can include any smart terminal such as a tablet computer or in-vehicle computer.

[0083] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0084] Please see Figure 4 , Figure 4 This illustrates the hardware structure of an electronic device according to another embodiment, the electronic device comprising: The processor can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to achieve the technical solutions provided in the embodiments of this application. The memory can be implemented in the form of read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory can store the operating system and other applications. When the technical solutions provided in the embodiments of this application are implemented through software or firmware, the relevant program code is stored in the memory and called and executed by the processor. Input / output interfaces are used to implement information input and output; The communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, Wi-Fi, Bluetooth, etc.). A bus is used to transfer information between various components of a device, such as processors, memory, input / output interfaces, and communication interfaces. The processor, memory, input / output interface, and communication interface are interconnected within the device via a bus.

[0085] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.

[0086] The memory can be used to store the computer program. The processor implements various functions of the terminal device by running or executing the computer program stored in the memory and calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function, etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device or other volatile solid-state storage device.

[0087] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for preventing spoofing during Ethernet data transmission.

[0088] It is understood that the content of the above method embodiments is applicable to the present computer-readable storage medium embodiments. The specific functions implemented by the present computer-readable storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0089] Those skilled in the art will understand that all or some of the steps, apparatuses, or functional modules / units in the methods disclosed above can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0090] The preferred embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the claims of the present application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and substance of the embodiments of the present application shall be within the scope of the claims of the present application.

Claims

1. A method for spoofing-resistant transmission of Ethernet data, characterized in that, The method includes: Upon receiving an Ethernet data frame sent by the sending end, a checksum segment is extracted from the Ethernet data frame; wherein the checksum segment includes: a first checksum and a target sequence number generated by the sending end; wherein the first checksum is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; A second verification value is calculated based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; If the second check value is not equal to the first check value, the Ethernet data frame is determined to be invalid and is then discarded. If the second check value is equal to the first check value, the Ethernet data frame is determined to be valid, and then the non-check data segment in the Ethernet data frame is transmitted to the application protocol layer.

2. The method for preventing spoofing during Ethernet data transmission according to claim 1, characterized in that, The process of generating the first verification value includes: At the end of the physical address, extract the first address byte data corresponding to the preset number of bytes; The target sequence number, the first address byte data, and the first transmission key are concatenated sequentially to generate a first data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the first data block is processed byte by byte until all bytes in the first data block have been processed. Then, the value of the operation register is used as the first check value.

3. The method for preventing spoofing during Ethernet data transmission according to claim 2, characterized in that, The calculation of the second verification value based on the target sequence number, the physical address, and the locally stored second transmission key includes: At the end of the physical address, extract the second address byte data corresponding to the preset number of bytes; The target sequence number, the second address byte data, and the second transmission key are concatenated sequentially to generate a second data block containing several bytes; Initialize the arithmetic register by setting its initial value to a preset initial value; Based on the preset initial value, the second data block is processed byte by byte until all bytes in the second data block have been processed. Then, the value of the operation register is used as the second check value.

4. The method for preventing spoofing during Ethernet data transmission according to claim 1, characterized in that, The process of generating the target sequence number includes: When a data frame transmission command is detected from the sending end, the current sequence number generated by the sending end is obtained; The sum of the preset numerical increment and the current serial number is used as the target serial number.

5. The method for preventing spoofing during Ethernet data transmission according to claim 4, characterized in that, The process of generating the Ethernet data frame includes: Obtain the application data that the sending end is currently transmitting; The target sequence number is concatenated with the first verification value to generate the verification data segment. The verification data segment is concatenated with the application data segment to generate the Ethernet data frame.

6. The method for preventing spoofing during Ethernet data transmission according to claim 4, characterized in that, Before calculating the second check value, the method further includes: Extract the historical sequence number stored locally; wherein, the historical sequence number is the sequence number corresponding to the last received valid Ethernet data frame; The serial number difference between the target serial number and the historical serial number is compared with a preset difference threshold. If the difference in serial numbers is less than the preset difference threshold, then the calculation operation of the second verification value is performed; If the sequence number difference is not less than the preset difference threshold, the Ethernet data frame is directly determined to be invalid and then discarded.

7. The method for preventing spoofing during Ethernet data transmission according to claim 3, characterized in that, The step of performing byte-by-byte operations on the second data block based on the preset initial value until all bytes in the second data block have been processed, and then using the value of the operation register as the second check value, includes: Repeat the following register operations until all bytes in the second data block have been processed, and use the updated target value of the operation register as the second check value: Extract the current byte from the second data block, perform an XOR operation between the current value of the arithmetic register and the current byte, and determine the updated value to be processed from the arithmetic register. Perform a shift operation on the value to be processed after the arithmetic register is updated, and output the target value after the arithmetic register is updated. When it is determined that all bytes in the second data block have not been processed, the updated target value of the operation register is used as the current value of the operation register for the next execution of the register operation.

8. A device for preventing spoofing during Ethernet data transmission, characterized in that, The device includes: The verification data segment extraction module is used to extract the verification data segment from the Ethernet data frame when receiving the Ethernet data frame sent by the sending end; wherein the verification data segment includes: a first verification value and a target sequence number generated by the sending end; wherein the first verification value is generated by the target sequence number, the physical address of the sending end, and the first transmission key of the sending end; The verification value calculation module is used to calculate a second verification value based on the target sequence number, the physical address, and the locally stored second transmission key; wherein the first transmission key and the second transmission key are the same keys pre-agreed upon by the sending end and the receiving end; The check value comparison module is used to determine that the Ethernet data frame is invalid and then discard the Ethernet data frame when the second check value is not equal to the first check value. The verification value comparison module is further configured to determine that the Ethernet data frame is valid when the second verification value is equal to the first verification value, and then transmit the non-verification data segment in the Ethernet data frame to the application protocol layer.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the anti-spoofing transmission method for Ethernet data as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements a method for preventing spoofing of Ethernet data as described in any one of claims 1 to 7.