Vehicle-mounted Ethernet rule compression method and device

By querying and matching access rules in on-board Ethernet, the issue of access rules issuance caused by insufficient hardware resources is solved, and the effective compression and issuance of access entries is realized, which improves hardware utilization and network security.

CN119996058APending Publication Date: 2025-05-13BEIJING JINGWEI HIRAIN TECH CO INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510322968.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing in-vehicle Ethernet rules and hardware resource conditions cannot guarantee that every access rule can be successfully issued to the hardware chip, resulting in some access rules being unable to be successfully issued, affecting network security and other issues.

Method used

By obtaining the access rules to be added for the target network layer, query whether there is an access rules to be added in the pre-built protocol table, and if they do not exist, it will be stored. According to the access rules to the pre-configured target network layer, multiple access entries matching the access rules to the target network layer are selected from the access rules to be added and sent to the hardware chip.

Benefits of technology

Effectively compress and issue access entries, improve hardware utilization, reduce CPU burden, and ensure network security and resource management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996058A_ABST
    Figure CN119996058A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-mounted Ethernet rule compression method and device. The method comprises the following steps: acquiring a to-be-added access rule of a target network layer; querying whether a to-be-added access rule exists in a pre-constructed protocol table or not; if the to-be-added access rule does not exist in the pre-constructed protocol table, storing the to-be-added access rule, and selecting a plurality of access entries matched with the matching item of the target network layer from the to-be-added access rule according to the pre-configured access rule corresponding to the target network layer; and issuing the plurality of access entries to the hardware chip. Therefore, the matching item corresponding to the access rule of each data layer in the vehicle-mounted Ethernet is pre-configured, and then the access entry in the access rule is issued according to the configured matching item of each data layer, so that the access entry can be effectively compressed and issued, and meanwhile, the utilization rate of hardware is also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle-mounted Ethernet communication security technology, and in particular to a method and device for compressing vehicle-mounted Ethernet rules. Background Art

[0002] ACL (Access Control List) is composed of a series of conditional rules, which can be the source address, destination address, port number, etc. of the message. It is an access control list applied to various software and hardware interfaces of network devices. In the existing access control list of automotive Ethernet rules, one access rule corresponds to an access entry in the hardware chip. By sending the access rule to the hardware chip, the access rights of the data flow in the network can be controlled, thereby achieving network security, resource management and flow control.

[0003] However, based on the existing hardware resource conditions of in-vehicle Ethernet rules, it cannot be guaranteed that every access rule can be successfully sent to the hardware chip. Especially in the in-vehicle system, there may be multiple network traffic filtering requirements, which will lead to a rapid increase in the number of access entries, which may cause some access rules to fail to be successfully sent to the hardware chip, which may indirectly affect network security and other issues. Summary of the invention

[0004] Based on the above-mentioned deficiencies of the prior art, the present application provides a method and device for compressing vehicle-mounted Ethernet rules to solve the problem of increasing the number of access entries caused by the prior art.

[0005] In order to achieve the above objectives, this application provides the following technical solutions:

[0006] The first aspect of the present application provides a method for compressing vehicle Ethernet rules, comprising:

[0007] Get the access rules to be added at the target network layer;

[0008] Querying whether the access rule to be added exists in the pre-built protocol table;

[0009] If the access rule to be added does not exist in the pre-constructed protocol table, the access rule to be added is stored, and according to the pre-configured access rule corresponding to the target network layer, a plurality of access entries matching the matching items of the target network layer are selected from the access rule to be added;

[0010] Send the plurality of access entries to the hardware chip.

[0011] Optionally, in the above-mentioned method for compressing in-vehicle Ethernet rules, after sending the plurality of access entries to the hardware chip, the method further includes:

[0012] When receiving a request to delete the access rule of the target network layer, searching the protocol table for whether the access rule exists;

[0013] If the access rule exists in the protocol table, deleting the access rule from the protocol table;

[0014] If the access rule does not exist in the protocol table, a prompt message is fed back to the front end; wherein the prompt message is used to prompt the user that the access rule does not exist in the protocol table and the access rule cannot be deleted.

[0015] Optionally, in the above-mentioned in-vehicle Ethernet rule compression method, deleting the access rule from the protocol table includes:

[0016] Acquire a target access entry corresponding to the access rule from the protocol table;

[0017] Searching the protocol table for a plurality of access rules corresponding to the target access entry;

[0018] The plurality of access rules corresponding to the target access entry are deleted from the protocol table.

[0019] Optionally, in the above-mentioned method for compressing in-vehicle Ethernet rules, after deleting the target access entry corresponding to the access rule from the protocol table, it also includes:

[0020] Detect whether the number of access rules corresponding to the target access entry in the pre-built target protocol table is zero;

[0021] If the number of access rules corresponding to the target access entry in the target protocol table is zero, it is determined that the access rule is deleted successfully;

[0022] If the number of access rules corresponding to the target access entry in the target protocol table is non-zero, it is determined that the access rule deletion has failed.

[0023] Optionally, in the above-mentioned method for compressing in-vehicle Ethernet rules, the method for constructing the protocol table includes:

[0024] Obtain all network access nodes; wherein one network access node corresponds to one access rule;

[0025] Combining each of the network access nodes to obtain multiple groups of access types;

[0026] According to each group of access types, generating a data structure corresponding to each network access node in each group of access types;

[0027] According to each of the data structures, each group of the access types and their corresponding network access nodes, a one-way linked list is constructed to obtain a protocol table.

[0028] Optionally, in the above-mentioned method for compressing in-vehicle Ethernet rules, after sending the plurality of access entries to the hardware chip, the method further includes:

[0029] For each of the access entries, determining whether the access entry matches access rules of at least two target network layers;

[0030] If the access entry matches the access rules of at least two target network layers, obtaining the number of fields corresponding to the access rules of all target network layers matched by the access entry;

[0031] A target network layer corresponding to the maximum number of fields is selected from the field numbers corresponding to the access rules of all the target network layers, and the access entry is matched with the target network layer corresponding to the maximum number of fields.

[0032] Optionally, in the above-mentioned vehicle Ethernet rule compression method, it also includes:

[0033] If the access rule to be added exists in the pre-built protocol table, the front end feeds back target prompt information; wherein, the target prompt information is used to prompt the user that the access rule to be added for the target network layer already exists in the protocol table and does not need to be added again.

[0034] A second aspect of the present application provides a compression device for vehicle-mounted Ethernet rules, comprising:

[0035] A rule acquisition unit, used for acquiring access rules to be added to a target network layer;

[0036] A query unit, used for querying whether the access rule to be added exists in the pre-built protocol table;

[0037] A selection unit, configured to store the access rule to be added if the access rule to be added does not exist in the pre-constructed protocol table, and select a plurality of access entries matching the matching items of the target network layer from the access rule to be added according to the pre-configured access rule corresponding to the target network layer;

[0038] The sending unit is used to send the multiple access entries to the hardware chip.

[0039] Optionally, in the above-mentioned vehicle-mounted Ethernet rule compression device, it also includes:

[0040] A first search unit, configured to search the protocol table for the access rule when receiving a request to delete the access rule of the target network layer;

[0041] a first deleting unit, configured to delete the access rule from the protocol table if the access rule exists in the protocol table;

[0042] The first feedback unit is used to feed back prompt information to the front end if the access rule does not exist in the protocol table; wherein the prompt information is used to prompt the user that the access rule does not exist in the protocol table and the access rule cannot be deleted.

[0043] Optionally, in the above-mentioned in-vehicle Ethernet rule compression device, the first deleting unit includes:

[0044] An entry acquisition unit, configured to acquire a target access entry corresponding to the access rule from the protocol table;

[0045] A second search unit, configured to search the protocol table for a plurality of access rules corresponding to the target access entry;

[0046] The second deleting unit is used to delete the multiple access rules corresponding to the target access entry from the protocol table.

[0047] Optionally, in the above-mentioned vehicle-mounted Ethernet rule compression device, it also includes:

[0048] A detection unit, used for detecting whether the number of access rules corresponding to the target access entry in the pre-built target protocol table is zero;

[0049] A first determining unit, configured to determine that the access rule is successfully deleted if the number of access rules corresponding to the target access entry in the target protocol table is zero;

[0050] The second determining unit is configured to determine that the access rule deletion fails if the number of access rules corresponding to the target access entry in the target protocol table is non-zero.

[0051] Optionally, in the above-mentioned vehicle-mounted Ethernet rule compression device, it also includes:

[0052] A node acquisition unit, used to acquire all network access nodes; wherein one network access node corresponds to one access rule;

[0053] A combining unit, used for combining each of the network access nodes to obtain multiple groups of access types;

[0054] A generating unit, configured to generate, according to each group of the access types, a data structure corresponding to each network access node in each group of the access types;

[0055] The construction unit is used to construct a one-way linked list according to each of the data structures, each group of the access types and their corresponding network access nodes to obtain a protocol table.

[0056] Optionally, in the above-mentioned vehicle-mounted Ethernet rule compression device, it also includes:

[0057] A judging unit, configured to judge, for each of the access entries, whether the access entry matches access rules of at least two target network layers;

[0058] a quantity acquisition unit, configured to acquire the number of fields corresponding to the access rules of all target network layers matched by the access entry if the access entry matches the access rules of at least two target network layers;

[0059] The matching unit is used to select the target network layer corresponding to the maximum number of fields from the number of fields corresponding to the access rules of all the target network layers, and match the access entry with the target network layer corresponding to the maximum number of fields.

[0060] Optionally, in the above-mentioned vehicle-mounted Ethernet rule compression device, it also includes:

[0061] The second feedback unit is used to feedback target prompt information to the front end if the access rule to be added exists in the pre-constructed protocol table; wherein the target prompt information is used to prompt the user that the access rule to be added for the target network layer already exists in the protocol table and does not need to be added again.

[0062] The present application provides a method for compressing in-vehicle Ethernet rules, which obtains the access rules to be added of the target network layer, and then queries whether the access rules to be added exist in the pre-built protocol table. If the access rules to be added do not exist in the pre-built protocol table, the access rules to be added are stored, and according to the access rules corresponding to the pre-configured target network layer, multiple access entries that match the matching items of the target network layer are selected from the access rules to be added, and finally the multiple access entries are sent to the hardware chip. Thus, by pre-configuring the matching items corresponding to the access rules of each data layer in the in-vehicle Ethernet network, and then sending the access entries in the access rules according to the configured matching items of each data layer, the access entries can be effectively compressed and sent, and the utilization rate of the hardware is also improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0064] Figure 1 A schematic diagram of the structure of an in-vehicle Ethernet regular communication system provided in an embodiment of the present application;

[0065] Figure 2 A flowchart of a method for compressing vehicle Ethernet rules provided in an embodiment of the present application;

[0066] Figure 3 A flowchart of a method for constructing a protocol table provided in an embodiment of the present application;

[0067] Figure 4 A schematic diagram of the structure of an access rule corresponding to a data link layer provided in an embodiment of the present application;

[0068] Figure 5 A schematic diagram of the structure of an access rule corresponding to the ARP protocol provided in an embodiment of the present application;

[0069] Figure 6 A schematic diagram of the structure of an access rule corresponding to a network layer provided in an embodiment of the present application;

[0070] Figure 7 A schematic diagram of the structure of an access rule corresponding to a transport layer provided in an embodiment of the present application;

[0071] Figure 8 A flowchart of a method for deleting access rules provided in another embodiment of the present application;

[0072] Fig. 9 A flowchart of another method for deleting access rules provided in another embodiment of the present application;

[0073] Fig.10 A flowchart of an access rule detection method provided by another embodiment of the present application;

[0074] Fig.11 A flowchart of a method for matching access entries provided in another embodiment of the present application;

[0075] Fig.12 A schematic structural diagram of a vehicle-mounted Ethernet rule compression device provided in another embodiment of the present application. DETAILED DESCRIPTION

[0076] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0077] In this application, relational terms such as first and second, etc. are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0078] An embodiment of the present application provides a method for compressing an in-vehicle Ethernet rule, which is applied to an in-vehicle Ethernet rule communication system to solve the problem of increasing the number of access entries caused by the prior art.

[0079] Alternatively, if Figure 1 As shown, an embodiment of the present application provides an in-vehicle Ethernet regular communication system, including: an in-vehicle network and a vehicle-cloud network.

[0080] It should be noted that the in-vehicle network is composed of TBOX (on-board processing and communication terminal) and various electronic control units (ECUs). The car-cloud network is composed of TBOX and the cloud.

[0081] Specifically, when the in-vehicle network communicates with the cloud, TBOX acts as a forwarding intermediate layer, and the in-vehicle network forwards the communication data to the cloud through TBOX. According to the TCP / IP transmission protocol, the data communication of the in-vehicle Ethernet rules will involve the data link layer, the address resolution protocol (Address Resolution Protocol, APR), the network layer and the transport layer. Therefore, the embodiment of the present application configures corresponding access rules for the data link layer, the network layer and the transport layer, respectively, so as to effectively reduce the access entries sent to the hardware. It should be emphasized that, by default, since the data going out of TBOX is safe by default, the embodiment of the present application only considers the data flow entering TBOX, so as to ensure the security and stability of the system.

[0082] Based on the in-vehicle Ethernet rule communication system provided above, an embodiment of the present application provides a method for compressing in-vehicle Ethernet rules, which is applied to the in-vehicle Ethernet rule communication system provided above, such as Figure 2 As shown, the specific steps include:

[0083] S201. Obtain access rules to be added at the target network layer.

[0084] It should be noted that the target network layer can be one of the data link layer, ARP protocol, network layer and transport layer. The specific needs are determined based on the user's selection. Among them, the subsequent access rules to be added and the access rules can both be ACL rules.

[0085] Optionally, when the user sends a request to the system to add access rules in the data link layer, the target network layer at this time is the data link layer. At the same time, the system will receive the request sent by the user and obtain the rules to be added in the data link layer sent by the user from the request.

[0086] S202: Query whether there is an access rule to be added in the pre-built protocol table.

[0087] It should be emphasized that the pre-built protocol table stores all access rules related to the data link layer, ARP protocol, network layer and transport layer. Therefore, when the access rule to be added is obtained, the protocol table will be queried to see whether the access rule to be added already exists, so as to avoid repeated addition and increase the burden on the CPU. Therefore, when the access rule to be added does not exist in the pre-built protocol table, it means that the access rule to be added can be added, so step S203 is executed.

[0088] Optionally, after executing step S202, the method further includes:

[0089] If there are access rules to be added in the pre-built protocol table, the front end will feedback the target prompt information.

[0090] The target prompt information is used to prompt the user that the access rule to be added for the target network layer already exists in the protocol table and does not need to be added again.

[0091] Specifically, when there are access rules to be added in the pre-built protocol table, it is necessary to directly feedback to the user that the access rules to be added already exist and do not need to be sent again, so as to avoid affecting the processing efficiency of the hardware.

[0092] Optionally, the present application embodiment provides a method for constructing a protocol table, such as Figure 3 As shown, the following steps are included:

[0093] S301. Obtain all network access nodes.

[0094] Specifically, adding access rules in the data link layer, network layer, address resolution protocol, and transport layer means that ACL entries will be generated in the hardware chip, thereby increasing the ACL entries. Therefore, in order to reduce the ACL entries, all network access nodes can be obtained from the in-vehicle Ethernet, where one network access node corresponds to one access rule.

[0095] S302: Combine each network access node to obtain multiple groups of access types.

[0096] It should be noted that in the embodiment of the present application, the data link layer, network layer, address resolution protocol and transport layer all have different ACL rules that need to be issued. Therefore, each network access node can be combined according to the different issuance rules of the data link layer, network layer, address resolution protocol and transport layer to obtain multiple groups of access types, so that it can be known which ACL rules need to be issued to the corresponding layer in the future.

[0097] S303: Generate a data structure corresponding to each network access node in each access type group according to each access type group.

[0098] It is understandable that, in order to process each ACL rule separately later, a corresponding data structure may be generated for each network access node (ACL rule).

[0099] S304: construct a one-way linked list according to each data structure, each group of access types and their corresponding network access nodes to obtain a protocol table.

[0100] Specifically, in order to store each data structure, each group of access types and their corresponding network access nodes, a one-way linked list can be constructed and stored in it, thereby obtaining a protocol table.

[0101] S203: Store the access rules to be added, and select multiple access entries that match the matching items of the target network layer from the access rules to be added according to the pre-configured access rules corresponding to the target network layer.

[0102] It should be emphasized that when the access rules to be added do not exist in the pre-built protocol table, a new ACL can be added to the system, that is, added to the chip management program, and then the chip management program sends the access rules to be added to the hardware. Since the operations of access rules at the data link layer, network layer and transport layer are deletion, addition and viewing, the operation process of each layer is the same. The main difference is that the information concerned by the access rules at each layer is different, that is, the matching items. Therefore, in the embodiment of the present application, the access rules and matching items corresponding to each layer will be pre-configured, so that when the chip management program is sent down, the chip management program will obtain the matching items of the target network layer according to the pre-configured access rules corresponding to the target network layer, and then select the access items that match the matching items from the access rules to be added, thereby greatly reducing the generation of access items to achieve the purpose of compressing access items. Among them, the access items can be ACL items.

[0103] Therefore, since the access rules of the data link layer are generally composed of the destination physical address (dmac), the source physical address (smac) and the protocol type of the upper layer (i.e., the network layer), and there are multiple physical ports on the TBOX, each physical port has a corresponding dmac, so the same electronic control unit (ECU) may communicate with different ports of the TBOX, which will lead to the same smac corresponding to the dmac of multiple TBOXes. Therefore, in order to reduce the generation of access entries, when configuring the access rules corresponding to the data link layer, dmac is not considered, only the protocol type and smac are concerned, among which the matching items of the data link layer are the protocol type and smac. Therefore, when the target network layer is the data link layer, the chip management program will filter out the access entries corresponding to the protocol type and smac from the access rules to be added when sending the access rules to be added to the hardware, and only send the access entries corresponding to the protocol type and smac to the hardware, thereby reducing the generation of access entries in the hardware chip. For specific access rules corresponding to the data link layer, please refer to Figure 4 The content shown.

[0104] It should also be noted that the access rules corresponding to the ARP protocol are generally composed of dmac, smac, destination ip address (dip), source ip address (sip) and protocol type. The ARP protocol is a protocol used to resolve IP addresses to MAC addresses. In the vehicle network, the ARP protocol is generally not required for TBOX to communicate with the internal ECU, because the static ARP has been set up when the ECU and TBOX are started, so there is no need for the ARP protocol to learn the MAC address, that is, smac. However, the MAC address on the ECU component required for TBOX to communicate with the outside world cannot be determined, so ARP address learning is required. Since there are multiple physical ports on the TBOX, each physical port has a corresponding dmac. The ECU of the same external Internet device may communicate with different physical ports of the TBOX, which will result in the same smac corresponding to the dmac of multiple TBOXs. In addition, each physical port of the TBOX is generally divided into subnet segments, and each subnet segment has a corresponding ip address. Each ip address and the ip address of the external Internet device may form an access rule. Therefore, in order to reduce the generation of access entries, when configuring the access rules corresponding to the ARP protocol, dmac (TBOX's mac), dip (TBOX's ip) and smac (ARP protocol learned MAC address) will not be considered, and only the Ethernet type corresponding to the sip and ARP protocols will be considered. Among them, the matching items of the ARP protocol are the Ethernet types corresponding to the sip and ARP protocols. Therefore, when the target network layer is the ARP protocol, the chip management program will filter out the access entries corresponding to the sip and Ethernet types from the access rules to be added when sending the access rules to the hardware, and only send the access entries corresponding to the sip and Ethernet types to the hardware. For specific access rules corresponding to the ARP protocol, please refer to Figure 5 The content shown.

[0105] It should also be emphasized that the access rules of the network layer are generally composed of dmac, smac, dip, sip and protocol types. Since there are multiple physical ports on TBOX, each physical port is divided into multiple subnet segments, and each subnet segment has a corresponding IP address, the IP address will be combined with the ECU's mac to obtain a large number of access rules. Therefore, in order to reduce access entries, when configuring the access rules corresponding to the network layer, dmac and dip are not considered (dmac and dip are both TBOX's). This is equivalent to filtering only the binding of the ECU's IP and mac, and only focusing on the protocol type, smac and sip. Therefore, when the target network layer is the network layer, the chip management program will filter out the access entries corresponding to the protocol type, smac and sip from the access rules to be added when sending the access rules to the hardware, ignoring dmac and dip, and only sending the access entries corresponding to the protocol type, smac and sip to the hardware. Among them, the matching items of the network layer are the protocol type, smac and sip. For specific access rules corresponding to the network layer, please refer to Figure 6 The content shown.

[0106] Another thing to pay attention to is the access rules of the transport layer. Since the access rules of the transport layer are generally composed of five tuples, the five tuples are dip, sip, destination port (dport), source port (sport) and protocol type. Based on the five-tuple information, the business needs and behaviors of network communication can be inferred. No information will be omitted here, because the five-tuple corresponds to the business logic. Access entries cannot be reduced simply by ignoring a certain information in the five-tuple. If a certain information in the five-tuple is ignored, the access rules cannot accurately match the data flow of each business, resulting in the inability to obtain the data flow information of the business, such as the inability to obtain the number of data packets sent or received by the business in a certain time period, thus affecting the business needs of the system processing. Therefore, an access rule at the transport layer will correspond to an access entry. Therefore, when configuring the access rules corresponding to the transport layer, the matching items of the transport layer are five-tuples. Therefore, when the target network layer is the transport layer, the chip management program will filter out the access entries corresponding to the five-tuple from the access rules to be added when sending the access rules to be added to the hardware, ignoring information other than the five-tuple (dip, sip, dport, sport and protocol type). For specific access rules corresponding to the transport layer, please refer to Figure 7 The content shown.

[0107] S204: Send multiple access entries to the hardware chip.

[0108] Specifically, when the target network layer is the data link layer, the chip management program sends the protocol type in the access rule to be added and each access entry corresponding to the smac to the hardware chip.

[0109] When the target network layer is the ARP protocol, the chip management program sends each access entry corresponding to the SIP and Ethernet types in the access rule to be added to the hardware chip.

[0110] When the target network layer is the network layer, the chip management program sends the protocol type, smac and sipc corresponding to each access entry in the access rule to be added to the hardware chip.

[0111] When the target network layer is the transport layer, the chip management program sends each access entry corresponding to the five-tuple (dip, sip, dport, sport and protocol type) in the access rule to be added to the hardware chip.

[0112] Optionally, after adding the access entry to the hardware chip, the added access rule can also be deleted from the hardware chip. Therefore, in another embodiment of the present application, a method for deleting an access rule is provided, such as Figure 8 As shown, the specific steps include:

[0113] S801. When a request to delete an access rule of a target network layer is received, it is checked whether there is an access rule in a protocol table.

[0114] Specifically, when receiving a request from the user to delete the access rules of the target network layer, the chip management program will first traverse the protocol table storing the access rules. This protocol table is usually a data structure that contains all configured access rules. Then the chip management program will check whether there are access rules for the target network layer in the protocol table, because the target network layer is usually composed of the source IP address, the target IP address, the protocol type, the source port, the target port, etc. The chip management program will compare the target network layer in the access rules with the target network layer specified in the request one by one to see if they match, that is, whether there are access rules for the target network layer in the protocol table. If there are access rules in the protocol table, the deletion operation will be performed, that is, step S802 will be executed. If there are no access rules in the protocol table, there is no deletion operation, so step S803 will be executed.

[0115] S802. Delete the access rule from the protocol table.

[0116] Optionally, when there are access rules in the protocol table, the access rules to be deleted can be deleted from the protocol table through the edit delete command.

[0117] For example, the delete command could be:

[0118] DELETE / v{version} / acl / rule / {aclRuleId}?clientToken={clientToken}HTTP / 1.1.

[0119] Optionally, in another embodiment of the present application, another specific implementation of step S802 is as follows: Fig. 9 As shown, the following steps are included:

[0120] S901. Obtain a target access entry corresponding to an access rule from a protocol table.

[0121] It should be emphasized that in order to completely delete an access rule, the access entry corresponding to the access rule must also be deleted. However, the target network layer may have multiple access rules corresponding to one access entry, that is, multiple access rules can be summarized into the same access entry. Therefore, when deleting an access rule, the corresponding access entry cannot be deleted directly, because this access entry may also contain other rules. Therefore, when deleting an access rule, the chip management program needs to first obtain the target access entry corresponding to the access rule from the protocol table.

[0122] S902: Search the protocol table for multiple access rules corresponding to the target access entry.

[0123] It should be noted that in order to successfully delete the access rules of the target network layer, the chip management program needs to track how many access rules correspond to the target access entry, including the access rules of the target network layer that the user needs to delete. Only when all access rules corresponding to the target access entry are deleted can it be determined that the access rules of the target network layer have been successfully deleted. Therefore, the chip management program needs to search for multiple access rules corresponding to the target access entry from the protocol table in advance.

[0124] S903: Delete multiple access rules corresponding to the target access entry from the protocol table.

[0125] Optionally, after deleting the access rule from the protocol table, the access entry also needs to be deleted. Therefore, after executing step S903, another embodiment of the present application further provides a method for deleting the access entry, such as Fig.10 As shown, the following steps are included:

[0126] S1001. Detect whether the number of access rules corresponding to the target access entry in the pre-built target protocol table is zero.

[0127] It should be noted that, since the protocol table contains two linked lists, one linked list stores the access rules in the target network layer (such as dmac, smac, dip, sip and protocol type in the ARP protocol), and the other linked list (that is, the target protocol table) only stores the matching items (such as sip and protocol type in the ARP protocol). If there are multiple access rules corresponding to the same matching items in the first linked list, there will only be one node in the second linked list, and the node contains the matching items, but the node will also have a parameter indicating how many access rules the node corresponds to in the first linked list. Only when the value corresponding to the parameter contained in the node in the second linked list is 0, it indicates that there is no association with the access rules in the first linked list. Therefore, when the value corresponding to the parameter is 0, the access entry corresponding to the access rule of the target network layer can be truly deleted in the hardware, so that the user's request to delete the access rule of the target network layer can be truly deleted successfully. Therefore, it is necessary to detect whether the number of access rules corresponding to the target access entry in the protocol table is zero. If the number of access rules corresponding to the target access entry in the protocol table is zero, it means that the node in the second linked list is not associated with the access rules in the first linked list, so step S1002 is executed. If the number of access rules corresponding to the target access entry in the protocol table is non-zero, it means that the nodes in the second linked list are still associated with the access rules in the first linked list, then the target access entry has not been deleted successfully, which means that the access rules of the target network layer requested to be deleted by the user have not been deleted successfully, so execute step S1003.

[0128] S1002. Determine whether the target access entry is deleted successfully.

[0129] Specifically, when the number of access rules corresponding to the target access entry in the protocol table is zero, information indicating that the access entry of the target network layer has been successfully deleted is fed back to the front end.

[0130] S1003. Determine that deletion of the target access entry fails.

[0131] Specifically, when the number of access rules corresponding to the target access entry in the protocol table is non-zero, information that the access entry of the target network layer has failed to be deleted is fed back to the front end.

[0132] S803: Feedback prompt information to the front end.

[0133] The prompt information is used to prompt that the access rule does not exist in the user protocol table and the access rule cannot be deleted.

[0134] Specifically, when the access rule does not exist in the protocol table, a prompt message needs to be sent to inform the user that the access rule of the target network layer does not exist in the hardware chip, and to reflect that the request operation has failed.

[0135] Optionally, after multiple access entries are sent to the hardware chip, the access entries may match multiple target network layers. Therefore, in order to handle this situation in a timely manner, in another embodiment of the present application, a matching method for access entries is provided, such as Fig.11 As shown, the specific steps include:

[0136] S1101. For each access entry, determine whether the access entry matches access rules of at least two target network layers.

[0137] It should be noted that, considering that the access entry may match multiple target network layers, it is necessary to determine whether the access entry matches the access rules of at least two target network layers for each access entry. If the access entry matches the access rules of at least two target network layers, then the access entry can be matched according to the longest match principle, so step S1102 is executed.

[0138] Optionally, if the access entry does not match the access rules of at least two target network layers, it means that the access entry only matches the last target network layer, so at this time, it is only necessary to match the access entry with the target network layer.

[0139] S1102. Obtain the number of fields corresponding to the access rules of all target network layers matched by the access entry.

[0140] Specifically, when an access entry matches the access rules of at least two target network layers, the access entry can be matched according to the longest match principle, that is, matching is performed according to the number of fields corresponding to the access rules of the target network layer. Therefore, it is necessary to first obtain the number of fields corresponding to the access rules of the matching target network layer.

[0141] S1103 . Select a target network layer corresponding to the maximum number of fields from the field numbers corresponding to the access rules of all target network layers, and match the access entry with the target network layer corresponding to the maximum number of fields.

[0142] Specifically, in order to ensure processing of the most complex data structure, maximize data utilization, and achieve the purpose of compressing ACL entries, the access entry may be matched with the ACL rule of the target network layer corresponding to the maximum number of fields.

[0143] For example, the ACL rule at the network layer has three fields (smac, sip, protocol), and the ACL rule at the data link layer has two fields (smac, ethernet type). Then, according to the longest match principle, the access entry will match the ACL rule at the network layer.

[0144] The present application provides a method for compressing in-vehicle Ethernet rules, which obtains the access rules to be added of the target network layer, and then queries whether the access rules to be added exist in the pre-built protocol table. If the access rules to be added do not exist in the pre-built protocol table, the access rules to be added are stored, and according to the access rules corresponding to the pre-configured target network layer, multiple access entries that match the matching items of the target network layer are selected from the access rules to be added, and finally the multiple access entries are sent to the hardware chip. Thus, by pre-configuring the matching items corresponding to the access rules of each data layer in the in-vehicle Ethernet network, and then sending the access entries in the access rules according to the configured matching items of each data layer, the access entries can be effectively compressed and sent, and the utilization rate of the hardware is also improved.

[0145] Another embodiment of the present application provides a compression device for vehicle-mounted Ethernet rules, such as Fig.12 As shown, it specifically includes the following units:

[0146] The rule acquisition unit 1201 is used to acquire the access rule to be added of the target network layer.

[0147] The query unit 1202 is used to query whether there is an access rule to be added in the pre-built protocol table.

[0148] The selection unit 1203 is used to store the access rule to be added if the access rule to be added does not exist in the pre-constructed protocol table, and select multiple access entries matching the matching items of the target network layer from the access rule to be added according to the pre-configured access rule corresponding to the target network layer.

[0149] The sending unit 1204 is used to send multiple access entries to the hardware chip.

[0150] It should be noted that the specific working process of the above modules in the embodiment of the present application can refer to steps S201 to S204 in the above method embodiment, which will not be repeated here.

[0151] Optionally, in another embodiment of the present application, a compression device for an in-vehicle Ethernet rule further includes:

[0152] The first searching unit is configured to search whether there is an access rule in the protocol table when receiving a request to delete the access rule of the target network layer.

[0153] The first deleting unit is used to delete the access rule from the protocol table if the access rule exists in the protocol table.

[0154] The first feedback unit is used to feed back prompt information to the front end if the access rule does not exist in the protocol table, wherein the prompt information is used to prompt the user that the access rule does not exist in the protocol table and the access rule cannot be deleted.

[0155] Optionally, in a vehicle Ethernet rule compression device provided by another embodiment of the present application, the first deletion unit includes:

[0156] The entry acquisition unit is used to acquire the target access entry corresponding to the access rule from the protocol table.

[0157] The second search unit is used to search the protocol table for multiple access rules corresponding to the target access entry.

[0158] The second deleting unit is used to delete the multiple access rules corresponding to the target access entry from the protocol table.

[0159] Optionally, in another embodiment of the present application, a compression device for an in-vehicle Ethernet rule further includes:

[0160] The detection unit is used to detect whether the number of access rules corresponding to the target access entry in the pre-built target protocol table is zero.

[0161] The first determining unit is used to determine that the access entry is successfully deleted if the number of access rules corresponding to the target access entry in the target protocol table is zero.

[0162] The second determining unit is configured to determine that the access entry deletion fails if the number of access rules corresponding to the target access entry in the target protocol table is non-zero.

[0163] Optionally, in another embodiment of the present application, a compression device for an in-vehicle Ethernet rule further includes:

[0164] The node acquisition unit is used to acquire all network access nodes, wherein one network access node corresponds to one access rule.

[0165] The combining unit is used to combine each network access node to obtain multiple groups of access types.

[0166] The generating unit is used to generate, according to each group of access types, a data structure corresponding to each network access node in each group of access types.

[0167] The construction unit is used to construct a one-way linked list according to each data structure, each group of access types and their corresponding network access nodes to obtain a protocol table.

[0168] Optionally, in another embodiment of the present application, a compression device for an in-vehicle Ethernet rule further includes:

[0169] The judging unit is used to judge, for each access entry, whether the access entry matches the access rules of at least two target network layers.

[0170] The quantity acquisition unit is used to acquire the number of fields corresponding to the access rules of all target network layers matched by the access entry if the access entry matches the access rules of at least two target network layers.

[0171] The matching unit is used to select the target network layer corresponding to the maximum number of fields from the number of fields corresponding to the access rules of all target network layers, and match the access entry with the target network layer corresponding to the maximum number of fields.

[0172] Optionally, in another embodiment of the present application, a compression device for an in-vehicle Ethernet rule further includes:

[0173] The second feedback unit is used to feedback target prompt information to the front end if there is an access rule to be added in the pre-built protocol table. The target prompt information is used to prompt the user that the access rule to be added for the target network layer already exists in the protocol table and does not need to be added again.

[0174] It should be noted that the specific working process of each module provided in the above embodiments of the present application can refer to the corresponding steps in the above method embodiments, and will not be repeated here.

[0175] In summary, an in-vehicle Ethernet rule compression device provided in an embodiment of the present application reduces the matching items corresponding to each layer of data transmission channels in the access rules by pre-configuring the access rules corresponding to each layer of data transmission channels, thereby achieving the purpose of compressing access entries, thereby improving the utilization rate of hardware and reducing the burden on the CPU.

[0176] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0177] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for compressing vehicle Ethernet rules, characterized in that: include: Obtaining the access rule to be added of the target network layer; wherein the target network layer is one of a data link layer, an address resolution protocol, a network layer, and a transport layer; Querying whether the access rule to be added exists in the pre-built protocol table; If the access rule to be added does not exist in the pre-constructed protocol table, the access rule to be added is stored, and according to the pre-configured access rule corresponding to the target network layer, a plurality of access entries matching the matching items of the target network layer are selected from the access rule to be added; Send the plurality of access entries to the hardware chip.

2. The method according to claim 1, characterized in that After sending the plurality of access entries to the hardware chip, the method further includes: When receiving a request to delete the access rule of the target network layer, searching the protocol table for whether the access rule exists; If the access rule exists in the protocol table, deleting the access rule from the protocol table; If the access rule does not exist in the protocol table, a prompt message is fed back to the front end; wherein the prompt message is used to prompt the user that the access rule does not exist in the protocol table and the access rule cannot be deleted.

3. The method according to claim 2, characterized in that Deleting the access rule from the protocol table includes: Acquire a target access entry corresponding to the access rule from the protocol table; Searching the protocol table for a plurality of access rules corresponding to the target access entry; The plurality of access rules corresponding to the target access entry are deleted from the protocol table.

4. The method according to claim 3, characterized in that After deleting the target access entry corresponding to the access rule from the protocol table, the method further includes: Detect whether the number of access rules corresponding to the target access entry in the pre-built target protocol table is zero; If the number of access rules corresponding to the target access entry in the target protocol table is zero, it is determined that the target access entry is deleted successfully; If the number of access rules corresponding to the target access entry in the target protocol table is non-zero, it is determined that the deletion of the target access entry has failed.

5. The method according to claim 1, characterized in that The method for constructing the protocol table includes: Obtain all network access nodes; wherein one network access node corresponds to one access rule; Combining each of the network access nodes to obtain multiple groups of access types; According to each group of access types, generating a data structure corresponding to each network access node in each group of access types; According to each of the data structures, each group of the access types and their corresponding network access nodes, a one-way linked list is constructed to obtain a protocol table.

6. The method according to claim 1, characterized in that After sending the plurality of access entries to the hardware chip, the method further includes: For each of the access entries, determining whether the access entry matches access rules of at least two target network layers; If the access entry matches the access rules of at least two target network layers, obtaining the number of fields corresponding to the access rules of all target network layers matched by the access entry; A target network layer corresponding to the maximum number of fields is selected from the field numbers corresponding to the access rules of all the target network layers, and the access entry is matched with the target network layer corresponding to the maximum number of fields.

7. The method according to claim 1, characterized in that Also includes: If the access rule to be added exists in the pre-built protocol table, the front end feeds back target prompt information; wherein, the target prompt information is used to prompt the user that the access rule to be added for the target network layer already exists in the protocol table and does not need to be added again.

8. A compression device for vehicle-mounted Ethernet rules, characterized in that: include: A rule acquisition unit, used for acquiring access rules to be added to a target network layer; A query unit, used for querying whether the access rule to be added exists in the pre-built protocol table; A selection unit, configured to store the access rule to be added if the access rule to be added does not exist in the pre-constructed protocol table, and select a plurality of access entries matching the matching items of the target network layer from the access rule to be added according to the pre-configured access rule corresponding to the target network layer; The sending unit is used to send the multiple access entries to the hardware chip.

9. The device according to claim 8, characterized in that Also includes: A first search unit, configured to search the protocol table for the access rule when receiving a request to delete the access rule of the target network layer; a first deleting unit, configured to delete the access rule from the protocol table if the access rule exists in the protocol table; The first feedback unit is used to feed back prompt information to the front end if the access rule does not exist in the protocol table; wherein the prompt information is used to prompt the user that the access rule does not exist in the protocol table and the access rule cannot be deleted.

10. The device according to claim 8, characterized in that The first deleting unit comprises: An entry acquisition unit, configured to acquire a target access entry corresponding to the access rule from the protocol table; A second search unit, configured to search the protocol table for a plurality of access rules corresponding to the target access entry; The second deleting unit is used to delete the multiple access rules corresponding to the target access entry from the protocol table.