Method and computer system for network access control
By deploying a Network Access Manager (NAM) software module in the vehicle network, the network status is monitored and access requests are verified, which solves the network access control problem under various wireless network communications of vehicle network nodes, realizes flexible network access and priority processing, and ensures the timeliness and security of critical services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-25
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies are difficult to apply to network access control when vehicle network nodes communicate through multiple wireless networks, especially in terms of multiple communication terminals and network priority processing.
By deploying the Network Access Manager (NAM) software module, network status is monitored and network access requests are verified based on trust configuration information. Data transmission paths are created, and differentiated services and network priority processing are provided.
It enables flexible network access control, ensuring the timeliness of critical services and network security, and adapts to vehicle network node communication in various wireless network environments.
Smart Images

Figure CN121815265A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of digital information transmission, and in particular, to a method and a computer system for network access control, a computer readable storage medium and a computer program product. BACKGROUND
[0002] In a typical in-vehicle network, each in-vehicle network node (e.g. infotainment system, etc.) can send network access requests to a communication terminal referred to as "T-Box" through a vehicle Ethernet, etc., which can be all network address translated by the T-Box to be routed to a vehicle external network, so that these in-vehicle electronic systems access the Internet through a cellular network.
[0003] However, the network access control applied in such a typical in-vehicle network can be difficult to apply to the case where each in-vehicle network node communicates through multiple wireless networks, multiple communication terminals, such as how to control the network access of multiple network nodes using multiple wireless networks and further provide network priority processing.
[0004] It is to be noted that the information disclosed in the above background section is only for the purpose of strengthening the understanding of the background of the present application, and thus can include information which does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] Embodiments of the present application provide a method and a computer system for network access control, a computer readable storage medium and a computer program product, in order to solve or at least alleviate one or more problems existing in the prior art.
[0006] According to an aspect of the present application, a method for network access control is provided, the method comprising: in response to receiving a network status query request from a client node in an in-vehicle network, sending network status information corresponding to the network status query request to the client node; verifying a network access request received from the client node according to trust configuration information, wherein the network access request comprises a wireless network selection based on the network status information; after determining that the network access request passes the verification, sending a message allowing network access to the client node, and creating a data transmission path between the client node and a wireless communication terminal corresponding to the wireless network selection according to the wireless network selection.
[0007] In one or more embodiments of the present application, optionally, the network access request further comprises: application identifiers of one or more applications requesting access to the network in an application deployed on the client node and an IP address of the client node.
[0008] In one or more embodiments of the application, optionally, the trust configuration information comprises a trust list including application identifiers of allowed applications and allowed client node IP addresses.
[0009] In one or more embodiments of the application, optionally, verifying the network access request received from the client node comprises determining whether the application identifiers of the one or more applications and the IP address exist in the trust list.
[0010] In one or more embodiments of the application, optionally, the wireless network selection comprises selecting a cellular network or a wireless local area network.
[0011] In one or more embodiments of the application, optionally, the client node comprises one or more of the following: an in-vehicle infotainment system, a central gateway module, and an advanced driver assistance system.
[0012] In one or more embodiments of the application, optionally, the message allowing network access comprises a differentiated services code point corresponding to the application identifier.
[0013] According to an aspect of the application, there is provided a computer system comprising: at least one memory; at least one processor; and a computer program stored on the memory and executable on the processor, the execution of the computer program on the processor causing: in response to receiving a network status query request from a client node in a vehicle network, sending, to the client node, network status information corresponding to the network status query request; verifying, according to trust configuration information, a network access request received from the client node, wherein the network access request comprises a wireless network selection based on the network status information; in response to determining that the network access request passes the verification, sending, to the client node, a message allowing network access, and creating, according to the wireless network selection, a data transmission path between the client node and a wireless communication terminal corresponding to the wireless network selection.
[0014] According to an aspect of the application, there is provided a computer readable storage medium having stored therein instructions which, when executed by a processor, cause any of the methods described above to be implemented.
[0015] According to an aspect of the application, there is provided a computer program product comprising computer instructions which, when executed by a processor, implement any of the methods described above. BRIEF DESCRIPTION OF DRAWINGS
[0016] The above and other features, aspects and advantages of the present application will become better understood when read with respect to the following detailed description, taken in conjunction with the accompanying drawings, wherein like reference numerals designate the same elements throughout the drawings, and wherein: Figure 1 A method for network access control according to some embodiments of the present application is shown; and Figure 2 is a schematic block diagram of a computer system. DETAILED DESCRIPTION
[0017] The present application will be more fully understood from the following detailed description taken in conjunction with the accompanying drawings, in which like reference numerals denote similar elements throughout the several views. The following detailed description includes specific details for the purpose of providing a thorough understanding of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring the concept of the application. Where applicable, embodiments of the present application and features thereof can also be combined with one another.
[0018] In the present application, the terms such as "comprise", "include", "have" and the like are intended to mean that the technical solutions of the present application include the stated elements and steps, but not excluding the presence of other elements and steps not directly or clearly stated.
[0019] Unless otherwise specified, the terms such as "first" and "second" are not intended to denote a sequence in time, space, size, etc., but are merely used to distinguish between elements, and are not intended to limit any element to only a single element.
[0020] In this application, the in-vehicle network can include a plurality of in-vehicle network nodes, which can initiate network access requests to a T-Box communication terminal as a server node providing access functions of long-range wireless networks (e.g. non-ground networks, cellular networks such as LTE networks and 5G networks, etc.). The above in-vehicle network nodes include In-Vehicle Infotaniment (IVI) nodes providing access functions of short-range wireless networks (e.g. Bluetooth networks, ZigBee networks, wireless local area networks such as 2.4GHz, 5GHz wireless local area networks, etc.), so that the vehicle can access the wireless local area network to update its software or firmware, provide audio and video content, etc. In the method provided in this application for a plurality of client nodes to access networks using a plurality of wireless networks, a network access manager (hereinafter referred to as NAM) software module can be deployed in the IVI node as a server node, so that the IVI node and other client nodes (such as Central Gateway Module (CGM), Advanced Driver Assistant System (ADAS), etc.) can be granted network access at least through both cellular networks and wireless local area networks. The following will be described in detail in conjunction with the accompanying drawings.
[0021] Figure 1 A method 100 for network access control according to some embodiments of the present application is shown, which includes steps 110-130.
[0022] In step 110, in response to receiving a network status query request from a client node in the in-vehicle network, network status information corresponding to the network status query request can be sent to the client node. Specifically, the NAM software module can be configured to monitor the network status of the long-range wireless network (e.g. cellular network) accessed by the T-Box communication terminal, and configured to monitor the network status of the short-range wireless network (e.g. wireless local area network) accessed by the IVI node. The client nodes (e.g. IVI, CGM, ADAS, etc. nodes) in the in-vehicle network can actively send network status query requests to the NAM software module as a server node. The NAM software module can be configured to send real-time network status information corresponding to the network status query request to the client node in response to the client node receiving the network status query request. In some embodiments, the network status information includes one or more of the following: network type (e.g. cellular network and wireless local area network), network connectivity, network delay, network rate, recommended network (e.g. recommended network based on evaluation rate and delay), and gateway address of the recommended network.
[0023] In some embodiments, the NAM software module can be configured to publish network status of long-range wireless networks (e.g., cellular networks) and network status of short-range wireless networks (e.g., wireless local area networks) in a periodic manner, for example, and accordingly, each client node (e.g., IVI, CGM, ADAS, etc. node) can receive the latest network status information (e.g., the network with lower latency and / or higher network rate in the wireless local area network or cellular network) from the NAM software module in a subscription rather than active query manner.
[0024] At step 120, the network access request received from the client node can be verified according to the trust configuration information. Specifically, in the case that each client node (e.g., IVI, CGM, ADAS, etc. node) subscribes to the service of the NAM software module publishing network status information, it can send a network access request to the NAM software module according to the network status information corresponding to the network status query request received from the NAM software module. The NAM software module can be configured to access the memory (e.g., non-volatile memory) storing the trust configuration information to obtain the trust configuration information, and compare the trust configuration information with the information in the network access request to verify whether the information in the network access request is compliant or expected information.
[0025] In some embodiments, the network access request described above includes wireless network selection based on the network status information. Specifically, each client node (e.g., IVI, CGM, ADAS, etc. node) can obtain the network type, network connectivity, network latency, network rate, recommended network, etc. from the network status information received from the NAM software module as described above. The client node can send a response message (e.g., confirming the selection of the wireless local area network recommended by the NAM software module) to the NAM software module regarding the wireless network selection. In addition, the client node can also select a wireless network corresponding to the input of the vehicle user according to the input, for example.
[0026] In some embodiments, the network access request described above also includes the application identifier (e.g., string corresponding to the application) of those applications (e.g., one or more applications) requesting access to the network in the application deployed (e.g., installed and run) on each client node and the IP address of each client node.
[0027] In some embodiments, the trust configuration information described above includes a trust list recording the application identifier of the allowed application (e.g., the application allowed to be deployed on the client node) and the allowed IP address (e.g., the static IP address of the predetermined client node).
[0028] In some embodiments, the NAM software module receiving the network access request from the client node can verify whether the network access request received from the client node is a compliant request by determining whether the application identifier of the application requesting access to the network and the IP address of the client node on which the application is located are present in the trust list when verifying the information in the network access request.
[0029] At step 130, after determining that the network access request is verified, a message allowing network access can be sent to the client node to create a data transmission path between the client node and the wireless communication terminal corresponding to the wireless network selection according to the wireless network selection. Specifically, the NAM software module can send a response message allowing network access to the client node sending the network access request after verifying that the network access request received from the client node is a compliant request. The response message can include a differentiated services code point corresponding to the application identifier in some examples, so that, for example, an Ethernet switch can perform prioritized operations based on the value of the differentiated services code point, thereby achieving differentiated services, ensuring the timeliness of critical services in the case of different priorities and quality of service requirements of data packets sent by different applications on different client nodes or data packets sent by different applications on the same client node (for example, these data packets can be added with the differentiated services code point in the response message in the IP header when sent).
[0030] In some embodiments, when a short-range wireless network (for example, a wireless local area network) is selected, the NAM software module can be configured to establish a routing path of the IVI node to the client node allowed to access the network, instructing the client node allowed to access the network (for example, a CGM node) to send data packets via the gateway of the IVI node and through, for example, network address translation to a vehicle external network such as the Internet (if the application in the IVI node is allowed to access the network, its data packets are transmitted through the routing path inside the IVI node). Accordingly, when a long-range wireless network (for example, a cellular network) is selected, the NAM software module can be configured to send the IP address of the client node allowed to access the network to the T-Box communication terminal (the T-Box communication terminal can be instructed by the NAM software module to add the address to the IP address whitelist), and configured to instruct the client node to send its data packets to a vehicle external network (for example, the Internet) via the gateway of the T-Box communication terminal. Thus, the method provides flexible network access for each client node based on real-time network status.
[0031] In some embodiments, to further ensure network security, the NAM software module can instruct the T-Box communication terminal to remove trusted IP addresses added to the IP address whitelist prior to power down or delete the IP address whitelist when the vehicle is powered down (e.g., the in-vehicle network nodes are hibernating or turned off).
[0032] While Figure 1 the steps in the method 1000 are presented and described in a particular order, one skilled in the art will recognize that some or all of the steps in the method 1000 can be performed in a different order, or omitted, and that some or all of the steps in the method 1000 can be performed in parallel, and that additional steps can be performed. Figure 1 Thus, the scope of the present disclosure should not be considered limited to the particular arrangement of steps illustrated in the method 1000.
[0033] Figure 2 is a schematic block diagram of a computer system 200. As shown in Figure 2 the computer system 200 includes at least one memory 210 (e.g., a non-volatile memory such as a flash memory, ROM, hard disk drive, magnetic disk, optical disk, etc.), at least one processor 220, and a computer program 230. The memory 210 stores the computer program 230 that is executable by the processor 220. The processor 220 is configured to execute the computer program 230 stored on the memory 210. By running the computer program stored on the memory or memories on one or more processors (e.g., in a way that multiple processors cooperate to run the computer program or in a way that a single processor runs the computer program alone), one or more steps or operations included in the method 1000 described above with reference to Figure 1 may be implemented.
[0034] According to another aspect of the present application, there is also provided a computer-readable storage medium having instructions stored thereon, which when executed by a processor, can implement one or more steps or operations included in the method 1000 described above with reference to Figure 1 may be implemented.
[0035] According to another aspect of the present application, there is also provided a computer program product including computer instructions, which when executed by a processor, can implement one or more steps or operations included in the method 1000 described above with reference to Figure 1 may be implemented.
[0036] The processor referred to in the present application can be an integrated circuit chip having a signal processing capability. In the implementation process, one or more steps or operations included in the method 1000 described above with reference to Figure 1One or more steps or operations included in the method can be performed by integrated logic circuitry of hardware in the processor or instructions in software form. The processor can be a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components. The general purpose processor can be a microprocessor or the processor can be any conventional processor.
[0037] Computer readable storage media described in the application include various types of computer storage media which can be non-transitory or transitory, and are accessible by a general purpose or special purpose computer. For example, computer readable storage media can include RAM, ROM, EPROM, EEPROM, registers, hard disks, removable disks, CD-ROMs or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other storage medium that can be used to carry or store desired program code means in the form of instructions or data structures and that can be accessed by a general purpose or special purpose computer, or a general-purpose or special-purpose processor. Combinations of the above should also be included within the scope of computer readable storage media. The exemplary storage media is coupled to the processor such the processor can read information from, and write information to, the storage media. In the alternative, the storage media can be integral to the processor.
[0038] The embodiments described herein are intended to be illustrative only and are not intended to limit the scope of the claimed subject matter. Those skilled in the art will readily devise other ways of practicing the claimed subject matter without departing from the scope of the disclosure. Those skilled in the art will appreciate that the description and examples are provided for the purpose of illustration and example only and are not intended to limit the various aspects of the disclosure or the precise form of disclosure presented. The technology recited in the disclosure can be practiced in different ways without departing from the spirit or scope of the disclosure.
Claims
1. A method for network access control, the method comprising: In response to receiving a network status query request from a client node in the vehicle network, network status information corresponding to the network status query request is sent to the client node; Based on the trust configuration information, verify the network access request received from the client node, wherein the network access request includes a wireless network selection based on the network status information; After confirming that the network access request has been verified, a message allowing network access is sent to the client node, and a data transmission path is created between the client node and the wireless communication terminal corresponding to the wireless network selection based on the wireless network selection.
2. The method as described in claim 1, wherein, The network access request also includes: the application identifier of one or more applications that are requesting network access in the applications deployed on the client node, and the IP address of the client node.
3. The method as described in claim 2, wherein, The trust configuration information includes a trust list, which includes the application identifier of the allowed application and the IP address of the allowed client node.
4. The method of claim 3, wherein, Verifying network access requests received from the client node includes: determining whether the application identifier and IP address of the one or more applications exist in the trust list.
5. The method of claim 1, wherein, The wireless network selection includes choosing either a cellular network or a wireless local area network.
6. The method of claim 1, wherein, The client node includes one or more of the following: in-vehicle infotainment system, central gateway module, and advanced driver assistance system.
7. The method of claim 2, wherein, The message allowing network access includes a differential service code point corresponding to the application identifier.
8. A computer system, comprising: At least one memory; At least one processor; as well as A computer program stored in the memory and executable on the processor, the execution of which causes the following operations: In response to receiving a network status query request from a client node in the vehicle network, network status information corresponding to the network status query request is sent to the client node; Based on the trust configuration information, verify the network access request received from the client node, wherein the network access request includes a wireless network selection based on the network status information; After confirming that the network access request has been verified, a message allowing network access is sent to the client node, and a data transmission path is created between the client node and the wireless communication terminal corresponding to the wireless network selection based on the wireless network selection.
9. A computer-readable storage medium storing instructions, characterized in that, When executed by a processor, the instructions cause the method described in any one of claims 1 to 7 to be implemented.
10. A computer program product, the computer program product comprising computer instructions, characterized in that, The computer instructions, when executed by a processor, implement the method as described in any one of claims 1 to 7.