Airborne network equipment management method and system based on hierarchical MAC address

By combining hierarchical MAC addresses and access policy libraries, the problems of complex device management and security risks in airborne networks are solved, enabling efficient device classification and dynamic permission management, and improving network security and compatibility.

CN121841676APending Publication Date: 2026-04-10XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

The lack of structured semantic information in MAC address management in existing airborne networks leads to complex device management, high security risks, and an inability to achieve on-demand access control.

Method used

A hierarchical MAC address structure is adopted, including custom semantic fields, to build an access policy library, and identity authentication and permission matching are performed through the IEEE 802.1X authentication protocol to establish a proactive defense closed loop.

Benefits of technology

It enables efficient classification and accurate identification of devices, reduces management complexity, improves security, and defends against MAC address spoofing and unauthorized device access. It is suitable for resource-constrained embedded devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841676A_ABST
    Figure CN121841676A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of airborne network communication, and provides an airborne network equipment management method and system based on a hierarchical MAC address, and the method comprises the steps: configuring a 48-bit hierarchical MAC address comprising a plurality of customized semantic fields for each piece of network equipment in an airborne network deployment stage; constructing an access strategy library according to the MAC address; when new network equipment is accessed, identity authentication and access permission matching are carried out according to the semantic field in the hierarchical MAC address and the access strategy library; and the original network performs communication control according to the MAC address and the flow table information, continuously monitors the consistency of the MAC address in the subsequent communication process, and triggers a safety response when the MAC address is abnormal. According to the method, automatic authentication and dynamic authorization of context sensing of the equipment can be realized without depending on a certificate or a secret key, MAC (Media Access Control) counterfeiting and illegal equipment access are effectively prevented, and the method is compatible with an IEEE 802.3 standard and is suitable for a high-safety and high-reliability new-generation airborne network environment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of airborne network communication, and relates to a hierarchical MAC address-based airborne network device management method and system, which is suitable for the automatic identity authentication, access permission matching and abnormal behavior monitoring of network devices in the network permission management of avionics systems of civil and military aircrafts. BACKGROUND

[0002] With the continuous progress of aircraft avionics system technology, electronic devices on modern aircrafts are increasingly diverse, covering key functional modules such as flight control, communication navigation, sensors, data processing, etc. These devices are connected to each other through an airborne network to achieve data transmission, information sharing and real-time monitoring. With the proposal of an open architecture for airborne systems, applications and hardware are gradually decoupled, and the deployment, expansion, update and monitoring of containerized applications need to consider device-to-device communication, port mapping and access permissions, etc., significantly increasing the complexity of network management.

[0003] In traditional airborne networks, MAC addresses are allocated by device manufacturers based on organization unique identifiers (OUI) and internal rules, and cannot reflect semantic information such as the region to which the device belongs, the function type or the access permission. This unstructured and contextless identification method makes it difficult for the network to implement unified management according to device categories or application attributes. For example, all subsystem devices use static and homogeneous MAC addresses when accessing the network, which cannot distinguish the differences in access permissions of different airborne applications to network resources, nor can it implement hierarchical access control according to the task criticality level, which is prone to security risks, resource conflicts and configuration errors.

[0004] In the face of the above challenges, an efficient and reliable device identification and management mechanism is urgently needed: not only to ensure the uniqueness of network device addresses, but also to reflect the region, function attributes of network devices through structured semantic information for classification management. For airborne applications of different critical tasks, hierarchical management according to access permissions is also needed to ensure that they can access the corresponding network resources as needed. SUMMARY

[0005] To solve the technical problems of low address space utilization, high conflict risk and complex management in the management of MAC addresses of existing airborne network devices, a hierarchical MAC address-based airborne network device management method is disclosed, which realizes efficient classification, accurate identification and dynamic permission management of devices by constructing a hierarchical MAC address structure. Specifically, the method comprises the following steps: S1. In the deployment stage of the airborne network, a 48-bit hierarchical MAC address is configured for each network device, and the MAC address comprises a plurality of custom semantic fields; S2, constructing an access policy library matching the on-board system architecture and the aircraft safety requirements based on the self-defined semantic field; S3, in the on-board network initialization stage, if any new network device accesses the on-board network, identity authentication and access permission matching are performed based on the self-defined semantic field in the hierarchical MAC address of the new network device and the access policy library, if the authentication is passed and the access permission is successfully matched, corresponding flow table information is generated and delivered to the sensing switch; any original network device in the on-board network automatically parses its hierarchical MAC address, and performs communication control on the device according to the flow table information; S4, according to the access permission matching result, granting or denying the access permission of each network device, and continuously monitoring the consistency of the hierarchical MAC address of each network device in the subsequent communication process, if an abnormality is detected, triggering a security response.

[0006] Further, in step S1, the hierarchical MAC address follows the 48-bit MAC address format of IEEE 802.3 standard, including I / G field, G / L field and multiple self-defined semantic fields; I / G field, as IEEE standard reserved bit, not participating in policy matching, used for identifying unicast or multicast address; G / L field, as IEEE standard reserved bit, not participating in policy matching, used for identifying global or local management address; The self-defined semantic field includes vendor code, network type code, device type code, hardware unique identifier, area location code and interface code, wherein the area location code and the device type code are used for permission matching when the network device accesses or communicates; Wherein, each field is non-overlappingly allocated in the 48-bit address space.

[0007] Further, in step S2, the access policy library is constructed based on at least the area location code and the device type code, the area location code is used to identify the device deployment area, and the device type code is used to identify the device function type.

[0008] Further, the access policy library is constructed and maintained by a network permission controller, the access rules of which are defined in the form of tuples, the tuples including at least two of source area code, destination area code, allowed device type code, network type code and flight phase constraint condition, used for matching the corresponding self-defined semantic field in the hierarchical MAC address of the device when the device accesses.

[0009] Further, the area location code supports dynamic update by management software when the network device state changes, while the hardware unique identifier remains unchanged.

[0010] Further, in step S3, the new network device is authenticated by IEEE802.1X authentication protocol, including: S31, the new network device sends an identity authentication request carrying its hierarchical MAC address to the sensing switch; S32, the sensing switch automatically parses the self-defined semantic field in its hierarchical MAC address and reports it to the network permission controller; S33, the network permission controller compares whether the area to which the current access port belongs is consistent with the device declared area according to the received self-defined semantic field; S34, if they are consistent and the device type code meets the access rules in the access policy library, the access permission authorization process is triggered, otherwise the access is denied.

[0011] Further, in step S4, the consistency of the hierarchical MAC address of each network device is continuously monitored in the subsequent communication process, and if an anomaly is detected, a security response is triggered, including: S41, the sensing switch performs fine-grained communication control according to the flow table information issued by the network permission controller; S42, the hierarchical MAC address of each network device packet is continuously checked in the communication process; S43, if the area code is changed, the field is forged or the field is inconsistent, the security response is triggered immediately and the device port is isolated.

[0012] Further, the security response includes at least one of port isolation, flow table revocation, and security alarm reporting.

[0013] The embodiment of the application also provides an airborne network device management system based on hierarchical MAC address, including an address configuration unit, an access policy management unit, an authentication and permission matching unit, and a security response unit.

[0014] The address configuration unit is configured to configure 48-bit hierarchical MAC addresses for each network device in the airborne network deployment stage, and the MAC address includes a plurality of self-defined semantic fields. The access policy management unit is configured to construct an access policy library matched with the airborne system architecture and the safety requirements of the aircraft based on the self-defined semantic fields. The authentication and permission matching unit is arranged on the network permission controller, and is used for, if any new network device accesses the airborne network in the airborne network initialization stage, carrying out identity authentication and access permission matching based on the self-defined semantic field in the hierarchical MAC address of the new network device and an access strategy library, generating corresponding flow table information if the authentication is passed and the access permission is successfully matched, and delivering the flow table information to the sensing switch; any original network device in the airborne network automatically parses the hierarchical MAC address of the device, and carries out communication control on the device according to the flow table information; The security response unit is arranged on the sensing switch, and is used for granting or denying the access permission of each network device according to the access permission matching result, and continuously monitoring the consistency of the hierarchical MAC address of each network device in the subsequent communication process, and triggering a security response if an exception is detected.

[0015] The method and system can realize efficient classification, accurate identification and dynamic permission management of the network devices according to the attributes such as the belonging area and the function type of the network devices, support dynamic adjustment of the access permission of the network devices, and thus construct a safe and reliable, intelligent and efficient, and highly maintainable new-generation airborne network access control system. 1. The hierarchical MAC address design makes the device identification structure clear, and combines the area position, network type, device type and hardware unique identification code, so that the device management is more efficient, and new area codes can be added as needed to support more airborne areas or task areas as the airborne network expands; Meanwhile, the structured semantic information of the area position code and the device type code embedded in the MAC address is used for access permission matching, identity authentication of the network device is realized without pre-setting a key or a digital certificate, the network device is effectively identified whether to be legal in the current area, and the defense capability against attacks such as MAC address forgery and illegal device access is significantly improved; In addition, the area code and the device type code are combined into the MAC address, the system increases the context complexity of the MAC address, and it is difficult to bypass the network security detection through simple forgery means.

[0016] 2. The flexibility of device management is realized, the identity authentication and communication permission allocation can be automatically completed when a new device accesses, and only the area position code needs to be updated when the belonging area of the device changes, without manually burning the hardware unique identification code or modifying the switch configuration, so that the management complexity and human error risk of the network device are greatly reduced; 3. The 48-bit MAC address format is fully compatible with IEEE 802.3 standard, the I / G and G / L standard bits are reserved for their original meanings, and the network device context information is delivered based on IEEE 802.1X authentication protocol, ensuring seamless integration with existing airborne network management systems; 4. The three-in-one active defense closed loop of "access authentication-operation monitoring-exception response" is constructed: not only the authentication is performed when the device accesses, but also the consistency of the MAC address semantic field is continuously checked during the communication process, once the regional code mutation, field tampering or inconsistency is detected, the security response such as port isolation is triggered immediately, effectively blocking the spread of faults and malicious attacks; 5. The network device does not need to deploy additional security agents, encryption modules or special authentication software, the identity authentication and policy execution are completed by the sensing switch and the network permission controller, which significantly reduces the computing and storage resource overhead of the avionics system terminal, and is suitable for resource-limited embedded devices. BRIEF DESCRIPTION OF DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0018] Figure 1 The flow chart of the airborne network device management method based on hierarchical MAC address of the present application; Figure 2 The architecture diagram of hierarchical MAC address; Figure 3 The network device management process based on hierarchical MAC address; Figure 4 The architecture diagram of the airborne network device management based on hierarchical MAC address of the present application; Among them, 401, address configuration unit; 402, access policy management unit; 403, authentication and permission matching unit; 404, security response unit. DETAILED DESCRIPTION

[0019] The embodiments of the present application will be described in detail below with reference to the drawings.

[0020] Following make the application's implementation through specific concrete example, the person skilled in the art can easily understand the other advantages and efficacy of the application from the disclosure of this specification. Obviously, the described embodiments are only a part of the embodiments of the application, not all the embodiments. The application can also be implemented or applied by another different specific implementation, and the details in the specification can be based on different views and applications, various modifications or changes are made without departing from the spirit of the application. It should be noted that the following embodiments and the features of the embodiments can be combined with each other without conflict. Based on the embodiments in the application, all other embodiments obtained by the person skilled in the art without creative labor are within the scope of protection of the application.

[0021] The embodiment of the application discloses a kind of based on hierarchical MAC address's airborne network equipment management method, refer to Figure 1 And Figure 3 The shown method includes the following steps: S1, in the deployment stage of airborne network, 48-bit hierarchical MAC address is configured for each network equipment, the MAC address includes multiple custom semantic fields; S2, based on the custom semantic field, access policy library that is matched with airborne system architecture and aircraft safety demand is built; S3, in the initialization stage of airborne network, if any new network equipment accesses the airborne network, based on the custom semantic field in the hierarchical MAC address of the new network equipment and access policy library, identity authentication and access permission matching are carried out, if authentication is passed and successfully matched access permission, corresponding flow table information is generated and is issued to sensing switch;Any original network equipment in the airborne network automatically parses its hierarchical MAC address, and the device is controlled according to the flow table information; S4, according to access permission matching result, grant or refuse the access permission of each network equipment, and the consistency of the hierarchical MAC address of each network equipment is continuously monitored in subsequent communication process, if abnormality is detected, security response is triggered.

[0022] In one embodiment, hierarchical MAC address is redivided on the traditional fixed length 48-bit MAC address. The hierarchical MAC address follows IEEE 48-bit Ethernet standard format, as shown in Figure 2 Including I / G field, G / L field and multiple custom semantic fields; I / G field, as IEEE standard reserved bit, does not participate in policy matching, for identifying unicast or multicast address; G / L field, as IEEE standard reserved bit, does not participate in policy matching, for identifying global or local management address; The custom semantic field includes a vendor code, a network type code, a device type code, a hardware unique identifier, a region location code, and an interface code, wherein the region location code and the device type code are used to match the permissions when the network device accesses or communicates. Each field is non-overlappingly allocated in a 48-bit address space.

[0023] More specifically, the hierarchical MAC address partitioning and bit width allocation are shown in Table 1 below: Table 1: Segment Description of Hierarchical MAC Address

[0024] In one embodiment, in step S2, the access policy library is constructed based at least on the region location code and the device type code, the region location code being used to identify the device deployment region, and the device type code being used to identify the device function type.

[0025] Specifically, the region location code is used to divide the onboard devices into several logical regions according to the structure of the aircraft and the task requirements, for example, into a cockpit, a cabin, a cargo hold, etc., each region having a unique region code, and the region being dynamically updated by the management software when the network device state changes, such as device state migration or task change.

[0026] In addition, the access policy library is constructed and maintained by a network permission controller, and the access rules are defined in the form of a tuple, the tuple including at least two of a source region code, a destination region code, an allowed device type code, a network type code, and a flight phase constraint condition, and used to match the corresponding custom semantic field in the hierarchical MAC address of the device when the device accesses.

[0027] In one embodiment, in step S3, the new network device is authenticated through an IEEE 802.1X authentication protocol, including: S31, the new network device sends an identity authentication request carrying its hierarchical MAC address to a sensing switch; S32, the sensing switch automatically parses the custom semantic field in its hierarchical MAC address and reports it to the network permission controller; S33, the network permission controller compares whether the region to which the current access port belongs is consistent with the device declared region according to the received custom semantic field; S34, if they are consistent and the device type code meets the access rules in the access policy library, an access permission authorization process is triggered, otherwise the access is denied.

[0028] In one embodiment, in step S4, consistency of the hierarchical MAC address is continuously monitored in the subsequent communication process, and if an abnormality is detected, a security response is triggered, including: S41, the switch perceives and executes fine-grained communication control according to the flow table information issued by the network permission controller; S42, the hierarchical MAC address of each network device message is continuously checked in the communication process; S43, if the area code change, field forgery or field inconsistency is detected, the security response is triggered immediately and the device port is isolated.

[0029] Further, the security response includes at least one of port isolation, flow table revocation, and security alarm reporting.

[0030] Based on the same inventive concept, the embodiment of the present application also provides a hierarchical MAC address-based airborne network device management system, as described in the following embodiment. Since the principle of solving the problem of the hierarchical MAC address-based airborne network device management system is similar to that of the hierarchical MAC address-based airborne network device management method disclosed in the above embodiment, the implementation of the hierarchical MAC address-based airborne network device management system can be referred to the implementation of the hierarchical MAC address-based airborne network device management method, and the repeated parts will not be described. The term "unit" or "module" used below can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiment is preferably implemented in software, hardware, or a combination of software and hardware is also possible and is conceived.

[0031] Figure 4 is a structural block diagram of the hierarchical MAC address-based airborne network device management system disclosed in the embodiment of the present application, as Figure 4 shown, the system includes an address configuration unit 401, an access policy management unit 402, an authentication and permission matching unit 403, and a security response unit 404, which will be described below.

[0032] Among them, the address configuration unit 401 is used to configure a 48-bit hierarchical MAC address for each network device in the airborne network deployment stage, and the MAC address includes a plurality of custom semantic fields; The access policy management unit 402 is used to construct an access policy library matched with the airborne system architecture and the aircraft safety requirements based on the custom semantic fields; The authentication and permission matching unit 403 is deployed on the network permission controller, and is configured to, in the airborne network initialization stage, perform identity authentication and access permission matching based on the customized semantic field in the hierarchical MAC address of a new network device and an access policy library if the new network device accesses the airborne network, and generate corresponding flow table information and deliver the flow table information to the aware switch if the authentication is passed and the access permission is successfully matched; any original network device in the airborne network automatically parses the hierarchical MAC address of the original network device, and performs communication control on the original network device according to the flow table information. The security response unit 404 is deployed on the aware switch, and is configured to grant or deny the access permission of each network device according to the access permission matching result, and continuously monitor the consistency of the hierarchical MAC address of each network device in the subsequent communication process, and trigger a security response if an abnormality is detected.

[0033] In one embodiment, the access policy management unit is further configured to update the access permission according to the dynamic change of the device area location code and the device type code, and implement dynamic permission management.

[0034] In specific implementation, the network permission controller manages and stores an access policy library of airborne devices, and performs device authentication and dynamic permission allocation according to the customized semantic field of the hierarchical MAC address and the rules in the access policy library, and then generates network flow table information; the aware switch parses the hierarchical MAC address in a network packet, and performs communication control and security isolation based on the flow table information.

[0035] More specifically, the network permission controller updates the access permission according to the dynamic change of the device area location code and the device type code, and implements dynamic permission management. The aware switch interacts with the network device through the IEEE 802.1X protocol, receives the hierarchical MAC address of the network device, parses the customized semantic field in the hierarchical MAC address, and then reports the hierarchical MAC address to the network permission controller; the network permission controller matches the rules in the access policy library according to the received customized semantic field, performs identity authentication and access permission matching, and generates flow table information; the network permission controller and the aware switch work cooperatively, and the flow table information delivered by the network permission controller dynamically checks the device permission and executes a security isolation strategy.

[0036] In one embodiment, the access policy library contains all access rules, and the access policy management unit generates flow table information by matching the customized semantic field in the hierarchical MAC address of the network device with the rules, to restrict the communication permission of the device.

[0037] In specific implementation, the network permission controller divides an airplane into a plurality of security isolation zones, and formulates the following rules for each security isolation zone according to the device type: Rule = [Source location area | Destination location area | Network type / protocol | Allow / deny | Constraint condition (such as device type, flight phase, security level)]; The network permission controller generates access rules according to the airborne system architecture and the aircraft safety requirements, and stores the access rules in an access policy library, so as to generate flow table information subsequently.

[0038] The method and system can realize efficient classification, accurate identification and dynamic permission management of devices according to the attributes of the network devices, such as the area to which the network devices belong and the function type, and support dynamic adjustment of the access permission of the network devices, thereby constructing a new generation of airborne network access control system that is safe and reliable, intelligent and efficient, and highly maintainable. Compared with the prior art, the above at least one technical solution adopted by the embodiments of the present specification can achieve at least the following beneficial effects: 1. Through hierarchical MAC address design, the device identification structure is clear, the area location, network type, device type and hardware unique identification code are combined, so that the device management is more efficient, and with the expansion of the airborne network, new area codes can be added as needed to support more airborne areas or task areas; At the same time, by embedding structured semantic information of "area location code + device type code" in the MAC address for access permission matching, network device identity authentication without preloading keys or digital certificates is realized, effectively identifying whether the network device is legal in the current area, and significantly improving the defense capability against MAC address forgery, illegal device access and other attacks; In addition, by combining the area code and the device type code into the MAC address, the system increases the context complexity of the MAC address, making it difficult to bypass network security detection through simple forgery means.

[0039] 2. Realize the flexibility of device management, when a new device accesses, identity authentication and communication permission allocation can be automatically completed, when the area to which the device belongs changes, only the area location code needs to be updated through the management software, without the need for manual programming of the hardware unique identification code or modifying the switch configuration, greatly reducing the management complexity and human error risk of the network device; 3. Completely compatible with the 48-bit MAC address format of IEEE 802.3 standard, preserving the I / G and G / L standard bit meanings, and delivering network device context information based on IEEE 802.1X authentication protocol, ensuring seamless integration with existing airborne network management systems; 4. Build a "access authentication - operation monitoring - abnormal response" three-in-one active defense closed loop: not only authenticate when the device accesses, but also continuously verify the consistency of the MAC address semantic field during communication, and immediately trigger security responses such as port isolation once the area code mutation, field tampering or inconsistency is detected, effectively blocking the spread of faults and malicious attacks; 5. The network device does not need to deploy additional security agent, encryption module or special authentication software, and the identity authentication and policy execution are completed by the sensing switch and the network permission controller, which significantly reduces the computing and storage resource overhead of the avionics system terminal and is suitable for resource-limited embedded devices.

[0040] In the embodiment, a computer device is provided, which includes a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the above-mentioned any hierarchical MAC address-based airborne network device management method when executing the computer program.

[0041] Specifically, the computer device can be a computer terminal, a server or similar computing device.

[0042] In the embodiment, a computer readable storage medium is provided, which stores a computer program for executing the above-mentioned any hierarchical MAC address-based airborne network device management method.

[0043] Specifically, the computer readable storage medium includes permanent and non-permanent, removable and non-removable media, which can be realized by any method or technology to store information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tape, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, the computer readable storage medium does not include transitory computer readable media such as modulated data signals and carriers.

[0044] Obviously, those skilled in the art should understand that each module or each step of the above-mentioned embodiments of the present application can be realized by a general computing device, which can be centralized on a single computing device or distributed on a network composed of multiple computing devices, and optionally, each module or each step can be realized by program codes executable by a computing device, so that each module or each step can be stored in a storage device and executed by a computing device, and in some cases, the steps shown or described can be executed in different orders, or each module can be manufactured as an individual integrated circuit module, or multiple modules or steps can be manufactured as a single integrated circuit module. Therefore, the embodiments of the present application are not limited to any specific combination of hardware and software.

[0045] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. The embodiments of the present application can be variously changed and modified by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for managing an on-board network device based on hierarchical MAC addresses, characterized in that, The application relates to an access control method for an onboard network, and belongs to the technical field of network security. In the onboard network deployment stage, 48-bit hierarchical MAC addresses are configured for network devices, and the MAC addresses comprise a plurality of custom semantic fields; Based on the custom semantic fields, an access policy library matching the onboard system architecture and the aircraft safety requirements is constructed; In the onboard network initialization stage, if any new network device accesses the onboard network, identity authentication and access permission matching are performed based on the custom semantic fields in the hierarchical MAC address of the new network device and the access policy library; if the authentication is passed and the access permission is successfully matched, corresponding flow table information is generated and is delivered to a sensing switch; any original network device in the onboard network automatically parses the hierarchical MAC address of the device, and communication control of the device is performed according to the flow table information; According to the access permission matching result, access permission of each network device is granted or refused, and consistency of the hierarchical MAC address of each network device is continuously monitored in the subsequent communication process; if an abnormality is detected, a safety response is triggered.

2. The hierarchical MAC address based onboard network device management method according to claim 1, wherein, The hierarchical MAC address follows the 48-bit MAC address format of the IEEE802.3 standard, and comprises an I / G field, a G / L field and a plurality of custom semantic fields; The I / G field is an IEEE standard reserved bit and does not participate in policy matching, and is used for identifying unicast or multicast addresses; The G / L field is an IEEE standard reserved bit and does not participate in policy matching, and is used for identifying global or local management addresses; The custom semantic fields comprise a manufacturer code, a network type code, a device type code, a hardware unique identifier, a region location code and an interface code, wherein the region location code and the device type code are used for permission matching when the network device accesses or communicates; Each field is non-overlappingly allocated in the 48-bit address space.

3. The hierarchical MAC address based onboard network device management method of claim 2, wherein, The access policy library is constructed based on at least the region location code and the device type code, the region location code is used for identifying a device deployment region, and the device type code is used for identifying a device function type.

4. The hierarchical MAC address based onboard network device management method of claim 3, wherein, The access policy library is constructed and maintained by a network permission controller, an access rule of the access policy library is defined in the form of a tuple, the tuple comprises at least two of a source region code, a destination region code, an allowed device type code, a network type code and a flight phase constraint condition, and is used for matching corresponding custom semantic fields in the hierarchical MAC address of the device when the device accesses.

5. The hierarchical MAC address based onboard network device management method of claim 2, wherein, The region location code is dynamically updated by management software when the state of the network device changes, and the hardware unique identifier remains unchanged.

6. The hierarchical MAC address based onboard network device management method of claim 1, wherein, Identity authentication of a new network device is performed through an IEEE802.1X authentication protocol, and the identity authentication comprises the following steps: The new network device sends an identity authentication request carrying the hierarchical MAC address of the new network device to a sensing switch; The sensing switch automatically parses the custom semantic fields in the hierarchical MAC address, and reports the custom semantic fields to a network permission controller; The network permission controller compares whether the region to which a current access port belongs is consistent with a device declared region according to the received custom semantic fields; If the region to which the current access port belongs is consistent with the device declared region and the device type code is consistent with an access rule in the access policy library, an access permission authorization process is triggered, otherwise, access is refused.

7. The hierarchical MAC address based onboard network device management method of claim 1, wherein, The consistency of the hierarchical MAC addresses of the network devices is continuously monitored in the subsequent communication process, and if an abnormality is detected, a security response is triggered, including: The perception switch executes fine-grained communication control according to the flow table information issued by the network authority controller; The hierarchical MAC addresses of the network device messages are continuously checked in the communication process; If the area code changes, the field is forged, or the field is inconsistent, the security response is triggered immediately and the device port is isolated.

8. The hierarchical MAC address based onboard network device management method according to claim 1 or 7, characterized in that, The security response includes at least one of port isolation, flow table revocation, and security alarm reporting.

9. A hierarchical MAC address based on-board network device management system, characterized by, It includes: An address configuration unit configured to configure 48-bit hierarchical MAC addresses for each network device in the airborne network deployment stage, the MAC address including a plurality of custom semantic fields; An access policy management unit configured to construct an access policy library matched with the airborne system architecture and the aircraft safety requirements based on the custom semantic fields; An authentication and permission matching unit deployed on the network authority controller, configured to, in the airborne network initialization stage, if any new network device accesses the airborne network, perform identity authentication and access permission matching based on the custom semantic fields in the hierarchical MAC address of the new network device and the access policy library, and if the authentication is passed and the access permission is successfully matched, generate corresponding flow table information and issue it to the perception switch; any original network device in the airborne network automatically parses its hierarchical MAC address, and performs communication control on the device according to the flow table information; A security response unit deployed on the perception switch, configured to grant or deny the access permission of each network device according to the access permission matching result, and continuously monitor the consistency of the hierarchical MAC addresses of the network devices in the subsequent communication process, and if an abnormality is detected, a security response is triggered.