Data processing method and apparatus, and vehicle
By adopting a packet filtering mechanism when the packet transmission direction is sent and a fast data path mechanism when the reception direction is adopted, the major kernel overhead caused by netfilter is solved, and the firewall performance and system performance are optimized.
Patent Information
- Application Number
- PCT/CN2024/141464
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-09
- Filing Date
- 2024-12-23
- Publication Date
- 2025-07-17
AI Technical Summary
The existing firewall technology in Linux systems is located in the network protocol stack, resulting in high kernel overhead, affecting system performance.
By using a packet filtering mechanism when the transmission direction of the data packet is the transmission direction and a fast data path mechanism when the reception direction is the reception direction, the data packets are avoided from being processed by the network layer, thereby optimizing the firewall performance.
Reduces system overhead and improves firewall efficiency and system performance.
Smart Images

Figure CN2024141464_17072025_PF_FP_ABST
Abstract
Description
Data processing method, device and vehicle
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 9, 2024, with application number 202410035706.5 and application name “Data Processing Method, Device and Vehicle”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of computer technology, and in particular to a data processing method, device, and vehicle. Background Art
[0003] With the rapid development of intelligent and connected vehicles, the Internet of Vehicles (IoV) has played a significant role in improving user experience and promoting smart mobility. However, IoV still faces security vulnerabilities such as data leakage and illegal intrusion, posing an increasingly serious cybersecurity challenge.
[0004] Firewall technology is used to achieve network security. iptables is a command-line tool for configuring the kernel firewall in the Linux operating system. Netfilter processes packets based on the instructions configured by iptables. However, in the iptables and netfilter frameworks, netfilter resides in the kernel's network protocol stack. Processing packets within the network protocol stack, implementing firewall functionality, incurs significant kernel overhead, impacting system performance.
[0005] Therefore, how to reduce overhead and optimize firewall performance has become a technical problem that needs to be solved urgently. Summary of the Invention
[0006] The present application provides a data processing method, device and vehicle that can reduce kernel overhead, optimize firewall performance, improve firewall efficiency and enhance system performance.
[0007] In order to achieve the above objectives, this application provides the following technical solutions:
[0008] In a first aspect, the present application provides a data processing method, which includes: obtaining a data packet; when the transmission direction of the data packet is a sending direction, processing the data packet according to a packet filtering mechanism to implement a firewall function; when the transmission direction of the data packet is a receiving direction, processing the data packet according to a fast data path mechanism to implement a firewall function, when the data packet is processed according to the fast data path mechanism, the data packet is not processed by the network layer.
[0009] In this application, different firewall processing operations are performed based on the transmission direction of the data packet. That is, the firewall function is implemented by processing the data packets in the sending direction according to the packet filtering mechanism, and the data packets in the receiving direction according to the fast data path mechanism. This expands the firewall configuration and management strategies, optimizes the firewall performance, and improves the firewall efficiency. In addition, it reduces system overhead and improves system performance.
[0010] According to a first aspect, the method is applied to a firewall system, the firewall system comprising a kernel layer and a driver layer; the kernel layer comprising a network filter module; and the driver layer comprising a fast data path module. Processing a data packet according to a packet filtering mechanism includes: processing the data packet according to the packet filtering mechanism provided by the network filter module; and processing the data packet according to a fast data path mechanism includes: processing the data packet according to the fast data path mechanism provided by the fast data path module.
[0011] In some examples, a kernel-layer network filter module includes a packet filtering mechanism, and the network filter module is attached to the kernel-layer network layer. When a data packet sent by the system passes through the network layer, the network filter module receives the data packet and processes the data packet according to the matching rules in the packet filtering mechanism to implement firewall functionality.
[0012] In other examples, a fast data path module at the driver layer includes a fast data path mechanism, and the fast data path module is connected to a network interface card (NIC) driver at the driver layer. When a data packet received by the system passes through the NIC driver, the fast data path module obtains the data packet and processes the data packet according to a matching rule in the fast data path mechanism to implement a firewall function.
[0013] In this application, the firewall system configures different functional modules and mechanisms for different data types. Data sent by the system is processed by the network filter module attached to the network layer; data packets received by the system are processed by the fast data path module at the driver layer. In this case, the received data is not processed by the network layer, which can reduce kernel overhead and improve system performance. Moreover, the fast data path module quickly processes the data packets based on the fast data path mechanism, which can accelerate data packet processing efficiency and improve firewall performance.
[0014] According to the first aspect, or any implementation of the first aspect above, the firewall system also includes an application layer and a hardware layer; when the data packet is transmitted from the hardware layer to the driver layer, the transmission direction of the data packet is a receiving direction; when the data packet is transmitted from the application layer to the kernel layer, the transmission direction of the data packet is a sending direction.
[0015] According to the first aspect, or any implementation of the first aspect above, processing the data packet according to the packet filtering mechanism includes: processing the data packet according to a rule matched by the data packet in the packet filtering mechanism.
[0016] In some examples, for a data packet sent by the system, the data packet is matched according to a packet filtering mechanism, a rule matching the data packet is determined, and a corresponding operation is performed on the data packet based on the rule.
[0017] According to the first aspect, or any implementation of the first aspect above, the method further includes: obtaining a first instruction set; the first instruction set includes processing instructions corresponding to data packets in the sending direction; and generating the packet filtering mechanism according to the first instruction set.
[0018] In some examples, a first instruction set is obtained, corresponding rules are parsed based on parameters of each instruction in the first instruction set, and a packet filtering mechanism is generated based on the rules corresponding to the first instruction set.
[0019] In some examples, the instructions in the first instruction set are firewall processing instructions corresponding to data packets with a transmission direction set as a sending direction by a user in a firewall management tool.
[0020] According to the first aspect, or any implementation of the first aspect above, processing the data packet according to the fast data path mechanism includes: processing the data packet according to a rule matched by the data packet in the fast data path mechanism.
[0021] In some examples, for a data packet received by the system, a matching rule for the data packet is determined according to a fast data path mechanism, and a corresponding operation is performed on the data packet based on the rule.
[0022] According to the first aspect, or any implementation of the first aspect above, the method also includes: obtaining a second instruction set; the second instruction set includes processing instructions corresponding to data packets in the receiving direction; determining a third instruction set based on the second instruction set, the third instruction set including fast data path instructions corresponding to each instruction in the second instruction set; generating the fast data path mechanism based on the third instruction set.
[0023] In some examples, the instructions in the second instruction set are firewall processing instructions corresponding to data packets with a transmission direction set to receive, as configured by a user in a firewall management tool. The third instruction set includes fast data path instructions corresponding to each instruction in the second instruction set. Fast data path instructions are instructions that can be recognized by the fast data path framework.
[0024] In some examples, a second instruction set is obtained, and the second instruction set is converted into a third instruction set according to a preset rule.
[0025] In some examples, the preset rules include packet filtering rules and packet processing rules.
[0026] In some examples, corresponding rules are parsed based on parameters of each instruction in the third instruction set, and a packet filtering mechanism is generated based on the rules corresponding to the third instruction set.
[0027] In other examples, the third instruction set is converted into a fast data path program, and a fast data path mechanism is generated according to the fast data path program.
[0028] In this application, the format of each instruction in the second instruction set is converted, and each instruction in the converted third instruction set can process data packets on the fast data path framework to implement firewall functions. In addition, configuration rules for fast data path instructions are designed to improve the versatility of fast data path instruction configuration and broaden the use scenarios of the fast data path framework. This application configures fast data path instructions based on the original firewall instructions. The configured fast data path instructions have good usability and improve firewall performance.
[0029] According to the first aspect, or any implementation of the first aspect above, the application layer includes a firewall management tool, and the method also includes: parsing the instructions provided by the firewall management tool to obtain a first instruction set and a second instruction set; the first instruction set includes processing instructions corresponding to data packets in the sending direction; the second instruction set includes processing instructions corresponding to data packets in the receiving direction.
[0030] In some examples, the instructions provided by the firewall management tool are parsed according to the transmission direction of the data packet indicated by each instruction to obtain the first instruction set and the second instruction set.
[0031] In some examples, the transmission direction of the data packet indicated by each instruction is determined according to a rule chain, and the instructions provided by the firewall management tool are parsed to obtain a first instruction set and a second instruction set.
[0032] In this application, the firewall instructions are parsed into a first instruction set and a second instruction set according to the transmission direction of the data packet indicated by each instruction provided by the firewall management tool, so that different configurations can be performed according to the parsed instruction sets, thereby accelerating the firewall processing efficiency and optimizing the firewall performance.
[0033] In a second aspect, the present application provides a firewall system. The firewall system includes: a first acquisition module for acquiring data packets in a sending direction; a first processing module for processing the data packets in the sending direction according to a packet filtering mechanism to implement a firewall function; a second acquisition module for acquiring data packets in a receiving direction; and a second processing module for processing the data packets in the receiving direction according to a fast data path mechanism to implement a firewall function. When the data packets in the receiving direction are processed according to the fast data path mechanism, the data packets in the receiving direction are not processed by the network layer.
[0034] In a third aspect, the present application provides a firewall device, comprising: a processor and a memory, the memory being coupled to the processor, the memory being used to store computer-readable instructions, and when the processor reads the computer-readable instructions from the memory, the firewall device executes the method of the first aspect and any one of the embodiments of the first aspect.
[0035] In a fourth aspect, the present application provides a vehicle comprising the firewall system as described in the second aspect or the firewall device as described in the third aspect.
[0036] Exemplary vehicles include cars, trucks, motorcycles, buses, lawn mowers, recreational vehicles, amusement park vehicles, construction equipment, trams, golf carts, trains, etc., which are not particularly limited in this application. The power of the above-mentioned vehicles can be provided by gasoline, diesel, electricity, solar energy, or hydrogen energy.
[0037] In a fifth aspect, the present application provides a chip system comprising at least one processor and at least one interface circuit, wherein the at least one interface circuit is used to perform transceiver functions, and the at least one processor is used to execute the method of the first aspect and any one of the embodiments of the first aspect.
[0038] In a sixth aspect, the present application provides a computer-readable storage medium, which includes a computer program. When the computer program runs on a computer, the computer executes the method of the first aspect and any one of the embodiments of the first aspect.
[0039] The technical effects corresponding to the second to sixth aspects and any implementation method of each aspect can be referred to the technical effects corresponding to the above-mentioned first aspect and any implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] FIG1 is a schematic diagram of a firewall system architecture provided by an embodiment of the present application;
[0041] FIG2 is a schematic diagram of a data packet processing architecture provided in an embodiment of the present application;
[0042] FIG3A is a schematic diagram of another firewall system architecture provided in an embodiment of the present application;
[0043] FIG3B is a schematic diagram of another firewall system architecture provided in an embodiment of the present application;
[0044] FIG4 is a schematic diagram of the hardware structure of a firewall device provided in an embodiment of the present application;
[0045] FIG5 is a schematic diagram of a vehicle structure provided in an embodiment of the present application;
[0046] FIG6 is a flow chart of a firewall configuration method provided in an embodiment of the present application;
[0047] FIG7 is a flow chart of a data processing method provided in an embodiment of the present application;
[0048] FIG8 is a schematic structural diagram of a chip system provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in this article is merely a way to describe the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0050] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the quantity of the technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include one or more of the features.
[0051] In the description of the embodiments of the present application, unless otherwise specified, "multiple" means two or more. In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way.
[0052] In some examples, Linux systems often use iptables and netfilter to implement firewall functionality. Iptables resides at the application layer. Users can configure and manage firewall commands and provide firewall rules or policies through the command-line tools provided by iptables. Iptables is also used to transmit configured commands to netfilter, which then generates rules to process packets based on the commands. Netfilter is a module within the kernel responsible for processing packets (such as filtering, modifying, or forwarding) according to preconfigured rules as they pass through the network protocol stack. In other words, users issue commands through iptables, and netfilter generates rules based on the commands. It then executes the corresponding actions to process packets, thus protecting the Linux system.
[0053] Among them, iptables generates instructions for processing data packets through tables and chains to achieve firewall functions.
[0054] Tables usually include the following: raw table, which is used to set protocol-level instructions and is responsible for removing the connection tracking mechanism on the data packet; mangle table, which is responsible for data packet disassembly, modification and other functions; nat table, which is responsible for the network address translation function of the data packet; filter table, which is responsible for the basic filtering function of the data packet.
[0055] Chains usually include the following: PREROUTING, which limits the input data before entering the local system from the network interface, and is used to process data packets before entering the local system, and is suitable for modifying the destination address, destination network address translation, etc.; INPUT, which limits the input data arriving at the local system, and is used to process data packets entering the local system; FORWARD, which limits the forwarding data forwarded through the local system, and is used to process data packets forwarded to other systems through the local system; OUTPUT, which limits the output data sent from the local system, and is used to process data packets generated and output by the local system; POSTROUTING, which limits the output data before leaving the local system, and is used to process data packets before leaving the local system, and is suitable for modifying the source address, realizing source network address translation, etc.
[0056] For example, Figure 1 shows a schematic diagram of a Linux system firewall architecture provided by an embodiment of the present application. As shown in Figure 1, the Linux system may include a user layer, a kernel layer, a driver layer, and a hardware layer.
[0057] The user layer includes applications and firewall management tools (i.e., iptables). The kernel layer includes the kernel interface, transport layer, network layer, firewall management tool kernel module, and network filter module (i.e., netfilter). Furthermore, the network filter module is attached to the network layer. The driver layer includes the network card driver. The hardware layer includes the network card device.
[0058] Before Linux implemented firewall functionality, users configured firewall instructions in the firewall management tool. The firewall management tool then sent these instructions to the firewall management tool's kernel module through a kernel interface. The kernel module then sent these instructions to the network filter module. The network filter module then generated firewall rules based on these instructions. When the system subsequently sent or received data packets, the network filter module processed them according to these rules, thus implementing the firewall functionality.
[0059] In one possible implementation, when a Linux system sends a data packet, the application sends the packet to the kernel interface of the kernel layer through a system call. The packet then passes through the transport layer to the network layer. Once the packet reaches the network layer, the network filter module attached to the network layer receives the packet, processes it, and sends it to the network layer. The network layer then sends the processed packet to the network card driver, which then outputs it through the network card device.
[0060] It is understandable that the network filter module in the system processes data packets according to the firewall rules that the data packets match, which means that corresponding operations are performed on the data packets according to the specific processing methods contained in the firewall rules. For example, if the network filter module determines that the method for processing data packets in the firewall rules that the data packets match is modification, the modified data packets are transmitted in the above-mentioned manner. If the network filter module determines that the method for processing data packets in the firewall rules that the data packets match is discarding, the data packet is discarded without performing subsequent transmission operations. If the network filter module determines that the method for processing data packets in the firewall rules that the data packets match is forwarding, the data packet is forwarded according to the information in the processing method. The embodiments of the present application do not limit the specific implementation method of processing data packets according to firewall rules.
[0061] In another possible implementation, when a Linux system receives a data packet, the network card driver receives the packet from the network card device and sends it to the network layer. Once the packet reaches the network layer, a network filter module attached to the network layer receives the packet, processes it, and sends it to the network layer. The network layer then sends the processed packet to the application via the transport layer and kernel interface.
[0062] However, in the above example, the network filter module is attached to the network layer in the network protocol stack. Data needs to pass through the network layer before being processed by the network filter module. The kernel overhead is large, affecting the firewall efficiency, data packet processing efficiency and system performance.
[0063] In other examples, the Linux system also includes an express data path (XDP) to process data packets through the XDP framework.
[0064] For example, Figure 2 shows a schematic diagram of a Linux system data packet processing architecture provided by an embodiment of the present application. As shown in Figure 2, the Linux system may include a user layer, a kernel layer, a driver layer, and a hardware layer.
[0065] The user layer includes application programs. The kernel layer includes the fast data path protocol module and the network protocol stack, which includes the transport layer and the network layer. The driver layer includes the fast data path module and the network card driver. The fast data path module is connected to the network card driver. The hardware layer includes the network card device.
[0066] In one possible implementation, the packet processing process is as follows: the network card device receives a packet and sends it to the network card driver. The network card driver receives the packet, processes it, and sends the processed packet to the network protocol stack. The processed packet is parsed and processed by the network layer and transport layer of the network protocol stack before being sent to the application.
[0067] In another possible implementation, the XDP framework processes data packets as follows: a network interface card (NIC) receives a data packet and sends it to the NIC driver. Once the data packet reaches the NIC driver, the fast data path module attached to the NIC driver retrieves the data packet, parses it layer by layer, and processes it.
[0068] Optionally, the XDP framework can process data packets in the following ways: XDP_PASS, which passes the data packet to the network protocol stack for processing; XDP_TX, which sends the data packet directly; XDP_DROP, which discards the data packet; and XDP_REDIRECT, which sends the data packet to the user program through the fast data path protocol module.
[0069] In the above example, each time the NIC driver receives a packet, the fast data path module attached to the NIC driver processes the packet, performing operations such as filtering, forwarding, or discarding. While the XDP framework improves packet processing efficiency, it cannot guarantee packet security.
[0070] In order to solve the technical problems described above, an embodiment of the present application provides a data processing method. The method includes: obtaining a data packet; when the transmission direction of the data packet is the sending direction, processing the data packet according to a packet filtering mechanism to implement a firewall function; when the transmission direction of the data packet is the receiving direction, processing the data packet according to a fast data path mechanism to implement a firewall function, when the data packet is processed according to the fast data path mechanism, the data packet is not processed by the network layer. The method provided by the embodiment of the present application optimizes firewall performance, improves firewall efficiency, reduces system overhead, and improves system performance.
[0071] The data processing method in the embodiments of the present application can be applied to application scenarios that implement firewall functions, such as network boundary protection, access control, application security, sending or receiving data, and other scenarios. The data processing method in the embodiments of the present application can be applied to various devices that use firewalls, and firewalls are used to protect the network security of devices. Various devices can include various means of transportation such as new energy vehicles, electric vehicles, buses, and cars. They can also include various electronic devices such as mobile phones, tablet computers, personal computers (PCs), wearable devices, etc. The embodiments of the present application do not place special restrictions on the specific form of the device. The embodiments of the present application do not place special restrictions on the application scenarios and types of firewalls.
[0072] For example, referring to Figure 3A, Figure 3A shows a schematic diagram of the architecture of a firewall system 30 provided in an embodiment of the present application. As shown in Figure 3A, the firewall system 30 may include a user layer, a kernel layer, a driver layer, and a hardware layer.
[0073] The user layer includes the application, the firewall management tool (i.e., iptables), the parsing module, the first instruction module, and the second instruction module. The kernel layer includes the kernel interface, the transport layer, the network layer, the firewall management tool kernel module, the network filter module (i.e., netfilter), the configuration module, and the fast data path protocol module. The network filter module is attached to the network layer. The driver layer includes the network card driver and the fast data path module. The fast data path module is attached to the network card driver. The hardware layer includes the network card device.
[0074] In an embodiment of the present application, before implementing the firewall function, the user configures the firewall instructions in the firewall management tool so that the system implements the firewall function according to the firewall instructions.
[0075] The firewall management tool is used to provide instructions for configuring and managing the firewall. These instructions can be instructions for the firewall to process packets in the outgoing direction or instructions for the firewall to process packets in the incoming direction. The embodiments of this application do not limit the number or specific content of the instructions configured by the firewall management tool.
[0076] The firewall management tool is also used to provide instructions to the parsing module. In other words, the firewall management tool is also used to send the configured instructions to the parsing module. Alternatively, the parsing module obtains the configured instructions from the firewall management tool.
[0077] The parsing module is configured to parse instructions provided by the firewall management tool to obtain a first instruction set and a second instruction set. The first instruction set includes processing instructions corresponding to data packets transmitted in a sending direction, and the second instruction set includes processing instructions corresponding to data packets transmitted in a receiving direction.
[0078] The parsing module is further configured to send the first instruction set to the first instruction module, and send the second instruction set to the second instruction module.
[0079] The first instruction module is used to obtain a first instruction set and is further used to send the first instruction set to the firewall management tool kernel module through a kernel interface.
[0080] The firewall management tool kernel module is used to send the first instruction set to the network filter module.
[0081] The network filter module is configured to generate a packet filtering mechanism based on a first instruction set. The packet filtering mechanism includes rules corresponding to each instruction in the first instruction set. When a data packet sent by the system passes through the network layer, the network filter module obtains the data packet and processes the data packet based on the rules matched by the data packet in the packet filtering mechanism to implement a firewall function.
[0082] The second instruction module is used to obtain a second instruction set. The second instruction module is also used to determine a third instruction set based on the second instruction set. The third instruction set includes a fast data path instruction corresponding to each instruction in the second instruction set.
[0083] It is understood that by changing the format of each second instruction in the second instruction set, the iptables instruction is configured as an XDP instruction so that the XDP framework can recognize the XDP instruction and perform corresponding processing according to the XDP instruction. This only changes the instruction format, and does not change the meaning of the instruction or the corresponding processing behavior.
[0084] The second instruction module is further configured to send the third instruction set to the configuration module.
[0085] The configuration module is configured to generate a fast data path mechanism based on the third instruction set. The fast data path mechanism includes rules corresponding to each instruction in the third instruction set. The configuration module is further configured to send the fast data path mechanism to the fast data path module.
[0086] The fast data path module is used to access the fast data path mechanism. When a data packet received by the system passes through the network card driver, the fast data path module obtains the packet and processes it according to the rules matched by the packet in the fast data path mechanism to implement firewall functions. Furthermore, when the data packet is processed according to the fast data path mechanism, it has not yet been processed by the network layer. In other words, before the data packet is transmitted to the network layer, it is processed by the fast data path mechanism at the driver layer, accelerating data packet processing efficiency.
[0087] The above examples illustrate how to configure the firewall, with different processing methods configured for packets in different transmission directions. For outgoing packets, the firewall is implemented using the packet filtering mechanism in Netfilter; for incoming packets, the firewall is implemented using the fast data path mechanism in the XDP framework.
[0088] It is understood that the fast data path mechanism in the fast data path module in FIG3A is generated based on the converted firewall instructions and can implement firewall functions. The fast data path module in FIG2 is only used to quickly process data packets. The fast data path module in FIG3A of the present embodiment can also implement firewall functions while quickly processing data packets.
[0089] The following uses sending or receiving data as an example to illustrate the specific implementation of the firewall function.
[0090] In one possible implementation, when the system sends a data packet, the application sends the packet to the kernel interface of the kernel layer through a system call. The packet then passes through the transport layer to the network layer. Once the packet reaches the network layer, a network filter module attached to the network layer receives the packet and processes it based on the matching rules within the packet filtering mechanism. If the packet continues to be sent, the network filter module returns the processed packet to the network layer. The network layer then sends the processed packet to the network card driver, which then sends the processed packet to the network card device.
[0091] In another possible implementation, when the system receives a data packet, the network card driver receives the data packet from the network card device, the fast data path module attached to the network card driver obtains the data packet, and processes the data packet according to the data packet matching rules in the fast data path mechanism provided by the fast data path module.
[0092] Optionally, the fast data path mechanism processes the packet based on the rules it matches. The fast data path mechanism can handle packets in the following ways: XDP_PASS, which passes the packet to the network filter module; XDP_TX, which transmits the packet directly; XDP_DROP, which discards the packet; and XDP_REDIRECT, which sends the packet to the user program via the fast data path protocol module.
[0093] It is understood that in the above example, each module in the firewall system 30 is an independent component, and the modules exchange data to complete the firewall function. In actual application, multiple modules in the firewall system 30 can be deployed on the same component to jointly implement the firewall function.
[0094] The modules in the firewall system described above are divided according to functional logic, but other divisions are possible. Furthermore, the modules may be named differently. Furthermore, each module may be implemented in hardware, software, or a combination of hardware and software. Whether a particular module is implemented in hardware, software, or a combination of hardware and software depends on the specific application and design constraints of the technical solution. Different modules may be implemented in different hardware, and multiple modules may be implemented in the same hardware; this is not specifically limited in the present embodiments.
[0095] For example, referring to Figure 3B, Figure 3B shows a schematic diagram of the architecture of another firewall system 31 provided in an embodiment of the present application. As shown in Figure 3B, the firewall system 31 may include a first acquisition module, a first processing module, a second acquisition module, and a second processing module.
[0096] The first acquisition module is used to acquire data packets in the sending direction.
[0097] The first processing module is used for processing the data packets in the sending direction according to the packet filtering mechanism to realize the firewall function. The first processing module includes a pre-configured packet filtering mechanism.
[0098] The second acquisition module is used to acquire data packets in the receiving direction.
[0099] The second processing module is configured to process the data packets in the receiving direction according to a fast data path mechanism to implement a firewall function. When the data packets in the receiving direction are processed according to the fast data path mechanism, the data packets in the receiving direction are not processed by the network layer. The second processing module includes the fast data path mechanism.
[0100] It is understandable that the firewall system 30 and the firewall system 31 in the above examples are possible system architectures of the firewall system. The embodiments of the present application do not limit the specific implementation of the system architecture of the firewall system.
[0101] It can be understood that the system architecture and business scenarios described in this application are intended to more clearly illustrate the technical solutions of this application, and do not constitute the sole limitation on the technical solutions provided by this application. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by this application are also applicable to similar technical problems.
[0102] Refer to FIG. 4 , which shows a hardware structure of a firewall device 40 provided in an embodiment of the present application.
[0103] As shown in FIG4 , the firewall device 40 includes a processor 41 , a memory 42 , a communication interface 43 , and a bus 44 . The processor 41 , the memory 42 , and the communication interface 43 may be connected via the bus 44 .
[0104] The processor 41 is used to manage and control the firewall device 40 and / or to execute the data processing method described below. The memory 42 is used to store program code and data of the firewall device 40. The communication interface 43 is used to support communication between the firewall device 40 and other network entities.
[0105] The processor 41 (or controller) is the control center of the firewall device 40 and can implement or execute the various exemplary logic blocks, unit modules, and circuits described in conjunction with the disclosure of this application. The processor or controller can be a general-purpose central processing unit (CPU), a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array (FPGA), or other programmable logic device, a transistor logic device (TLD), a hardware component, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor. The processor 41 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, or a combination of a digital signal processor and a microprocessor.
[0106] As an example, the processor 41 may include one or more CPUs, such as CPU 0 and CPU 1 shown in FIG. 4 .
[0107] The memory 42 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or a flash memory, a hard disk or a solid-state drive; it can also be an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory 42 can also include a combination of the above-mentioned types of memories. In one possible implementation, the memory 42 can exist independently of the processor 41. The memory 42 can be connected to the processor 41 via a bus 44 for storing data, instructions or program codes. When the processor 41 calls and executes the instructions or program codes stored in the memory 42, the data processing method provided in the embodiment of the present application can be implemented.
[0108] In another possible implementation, the memory 42 may also be integrated with the processor 41 .
[0109] Communication interface 43 is used to connect firewall device 40 to other devices via a communication network. The communication network can be a transceiver circuit, Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc. Communication interface 43 can include a receiving unit for receiving data and a sending unit for sending data.
[0110] Bus 44 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. This bus can be classified as an address bus, a data bus, a control bus, etc. For ease of illustration, FIG4 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.
[0111] It should be noted that the structure shown in FIG4 does not constitute a limitation on the firewall device 40. In addition to the components shown in FIG4, the firewall device 40 may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0112] FIG5 is a schematic diagram of the structure of a vehicle 500 provided in an embodiment of the present application. Referring to FIG5 , vehicle 500 may include various subsystems, such as a travel system 510, a sensor system 520, a control system 530, one or more peripheral devices 540, a power supply 550, a computer system 560, and a user interface 570. Optionally, vehicle 500 may include more or fewer subsystems, and each subsystem may include multiple components. Furthermore, each subsystem and component of vehicle 500 may be interconnected via wired or wireless connections.
[0113] Propulsion system 510 may include components that provide powered motion for vehicle 500. Engine 511 may be an electric motor or other types of engine combinations. Engine 511 converts energy source 512 into mechanical energy. Examples of energy source 512 include solar panels, batteries, and other sources of electricity. Transmission 513 may transmit mechanical power from engine 511 to wheels 514.
[0114] The sensor system 520 may include a number of sensors that sense information about the environment surrounding the vehicle 500. For example, the sensor system 520 may include a positioning system 521, such as a global positioning system (GPS), a BeiDou system, or other positioning systems, an inertial measurement unit (IMU) 522, a radar 523, a laser rangefinder 524, and a camera 525.
[0115] Control system 530 controls the operation of vehicle 500 and its components. Control system 530 may include various components, including a steering system 531, a throttle 532, a brake unit 533, a computer vision system 534, a path control system 535, and an obstacle avoidance system 536, which may also be referred to as an obstacle avoidance system.
[0116] Vehicle 500 interacts with external sensors, other vehicles, other computer systems, or users via peripheral devices 540. Peripheral devices 540 may include a wireless communication system 541, an onboard computer 542, a microphone 543, and / or a speaker 544.
[0117] Power source 550 may provide power to various components of vehicle 500 .
[0118] Some or all functions of vehicle 500 are controlled by computer system 560. Computer system 560 may include at least one processor 561 that executes instructions 5621 stored in a non-transitory computer-readable medium, such as memory 562. Computer system 560 may also be a plurality of computing devices that control individual components or subsystems of vehicle 500 in a distributed manner.
[0119] The processor 561 may be any conventional processor, such as a commercially available central processing unit (CPU). Alternatively, the processor may be a dedicated device such as an application-specific integrated circuit (ASIC) or other hardware-based processor.
[0120] In some embodiments, memory 562 may include instructions 5621 (e.g., program logic) that are executable by processor 561 to perform various functions of vehicle 500. Memory 562 may also include additional instructions, including instructions for sending data to, receiving data from, interacting with, and / or controlling one or more of travel system 510, sensor system 520, control system 530, and peripherals 540.
[0121] In addition to instructions 5621, memory 562 may also store data such as road maps, route information, the vehicle's location, direction, speed, and other vehicle data, and other information. This information may be used by vehicle 500 and computer system 560 during operation of vehicle 500 in autonomous, semi-autonomous, and / or manual modes.
[0122] The user interface 570 is used to provide information to or receive information from a user of the vehicle 500 .
[0123] Computer system 560 may control functions of vehicle 500 based on input received from various subsystems (eg, travel system 510 , sensor system 520 , and control system 530 ) and from user interface 570 .
[0124] In some embodiments, the vehicle 500 may also include a vehicle controller (not shown in FIG. 5 ), which can also be described as a powertrain controller and is the core control component of the entire vehicle. It collects input information from various systems and components, makes corresponding judgments based on the input information, and then controls the operation of various components in the vehicle 500 to drive the vehicle 500. Specifically, as the command and management center of the vehicle 500, the main functions of the vehicle controller include: drive torque control, optimized control of braking energy, energy management of the entire vehicle, maintenance and management of the controller area network (CAN), fault diagnosis and handling, and vehicle status monitoring. It plays a role in controlling vehicle operation. Therefore, the quality of the vehicle controller directly determines the stability and safety of the vehicle.
[0125] Alternatively, one or more of the above components may be installed or associated separately from the vehicle 500. For example, the memory 562 may be partially or completely separate from the vehicle 500. The above components may be communicatively coupled together in a wired and / or wireless manner.
[0126] Optionally, the above components are only an example. In actual applications, the components in the above modules may be added or deleted according to actual needs. Figure 5 should not be understood as a limitation on the embodiments of the present application.
[0127] The vehicle 500 may be a new energy vehicle, an electric vehicle, a car, a truck, a motorcycle, a bus, a boat, an airplane, a helicopter, a lawn mower, an amusement vehicle, an amusement park vehicle, construction equipment, a tram, a golf cart, or a train, etc., and is not particularly limited in this embodiment of the present application. The vehicle may be powered by gasoline, diesel, electricity, solar energy, hydrogen energy, etc.
[0128] In other embodiments of the present application, the vehicle may further include hardware structures and / or software modules to implement the aforementioned functions in the form of hardware structures, software modules, or a combination of hardware structures and software modules. Whether a particular one of the aforementioned functions is implemented in the form of hardware structures, software modules, or a combination of hardware structures and software modules depends on the specific application and design constraints of the technical solution.
[0129] The method provided in the embodiments of the present application is described below with reference to the accompanying drawings.
[0130] To optimize firewall performance and reduce system overhead, this application proposes a data processing method. This method can be executed by a vehicle or other device outside the vehicle, such as a mobile phone, computer, or other electronic device. Alternatively, it can be a processor on the vehicle or other device outside the vehicle, such as processor 41 or processor 561 mentioned above. Before processing data, this application also requires configuring the firewall.
[0131] The present application embodiment is introduced by taking a new energy vehicle as an example. Referring to FIG6 , FIG6 shows a flowchart of a firewall configuration method provided by the present application embodiment. The firewall configuration method includes the following steps S601-S605:
[0132] S601: The vehicle controller obtains a command from the firewall.
[0133] In the embodiments of the present application, the vehicle controller can be a core control component of the vehicle, such as an onboard system (IMS) on the vehicle. The IMS can connect to the network to implement intelligent functions. To ensure network security when the IMS connects to the network, the IMS is configured with a firewall to protect the IMS from unauthorized access and malicious attacks.
[0134] In a possible implementation, the vehicle controller obtains a firewall instruction set by the user.
[0135] Optionally, the vehicle controller includes a firewall management tool (i.e., iptables), which provides instructions for configuring and managing the firewall. For example, the firewall management tool provides a command line interface, where a user sets firewall instructions (i.e., iptables instructions) to provide filtering rules or policies for the firewall. The vehicle controller receives the firewall instructions in response to the user's operation to set the firewall instructions.
[0136] S602: The vehicle controller parses the instructions of the firewall to obtain a first instruction set and a second instruction set.
[0137] It's understood that the VCU interacts with the network, sending and receiving data packets. Therefore, when configuring firewall instructions, corresponding instructions can be configured for packets entering and leaving the VCU, allowing the firewall to filter and control access.
[0138] In an embodiment of the present application, the vehicle controller parses the instructions of the firewall according to the transmission direction of the data packet indicated by each instruction in the instructions of the firewall to obtain the first instruction set and the second instruction set.
[0139] The first instruction set includes processing instructions corresponding to data packets whose transmission direction is a sending direction, and the second instruction set includes processing instructions corresponding to data packets whose transmission direction is a receiving direction.
[0140] In a possible implementation, the vehicle controller determines the transmission direction of the data packet indicated by each instruction according to the rule chain, parses the instructions of the firewall, and obtains the first instruction set and the second instruction set.
[0141] Optionally, the firewall instruction is generated according to a firewall management tool (ie, iptables). The generated firewall instruction complies with the configuration rules of iptables, and the transmission direction of the data packet indicated by the instruction can be determined through the rule chain in the instruction.
[0142] In some examples, PREROUTING, INPUT, and FORWARD in the iptables rule chain are used to limit input data. That is, the transmission direction of the data packet indicated by the instructions containing the above rule chain is the receive direction (receive, RX). And POSTROUTING and OUTPUT in the iptables rule chain are used to limit output data. That is, the transmission direction of the data packet indicated by the instructions containing the above rule chain is the transmit direction (transmit, TX). The instructions containing PREROUTING, INPUT, and FORWARD are merged into a first instruction set, and the instructions containing POSTROUTING and OUTPUT are merged into a second instruction set.
[0143] For example, the firewall instructions set by the user in iptables include the following instructions:
[0144] "iptable-A INPUT-s 10.0.0.5-j DROP;
[0145] iptable-t nat-A PREROUTING-i eth0-p tcp-dport 80-j DNAT--to-destination192.168.10.6:13400;
[0146] iptable-t nat-A POSTROUTING-s 192.168.1.100–j SNAT–to-source 192.168.2.100”.
[0147] In the example above, the first command, "iptable -A INPUT -s 10.0.0.5 -j DROP," means that if the local system receives a packet with a source address of 10.0.0.5, it should drop the packet. This command specifies that the rule chain is INPUT, specifically, it means to drop a received packet. Therefore, this command specifies that the packet should be transmitted in the receive direction.
[0148] In the above example, the second command, "iptable -t nat -A PREROUTING -i eth0 -p tcp-dport 80 -j DNAT --to-destination 192.168.10.6:13400," translates the destination address. For TCP packets arriving at the local system from interface eth0 with destination port 80, the destination address is changed to 192.168.10.6, and the destination port is changed to 13400. This command specifies the PREROUTING rule chain, which specifically changes the destination address of received packets. Therefore, this command specifies the receiving direction for packets.
[0149] In the above example, the third command, "iptable -t nat -A POSTROUTING -s 192.168.1.100 -j SNAT --to-source 192.168.2.100," modifies the source network address of packets leaving the local system from 192.168.1.100 to 192.168.2.100. This command specifies the rule chain to be POSTROUTING, specifically changing the source network address of packets being sent from the local system. Therefore, this command specifies the outbound direction for packets.
[0150] Based on the above example, it can be determined that the first instruction set includes "iptable-t nat-A POSTROUTING-s 192.168.1.100-j SNAT--to-source 192.168.2.100"; the second instruction set includes "iptable-A INPUT-s 10.0.0.5-j DROP" and "iptable-t nat-A PREROUTING-i eth0-p tcp-dport 80-j DNAT--to-destination 192.168.10.6:13400".
[0151] In this application, the vehicle controller parses the firewall instructions into a first instruction set and a second instruction set according to the transmission direction of the data packet indicated by each instruction of the firewall, so as to perform different configurations according to the parsed instruction sets, speed up the firewall processing efficiency, and optimize the firewall performance.
[0152] After step S602, the vehicle controller may execute step S603 according to the first instruction set obtained after parsing; the vehicle controller may also execute steps S604-S605 according to the second instruction set obtained after parsing.
[0153] S603: The vehicle controller obtains a first instruction set and generates a packet filtering mechanism according to the first instruction set.
[0154] In an embodiment of the present application, the vehicle controller also includes a network filter module (also known as netfilter). The network filter module obtains a first instruction set, parses corresponding rules based on the parameters of each instruction in the first instruction set, and generates a packet filtering mechanism based on the rules corresponding to the first instruction set.
[0155] For example, Netfilter obtains a first instruction set, determines the rules corresponding to the first instruction set, and integrates these rules into a series of hook functions to generate a packet filtering mechanism. Netfilter is attached to the network layer. When a data packet sent by the system passes through the network layer, Netfilter matches the packet, determines the rules that the packet matches, and performs corresponding actions on the packet based on the rules, such as dropping, modifying, or forwarding the packet, thereby implementing firewall functions.
[0156] Based on the example of S602 above, the first instruction set includes "iptable -t nat -A POSTROUTING -s 192.168.1.100 –j SNAT –to-source 192.168.2.100". The vehicle controller sends this first instruction set to netfilter, which generates a packet filtering mechanism based on this first instruction set. This allows the local system to modify the source network address of data packets with a source network address of 192.168.1.100 to 192.168.2.100 before sending the data packets.
[0157] In this application, the above method is used to complete the firewall function configuration when the system sends data packets, and configure the packet filtering mechanism for the firewall. When the system subsequently sends data packets, the packets are processed according to the configured packet filtering mechanism to realize the firewall function and improve system security.
[0158] S604: The vehicle controller obtains the second instruction set and determines a third instruction set based on the second instruction set.
[0159] In an embodiment of the present application, the third instruction set includes fast data path instructions corresponding to each instruction in the second instruction set.
[0160] In the embodiment of the present application, the fast data path instruction is an instruction that can be recognized by the XDP framework. The fast data path instruction includes a filtering instruction and / or a processing behavior.
[0161] In an embodiment of the present application, the vehicle controller also includes an XDP framework, which can obtain data packets received by the local system at the network card driver and quickly process the data packets. Therefore, in an embodiment of the present application, the XDP framework is configured with a corresponding firewall function, and the XDP framework is used to process the data packets received by the local system to implement the firewall function. That is, in an embodiment of the present application, the firewall function is implemented by the packet filtering mechanism for data packets whose transmission direction is the sending direction; and the firewall function is implemented by the XDP framework for data packets whose transmission direction is the receiving direction.
[0162] In an embodiment of the present application, the vehicle controller obtains the second instruction set and converts the second instruction set into a third instruction set according to preset rules.
[0163] Optionally, the preset rules include packet filtering rules and packet processing rules. That is, the iptables instructions in the second instruction set are converted into XDP instructions that can be recognized by the XDP framework according to the preset rules, so as to complete the filtering and processing of the received data through the XDP framework.
[0164] For example, the preset rule is: xdp filter[XXX]set[XXX][YYY]. In the preset rule, xdp filter is an instruction for configuring the XDP filter to filter and process packets. The first [XXX] is the field of the packet in the packet filtering rule. The set instruction is used to set the processing behavior. The second [XXX] is the value to be set for the field of the filtered packet. The first [XXX] and second [XXX] can indicate different fields. [YYY] is the specific processing behavior in the packet processing rule.
[0165] For example, the fields of the data packet represented by the first [XXX] and the second [XXX] include the following: network card device name (device), source physical address (source media access control address, smac), destination physical address (destination media access control address, dmac), virtual local area network ID (vlanid), virtual local area network priority (vlanpri), Ethernet type (ethertype), source IP address (source IP address, src_ip), destination IP address (destination IP address, dst_ip), protocol (protocol) (protocols include address resolution protocol (ARP), internet control message protocol (ICMP), user datagram protocol (UDP), transmission control protocol (TCP), network protocol (IP) and internet protocol version 4 (IPv4), etc.), destination port number (destination port number), and the like. number, dport), transport layer destination port number (layer4 destination port number, l4_dport), source port number (source port number, sport), and transport layer source port number (layer4 source port number, l4_sport), etc.
[0166] For example, the processing actions represented by [YYY] include the following: drop, discarding the data packet; pass, transferring the data packet to the network filter module; redirect, forwarding the data packet to the user program; tx, sending the data packet directly from the network card device.
[0167] Based on the example of S602 above, the second instruction set includes “iptable -A INPUT -s 10.0.0.5 -j DROP” and “iptable -t nat -A PREROUTING -i eth0 -p tcp-dport 80 -j DNAT --to-destination 192.168.10.6:13400”.
[0168] According to the preset rules, "iptable -A INPUT -s 10.0.0.5 -j DROP" is translated into "xdp filter src_ip=10.0.0.5set drop." This command targets the XDP framework and sets a filter on the XDP framework for all packets with a source IP address of 10.0.0.5. This filter directly drops the packets and prevents them from being passed to other processing logic on the local system. In other words, an XDP filter is set to drop specific types of packets.
[0169] According to the preset rules, "iptables -t nat -A PREROUTING -i eth0 -p tcp-dport 80 -j DNAT --to-destination 192.168.10.6:13400" is translated into "xdp filter device = etho and protocol = tcp and 14_dport = 80 set pass and dst_ip = 192.168.10.6 and 14_dport = 13400." This command targets the XDP framework. For TCP packets received from interface eth0 with destination port 80, the destination network address is modified to 192.168.10.6 and the destination port to 13400. The packets are then passed to other processing logic on the local system. This sets an XDP filter, allowing only specific types of packets to pass through and forwarding them to other processing logic for further processing.
[0170] That is, the converted third instruction set includes "xdp filter src_ip=10.0.0.5 set drop" and "xdp filter device=etho and protocol=tcp and 14_dport=80 set pass and dst_ip=192.168.10.6 and 14_dport=13400".
[0171] In this application, the format of each instruction in the second instruction set is converted, and each instruction in the converted third instruction set can process data packets on the XDP framework to implement firewall functions. When the system receives data, the data packets can be quickly processed through the XDP framework, which can speed up the data processing rate and improve firewall performance. In addition, configuration rules for fast data path instructions are designed to improve the versatility of XDP instruction configuration and broaden the use scenarios of the XDP framework. Based on the original iptables instruction configuration, the fast data path instructions after configuration have better usability and are conducive to improving firewall performance.
[0172] S605: The vehicle controller generates a fast data path mechanism according to the third instruction set.
[0173] In an embodiment of the present application, the vehicle controller parses the corresponding rules based on the parameters of each instruction in the third instruction set, and generates a packet filtering mechanism based on the rules corresponding to the third instruction set.
[0174] In an embodiment of the present application, the vehicle controller converts the third instruction set into a fast data path program and generates a fast data path mechanism according to the fast data path program.
[0175] In some embodiments of the present application, the vehicle controller includes a fast data path program template corresponding to each field in the data packet and each processing behavior of the data packet. For example, a fast data path program template is pre-set for the pass behavior, and a corresponding fast data path program template is pre-set for each protocol.
[0176] In one possible implementation, for each fast data path instruction in the third instruction set, the vehicle controller configures the XDP preconfigured program corresponding to the instruction based on the fields and processing behavior contained in the instruction. Thus, each fast data path instruction has its own corresponding XDP preconfigured program. The vehicle controller then combines the XDP preconfigured programs corresponding to each fast data path instruction in the third instruction set to obtain the fast data path program corresponding to the third instruction set. Finally, based on the fast data path program, the corresponding rules are parsed and a fast data path mechanism is generated based on the rules.
[0177] Illustratively, based on the example of S604 above, the third instruction set includes “xdp filter src_ip=10.0.0.5 set drop” and “xdp filter device=etho and protocol=tcp and 14_dport=80 set pass and dst_ip=192.168.10.6 and 14_dport=13400”.
[0178] The "xdp filter src_ip=10.0.0.5 set drop" command contains the "src_ip" field and the "drop" action. Therefore, the vehicle controller configures the XDP preconfigured program 1 corresponding to "xdp filter src_ip=10.0.0.5 set drop" based on the fast data path program templates corresponding to "src_ip" and "drop." The "xdp filter device=eth0 and protocol=tcp and14_dport=80 set pass and dst_ip=192.168.10.6 and 14_dport=13400" command contains the "device," "protocol," "14_dport," and "dst_ip" fields, and the "pass" action. Therefore, the vehicle controller configures the fast data path program templates corresponding to "device," "protocol," "14_dport," "dst_ip," and "pass" to generate XDP preconfigured program 2, corresponding to "xdp filter device = etho and protocol = tcp and 14_dport = 80, set pass and dst_ip = 192.168.10.6 and 14_dport = 13400." The vehicle controller then combines XDP preconfigured program 1 and XDP preconfigured program 2 to generate fast data path program A, corresponding to the third instruction set. The vehicle controller generates a fast data path mechanism based on fast data path program A, configures this fast data path mechanism into a fast data path module, and attaches the fast data path module to the network interface card driver. When a data packet received by the system passes through the network interface card driver, the fast data path module obtains the packet, determines a matching rule based on the fast data path mechanism, and performs corresponding actions on the packet based on the matching rule, such as forwarding, discarding, or modifying, thereby implementing firewall functionality.
[0179] In this application, the above method is used to complete the firewall's functional configuration when the system receives data packets, and configure the firewall with a fast data path mechanism. When the system subsequently receives data packets, it processes the received data according to the configured fast data path mechanism, realizing the firewall function and improving security.
[0180] It is understood that the above example illustrates how to configure the firewall function. The following details how to process data based on the configured firewall.
[0181] 7 , which shows a flow chart of a data processing method according to an embodiment of the present application, the data processing method includes the following steps S701 - S703 :
[0182] S701: The vehicle controller obtains a data packet.
[0183] In an embodiment of the present application, the vehicle controller includes a firewall system, which includes an application layer, a kernel layer, a driver layer and a hardware layer.
[0184] In a possible implementation, the data packet acquired by the vehicle controller is a data packet sent to the vehicle controller by other devices or networks.
[0185] In another possible implementation, the data packet acquired by the vehicle controller is a data packet generated by the vehicle controller itself, and the vehicle controller sends the data packet to other devices or networks.
[0186] In some examples, when a data packet is transmitted from the hardware layer to the driver layer, the transmission direction of the data packet is a receiving direction.
[0187] In other examples, when a data packet is transmitted from the application layer to the kernel layer, the transmission direction of the data packet is a sending direction.
[0188] S702: When the transmission direction of the data packet is the sending direction, the vehicle controller processes the data packet according to the packet filtering mechanism to implement a firewall function.
[0189] In an embodiment of the present application, the kernel layer in the firewall system of the vehicle controller includes a network filter module (ie, netfilter).
[0190] In a possible implementation, the vehicle controller processes the data packet according to a packet filtering mechanism, including: the vehicle controller processes the data packet according to the packet filtering mechanism provided by a network filter module.
[0191] It can be understood that the network filter module in the embodiment of the present application includes a packet filtering mechanism configured based on the firewall configuration method shown in Figure 6 above.
[0192] In another possible implementation, the vehicle controller processes the data packet according to a packet filtering mechanism, including: the vehicle controller processes the data packet according to a rule matched by the data packet in the packet filtering mechanism.
[0193] For example, based on the above example of S603, if the source IP address of the data packet to be sent by the vehicle controller is 192.168.1.100, the vehicle controller determines that the rule matching the data packet in the packet filtering mechanism is the rule corresponding to the instruction "iptable-t nat-A POSTROUTING-s 192.168.1.100-j SNAT--to-source 192.168.2.100", then the source network address of the data packet is modified to 192.168.2.100, and then the data packet is sent.
[0194] S703. When the transmission direction of the data packet is the receiving direction, the vehicle controller processes the data packet according to the fast data path mechanism to implement the firewall function. When the data packet is processed according to the fast data path mechanism, the data packet is not processed by the network layer.
[0195] In an embodiment of the present application, the driver layer in the firewall system of the vehicle controller includes a fast data path module.
[0196] In a possible implementation, the vehicle controller processes the data packet according to a fast data path mechanism, including: the vehicle controller processes the data packet according to the fast data path mechanism provided by the fast data path module.
[0197] It is understood that after the system receives a data packet, it is first processed by the fast data path mechanism of the driver layer. At this point, the data packet is not processed by the network layer. In this application, the fast data path mechanism can quickly process the data packet in the early stage of receiving the data packet to implement the firewall function, which can reduce system overhead and optimize firewall efficiency and performance.
[0198] It can be understood that the fast data path module in the embodiment of the present application includes a fast data path mechanism configured based on the firewall configuration method shown in Figure 6 above.
[0199] In another possible implementation, the vehicle controller processes the data packet according to a fast data path mechanism, including: the vehicle controller processes the data packet according to a rule matched by the data packet in the fast data path mechanism.
[0200] Exemplarily, based on the above example of S605, if the source IP address of the data packet received by the vehicle controller is 10.0.0.5, the vehicle controller determines that the rule matched by the data packet in the fast data path mechanism is the rule corresponding to the instruction "xdp filter src_ip=10.0.0.5set drop", then the data packet is discarded.
[0201] In this application, the firewall system framework includes iptables, netfilter, and XDP. Data received by the system can be quickly processed by the fast data path mechanism at the driver layer, and data sent by the system can be processed by the packet filtering mechanism at the network layer, effectively improving firewall performance.
[0202] Through the above process, the vehicle controller in the embodiment of the present application performs different firewall processing operations on the acquired data packets according to the transmission direction of the data packets. When the data packet transmission direction is the sending direction, the vehicle controller processes the data packet according to the packet filtering mechanism to implement the firewall function; when the data packet transmission direction is the receiving direction, the vehicle controller processes the data packet according to the fast data path mechanism to implement the firewall function, and when the data packet is processed according to the fast data path mechanism, the data packet is not processed by the network layer. The solution of the embodiment of the present application performs different firewall processing operations according to the transmission direction of the data packet, expands the firewall framework and firewall configuration and management strategies, optimizes firewall performance, improves firewall efficiency, reduces system overhead, and improves system performance.
[0203] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of method. In order to realize the above functions, it includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily appreciate that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0204] An embodiment of the present application also provides a chip system, as shown in Figure 8, the chip system 800 includes at least one processor 801 and at least one interface circuit 802. As an example, when the chip system 800 includes one processor and one interface circuit, the one processor may be the processor 801 shown in the solid box in Figure 8 (or the processor 801 shown in the dotted box), and the one interface circuit may be the interface circuit 802 shown in the solid box in Figure 8 (or the interface circuit 802 shown in the dotted box). When the chip system 800 includes two processors and two interface circuits, the two processors include the processor 801 shown in the solid box in Figure 8 and the processor 801 shown in the dotted box, and the two interface circuits include the interface circuit 802 shown in the solid box in Figure 8 and the interface circuit 802 shown in the dotted box. This is not limited.
[0205] The processor 801 and the interface circuit 802 can be interconnected via a line. For example, the interface circuit 802 can be used to receive signals. For another example, the interface circuit 802 can be used to send signals to other devices (such as the processor 801). For example, the interface circuit 802 can read instructions stored in a memory and send the instructions to the processor 801. When the instructions are executed by the processor 801, the firewall device can execute the various steps in the above embodiment. Of course, the chip system can also include other discrete components, which are not specifically limited in the embodiments of the present application.
[0206] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application-specific integrated circuit (ASIC), a system on a chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chip.
[0207] It should be understood that each step in the above method embodiment can be completed by hardware integrated logic circuits in a processor or by software instructions. The method steps disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware processor, or by a combination of hardware and software modules in a processor.
[0208] An embodiment of the present application further provides a computer-readable storage medium storing one or more computer programs, wherein the one or more computer programs include instructions that, when executed by a computer, enable the computer to execute the corresponding process of the data processing method in the above embodiment.
[0209] In some embodiments, the disclosed methods may be implemented as computer program instructions encoded in a machine-readable format on a computer-readable storage medium or on other non-transitory media or articles of manufacture.
[0210] An embodiment of the present application further provides a computer program product. When the computer program product is run on a computer, the computer is caused to execute the above-mentioned related steps to implement the data processing method in the above-mentioned embodiment.
[0211] The apparatus, computer-readable storage medium, computer program product, or chip provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods provided above, and will not be repeated here.
[0212] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A data processing method, characterized in that, The method includes: Obtaining a data packet; When the transmission direction of the data packet is the sending direction, processing the data packet according to a packet filtering mechanism to implement a firewall function; When the transmission direction of the data packet is the receiving direction, processing the data packet according to a fast data path mechanism to implement a firewall function. When processing the data packet according to the fast data path mechanism, the data packet does not undergo network layer processing.
2. The method according to claim 1, characterized in that, The method is applied to a firewall system, which includes a kernel layer and a driver layer; the kernel layer includes a network filter module; the driver layer includes a fast data path module; Processing the data packet according to the packet filtering mechanism includes: Processing the data packet according to the packet filtering mechanism provided by the network filter module; Processing the data packet according to the fast data path mechanism includes: Processing the data packet according to the fast data path mechanism provided by the fast data path module.
3. The method according to claim 2, wherein The firewall system further includes an application layer and a hardware layer; When the data packet is transmitted from the hardware layer to the driver layer, the transmission direction of the data packet is the receiving direction; When the data packet is transmitted from the application layer to the kernel layer, the transmission direction of the data packet is the sending direction.
4. The method according to any one of claims 1 to 3, characterized in that, Processing the data packet according to the packet filtering mechanism includes: Processing the data packet according to the rule matched by the data packet in the packet filtering mechanism.
5. The method according to claim 4, wherein The method further includes: Obtaining a first instruction set; the first instruction set includes processing instructions corresponding to data packets in the sending direction; Generating the packet filtering mechanism according to the first instruction set.
6. The method according to any one of claims 1 to 3, characterized in that, Processing the data packet according to the fast data path mechanism includes: Processing the data packet according to the rule matched by the data packet in the fast data path mechanism.
7. The method according to claim 6, wherein The method further includes: Obtaining a second instruction set; the second instruction set includes processing instructions corresponding to data packets in the receiving direction; Determining a third instruction set according to the second instruction set, where the third instruction set includes fast data path instructions corresponding to each instruction in the second instruction set; Generating the fast data path mechanism according to the third instruction set.
8. The method according to claim 3, characterized in that, The application layer includes a firewall management tool, and the method further includes: Parsing the instructions provided by the firewall management tool to obtain a first instruction set and a second instruction set; the first instruction set includes processing instructions corresponding to data packets in the sending direction; the second instruction set includes processing instructions corresponding to data packets in the receiving direction.
9. A firewall system, characterized in that, Includes: A first obtaining module, configured to obtain data packets in the sending direction; A first processing module, configured to process the data packets in the sending direction according to a packet filtering mechanism to implement a firewall function; A second obtaining model, configured to obtain data packets in the receiving direction; A second processing module, configured to process the data packets in the receiving direction according to a fast data path mechanism to implement a firewall function. When processing the data packets in the receiving direction according to the fast data path mechanism, the data packets in the receiving direction do not undergo network layer processing.
10. A firewall device, characterized in that, Includes: A processor and a memory, the memory being coupled to the processor, the memory being configured to store computer-readable instructions, and when the processor reads the computer-readable instructions from the memory, causing the firewall device to execute the method according to any one of claims 1-8.
11. A vehicle, characterized in that, The vehicle includes the firewall system according to claim 9 or the firewall device according to claim 10.
12. A chip system, characterized in that, Comprising at least one processor and at least one interface circuit, the at least one interface circuit being configured to perform transceiver functions, and the at least one processor being configured to execute the method according to any one of claims 1-8.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a computer program, and when the computer program runs on a computer, causing the computer to execute the method according to any one of claims 1-8.
Citation Information
Patent Citations
Processing method and device for data in Linux system
CN109660535A
Data filtering method and device and computer readable medium
CN115883255A
Vehicle-mounted firewall function implementation method, device and equipment and readable storage medium
CN116743464A
Data processing method and device and vehicle
CN118054935A
Vehicular firewall providing device
US20210297388A1