Apparatus and method for executing network diagnostic program
By designing a device including a diagnostic testing device and a diagnostic control device in the automotive network, the problem of message-based protocol network communication fault detection in modern cars is solved, and the reliability and security of network communication are realized.
Patent Information
- Application Number
- CN202411603575.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-11-11
- Publication Date
- 2025-06-13
AI Technical Summary
The message-based protocol network in modern cars is prone to failure or temporary interruption during communication, resulting in unpredictable side effects and affecting the safety of the car. The prior art is difficult to detect potential failures before communication failures occur.
An apparatus is designed, including a diagnostic testing device and a diagnostic control device, for executing a network diagnostic program in a multi-node message-based protocol network. The device ensures the reliability of network communication by receiving diagnostic requests and responses, comparing message identifiers, and performing diagnostic tests using test patterns when matching.
The ability to detect potential failures in automotive networks is realized, ensuring the reliability and security of communications is ensured, and the risks brought about by communication failures are reduced.
Smart Images

Figure CN120151235A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a device and an associated method for performing network diagnostic procedures within a message-based protocol network. Background Art
[0002] Many modern systems require a network with multiple nodes. For example, modern vehicles are equipped with many electronic components for different functions. These modules are typically connected via networks such as Controller Area Network (CAN), Local Interconnect Network (LIN), or Ethernet. Each function within a vehicle is typically implemented by multiple components that exchange data via the network. For example, an electric power steering module requires accurate information about, for example, the steering angle, steering torque, and speed of the vehicle. In addition, many of these functions are related to the safety of the vehicle. Due to the increasing number of modules and functions within modern vehicle designs, the requirements for safety and reliability within the network are also increasing. A fault or a short interruption during communication can lead to unpredictable side effects that may affect the safety of the vehicle. To ensure that the communication works reliably throughout the lifespan of the vehicle, an appropriate diagnostic system is used that detects potential faults, ideally before a communication fault occurs. Summary of the Invention
[0003] According to a first aspect of the present disclosure, there is provided a device configured to perform a network diagnostic procedure within a message-based protocol network including a plurality of nodes, the device comprising:
[0004] diagnostic test means configured to perform diagnostic tests; and
[0005] diagnostic control means, wherein, to perform the network diagnostic procedure, the diagnostic control means is configured to:
[0006] receive a diagnostic request from a commander node, wherein the diagnostic request is directed to a target node and wherein the diagnostic request includes a first message identifier;
[0007] compare the first message identifier with a predetermined diagnostic identifier;
[0008] receive a diagnostic response from the target node, wherein the diagnostic response includes a second message identifier and a test pattern; and
[0009] compare the second message identifier with a predetermined diagnostic identifier;
[0010] if the first message identifier and the second message identifier are the same as the predetermined diagnostic identifier, then:
[0011] use the diagnostic test means to perform a diagnostic test using the test pattern.
[0012] In one or more embodiments, the diagnostic test is an interference diagnostic test.
[0013] In one or more embodiments, the interference diagnostic test is configured to interfere with other signals in the message-based protocol network.
[0014] In one or more embodiments, the message-based protocol network is a Controller Area Network (CAN), and the CAN includes a first bus wire and a second bus wire coupled to each node within the network.
[0015] In one or more embodiments, the diagnostic control device is configured to receive the diagnostic request from the transmit data (TXD) pin of the commander node. The diagnostic control device may be configured to receive the diagnostic response from the receive data (RXD) pin of the commander node.
[0016] In one or more embodiments, the diagnostic control device further includes a timer, wherein the diagnostic control device is configured to start the timer in response to receiving the diagnostic request. The diagnostic control device may be configured to terminate the network diagnostic procedure if the diagnostic response is not received within a predetermined time period starting from when the diagnostic control device starts the timer.
[0017] In one or more embodiments, the diagnostic control device is configured to terminate the network diagnostic procedure when:
[0018] the first message identifier is not the same as the predetermined diagnostic identifier; and / or
[0019] the second message identifier is not the same as the predetermined diagnostic identifier.
[0020] In one or more embodiments, the diagnostic control device is configured to terminate the network diagnostic procedure if the test pattern is not the same as a predetermined test pattern.
[0021] In one or more embodiments, the predetermined test pattern is hard-coded.
[0022] In one or more embodiments, the diagnostic response includes a header and a payload. The test pattern may be included in the payload of the diagnostic response.
[0023] In one or more embodiments, the predetermined diagnostic identifier is hard-coded.
[0024] In one or more embodiments, the device is configured to sequentially perform diagnostic tests for each node in the message-based protocol network.
[0025] According to a second aspect of the present disclosure, there is provided a method for performing a network diagnostic procedure within a message-based protocol network, the method comprising:
[0026] Receiving a diagnostic request from a commander node, wherein the diagnostic request is also directed to a target node, and wherein the diagnostic request includes a first message identifier;
[0027] Receiving a diagnostic response from the target node, wherein the diagnostic response includes a second message identifier and a predetermined test pattern;
[0028] Comparing the first message identifier and the second message identifier with a predetermined diagnostic identifier;
[0029] If the first message identifier and the second message identifier are the same as the predetermined diagnostic identifier, performing a diagnostic test on the predetermined test pattern using a diagnostic test device; and
[0030] If the first message identifier and the second message identifier are not the same as the predetermined diagnostic identifier, terminating the network diagnostic procedure.
[0031] Although the present disclosure admits of various modifications and alternative forms, details thereof have been shown by way of example in the drawings and will be described in detail. However, it should be understood that other embodiments beyond the specific embodiments described are also possible. All modifications, equivalents, and alternative embodiments falling within the spirit and scope of the appended claims are also covered.
[0032] The foregoing discussion is not intended to represent every example embodiment or every implementation within the scope of the current or future claim sets. The following figures and detailed description also illustrate various example embodiments. The various example embodiments can be more fully understood by considering the following detailed description in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] One or more embodiments will now be described by way of example only with reference to the accompanying drawings, in which:
[0034] Figure 1 An example embodiment showing an example of a CAN network;
[0035] Figure 2 An example CAN network is shown, which is used to describe a method for locating a fault within the network;
[0036] Figure 3 An example interference diagnostic test message according to an embodiment of the present disclosure is shown;
[0037] Figure 4Shows a network according to an embodiment of the present disclosure, which can perform interference diagnosis tests when the network is active;
[0038] Figure 5 Shows the structure of a network diagnostic device according to an embodiment of the present disclosure;
[0039] Figure 6 Shows a flowchart of a method for executing a diagnostic test program according to an embodiment of the present disclosure;
[0040] Figure 7 Shows a flowchart outlining overall network diagnosis according to an embodiment of the present disclosure;
[0041] Figure 8 Shows an example device that can be used to implement a network diagnostic program in a CAN network according to an embodiment of the present disclosure;
[0042] Figure 9 Shows an example structure for diagnostic responses that can be used in a CAN network according to an embodiment of the present disclosure; and
[0043] Figure 10 Shows that can be used Figure 8 Examples of interference diagnosis tests performed in a CAN network using a diagnostic test device. Detailed Description
[0044] Figure 1 Shows an example of a CAN network 100. In Figure 1 there are a plurality of nodes 101 connected to the CAN bus 102. The CAN bus 102 includes two wires, namely CAN High (CANH) and CAN Low (CANL). Using CANH and CANL, the nodes 101 within the CAN network 100 can send and receive differential signals by sending different voltages along each wire of the CAN bus 102, thereby generating differential signals that can be interpreted by other nodes 101. This particular CAN structure 100 includes two star points 103. The star points 103 are used to reduce the complexity of the bus 102 required to connect each node 101 in the network 100 to each other node 101.
[0045] Each node 101 within the CAN network 100 includes a transceiver, which includes a transmitter 104 and a receiver 105. The transmitter 104 sends signals to the bus 102, and the receiver 105 receives signals from the bus 102. Each node 101 is connected to a host controller (not shown) by means of a transmit data (TXD) pin 106 and a receive data (RXD) pin 107. The TXD pin 106 is used to provide signals for the transmitter 104 to send, and the RXD pin 107 is used to provide the data received by the receiver 105 to the host controller (not shown).
[0046] Multiple faults may occur within the network of a CAN network 100 as described, for example, Figure 1 in Figure 1 . For example, the network wires may short circuit to ground, or the wires may break. These faults may cause errors in the CAN network 100. Therefore, it may be beneficial for the network to introduce fault detection and diagnostic techniques to be equipped to mitigate these risks. To repair a fault, it may be necessary to locate the position of the fault within the network.
[0047] Figure 2 FIG. shows an example CAN network 200 that can be used to describe a method for locating a fault within the network 200. In this example, the initiator node 201a has initiated a diagnostic test program to detect and locate an impedance fault 208 within the network 200. The initiator node 201a performs diagnostic tests sequentially with each other node 201b (responder node 201b) within the network 200. In this example, each diagnostic test measures the impedance of the network 200 in the path between the initiator node 201a and the corresponding responder node 201b, ignoring all other connections of the network 200 outside of this path. As a result of the diagnostic test, the initiator node 201a receives impedance test measurement results 209 of each responder node 201b that has been tested. Once each impedance test measurement result 209 has been received, a host controller (not shown) corresponding to the initiator node 201a is able to compare the impedance test measurement results 209 with each other to detect and locate the fault 208. Depending on the network topology, one or more faults 208 can be detected simultaneously within the network 200.
[0048] In this example, the fault 208 is located between two star points 203. Therefore, the impedances of the responder nodes 201b connected to the first star point 203 (SP1) will be equal to each other, and the impedances of the responder nodes 201b connected to the second star point 203 (SP2) will be equal to each other. The two sets of equal impedances are different from each other, so the fault 208 (which causes a change in impedance on the bus) must be located between the two star points 203. The magnitude of the impedance difference caused by the fault 208 can also be determined by evaluating the impedance difference between the two sets. Therefore, both the severity and the location of the fault 208 can be determined.
[0049] Generally speaking, two types of diagnostic systems can be distinguished: non-intrusive systems and intrusive systems. Non-intrusive systems allow measurements to be made without compromising communication. Measurements made by intrusive systems affect communication or even completely disrupt communication.
[0050] The interference-free diagnostic system allows continuous monitoring of the network during operation (e.g., the operation of a vehicle); that is, continuous monitoring of the network while active communication is in progress. This allows the interference-free diagnostic method to detect faults as soon as possible. However, certain types of faults cannot be detected using these methods. For example, a short circuit from a network wire to ground can be easily detected, but a break in the wire is difficult to detect.
[0051] Interference diagnostic systems can generally detect more faults because they do not need to avoid damaging other signals that are currently being transmitted on the network. However, using interference diagnostic systems is not without risks. For example, when a vehicle is in motion, trouble-free communication must be carried out. When interference measurement is desired in a vehicle network, the manufacturer must ensure that these interference diagnostic systems are not accidentally activated because these tests may have an impact on network communication. Applying interference measurement can be even more difficult when the measurement process requires the cooperation of more than one module because these modules may be manufactured by different companies, which may make it more difficult to ensure that all modules work perfectly together. Therefore, interference measurement is generally only feasible in special test modes that are applied in a safe environment such as a garage or when the vehicle is parked. The disadvantage of such test modes is that transient faults that are only visible during operation cannot be captured. Such faults can include fluttering contacts (i.e., electrical contacts that may occasionally disconnect, especially when the vehicle is in motion), which cause communication faults during vehicle movement, or temperature effects that only occur when the vehicle has reached its operating temperature.
[0052] Another difficulty regarding interference diagnostic systems is that the diagnostic systems may be deliberately misused. Modern vehicles are usually connected to the Internet to provide functions such as over-the-air (OTA) updates. Such vehicles are gradually becoming targets for hackers who may try to maliciously misuse the available functions. Interference diagnostic systems can be a huge risk for vehicle manufacturers because if hackers find a way to activate the interference diagnostic systems outside of the required operating conditions, these systems may disrupt the entire network communication.
[0053] One or more examples of the present disclosure relate to a way of inserting interference diagnostic messages into an operating communication network and securely isolating the interference diagnostic messages from regular messages. Thus, the examples disclosed herein can allow the application of interference diagnostic techniques during the operation of a vehicle (or other device), and thus can expand the range of detectable problems. For example, potential faults that may have been caused by corrosion or aging effects can be discovered. As will be discussed below, this can be achieved by using specific hardware for the nodes that perform diagnostic measurements. The specific hardware can implement security measures to ensure that the diagnostic hardware is only synchronously activated with the appropriate section of the test message. Regular messages can be protected by the hardware from being erroneously distorted. The security measures also reduce the likelihood of hackers accessing the diagnostic system to attack network communication.
[0054] Although the present disclosure mainly discusses applications within the CAN network of an automobile, it should be understood that the techniques disclosed herein can also be applied to other types of message-based communication protocols and different network applications.
[0055] To perform interference diagnostic testing, as will be discussed below, it is beneficial to use appropriate test messages. The payload of a test message can be divided into two parts. The first part contains a message identifier for identifying a diagnostic message, and the second part consists of a test pattern for use by diagnostic hardware for diagnostic measurements. This message identifier can be supplementary to any standard identification information that is typically found in the header of the communication protocol under discussion.
[0056] Figure 3 An example interference diagnostic test message 310 according to an embodiment of the present disclosure is shown. Depending on the particular message-based protocol network being used, the diagnostic test message 310 includes a header 311, a payload 312, and a message end component 313. Generally, the header 311 contains identification information about the message, the payload 312 contains message data, and the message end component 313 indicates the end of the message.
[0057] The diagnostic test message 310 according to an embodiment of the present disclosure further includes a message identifier 314 and a test pattern 315 within its payload 312. The message identifier 314 is a predetermined pattern that can be recognized by hardware (which is described below in the context of CAN with reference to Figure 4 and 5 to identify the message as the diagnostic test message 310. The test pattern 315 is another predetermined pattern that can be used to perform an interference diagnostic test. In this example, the test pattern 315 does not carry information.
[0058] Figure 4 A network 400 according to an embodiment of the present disclosure is shown, which can perform interference diagnostic testing when the network 400 is active. Figure 4 The message-based protocol network shown in Figure 1 is a CAN network 400 similar to the CAN network described in Figure 4 In Figure 4as shown in), or may be located outside its associated node 401. The network diagnostic device 420 is connected to the TXD pin 406 and the RXD pin 407 of its associated node 401 such that the network diagnostic device can process the signals provided to these pins. The network diagnostic device 420 is also connected to the host controller (not shown) of its associated node 401 via a communication interface 421. In this embodiment, the communication interface 421 is a Serial Peripheral Interface (SPI), but other embodiments may include any type of bidirectional digital interface, such as Inter-Integrated Circuit (I2C) or Universal Asynchronous Receiver-Transmitter (UART). The communication interface 421 allows: configuration data to be sent from the host controller to the network diagnostic device; and the measured diagnostic test data to be provided to the host controller after the diagnostic test has been completed. In this particular embodiment, the network diagnostic device 420 is connected to the bus 402 outside its associated node 401. That is, the network diagnostic device 420 has its own connection terminals (CDH, CDL) for direct connection to the CAN bus 402. These connection terminals are different from the connection terminals 418 of the associated node 401a that are also connected to the CAN bus 402. Advantageously, this allows the network diagnostic device 420 to perform diagnostic tests on the network 400 without being affected by any common mode chokes 419 associated with the node 401.
[0059] The network diagnostic device 420 is configured to execute a network diagnostic program in accordance with an embodiment of the present disclosure. The network diagnostic program may be initiated when the network diagnostic device 420 detects that the bus 402 is quiet. Any node 401 within the network that has an associated network diagnostic device 420 may initiate the network diagnostic program. During the duration of the network diagnostic program, the node 401 that initiates the network diagnostic program will be referred to as the commander node 401a. The host controller (not shown) of the commander node 401a may send a diagnostic request to the target node 401b (which is in Figure 4Arbitrarily shown as node 4) to initiate a network diagnostic program. The diagnostic request includes a message identifier, which must be the same as a predetermined diagnostic identifier known to the network diagnostic device 420 in order to continue the network diagnostic program. In this way, the diagnostic request can be easily distinguished from other messages. The network diagnostic device 420 detects this diagnostic request and uses the TXD pin 406 of the commander node 401a to verify the source of the diagnostic request. In this example, the network diagnostic device 420 receives the diagnostic request from the TXD pin 406 of the commander node 401a. In other examples, the network diagnostic device 420 may receive the diagnostic request from the RXD pin 407 and use the information on the TXD pin 406 of the commander node 401a to verify the source of the diagnostic request. In yet another example, the network diagnostic device 420 may receive the diagnostic request directly from the CAN bus 402 and again use the information on the TXD pin 406 of the commander node 401a to verify the source of the diagnostic request. In any case, the network diagnostic device 420 can determine that the diagnostic request is correct and that the diagnostic request originates from (or does not originate from) the commander node 401a.
[0060] Once the target node 401b receives the diagnostic request from the commander node 401a, the target node 401b responds with a diagnostic response that includes a message identifier. Assuming no errors occur, the network diagnostic device 420 knows to expect this diagnostic response. In order to continue the network diagnostic program, the message identifier should be the same as a predetermined diagnostic identifier known to the network diagnostic device 420. The diagnostic response from the target node 401b also includes a test pattern. In other words, the diagnostic response from the target node 401b is similar to the diagnostic test message described with respect to Figure 3 In some embodiments, a diagnostic request is not required to initiate a diagnostic test. In such embodiments, the network diagnostic device 420 still verifies that the diagnostic response (in this case the first message sent) originates from a different node 401b than the node 401a associated with the network diagnostic device. Whether or not a diagnostic request is sent, all subsequent steps are the same.
[0061] The network diagnostic device 420 receives a diagnostic response via the RXD pin 407 of the commander node 401a. By simultaneously listening on the TXD pin 406 of the commander node, the network diagnostic device 420 can determine that the diagnostic response originated from a node 401 other than the commander node 401a. This ensures that two independent nodes are required to communicate before any intrusive diagnostic tests can be performed on the network. This advantageously reduces the risk of performing intrusive diagnostic tests at the wrong time for two reasons. First, the probability that two nodes will cooperate to erroneously initiate an intrusive diagnostic test is lower than the probability that a single node will erroneously initiate an intrusive diagnostic test. Second, the requirement for two independent nodes to cooperate to initiate an intrusive diagnostic test increases the difficulty for any external party to maliciously initiate an intrusive diagnostic test within the network.
[0062] In this embodiment, once the network diagnostic device 420 has received a diagnostic request from the commander node 401a and a diagnostic response from the target node 401b, the network diagnostic device 420 compares the message identifiers of the diagnostic request and the diagnostic response with a predetermined diagnostic identifier. In another embodiment, once the diagnostic request and the diagnostic response are received, the diagnostic request and the diagnostic response are compared with a predetermined diagnostic identifier. The predetermined diagnostic identifier can be hard-coded and can be a specific checksum or a cyclic redundancy check (CRC) code. If both message identifiers are the same as the predetermined diagnostic identifier, the network diagnostic device 420 uses the test pattern in the diagnostic response from the target node 401b to perform a diagnostic test.
[0063] A network diagnostic program can be used to sequentially perform diagnostic tests on each node 401 in a message-based protocol network.
[0064] If an error frame occurs, the transmitting node 401 can repeat the message that would have been successful because the network diagnostic device 420 will remain inactive until a new diagnostic request is sent. In this way, potential disruption to network communication is reduced.
[0065] Figure 5 The structure of a network diagnostic device 520 according to an embodiment of the present disclosure is shown. The network diagnostic device 520 includes a diagnostic control device 530 and a diagnostic test device 540. The diagnostic control device 530 is connected to the TXD pin 506 and the RXD pin 507 (or equivalents) of the nodes within the network. The diagnostic control device 530 may include a voltmeter (not shown) for receiving signals. The diagnostic control device 530 is also connected to the controller associated with the node via a communication interface 521. The diagnostic test device 540 is connected to the diagnostic control device 530 and the network bus 502.
[0066] In this embodiment, the diagnostic control device 530 includes a protocol engine 531 (depending on the specific network protocol in use), a timer 532, and a diagnostic control module 533. The diagnostic control device 530 can use the protocol engine 531 to identify a diagnostic request from the TXD pin 506 of its associated node and also identify a diagnostic response from the RXD pin 507 of its associated node. Alternatively, as indicated above, the diagnostic control device 530 can use the protocol engine 531 to identify both a diagnostic request and a diagnostic response from the RXD pin 507 and use the TXD pin 506 to verify the source of each message. The diagnostic control device 530 uses the protocol engine 531 to compare the message identifiers of the diagnostic request and the diagnostic response with a predetermined diagnostic identifier. Only when the message identifiers of the diagnostic request and the diagnostic response are the same as the predetermined diagnostic identifier will the diagnostic control device 530 use the protocol engine 531 to automatically perform a diagnostic measurement based on the received test pattern. To achieve this, first, the protocol engine 531 activates the diagnostic control module 533. The diagnostic control module 533 activates the diagnostic test device 540, and the protocol engine 531 uses the diagnostic test device 540 to perform a diagnostic test based on the test pattern of the diagnostic response. In some embodiments, the protocol engine 531 synchronizes the diagnostic control module 533 with the diagnostic response to ensure that the diagnostic test device 540 performs a diagnostic test only based on the test pattern of the diagnostic response. In some examples, the test pattern can be constructed differently to perform different types of diagnostic tests. In such examples, the protocol engine 531 synchronizes the diagnostic control module 533 so as to perform a diagnostic test at an appropriate time and according to the specific requirements of the test pattern. For example, the test pattern can be constructed to include pauses, perhaps to check for other activities within the network.
[0067] In this embodiment, the diagnostic control device 530 further includes a timer 532. After the diagnostic control device 530 receives and correctly identifies a diagnostic request from the TXD pin 506, the protocol engine 531 can activate the timer 532. If the diagnostic control device 530 does not receive a diagnostic response within a predetermined period of time after the timer 532 is started, the diagnostic control device 530 will stop being active until it receives another diagnostic request and verifies the diagnostic request with the activity on the TXD pin 506. In this way, the diagnostic test device 540 cannot perform an interference diagnostic test unless a diagnostic response is received within the predetermined period of time. Therefore, the probability that the network diagnostic device 520 performs an unwanted or untimely interference diagnostic test within the network can be reduced. Thus, the timer 532 can beneficially add an additional level of security to the network.
[0068] Figure 6 A flowchart showing a method of executing a diagnostic test program 650 according to an embodiment of the present disclosure is shown. Figure 6Most of the method is performed by a network diagnostic device having associated commander nodes and node controllers as discussed above. In this embodiment, the diagnostic test program includes some additional security features, as will be discussed below.
[0069] When a commander node wishes to start the 651 network diagnostic program 650, the first step is for the commander node to check for activity 652 on the network. If the activity on the network is above the network activity threshold 652, the diagnostic test program 650 is terminated 666. That is, the commander node does not send a diagnostic request, and thus the network diagnostic device does not perform any processing related to the network diagnostic program 650. The diagnostic control device may send an error message to the node controller. In this way, the possibility of performing an interfering diagnostic test while the network is active is reduced. If the activity on the network is below the threshold 652, the diagnostic test program 650 proceeds to the next step in the flowchart.
[0070] Next, the node controller sends a diagnostic request 653, which is directed to the target node and is also received by the network diagnostic device. The diagnostic request includes a first message identifier, as referenced above Figure 4 described. The network diagnostic device then compares the first message identifier with a predetermined diagnostic identifier 654. If the first message identifier is not the same as the predetermined diagnostic identifier 655, the diagnostic test program 650 is terminated 666. That is, the diagnostic control device sends an error message to the node controller and stops all activity until further notice. In this way, the network diagnostic device does not perform an interfering diagnostic test in response to the transmission of something other than a diagnostic request. This reduces the risk of performing an unwanted interfering diagnostic test. If the first message identifier is the same as the predetermined diagnostic identifier 655, the diagnostic test program 650 proceeds to the next step.
[0071] Next, the network diagnostic device starts a timer 656 (or if the timer is already active for any reason, the network diagnostic restarts the timer 656). If the period of time since the timer was started 656 reaches a threshold period of time before a diagnostic response 657a is received, the diagnostic test program 650 is terminated. In this way, this allowable response time enables the network diagnostic program to restart in the event that a diagnostic request is ignored or a diagnostic response is lost for any reason. As discussed above with respect to Figure 4 discussed, for security and safety purposes, two nodes are required to initiate an interfering diagnostic test. Accordingly, the network diagnostic device checks whether the diagnostic response originated from a node different from the commander node 657b. Thus, if a diagnostic response including a second message identifier and a test pattern is received from a different node after the timer is started 657a, 657b and before the threshold period of time is reached, the network diagnostic test program 650 continues.
[0072] Next, the network diagnostic device compares the second message identifier with a predetermined diagnostic identifier 658. If the second message identifier is not the same as the predetermined diagnostic identifier 659, the network diagnostic test process 650 is terminated 666. In this way, the network diagnostic device does not perform an interference diagnostic test in response to a transmission that is not a diagnostic response. This reduces the probability of erroneously performing an interference diagnostic test and also increases the difficulty for a hacker to initiate an interference diagnostic test to disrupt the network. By using a hard-coded predetermined diagnostic identifier, this can further enhance the security improvement. This is because the predetermined diagnostic identifier cannot be manipulated by a third party. In either case, if the second message identifier is the same as the predetermined diagnostic identifier, the network diagnostic procedure 650 continues.
[0073] Next, the network diagnostic device begins an interference diagnostic test 660 using the test pattern in the diagnostic response. The network diagnostic device can access a predetermined test pattern in the memory. As discussed above, the predetermined test pattern can be hard-coded in the memory. If the network diagnostic device detects an unexpected bit 661 in the test pattern from the diagnostic response, the network diagnostic procedure 650 is terminated 666. That is, if the received test pattern is not the same as the predetermined test pattern, the network diagnostic procedure 650 is terminated 666. In this way, if for any reason the interference diagnostic test has been erroneously started, the interference diagnostic test will be immediately cancelled to minimize the risk of interfering with important signals within the network. Additionally, the requirement to use a predetermined test pattern also increases the difficulty for a hacker to maliciously perform an interference test within the network. If no unexpected bit 661 is detected within the test pattern from the diagnostic response, the network diagnostic procedure 650 can continue.
[0074] In a message-based protocol network, each message can be assigned a priority value. This priority value is used to determine which messages have precedence in the case where multiple nodes are simultaneously attempting to send messages. Techniques for assigning priority values and coordinating data transmission based on message priority values are known in the art and are not within the scope of the present disclosure. In the present disclosure, the interference network diagnostic test is assigned a low priority value. This is to prevent the interference network test from delaying important signals within the network that may be more directly related to security. In this way, the impact of the interference diagnostic test on other messages within the network can be reduced. This can enable critical messages to be sent and received within the network during the test, which otherwise might not be possible.
[0075] Repeat the previous step of ensuring that the test pattern conforms to expectations 661 until the interference diagnostic test is completed 663. If at any time during the interference diagnostic test the test pattern presents an unexpected bit 661, the network diagnostic procedure 650 is terminated 666.
[0076] If the interference diagnostic test is completed 663 without being terminated 666 for any reason (where any instance of termination 666 causes the network diagnostic device to refrain from performing any processing related to the network diagnostic program 650 until another diagnostic request is received), the network diagnostic device sends the results of the interference diagnostic test to the node controller 664. The node controller may store or interpret the interference diagnostic test data as needed. The network diagnostic test program is now complete 665.
[0077] As will be appreciated, an interference diagnostic test is performed within the network using a predetermined test pattern. In the event of any unexpected event within the network, the interference diagnostic test may be terminated immediately. In this way, the impact of the interference diagnostic test on other messages within the network can be minimized, thereby allowing the interference diagnostic test to be performed within an active network. This combination of security elements allows the diagnostic test device to be used securely in parallel with normal network communication. Thus, faults that occur only during the operation of the network can be detected by performing the interference diagnostic test as described herein.
[0078] Figure 7 A flowchart showing an overview example of an overall network diagnosis 770 in accordance with an embodiment of the present disclosure is shown. As described above with respect to Figure 2 it may be beneficial to locate the position of a fault within the network. Thus, the method described with respect to Figure 2 may be combined with the network diagnostic program described with respect to Figure 6 to provide a complete example of how the techniques of the present disclosure may be used within the network.
[0079] First, the overall network diagnostic program 771 is started and an initial value is assigned to the named variable n 772. The named variables and values defined herein are merely exemplary values assigned arbitrarily, and any reasonable alternative may also be used. In this example, n is set to 1, where n corresponds to the number assigned to each node within the network, and the node numbers start from 1 and increase by 1 for each node until each node has been assigned a number.
[0080] If node n is not the commander node 773, the network diagnostic program 750 is performed for node n (similar to that described above with respect to Figure 6(The network diagnostic program described herein). In this embodiment, if for any reason the network diagnostic program 750 terminates 774, the commander node may wait for a predetermined waiting period 775. After waiting for the predetermined waiting period 775, the commander node may start the network diagnostic program 750 again for node n. In this way, any other messages that may exist in the network have time to be processed. In some other embodiments, if the network diagnostic program 750 terminates 774, an error message is sent to the node controller associated with the commander node. In this embodiment, the commander node processes the error message and may initiate another diagnostic test program for any node within the network at any future time and for any reason.
[0081] If the network diagnostic program 750 completes 774, that is, the network diagnostic program 750 does not terminate 774, the named variable n is incremented by 1 776. In other words, if the network diagnostic program 750 completes without terminating, then n = n + 1. If node n was previously the commander node 773, the network diagnostic program 750 and the following steps 774 and 775 are skipped, and the named variable is incremented by 1 776. In this way, the commander node cannot initiate an interference diagnostic test on itself and an unbreakable loop is avoided. If the new value of the named variable n is greater than the total number of nodes in the network 777, the named variable n is reset to 1 772, and the overall network diagnostic program 770 can continue. If the named variable n is not greater than the total number of nodes in the network 777, the network diagnostic program 750 is started for the new node n, and the overall network diagnostic program can continue.
[0082] If at any time within the network diagnostic program 770 the interference diagnostic test results are obtained for each node within the network (steps not shown), the complete data set can be analyzed in order to find the location (and in some cases, the severity) of the fault within the network. Once the location of the fault is detected, actions can be taken to repair or mitigate the effects of the fault. For example, the network can indicate the fault location to the user to allow repair. As a result of the fault location detection, any other reasonable actions can be taken.
[0083] As will be apparent, this overall diagnostic program 750 is merely an example implementation of a network diagnostic program that can be used to locate faults within a network. Any alternative method of sequentially performing interference diagnostic tests on each node within the network can be implemented. In some embodiments, an alternative method of sequentially performing interference diagnostic tests only on a subset of the nodes within the network can be implemented.
[0084] Figure 8 An example device that can be used to implement a network diagnostic program in a CAN network 800 is shown in accordance with an embodiment of the present disclosure. The CAN network 800 is similar to that referred to above Figure 1 and 4The CAN network described herein. In this example, at least one node 801 is associated with a diagnostic control device 830 and a diagnostic test device 840. In the same manner as described above, the network control device 830 is connected to the TXD pin 806 and the RXD pin 807 of its associated node, and the host controller (not shown) of its associated node 801 through a communication interface 821. The diagnostic test device 840 is connected to the diagnostic control device 830 and the bus 802. In this example, the diagnostic test device 840 includes an impedance tuner 841 connected between two wires (CANH and CANL) of the bus 802.
[0085] First, the host controller (not shown) of the commander node 801 configures the diagnostic control device 830 by means of the communication interface 821. This configuration may include sending information about a predetermined diagnostic identifier and / or information about an interference diagnostic test to be performed when appropriate conditions are met. If the activity on the CAN network is below an activity threshold, the host controller (not shown) sends a diagnostic request from the commander node 801, which is directed to a target node (not shown). The diagnostic request can be any message compatible with the CAN protocol. The message includes a message identifier identical to the predetermined diagnostic identifier. The diagnostic control device 830 also receives the diagnostic request from the commander node 801, which is intended for the target node. The diagnostic control device 830 measures the activity on the TXD pin 806 to verify the source of the message. The diagnostic control device 830 also uses the data received from the RXD pin 807 to interpret the diagnostic request. This reduces the likelihood of any unauthorized node successfully triggering an interference diagnostic test.
[0086] The diagnostic control device 830 compares the message identifier from the diagnostic request with the predetermined diagnostic identifier, and if the message identifier is the same as the predetermined diagnostic identifier, it starts a timer 832. To continue, the target node (not shown) must reply with a diagnostic response within a threshold time period since the timer 832 was started.
[0087] Assuming a normal scenario, the target node (not shown) replies with a diagnostic response within a threshold time period since the timer 832 was started, and this diagnostic response is received by the diagnostic control device 830 by means of the RXD pin 807. The diagnostic response is compatible with the CAN protocol and includes a header, a message identifier, and a test pattern. Refer to the following with respect to Figure 9Describe an example diagnostic response. The diagnostic control device 830 checks the header and compares the message identifier from the diagnostic response with a predetermined diagnostic identifier. If the message identifier from the diagnostic response is the same as the predetermined diagnostic identifier and the header meets expectations, the diagnostic control device 830 proceeds with the network diagnostic procedure and may reset the timer 832. The diagnostic control device may also check the signaling on the TXD pin 806 to confirm that the diagnostic response is from a node different from the commander node 801.
[0088] To perform the interference diagnostic test, in this example, the diagnostic control device controls the timing of the diagnostic test device 840 such that the interference diagnostic test is performed using only the appropriate portion of the test pattern within the diagnostic response. In this way, the measurement is synchronized with the diagnostic response.
[0089] According to the above regarding Figure 6 the described diagnostic test protocol, the interference diagnostic test can be immediately terminated in any unexpected situation.
[0090] The interference diagnostic test may include the diagnostic control device 830 adjusting the resistance of the impedance tuner 841 to modulate the impedance on the bus 802 and then measuring the result. In some examples, the diagnostic control device 830 may use the impedance tuner 841 to reduce the resistance of the bus until the differential voltage between CANH and CANL drops below a predetermined threshold. Since this test is performed on the test pattern of the message from the target node, the impedance of the network connection between the target node and the commander node can be measured, ignoring other segments of the network. Therefore, the impedance test can be performed in this way to determine the network impedance in the segment between each pair of nodes. Thus, the location and severity of a fault (which affects the impedance of the network wire) can be detected, as described above regarding Figure 2 described.
[0091] If the interference diagnostic test is completed without being terminated, the interference diagnostic test result is sent to the host controller (not shown) of the commander node 801 via the communication interface 821. The host controller (not shown) may interpret the diagnostic test result or store the diagnostic test result to be interpreted in the future.
[0092] This diagnostic test procedure can be sequentially performed for one or more nodes in the network. Once the host controller (not shown) associated with the commander node 801 receives all the required interference diagnostic tests, the host controller can analyze the interference diagnostic tests combinatorially to determine the location and / or severity and / or presence of one or more possible faults in the network.
[0093] Figure 9 An example structure of a diagnostic response that can be used in a CAN network according to an embodiment of the present disclosure is shown. The diagnostic response structure 910 is as described above regarding Figure 3Specific examples of the described diagnostic test messages. The diagnostic response structure 910 includes a header 911, a payload 912, and a message end segment 913. The header 911 is a control field that includes identification information about the message, such as a data length code (DLC) for indicating the transmission length and / or an identifier for indicating the response node from which the response is coming. The payload 912 contains a message identifier 914 and a test pattern 915. The message end component indicates the end of the message and may include an acknowledgment bit, a frame end bit, and / or a CRC that can be used as a standard in the CAN protocol for error detection.
[0094] The message identifier 914 is an extension of the header 911 and may include a specific 16-bit CRC code ( Figure 9 D0 and D1 in Figure 9 ), and is recognized by the diagnostic control device. Since the first data byte already includes the CRC code, it is possible to perform identification before starting the test pattern. This ensures that the interference diagnostic test can be safely started. The message identifier 914 may also include an additional pattern (
[0095] D2 in
[0096] Figure 9 Figure 9 ), which can be used to help the diagnostic control device synchronize the diagnostic test device in order to precisely perform the interference diagnostic test. The additional pattern can also prevent padding bits from being inserted into the test pattern. The additional pattern can be 0xAA. The additional pattern can also provide a time window for the diagnostic control device to monitor the TXD pin to ensure that the diagnostic response comes from different nodes in the network. This allows the diagnostic control device to ensure that two different nodes are involved before any interference diagnostic test can be performed. The header 911 and the message identifier 914 are used in combination to identify the diagnostic response.
[0097] Figure 10 An example of interference diagnostic test 1080 performed in a CAN network by a diagnostic test device that can be used Figure 8 is shown. In this example, interference diagnostic test 1080 involves gradually decreasing the impedance of an impedance tuner until the differential voltage between CANH and CANL detected by the receiver of an associated node drops below a voltage threshold. In Figure 10 the example, the voltage threshold is 1V. After this voltage threshold is reached, the measurement process is completed, and the measured impedance value can be read out via a communication interface.
[0098] After interference diagnostic test 1080 is completed for a target node, another interference diagnostic test 1080 can be initiated for a different target node at a future time when network activity is below a predetermined activity threshold.
[0099] Other suitable interference diagnostic tests can be performed using the device or method according to the present disclosure to supplement or replace the interference diagnostic test represented by Figure 10 .
[0100] Unless a specific order is explicitly stated, the instructions and / or flowchart steps in the figure above can be executed in any order. Moreover, those skilled in the art will recognize that although one example instruction set / method has been discussed, the materials in this specification can be combined in many ways to produce other examples, and should be understood within the context provided by this detailed description.
[0101] In some example embodiments, the instruction set / method steps described above are implemented as functions and software instructions embodied in an executable instruction set that is implemented on a computer or a machine programmed and controlled by the executable instructions. Such instructions are loaded for execution on a processor (e.g., one or more CPUs). The term processor includes a microprocessor, a microcontroller, a processor module or subsystem (including one or more microprocessors or microcontrollers), or other control or computing devices. A processor can refer to a single component or multiple components.
[0102] In other examples, the instruction set / method shown herein and the data and instructions associated therewith are stored in corresponding storage devices, which are implemented as one or more non-transitory machine or computer-readable or computer-usable storage media. Such computer-readable or computer-usable storage media are considered part of an article (or article of manufacture). An article or article of manufacture can refer to any single manufactured component or multiple components. One or more non-transitory machine or computer-usable media as defined herein do not include signals, but such one or more media are capable of receiving and processing information from signals and / or other transitory media.
[0103] Example embodiments of the materials discussed in this specification may be implemented, in whole or in part, via a network, a computer, or data-based devices and / or services. These may include the cloud, the Internet, an intranet, mobile devices, desktop computers, processors, lookup tables, microcontrollers, consumer devices, infrastructure, or other enabling devices and services. As used herein and in the claims, the following non-exclusive definitions are provided.
[0104] In one example, one or more of the instructions or steps discussed herein are automated. The term automated or automatic (and its like variations) means the use of a computer and / or mechanical / electrical devices to control the operation of a device, system, and / or process without human intervention, observation, effort, and / or decision-making.
[0105] It should be understood that any components that are alleged to be coupled may be directly or indirectly coupled or connected. In the case of indirect coupling, additional components may be disposed between the two components that are alleged to be coupled.
[0106] In this specification, example embodiments have been presented in accordance with a selected set of details. However, those of ordinary skill in the art will understand that many other example embodiments may be practiced that include different selected sets of these details. It is intended that the appended claims cover all possible example embodiments.
Claims
1. A device configured to perform a network diagnostic procedure within a message-based protocol network comprising a plurality of nodes, characterized in that The device comprises: a diagnostic test device configured to perform a diagnostic test; and A diagnostic control device, wherein, in order to execute the network diagnostic program, the diagnostic control device is configured to: receiving a diagnostic request from a commander node, wherein the diagnostic request is directed to a target node, and wherein the diagnostic request includes a first message identifier; comparing the first message identifier to a predetermined diagnostic identifier; receiving a diagnostic response from the target node, wherein the diagnostic response includes a second message identifier and a test pattern; and comparing the second message identifier to a predetermined diagnostic identifier; If the first message identifier and the second message identifier are the same as the predetermined diagnostic identifier, then: The diagnostic test device is used to perform a diagnostic test using the test pattern.
2. The device according to claim 1, characterized in that The diagnostic test is an interference diagnostic test.
3. The device according to claim 2, characterized in that The interference diagnostic test is configured to interfere with other signals in the message based protocol network.
4. Apparatus according to any preceding claim, characterised in that The message based protocol network is a Controller Area Network (CAN) comprising a first bus conductor and a second bus conductor coupled to each node within the network.
5. The device according to claim 4, characterized in that: The diagnostic control device is configured to receive the diagnostic request from a transmit data TXD pin of the commander node; and The diagnostic control device is configured to receive the diagnostic response from a receive data RXD pin of the commander node.
6. Apparatus according to any preceding claim, characterised in that The diagnostic control device further comprises a timer, wherein: The diagnostic control device is configured to start the timer in response to receiving the diagnostic request; and The diagnosis control device is configured to terminate the network diagnosis program if the diagnosis control device does not receive the diagnosis response within a predetermined period of time from when the timer is started.
7. Apparatus according to any preceding claim, characterised in that The diagnosis control device is configured to terminate the network diagnosis program in the following cases: The first message identifier is different from the predetermined diagnostic identifier; and / or The second message identifier is different from the predetermined diagnostic identifier.
8. Apparatus according to any preceding claim, characterised in that The diagnosis control device is configured to terminate the network diagnosis program if the test pattern is not identical to a predetermined test pattern.
9. The device according to claim 8, characterized in that The predetermined test pattern is hard coded.
10. A method for performing a network diagnostic procedure within a message-based protocol network, characterized in that The method comprises: receiving a diagnostic request from a commander node, wherein the diagnostic request is also directed to a target node, and wherein the diagnostic request includes a first message identifier; receiving a diagnostic response from the target node, wherein the diagnostic response includes a second message identifier and a predetermined test pattern; comparing the first message identifier and the second message identifier to a predetermined diagnostic identifier; If the first message identifier and the second message identifier are the same as the predetermined diagnostic identifier, performing a diagnostic test on the predetermined test pattern using a diagnostic test device; and If the first message identifier and the second message identifier are not identical to the predetermined diagnostic identifier, the network diagnostic procedure is terminated.