Method for operating a functionally reliable audio output system
By using acoustic watermarks and code comparison methods in the audio output system, the problem of difficulty in ensuring the functional reliability of the audio output system in the prior art is solved, and simple and economical functional reliability verification and transmission path inspection are achieved.
Patent Information
- Application Number
- CN202080057490.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-20
- Filing Date
- 2020-09-10
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-09-10
AI Technical Summary
The prior art is difficult to ensure the functional reliability of the audio output system without adding complexity and cost, especially when the system is running, checking all technical components in the transmission path.
By generating code assigned to the alarm in a simple authenticated computing node and transmitting it to a complex computing node, an output signal with an acoustic watermark is generated, and transmitted to an independent computing process, the code contained in the output signal is obtained, and it is transmitted back to the simple authenticated computing node, and the code comparison is performed to verify the functional reliability of the audio output system.
It is achieved to easily check the functional reliability of the audio output system, especially the functional reliability of its components, without adding complexity and cost, and to enable inspection of the transmission path while the system is running.
Smart Images

Figure CN114223030B_ABST
Abstract
Description
Field of the Invention
[0001] The present invention relates to a method for operating a functionally reliable audio output system, a functionally reliable audio output system, a vehicle comprising such an audio output system, and also to a computer program product for performing the method, and a data carrier comprising such a program. Background Art
[0002] Functionally reliable audio output is achieved by systems that are themselves considered to have sufficient functional reliability or that operate with the help of complex monitoring devices based on digital signal processing. Otherwise, content verification of the correct output audio signal can only be provided to a very limited extent, for example, in the form of simple measured values at maximum level. In addition, there are diagnostic methods that employ test signals perceptible to humans and, in the case of automotive production, for example, check the correct installation and function of infotainment components in a vehicle.
[0003] Complex digital signal processing devices are relatively complex and expensive and are therefore shared with systems having unreliable functions. Thus, functional reliability verification is very complex because, in addition to complex signal processing, unreliable parts of the function must also be considered. Usually, not all technical components involved in acoustic transmission are checked because this is not possible when there are no perceptible test signals during system operation.
[0004] Therefore, it would be desirable if a functionally reliable audio output system could not only resort to complex and expensive devices but also to devices with simple authentication, ensure functional reliability without excessive increase in complexity, and also perform checks on the technical components involved in transmission during system operation. Summary of the Invention
[0005] A method for operating a functionally reliable audio output system with a computationally simple node and a computationally complex node according to the present invention comprises the following steps:
[0006] - generating a code assigned to an alert in the computationally simple node;
[0007] - transmitting the code to the computationally complex node;
[0008] - generating an output signal with an acoustic watermark in a first computational process;
[0009] - transmitting the output signal to a second computational process independent of the first computational process;
[0010] - obtaining, in a second computational process independent of the first computational process, the code contained in the output signal;
[0011] - Transmit the code to a computationally simple authentication node; and
[0012] - Verify whether the audio output system is functionally reliable based on a comparison of the generated code with the code based on the received code.
[0013] This has the following advantages: costs and complexity can be reduced, and the functional reliability of the audio output system, in particular the functional reliability of its components, can be checked in a simple manner.
[0014] Advantageously, the method according to the invention comprises the following steps:
[0015] - Transmit the output signal to a second computational process independent of the first computational process;
[0016] The method includes the following steps:
[0017] - Emit the output signal by means of a sound transducer;
[0018] - Receive an acoustic signal by means of a sound sensor, the acoustic signal including the output signal output by the sound transducer;
[0019] And the following steps:
[0020] - In a second computational process independent of the first computational process, ascertain the code included in the output signal;
[0021] Ascertain the code included in the output signal from the acoustic signal.
[0022] This has the following advantages: the functional reliability of the entire transmission path can be checked in a simple and efficient manner.
[0023] Advantageously, the method according to the invention further includes the following steps:
[0024] - Transmit a first control signal from the computationally simple authentication node to a computationally complex node in order to cause the first signal to be incorporated into the output signal.
[0025] This has the following advantages: additional information, in particular reliability-related information, can be transmitted and activated, and thus the reliability and flexibility of the method can be increased.
[0026] Alternatively or additionally, the following steps may also be performed:
[0027] - Superimpose the generated code on a code known to the computationally simple authentication node and characteristic of the signal;
[0028] - Generate the output signal from the acoustic watermark and at least one of the first signal or the second signal; and
[0029] - Transmit a second control signal from the simply authenticated computing node to the complex computing node in order to activate a limiting stage that can limit the signal level of the second signal.
[0030] This has the following advantages: Additional functions, especially those related to reliability, can be transmitted and activated, and thus the reliability and flexibility of the method can be increased.
[0031] Advantageously, the method according to the invention includes the following additional steps:
[0032] - Transmit a third control signal from the complex computing node to the simply authenticated computing node in order to inform that the second signal is included in the output signal.
[0033] This has the following advantages: Signals that are not related to reliability can be used, and the inspection can be made simpler and more flexible.
[0034] Advantageously, the method according to the invention repeats the following steps:
[0035] - In a second computing process independent of the first computing process, obtain the code contained in the acoustic signal; and
[0036] - Transmit the code to the simply authenticated computing node.
[0037] In this case, in particular, the code can always / repeatedly be present in the output signal, and the code based on the received code can be generated by statistically processing the code that is repeatedly determined and transmitted to the simply authenticated computing node.
[0038] This has the following advantages: The evaluation, inspection, and protection of the transmission are particularly reliable and robust and can resist interference effects.
[0039] Furthermore, the method according to the invention can be characterized in that the comparison of the generated code with the code based on the received code results in a probability of positive verification. In this case, this indicates that the audio output system is thus probably functionally reliable with a certain probability. In this case, at least one threshold can be provided, and when this threshold is exceeded, a positive verification of functional reliability is determined, while when it is below the threshold, a negative verification or non-verification of functional reliability is determined. Alternatively or additionally, the comparison of the generated code with the code based on the received code can result in a probability of negative verification, that is, the audio output system is probably functionally unreliable with a certain probability. In this case, at least one threshold can also be provided, and when it is below the threshold, a negative verification of functional reliability is determined, while when it is exceeded, a positive verification or non-verification of functional reliability is determined.
[0040] This has the following advantages: The reliability can be flexibly set as required.
[0041] Advantageously, in the case of negative verification and / or non-verification, thus when the audio output system is functionally unreliable, the method according to the invention performs at least one of the following steps:
[0042] - Drive a simpler but reliable alternative audio output;
[0043] - Switch the system to a reliable state;
[0044] - Inform the driver of the existence of a system fault;
[0045] - Check based on the redundant characteristics of the audio output system; and
[0046] - Compensate based on the redundant characteristics of the audio output system.
[0047] This has the following advantages: It can flexibly respond to functional reliability faults as required, and can inform the driver of reliability-related situations at any time.
[0048] The functionally reliable audio output system for performing the method according to the invention according to the invention includes a sound converter, a sound sensor, a simply authenticated computing node, and a complex computing node.
[0049] This has the following advantages: The production of this audio output system can be simple and more cost-effective. In addition, the advantages of this method apply to the audio output system.
[0050] Advantageously, the audio output system according to the invention is characterized in that the first computing process and the second computing process independent of the first computing process are executed on the same physical computing node, wherein, in particular, the first computing process and the second computing process are separated from each other by at least one memory isolation technique.
[0051] This has the following advantages: It improves the reliability in the face of possible programming errors, for example, and can reduce the proportion of complex components.
[0052] In an alternative embodiment, the encoding of the acoustic alarm signal S with the watermark W has been pre-implemented in an authenticated environment such that the watermark starts from the beginning part of the audio data stored in the audio output system or the vehicle. As a result, the computational operations of the audio output system can be simplified. Therefore, each alarm is also assigned a fixed code or code pair. This assignment can be stored in a separate database. Therefore, the simply authenticated computing node that can obtain it can also transmit only the representative identifier of the alarm to the complex node, rather than necessarily transmitting the code.
[0053] This has the following advantages: Errors due to knowledge of the code in complex nodes can thereby be prevented, and the required data processing is reduced and simplified. In this case, the complex node has no information about the code at all.
[0054] Accordingly, a method for operating a functionally reliable audio output system for computing nodes with simple authentication and complex computing nodes includes at least one of the following steps:
[0055] - Reading, in a computing node (A) with simple authentication, a representative identifier assigned to an alert (R) and a code (A1) from a database;
[0056] - Transmitting the representative identifier to the complex computing node (B);
[0057] - Generating, in a first computing process (B1), an output signal (Y) with an acoustic watermark (W);
[0058] - Transmitting the output signal (Y) to a second computing process (B2) independent of the first computing process (B1);
[0059] - Determining, in a second computing process (B2) independent of the first computing process (B1), a code (A2) contained in the output signal (Y);
[0060] - Transmitting the code (A2) to the computing node (A) with simple authentication; and
[0061] - Verifying whether the audio output system is functionally reliable based on a comparison of the read-in code (A1) with the code based on the received code (A2).
[0062] A vehicle according to the present invention includes a functionally reliable audio output system according to the present invention, and the vehicle is configured to perform the method according to the present invention.
[0063] This has the following advantages: The production of the vehicle can thereby be made more cost-effective, and the functional reliability is maintained. In addition, the advantages of the method according to the present invention and the audio output system according to the present invention also apply to the vehicle according to the present invention.
[0064] A computer program product according to the present invention includes instructions that, when executed by an embedded system, cause the embedded system to perform the method according to the present invention.
[0065] This has the following advantages: The method can be flexibly adapted and executed on many different systems.
[0066] A data carrier according to the present invention stores the computer program product according to the present invention.
[0067] This has the following advantages: The computer program can be easily transmitted, saved, and copied.
[0068] The method checks the entire acoustic transmission path up to the driver, including the speaker. For this purpose, no test signal perceptible to humans is required. The method for identifying the acoustic watermark is very reliable and robust in the face of external interference, so that this method can be used even in the presence of acoustic interference from the vehicle interior or the surrounding environment. The present invention enables the use of uncertified processors, i.e., complex processors, which can also perform many other tasks in addition to audio output. In particular, this can be implemented in a system in which, in addition to the reliability-related audio signal S, the driver must also be made to listen attentively to other audio signals. Another basic advantage of the present invention is the division into simple parts, which can be proven to be reliable enough according to ASIL and do not require complex or fast signal processing of this part at the same time as the audio samples / audio sampling values. This makes currently commercially available processors highly cost-effective. The present invention can also use typical devices of the driver information system for the entertainment, information, and voice control of the driver to provide safety-related sound alerts or notifications, the safety of which does not need to be verified in terms of safety at a higher ASIL (Automotive Safety Integrity Level) level than QM (Quality Management), because the entire acoustic transmission path is monitored by relatively simple and inexpensive components. In many cases, the failure of individual components can be identified in a timely manner before a safety-critical situation occurs for the driver, the components can be replaced, or in the case of a safety-critical sound alert, these failures can be tolerated if redundancy is available.
[0069] In addition to use in vehicles, it can also be used to provide safety-related announcements in public buildings and transportation systems, industrial facilities, etc.
[0070] The concept of audio output regarding functional safety according to the present invention can, for example, reach the certification standard of ASIL B. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Further features, attributes, and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings, schematically shown in the drawings:
[0072] Figure 1 A diagram showing a method for operating a functionally reliable audio output system according to the present invention is shown;
[0073] Figure 2 A diagram showing digital signal processing is shown; and
[0074] Figure 3 A further diagram showing digital signal processing is shown. Detailed implementation mode
[0075] Figure 1 Schematically shows a reliable audio output system X according to the present invention. The functionally reliable audio output system X is divided in such a way that a computationally equipped node A that can be authenticated relatively simply (in particular, can be authenticated according to ASIL, i.e., for example, has low complexity and limited computing power) assigns code A1 to a specific alarm R in a sequence controller (program) G and transmits this code to a more complex node B, and this more complex node generates a signal W from the code A1 and the acoustic alarm signal S to be output by means of digital signal processing C in a computational process B1, and the signal W is masked by the alarm signal S to be output, that is, a human being cannot distinguish the output signal S from the superposition of the signals S and W. For this purpose, the sequence controller G transmits a control signal A3 to the computational process B1, which activates the output of the signal S and switches to the alarm signal S as a reference signal for the signal processing C. In order to reliably and unambiguously distinguish the signal source S of the alarm sound from any other audio signal M, in addition to the code A1, a characteristic code BK (for example, the checksum of an associated audio file) known to the node A and not equal to the zero point of the signal source S can be superimposed on the code A1 (for example, by means of a bitwise exclusive OR function (XOR)). For other audio signals M, A1 may remain unchanged, for example, by performing an "OR" operation between zero and A1. The signal W is also referred to as an acoustic watermark. The modulation and coding of A1 for forming the acoustic watermark W are generally implemented in redundant and human-auditory-independent signal components in the alarm signal S.
[0076] The signals S and W, and optionally an additional signal M (such as music), are added together to form an output signal Y. In the case where the alarm signal S must be output, the sequence controller G transmits the signal A4 to the computing process B1, which activates the limiting stage L and limits the signal level of M to such an extent that the driver does not fail to hear the alarm signal S, and the recognition of the watermark in the output signal Y is not overly disturbed or delayed. The computing process B1 generally outputs the output signal Y to the amplifier V, which outputs the amplified signal as an output signal to the sound converter LS (such as a loudspeaker). The sound generated by the sound converter LS and possible other noises, i.e., the acoustic signal Z1, are received by both the driver and the sound sensor MIC. The sound sensor converts this signal into a signal stream Z (of samples / sampled values) and feeds this signal stream to the second computing process B2. The second computing process is advantageously located in the same physical computing node B, thus not only saving costs but also being accommodated in a dedicated computing node. By means of signal processing D, the computing process B2 learns the (most likely) code A2 contained in the signal. The computing process B2 must operate completely independently of the computing process B1, in particular not knowing the code A1 in advance. The most likely code A2 contained in the signal stream Z is transmitted to the computing node A through multiple repetitions, and this computing node evaluates the learned code in the statistical process H. After sufficient code repetitions, the sequence controller K in the computing node A can then determine reliably enough, with respect to the alarm sound output by comparing with the code A2 averaged over many cycles, whether there is a code A1BK from the loudspeaker present in the received acoustic signal Z1, thus providing the driver with the audibility of the alarm signal. In the case where the average code A2 does not correspond to A1BK, there is a fault in the system, and the computing node A can drive a simpler but reliable alternative audio output BZ, or switch the system to a reliable state, i.e., the presence of the system fault is reliably notified to the driver. For the sufficient reliability of the entire system, it must be ensured that the code A1 is unknown to the computing process. This can be achieved through memory isolation techniques (such as, by means of a memory management unit and an operating system supporting process isolation). To increase the reliability of the system and enhance the robustness against interfering signals, the code to be encoded can be repeated multiple times in the signal distribution curve, and the signal to be encoded can be evaluated by random processing H in the computing node A before making a determination regarding the presence of a system fault in the sequence controller K of the computing node A. In particular, a correlation filter is suitable for this purpose; for example, a signal matching filter (optimal filter, matched filter) can also be used.
[0077] During the signal output and the evaluation of whether the output signal can be heard by the person to be notified, various factors can be considered. In particular, the ambient volume and other information, in particular personal information, personal settings, and listening habits, can be considered. In this regard, for example, seat settings, body posture, typical volume settings, and information about limitations or hypersensitivity, especially with regard to the person's hearing ability, can be considered. The presence or use of external devices, in particular hearing aids and their settings, can also be considered. This is advantageously achieved by communication between the external device and the vehicle components, but can also be determined indirectly by vehicle sensors. In this regard, for example, a camera can determine the absence of hearing aids and / or that sounds and other noises are played back at an increased volume.
[0078] If there is a signal M that is loud enough, the functionality of the transceiver system can also be checked in the background without an alarm. The fact that the audio signal M is loud enough can be determined by the limiter stage L, since the limiter stage measures the current power of the signal and this can be transmitted as a control signal A5 to the sequence controller K. The audio signal M (instead of the alarm S) is fed to the signal processing C and is processed like S. If the control signal A5 indicates a sufficient audio volume, the sequence controller K can determine whether there is a system fault based on the received code A2. Generally speaking, in this case, since there is no hazard, a decision does not need to be made within a short time, so a correspondingly longer statistical evaluation time is allowed, and thus the reliability of the correct decision regarding the presence of a system fault is increased. The sequence controller K can use the result of the background check to immediately inform the driver of the presence of a system fault by means of some other functional method (for example, by visual output or an alternative sound output) and can, for example, request finding a service facility. Since audio output is now usually implemented via multiple sound converters (speakers) and sound is usually also received via multiple microphones MIC to improve the direction effect, there is usually a redundant acoustic system that only fails in the unlikely case that all sound converters or microphones fail simultaneously. The signal processing D and the sequence controller K can take this into account. For example, as long as there is still a signal stream Z with a correct identification code from at least one microphone, the failure of one or more microphones can be easily identified. By alternately superimposing the code A1 only on one speaker channel, or by superimposing different codes (statistically independent of each other) on the individual speakers, the speakers can also be tested individually. In these cases, the service situation can be informed to the driver before the system fails.
[0079] However, if the external acoustic interference signal is so large that all microphones fail, for example, by being driven to their limits, a significant system failure may be wrongly identified. However, the acoustic signal Z1 of overspeed driving can be recognized by the signal processing D and can be distinguished from the typical signal distribution curve of a faulty microphone, since a faulty microphone does not provide an audio signal level or only provides a low level. In the case of overspeed driving, the signal processing D then sends a special code A2 to the sequence controller K, which can output an alarm to the driver by some other means (e.g., by visual output), since the acoustic transmission path to the driver is no longer ensured.
[0080] In addition, there is a possibility of errors occurring during the generation, processing, and / or transmission of signals, so the probabilities corresponding to code A1 and code A2 are basically always 1. For example, this may be because the computing process B1 is not properly separated from the computing process B2, so that code A1 is known to or misused by the computing process B2. Such an error can be detected by changing or erasing these codes in the complete memory after using code A1 or code A1BK in the computing process B1.
[0081] Alternatively or additionally, especially in the case where the transmission path from the amplifier V via the sound converter LS to the human ear can be classified as functionally reliable or verified in some other way, the output signal Y can also be directly fed to the computing process B2. With a verified transmission path, the complete processing path including the acoustic transmission can thus be classified as functionally reliable. In particular, the code actually contained in the acoustic signal is thus also basically transmitted to the computing process B2 as if by pure electronic transmission.
[0082] Figure 2An exemplary implementation of digital signal processing C (encoder) is shown and described. The code to be encoded can be spread over a large frequency range by binary phase shift keying (BPSK), which can be achieved by a simple multiplication of the signal in the case of encoding the mapped signal (e.g., -1; 1) from a known pseudo-random signal sequence (PRBS source) and a cyclically repeated code sequence. The code to be encoded is superimposed (e.g., using the XOR function) with such a known pseudo-random signal sequence from the PRBS source (having an approximately white spectrum and having a distinct peak in its autocorrelation function), which simplifies the identification of the start and period of the pulse sequence because the autocorrelation function has a distinct maximum after exactly one period. Finally, the signal can be multiplied by a cosine function to obtain a spectral shift that contributes maximally to the appropriate value. Additionally, the resulting signal sequence can be weighted in the frequency domain by a human psychoacoustic model (e.g., by fast Fourier transform FFT) such that the signal W remains below the perception threshold of human hearing. In this case, the masking model provides an estimate of the masking threshold to the weighting process such that the audio signal M and / or the alert S only mask the changes caused by the code. Additionally, the code to be encoded can be modified such that the receiver can identify transmission errors, for example, by means of convolutional codes.
[0083] If multiple security-related sounds must be output simultaneously, PNR signals with orthogonal codes can be used for different sounds in order to better and reliably distinguish different encoded cycle lengths.
[0084] Figure 3Exemplary embodiments of a signal processing D (decoder) are presented and described, and the signal processing has a matched filter to which a sampled data stream z[k] (i.e., the signal stream Z from a microphone) is fed. The matched filter has an impulse response d[N - n] that is time-reversed with respect to the PRBS signal and has maximum correlation or anticorrelation with the input signal in each case at the limit of the symbol duration Tsymb = n * T0. These extrema are identified by a synchronization unit and drive a sampling unit that samples the output o[k] of the matched filter at time point n and feeds it to a threshold decision unit. The threshold decision unit determines whether there is sufficient correlation for a positive bit (the data bit g[n] is the same as the PRBS sequence d[n]) or sufficient anticorrelation for a negative bit (the data bit g[n] is different from the PRBS sequence d[n]) based on a threshold S selected empirically. If this is not the case, the decision unit outputs 0, indicating an unrecognized bit or a bit error. Thus, a code A2 representing an estimate of the code A1BK appears at the output of the decoder D. Since this code A2 may still have bit errors or even estimation errors, the code is transmitted to a random evaluation unit H in a computing node A over many periods N of the code sequence A1. The evaluation unit can then perform a random evaluation very simply by adding data bits at the same bit positions of the received codeword A2 and can feed the result to the threshold decision unit in a sequence controller K.
[0085] In an alternative embodiment, it may also be that the encoding of the acoustic alarm signal S with the watermark W has already been pre-implemented in a certified environment such that the watermark starts from the beginning of the audio data stored in the audio output system X or in a vehicle. As a result, the computational operations of the audio output system X can be simplified. Thus, each alarm R is also assigned a fixed code A1 or a code pair A1, BK. This assignment can be stored in a separate database. Thus, a computing node A that can be simply authenticated can also transmit only a representative identification of the alarm R to a complex node B and not necessarily the code A1. As a result, errors due to knowledge of the code A1 in the complex node B can be prevented. In this case, the complex node B has no information about the code A1 at all.
[0086] Therefore, first, the simply authenticated computing node A reads from the database the representative identifier assigned to the alert R and the code A1. This representative identifier is transmitted to the complex computing node B, where the audio signal assigned to the alert is determined, which audio signal at least includes the code A1 as a watermark. The computing node B is not allowed to access the database containing the code A1 and the representative identifier. In this case, the audio signal is pre-created in an authenticated environment and stored on the audio output system during or after its generation. In this case, the authenticated environment is suitable for creating audio output data for safety-critical applications in the automotive field, so that a high ASIL level (i.e., higher than the QM level) can be achieved. In the first computing process B1, an output signal Y including the audio signal with the code A1 is then generated. The output signal is then transmitted to a second computing process B2 independent of the first computing process B1. In the second computing process, the code A2 included in the output signal Y is then extracted. Then, the extracted or received code A2 is transmitted to the simply authenticated computing node A. In the simply authenticated computing node, the read code A1 is then compared with the code based on the received code A2 to verify whether the audio output system is functionally reliable.
[0087] Transmitting the output signal Y to the second computing process B2 independent of the first computing process B1 via the speaker-microphone path is particularly advantageous. Thus, it can be verified whether the audio output system is functionally reliable.
[0088] The audio signal that already includes the watermark as well as the associated representative identifier and the code A1 can also be advantageously provided to the audio output system subsequently by means of a software update, in particular an update provided by means of remote maintenance, i.e., the so-called over-the-air update.
[0089] In this case, such a functionally reliable audio output system X includes at least one sound transducer LS, a sound sensor MIC, a simply authenticated computing node A, a database, and a complex computing node B.
[0090] In a vehicle, in particular, the sound transducer and the sound sensor can also be configured in the form of decorative components. In addition, the spatial directional emission of sound waves can also be performed by means of a laser.
[0091] Although the present invention has been shown and described more specifically by preferred exemplary embodiments, the present invention is not limited to the disclosed examples. Those skilled in the art can arrive at its variants without departing from the scope of protection of the present invention as defined, for example, by the appended patent claims.
Claims
1. A method for operating a functionally reliable audio output system (X), the audio output system having a simply authenticated computing node (A) and a complex computing node (B), the method comprising the following steps: - generating, in the simply authenticated computing node (A), a code (A1) assigned to an alert (R); - transmitting the code (A1) to the complex computing node (B); - generating, in a first computing process (B1), an output signal (Y) having an acoustic watermark (W); - transmitting the output signal (Y) to a second computing process (B2) independent of the first computing process (B1); - ascertaining, in the second computing process (B2) independent of the first computing process (B1), a code (A2) contained in the output signal (Y); - transmitting the code (A2) to the simply authenticated computing node (A); and - verifying whether the audio output system is functionally reliable based on a comparison of the generated code (A1) with a code based on the received code (A2).
2. The method according to claim 1, characterized in that the step of - transmitting the output signal (Y) to a second computing process (B2) independent of the first computing process (B1); comprises the following steps: - transmitting the output signal (Y) by means of a sound transducer (LS); - receiving an acoustic signal (Z1) by means of a sound sensor (MIC), the acoustic signal comprising the output signal (Y) output by the sound transducer (LS); and the step of - ascertaining, in the second computing process (B2) independent of the first computing process (B1), a code (A2) contained in the output signal (Y); ascertaining the code (A2) contained in the output signal (Y) from the acoustic signal (Z1).
3. The method according to claim 1 or 2, characterized in that the method further comprises the following step: - transmitting a first control signal (A3) from the simply authenticated computing node (A) to the complex computing node (B) so as to cause a first signal (S) to be incorporated into the output signal (Y).
4. The method according to claim 3, comprising at least one of the following steps: - superimposing the generated code (A1) with a code (BK) known to the simply authenticated computing node (A) and characteristic of the signal (S); - generating the output signal (Y) from at least one of the acoustic watermark (W) and the first signal (S) or the second signal (M); and - transmitting a second control signal (A4) from the simply authenticated computing node (A) to the complex computing node (B) so as to activate a limiting stage (L) which can limit the signal level of the second signal (M).
5. The method according to claim 1 or 2, characterized in that the method further comprises the following step: - transmitting a third control signal (A5) from the complex computing node (B) to the simply authenticated computing node (A) so as to inform that the second signal (M) is included in the output signal (Y).
6. The method according to any one of the preceding claims, characterized in that the following steps are repeatedly executed: - In a second computing process (B2) independent of the first computing process (B1), the code (A2) contained in the acoustic signal (Z1) is known; And - The code (A2) is transmitted to the simply authenticated computing node (A); Wherein, in particular, the codes (A1, A1BK) are always present in the output signal (Y), and the code based on the received code (A2) is generated by statistically processing (H) the code (A2) that is repeatedly determined and transmitted to the simply authenticated computing node (A).
7. The method according to claim 6, Characterized in that The comparison of the generated code (A1, A1BK) with the code based on the received code (A2) gives a probability of positive verification, that is, there is a certain probability that the audio output system (X) is functionally reliable, and, At least one threshold is provided, and when this threshold is exceeded, a positive verification of functional reliability is determined, And when it is below this threshold, a negative verification or non-verification of functional reliability is determined, And / or, The comparison of the generated code (A1) with the code based on the received code (A2) gives a probability of negative verification, that is, there is a certain probability that the audio output system (X) is functionally unreliable, And, At least one threshold is provided, and when it is below this threshold, a negative verification of functional reliability is determined, And when it exceeds this threshold, a positive verification or non-verification of functional reliability is determined.
8. The method according to any one of the preceding claims, Characterized in that In the case of negative verification and / or non-verification, that is, in the case where the audio output system (X) is functionally unreliable, at least one of the following operations is performed: - Driving a simpler but reliable alternative audio output (BZ); - Switching the system to a reliable state; - Informing the driver of the existence of a system fault; - Checking based on the redundant characteristics of the audio output system (X); and - Compensating based on the redundant characteristics of the audio output system (X).
9. A functionally reliable audio output system (X) for performing the method according to any one of claims 1 to 8, the audio output system comprising a sound converter (LS), a sound sensor (MIC), a simply authenticated computing node (A), and a complex computing node (B).
10. The audio output system (X) according to claim 9, Characterized in that The first computing process and the second computing process (B2) independent of the first computing process (B1) are executed on the same physical computing node (B), wherein, in particular, the first computing process (B1) and the second computing process (B2) are separated from each other by at least one memory isolation technique.
11. A vehicle comprising the functionally reliable audio output system (X) according to any one of claims 9 and 10, the audio output system being used to perform the method according to any one of claims 1 to 8.
12. A computer program product comprising instructions which, when the program product is executed by an embedded system, cause the embedded system to perform the method according to any one of the preceding claims 1 to 8.
13. A data carrier on which there is stored a computer program product according to claim 12.
14. A method for operating a functionally reliable audio output system, the audio output system having a simply authenticated computing node and a complex computing node, the method at least comprising the following steps: - Reading into the simply authenticated computing node (A) a representative identifier assigned to an alert (R) and a code (A1) from a database; - Transmitting the representative identifier to the complex computing node (B); - Generating, in a first computing process (B1), an output signal (Y) having an acoustic watermark (W); - Transmitting the output signal (Y) to a second computing process (B2) independent of the first computing process (B1); - Learning, in a second computing process (B2) independent of the first computing process (B1), a code (A2) contained in the output signal (Y); - Transmitting the code (A2) to the simply authenticated computing node (A); and - Verifying whether the audio output system is functionally reliable based on a comparison of the read-in code (A1) with a code based on the received code (A2).
15. A functionally reliable audio output system (X) for performing the method according to claim 14, the audio output system comprising a sound transducer (LS), a sound sensor (MIC), a simply authenticated computing node (A), a database, and a complex computing node (B).