Method for ensuring time synchronization in a server ECU
By initializing a unique clock identifier in the vehicle network and sending a disguised time synchronization message, hiding the highest-level clock position, the time synchronization single point failure and attack problems are solved, network security and reliability are improved, and flexible software design that supports advanced vehicle functions.
Patent Information
- Application Number
- CN202080087221.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-20
- Filing Date
- 2020-12-17
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2040-12-17
AI Technical Summary
The existing time synchronization method cannot effectively protect the highest-level timing device from attacks, resulting in a single point of time synchronization failure in the vehicle network, affecting the safety of vehicle operation and the accuracy of data recording, and the existing protection mechanism is difficult to detect network configuration changes and attacks.
By initializing the unique clock identifier of the highest-level clock in a network device and sending additional time synchronization messages masquerading as the highest-level clock, hiding the location of the real highest-level clock, using shadow controllers and time correction mechanisms, ensuring the security and integrity of time synchronization.
Effectively prevent unauthorized attacks and time synchronization distortion, reduce system costs, improve the security and reliability of vehicle networks, support flexible software design and application, adapt to advanced functions such as autonomous driving, and do not require additional hardware investment.
Smart Images

Figure CN114830565B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication network having network devices that are synchronized with each other. Background Art
[0002] Ethernet technology is increasingly being used in vehicles, replacing older or proprietary data connections and data buses. At Layer 3 of the OSI layer model, Ethernet connections support a wide range of switching protocols to transfer data packets between transmitters and receivers. Higher protocol layers segment the data stream into packets, process communication between communicating systems, convert the data into a system-independent form, and ultimately provide functionality to the application.
[0003] Almost all Ethernet communication networks used in vehicles utilize time synchronization protocols, which provide a global network time base synchronized across all network devices. The popularity of time-synchronized network devices is expected to continue to increase in the future.
[0004] The IEEE 802.1AS standard provides such a time synchronization protocol. A master-slave clock hierarchy is established, starting with the so-called "best clock" (also called the grandmaster or grandmaster clock) in the network. This grandmaster clock provides the network's time base, to which all other network devices synchronize. This grandmaster clock is determined using the so-called Best Master Clock Algorithm (BMCA) and announced within the network. To this end, network devices supporting IEEE 802.1AS send announcement messages containing information about their internal clocks to other directly connected network devices. This information about the internal clocks provides information about the accuracy of the respective clocks, their reference or time base, and other properties that can be used to determine the best clock in the network. The recipient of such an announcement message compares the information received regarding the characteristics of its own internal clock with any messages received from other ports regarding the clocks of other network devices. If the other network device has better clock parameters, it accepts the clock of the other network device. After a short period of time, the best clock in the network is determined, and this best clock then becomes the grandmaster clock in the network. Time synchronization messages are broadcast from the grandmaster clock across the network. A network device that receives a time synchronization-related message does not simply forward the message, but corrects the time information for the delay time on the previously determined connection (through which the network device receives the time synchronization-related message from the directly connected network device) and for the internal processing time, and then retransmits the time synchronization-related message together with the corrected time information.
[0005] In a clock hierarchy based on IEEE 802.1AS and the Generic Precision Time Protocol (gPTP) defined therein, only a single network device provides the best clock for the entire network. Therefore, this network device controls and regulates the entire vehicle's time. All other network device clocks in the network are governed by this single clock. Some vehicle manufacturers even synchronize other standard networks, such as CAN, through this Ethernet time master, meaning that nearly all network devices in the vehicle are informed of their system time by the network device providing the highest-level timekeeping. Consequently, a single network device represents a single point of failure in the network or vehicle, and its failure or manipulation could have serious implications for the vehicle's operational safety. Thus, in vehicles with a high degree of driver assistance or (semi-)autonomous driving systems, for example, large amounts of sensor data captured within narrow time windows must be processed together to derive appropriate control signals for the vehicle's actuators. The most accurate possible time recording of sensor data can also be crucial for documentation purposes, such as when stored in log files that can be analyzed to reconstruct faults or operational errors. Insurance companies and law enforcement agencies are particularly interested in this latter aspect. Therefore, the secure and synchronized provision of time information is crucial.
[0006] Current time synchronization methods and protocols do not provide an easy way to protect the highest-level timekeeping device. Each network device can easily infer which network device is the highest-level timekeeping device based on time synchronization messages sent as simple multicast Ethernet frames to multiple or all network devices in the network. Protection mechanisms at higher protocol layers, such as IPSEC or TLS, do not yet function at this level. The MAC address of the highest-level timekeeping device contained in time synchronization messages allows attackers to easily identify network devices and initially locate them as particularly worthwhile targets, which they can then focus their attacks on.
[0007] Several methods are known in the art for detecting changes to the configuration or structure of a communications network using network time synchronization. Unauthorized changes to the network configuration can include, for example, inserting network equipment in preparation for an attack that intercepts messages for analysis and, if necessary, retransmits the altered messages. This can be used to prevent or at least undermine secure and proper operation.
[0008] DE 10 2014 200 558 A1 describes secure network access protection via authenticated timekeeping. This document describes how authentication protocols are intended to ensure timekeeping, determine delay times, and / or use additional protocols to verify the integrity of time synchronization messages. However, this application cannot detect parameter changes or whether the quality of the clock parameters is actually correct.
[0009] DE 10 2012 216 689 B4 describes a method for monitoring an Ethernet-based communication network in a motor vehicle by monitoring the communication connection between two network nodes connected via the communication network, and a correspondingly configured network node. In this case, the method provides for bidirectional and cyclic measurement of the delay time of signals between the network nodes of the communication network, and evaluation of changes in the signal delay time. Furthermore, to detect this type of attack, the application proposes monitoring the delay time of time-synchronization-related messages within the communication network. Additional network devices connected between two network devices that intercept and forward messages will inevitably alter the message delay time, even if the forwarded messages remain unchanged.
[0010] DE 10 2017 219 209 A1 checks the plausibility of time synchronization messages. This document discloses a method for detecting incorrect timestamps in Ethernet messages, which involves the following steps: receiving an Ethernet message containing a timestamp via a control unit of a motor vehicle; determining the time difference between the global time of the timestamp and the local time of the control unit's clock; and detecting the timestamp of the Ethernet message as incorrect. If the timestamp is detected as incorrect, the global time of the timestamp is replaced by the local time of the control unit's clock.
[0011] There are also known methods that use time synchronization protocols to detect when a new control device has been inserted as a bug in a vehicle's electrical system. However, this method cannot detect whether an attack / error has occurred on a known control unit.
[0012] DE 10 2015 209 047 A1 discloses a method for providing time synchronization in nodes connected to an Audio Video Bridging (AVB) Ethernet communication network. The method includes the following steps: receiving static notification messages from neighboring nodes and forming a static superlative timer table; reselecting a superlative timer by referring to the static superlative timer table when a synchronization message timer expires; and updating the static superlative timer table based on the reselection of the superlative timer. This method can quickly schedule synchronization in the Audio Video Bridging (AVB) Ethernet communication network and minimize network load.
[0013] The optimal clock, also known as the superlative timekeeping device, represents a single point of failure. If this single control unit, controller, or implementation is compromised, the attacker could manipulate the entire time in the vehicle. This could affect the execution of actions, the fusion of sensor data, and the storage of log data, for example, potentially leading to devastating consequences ranging from system failure to system crash. Synchronization messages are sent via multicast and can therefore be received by many, potentially all, subscribers. This represents a very serious threat in terms of automation methods and the safety requirements of ISO 26262.
[0014] However, to date, no known application has addressed the question of how to protect top-level timing devices from attacks using simple means without losing basic compliance with the IEEE 802.1AS standard.
[0015] Ethernet-based time synchronization represents a single point of failure in the vehicle, since firstly there is only one time master and secondly the exact location of the top-level timing device can be identified at any point in the network. Summary of the Invention
[0016] It is therefore an object of the present invention to specify a method for ensuring time synchronization in a vehicle electrical system and a network device implementing the method.
[0017] This object is achieved by the method specified in claim 1 and the network device specified in claim 5. Embodiments and further developments are specified in the respective dependent claims.
[0018] A method for ensuring time synchronization in a server ECU, wherein the time synchronization is performed according to a time synchronization standard, the method comprising: initializing time synchronization of components of the server ECU; storing a unique clock identifier of a highest-level clock determined during the initialization in each component of the server ECU that does not provide a previously determined highest-level clock; identifying a shadow controller selected from a component of the server ECU; sending a synchronization message; querying the shadow controller for the time of issuance; inserting the time in a subsequent message by the controller forming the highest-level clock and resending the time; sending (206) additional time synchronization-related messages by a selected network device that does not provide a previously determined highest-level clock, wherein the time information sent in the additional time synchronization-related messages and the clock parameters and domain numbers that are important for determining the best clock with the help of BMCA are consistent with or similar to the time information and clock parameters and domain numbers of the previously determined highest-level clock, wherein these additional time synchronization-related messages contain a unique clock identifier corresponding to the identifier of the corresponding selected network device.
[0019] It is particularly advantageous if the time synchronization is initialized in a secure environment where attacks can be ruled out with a sufficiently high probability, for example at the end of the production process for a product containing a secure network. For example, in all types of vehicles, a single initialization may be sufficient, especially if the network or its configuration is not changed again after initialization.
[0020] The method according to the present invention further includes sending additional time synchronization-related messages by a selected network device that does not provide the previously determined grandmaster clock, wherein the time information, clock parameters, and field numbers that are important for determining the best clock using BMCA sent in these additional time synchronization-related messages are consistent with or similar to the time information, clock parameters, and field numbers of the previously determined grandmaster clock. However, these additional time synchronization-related messages contain a unique clock identifier that corresponds to the identifier of the corresponding selected network device. According to the IEEE 802.1AS standard, the clock parameters that are important for performing BMCA include, among other things, the values of the variables priority1, priority2, clockClass, clockAccuracy, offsetScaledLogVariance, and timeSource. Therefore, to anyone monitoring network traffic, each of the additional time synchronization-related messages sent by the selected network device appears to originate from the grandmaster clock, just like the time synchronization-related messages from the grandmaster clock determined during initialization, meaning that an observer sees a large number of grandmaster clocks present in the network.
[0021] The selected network devices preferably cyclically transmit their additional time synchronization-related messages corresponding to the time synchronization-related messages of the grandmaster clock determined during initialization. Thus, each of the selected network devices represents a pseudo-grandmaster clock that behaves as if it were the only and best clock in the network. To an external observer, the pseudo-grandmaster clock cannot be distinguished from the grandmaster clock determined during initialization, despite the fact that the time synchronization tree differs in how time synchronization-related messages are propagated within the network, because the additional time synchronization-related messages are transmitted using the same field number.
[0022] Once the unique clock identification of the grandmaster clock determined during initialization has been sent to all network devices, the selected network devices can start sending additional time synchronization related messages. However, it is also possible to send additional time synchronization related messages only when the first time synchronization of all network devices in the network has been completed.
[0023] All network devices follow the standard and forward each of the additional time synchronization related messages in the same manner as the time synchronization related messages sent by the grandmaster clock determined during initialization. This means that time synchronization related messages are sent to other directly connected network devices after the time information has been corrected for delay times on the receiving link and internal processing times.
[0024] These network devices are connected to each other via physical interfaces. Time synchronization-related messages are sent via the logical ports defined for the interfaces, meaning that a point-to-point connection for time synchronization exists between two network devices even when the physical transmission medium is shared. In this specification, the term interface is used synonymously with the term port, unless the context indicates otherwise.
[0025] For an observer who starts listening to the network traffic only after initialization has been completed, the method according to the invention makes it quite difficult, or even impossible, to identify the grandmaster determined during initialization.
[0026] The selection of network devices that, in addition to the grandmaster clock, also transmit their own time synchronization-related messages and thereby masquerade as the grandmaster clock may include a check to determine whether the network device is critical to the operation of the network or the system comprising the network and, therefore, should not be used as bait for a possible attack. Critical network devices are, for example, network devices that interconnect multiple network segments (such as switches, bridges), or network devices that implement functions that other network devices cannot perform (such as domain computers for automated or autonomous driving or other safety-related functions). Preferably, such network devices are not selected. The selection may also involve a check to see whether the network device is configured to perform general-purpose functions or software that can also be performed by another network device within the network and can be relocated to one of these other network devices accordingly (if necessary, for example, if an attack on the network device is detected). Preferably, such network devices may be selected to transmit their own time synchronization-related messages, as the selected network devices may be network devices located at the edge of the network and / or providing non-safety-related functions and isolated from the rest of the network, such that they will not cause significant failures if an attack is detected. The same applies to network devices that are only connected to a few other network devices, such as network devices that have only one port and, accordingly, only one neighbor and can therefore be more easily isolated. Preferably, the selection of network devices to send their own time synchronization-related messages can also involve network devices that have particularly strong security mechanisms and are therefore more resilient to attacks. In a simple case, the selection of network devices to send their own time synchronization-related messages can include reading a flag that was set when the network device was manufactured or when the network device was configured to operate in the network. Other features for determining whether a network device can be configured to send additional time synchronization-related messages can be determined by appropriate capability queries.
[0027] In a network device that does not provide a grandmaster clock determined during initialization, the method according to the present invention further comprises receiving a time synchronization-related message on a first network interface and checking to determine whether a clock identification transmitted in the time synchronization-related message is consistent with a stored clock identification of the grandmaster clock determined during initialization. If these clock identifications are consistent, synchronizing the local clock using the time information received in the time synchronization-related message.
[0028] A further development of the method according to the present invention includes monitoring the time information transmitted in additional time synchronization-related messages for discrepancies relative to the time information transmitted in a time synchronization-related message containing the clock identification of the grandmaster clock determined during initialization. As long as the network device is synchronized with the grandmaster clock determined during initialization, the time information based on which this comparison is made can also be provided by the clock of the network device. If a discrepancy in time information is confirmed, the additional time synchronization-related message containing the associated clock identification of the confirmed discrepancy can be blocked, i.e., not forwarded to the network. If the discrepancy is the result of an attack on the network device, an attacker monitoring the network at only one point will not notice this blocking because the time synchronization-related message has not been acknowledged by the recipient. Alternatively, the discrepant time information transmitted in the received additional time synchronization-related message can be corrected and forwarded based on time information received from the grandmaster clock determined during initialization. The basis for the time correction can also be a local clock synchronized with the grandmaster clock determined during initialization. Alternatively, or in addition, a corresponding message can be sent to a previously acknowledged network device of the network, which is configured to initiate and / or control appropriate protective measures. Suitable protective measures may include, for example, isolating the network device that is sending the discrepant time information, or individual flows or messages from the network device, from the rest of the network, or rebooting the network device in question.
[0029] One embodiment of the method according to the present invention includes: sporadically or cyclically sending time synchronization-related messages having time information that differs from the actual time by the grandmaster clock determined during initialization; and monitoring additional time synchronization-related messages sent by other network devices to see whether these additional time synchronization-related messages accordingly reflect the differing time information. If this is not the case - the tolerance that is inevitable during synchronization can be ignored, then there may be a fault or attack, and the network device providing the grandmaster clock determined during initialization can send a corresponding message to a previously confirmed network device of the network, which is configured to initiate and / or control appropriate protective measures, such as isolating the network device that does not reflect the change in the differing time information from the rest of the network. If the additional time synchronization-related messages sent by the other network devices reflect the changed time information, then it can be considered that the behavior of all pseudo-grandmaster clocks complies with the rules.
[0030] A computer program product according to the invention comprises instructions which, when executed by a computer, cause said computer to carry out one or more embodiments and further developments of the method described above.
[0031] Controllers that have implemented the time master functionality need to take care of certain interrupts and also reserve resources for this. However, the present disclosure enables the use of almost any controller, which in turn reduces system costs and resources.
[0032] The effects provided by this method—protection against unauthorized attacks on time synchronization, communication distortion, and device swapping—can also be achieved in other ways, for example, using hardware encryption (or authentication) with a higher level of security. This method allows for cheaper implementation of protection mechanisms (useful for meeting ISO 26262 requirements) and also reduces system costs. This method can even be introduced later via OTA.
[0033] In contrast, in vehicles, it is often uneconomical to purchase sufficient hardware equipment for seamless encrypted communication for all subscribers connected to the network. The described method requires significantly fewer hardware resources (can be implemented using existing implementations) and thus significantly increases the security level without necessarily being associated with higher production costs for the network or the devices connected to it.
[0034] Such a method may in particular be implemented in the form of software that can be distributed as an update or upgrade to existing software or firmware of subscribers in the network and in this respect is a standalone product.
[0035] The present invention advantageously improves the quality of software-based applications (e.g., automated driving)—in particular, without requiring additional financial expenditure. When using the newly introduced Ethernet protocol in automobiles, it is desirable to utilize simple technologies and mechanisms of a given technical nature without requiring expensive implementations or additional hardware. The network system according to the present invention offers improvements in terms of cost and reliability.
[0036] Advantageously, the present invention makes it possible to significantly and very simply increase the security of vehicle networks, particularly without requiring additional financial expenditure. When using the newly introduced Ethernet protocol in automobiles, it is necessary to utilize simple technologies and mechanisms of a given technical nature without the need for expensive implementations or other additional hardware. Early analysis of communication paths allows for earlier detection of attacks and abnormal behavior, thus allowing vulnerabilities and errors to be identified before vehicle delivery. The network system according to the present invention is improved in terms of cost and reliability. The present invention also clearly defines the testability of the system, which allows for savings in testing costs. Furthermore, the present invention provides transparent security functions.
[0037] Today, most applications are implemented, customized and adapted for only one vehicle type or model. The proposed approach allows for a more flexible design of the software and for generating value-added services from the underlying system without having to program them permanently into the software in advance. Today, we practically have to assume the worst-case scenario, which consumes resources (money) and loses quality. The present invention allows software developers and software architects to provide software / applications that can be tailored more flexibly and precisely to the requirements of the application. Incorporating the cited approach into the software allows for optimizations within the control unit. This means that the software can be designed to be more independent of the platform and vehicle type.
[0038] New technologies can no longer be suppressed in cars. Protocols like IP, AVB, and TSN have thousands of pages of specifications and test suites. The controllability of these new protocols in cars is not immediate.
[0039] The new approach can be integrated into existing networks without disrupting existing equipment and, because existing protocols can be used, no standards are violated.
[0040] The use of this method will also be possible for other communication systems with clock synchronization components and embedded systems.
[0041] The computer program product can be stored on a computer-readable medium or data carrier. In a physical embodiment, the data carrier can be, for example, a hard disk, a CD, a DVD, a flash memory, etc. However, the data carrier or medium can also include a modulated electric, electromagnetic or optical signal that can be received by a computer with the aid of an appropriate receiver and stored in the computer's memory.
[0042] In addition to a microprocessor, non-volatile and volatile memory, and a timer, at least one network device according to the present invention includes at least one physical communication interface. The components of the network device are communicatively connected to each other via one or more data lines or data buses. The memory of the network device contains computer program instructions that, when executed by the microprocessor, configure the network device to implement one or more embodiments of the method described above.
[0043] The present invention protects the superordinate timing device by masking or hiding previously easily detectable traces of the superordinate timing device with numerous false traces, making it more difficult for an attacker to determine the superordinate timing device's location within the network. An attacker is then unable to carry out an attack, or at least requires considerable time. Attacks that do not accidentally and immediately affect the superordinate timing device can be detected, and appropriate defensive measures can be taken while the system remains synchronized with the required accuracy.
[0044] The method according to the present invention can be implemented using existing network equipment. If necessary, only the software or state machine for receiving and processing time synchronization-related messages needs to be adapted so that only the time synchronization-related messages of the grandmaster clock determined during initialization are used to synchronize the clocks, while still forwarding additional time synchronization-related messages rather than simply deleting them. Consequently, implementing the method requires only minimal additional cost (if any). Existing systems can also be configured to implement the method using appropriately modified software. Another advantage of the method according to the present invention is that the specific underlying hardware platform is irrelevant, as long as the platform supports synchronization according to the IEEE 802.1AS standard. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The present invention will be explained below by way of example with reference to the accompanying drawings, in which:
[0046] Figure 1 shows an illustrative block diagram of a network synchronized according to a time synchronization standard,
[0047] Figure 2 Shows the number of Figure 1 A block diagram of the network,
[0048] Figure 3 An illustrative block diagram of a network which is synchronized according to a time synchronization standard and which implements the method according to the invention is shown.
[0049] Figure 4 Shows the number of Figure 3 A first representation of the block diagram of the network,
[0050] Figure 5 Shows the number of Figure 3 The second representation of the block diagram of the network is,
[0051] Figure 6 shows a schematic flow chart of aspects of the method according to the invention,
[0052] Figure 7a A schematic block diagram of a network device for implementing the method is shown,
[0053] Figure 7b A schematic block diagram of a network device implementing the method is shown, the schematic block diagram showing a number of components individually and the formation of time information as an overall solution,
[0054] Figure 8 It shows that the synchronization message contains the address of the highest-level timer.
[0055] In the drawings, the same or similar elements may be referred to by the same reference numerals. DETAILED DESCRIPTION
[0056] Figure 1 An illustrative block diagram of a server ECU 100 synchronized according to a time synchronization standard is shown, comprising a plurality of network devices 102, 104, 106, and switches 108, 110, and 112, all synchronized with a first grandmaster clock. In this case, controller 102 and switch 108, controller 102 and switch 104, controller 104 and switch 110, controller 104 and switch 106, and controller 106 and switch 112 are each interconnected via a bidirectional communication connection. Access is via Ethernet or another bus, such as MDIO or SPI. Controllers 102, 104, and 106 are also connected to other network devices (not shown) via bidirectional communication connections. Each component 102 to 112 of the server ECU has a timer that can be synchronized according to the time synchronization standard. After executing the method specified in the standard, controller 102 is established as the grandmaster clock for the entire system, i.e., time synchronization-related messages are sent from controller 102 to the network. In this case, controller 102 sends a time synchronization-related message, for example, to controller 106 connected to it, as well as to another network device (not shown in the figure). The direction of the time synchronization-related message is indicated in each case by a white-filled arrow shown next to the communication connection. Switch 108 corrects the time information received from controller 108 for the previously determined delay time on the communication connection to controller 102 and the time required for correction and forwarding in switch 108, and resends the correspondingly modified time synchronization-related message to the other network device (not shown in the figure). In addition to the corrected time information, the time synchronization-related message also contains information about the system's grandmaster clock (in this case, controller 102). Controller 104 proceeds accordingly and again sends the time synchronization-related message, corrected for the applicable delay time, to switches 110 and 102, as well as to the other network device (not shown in the figure). Similarly, network device 102 sends the corrected time information to switch 108. Due to the corresponding correction of the time information before forwarding, all timers in the network devices are synchronized to the time of the grandmaster clock, except for any remaining residual inaccuracies caused by individual differences in the correction of the time information before forwarding. The grandmaster clock cyclically sends time synchronization related messages to the network and then redistributes these messages as described above.
[0057] Figure 1The X shown in the figure represents an attacker who wishes to discover which network device is providing the grandmaster clock by snooping network traffic. Snooping is indicated by an arrow pointing away from the triangle with the exclamation point. Because each time synchronization-related message contains a clock identifier and the corresponding MAC addresses of the sender and receiver, an attacker can easily identify network device 102 as the grandmaster clock in the network and select it as a target for attack. The arrow indicating snooping is intended to be understood as an example only—snooping and attacks can occur at any point in the network.
[0058] In the method, the present disclosure proposes to hide from the attacker the Figure 1 The disclosure of the present invention proposes that the timestamps are unconditionally (and most importantly) robust, or originate from the same node and are not generated by the controller or controller software where the sender address is used.
[0059] Figure 1 A method for solving the above-described problem is shown. A server ECU 100 is shown, in which multiple controllers 102, 104, 106 and multiple Ethernet switches 108, 110, 112 are integrated. Various time synchronization software (such as PTP, gPTP, or 802.1AS) runs on each of these controllers. One of these controllers is the highest-level timing device 102. Although the highest-level timing device sends a time synchronization message A containing its sender's address, it obtains the actual timestamp or reference time from the switch module 108. The time synchronization message D transmitted to sensors and other control devices via the network always includes the ID (MAC address or IP address) from the controller 102, but obtains the timestamp from the switch (which needs to be protected).
[0060] Since the time synchronization messages D are sent by multicast, they can also be received and interpreted quite easily by foreign or manipulated ECU / SW 102, 104, 106. The address of the highest level timing device is in the message, e.g. Figure 8 As indicated in .
[0061] If this controller 102 is now compromised, the actual best clock 102 is not compromised, and attacker X does not know this. The controllers 102, 104, 106 or the software that performs time synchronization can now be changed relatively easily, and synchronization can continue seamlessly using the same infrastructure (i.e., the same switches 108, 110, 112). Therefore, there will be no jump in time. The entire control unit itself is not directly vulnerable to network-level attacks because it is composed of many units.
[0062] The method 200 can be always active or triggered by a specific use case. The motivation for doing so can be to change to a higher automation level, security level if there is online access or if an ongoing attack is suspected.
[0063] Now determine the controller from which to extract the actual time. This controller can be a switch 108, 110, 112 or another controller 102, 104, 106, ideally with a direct connection. Access is via Ethernet or another bus such as MDIO or SPI.
[0064] The time synchronization software in controller 102 is now started. To this end, a synchronization message is sent to shadow controller 108, i.e., the switch from which the timestamp is obtained in the form of a synchronization message. Transmitting this message D by the "shadow controller" switch 108 causes the hardware timestamp to be written to a register at the output, for example, and the message is sent without modification. In this case, the sender address of controller 102 is used, not that of switch 108.
[0065] The controller 102 then queries the register of the corresponding port to the shadow controller 108 via a hardware line or Ethernet or SPI and obtains the time so that it can be inserted into the newly generated subsequent message. The message is then sent to the shadow controller 108 (for each port) and sent unchanged.
[0066] Even though the actual controller 102 has now generated the messages in software and assembled the frames, these messages do not originate from said controller.The synchronization of the vehicle electrical system can be performed with constant accuracy.
[0067] Figure 2 Shown are the values from the Figure 1 Block diagram of server ECU 100. After identifying controller 106 as the grandmaster clock, an attacker could attempt to manipulate the timer itself or the time synchronization-related messages sent by controller 106. Due to synchronization, all network devices will accept the manipulated time information, and after a short period of time, all controllers of the server ECU will be synchronized to an incorrect time (indicated by the shading of the blocks representing the controllers). In the event of such an attack, it is prescribed to use another switch to obtain time information.
[0068] Figure 3 An illustrative block diagram of a network 100 is shown that is synchronized according to the IEEE 802.1AS standard and implements the method according to the present invention. The controller and switch of the server ECU are connected to the Figure 1 and Figure 2 The controllers and switches correspond to each other, and like Figure 1As in Figure 1, network device 112 has been defined as the grandmaster clock. Switch 112 sends applicable time synchronization-related messages to the network, which are forwarded by other network devices after the time information has been corrected according to the standard, as indicated by the white-filled arrows. However, according to the present invention, network devices are configured to send additional time synchronization-related messages to the network after time synchronization has been initialized. Controller 102, switch 110, and another network device (not shown) each send additional time synchronization-related messages containing clock parameters and time information that are equal to or correspond to those of the grandmaster clock, but with their own unique clock identifiers. Arrows representing time synchronization-related messages originating from these additional grandmaster clocks are shaded differently accordingly. An attacker would see a large number of time synchronization-related messages sent by different controllers or switches, each of which would appear to originate from the grandmaster clock and contain the same synchronized time information. This makes it quite difficult for an attacker to determine which network device or controller is actually providing the grandmaster clock. The selection of the controller that sends the additional time synchronization-related messages should take into account that the controller should be as easily isolated as possible or particularly well-suited to attack.
[0069] Figure 4 Shows the number of Figure 3 Figure 1 is a first representation of a block diagram of the server ECU 100. An attacker has targeted the switch 108 and changed the time information included in the time synchronization related messages of this network device, which is indicated by the bold diagonal shading of the clock symbol, the box representing the network device and the arrow representing the time synchronization related message with an indicated direction away from the network device. The controller 102 is still synchronized to the time provided by the switch 112 and detects that the time synchronization related messages from the network device 108 include incorrect time information. Therefore, the switch is a "shadow controller". For example, the controller 102 can now correct the time information included in the time synchronization related messages from the switch 108 based on its own time (which is synchronized to the "real" highest level clock) and can send the corrected time information to the network. This is indicated by the thinner diagonal shading of the arrow. However, as Figure 5 As shown in , the network device 102 may also ignore time synchronization related messages from the switch 108 and not resend them to the network.
[0070] Figure 6A schematic flow chart illustrating aspects of a method 200 according to the present invention is shown. In step 202, time synchronization is initialized in a generally known manner (e.g., by executing a best master clock algorithm), followed by storing the unique clock identifier of the grandmaster clock determined during initialization in step 204. In step 203, a shadow controller is identified. Step 204 can be performed in each controller of a server ECU. In step 206, selected components of the server ECU that do not provide the previously determined grandmaster clock send additional time synchronization-related messages according to the present invention.
[0071] At this point, the method can proceed in different ways. Typically, in step 208, time synchronization-related messages from the grandmaster clock determined during initialization, as well as the additional time synchronization-related messages sent by the selected components in step 206, are received by nearly all components. Controllers and switches that themselves send time synchronization-related messages logically do not receive their own time synchronization-related messages. In step 210, each network device checks whether the received time synchronization-related message originates from the grandmaster clock determined during initialization, which is designated as switch 108. If so, i.e., the "yes" branch of step 210, then in step 212, the controller synchronizes its own timer so that the delay on the receiving connection is corrected before step 214. In step 213, a synchronization message is sent. In step 215, the shadow controller (switch) is queried for the outgoing time, and in step 216, this time is inserted in the subsequent message, and the shadow controller or switch 102 retransmits.
[0072] If the additional component is directly connected to the controller, then for step 216, the controller sends a message to the adjacent network device having the Figure 8 The time synchronization related message includes time information of the setting content, and the time information may be corrected for the internal delay time in step 214.
[0073] Additionally, it is also possible to perform a monitoring of the discrepancy in step 220 and to prevent retransmission in step 222. The time information can then be corrected in step 224 and the message D can be sent to the other network devices in step 226.
[0074] If the time synchronization related message does not originate from the grandmaster clock determined during initialization, the controller corrects the received time information for delays on the receiving connection and known internal delays in step 214 and sends a time synchronization related message containing the corrected time information to the neighboring component in step 216.
[0075] Furthermore, a check may be performed in step 220 to determine whether the time information received in the additional time synchronization-related message differs from the time information transmitted in the time synchronization-related message containing the clock identification of the grandmaster clock determined during initialization. If this is not the case, no further action is required. However, if a discrepancy is detected that cannot be explained by unavoidable tolerances during synchronization, forwarding of the additional time synchronization-related message may be blocked in step 222. Alternatively, in step 224, the discrepant time information may be corrected based on the time information of an internal clock synchronized to the grandmaster clock determined by the shadow controller during initialization, and then, in step 216, the time information may be retransmitted after the corrected delay time and delay. Alternatively, or in addition, in step 226, a message may be sent to a previously identified switch or controller of the server ECU, which is configured to initiate and / or control protective measures.
[0076] FIG7 shows an exemplary block diagram of a network device 400 configured to perform a method according to the present invention. In addition to a microprocessor 402, the network device 400 includes volatile and non-volatile memories 404 and 406, two communication interfaces 408, and a synchronizable timer 410. The components of the network device are communicatively coupled to one another via one or more data connections or data buses 412. The non-volatile memory 406 contains program instructions that, when executed by the microprocessor 402, implement at least one embodiment of the method according to the present invention.
[0077] Figure 8 The invention describes how the address of the top-level timer is formed together with the synchronization message and what information is included in the synchronization message. Furthermore, in the event of an attack, identifying the shadow controller (108, 110, 112) allows communication to be transferred to other controllers (102, 104, 106). This allows detection of whether the top-level timer is under attack. If so, the controller is changed while retaining the shadow controller. Despite the attack, the network and sensors are not restricted and no time jump occurs.
[0078] List of reference numerals:
[0079] 100 Vehicle Network
[0080] 102 SOC, μP or μC
[0081] 104 SOC, μP or μC
[0082] 106 SOC, μP or μC
[0083] 108 Switch
[0084] 110 Switch
[0085] 112 switches
[0086] 200 Methods
[0087] 202 Initialization
[0088] 203 Identifying Shadow Controllers
[0089] 204 Storage
[0090] 206 Send
[0091] 208 Receive
[0092] 210 Check clock logo
[0093] 212 Start time synchronization
[0094] 213 Send synchronization message
[0095] 214 Correction Time
[0096] 215 Query the shadow controller (switch) for the sending time
[0097] 216 Insert the time in the subsequent message and resend
[0098] 220 Monitoring Differences
[0099] 222 Resend Blocked
[0100] 224 Correction time information
[0101] 226 Send Message
[0102] 400 Network Equipment
[0103] 402 Microprocessor
[0104] 404 RAM
[0105] 406 ROM
[0106] 408 Communication Interface
[0107] 410 Timer / Clock
[0108] 412 bus
[0109] 500 Ethernet header
[0110] 510 PTP message
[0111] 511 The address of the highest level timekeeping device
[0112] 512 Timestamp
[0113] 520 FCS。
Claims
1. A method (200) for ensuring time synchronization in a server ECU (100), wherein: Time synchronization is performed according to a time synchronization standard. The method includes: - initializing (202) time synchronization of components (102, 104, 106, 108, 110, 112) of the server ECU (100); - storing (204) a unique clock identification of the grandmaster clock determined during initialization (202) in each of the components (102, 104, 106, 108, 110, 112) of the server ECU (100) that does not provide a previously determined grandmaster clock; - identifying a shadow controller selected from a component (102, 104, 106, 108, 110, 112) of the server ECU (100); - Send synchronization message (213); - Query the shadow controller for the issuance time (215); - inserting the time in the subsequent message by the controller forming the grandmaster clock and resending the time (216); - sending (206) additional time synchronization related messages by selected network devices that do not provide the previously determined grandmaster clock, wherein the time information sent in the additional time synchronization-related message, as well as the clock parameters and field numbers that are relevant for determining the best clock by means of the best master clock algorithm, are identical or similar to the time information, clock parameters and field numbers of the previously determined grandmaster clock, The additional time synchronization related message contains a unique clock identifier corresponding to the identifier of the corresponding selected network device.
2. The method (200) of claim 1, further comprising: In a network device that does not provide the grandmaster clock determined during initialization (202): - receiving (208) a time synchronization related message on the first network interface; - checking (210) whether the clock identification transmitted in the time synchronization related message coincides with the stored clock identification of the grandmaster clock determined during the initialization (202) and, if this is the case, correcting (214a) the time information received in the time synchronization related message by a delay time determined in accordance with IEEE 802.1AS and synchronizing (212) the local clock by using the time information received in the time synchronization related message.
3. The method (200) of claim 2, further comprising: If a network device has two or more interfaces that connect to other network devices, then: - correcting (214a, 214b) time information received in time synchronization related messages according to a delay time determined according to IEEE 802.1AS and / or device internal delay; and - sending (216) the correspondingly corrected time synchronization related message via the one or more second network interfaces.
4. The method (200) according to any one of claims 1 to 3, further comprising: - receiving (208) a time synchronization related message on the first network interface; - monitoring (220) the time information transmitted in the additional time synchronization-related messages with respect to differences relative to the time information transmitted in the time synchronization-related messages containing the clock identification of the grandmaster clock determined during the initialization (202); as well as - preventing (222) additional time synchronization related messages containing clock identifications of network devices that have been identified as discrepant; or - correcting (224) the discrepant time information before forwarding based on the time information received from the grandmaster clock determined during initialization; and / or - sending (226) a message to a previously identified network device of the network, the previously identified network device being configured to initiate and / or control protective measures.
5. The method (200) according to any one of claims 1 to 3, wherein: The grandest clock determined during initialization (202) sporadically or cyclically sends time synchronization-related messages whose time information differs from the actual time, wherein the network device providing the grandest clock determined during initialization (202) monitors (220) additional time synchronization-related messages sent by other network devices in the following respects, i.e., whether these additional time synchronization-related messages respectively reflect the difference in time information, wherein, if this is not the case, the network device providing the grandest clock determined during initialization sends (226) a corresponding message to a previously confirmed network device of the network, which is configured to initiate and / or control protection measures.
6. A network device (400) comprising a microprocessor (402), a volatile memory and a non-volatile memory (404, 406), a synchronizable timer (410), and at least one communication interface (408) communicatively coupled to one another via one or more data lines or a data bus (412), wherein: The network device (400) is configured to perform the method according to one of claims 1 to 5.
7. A computer program product comprising instructions which, when a computer executes the program, cause the computer to carry out the method (200) according to one of claims 1 to 5.
8. A computer-readable medium having stored thereon the computer program product according to claim 7.
9. A vehicle comprising a network having a plurality of network devices (400) according to claim 6.
Citation Information
Patent Citations
Method for monitoring an Ethernet-based communication network in a motor vehicle
DE102012216689B4
Secure network access protection via authenticated time measurement
DE102014200558A1
Method and apparatus for providing time synchronization in an in-vehicle Ethernet communication network
DE102015209047A1
Method for detecting a faulty timestamp of an Ethernet message and control unit for a motor vehicle
DE102017219209A1
Self-adaptive clock synchronous system
CN102684808A