Method for checking the validity of sensor data in an Ethernet vehicle network
Through the IEEE 802.1AS protocol and PTP method, the propagation time and medium type are determined, the timestamp difference is calculated, and the message is transmitted using dynamic key encryption. This solves the problem of insufficient timestamp verification in the vehicle network, improves the synchronization and fusion accuracy of sensor data, and enhances the safety and reliability of the vehicle.
Patent Information
- Application Number
- CN202080087210.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-20
- Filing Date
- 2020-12-16
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2040-12-16
AI Technical Summary
In existing technologies, the timestamp verification scheme in vehicle networks is insufficient, resulting in the inability to reliably handle timestamp mismatches during sensor data fusion, which may affect the safe operation of the vehicle.
Through the IEEE 802.1AS protocol and PTP method, the propagation time, transmission medium type and clock generator speed are determined, the timestamp difference is calculated, and the transmission message is encrypted using a dynamic key to ensure the accuracy and security of time synchronization.
It improves the synchronization and fusion accuracy of sensor data, enhances the security and reliability of the vehicle network, reduces hardware requirements and system load, and reduces costs.
Smart Images

Figure CN114846752B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for checking the validity of sensor data Background Art
[0002] Automakers (OEMs) and Tier 1 suppliers in the automotive industry are preparing for the next generation of architectures for vehicle controllers, or electronic control units (ECUs). One development is the so-called "zone-oriented architecture," in which control devices are grouped into zones, such as the right front door zone. This differs from previous architectures in that controllers are located in specific physical or spatial locations to optimally capture data from sensors positioned there. Thus, for example, a control unit collecting data from sensors in the right front door could be located in the right front door zone.
[0003] It is also contemplated to localize or distribute software execution for features and applications to other controllers and processors. This localization or distribution can be part of optimization and can also be used in the event of errors or failures (e.g., of a control device). This localization or distribution is referred to as dynamic migration or simply migration. It is expected that large-scale production of dynamic software migration to other control devices / processors within the vehicle will soon be possible.
[0004] Ethernet is the preferred network for connecting control devices in a network. Ethernet technology is becoming increasingly popular in the electrical systems of vehicles and supplier products. Using Ethernet technology requires efficient synchronization concepts.
[0005] Existing Ethernet systems can use implementations of the IEEE 802.1AS time synchronization standard. Two variants that have garnered particular attention are 802.1AS-Rev Select and 802.1AS-Rev Time Domain, the latter being a mandatory requirement of the former. Other protocols beyond the physical transport standard are Ethernet AVB and its successor, Ethernet TSN. Ethernet AVB has already been introduced into mass production in automobiles. An important substandard of Ethernet TSN and AVB is the IEEE 802.1AS time synchronization standard, which relies on the main IEEE 802.1 standard for higher-layer LAN protocols (bridging). Both standards use the IEEE 1588 Precision Time Protocol (PTP) to establish a common time base in Ethernet networks.
[0006] At Layer 3 of the OSI layer model, Ethernet connections support a wide range of switching protocols for transmitting data packets between transmitters and receivers. In higher protocol layers, data streams are segmented into packets, processes are communicated between the communicating systems, data is converted into a system-independent form, and finally, functionality is provided to the application.
[0007] Almost all Ethernet communication networks used in vehicles utilize protocols related to time synchronization, which provide a global network time base synchronized across all network devices. The popularity of time-synchronized network devices is expected to continue to increase in the future.
[0008] The IEEE 802.1AS standard provides a protocol related to time synchronization. A master-slave clock hierarchy is established based on the so-called "best clock" (also called the grandmaster or grandmaster clock) in the network. The grandmaster clock provides the network's time base, to which all other network devices synchronize. The grandmaster clock is determined using the so-called Best Master Clock Algorithm (BMCA) and announced within the network. To this end, IEEE 802.1AS-compliant network devices send Announce messages containing information about their internal clocks to other directly connected network devices. This information about the internal clocks provides an indication of the accuracy of the respective clocks, their reference or time base, and other properties that can be used to determine the best clock in the network. The recipient of these Announce messages compares the received information with the characteristics of their own internal clocks and compares any messages received from other ports with information related to the clocks of other network devices. If the clock in another network device has better clock parameters, it will accept the clock. Within a short period of time, the best clock in the network is determined, and this best clock then becomes the grandmaster clock in the network. Messages related to time synchronization are broadcast across the network based on the grandmaster clock. A network device that receives a message related to time synchronization does not simply forward the message, but corrects the time information with respect to the previously determined propagation time on the connection (via which the network device receives the message related to time synchronization from a directly connected network device) and the internal processing time, and then the network device retransmits the message related to time synchronization and the corrected time information.
[0009] In a clock hierarchy based on IEEE 802.1AS and the generalized Precision Time Protocol (gPTP) defined therein, only a single network device always provides the best clock in the network. Therefore, this network device controls and regulates the entire vehicle's time. All other clocks in network devices within the network are governed by this single clock. Some vehicle manufacturers even synchronize other standard networks (such as CAN) via this Ethernet time master, meaning that nearly all network devices in the vehicle are informed of their system time by the network device providing the highest-level timekeeping. Consequently, a single network device represents a single point of failure in the network or vehicle, whose failure or manipulation could have serious consequences for the vehicle's operational safety. Therefore, in vehicles with highly assisted or (semi-)autonomous driving systems, for example, large amounts of sensor data captured within narrow time windows must be processed together to derive appropriate control signals for the vehicle's actuators. The most accurate possible time registration of sensor data can also be crucial for documentation purposes, such as when stored in log files that can be analyzed to reconstruct malfunctions or operational errors. Reconstructing operational errors is of particular interest to insurance companies and law enforcement agencies. Therefore, the secure and synchronized provision of time information is crucial.
[0010] According to EP 2 759 174 A1, the difference between the counter of the receiving node and the counter of the receiving node is determined based on the timestamp and the error calculation unit. The error value is calculated from the difference between the two counter values (absolute values) or using the difference between the drifts of the two counter values.
[0011] EP 2 490 357 A2 describes a method for synchronizing a local estimate of the global network time of a receiving node in a network with a global network time reference from at least one of a first transmitting node and a second transmitting node in the network. The clock synchronization method allows for determining free-running nodes in an avionics network to detect whether the node is synchronized. If so, a synchronization flag is set.
[0012] US 2008 183 896 A1 explains that a receiving server declares its time parameters invalid when a communication loss is detected for too long a duration, which duration is predefined for the network and is a function of the maximum drift rate of the server's clock relative to the clock of the server's clock source.
[0013] EP 2 191 300 A1 discloses a sensor network for acquiring seismic data, wherein a clock update period is determined based on a maximum permissible time deviation and a determined (current) frequency drift.
[0014] EP 2 382 829 A1 discloses a method for synchronizing a reference frequency of a base transceiver station (BTS) with a reference frequency of a base station controller (BSC). The method comprises a series of steps, wherein a synchronization packet is transmitted and provided with a transmission timestamp and a reception timestamp. After an observation period, a network-delivered evaluation is evaluated. If the evaluation is sufficiently high, a confidence level for the received synchronization packet is determined. Only if the confidence level is above a threshold value is the reference frequency of the oscillator in the base transceiver station corrected.
[0015] The number of environmental sensor systems in automobiles has been increasing for years. In 2016, laser scanners were introduced into mass production, in addition to the existing ultrasonic and radar sensors. While the use of diverse sensor systems in automobiles is nearly ready for mass production, there are still unresolved challenges in fusing the resulting sensor data. Data fusion can be used to compensate for weaknesses in individual sensor systems and ensure greater robustness through redundancy. To ensure consistent data quality for ADAS systems, even in traffic jams or urban environments, different sensor systems monitoring the same field of view are required for safety-critical operations such as emergency braking. The term sensor fusion describes the merging of data from different sensors. The goal of sensor fusion is to ensure that the resulting data is of higher quality in all respects than the individual data obtained from each sensor. Furthermore, a distinction is made between homogeneous and heterogeneous sensor networks. In homogeneous sensor networks, all sensors use the same physical measurement principle and are therefore subject to the same physical limitations (such as range, accuracy, and noise sensitivity). In heterogeneous sensor networks, on the other hand, different measurement technologies are used, meaning that weaknesses in one sensor can sometimes be compensated for by another. Here, sensor fusion is categorized into complementary, competitive, and cooperative.
[0016] Several methods are known in the art for detecting changes in the configuration or structure of a communications network using network time synchronization. To exploit the added benefits of sensor fusion, it is necessary to monitor data flows and their correlation with one another. Unauthorized changes to the network configuration can cause disruptions, which can involve preparing an attack that intercepts messages for analysis and, if necessary, retransmits modified messages. This can be used to prevent or at least disrupt secure and correct operation.
[0017] Currently, there are no solutions for validating timestamps. If a fusion unit is expected to fuse two packets but the timestamps don't match, how should it behave? Of course, this doesn't necessarily mean the data is stale and unusable, but rather that the timestamps are incorrect. It should also be noted that all packets are actually important, and it's often impossible to omit any of them. For example, in an ADAS system, there's no time to re-request a lost packet. Safety-critical issues caused by lost data can have serious consequences and could lead to incorrect control of actuators in the system. Summary of the Invention
[0018] It is therefore an object of the present invention to provide a method which detects when timestamps are incorrectly assigned and, as a result of this detection, checks the assigned data to know whether the data belong together (because they have different time origins) so that they can be used reliably by means of sensor fusion.
[0019] This object is achieved by a method as claimed in claim 1 and a control unit as claimed in claim 11. Embodiments and further developments are specified in the corresponding dependent claims.
[0020] In other words, the object of the present invention is to safely monitor and ensure time synchronization in an onboard network.
[0021] Time can be distorted by errors, temperature, or attacks. Especially in autonomous driving, the performance of time-controlled actions, such as the synchronization of sensors (cameras, lidar, radar, etc.) and their data streams, is becoming increasingly important. These functions, in particular, require plausibility checks to verify, for example, whether the vehicle can be operated or whether the driver should continue driving. The advantages of the present invention can be found in the specification of mechanisms and methods for verifying and checking the validity of timestamps in sensor messages.
[0022] The method can be used to identify whether timestamps are being deliberately distorted and whether an attack is possible. Furthermore, the method detects whether timestamps may be invalid even if synchronization has not yet occurred. Timestamps can also be incorrect, for example, due to so-called bit rotation (which is detected by the described method). If the last successful synchronization is unknown, this can be determined using a specified method. This method increases security in the Ethernet domain.
[0023] The advantage of the present invention is that the synchronization accuracy of sensor data within the network, and therefore the fusion accuracy, is improved and guaranteed, as standards such as Ethernet or AUTOSAR currently do not provide any automotive tools. This means that the proposed approach can detect abnormal behavior or possible errors / attacks. By implementing this mechanism and protocol, any additional hardware and proprietary protocols can be eliminated. This also means that the number of communication technologies in the vehicle does not need to be further increased, nor does it require the operation or connection of additional lines.
[0024] A further advantage can be seen in the method's reduced load on the vehicle's data bus. Less synchronization is required, which also has a positive impact on μC resources, any errors, and power consumption. A major advantage of the present invention also stems from the fact that Ethernet can perform time-controlled actions without requiring additional hardware components, such as temperature-controlled crystals or security modules. The Ethernet in-vehicle network according to the present invention offers improvements in terms of cost and reliability.
[0025] This approach may in particular be implemented in the form of software that can be distributed as an update or upgrade to existing software or firmware of subscribers in the network and in this respect is a standalone solution.
[0026] This detection makes it possible to ascertain, for example, whether a neighboring control device is exposed to a specific risk, such as excessive or insufficient temperature, a fault, or an attack.
[0027] Detecting modifications in the network offers another approach to ensuring data security and functional safety in vehicle networks. For example, if a modified control device is used, neither the driver nor the workshop would be aware of it. Ethernet vehicle networks and control devices can detect errors based on the methods described.
[0028] This invention and the resulting solution are particularly relevant for the automotive industry, as reliability and security over Ethernet are crucial in cars and will only grow in importance. In the coming years, sensors (cameras and radars) will also transmit uncompressed data over Ethernet. These data rates will require further technologies to make Ethernet systems more secure and performant. This approach will help facilitate these applications.
[0029] The current problem and the problem with any new system is the dependence on the communication interface and its support. The invention described here allows for more platform-independent development. The implementation of the invention allows for longer lifecycles and reduces the necessary maintenance.
[0030] For example, more precise synchronization allows for safer and more reliable execution of more real-time-critical actions (sensor fusion). The quality of sensor data fusion improves, which ultimately leads to better environment models and better trajectories.
[0031] On the other hand, especially in the field of ADAS, it is often uneconomical to equip all subscribers connected to the network with hardware sufficient for fully encrypted communication. The described method requires significantly fewer hardware resources and can be implemented using existing implementations, thus significantly increasing the security level without necessarily being associated with higher production costs for the network or the devices connected to it.
[0032] Using the newly introduced Ethernet protocol in automobiles requires simple technology and mechanisms, given the nature of the technology, to enable implementation without expensive implementations and additional hardware. Early analysis of communication paths allows for earlier detection of attacks and abnormal behavior, allowing vulnerabilities and errors to be identified before vehicle delivery. The network system according to the present invention improves cost and reliability. The present invention also more clearly defines the system's testability, reducing testing costs. Furthermore, the present invention provides transparent security functionality.
[0033] The method can be implemented in a control device and can use an on-board network consisting of different control devices to ensure improved protection of time synchronization.
[0034] This object is achieved by a method as claimed in claim 1 and a control unit as claimed in claim 11. Embodiments and further developments are specified in the corresponding dependent claims.
[0035] In one embodiment of the method for checking the validity of sensor data of an Ethernet vehicle network, the following steps are performed in a motor vehicle:
[0036] Determining a propagation time (9) of a first signal (10) on a first connection path (6) between a first control unit (3) of the Ethernet vehicle network (2) and a second control unit (4) of the Ethernet vehicle network (2);
[0037] determining a maximum speed (11) of the first connection path (6) based on the propagation time (9); and
[0038] The type (12) of the transmission medium of the first connection path (6) is determined based on the maximum speed (11).
[0039] Furthermore, at least a first control unit (3) of the Ethernet vehicle network is identified; at least the first control unit of the Ethernet vehicle network is synchronized; a synchronization interval is determined; a drift of a timer of the first control unit is determined; a time stamp of the first control unit is determined; a time stamp of the first control unit is read or a time of the first control unit is queried; the time stamp is compared with a reference clock of the Ethernet vehicle network; a propagation time measurement is performed; a speed of an associated clock generator is determined; a time difference of the synchronization interval is determined; and a last synchronization is determined.
[0040] Furthermore, the determination of the propagation time of the first signal and the determination of the maximum speed of the first connection path as well as the determination of the type of transmission medium of the first connection path can lead to the formation of an entropy source for determining at least one dynamic key of the connection path, which is used to encrypt the time synchronization message of the connection path 6.
[0041] In another embodiment of the method, the drift of the timer is determined by IEEE 802.1AS protocol.
[0042] A further embodiment of the invention is distinguished in that the comparison of the timestamp with the reference clock of the Ethernet onboard network (3) results in the calculation of a difference in the form of Tdevice=Treference-Tsuspect.
[0043] Another embodiment of the present invention is characterized in that the speed of the clock generator is determined by a PTP NRR (Neighboring Rate Ratio) method.
[0044] Another embodiment of the present invention is characterized in that the type of the transmission medium and the determination of the synchronization interval, the determination of the drift of the timer of the first control unit, the determination of the timestamp of the first control unit, the determination of the speed of the associated clock generator, the determination of the time difference of the synchronization interval, and the determination of the last synchronization are transmitted to a program in the Ethernet vehicle network, and the connection path selection of the program is adapted based on the type of the transmission medium.
[0045] Another embodiment of the present invention is characterized in that the type of transmission medium is determined to be optical, copper or wireless.
[0046] Another embodiment of the invention is characterized in that a transmission security value (15) is assigned to the first connection path (6) based on the type of the transmission medium (12), which transmission security value describes the probability of loss of data transmitted via the first connection path (6).
[0047] Another embodiment of the present invention is characterized in that propagation times of a plurality of signals on the first connection path are determined and the fastest propagation time among the plurality of signals is selected, and the maximum speed of the first connection path is determined based on the fastest propagation time.
[0048] Another embodiment of the present invention is characterized in that a propagation time of a second signal on a second connection path between the first control unit and the second control unit, which is different from the first connection path, is determined, and a maximum speed of the second connection path is determined, and the type (19) of the transmission medium of the second connection path (7) is determined based on the maximum speed (11) of the second connection path (7).
[0049] Another embodiment of the present invention is characterized in that the method is performed after the first control unit (3) changes from the normal operating mode to the energy-saving mode and / or from the energy-saving mode to the normal operating mode.
[0050] Another embodiment of the present invention is characterized in that the propagation time of the first signal is determined using the first control unit, and the propagation time of a third signal on a third connection path between the second control unit (4) and the third control unit (5) which is only indirectly connected to the first control unit is determined using a third control unit of the Ethernet vehicle network, the determination of the propagation time of the third signal being triggered by a service message sent from the first control unit to the third control unit.
[0051] An embodiment of a control unit for an Ethernet vehicle network (which takes the form of a first control unit) allows: sending a signal to a second control unit of the Ethernet vehicle network and receiving the signal from the second control unit; determining the propagation time of the signal on a connection path to the second control unit; determining a maximum speed of the connection path based on the propagation time and determining the type of transmission medium of the connection path based on the maximum speed, the control unit comprising at least one microprocessor, a volatile memory and a non-volatile memory, at least two communication interfaces, a synchronizable timer, the non-volatile memory containing program instructions which, when executed by the microprocessor, are capable of implementing and executing at least one embodiment of the method according to claims 1 to 10.
[0052] A further embodiment of the Ethernet on-board network for a motor vehicle is characterized in that the first control unit and the second control unit are connected to one another via at least one connection path, and in that the first control unit is in the form as claimed in claim 11 .
[0053] A further embodiment of the Ethernet vehicle network is distinguished in that the Ethernet vehicle network comprises a third control unit which is only indirectly connected to the first control unit and is directly connected to the second control unit via a third connection path, wherein the third control unit is designed to determine a propagation time of a third signal on the third connection path, wherein the first control unit is designed to trigger the determination of the third signal propagation time by a service message to the third control unit.
[0054] One embodiment is represented by a computer program product comprising instructions which, when executed by a computer, cause the computer to carry out the method as claimed in one or more of claims 1 to 10.
[0055] An embodiment of a computer-readable medium is provided, on which the computer program product of claim 12 is stored.
[0056] The computer program product according to the invention contains instructions which, when executed by a computer, cause said computer to carry out one or more embodiments and further developments of the method described above.
[0057] The computer program product may be stored on a computer-readable medium or data carrier. The data carrier may be physically embodied as, for example, a hard disk, a CD, a DVD, a flash memory, etc. However, the data carrier or the medium may also include a modulated electrical, electromagnetic or optical signal that can be received by a computer via an appropriate receiver and stored in the computer's memory.
[0058] At least one control unit according to the present invention includes at least one physical communication interface, a microprocessor, non-volatile memory, volatile memory, and a timer. The components of the control unit are communicatively connected to one another via one or more data lines or a data bus. The memory of the control unit contains computer program instructions that, when executed by the microprocessor, configure the network device to implement one or more embodiments of the above-described method.
[0059] The method according to the present invention can be implemented using existing network equipment. If necessary, only the software or state machine for receiving and processing time synchronization messages needs to be adapted so that only time synchronization messages from the grandmaster clock determined during initialization are used for clock synchronization, while additional time synchronization messages are forwarded rather than simply deleted. Consequently, the implementation incurs only minimal additional costs, if any. Even existing systems can be configured to implement the method by appropriate software changes. Another advantage of the method according to the present invention is that the specific underlying hardware platform is irrelevant, as long as the platform supports synchronization according to the IEEE 802.1AS standard. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] The present invention will be explained below by way of example with reference to the accompanying drawings, in which:
[0061] Figure 1a shows a schematic plan view of a motor vehicle having an exemplary embodiment of an Ethernet on-board network according to the invention;
[0062] Figure 1b shows a schematic representation of an Ethernet vehicle network having a first control unit, a second control unit and a third control unit, which are connected via a first connection path, a second connection path and a third connection path;
[0063] Figure 2 The complete sequence of the method and the determination of the current time of the node to be checked and the properties of its clock generator are shown;
[0064] Figure 3 A flow chart for encrypting a time synchronization message for determining the type of transmission medium of a corresponding connection path is shown;
[0065] Figure 4 shows a representation of a sawtooth pattern of frequency drift when time synchronization is successful;
[0066] Figure 5 A graphical representation of a computational asynchronous cycle is shown;
[0067] Figure 6a shows a sequence for determining sensor offsets for sensor fusion;
[0068] Figure 6b shows the determination of the time of the last successful synchronization;
[0069] Figure 7 shows a flow chart for determining the frequency of a single crystal;
[0070] Figure 8A flow chart for calculating a key and sending a message is shown;
[0071] Figure 9 shows a flow chart for using keys over time;
[0072] Figure 10 A flow chart showing a procedure for adapting an Ethernet vehicle network;
[0073] Figure 11 A flow chart showing a procedure for adapting an Ethernet vehicle network;
[0074] Figure 12 A flow chart for determining and storing the propagation time of a signal is shown;
[0075] Figure 13 A flow chart for illustratively adapting a procedure in an Ethernet vehicle network is shown;
[0076] Figure 14 A flow chart for illustratively adapting a procedure in an Ethernet vehicle network is shown;
[0077] Figure 15 shows a flow chart for evaluating usage of received data based on the last successful synchronization time;
[0078] Figure 16 shows the design of the control unit;
[0079] Figure 17 An encrypted link with a dynamic key generated from communications with the control unit is shown;
[0080] Figure 18 shows a representation of a use case for data fusion;
[0081] Figure 19 shows a representation of the use case for data fusion with data loggers;
[0082] Figure 20 A representation of the correct data assignment for data fusion is shown;
[0083] Figure 21 A representation of erroneous data assignments for data fusion is shown;
[0084] Figure 22 A sequence is shown in which data is retroactively erased if the synchronization time exceeds a limit value.
[0085] In the drawings, the same or similar elements may be referred to using the same reference numbers. DETAILED DESCRIPTION
[0086] Figure 1aA motor vehicle 1 is shown in plan view. It includes an Ethernet vehicle network 2. According to an exemplary embodiment, Ethernet vehicle network 2 further includes a plurality of control units 3, 4, and 5, which may also be referred to as control devices or control apparatuses. The control units are interconnected via connection paths. Due to the existing topology of Ethernet vehicle network 2 in the exemplary embodiment, multiple parallel communication paths exist between the control units. For example, the connection paths may be formed from different media types or materials.
[0087] For example, as the number of Ethernet variants increases, dynamic changes in connection speeds will also be used. This means, for example, that the speed can be changed at runtime. For example, a 10 Gbit / s connection path can be changed to 100 Mbit / s, saving energy. Because this is a dynamic function, it is possible that the in-vehicle network may be in a different form after delivery or initial installation in a motor vehicle than after a software update or in the event of a malfunction.
[0088] Ethernet vehicle network 2 includes at least one first control unit 3, a second control unit 4, and an additional third control unit 5. First control unit 3 is connected to second control unit 4 via a first connection path 6. Furthermore, according to an exemplary embodiment, first control unit 3 is also connected to second control unit 4 via a second connection path 7.
[0089] For example, the first control unit 3 , the second control unit 4 and / or the third control unit 5 may be implemented as control devices or network switches. The second control unit 4 and the third control unit 5 are connected to each other via a third connection path 8 .
[0090] according to Figure 1a In the exemplary embodiment of FIG, first control unit 3 and second control unit 4 are directly connected to each other via first connection path 6, while first control unit 3 and second control unit 4 are only indirectly connected via second connection path 7 because second connection path 7 is divided into two parts by another control unit. However, according to another exemplary embodiment, second connection path 7 can also directly connect first control unit 3 and second control unit 4 to each other.
[0091] In general, this method is suitable for detecting errors in synchronization.
[0092] like Figure 2As shown, the duration of the asynchrony can be calculated or determined, or the time and the last time a synchronization was performed correctly can be calculated or determined. Based on the existing synchronization, the method proposes to determine the inaccuracy of the clocks in the network, for example the inaccuracy of the clocks of "my" neighbor ECUs or "neighbor" CPUs, which can be located in the same ECU. Based on these determined data, the timestamp of the component, together with the clock of "my" own clock or the clock of the most advanced timing device, and the synchronization interval can be used to calculate how much time has passed since the last synchronization. It is thus possible to determine the time when the last successful synchronization occurred. At a time, also referred to as the determination time, the timestamp from the ECU of the control device, which it is desired to know whether it is still in a synchronized state, is recorded. A series of parameters is then used as the basis for determining in how many synchronization intervals or from what time the component is no longer successfully synchronized, such as Figure 4 As shown in the example.
[0093] The method thus determines when the last successful synchronization of a node occurred and thus also how long it has been since the node was synchronized. This is the basis for deciding whether the sensor data is trustworthy and therefore usable.
[0094] Figure 4 This demonstrates message-based time synchronization. After a synchronization message arrives, the internal clock or offset is adjusted. The clock then continues to operate according to its own characteristics until the next synchronization.
[0095] from Figure 2 As can be seen, the method begins by interrogating the time of a node, μC, switch, entire ECU, or control unit 3, 4, or 5, or by reading the time via a timestamp. This value is stored. The method then determines the frequency drift of the timer via the 802.1AS protocol (Pdelay query). In this way, the periodic message, which is actually used to measure the propagation time and is transmitted anyway, is used to calculate the operating speed of the clock generator of the ECU / μC, or entire ECU, or control unit 3, 4, or 5.
[0096] according to Figure 3A sequential process is used to measure propagation time. A port (initiator) starts the measurement by sending a Delay_request message to the port (responder) connected to it and generating a departure timestamp t1. This departure timestamp represents the hardware timestamp written as late as possible when leaving the Ethernet transceiver. When the packet arrives, the responder generates a timestamp t2. In response, the responder sends a Delay_Response message. In this message, the responder transmits the reception timestamp t2 of the Delay_Request message. When the message leaves the responder, the responder in turn generates a timestamp t3, which is sent in the subsequent Delay_Response_Follow_Up message. When the initiator receives the Delay_Response message, it generates a timestamp t4. The initiator can use the four timestamps t1 to t4 to calculate the average propagation time of the covered route.
[0097] PTP defines a master / slave clock hierarchy with the best clock within the network. The time base of the nodes in the network is derived from this clock (the highest-level timing device). The best master clock algorithm (BMCA) is used to determine the clock type and announce this information in the network. IEEE802.1AS-compliant systems periodically send Announce messages with information about the best clock in the cloud to their neighboring nodes. The recipient of this message compares this information with the characteristics of its clock and any messages already received from another port. A time synchronization spanning tree is established based on these messages. In this process, each port is assigned one of four port states. A port whose path to the highest-level timing device is shorter than the path to its link partner is set to the "master port" state. This state is assigned when other ports at the node do not already have the "slave" state. It is disabled by ports that cannot fully support the PTP protocol. If none of the other three states are applicable, the "passive" state is selected.
[0098] Finally, time information is exchanged via the Sync_Follow_Up mechanism. A master port periodically sends Sync and Follow_Up messages to its adjacent link partner. When a Sync message leaves the master port, a timestamp is generated that is immediately transmitted in the subsequent Follow_Up message. This timestamp corresponds to the current time of the highest-level timer at the time the Sync message is sent. Messages originating from the highest-level timer are not forwarded but are regenerated in each node (including switches).
[0099] like Figure 6aAs shown, the speed of the clock generator can be determined or calculated using the PTP NRR (Neighbor Rate Ratio) method. Periodic PDelay messages are used to calculate the speed (offset) of the clock generator relative to a reference clock. The read or queried time (Tsuspect) is assigned to the current system time (Tref), so this time is trusted, whether it is the highest-level timekeeping device or the time when the data is important. If the component to be verified is a sensor, the sensor fusion time can be used as a reference. This means first determining the difference between the two times.
[0100] Tdeviation = Treference – Tsuspect
[0101] The synchronization frequency can first be used to calculate how large the maximum T deviation should be: In the case of Ethernet, the interface between the PHY (transceiver) and the MAC is the explicit interface for recording time information. The clock frequency of this interface (xMII) is a nominal frequency f of 25 MHz. Crystals used in AVB / TSN-compliant implementations of Automotive Ethernet must not exceed a maximum inaccuracy f of ±100 ppm. Therefore, the worst-case crystal connected to the interface would result in a frequency deviation of 5 kHz relative to the nominal frequency f, according to the following formula:
[0102] df=(f*fo) / 10^6
[0103] The period variation between the maximum frequency (2500 × 2500 Hz) and the minimum frequency (24997500 Hz) is 8 ps within a 40 ns period duration. This means that within 40 ns, the maximum time difference between the two crystals (and therefore the two ECUs) at +25°C is 8 ps. Within the standard synchronization interval of 125 ms, there can be exactly 3,125,000 periods of 40 ns each, corresponding to a maximum deviation of 25 μs.
[0104] According to the IEEE 802.1AS specification, the synchronization interval can be between 31.25ms and 32 seconds. This means that for the minimum interval, the worst-case deviation is 6.25μs, and for the maximum interval, the worst-case deviation is 6.4ms.
[0105] Figure 6b The method schematically indicates how to use the aforementioned formula to calculate the time when the last synchronization occurred by determining the speed of the clock generator and the knowledge of the synchronization interval Tdeviation.
[0106] exist Figure 1bThe exemplary embodiment of the Ethernet vehicle network 2 shown has a first control unit 3, a second control unit 4, and a third control unit 5. Furthermore, the Ethernet vehicle network 2 has a first connection path 6, a second connection path 7, and a third connection path 8. According to the exemplary embodiment, a propagation time 9 of a first signal 10 on the first connection path 6 is determined. The propagation time 9 describes the length of time it takes for the first signal 10 to travel from the first control unit 3 to the second control unit 4 via the first connection path 6 (or vice versa). Based on the propagation time 9 of the first signal 10, a maximum speed 11 of the first connection path 6 is determined. For example, in this case, the maximum speed 11 of the first connection path 6 varies depending on the length of the cable, the transmission speed, and / or the type of medium, or the type of transmission medium. Based on the maximum speed 11, the type 12 of the transmission medium of the first connection path 6 is determined.
[0107] According to this exemplary embodiment, the type of transmission medium 12 is determined to be optical, copper, or wireless. In the optical case, the first connection path 6 is, for example, in the form of a fiber optic connection. In the copper case, the first connection path is, for example, formed by a cable having twisted pairs, such as an unshielded twisted pair (UTP) cable. In the wireless case, the first connection path 6 is essentially in the form of a radio link, and the first control unit 3 and / or the second control unit 4 have a radio receiver and / or a radio transmitter or are connected to a radio receiver and / or a radio transmitter.
[0108] The control unit 3 determines the propagation time for transmitting data via the onboard network to the control unit 4. An important factor is that the propagation time is determined in some form based on the actual physical conditions of the transmission path from the first control unit 3 to the control unit 4, that is, the transmission path has physical conditions or properties that, when changed, will cause the determined propagation time to change.
[0109] In this case, control unit 3 determines the propagation time for data transmission via the network to control unit 4. This can be accomplished in alternative ways. For example, the propagation time can occur during the time synchronization between the first and second subscribers, for example, according to the IEEE 802.1AS time synchronization standard and the PTP protocol contained therein. For example, the "Delay Request" and "Peer Delay" messages implemented within this protocol can be used as data packets. However, the method is not limited to this. The only important factor is that the propagation time is determined in some form based on the actual physical conditions of the transmission path from the first subscriber / control unit 3 to the second subscriber / control unit 4, that is, the transmission path has physical conditions or properties that, when changed, will cause the determined propagation time to change.
[0110] Furthermore, the first control unit 3 determines the message frequency of the other control unit 4, which is derived in principle from the speed of the PLL and the crystal. From these two values, which vary continuously due to temperature, aging, etc., the control unit 3 derives the key for encrypting these time messages.
[0111] The time synchronization message is encrypted using a generated dynamic key, which can generally be obtained from various parameters related to the connection partner.
[0112] like Figure 3 As shown, a separate, constantly changing key is also generated based on line delay 221 and message frequency 213. This key is unique per unit time and is also different for each link. Thanks to this approach, the key never exists twice in the network. Generating the key through a combination of point-to-point line delay and crystal frequency makes it particularly resistant to attempts to circumvent it, as the key is constantly changing and will be different for each link in the vehicle network.
[0113] These two values can be combined directly or supplemented with other static values to generate a key. These static values must be known to both control devices (such as their addresses, for example). The respective control units (the method can be performed on both control units, or on the subscriber / link partner) use these values to determine a random value to derive a single key for encryption, which is only valid for a short period of time. The key changes over and over again based on previous measurements; these measurements do not require any additional effort, as they are used for time synchronization.
[0114] The type of transmission medium 12 is communicated to a program 13 in the Ethernet vehicle network 2. For example, program 13 may reside in the first control unit 3, the second control unit 4, or the third control unit 5, or another control unit in the Ethernet vehicle network 2. The type of transmission medium 12 serves as the basis for adapting the connection path selection 14. Thus, program 13 can use connection path selection 14 to, for example, transmit data via a different connection path than was previously selected. However, program 13 can also, for example, interrupt data transmission via connection path selection 14 and resume it at a later time.
[0115] According to an exemplary embodiment, a transmission security value 15 is assigned to the first connection path 6 based on the type of transmission medium 12. The transmission security value describes the probability of loss of data transmitted via the connection path. In other words, the transmission security value 15 indicates the degree of reliability with which data can be transmitted via the first connection path. This value is provided to the entropy source 200. For example, if the security limit value is not met and data can only be transmitted in an unsecured manner, it must be expected that the data will arrive at its destination with a certain delay, or even not at all, if the data is not worth sending again due to the requirement for it to be up-to-date.
[0116] According to another exemplary embodiment, the propagation times of a plurality of signals on the first connection path 6 are determined and the fastest propagation time of the plurality of signals is selected. The maximum speed 11 of the first connection path 6 is then determined based on the fastest propagation time.
[0117] The control unit begins measuring delay and waits for a link partner message. Based on the received message using the PTP protocol, the line delay can be measured. If one link partner begins measuring delay, the other link partner will inevitably notice this and also begin measuring, so that the two measurements can generate correlated values.
[0118] The type 12 of the transmission medium of the second connection path 7 and / or the third connection path 8 can also be determined analogously to the above-described method.
[0119] Each recorded value is unique, kept confidential, and stored in the control device. It is also not transmitted over the network—nor does it need to be. Discovering the key through trial and error alone is completely impossible. The individual keys are generated by taking into account two values: first, the frequency of each crystal is different, and second, the line delay of each link is different. Adding these two fluctuating values yields a third value, even more difficult to guess—the key value. Line delay typically ranges from 50 to 500 nanoseconds, and frequency is a parameter and is given in ±ppm. The round-trip line delay is based on the same channel, which is why the calculated values are identical on both sides of the link. Therefore, no parameter exchange is necessary. This means that both partners have the same values for key generation at approximately the same time. One link partner uses these two values from the previous measurement for encryption, while the other partner uses its previous value for decryption.
[0120] Therefore, provision is also made for determining a propagation time 16 of a second signal 17 on the second connection path 7. Based on the propagation time 16 of the second signal 17, a maximum speed 18 of the second connection path 7 is then determined. Based on the maximum speed 18 of the second connection path 7, a type 19 of the transmission medium of the second connection path 7 is further determined.
[0121] As long as no new line measurement is performed, it is advantageous to use the current key A1. This way, the link partner always knows which key to use if no new line measurement has been initiated beforehand. New keys should / can be generated periodically (e.g., at a predefined frequency), either as needed, triggered by a trigger, or always immediately before sending an important message.
[0122] The first control unit 3, the second control unit 4, and the third control unit 5 can each operate in a normal operating mode or an energy-saving mode. In energy-saving mode, the corresponding control unit consumes less energy than in normal operating mode. For example, in energy-saving mode, the speed of the port of the corresponding control unit can be reduced compared to the speed in normal operating mode. However, the reduced port speed will also affect the corresponding maximum speed of the corresponding connection path.
[0123] According to another exemplary embodiment, a service message 20 can be sent from the first control unit 3 to the third control unit 8. The determination of the propagation time 21 of the third signal 22 is then triggered by the service message 20. The third signal 22 is sent between the second control unit 4 and the third control unit 5. According to an exemplary embodiment, the propagation time 21 of the third signal 22 is determined by the third control unit 5.
[0124] Figure 10 A general description of a method for determining propagation time is provided. In step S1, the propagation time 9 of a first signal 10 is determined. In step S2, the type of transmission medium 12 is determined. Finally, in step S3, a program 13 is adapted. In step S4, the propagation time 9 of the first signal 10 is determined. Consequently, in step S5, the type of transmission medium 12 can be determined. The type of transmission medium 12 can, in turn, include the following parameters: speed 23, medium 24, cable length 25, power transmission 26, and bit error rate 27. Finally, in step S6, the program 13 is adapted and a connection path selection 14 is selected.
[0125] According to this example, it is proposed to measure the propagation time of signals between connected control units or controllers. The propagation times 9, 16, and 21 can be measured using methods from the IEEE 1588 or IEEE 802.1AS standards, for example. Methods can also be provided by TTEthernet (Time Triggered Ethernet), for example, to determine the corresponding propagation times 9, 16, and 21.
[0126] Figure 12The determination of the corresponding propagation times 9, 16, and 21 is shown. Local and non-local queries for propagation times are described. A program 13 (which is executed, in particular, on at least one control unit) preferably first determines the local propagation time locally, or if more than one control unit is directly connected, determines multiple propagation times. Then, preferably using a service-oriented method, such as SOME / IP (scalable service-oriented middleware over IP), the other control units are queried about their propagation times to their neighbors. This can be done centrally or in a decentralized manner. The query can be performed once at system startup, during definition, or after a software update, or it can be performed periodically to detect dynamic changes. This data, in particular the address of the control unit, is then stored and assigned for the first time. In step S7, the corresponding propagation time to the directly connected control unit is determined. In step S8, the corresponding propagation times for other connection paths are queried. In step S9, the corresponding propagation times and their associated connection partners are stored.
[0127] Figure 13 Another method for deriving other speeds based on reference measurements is shown. For example, if the current temperature is very high or the cable used is poor, the pre-stored values may be very inaccurate. Therefore, it is proposed that the application or program 13 itself performs measurements on its own control unit, in particular based on its own parameters and the other speeds that can then be derived and calculated from them. In step S10, an analysis is performed for each local Ethernet port. In step S11, a test is performed to determine whether the channel parameters are known. If this is not the case, step S12 follows and the method ends. If this is the case, step S13 follows, in which the corresponding propagation times 9, 16 and 21 are determined. In step S14, storage is performed and the determined propagation times are related to the channel parameters. In step S15, a reference value list is created.
[0128] Figure 14 A possible optimization is shown by knowing the type of transmission medium 12, 19. In step S16, it is determined whether the type of transmission medium 12, 19 is copper. If this is the case, step S17 follows, in which it is confirmed that PoDL (Power over Data Line) (that is, Power over Ethernet) is possible. If the decision in step S16 is that the medium is not copper, step S18 follows. In step S18, a check is performed to determine whether the type of transmission medium 12 is optical. If this is the case, step S19 follows. In step S19, it is found that the bit error rate is therefore low and the reliability of the connection path is therefore high. In step S20, the option of deactivating the RX (receive unit) or TX (transmit unit) of the control unit 3, 4, 5 is provided if it is not required.
[0129] If the determination in step S18 is that the medium or type 12 of the transmission medium is not optical, then in step S21 it is assumed that the corresponding connection path (as the relevant connection path) is in the form of a direct MII (Media Independent Interface) connection. In this case, the corresponding control unit is adapted to, for example, IEEE 802.1CB (Frame Duplication and Redundancy Elimination).
[0130] Another option comes from knowing the transmission speed. In conjunction with the current data flow, for example, data can be deliberately transmitted using high-bandwidth connections and, as a result, other unneeded connection paths can be deactivated, thus saving energy.
[0131] For high-bandwidth connections, there's also the option of using redundancy mechanisms (such as IEEE 802.1CB). Since data is transmitted continuously and redundantly in this case, high bandwidth is required. It's also conceivable to adapt the application to the speed of the transmission path. For example, a camera could adapt the resolution of the transmitted image data to the speed of link or connection paths 6, 7, or 8.
[0132] In addition to the microprocessor 402, Figure 16 The control units 3, 4, 5 in the network device further comprise a volatile memory 404 and a non-volatile memory 406, two communication interfaces 408, and a synchronizable timer 410. The elements of the network device are communicatively connected to one another via one or more data connections or data buses 412. The non-volatile memory 406 contains program instructions which, when executed by the microprocessor 402, implement at least one embodiment of the method according to the present invention, and an entropy source is formed in the volatile memory 404 and / or the non-volatile memory 406, which is then used to form the dynamic key 28 for the connection path 6. Figure 17 The decoding sequence of the dynamic key during decryption is shown in .
[0133] Figure 15 This demonstrates how to evaluate the use of received data based on the time of its last successful synchronization. This sequence can be used to determine whether the checked data to be stored is also suitable for the corresponding application. This is particularly advantageous if the data is stored on a data logger. The correctness of the data content is also crucial for the data logger. For example, in the event of an accident, it is important whether the camera detects a pedestrian. If incorrect data or data with an incorrect time is recorded, the recording is invalid and cannot be detected without this method.
[0134] The query component analyzes the data flow and the sender of the data flow, such as Figure 22This method can serve as the basis for determining when data was last trusted. The nominal limit values are determined by the function, the system manufacturer, or the use case itself. These may vary for each ECU and each use case. Based on these limit values, data can be classified as valid, invalid, or untrustworthy.
[0135] Figure 18 and Figure 19 Two use cases are shown where time synchronization is crucial and where this approach is used. Firstly, different data from different sensors / control devices needs to be fused, said data being included in the sensor messages based on time information, and secondly, they can also be stored to provide evidence in the event of an error.
[0136] Figure 20 It is shown that the timestamps in the data are used as a basis for fusing and storing the data so that the correct data can be assigned to the time.
[0137] Figure 21 This figure shows the arrival of different sensor data frames at a fusion unit, or, for example, a data logger. The data logger assigns data not in the order of arrival but rather according to its timestamp, which is based on a previously synchronized time. Because data in a network must take paths of varying lengths, sensor data is typically sorted based on when it was created.
[0138] Figure 21 The example shows incorrect timestamps, i.e., inconsistencies in the sensor data occurred during fusion, resulting in faulty time synchronization. The proposed method was not used. This method improves the precision and accuracy of clock synchronization to achieve real-time capabilities in Ethernet vehicle networks. The quality of a synchronization protocol is primarily measured by its achievable synchronization accuracy, which can be derived from this method as additional information.
[0139] Figure 22 It shows how to retroactively erase the sequence of data if the synchronization time exceeds a limit. This method can also be used, for example, in a data logger use case if data has already been stored (or is about to be stored). It is also important for a data logger whether the data content is correct - for example, in the event of an accident it is important whether a camera detects a pedestrian. If incorrect data or data with incorrect time is recorded, the recording is invalid. The query component analyzes the data stream and the sender of the data stream, such as Figure 22 This method can serve as the basis for determining when data was last trusted. The nominal limit values are determined by the function, the system manufacturer, or the use case itself. These may vary for each ECU and each use case. Based on these limit values, data can be classified as valid, invalid, or untrustworthy.
[0140] The querying component, such as a data logger or cloud storage unit, wants to check the command for a stored data set (such as a sensor data stream) of the verification component. This can be done, for example, by checking the address, stream, or timestamp. To do this, the last successful synchronization is checked and the last valid time of the data is determined. The storage is checked and incorrectly synchronized data sets are rejected.
[0141] Reference Signs List
[0142] 1 Motor Vehicle
[0143] 2 Ethernet in-vehicle network
[0144] 3 First control unit
[0145] 4 Second control unit
[0146] 5 Third control unit
[0147] 6 First connection path
[0148] 7 Second connection path
[0149] 8 Third connection path
[0150] 9 Propagation time of the first signal
[0151] 10 First Signal
[0152] 11 Maximum speed of the first connection path
[0153] 12 Type of transmission medium of the first connection path
[0154] 13 Procedure
[0155] 14 Connection Path Selection
[0156] 15 Transmission security value
[0157] 16 Propagation time of the second signal
[0158] 17 Second Signal
[0159] 18 Maximum speed of the second connection path
[0160] 19 Type of transmission medium for the second connection path
[0161] 20 Service Messages
[0162] 21 The propagation time of the third signal
[0163] 22 Third Signal
[0164] 23 Speed
[0165] 24 Medium
[0166] 25 Cable length
[0167] 26 Power Transmission
[0168] 27 Bit Error Rate
[0169] 28 Dynamic Key
[0170] 29 Time synchronization message
[0171] 200 Entropy Source
[0172] 211 sent at time t1
[0173] 212 Received at time t4
[0174] 213 Received at time t4
[0175] 221 received at time t2
[0176] 222 sent at time t3
[0177] 223 Delayed sending at time t3
[0178] 300 Encrypted message at time t5
[0179] 400 control unit
[0180] 402 Microprocessor
[0181] 404 RAM
[0182] 406 ROM
[0183] 408 Communication Interface
[0184] 410 Timer
[0185] 412 Bus / communication interface
[0186] 1001 Receive encrypted message
[0187] 1002 Start line delay measurement and frequency measurement
[0188] 1003 Request the last line measurement and frequency parameters
[0189] 1004 Generate Key
[0190] 1005 Decrypt the message
Claims
1. A method for checking the validity of sensor data of an Ethernet on-board network (2) in a motor vehicle (1), wherein: Perform the following steps: d) determining a propagation time (9) of a first signal (10) on a first connection path (6) between a first control unit (3) of the Ethernet onboard network (2) and a second control unit (4) of the Ethernet onboard network (2); e) determining a maximum speed (11) of the first connection path (6) based on the propagation time (9); and f) determining a type (12) of the transmission medium of the first connection path (6) based on the maximum speed (11), It is characterized by performing the following steps: - identifying at least one first control unit (3) of the Ethernet vehicle network (2); - at least one first control unit (3) of a synchronous Ethernet onboard network (2); -determine the synchronization interval; - determining the drift of the timer (410) of the first control unit (3); - determining a timestamp of the first control unit (3); - reading the timestamp of the first control unit (3) or querying the time of the first control unit (3); - compare this timestamp with the reference clock of the Ethernet vehicle network (2); - perform propagation time measurements; - determining the speed of the associated clock generator; - Determine the time difference of the synchronization interval; - Determine the last synchronization, determine the time when the node's last successful synchronization occurred and therefore also determine how long the node has been out of synchronization, wherein the sensor data is evaluated based on the time of the last successful synchronization and classified as valid, invalid or unreliable based on nominal limit values.
2. The method according to claim 1, characterized in that The timer drift is determined by the IEEE 802.1ASD8.3 protocol.
3. The method according to claim 1 or 2, characterized in that The comparison of the timestamp with the reference clock of the Ethernet vehicle network (2) is achieved by calculating the difference in the form of Tdevice=Treference-Tsuspect.
4. The method according to claim 1 or 2, characterized in that The speed of the clock generator is determined by the PTP NRR neighbor rate ratio method.
5. The method according to claim 1 or 2, characterized in that The type of transmission medium (12) and -Determination of synchronization interval - Determination of the drift of the timer (410) of the first control unit (3) - Determination of the time stamp of the first control unit (3) - Determination of the speed of the associated clock generator -Determination of the time difference of the synchronization interval - Determination of the last synchronization A program (13) is transmitted to the Ethernet vehicle network (2), and a connection path selection (14) of the program (13) is adapted based on the type of transmission medium (12).
6. The method according to claim 1 or 2, characterized in that The type of transmission medium (12) is determined to be optical, copper or wireless.
7. The method according to claim 1 or 2, characterized in that A transmission security value (15) is assigned to a first connection path (6) based on the type of transmission medium (12), which describes the probability of loss of data transmitted via the first connection path (6).
8. The method according to claim 1 or 2, characterized in that The propagation times of a plurality of signals on a first connection path (6) are determined and the fastest propagation time among the plurality of signals is selected, the maximum speed (11) of the first connection path (6) being determined based on the fastest propagation time.
9. The method according to claim 1 or 2, characterized in that A propagation time (16) of a second signal (17) on a second connection path (7) between a first control unit (3) and a second control unit (4), which is different from the first connection path (6), is determined, and a maximum speed (11) of the second connection path (7) is determined, the type (19) of the transmission medium of the second connection path (7) being determined based on the maximum speed (11) of the second connection path (7).
10. The method according to claim 1 or 2, characterized in that The method is performed after the first control unit (3) changes from the normal operating mode to the energy-saving mode and / or from the energy-saving mode to the normal operating mode.
11. The method according to claim 1 or 2, characterized in that A propagation time (9) of a first signal (10) is determined using a first control unit (3), and a propagation time (21) of a third signal (22) is determined using a third control unit (5) of an Ethernet vehicle network (2) on a third connection path (8) between a second control unit (4) and the third control unit (5) of the Ethernet vehicle network (2) and connected only indirectly to the first control unit (3), wherein the determination of the propagation time (21) of the third signal (22) is triggered by a service message (20) sent from the first control unit (3) to the third control unit (5).
12. A control unit for an Ethernet vehicle network (2), the control unit being designed as a first control unit (3) to: - Sending a signal (10) to a second control unit (4) of the Ethernet vehicle network (2) and receiving a signal (10) from a second control unit (4); - determining the propagation time (9) of the signal (10) on the connection path (6) to the second control unit (4); - determining a maximum speed (11) of the connection path (6) based on the propagation time (9); and - determining the type (12) of the transmission medium of the connection path (6) based on the maximum speed (11), and include at least - a microprocessor (402), - volatile memory (404) and non-volatile memory (406), - at least two communication interfaces (408), - a synchronizable timer (410), The non-volatile memory (406) contains program instructions that, when executed by the microprocessor (402), It is characterized by: Any embodiment of the method according to claims 1 to 10 can be implemented and carried out.
13. An Ethernet on-board network (2) for a motor vehicle (1), the Ethernet on-board network having a first control unit (3) and a second control unit (4), wherein: The control units (3, 4) are connected to one another via at least one connecting path (6, 7), and the first control unit (3) is designed according to claim 11.
14. The Ethernet vehicle network (2) according to claim 13, characterized in that The Ethernet vehicle network (2) comprises a third control unit (5) which is only indirectly connected to the first control unit (3) and directly connected to the second control unit (4) via a third connection path (8), wherein the third control unit (5) is designed to determine a propagation time (21) of a third signal (22) on the third connection path (8), wherein the first control unit (3) is designed to trigger the determination of the propagation time (21) of the third signal (22) by means of a service message (20) sent to the third control unit (5).
15. A computer program product comprising instructions which, when executed by a computer, cause the computer to perform the method (200) according to any one of claims 1 to 10.
16. A computer-readable medium having stored thereon the computer program product according to claim 14.
17. A vehicle comprising an Ethernet on-board network having a plurality of control units (3, 4, 5) according to claim 12.
Citation Information
Patent Citations
Low- power satellite-timed seismic data acquisition system
EP2191300A1
A method of time synchronization of free running nodes in an avionics network
EP2490357A2
Method and apparatus for time synchronisation in wireless networks
EP2759174A1
Definition of a primary active server in a coordinated timing network
US20080183896A1
Method for detecting a faulty timestamp of an Ethernet message and control unit for a motor vehicle
DE102017219209A1