Method for ensuring time synchronization of in-vehicle Ethernet network
By dynamically generating a key for encrypting time synchronization messages, the problem of time synchronization messages being easily tampered in the prior art is solved, and the operation security and network security of the vehicle are improved.
Patent Information
- Application Number
- CN202080087517.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-18
- Filing Date
- 2020-12-16
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2040-12-16
AI Technical Summary
The existing time synchronization methods and protocols fail to provide effective protection options, resulting in the time synchronization messages in the vehicle being easily tampered with, affecting the operational safety of the vehicle.
By determining the signal propagation time, maximum speed, and transmission medium type to form an entropy source, the keys used to encrypt time synchronization messages are dynamically generated, ensuring that each link has a unique key.
Improves security in the Ethernet field, prevents unauthorized eavesdropping and communication distortion, ensures the secure transmission of time-synchronized messages, and enhances the operational security of the vehicle.
Smart Images

Figure CN114846769B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication network comprising network devices synchronized with each other. Technical Background
[0002] Automobile manufacturers (OEMs) and Tier 1 suppliers in the automotive industry are preparing for the next-generation architecture of vehicle controllers or electronic control devices / control units (ECUs). One development is the so-called "zone-oriented architecture", in which control devices are grouped into zones such as the right front door zone. The difference from previous architectures is that the controllers are located at specific physical or spatial positions in order to optimally capture data from sensors located there. Thus, for example, a control unit that collects data from sensors of the right front door can be located in the right front door zone.
[0003] It is also considered to localize or distribute the software execution of features and applications to other controllers and processors. Such localization or distribution can be part of the optimization and can also be used in the event of an error or failure (e.g., of a control device). Such localization or distribution is called dynamic migration or simply migration. Mass production of dynamically migrating software to other control devices / processors within a vehicle is expected to be achieved soon.
[0004] Ethernet can be the preferred network for connecting control devices in a network. Ethernet technology is becoming increasingly popular in the electrical systems of vehicles and supplier products. The use of Ethernet technology requires an effective synchronization concept.
[0005] Existing Ethernet systems can use implementations of the time synchronization standard IEEE 802.1AS. Two variants that have received particular attention are the selection of 802.1AS-Rev and the time domain of 802.1AS-Rev, with the latter being a mandatory requirement for the former. Other protocols outside of the physical transmission standard are Ethernet AVB and its successor Ethernet TSN. Ethernet AVB has been introduced into mass production in automobiles. Important sub-standards for Ethernet TSN and AVB are the time synchronization standard IEEE 802.1AS, which depends on the main standard IEEE 802.1 to implement higher-layer LAN protocols (bridging). Both of these standards use the IEEE 1588 Precision Time Protocol (PTP) to establish a common time base in an Ethernet network.
[0006] At the third layer of the OSI layer model, Ethernet connections support a large number of switching protocols for transmitting data packets between a transmitter and a receiver. In higher protocol layers, data streams are segmented into packets, process communication is carried out between communication systems, data is converted into a system-independent form, and finally functions are provided for applications.
[0007] Almost all Ethernet communication networks used in vehicles use a protocol related to time synchronization, which provides a global network time base synchronized among all network devices. The penetration rate of time synchronization network devices is expected to continue to increase in the future.
[0008] The IEEE 802.1AS standard provides such a protocol related to time synchronization. Based on the so-called "best clock" (also known as the master or master clock) in the network, a master-slave clock hierarchy is established. The master provides the time base for the network, and all other network devices in the network are synchronized with this time base. The master is determined by the so-called Best Master Clock Algorithm (BMCA) and announced within the network. For this purpose, IEEE 802.1AS-compliant network devices send Announce messages containing information about their internal clocks to other directly connected network devices. The information about the internal clock provides an indication of the accuracy of the corresponding clock, its reference or time reference, and other properties that can be used to determine the best clock in the network. The recipient of such an Announce message compares the received information with the characteristics of its own internal clock and compares any messages already received from another port with the information related to the clocks of other network devices, and accepts the clock when the clock in another network device has better clock parameters. In a short time, the best clock in the network is determined, and this best clock then becomes the master in the network. Based on the master, messages related to time synchronization are broadcast through the network. Network devices receiving messages related to time synchronization do not simply forward the message, but correct the time information for the previously determined propagation time on the connection (through which the network device receives messages related to time synchronization from directly connected network devices) and the internal processing time, and then the network device re-transmits the message related to time synchronization and the corrected time information.
[0009] In the case of a clock hierarchy according to IEEE 802.1AS and the generalized precise time protocol (gPTP) defined therein, only a single network device always provides the best clock in the network. Therefore, this network device controls and regulates the entire time of the vehicle. All other clocks in the network devices in the network are specifically managed by this one clock. Some vehicle manufacturers even synchronize other standard networks (e.g., CAN) via this Ethernet time master, which means that almost all network devices in the vehicle are informed of the system time by the network device providing the master. Therefore, a single network device is defined as a single point of failure in the network or vehicle, and a failure or manipulation of this device may have a serious impact on the operational safety of the vehicle. Therefore, for example, in a vehicle with a highly driver support provided by an appropriate system or having a (semi)-autonomous driving system, a large amount of sensor data captured within a narrow time window must be processed together in order to derive appropriate control signals for the actuators in the vehicle. The most accurate possible time registration of the sensor data is also very important for documentation purposes (e.g., when stored in a log file, where the log file can be analyzed to reproduce malfunctions or operational errors). Reproducing incorrect operations is of particular interest to insurance companies and law enforcement agencies. Therefore, it is crucial to provide time information safely and synchronously.
[0010] To detect attacks of this type, DE 10 2012 216 689 B4 proposes monitoring the propagation time of messages related to time synchronization within a communication network. Even if the forwarded message is not changed, an additional network device that intercepts and forwards the message between two network devices will inevitably change the propagation time of the message.
[0011] Also, taking AUTOSAR considerations as an example, almost all data exchanged between control units is transmitted via IP, and therefore, the IP layer (i.e., all features and services of the IP layer) is used. The focus here is on IP-Sec. IPsec (short for Internet Security Protocol) is a set of protocols designed to allow secure communication over an IP network. The goal is to provide encryption-based security at the network level. IPsec provides this possibility through connectionless integrity as well as access control and authentication of data. Additionally, IPsec ensures the confidentiality and authenticity of the packet sequence through encryption.
[0012] As can be seen from the example of gPTP or 802.1AS, time synchronization is not transmitted via the IP layer and is not yet protected within the vehicle. Protocols of the same kind such as IPSec do not exist at the lower layers of the vehicle or would result in higher costs (e.g., MACSEC). Usually, messages are transmitted via Ethernet. Ethernet is the actual transport protocol here, i.e., messages are not transmitted via the IP layer. The protection mechanisms implemented and available there cannot be used.
[0013] Therefore, current methods and protocols related to time synchronization do not provide any simple protection options. Each network device can easily infer which network device in the network is the master from time synchronization-related messages sent as simple multicast Ethernet frames to multiple or all network devices in the network. Protection mechanisms at higher protocol layers such as IPSEC or TLS are not yet effective at this level. On the other hand, if time synchronization messages are sent via IP, the accuracy of clock synchronization or actual data fusion will be lost. If, for example, data related to sensor fusion is changed but data from, for example, a camera and a radar that do not belong together is fused, the manipulation may have serious consequences.
[0014] Several methods for using the time synchronization of a network to detect changes in the configuration or structure of a communication network are known from the prior art. For example, an unauthorized change to the configuration of a network can include inserting a network device to prepare for an attack, which intercepts messages for analysis and retransmits the changed messages if necessary. This can be used to prevent or at least interrupt safe and correct operation. Summary of the Invention
[0015] Therefore, an object of the present invention is to specify a method for ensuring improved protection of time synchronization, a control device for implementing the method, and a vehicle network for ensuring improved protection of time synchronization.
[0016] This object is achieved by the method according to claim 1 and the control unit according to claim 11. Embodiments and further developments are detailed in the corresponding dependent claims.
[0017] In an embodiment of a method for ensuring time synchronization of an Ethernet vehicle network 2 of a motor vehicle 1, the following steps are performed:
[0018] - Determine the propagation time 9 of a first signal 10 on a first connection path 6 between a first control unit 3 and a second control unit 4 of the Ethernet vehicle network 2;
[0019] - Determine the maximum speed 11 of the first connection path 6 based on the propagation time 9; and
[0020] - Determine the type 12 of the transmission medium of the first connection path 6 based on the maximum speed 11,
[0021] An entropy source is formed by determining the propagation time 9 of the first signal 10, determining the maximum speed 11 of the first connection path, and determining the type 12 of the transmission medium of the first connection path 6. At least one dynamic key 28 of the connection path 6 is determined according to the entropy source, and the at least one dynamic key is used to encrypt the time synchronization message of the connection path 6.
[0022] In another embodiment of the method, the dynamic key 28 of the connection path 6 is formed in such a way that the dynamic key is unique for each link in the Ethernet in-vehicle network per unit time.
[0023] Another embodiment of the present invention is characterized in that the dynamic key 28 of the connection path 6 is generated by combining the point-to-point line delay and the message frequency.
[0024] Another embodiment of the present invention is characterized in that the type 12 of the transmission medium is transmitted to the program 13 in the Ethernet in-vehicle network 2, the connection path selection 14 of the program 13 is adapted according to the type 12 of the transmission medium, the program 13 records all information of the entropy source, and the dynamic key 28 of the connection path 6 is generated.
[0025] In another embodiment of the method, the type 12 of the transmission medium is determined to be optical, copper, or wireless.
[0026] Another embodiment of the present invention is characterized in that a transmission security value 15 is assigned to the first connection path 6 based on the type 12 of the transmission medium, and the transmission security value describes the loss probability of the data transmitted through the first connection path 6.
[0027] Another embodiment of the method is characterized in that the propagation times of a plurality of signals on the first connection path 6 are determined, the fastest propagation time among the plurality of signals is selected, and the maximum speed 11 of the first connection path 6 is determined based on the fastest propagation time.
[0028] Another embodiment of the method is characterized in that the propagation time 16 of the second signal 17 on the second connection path 7 different from the first connection path 6 between the first control unit 3 and the second control unit 4 is determined, the maximum speed 11 of the second connection path 7 is determined, and the type 19 of the transmission medium of the second connection path 7 is determined based on the maximum speed 11 of the second connection path 7.
[0029] Another embodiment of the method is characterized in that the method is executed after the first control unit 3 changes from the normal operation mode to the energy-saving mode and / or from the energy-saving mode to the normal operation mode.
[0030] In another embodiment, the first control unit 3 is used to determine the propagation time 9 of the first signal 10, and the third control unit 5 of the in-vehicle Ethernet network 2 is used to determine the propagation time 21 of the third signal 22 on the third connection path 8 between the second control unit 4 and the third control unit 5, which is only indirectly connected to the first control unit 3. The determination of the propagation time 21 of the third signal 22 is triggered by a service message 20 sent from the first control unit 3 to the third control unit 5.
[0031] Embodiment of a control unit for an in-vehicle Ethernet network 2, the control unit being designed as a first control unit 3 to:
[0032] - Send a signal 10 to a second control unit 4 of the in-vehicle Ethernet network 2 and receive the signal 10 from the second control unit 4;
[0033] - Determine the propagation time 9 of the signal 10 on the connection path 6 to the second control unit 4;
[0034] - Determine the maximum speed 11 of the connection path 6 based on the propagation time 9; and
[0035] - Determine the type 12 of the transmission medium of the connection path 6 based on the maximum speed 11, wherein the control unit 3 at least includes
[0036] - A microprocessor 402,
[0037] - A volatile memory 404 and a non-volatile memory 406,
[0038] - At least two communication interfaces 408,
[0039] - And a synchronizable timer,
[0040] And the non-volatile memory 406 contains program instructions which, when executed by the microprocessor 402, implement at least one embodiment of the method according to the invention as claimed in claims 1 to 10, and the entropy source is formed in the volatile memory 404 and / or the non-volatile memory 406, the entropy source being used to form the dynamic key 28 of the connection path 6.
[0041] Embodiment of an in-vehicle Ethernet network 2 for a motor vehicle 1, the in-vehicle Ethernet network having a first control unit 3 and a second control unit 4, wherein these control units 3, 4 are connected to each other via at least one connection path 6, 7, and the first control unit 3 is designed as claimed in claim 11.
[0042] Another embodiment of the in-vehicle Ethernet network is characterized in that the in-vehicle Ethernet network 2 has a third control unit 5, which is only indirectly connected to the first control unit 3 and is directly connected to the second control unit 4 through a third connection path 8, wherein the third control unit 5 is designed to determine the propagation time 21 of a third signal 22 on the third connection path 8, and wherein the first control unit 3 is designed to trigger the determination of the propagation time 21 of the third signal 22 by means of a service message 20 to the third control unit 5.
[0043] One embodiment is represented by a computer program product. The computer program product includes instructions which, when the program is executed by a computer, cause the computer to perform the method 200 as described in one or more of claims 1 to 10.
[0044] One embodiment is provided on a computer-readable medium, on which the computer program product as described in claim 12 is stored.
[0045] One embodiment is provided in a vehicle, which has a plurality of control units 3, 4, 5 as described in claim 12, and the vehicle includes an in-vehicle Ethernet network.
[0046] The present invention improves security in the field of Ethernet and thus makes up for security vulnerabilities. In addition, a standardizable method for facilitating the use of Ethernet in a vehicle is provided.
[0047] This method involves a control unit determining the propagation time of data transmission to a second control unit via an in-vehicle network. The important factor is that the propagation time is determined in some form based on the actual physical conditions of the transmission path from the first control unit to the second control unit, that is to say, the transmission path has physical conditions or properties, and when they change, the determined propagation time will change. A separate and constantly changing key is generated based on the line delay and the message frequency. This key is unique within each unit of time and is also different for each link, and there will be no two identical keys in the network.
[0048] In other words, the time synchronization message is encrypted using a dynamic key, which can be obtained from various parameters related to the connection partner that form an entropy source.
[0049] Generating the key by combining the point-to-point line delay and the crystal frequency makes the key particularly resistant to attempts to bypass it, because firstly the key is constantly changing, and secondly the key will be different for each link in the vehicle network. These two values can be used directly in combination or can be extended by other static values in order to generate the key, and these static values must be known to the two control devices or control units (such as addresses).
[0050] In this context, the consideration of the previously determined propagation times and message frequencies is an entropy source for further enhancing security. In the sense of converting non-deterministic physical processes (such as electronic noise or radioactive decay) into digital signals, typical random number generators for computers (and especially for embedded systems or network components) are not "true" random number generators. Instead, pseudo-random number generators are used here. Starting from initialization, these generators produce digital sequences in a deterministic manner and often rely on quasi-random system events for initialization.
[0051] The effects provided by this method (i.e., preventing unauthorized eavesdropping, communication distortion, and device swapping) can also be achieved in other ways with a higher security level, for example, by using a control unit or hardware encryption employed in the vehicle network.
[0052] On the other hand, in a vehicle, it is generally uneconomical to equip all subscribers connected to the network with hardware devices sufficient for seamless encrypted communication. The described method requires significantly fewer hardware resources and can be put into action using existing implementations, thereby significantly enhancing the security level, which is not necessarily related to higher production costs of the vehicle network or the devices connected to it.
[0053] As described above, the main advantage of this method is that even without using additional hardware, this method can use the line from the first subscriber to the second subscriber as a hardware-related entropy generation means for randomly generating time encryption. This method can especially be implemented in the form of software, which can be distributed as an update or upgrade to the existing software or firmware of the subscribers in the network and is an independent solution in this regard.
[0054] The execution quality of software-based applications (such as autonomous driving) can be advantageously improved by the present invention, especially without additional financial expenditure. The vehicle network according to the present invention is improved in terms of cost and reliability. Therefore, a software-based method can be used to generate meta-information from a control unit or a vehicle network, so as to then create higher-level functions therefrom.
[0055] Advantageously, the present invention allows for a very easy and significant enhancement of the security of the vehicle network. The use of the newly introduced Ethernet protocol in an automobile requires mechanisms that utilize simple technologies and given technical properties in order to be able to be implemented without expensive implementation and additional hardware. Attacks and abnormal behaviors can be detected earlier by early analysis of the communication path, thereby allowing vulnerabilities and errors to be identified before vehicle delivery. The vehicle network according to the present invention is improved in terms of cost and reliability. The present invention more clearly defines the testability of the vehicle network and can thus save test costs. The present invention also provides transparent security functions.
[0056] The proposed method ensures that each link in a vehicle and thus each link in every vehicle worldwide has a different encryption. Consequently, in-vehicle networks are significantly more secure than comparable systems because the keys are constantly changing and are also based on a secure entropy source.
[0057] The present invention allows for an improvement in the quality of distributed applications, such as sensor fusion. The advantage of the application-specific determination of a better clock lies in the improved time synchronization of the selected application. This allows for the maximum possible accuracy to be obtained from this protocol or a similar protocol with only one timing node. This results in a more accurate synchronization, which means that more expensive crystals and components can be dispensed with. This also has an impact on the buffer storage that would otherwise be required, so that the buffer storage can be dispensed with or reduced. Thus, the fusion of different data (e.g., camera and radar) can be improved and made more accurate. In addition, the recording of data can be made more precise.
[0058] The present invention enables higher-quality platform-independent software. This method makes the software more flexible and advantageously allows the use of information from the underlying system without having to permanently program it into the software beforehand. The present invention allows software developers and software architects to provide software / applications that can be customized more flexibly and precisely according to the requirements of the application. Incorporating the cited method into the software allows for optimization in the respective case or within the control device. This means that the software becomes more platform-independent.
[0059] The advantage of the present invention is that there is no need to change the ordinary hardware, but rather the existing hardware can continue to be used. The new method can be integrated into the existing network without damaging the existing devices or control units. The used standards are not violated because existing protocols can be used.
[0060] Once the unique clock identification of the master clock determined during initialization has been sent to all network devices, the selected network devices can start sending encrypted messages related to time synchronization. However, it is also possible to start sending encrypted messages related to time synchronization only when the first time synchronization of all network devices in the network is completed.
[0061] The control units are connected to each other via physical interfaces. Messages related to time synchronization are sent via the logical ports defined for the interfaces, which means that there is a point-to-point connection for time synchronization between two network devices even when sharing a physical transmission medium. In this specification, unless the context otherwise requires, the term interface is used synonymously with the term port.
[0062] A computer program product according to the present invention contains instructions that, when executed by a computer, cause the computer to execute one or more embodiments and further developments of the above-described method.
[0063] The computer program product can be stored on a computer-readable medium or data carrier. The data carrier can be physically embodied as, for example, a hard disk, CD, DVD, flash memory, etc.; however, the data carrier or the medium can also include modulated electrical, electromagnetic or optical signals, which can be received by a suitable receiver by the computer and can be stored in the memory of the computer.
[0064] The control unit according to the invention comprises at least one physical communication interface, in addition to a microprocessor, a volatile memory and a non-volatile memory, and a timer. The components of the control unit are communicatively connected to each other via one or more data lines or data buses. The memory of the control unit contains computer program instructions which, when executed by the microprocessor, configure the network device to implement one or more embodiments of the above method.
[0065] The method according to the invention can be implemented using existing network devices, where, if necessary, only the software or state machine for receiving and processing messages related to time synchronization needs to be adjusted so as to synchronize the clock using only messages related to the time synchronization with the master clock determined during initialization, but still forward additional messages related to time synchronization instead of simply deleting them. Thus, the implementation process only incurs very low additional costs (if any). Even existing systems can be configured to implement the method by appropriately changing the software. Another advantage of the method according to the invention is that as long as synchronization according to the IEEE 802.1AS standard is supported, a specific underlying hardware platform is irrelevant. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] The invention will be explained below by way of example with reference to the drawings. In the drawings:
[0067] Figure 1 A schematic plan view of a motor vehicle is shown, which motor vehicle has an exemplary embodiment of an in-vehicle Ethernet network according to the invention;
[0068] Figure 2 A schematic representation of an in-vehicle Ethernet network is shown, which in-vehicle Ethernet network has a first control unit, a second control unit and a third control unit, which control units are connected via a first connection path, a second connection path and a third connection path;
[0069] Figure 3 A flow chart for encrypting time synchronization messages for determining the type of transmission medium of a corresponding connection path is shown;
[0070] Figure 4 A representation of the link delay of two connected control devices and a measurement of the message frequency are shown;
[0071] Figure 5 Shows a flowchart of repeatedly generating a key;
[0072] Figure 6 Shows a flowchart for measuring a delay that forms a first parameter of a key;
[0073] Figure 7 Shows a flowchart for determining an individual crystal frequency that forms a second parameter of a key;
[0074] Figure 8 Shows a flowchart for calculating a key and sending a message;
[0075] Figure 9 Shows a flowchart for using a key over time;
[0076] Figure 10 Shows a flowchart for determining the type of transmission medium of a corresponding connection path;
[0077] Figure 11 Shows a flowchart for adapting a program in an Ethernet in-vehicle network;
[0078] Figure 12 Shows a flowchart for determining and storing the propagation time of a signal;
[0079] Figure 13 Shows a flowchart for creating a list of reference values for propagation time;
[0080] Figure 14 Shows a flowchart for illustratively adapting a program in an Ethernet in-vehicle network;
[0081] Figure 15 Shows an encryption link using a dynamic key generated from communication of a control unit;
[0082] Figure 16 Shows the design of a control unit;
[0083] Figure 17 Shows a sequence for decoding.
[0084] Elements that are the same or similar in the drawings may be represented by the same reference numerals. Detailed Description
[0085] Figure 1A plan view of a motor vehicle 1 is shown. The motor vehicle 1 has an Ethernet in-vehicle network 2. According to an exemplary embodiment, the Ethernet in-vehicle network 2 in turn has a plurality of control units 3, 4, 5, which can also be referred to as control devices or control equipment. In this case, the control units are connected to each other by connection paths. Due to the existing topology of the Ethernet in-vehicle network 2 in the exemplary embodiment, there are a plurality of parallel communication paths between the control units. For example, the connection paths can be formed by different media types or materials.
[0086] For example, with the increase in the number of Ethernet variants, the dynamic change of the connection speed will also be used. This means that, for example, the speed can be changed during operation. For example, a connection path of 10 Gbit / s can be changed to 100 Mbit / s, thereby saving energy. Since this is a dynamic function, it may happen that, for example, the in-vehicle network is different in form after delivery or initial installation in the motor vehicle than after a software update or in the event of a fault.
[0087] The Ethernet in-vehicle network 2 has at least a first control unit 3, a second control unit 4 and a further third control unit 5. The first control unit 3 is connected to the second control unit 4 via a first connection path 6. Furthermore, according to the exemplary embodiment, the first control unit 3 is also connected to the second control unit 4 via a second connection path 7.
[0088] The first control unit 3, the second control unit 4 and / or the third control unit 5 can, for example, be in the form of a control device or a network switch. The second control unit 4 and the third control unit 5 are connected to each other via a third connection path 8.
[0089] According to Figure 1 the exemplary embodiment, the first control unit 3 and the second control unit 4 are directly connected to each other via the first connection path 6, while the first control unit 3 and the second control unit 4 are only indirectly connected via the second connection path 7 because the second connection path 7 is divided into two parts by another control unit. However, according to another exemplary embodiment, the second connection path 7 can also directly connect the first control unit 3 and the second control unit 4 to each other.
[0090] Figure 2Shows another exemplary embodiment of the in-vehicle Ethernet network 2. The in-vehicle Ethernet network 2 has a first control unit 3, a second control unit 4, and a third control unit 5. In addition, the in-vehicle Ethernet network 2 also has a first connection path 6, a second connection path 7, and a third connection path 8. According to the exemplary embodiment, the propagation time 9 of the first signal 10 on the first connection path 6 is determined. The propagation time 9 describes the time length for the first signal 10 to be relayed from the first control unit 3 to the second control unit 4 via the first connection path 6 (or vice versa). Based on the propagation time 9 of the first signal 10, the maximum speed 11 of the first connection path 6 is determined. The maximum speed 11 of the first connection path 6 varies in this case, for example, according to the cable length, transmission speed, and / or medium type, or transmission medium type. Based on the maximum speed 11, the type 12 of the transmission medium of the first connection path 6 is determined.
[0091] According to the exemplary embodiment, the type 12 of the transmission medium is defined as optical, copper, or wireless. In the optical case, the first connection path 6 takes the form of, for example, a fiber optic connection. In the copper case, the first connection path is formed, for example, by a cable with twisted pairs, such as an unshielded twisted pair (UTP) cable. In the wireless case, the first connection path 6 basically takes the form of a radio link, and the first control unit 3 and / or the second control unit 4 has a radio receiver and / or a radio transmitter or is connected to a radio receiver and / or a radio transmitter.
[0092] Combined with Figure 3 the sequence shown, the control unit 3 averages the propagation time of data transfer from the in-vehicle network to the control unit 4. The important factor is that the propagation time is determined in some form based on the actual physical conditions of the transmission path from the first control unit 3 to the control unit 4, that is, the transmission path has physical conditions or properties, and when they change, the determined propagation time will change.
[0093] The proposed method involves a control unit 3 determining the propagation time of data transfer from the network to the control unit 4. This can be performed in any desired manner. For example, the propagation time can occur, for example, during the time synchronization process between the first subscriber and the second subscriber according to the time synchronization standard IEEE 802.1AS and the PTP protocol included therein. Therefore, for example, the "delay request" message and the "peer delay" message implemented as part of the protocol can be used as data packets, as Figure 3 shown. However, the method is not limited to this. The important factor is only that the propagation time is determined in some form based on the actual physical conditions of the transmission path from the first subscriber / control unit 3 to the second subscriber / control unit 4, that is, the transmission path has physical conditions or properties, and when they change, the determined propagation time will change.
[0094] In addition, the first control unit 3 determines the message frequency of the control unit 4 on the other side, which is basically obtained from the speeds of the PLL and the crystal. The control unit 3 obtains a key for encrypting these time messages from these two values that are constantly changing due to temperature, aging, etc.
[0095] The time synchronization messages are encrypted using the generated dynamic key, which generally can be obtained from various parameters related to the connection partner.
[0096] A separate and constantly changing key is generated based on the line delay 221 and the message frequency 213. This key is unique within each unit of time and is also different for each link. Due to this method, there will be no duplicate keys in the network, as Figure 15 shown. Generating the key through the combination of the point-to-point line delay and the crystal frequency makes the key particularly resistant to attempts to bypass it, because firstly the key is constantly changing, and secondly the key will be different for each link in the vehicle network.
[0097] These two values can be directly combined for use or can be extended by other static values (such as an address) that must be known to the two control devices in order to generate the key.
[0098] The corresponding control unit (the method can be executed on these two control units, or on the subscriber / link partner) determines a random value therefrom in order to obtain a separate key for encryption, which is only valid for a short period of time. As Figure 3 shown, the key changes repeatedly based on previous measurements, which do not represent any additional work because they are for time synchronization.
[0099] The type 12 of the transmission medium is transmitted to the program 13 in the in-vehicle Ethernet network 2. The program 13 can be present, for example, in the first control unit 3, the second control unit 4, or the third control unit 5, or another control unit of the in-vehicle Ethernet network 2. The type 12 of the transmission medium is regarded as the basis for adapting the connection path selection 14. Thus, the program 13 can use the connection path selection 14 to send data, for example, via a different connection path compared to before the connection path selection. However, the program 13 can also, for example, interrupt sending data via the connection path selection 14 and can resume at a later time.
[0100] According to an exemplary embodiment, a transmission security value 15 is assigned to the first connection path 6 based on the type 12 of the transmission medium. The transmission security value describes the probability of loss of data transmitted through the connection path. That is, the transmission security value 15 illustrates the reliability with which data can be transmitted through the first connection path. This is provided to the entropy source 200. If, for example, a safety limit value is not reached and data can only be transmitted unreliably, it must be expected that the data will reach its destination with a certain delay or will not reach its destination at all in cases where it is not worth retransmitting the data because the data is required to be up-to-date.
[0101] According to another exemplary embodiment, the propagation times of a plurality of signals on the first connection path 6 are determined, and the fastest propagation time among the plurality of signals is selected. Then, based on the fastest propagation time, the maximum speed 11 of the first connection path 6 is determined.
[0102] The control unit starts measuring the delay and waits for the reception of a link partner message. Based on the message received using the PTP example, the line delay can be measured as Figure 6 shown. If one link partner starts measuring the delay, the other link partner will inevitably notice this and should also start measuring so that the two measurements can also generate relevant measurement values, as Figure 3 shown.
[0103] For the sake of explanation, the PTP example is used here to demonstrate the process. PTP defines three mechanisms: measuring the line delay between adjacent nodes, determining the best clock, and exchanging time information. The purpose of the peer delay mechanism is to measure the delay between two connected ports. The measured propagation time is used to correct the node's time information and include this time. The Delay_Request messages are sent cyclically and independently by two communication partners to each other. If the corresponding node is IEEE 802.1AS-compatible, the node will respond with Delay_Response messages and Pdelay_Resp_Follow_Up messages. These messages arrive with hardware timestamps and are forwarded to the PTP application. This allows the determination of the delay and time difference to the adjacent port. The port (initiator) starts the measurement by sending a Delay_Request message to the port (responder) connected to it and generating an egress timestamp t1. This egress timestamp represents the hardware timestamp written as late as possible when leaving the Ethernet transceiver. When the packet arrives, the responder generates a timestamp t2. In response, the responder sends a Delay_Response message. In this message, the responder transmits the receive timestamp t2 of the Delay_Request message. When this message leaves the responder, the responder further generates a timestamp t3, which is sent in the subsequent Delay_Response_Follow_Up message. When the initiator receives the Delay_Response message, the initiator generates a timestamp t4. The initiator can use the four timestamps t1 to t4 to calculate the average propagation time of the covered route.
[0104] PTP defines the master / slave clock hierarchy with the best clock in the AVB network. The time base of the nodes in the network is obtained from this clock (i.e., the master). The best master clock algorithm (BMCA) is used to determine this clock type, and this information is announced in the network. IEEE 802.1AS-compatible systems send periodic Announce messages with information about the best clock in the AVB cloud to their adjacent nodes. The recipients of such messages compare this information with the characteristics of their clocks and any messages already received from another port. Based on these messages, a time synchronization spanning tree is established. During this process, one of four port states is assigned to each port. The port with a shorter path to the master than its link partner is set to the "master port" state. This state is assigned when no other port at the node has the "slave" state. Disabling is selected by ports that do not fully support the PTP protocol. If none of the other three states are applicable, the "passive" state is selected.
[0105] Finally, time information is exchanged through the Sync_Follow_Up mechanism. The master port cyclically sends Sync messages and Follow_Up messages to adjacent link partners. When the Sync message leaves the master port, a timestamp is generated that is immediately transmitted in the subsequent Follow_Up message. This timestamp corresponds to the current time of the master at the time the Sync message was sent. Messages originating from the master are not forwarded but regenerated in each node (including switches). Then, measurements are started to determine the individual crystal frequencies from the message frequencies. The frequency can be calculated based on the reception of messages using the PTP example, as Figure 3 shown. It is not always possible to see that the link partner is also measuring the frequency simultaneously, which is why the frequency measurement should be continuously performed.
[0106] The type 12 of the transmission medium of the second connection path 7 and / or the third connection path 8 can also be determined similarly to the above method. The individual recorded values are different, kept confidential each time, and stored in the control device, and are not transmitted over the network either - these values do not have to be transmitted. It is completely impossible to discover the key only through trial and error. A separate key is generated by taking these two values into account. First, the frequency of each crystal is different, and second, the line delay of each link is different. Here, adding the two fluctuating values together gives a third value - the value of the key - that is more difficult to guess. The line delay usually may be in the range of 50 to 500 nanoseconds, and the frequency is a parameter given in + / - ppm. The round-trip line delay is based on the same channel, which is why the calculated values on both sides of the link are the same. Therefore, there is no need to exchange parameters.
[0107] NRR determines the measured ratio between the frequency of the LocalClock unit of the Timeaware system connected to the port at the other end of the connection and the frequency of the LocalClock unit of this timing system.
[0108] The time-aware system can be equivalent to the control unit here.
[0109] NRR is also available to both partners without the need for exchange. The sending node exactly knows the sending time of the message (hardware timestamp), and the receiving node exactly knows the sending time of the message from the previous line measurement.
[0110] This means that the two partners almost simultaneously have the same values to generate the key. One link partner encrypts using these two values obtained from the previous measurement, while the other link partner decrypts using its previous values.
[0111] Accordingly, it is also specified to determine the propagation time 16 of the second signal 17 on the second connection path 7. Then, based on the propagation time 16 of the second signal 17, the maximum speed 18 of the second connection path 7 is determined. Furthermore, based on the maximum speed 18 of the second connection path 7, the type 19 of the transmission medium of the second connection path 7 is determined.
[0112] As long as no new line measurement is performed, it is advantageous to use the current key A1, as Figure 10 shown. In this way, if no new line measurement has been initiated beforehand, the link partner always knows which key to use. The new key should / can be generated cyclically (e.g., at a predefined frequency), or be triggered by a trigger as needed or always immediately before sending an important message.
[0113] The first control unit 3, the second control unit 4, and the third control unit 5 can all operate in a normal operation mode or an energy-saving mode. In the energy-saving mode, the corresponding control unit consumes less energy than in the normal operation mode. For example, in the energy-saving mode, the speed of the ports of the corresponding control unit can be reduced compared to the speed in the normal operation mode. Then, the reduced port speed also affects the corresponding maximum speed of the corresponding connection path.
[0114] According to another exemplary embodiment, the service message 20 can be sent from the first control unit 3 to the third control unit 8. Then, the determination of the propagation time 21 of the third signal 22 is triggered by the service message 20. The third signal 22 is sent between the second control unit 4 and the third control unit 5. According to the exemplary embodiment, the third control unit 5 determines the propagation time 21 of the third signal 22.
[0115] Figure 10 An overall description of the method for determining the propagation time is provided. In step S1, the propagation time 9 of the first signal 10 is determined. In step S2, the type 12 of the transmission medium is determined. Finally, in step S3, the program 13 is adapted.
[0116] Figure 11 A flowchart for calculating the respective parameters or the respective parameters assigned to the type 12 of the transmission medium is shown. In step S4, the propagation time 9 of the first signal 10 is determined. Thus, in step S5, the type 12 of the transmission medium can be determined. The type 12 of the transmission medium can further include the following parameters: speed 23, medium 24, cable length 25, power transmission 26, bit error rate 27. Finally, in step S6, the adaptation of the program 13 and the connection path selection 14 follow.
[0117] According to an exemplary embodiment, a propagation time of a signal between connected control units or controllers is measured. A method such as the standard IEEE 1588 or IEEE 802.1AS can be used to measure the propagation times 9, 16, and 21. The method can also be provided by TTEthernet (Time-Triggered Ethernet), for example, to determine the corresponding propagation times 9, 16, and 21.
[0118] Figure 12 The determination of the corresponding propagation times 9, 16, and 21 is shown. A local and non-local query of the propagation time is described. The program 13 (which is particularly executed on at least one control unit) preferably first locally determines the local propagation time, or determines multiple propagation times if more than one control unit is directly connected. Then, preferably by a service-oriented method such as SOME / IP (Scalable Service-Oriented Middleware based on IP), other control units are queried for their propagation times to their neighbors. This can be implemented centrally or in a decentralized manner. The query can be executed once at system startup, definition, or after a software update, or can be executed cyclically to detect dynamic changes. Then, these data are stored and assigned for the first time, particularly including the addresses of the control units.
[0119] In step S7, the corresponding propagation times to directly connected control units are determined. In step S8, the corresponding propagation times of other connection paths are queried. In step S9, the corresponding propagation times and their associated connection partners are stored.
[0120] Figure 13 Another method for obtaining other speeds based on a reference measurement is shown. For example, if the current temperature is very high or the cable used is poor, the pre-stored values may be very inaccurate. Therefore, it is proposed that the application or program 13 itself performs measurements on its own control unit, particularly according to its own parameters and other speeds that can then be obtained and calculated therefrom.
[0121] In step S10, each local Ethernet port performs an analysis once. In step S11, a test is performed on whether the channel parameters are known. If this is not the case, then step S12 is performed next, and the method ends. If this is the case, then step S13 is performed next, in which the corresponding propagation times 9, 16, and 21 are determined. Storage is performed in step S14, and the determined propagation times are related to the channel parameters. In step S15, a reference value list is created.
[0122] Figure 14Shows possible optimizations based on knowledge of the types 12, 19 of the transmission medium. In step S16, it is determined whether the types 12, 19 of the transmission medium are copper. If this is the case, then step S17 follows, in which it is confirmed that PoDL (Power over Data Lines) (that is, power supply via Ethernet) is possible. If the determination in step S16 is that the medium is not copper, then step S18 follows. In step S18, an inspection is performed to determine whether the type 12 of the transmission medium is optical. If this is the case, then step S19 follows. In step S19, it is found that the bit error rate is thus low and the reliability of this connection path is thus high. In step S20, the option is provided to deactivate the RX (receive unit) or TX (transmit unit) of the control units 3, 4, 5 if they are not required.
[0123] If the determination in step S18 is that the medium or type 12 of the transmission medium is not optical, then in step S21 it is assumed that the corresponding connection path (as the relevant connection path) takes the form of a direct MII (Media Independent Interface) connection. In this case, the corresponding control unit is suitable for, for example, IEEE P802.1CB (Frame Replication and Redundancy Elimination).
[0124] Another option comes from knowledge of the propagation speed. In combination with the current data stream, data can be intentionally transmitted using a high-bandwidth connection, and thus, other unnecessary connection paths can be deactivated, thereby saving energy.
[0125] In addition, for high-bandwidth connections, there is the option of using a redundancy mechanism (for example, IEEE 802.1CB). Since data is continuously transmitted redundantly in this case, a high bandwidth is required for this. It is also conceivable to adapt the application according to the speed of the transmission path. For example, a camera can adapt the resolution of the image data to be transmitted according to the speed of the link or connection paths 6, 7, 8.
[0126] In addition to the microprocessor 402, the control units 3, 4, 5 also include a volatile memory 404 and a non-volatile memory 406, two communication interfaces 408, and a synchronizable timer. The elements of the network device are communicatively connected to each other via one or more data connections or data buses 412. The non-volatile memory 406 contains program instructions which, when executed by the microprocessor 402, implement at least one embodiment of the method according to the invention, and an entropy source is formed in the volatile memory 404 and / or the non-volatile memory 406, and the entropy source is then used to form the dynamic key 28 of the connection path 6. Figure 17 Shows the decoding sequence of the dynamic key during decryption.
[0127] List of reference numerals
[0128] 1 Motor vehicle
[0129] 2 In-vehicle Ethernet network
[0130] 3 First control unit
[0131] 4 Second control unit
[0132] 5 Third control unit
[0133] 6 First connection path
[0134] 7 Second connection path
[0135] 8 Third connection path
[0136] 9 Propagation time of the first signal
[0137] 10 First signal
[0138] 11 Maximum speed of the first connection path
[0139] 12 Type of transmission medium of the first connection path
[0140] 13 Program
[0141] 14 Connection path selection
[0142] 15 Transmission security value
[0143] 16 Propagation time of the second signal
[0144] 17 Second signal
[0145] 18 Maximum speed of the second connection path
[0146] 19 Type of transmission medium of the second connection path
[0147] 20 Service message
[0148] 21 Propagation time of the third signal
[0149] 22 Third signal
[0150] 23 Speed
[0151] 24 Medium
[0152] 25 Cable length
[0153] 26 Power transmission
[0154] 27 Bit error rate
[0155] 28 Dynamic key
[0156] 29 Time synchronization message
[0157] 200 Entropy source
[0158] 211 Transmit at time t1
[0159] 212 Receive at time t4
[0160] 213 Receive at time t4
[0161] 221 Receive at time t2
[0162] 222 Transmit at time t3
[0163] 223 Delayed transmit at time t3
[0164] 300 Encrypt message at time t5
[0165] 400 Control unit
[0166] 402 Microprocessor
[0167] 404 RAM
[0168] 406 ROM
[0169] 408 Communication interface
[0170] 412 Bus / communication interface
[0171] 1001 Receive encrypted message
[0172] 1002 Start line delay measurement and frequency measurement
[0173] 1003 Request previous line measurement and frequency parameters
[0174] 1004 Generate key
[0175] 1005 Decrypt message
[0176] A1 Calculate line delay 1 and calculate crystal frequency 1
[0177] A2 Calculate line delay 2 and calculate crystal frequency 2
[0178] B1 Calculate line delay 1 and calculate crystal frequency 1
[0179] B2 Calculate line delay 2 and calculate crystal frequency 2
Claims
1. A method for ensuring time synchronization of an in-vehicle Ethernet network (2) of a motor vehicle (1), wherein, Perform the following steps: - Determine the propagation time (9) of a first signal (10) on a first connection path (6) between a first control unit (3) of an in-vehicle Ethernet network (2) and a second control unit (4) of the in-vehicle Ethernet network (2); - Determine the maximum speed (11) of the first connection path (6) based on the propagation time (9); and - Determine the type (12) of the transmission medium of the first connection path (6) based on the maximum speed (11), characterized in that an entropy source is formed by determining the propagation time (9) of the first signal (10), determining the maximum speed (11) of the first connection path, and determining the type (12) of the transmission medium of the first connection path (6), and at least one dynamic key (28) for the first connection path (6) is determined according to the entropy source, and the at least one dynamic key is used to encrypt the time synchronization messages of the first pair of connection paths (6).
2. The method according to claim 1, characterized in that, The dynamic key (28) of the first connection path (6) is unique for each link in the in-vehicle Ethernet network at each unit of time.
3. The method according to claim 1 or 2, characterized in that, The dynamic key (28) of the first connection path (6) is generated by combining the point-to-point line delay and the message frequency.
4. The method according to any one of claims 1 to 3, characterized in that the type (12) of the transmission medium is transmitted to a program (13) in the in-vehicle Ethernet network (2) and the connection path selection (14) of the program (13) is adapted according to the type (12) of the transmission medium, and the program (13) records all information of the entropy source and generates the dynamic key (28) of the first connection path (6).
5. The method according to any one of claims 1 to 3, characterized in that the type (12) of the transmission medium is determined to be optical, copper, or wireless.
6. The method according to one of the preceding claims, characterized in that, A transmission security value (15) is assigned to the first connection path (6) based on the type (12) of the transmission medium, and the transmission security value describes the loss probability of data transmitted through the first connection path (6).
7. The method according to one of the preceding claims, characterized in that, Determine the propagation times of a plurality of signals on the first connection path (6) and select the fastest propagation time among the plurality of signals, wherein the maximum speed (11) of the first connection path (6) is determined based on the fastest propagation time.
8. The method according to one of the preceding claims, characterized in that, Determine the propagation time (16) of a second signal (17) on a second connection path (7) different from the first connection path (6) between the first control unit (3) and the second control unit (4), and determine the maximum speed (11) of the second connection path (7), wherein the type (19) of the transmission medium of the second connection path (7) is determined based on the maximum speed (11) of the second connection path (7).
9. The method according to one of the preceding claims, characterized in that, The method is executed after the first control unit (3) changes from a normal operation mode to an energy-saving mode and / or from an energy-saving mode to a normal operation mode.
10. The method according to one of the preceding claims, characterized in that, The propagation time (9) of a first signal (10) is determined using a first control unit (3), and the propagation time (21) of a third signal (22) on a third connection path (8) that is only indirectly connected to the first control unit (3) between a second control unit (4) and a third control unit (5) of an in-vehicle Ethernet network (2) is determined using a third control unit (5), wherein the determination of the propagation time (21) of the third signal (22) is triggered by a service message (20) sent from the first control unit (3) to the third control unit (5).
11. A control unit for an in-vehicle Ethernet network (2), which is designed as a first control unit (3) to: - send a signal (10) to a second control unit (4) of the in-vehicle Ethernet network (2) and receive the signal (10) from the second control unit (4); - determine the propagation time (9) of the signal (10) on a first connection path (6) leading to the second control unit (4); - determine the maximum speed (11) of the first connection path (6) based on the propagation time (9); and - determine the type (12) of the transmission medium of the first connection path (6) based on the maximum speed (11), It is characterized in that The control unit (3) at least includes: - a microprocessor (402), - a volatile memory (404) and a non-volatile memory (406), - at least two communication interfaces (408), - a synchronizable timer, The non-volatile memory (406) contains program instructions that, when executed by the microprocessor (402), implement the method according to any one of claims 1 to 10, and form an entropy source in the volatile memory (404) and / or the non-volatile memory (406), and form a dynamic key (28) for the first connection path (6) according to the entropy source.
12. An in-vehicle Ethernet network (2) for a motor vehicle (1), the in-vehicle Ethernet network having a first control unit (3) and a second control unit (4), wherein, These control units (3, 4) are connected to each other through at least one connection path (6, 7), and the first control unit (3) is constructed according to claim 11.
13. The in-vehicle Ethernet network (2) according to claim 12, characterized in that, The in-vehicle Ethernet network (2) has a third control unit (5) that is only indirectly connected to the first control unit (3) and is directly connected to the second control unit (4) through a third connection path (8), wherein the third control unit (5) is designed to determine the propagation time (21) of a third signal (22) on the third connection path (8), and the first control unit (3) is designed to trigger the determination of the propagation time (21) of the third signal (22) by sending a service message (20) to the third control unit (5).
14. A computer program product that includes instructions that, when executed by a computer, cause the computer to execute the method according to any one of claims 1 to 10.
15. A computer-readable medium having a computer program stored thereon, characterized in that, When executed by a computer, the computer program implements the method according to any one of claims 1 to 10.
16. A vehicle that includes the in-vehicle Ethernet network (2) according to claim 12 or 13.
Citation Information
Patent Citations
Method for monitoring an Ethernet-based communication network in a motor vehicle
DE102012216689B4
Method for generating random number in cognitive radio network and communication key generation method
CN101980557A
Systems for transmitting or receiving signals encrypted by deterministic chaos and transmission system, in particular radio communications system comprising such systems
EP1071242A1