Identifying Errors in a Computer Network

By comparing the actual configuration with the target configuration in the coupling elements of the computer network, and combining the diagnostic counter and traffic supervision/shaping mechanism, it is possible to identify and resolve errors or exceptions of autonomous motor vehicles in the computer network, and to achieve efficient and reliable data packet forwarding of the network.

CN115443625BActive Publication Date: 2025-06-10BMW AG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180030615.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-04-27
Filing Date
2021-04-08
Publication Date
2025-06-10
Estimated Expiration
2041-04-08

AI Technical Summary

Technical Problem

There are errors or exceptions in computer networks, especially in computer networks where autonomous driving motor vehicles are computer networks, resulting in undesirable behavior when data packets are forwarded or discarded.

Method used

Identify configuration errors or exceptions by setting the target configuration in the coupling element and comparing it with the actual configuration. At the same time, the diagnostic counter and traffic supervision/shaping mechanism are used to determine packet drop situations and network traffic patterns to identify abnormalities.

Benefits of technology

Effectively identify and locate errors or exceptions in the computer network, ensure that packet forwarding and discarding meets the expected configuration, and improve network integrity and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115443625B_ABST
    Figure CN115443625B_ABST
Patent Text Reader

Abstract

One aspect of the present invention relates to a device for identifying errors in a computer network, wherein the network includes at least one coupling element that connects at least two network participants to each other; the coupling element includes a memory for the actual configuration of the coupling element; the coupling element forwards or discards data packets according to the actual configuration; the device includes a target configuration of the coupling element; and the device is configured to compare the actual configuration with the target configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Field of the Invention

[0001] The present invention relates to devices and methods for identifying errors and anomalies in computer networks. Background Art

[0002] In the context of this document, the term "automated driving" can be understood as driving with automatic longitudinal or lateral guidance or automated driving with automatic longitudinal and lateral guidance. The term "automated driving" includes automated driving with any degree of automation. Exemplary degrees of automation are assisted, partially automated, highly automated, or fully automated driving. These degrees of automation are defined by the Federal Highway Research Institute (BASt) (see BASt publication "Forschung kompakt", No. 11, 2012). In assisted driving, the driver continuously performs longitudinal or lateral guidance, while the system takes over other functions within certain limits. In semi-automated driving (TAF), the system takes over longitudinal and lateral guidance for a certain period of time and / or in specific situations, where the driver must continuously monitor the system, just like in assisted driving. In highly automated driving (HAD), the system takes over longitudinal and lateral guidance for a certain period of time, and the driver does not have to continuously monitor the system; however, the driver must be able to take over vehicle control within a certain time. In fully automated driving (VAF), the system can automatically handle driving in all situations for specific application scenarios; for such application scenarios, the driver is no longer required. According to the definition of BASt, the above-mentioned four degrees of automation correspond to SAE levels 1 to 4 of the SAE J3016 standard (SAE - Society of Automotive Engineers). For example, according to BASt, highly automated driving (HAF) corresponds to level 3 of the SAE J3016 standard. In addition, SAE level 5 is defined in SAE J3016 as the highest degree of automation, which is not included in the BASt regulations. SAE level 5 corresponds to driverless driving, where the system can automatically handle all situations during the entire journey like a human driver; usually, the driver is no longer required. Summary of the Invention

[0003] It is an object of the present invention to identify errors or anomalies in computer networks, especially in the computer networks of automated motor vehicles.

[0004] This object is achieved by the features of the independent claims. Advantageous embodiments are described in the dependent claims. It should be noted that additional features of claims which are subordinate to an independent claim can, without the features of the independent claim or in combination with only a subset of the features of the independent claim, form an invention which is independent and independent of the combination of all features of the independent claim, and this independent invention can be the subject of an independent claim, a divisional application or a subsequent application. This also applies to the technical teachings described in the specification, which can form an invention independent of the features of the independent claim.

[0005] A first aspect of the present invention relates to a device for identifying errors or anomalies in a computer network.

[0006] A computer network, in particular an Ethernet network, includes at least one coupling element (connecting element), in particular a switch or a hub. A switch (the English for "Schalter", "Umschalter" or "Weiche", also known as a network switch or distributor) refers to a coupling element that interconnects network segments in a computer network. Within a segment (broadcast domain), the switch ensures that data packets reach their destinations.

[0007] The term switch generally refers to a multi-port bridge, i.e., an active network device that forwards frames based on information from the data link layer (Layer 2) of the OSI model. Sometimes the more precise terms "bridging hub" or "switching hub" are also used. In the IEEE 802.3 standard, this function is called MAC bridging.

[0008] A device equivalent to a switch on network Layer 1 (Layer 1) is called a (repeater) hub. A switch that additionally processes data at the network layer (Layer 3 and higher) is usually called a Layer 3 switch or a multi-layer switch and can perform the functions of a router. In non-Ethernet networks, the coupling task is assigned to a so-called gateway, which can interconnect heterogeneous networks in a manner similar to a router or a switch.

[0009] The coupling element connects at least two network participants to each other, where a network participant can also be another coupling element.

[0010] The coupling element includes a memory for the actual configuration of the coupling element and decides whether to forward or discard a data packet according to this actual configuration.

[0011] The device includes a target configuration for the coupling element and is configured to compare the actual configuration with the target configuration.

[0012] The comparison between the target configuration and the actual configuration can be performed one or more times, where in particular the comparison is repeated regularly.

[0013] The present invention is based on the following recognition: The actual configuration in the memory of a coupling element may be tampered with due to errors such as external interference, which may lead to unexpected behavior when forwarding or discarding data packets.

[0014] Furthermore, based on the following recognition: Even if the configuration is correct or not tampered with, due to external influences, systematic or random errors, the coupling element may exhibit behavior different from that specified by the configuration.

[0015] By comparing the actual configuration with the target configuration, it can be determined at least in a snapshot whether the actual configuration has changed due to errors compared to the target configuration. Although the target configuration may also change due to errors, the probability that the same error occurs when comparing the actual configuration and the target configuration is extremely low, and technically it can be reduced to any degree by coding measures. In an advantageous embodiment, the device is a network participant connected to the coupling element.

[0016] In addition to the actual configuration, the device can also access the diagnostic counters of the coupling element in order to be able to determine, for example, when, which, and how many data packets are discarded and the reasons. In an advantageous design, this mechanism can be used to ensure the integrity of certain configuration items. The device is set to send a specified number of data packets to another network participant through the coupling element at a specified time point - these data packets are suitable for testing the configuration items of the coupling element for network separation of the primary and secondary control units, determine the number of data packets discarded by the coupled unit, and compare the number of data packets sent to other network participants with the number of data packets discarded by the coupled unit.

[0017] Suitable data packets are data packets that can be used to test the correctness of the individual components of the configuration. For example, data packets with an unconfigured VLAN should be discarded. The knowledge of the target system behavior, i.e., the signature of the overall network, can also be advantageously used.

[0018] The present invention is based on the recognition that the number of data discarded by a properly operating coupling element is specified by configuration limitations (e.g., the amount of data defined each time), or other configurable attributes or filtering rules, and by the performance of the coupling element itself.

[0019] In another advantageous embodiment, the configuration of the coupling element at least specifies an upper limit of the data packets to be forwarded by the coupling element within a specified time, in particular by specifying a data rate in Mbit / s, for example.

[0020] For example, this is traffic shaping. Traffic shaping describes a form of queue management in a packet-switched data network, where packets are delayed or dropped according to specific criteria to meet specific demand configuration requirements. This function is performed through the interaction of a network scheduler and a network shaper and is essentially a form of rate limiting. Traffic shaping is unidirectional and usually memoryless, which means that, contrary to flow control, it operates without control information from the other party.

[0021] Alternatively, this is traffic policing, for example. Traffic policing is a traffic technique similar to traffic shaping, except that it applies to incoming packets and installs rules that allow non-compliant packets to be dropped. In contrast to traffic shaping, packets are not cached, but the frequency of dropped policing packets is recorded.

[0022] In another advantageous embodiment of the invention, the configuration of the coupling element gives an upper limit for forwarding the packets received by a network participant within a specified time (e.g., by traffic policing), and / or an upper limit for forwarding the packets sent to a network participant within a specified time (e.g., by traffic shaping). In particular, the upper limit can be selected such that it does not affect the complete network and its characteristic traffic signature, but identifies abnormal traffic or misconfigurations and drops the packets belonging to an atypical traffic pattern. These packet losses can be used as an indicator of network integrity.

[0023] As a supplement to this embodiment, useful traffic can also be designed such that the selected upper limit can be made narrower and more sensitive. For example, this can be achieved by "slipping" short-term high data rates into longer time intervals to avoid traffic peaks.

[0024] In another advantageous embodiment, the device is arranged to compare the difference between the number of packets sent to another network participant and the number of packets dropped by the coupling unit with at least one upper limit of the packets forwarded by the coupling element within a specified time.

[0025] The present invention is based on the recognition that conclusions about a misconfiguration of the coupling unit can be drawn by means of the comparison. In addition, the coupling element consists of a large number of technical elements that together form an effect chain. The configuration is only part of this effect chain. From this, a fault in the entire effect chain within the coupling element can be inferred by means of the comparison, which can be identified by measurement and leads to a deviation from the target function.

[0026] In another advantageous design, any comparison is carried out with the highest available ASIL integrity.

[0027] In another advantageous design, the comparison is triggered by an element outside the effect chain, which has been developed with the required integrity (e.g., in accordance with ISO 26262 or IEC 61508), and the result is also read therefrom. The comparison takes place within an overall element outside the effect chain. In order to intercept dangerous false-negative cases, the selected pattern of the test data to be queried, read, and sometimes sent must be selected very complexly such that an E / E error in the effect chain could produce this situation randomly or systematically, which is highly unlikely.

[0028] In another advantageous design, the individual elements within the effect chain can also be developed in accordance with the required integrity, and these elements are checked by an overall element outside the effect chain. The error cases thus avoided no longer need to be compensated for by higher-level measures performed by elements outside the effect chain. For example, this can lead to a reduction in the requirements for the query pattern, read pattern, and possibly necessary test data used.

[0029] Another advantageous embodiment of the present invention is a driving system for the autonomous driving of a motor vehicle, wherein the driving system includes a primary control unit for autonomous driving and a secondary control unit for autonomous driving.

[0030] For example, due to the functional safety requirements for a redundant system structure, the autonomous driving function can be divided into a primary control unit and a secondary control unit. The primary control unit and the secondary control unit each include the device and the coupling element according to any one of the preceding claims, wherein the coupling elements are connected to each other.

[0031] This particularly results in a network topology in which the device of the primary control unit is connected to the coupling element of the primary control unit, which in turn is connected to the coupling element of the secondary control unit, and the latter coupling element is in turn connected to the device of the secondary control unit.

[0032] In another advantageous embodiment, the configuration of the coupling elements respectively specifies an upper limit for forwarding data packets received by a network participant within a specified time, and an upper limit for forwarding data packets sent to a network participant within a specified time, wherein the upper limit for forwarding data packets sent to a corresponding other coupling element within a specified time is lower or higher than the upper limit for forwarding data packets received by a coupling element within a specified time.

[0033] The present invention is based on the recognition that faults within the effect chain in two coupling elements, in particular the fault configuration of two coupling units, can be determined by a selected ratio between the two upper limits.

[0034] In a further advantageous embodiment of the invention, the primary control unit and the secondary control unit each comprise a device according to any one of claims 2, 3, 4 or 5, wherein the specified point in time is before activating the automated driving mode of the motor vehicle and / or during the active automated driving mode of the motor vehicle.

[0035] The invention is based on the recognition that the error identification by the invention is only a snapshot, and an error can occur shortly after the error identification.

[0036] Since the occurrence of an error can be regarded as a statistical process, the cumulative probability of error occurrence increases over time. Therefore, it is advantageous to select the specified point in time shortly before activating the automated driving mode to reduce the likelihood of a failure occurring before this safety-critical event.

[0037] To ensure a sufficiently high level of error identification in the invention / measure and thus ensure its availability in an emergency, it must be ensured that a failure is unlikely to occur together with a babbling idiot. Background: An undetected measure (shaping / regulation) failure (latent error) will immediately cause a failure on both sides of the subnet in the event of a babbling idiot error. For this purpose, two key points must be covered:

[0038] 1. If a systematic error occurs, it must necessarily be caused by a change in the environmental variables. Therefore, it must be ensured that the measure (shaping / regulation) is reviewed under as identical boundary conditions as possible, under which a babbling idiot might trigger a safety-related event. A suitable point in time for a highly automated vehicle would be, for example, shortly before the driving task is transferred from the driver to the vehicle and, if possible, during automated driving. An unsuitable point in time is when the vehicle is, for example, in an idle mode, i.e., the boundary conditions do not correspond to those during highly automated driving.

[0039] 2. To sufficiently counteract random errors, the repetition frequency of the review of the invention / measure (shaping / regulation) must be selected such that the assumed error rate that invalidates the invention multiplied by the probability of a babbling idiot occurring within the monitoring interval is small enough to meet the integrity requirements. If this is not met, the monitoring interval must be reduced.

[0040] In another advantageous embodiment, the device of a control unit is configured to send a data packet with a low priority to another device at at least one specified time point via a coupling element of the control unit and a coupling element of another control unit, wherein the priority of the data packet is selected such that in each case of an accidental communication (which, for example, suppresses useful communication), the data packet is discarded by one of the coupling elements between the two coupling units, and the corresponding other device is configured to essentially expect to receive this data packet at the specified time point.

[0041] A second aspect of the invention relates to a method for identifying errors in a computer network, wherein the network includes at least one coupling element connecting at least two network participants to each other, the coupling element including a memory for the actual configuration of the coupling element, and the coupling element forwards or discards data packets according to the actual configuration.

[0042] One step of the method is to compare the actual configuration with the target configuration of the coupling element.

[0043] The statements made above regarding the device according to the invention in accordance with the first aspect of the invention also apply mutatis mutandis to the method according to the invention in accordance with the second aspect of the invention. Advantageous embodiments of the method according to the invention that are not explicitly described herein and in the claims correspond to the advantageous embodiments of the device according to the invention introduced above or described in the claims. Description of the Drawings

[0044] The invention will be described below with reference to embodiments with the aid of the drawings. Among them:

[0045] Figure 1 An embodiment of a driving system according to the invention is shown; and

[0046] Figure 2 An exemplary course of the data transfer rate is shown. Detailed Description of the Invention

[0047] Figure 1 A driving system for the autonomous driving of a motor vehicle is shown, wherein the driving system includes a primary control unit hPAD for autonomous driving and a secondary control unit mPAD for autonomous driving.

[0048] The primary control unit hPAD and the secondary control unit mPAD each include a device V1, V2 according to the invention and coupling elements S1, S2, wherein the coupling elements S1, S2 are connected to each other.

[0049] The coupling elements S1, S2 and the devices V1, V2 form a computer network, wherein the coupling elements S1, S2 and the devices V1, V2 are network participants.

[0050] The coupling elements S1, S2 each include a memory for the actual configuration of the coupling elements S1, S2, and the coupling elements S1, S2 are each arranged to forward or discard data packets according to the actual configuration.

[0051] The devices V1, V2 each include a target configuration for the respective coupling elements S1, S2 of their control units hPAD, mPAD, and the devices V1, V2 are each arranged to compare the actual configuration with the target configuration.

[0052] The devices V1, V2 are respectively arranged to send a predetermined number ds of data packets to another network participant, such as to the respective other device V1, V2, via the coupling elements S1, S2 at a specified time point.

[0053] Before activating the autonomous driving mode of the motor vehicle at the specified time point, and / or during the activated autonomous driving mode of the motor vehicle.

[0054] The configurations of the coupling elements respectively specify at least one upper limit O1, O2 for forwarding data packets received by the network participant within a specified time and an upper limit for forwarding data packets sent to the network participant within a specified time, wherein the upper limit O1 for forwarding data packets sent to another coupling element S1, S2 within a specified time is lower than the upper limit O2 for forwarding data packets received by one coupling element S1, S2 within a specified time.

[0055] Furthermore, the devices V1, V2 are respectively arranged to determine the number I1, I2 of data packets discarded by the coupling units S1, S2, and to compare the difference between the number ds of data packets sent to other network participants and the number I1, I2 of data packets discarded by the coupling units S1, S2 with at least one upper limit O1, O2 for the data packets to be forwarded by the coupling units S1, S2 within a specified time.

[0056] In addition, the devices V1, V2 of the control units hPAD, mPAD are respectively arranged to send data packets with a low priority to another device V1, V2 at at least one specified time point via the coupling elements S1, S2 of this control unit hPAD, mPAD and the coupling elements S1, S2 of another control unit hPAD, mPAD, wherein the priority of the data packets is selected such that in the case of any unexpected communication between the two coupling units S1, S2, which for example suppresses useful communication, the data packets are discarded by one of the coupling elements S1, S2, and the other device V1, V2 is arranged to expect to receive this data packet substantially at the specified time point.

[0057] Figure 2An example curve of the data transfer rate is shown. Here, the data transfer rate is plotted in MBit against time t.

[0058] Here, the data transfer level NL, which is usually transmitted as the payload, is shown. This payload NL is lower than two upper limits O1, O2. The upper limit O1 for forwarding the data packets sent to another coupling element S1, S2 within a specified time is lower than the upper limit O2 for forwarding the data packets received by a coupling element S1, S2 within a specified time.

[0059] In addition, three so-called bursts B1, B2, B3 are shown. These bursts occur at specified time points due to the device V1, V2 sending a predetermined number ds of data packets to another network participant via the coupling elements S1, S2.

[0060] Burst B1 here indicates the number ds of data packets actually sent by the devices V1, V2. This number ds exceeds the two upper limits O1, O2. If the coupling elements S1, S2 are working properly, the first coupling units S1, S2 will discard a number I1 of data packets. Therefore, only one burst B2 will reach the corresponding other coupling unit S1, S2. This other coupling unit S1, S2 will discard I2 data packets, so that only one burst B3 will reach the other devices V1, V2.

[0061] Since both the number ds of data packets and the two upper limits O1, O2 are known, the receiving devices V1, V2 can determine whether there is an error in the computer network, such as an actual configuration error of the coupling elements S1, S2, by comparing the actually received data packets with the number of expected data packets, which is caused by the difference between the number ds of data packets sent to the devices and the upper limits O1, O2.

[0062] For example, if the number of actually received data packets exceeds the upper limit O2 for forwarding the data packets received by the network participant within a specified time, it can be inferred that there is an error in the actual configuration of the receiving coupling elements S1, S2.

[0063] For example, if the number of actually received data packets exceeds the upper limit O1 for forwarding the data packets sent to the network participant within a specified time, it can be inferred that there is an error in the actual configuration of the sending coupling elements S1, S2.

Claims

1. A device (V1, V2) for identifying errors in a computer network, wherein, · the computer network includes at least one coupling element (S1, S2) that connects at least two network participants of the computer network to each other; · the coupling element (S1, S2) includes a memory for the actual configuration of the coupling element (S1, S2); · the coupling element (S1, S2) forwards or discards data packets according to the actual configuration; · the device (V1, V2) includes a target configuration of the coupling element (S1, S2); and · the device (V1, V2) is configured to compare the actual configuration with the target configuration, where the device (V1, V2) is a network participant connected to the coupling element (S1, S2), and the device (V1, V2) is configured to: · send a predetermined number (ds) of data packets to another network participant through the coupling element (S1, S2) at a specified time point; · determine the number (I1, I2) of data packets discarded by the coupling element (S1, S2); and · compare the number (ds) of data packets sent to the other network participant with the number (I1, I2) of data packets discarded by the coupling element (S1, S2).

2. The device (V1, V2) according to claim 1, wherein, the configuration of the coupling element (S1, S2) specifies at least one upper limit (O1, O2) of the data packets forwarded by the coupling element (S1, S2) within a specified time.

3. The device according to claim 2, wherein, the configuration of the coupling element (S1, S2) · specifies at least one upper limit (O2) for forwarding data packets received by a network participant within a specified time; and / or · specifies at least one upper limit (O1) for forwarding data packets sent to the network participant within a specified time.

4. The device (V1, V2) according to claim 2 or 3, wherein, the device (V1, V2) is configured to, · compare the difference between the number (ds) of data packets sent to the other network participant and the number (I1, I2) of data packets discarded by the coupling element (S1, S2) with at least one upper limit (O1, O2) of the data packets forwarded by the coupling element (S1, S2) within a specified time.

5. A driving system for the autonomous driving of a motor vehicle, wherein, the driving system includes a primary control unit (hPAD) for autonomous driving and a secondary control unit (mPAD) for autonomous driving. The primary control unit (hPAD) and the secondary control unit (mPAD) each include a device (V1, V2) and a coupling element (S1, S2) according to any one of claims 1 to 4, wherein the coupling elements (S1, S2) are connected to each other.

6. The driving system according to claim 5, wherein, · The configurations of the coupling elements (S1, S2) respectively specify an upper limit (O1, O2) for forwarding data packets received by a network participant within a specified time period, and an upper limit for forwarding data packets sent to the network participant within a specified time period; and · The upper limit (O1) for forwarding data packets sent to another coupling element (S1, S2) within a specified time period is lower than the upper limit (O2) for forwarding data packets received by a coupling element (S1, S2) within a specified time period.

7. The driving system according to claim 5 or 6, wherein the specified time point · is temporally before activating the autonomous driving mode of the motor vehicle; and / or · is during the active autonomous driving mode of the motor vehicle.

8. The driving system according to claim 5, wherein the means (V1, V2) of a control unit (hPAD, mPAD) are configured to send data packets with low priority to another means (V1, V2) at at least one specified time point via the coupling elements (S1, S2) of the control unit (hPAD, mPAD) and the coupling elements (S1, S2) of another control unit (hPAD, mPAD), wherein the priority of the data packets is selected such that in each case of unexpected communication between the two coupling elements (S1, S2), the data packets are discarded by one of the two coupling elements (S1, S2), and the corresponding other means (V1, V2) is configured to expect to receive the data packets at the specified time point.

9. A method for identifying errors in a computer network, wherein the computer network includes at least one coupling element (S1, S2) that connects at least two network participants of the computer network to each other, the coupling element (S1, S2) includes a memory for the actual configuration of the coupling element (S1, S2), and the coupling element (S1, S2) forwards or discards data packets according to the actual configuration, and the method includes the following steps: · Comparing the actual configuration with a target configuration of the coupling element (S1, S2), wherein the method further includes: · Sending a predetermined number (ds) of data packets to another network participant via the coupling element (S1, S2) at a specified time point; · Determining the number (I1, I2) of data packets discarded by the coupling element (S1, S2); and · Comparing the number (ds) of data packets sent to the other network participant with the number (I1, I2) of data packets discarded by the coupling element (S1, S2).

Citation Information

Patent Citations

  • Detection of abnormal configuration changes

    US20170364053A1

  • Network interface protected against attacks

    WO2020035584A1