Method and device for operating secure data communication between functional units for a vehicle
By collecting and sending signatures using the time window of the system fault-tolerant time in the data communication between vehicle functional units, the problem of high resource demand in the prior art is solved and resource efficient data communication is achieved.
Patent Information
- Application Number
- CN202211362071.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-11-02
- Filing Date
- 2022-11-02
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-11-02
AI Technical Summary
The prior art has high resource requirements in data communication between vehicle functional units, especially in terms of transmission and computing signatures, resulting in limitations on transmission and computing capabilities.
By adopting a new communication protocol between vehicle functional units, using the time window of system fault-tolerant time, data packets are collected and common signatures are determined and sent within that time period, resource requirements are reduced.
It realizes efficient data communication with resources, reduces the resource requirements for transmission and computing signatures, and can effectively conduct data communication under existing resource limitations.
Smart Images

Figure CN116074011B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for operating secure data communication between functional units for a vehicle, a corresponding device, a functional unit for a vehicle, and a corresponding computer program. Background Art
[0002] Conventional protocols for data communication stipulate, for example, that each message exchanged between units within the scope of network security is provided with a signature. The higher the amount of information (Botschaften) to be transmitted per unit time, the higher the resource requirements. For example, in the case of common AES128 encryption, a signature of 16 bytes is generated for a CAN message containing 8 bytes of user data. Thus, the amount of data to be transmitted triples. Even if only a part of the signature is transmitted, doubling of the amount of data can still be achieved. Summary of the Invention
[0003] Against this background, the object of the present invention is to create an improved method for operating data communication between functional units for a vehicle, an improved device for operating data communication between functional units for a vehicle, an improved functional unit for a vehicle, and an improved computer program.
[0004] This object is solved by a method for operating data communication between functional units for a vehicle, a device for operating data communication between functional units for a vehicle, a functional unit for a vehicle, and a computer program according to the independent claims.
[0005] According to an embodiment, data communication can be run between functional units for a vehicle, in particular according to a communication protocol for communication for message verification, wherein regular data communication (such as sensor signals) can be carried out separately from the calculation, transmission, and (optionally) checking of associated signatures. The data communication can be used, for example, in the communication between controllers and additionally or alternatively for sensor communication. According to an embodiment, a time window of system fault tolerance time can be used in particular to collect data or data packets within a period of time, determine and transmit a common signature for the collected data.
[0006] Advantageously, according to an embodiment, a resource - efficient communication protocol for message verification in communication can be provided in particular. If, according to an embodiment, not every message (i.e., every data packet) is individually protected by a signature, the computational cost for calculating the signature and the transmission cost for transmitting the signature can be saved for each message. Thus, the limitations of existing resources, such as transmission capacity, computational capacity, etc., can be complied with in particular. Different from traditional protocols in which a separate signature is used for each transmitted message so that an attack can be immediately identified and the receiver can identify the attack after receiving the message, according to an embodiment, it can be advantageously utilized that in the automotive field, it is sufficient to identify a potential attack within the fault - tolerance time of the system. According to an embodiment, this additional time period of the system fault - tolerance time can be advantageously utilized to reduce the resource requirements for signatures.
[0007] A method for operating data communication between functional units for a vehicle is proposed, wherein the method has the following steps:
[0008] Collect a predefined number of data packets sent from a sending unit to a receiving unit in the data buffer of the sending unit to generate a data block, wherein one data packet is sent in each predefined time step, and the data packets are collected over a predefined collection duration that is the sum of the time steps of the predefined number of data packets of the continuous data block;
[0009] Determine a signature for verifying the data block, wherein the signature is determined over a predefined determination duration that lasts for a plurality of time steps; and
[0010] Send the signature in multiple parts from the sending unit to the receiving unit over a predefined transmission duration, wherein a part of the signature is sent in each time step;
[0011] wherein the collection step, the determination step, and the sending step are performed such that the sum of the collection duration, the determination duration, and the sending duration is less than a predefined system fault - tolerance time.
[0012] The vehicle can be a motor vehicle, such as a passenger car, a truck or other commercial vehicle. The functional unit can have at least one transmitting unit and at least one receiving unit. The controller or sensor of the vehicle can be implemented as or used as a transmitting unit. Additionally, another controller or another sensor of the vehicle can be implemented as or used as a receiving unit. The transmitting unit and the receiving unit can be connected to each other or connected to each other in a manner capable of transmitting data. Each data packet can represent sensor data, control data, etc. For example, control signals, sensor signals, etc. can be sent in the form of divided data packets. The method can also have a transmitting step of sending a predefined number of data packets to the receiving unit. The system fault tolerance time can be given by the specifications of one or more functional units in data communication, the data transmission path, and (additionally or alternatively). The time window of the system fault tolerance time can be defined in the following way: how long a system can tolerate a potential attack without reaching a safety-critical state. For example, it can be tolerated that the signal change of a sensor is suppressed for up to 300 milliseconds due to an attack if the attack can be recognized within this time window and the system can be switched to a safe state. The interference of data communication itself can be recognized by means of end-to-end protection measures independently of message verification.
[0013] According to one embodiment, the collection step, the determination step and the transmission step can be executed such that the sum of the collection duration and the determination duration is less than or equal to the sum of the determination duration and the transmission duration. Such an embodiment provides the advantage that the response time to a potential attack can be adapted to a given system fault tolerance time by designing the number of time steps of the collection duration, the determination duration and the transmission duration.
[0014] The collection step, the determination step and the transmission step can also be executed such that the sum of the determination duration and the transmission duration is less than twice the collection duration. Such an embodiment provides the advantage that the response time to a potential attack can be adapted to a given system fault tolerance time by designing the number of time steps of the collection duration, the determination duration and the transmission duration.
[0015] In addition, the determination step and the transmission step can be executed such that the determination duration and the transmission duration are of the same length. Such an embodiment provides the advantage that the response time to a potential attack can be adapted to a given system fault tolerance time by designing the number of time steps of the collection duration, the determination duration and the transmission duration.
[0016] Alternatively, the determination step and the sending step can be performed such that the determination duration and the sending duration are of different lengths. Such an embodiment provides the advantage that the response time to a potential attack can be adapted to a given system fault tolerance time by designing the number of time steps for the collection duration, the determination duration, and the sending duration.
[0017] Furthermore, the collection step, the determination step, and the sending step can be performed such that the determination duration is at most as long as the collection duration, and additionally or alternatively, such that the sending duration is at most as long as the collection duration. Such an embodiment provides the advantage that the response time to a potential attack can be adapted to a given system fault tolerance time by designing the number of time steps for the collection duration, the determination duration, and the sending duration.
[0018] According to one embodiment, in the sending step, the signature for the already sent data block and the current data block can be sent together. Here, in each time step, a part of the signature can be sent crosswise together with at least one data packet of the data block. Such an embodiment provides the advantage that a so-called replay attack can already be recognized within the sending duration plus the check duration of the signature in the receiver. The duration between creating the data and verifying the data in the receiver is not affected by this and thus remains unchanged. Although the data and the signature are transmitted together, these two elements can be decoupled in time. A signature can be set for a previously sent data block. Thus, a message can be sent, by which it is made more difficult for an attacker to manipulate only a part, for example, the user data.
[0019] In the sending step, the signature and a data packet can be sent, wherein in each time step, a part of the signature determined for the data block is sent together with a data packet.
[0020] It is also possible to perform the collection step, the determination step, and the sending step in a periodically repeating manner. Here, it is possible to collect additional data packets over a predefined additional collection duration in order to generate an additional data block, wherein it is possible to determine an additional signature for verifying the additional data block over a predefined additional determination duration, and wherein it is possible to send the additional signature in multiple parts from the sending unit to the receiving unit during a predefined additional sending duration. In other words, in the case of periodic repetition, in the collection step, it is possible to collect additional data packets over a predefined additional collection duration in order to generate an additional data block, in the determination step, it is possible to determine an additional signature for verifying the additional data block over a predefined additional determination duration, and in the sending step, it is possible to send the additional signature in multiple parts from the sending unit to the receiving unit during a predefined additional sending duration. The collection step, the determination step, and the sending step can hereby be performed sequentially (in Reihe), serially, or continuously. Such an embodiment offers the advantage that efficient verification of any amount of data can be achieved.
[0021] According to one embodiment, the collection step, the determination step, and the sending step can be performed such that the additional collection duration directly follows the collection duration, and additionally or alternatively, such that the additional collection duration overlaps in time with the determination duration and additionally or alternatively overlaps in time with the sending duration in part. Alternatively, the additional collection duration can follow the collection duration after an intermediate duration. If two durations overlap in time or overlap in part in time, this means that there is an overlapping time region in which the two durations proceed in parallel. Such an embodiment offers the advantage that the steps of the method can also be performed at least partly in parallel in time, wherein different data blocks can thus be processed.
[0022] In addition to the sending-side steps that can be performed on the side of the sending unit as already mentioned, the method can also have receiving-side steps that can be performed on the side of the receiving unit. After transmitting the signature, the receiving unit can determine the trustworthiness for a set of received data packets (i.e., data blocks). For this purpose, the receiving unit can cache the received data packets until the signature has been sent. The data packets received during this period can be used without risk as long as the signature can be checked within the system fault tolerance time and countermeasures can be taken against the identified attacks.
[0023] The solution proposed here also creates a device that is configured to perform, control, or implement the steps of a variant of the method proposed here in the corresponding apparatus. Through this implementation variant of the solution in the form of a device, the task underlying the solution can also be solved quickly and efficiently.
[0024] For this purpose, the device can have at least one computing unit for processing signals or data, at least one storage unit for storing signals or data, at least one interface to a sensor or actuator for reading in sensor signals of the sensor or outputting data signals or control signals to the actuator, and / or at least one communication interface for reading in or outputting data embedded in a communication protocol. The computing unit can be, for example, a signal processor, a microcontroller, etc., wherein the storage unit can be a volatile memory, a flash memory, an EEPROM or a magnetic storage unit. The communication interface can be designed for reading in or outputting data wirelessly and / or wired, wherein a communication interface capable of reading in or outputting wired data can read in these data from a corresponding data transmission line, for example electrically or optically, or output these data to a corresponding data transmission line.
[0025] At present, a device can be understood as an electric appliance that processes sensor signals and outputs control signals and / or data signals according to the sensor signals. The device can have an interface that can be constructed in hardware and / or software form. In the construction in hardware form, the interface can be, for example, a part of a so-called system ASIC that contains the most diverse functions of the device. However, it is also possible that the interface is a respective integrated circuit or is at least partially composed of discrete structural elements. In the construction in software form, the interface can be a software module that exists on a microcontroller together with other software modules.
[0026] A functional unit for a vehicle is also proposed, wherein the functional unit has an embodiment of the device mentioned in this article, wherein the functional unit is embodied as a control unit or a sensor or an actuator.
[0027] The functional unit can be installable or installed in a vehicle, or in other words can be embodied as part of a vehicle. The vehicle can include at least one functional unit having one embodiment of the device mentioned in this article.
[0028] Also advantageous is a computer program product or a computer program with a program code, which can be stored on a machine-readable carrier or storage medium (such as a semiconductor memory, hard disk storage or optical storage) and which is used to execute, implement and / or control the steps of the method according to one of the aforementioned embodiments, in particular when the program product or the program is executed on a computer or device. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In the following description, an embodiment of the solution proposed here is explained in more detail with reference to the accompanying drawings. The drawings show:
[0030] Figure 1 A schematic illustration of a vehicle having a functional unit and an exemplary embodiment of a device for operating data communication;
[0031] Figure 2 A flow chart of an embodiment of a method for operating a data communication between functional units for a vehicle; and
[0032] Figure 3 Used for Figure 2 Schematic timing diagram of the method in . DETAILED DESCRIPTION
[0033] Figure 1 A schematic illustration of a vehicle 100 is shown with an exemplary embodiment of functional units 105, 110 and a device 120 for operating data communication. The vehicle 100 is a motor vehicle, for example a passenger car, a motorcycle, an electric bicycle, a truck or another commercial vehicle. Figure 1 In the illustration of FIG. 1 , only a first functional unit 105 used as a receiving unit and a second functional unit 110 used as a transmitting unit are shown as an example in the vehicle 100. The first functional unit 105 is implemented as a controller or a sensor, for example. The second functional unit 110 is implemented as a controller or a sensor, for example. The first functional unit 105 and the second functional unit 110 are connected to each other in a data-transmittable manner.
[0034] The second functional unit 110 has a device 120 for operating a data communication between the functional units 105 and 110. The device 120 includes a collection device 122, a data buffer 124, a determination device 126 and a transmission device 128. The second functional unit 110 also has a transmission device 112. The transmission device 112 is designed to send data packets 115 to the first functional unit 105 serving as a receiving unit via the device 120. In this case, the transmission device 112 is designed to send a data packet 115 in each predefined time step. The data packets 115 are, for example, parts of control signals, sensor signals, etc.
[0035] The collecting device 122 of the device 120 is designed to collect a predefined number of transmitted data packets 115 in a data buffer 124 in order to generate a data block 125. The collecting device 122 is designed to collect the data packets 115 over a predefined collection duration, which is the sum of the time steps of the predefined number of data packets 115 of the data block 125. In other words, the collection duration includes the same number of time steps as the predefined number of data packets. The predefined number of data packets 115 from which the data block 125 is generated is determined by the size of the data buffer 124. The data block 115 generated from the collected data packets 115 includes individual transmitted messages or data packets 115, for example when new sensor signals are available.
[0036] The determining device 126 of the device 120 is configured to determine a signature 127 for verifying a data block 125. Herein, the determining device 126 is configured to determine the signature 127 over a predefined determination duration that lasts for a plurality of time steps. The determining device 126 is for example configured to use a determination rule to determine the signature 127.
[0037] The transmitting device 128 of the device 120 is configured to transmit the signature 127 in multiple parts to the receiving unit 105 via the interface 129 of the device 120 over a predefined transmission duration. Herein, the transmitting device 128 is configured to transmit a part of the signature 127 in each time step.
[0038] The collecting device 122, the determining device 126, and the transmitting device 128 are configured to adjust the collection duration, the determination duration, and the transmission duration such that the sum of the collection duration, the determination duration, and the transmission duration is less than a predefined system fault tolerance time.
[0039] According to one embodiment, the transmitting device 128 is configured to transmit the signature 127 and the data block 125. Herein, the transmitting device 128 is configured to transmit a part of the signature 127 together with at least one data packet among the data packets 115 of the data block 125 in each time step.
[0040] Figure 2 A flowchart showing an embodiment of a method 200 for running data communication between functional units for a vehicle is presented. The method 200 for running can be implemented in combination with Figure 1 the devices in [device name] or similar devices or in the case of using Figure 1 the devices in [device name] or similar devices. The method 200 for running includes a collection step 210, a determination step 220, and a transmission step 230.
[0041] In the collection step 210, a predefined number of data packets transmitted from the transmitting unit to the receiving unit are collected or cached in the data buffer of the transmitting unit to generate a data block. One data packet is transmitted in each predefined time step. The data packets are collected over a predefined collection duration that lasts for the sum of the time steps of the predefined number of data packets of the data block. Then, in the determination step 220, a signature for verifying the data block is determined. Herein, the signature is determined over a predefined determination duration that lasts for a plurality of time steps. Then again, in the transmission step 230, the signature is transmitted from the transmitting unit to the receiving unit in multiple parts over a predefined transmission duration. Herein, a part of the signature is transmitted in each time step.
[0042] Here, the collection step 210, the determination step 220, and the transmission step 230 are performed such that the sum of the collection duration, the determination duration, and the transmission duration is less than a pre-given fault tolerance time for data communication.
[0043] Figure 3 shows Figure 2 a schematic timing diagram 300 of the method in or a similar method. Along the time axis, the first example A, the second example B, and the third example C of the chronological order of performing the Figure 2 method steps in are shown. On this time axis, a predefined time step t, for example 10 ms, is plotted, where only the first time step 0 to the thirty-second time step 31 are shown. For each of the examples A to C, different, successive processes of the repeated execution of the method steps are plotted the collection durations 310, the determination durations 320, the transmission durations 330, and further collection durations 310-1, 310-2, 310-3, further determination durations 320-1, 320-2, and further transmission durations 330-1, 330-2. In particular, in all examples A to C, the collection durations 310, 310-1, 310-2, 310-3 are of the same length, exemplarily only 8 time steps t.
[0044] For Figure 2 the method in and thus for Figure 3 the examples A to C in also applies: The collection step, the determination step, and the transmission step can be performed in a periodically repeating manner (in particular, repeatedly multiple times), where additional data packets are collected over a predefined further collection duration 310-1 / 310-2 / 310-3 in order to generate further data blocks, where additional signatures for verifying the further data blocks are determined over a predefined further determination duration 320-1 / 320-2, and where the additional signatures are sent from the sending unit to the receiving unit in multiple parts during a predefined further transmission duration 330-1 / 330-2. According to the embodiments presented here, the method steps are performed using durations that remain constant in different processes of the repeated execution.
[0045] Here, the collection step, determination step, and sending step can be performed such that an additional collection duration 310-1 directly follows the collection duration 310, i.e., the message data collection time window. The collection step, determination step, and sending step can also be performed such that the additional collection duration 310-1 temporally overlaps with the determination duration 320, i.e., the signature determination time window, for example, between the ninth and sixteenth time steps in the first example A, between the ninth and fourteenth time steps in the second example B, and between the ninth and twelfth time steps in the third example C, and optionally, additionally temporally partially overlaps with the sending duration 330, i.e., the signature sending time window, for example, between the fifteenth and sixteenth time steps in the second example B and between the thirteenth and sixteenth time steps in the third example C. Further, the collection step, determination step, and sending step can be performed such that the sum of the collection duration 310 and the determination duration 320 is less than or equal to the sum of the determination duration 320 and the sending duration 330. The collection step, determination step, and sending step can also be performed such that the sum of the determination duration 320 and the sending duration 330 is less than twice the collection duration 310. Additionally, the collection step, determination step, and sending step can be performed such that the determination duration 320 is at most as long as the collection duration 310 and / or the sending duration 330 is at most as long as the collection duration 310. The statements in this paragraph also correspondingly apply to the corresponding durations of other processes of repeated execution of the method steps.
[0046] For Figure 3 the first example A in
[0047] applies: The determination step and the sending step are performed such that the determination duration 320 and the sending duration 330 are of the same length. Additionally, here, the collection duration 310, the determination duration 320, and the sending duration 330 are of the same length. Similarly, for the durations of other processes of repeated execution of the method steps: According to the first example A, all durations are of the same length. Figure 3 the second example B and the third example C in
[0048] Referring to the accompanying drawings described above, the embodiments and the advantages of the embodiments are briefly summarized again in a concise and in other words manner.
[0049] As is known, the transmission or communication of sensor signals in the form of data packets 115 by the transmitting device 112 occurs periodically in each time step, for example every 10 ms with a checksum, as practiced within the scope of ISO 26262. To verify the transmitted data packets 115, the following steps are respectively performed over a period of multiple time steps t:
[0050] 1. The transmitted sensor values or data packets 115 are additionally collected in the data buffer 124.
[0051] 2. If the data buffer 124 is filled, the signature 127 of the data packets 115 with respect to the data block 125 is determined or calculated in a manner distributed over multiple time steps t.
[0052] 3. The signature 127 is sent to the receiver segment by segment, also distributed over multiple time steps t. This process is aimed at enabling the serial execution of the aforementioned three steps over multiple time steps t with reduced resource requirements and the parallel execution within one time step t. For this purpose, also refer to Figure 3 Example A in the first. Thus, the data buffer 124 is always filled in parallel, the signature 127 with respect to the content of the previously filled data buffer 124 (i.e., the data block 125) is determined, and the signature 127 is sent. By designing the number of time steps t for caching data or collecting data packets 115, for signature calculation or determining the signature 127, and for sending the signature 127, the response time to an attack can be adapted to the fault tolerance time of the system. For this purpose, also refer to Figure 3 Example B in the second and Example C in the third.
[0053] In particular, in order to shorten the recognition time of a simple replay attack, according to an embodiment, the signature 127 can be sent together with the data to be protected (i.e., the data packets 115 of the data block 125) or in the same message. Then, the recognition time for a replay attack is as long as the transmission duration 330 plus the time for checking the signature at the receiver. The recognition time for unverified data is as long as the sum of the collection duration 310, the determination duration 320, and the transmission duration 330.
[0054] According to an embodiment, for example, compared to a MAC (Message Authentication Code), proportionally to the ratio between the periodic information transmission and the amount of data collected, only a small fraction of the computing and transmission capabilities are required. For example, if 8 data packets of sensor data are signed together, the resource requirement is reduced to 1 / 8 compared to the individual signature of each data packet. In this way, it is possible to reliably meet the requirements for authenticated communication even within the scope of network security using inexpensive controllers and low-performance communication links (e.g., serial communication, SENT, PSI, etc.). Therefore, it is also possible to avoid using more expensive and / or more failure-prone communication buses (e.g., CAN-FD or Ethernet) to be able to transmit additional signature data.
[0055] The computing and transmission capabilities that can be saved through the embodiment are also briefly illustrated by taking the intelligent sensors of a vehicle as an example. For example, an inexpensive, slow-ticking 16-bit microcontroller is used for sensor data processing, and a robust serial interface with a low transmission speed is used for sensor data transmission. Here, the task cycle time t for processing and transmitting sensor data is, for example, 10 ms. In the case of no data caching or data collection and with AES128 signature (where sensor data is processed every 10 ms), the calculation of the signature in the software lasts 2.5 ms and thus results in a 25% CPU load. For transmitting the signature, in the case of a complete MAC, a bus load of 83% is reached, or in the case of a partial MAC with restricted verification, a bus load of 20% is reached. According to Figure 3 In the first example A in, by using data caching or data collection and also using AES128, a signature 127 of 8 sensor values (i.e., 8 task cycle times) is obtained together, where the sensor values are detected every 10 ms, as follows: The determination of signature 127 only lasts 2.5 ms / 8 = 0.3 ms for each time step t with a 3% CPU load. For transmitting signature 127 for each time step t, in the case of a complete transmission MAC, a bus load of 83% / 8 = 10% is reached.
[0056] List of reference numerals
[0057] 100 Vehicle
[0058] 105 First functional unit
[0059] 110 Second functional unit
[0060] 112 Transmitting device
[0061] 115 data packet
[0062] 120 device
[0063] 122 collection device
[0064] 124 data buffer
[0065] 125 data block
[0066] 126 determination device
[0067] 127 signature
[0068] 128 transmission device
[0069] 129 interface
[0070] 200 method for operation
[0071] 210 collection step
[0072] 220 determination step
[0073] 230 transmission step
[0074] 300 timing diagram
[0075] 310 collection duration
[0076] 320 determination duration
[0077] 330 transmission duration
[0078] 310-1, 310-2, 330-3 additional collection duration
[0079] 320-1, 310-2 additional determination duration
[0080] 330-1, 330-2 additional transmission duration
[0081] A first example
[0082] B second example
[0083] C third example
[0084] t time step
Claims
1. A method (200) for performing data communication between functional units (105, 110) for a vehicle (100), wherein, the method (200) has the following steps: collecting (210) a predefined number of data packets (115) sent by a sending unit (110) to a receiving unit (105) in a data buffer (124) of the sending unit (110) to generate a data block (125), wherein one data packet (115) is sent in each predefined time step (t), and wherein the data packets (115) are collected over a predefined collection duration (310) that is the sum of the time steps (t) of the predefined number of data packets (115) that make up the data block (125); determining (220) a signature (127) for verifying the data block (125), wherein the signature (127) is determined over a predefined determination duration (320) that lasts for a plurality of time steps (t); and sending (230) the signature (127) in multiple parts from the sending unit (110) to the receiving unit (105) over a predefined sending duration (330), wherein a part of the signature (127) is sent in each time step (t); wherein the collection step (210), the determination step (220), and the sending step (230) are performed such that the sum of the collection duration (310), the determination duration (320), and the sending duration (330) is less than a predefined system fault tolerance time.
2. The method (200) according to claim 1, wherein, the collection step (210), the determination step (220), and the sending step (230) are performed such that the sum of the collection duration (310) and the determination duration (320) is less than or equal to the sum of the determination duration (320) and the sending duration (330).
3. The method (200) according to claim 1 or 2, wherein, the collection step (210), the determination step (220), and the sending step (230) are performed such that the sum of the determination duration (320) and the sending duration (330) is less than twice the collection duration (310).
4. The method (200) according to claim 1 or 2, wherein, the determination step (220) and the sending step (230) are performed such that the determination duration (320) and the sending duration (330) are of the same length.
5. The method (200) according to claim 1 or 2, wherein, the determination step (220) and the sending step (230) are performed such that the determination duration (320) and the sending duration (330) are of different lengths.
6. The method (200) according to claim 1 or 2, wherein, The collection step (210), the determination step (220), and the transmission step (230) are performed such that the determination duration (320) is at most as long as the collection duration (310) and / or the transmission duration (330) is at most as long as the collection duration (310).
7. The method (200) according to claim 1 or 2, wherein, in the transmission step (230), a signature (127) for a transmitted data block (125) and the current data block (125) are transmitted together, wherein, at each time step (t), a part of the signature (127) is transmitted crosswise together with at least one data packet of the data packets (115) of the data block (125).
8. The method (200) according to claim 1 or 2, wherein, in the transmission step (230), the signature (127) and a data packet (115) are transmitted, wherein, at each time step (t), a part of the signature (127) determined for the data block (125) is transmitted together with a data packet (115).
9. The method (200) according to claim 1 or 2, wherein, the collection step (210), the determination step (220), and the transmission step (230) are performed in a periodically repeating manner, wherein additional data packets (115) are collected over a predefined additional collection duration (310-1, 310-2, 310-3) to generate additional data blocks (125), wherein additional signatures (127) for verifying the additional data blocks (125) are determined over a predefined additional determination duration (320-1, 320-2), and wherein, during a predefined additional transmission duration (330-1, 330-2), the additional signatures (127) are transmitted in multiple parts from the transmission unit (110) to the reception unit (105).
10. The method (200) according to claim 9, wherein, the collection step (210), the determination step (220), and the transmission step (230) are performed such that the additional collection duration (310-1, 310-2, 310-3) directly follows the collection duration (310), and / or such that the additional collection duration (310-1, 310-2, 310-3) overlaps in time with the determination duration (320) and / or partially overlaps in time with the transmission duration (330).
11. A device (120), the device being arranged to perform and / or control the steps of the method (200) according to any one of claims 1 to 10 in corresponding units in the device (120).
12. A functional unit (110) for a vehicle (100), wherein, The functional unit (110) has a device (120) according to claim 11, wherein the functional unit (110) is implemented as a controller or a sensor or an actuator.
13. A machine-readable storage medium having stored thereon a computer program which is set up to carry out and / or control the steps of a method (200) according to any one of claims 1 to 10.
Citation Information
Patent Citations
Method and system for controlling vehicle closing element
CN103569050A
Clock synchronization method, system and device, intelligent terminal, vehicle terminal and medium
CN109495263A