Determining correctness of actually received timestamps

By using a verifier in an autonomous vehicle to determine the correctness of timestamps, the synchronization problem between Flexray and the Ethernet communication bus was solved, achieving high-security-level inter-system synchronization, meeting ASIL D requirements, and improving the system's security integrity and timestamp accuracy.

CN116158027BActive Publication Date: 2026-02-27BMW AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202180063602.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-09-23
Filing Date
2021-08-26
Publication Date
2026-02-27
Estimated Expiration
2041-08-26

AI Technical Summary

Technical Problem

In autonomous vehicles, the synchronization between multiple communication buses and ECUs is difficult to meet the high safety level ASIL D requirements, especially the timestamp synchronization between Flexray and Ethernet communication buses, which does not meet the functional safety requirements of interference-free capability.

Method used

The correctness of the actual received timestamps provided by the first ECU of the communication network is determined by using a verifier. The master clock and the verifier's slave clock synchronization method are combined with deterministic communication standards to predict and compare timestamps to ensure synchronization and security levels.

Benefits of technology

It achieves high-level synchronization between multiple communication buses and ECUs, meets ASIL D requirements, ensures interference-free operation between systems, and improves the accuracy of timestamps and the security and integrity of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116158027B_ABST
    Figure CN116158027B_ABST
Patent Text Reader

Abstract

A method for determining, using a verifier, the correctness of an actually received timestamp provided by a first ECU of a communication network is provided. The communication network includes a master clock; the first ECU having a first slave clock; the verifier having a second slave clock; and a first communication bus connecting the first ECU, the verifier, and the master clock to each other. The first ECU uses a first communication standard having a determinism scheme. The method for determining, using the verifier, the correctness of the actually received timestamp provided by the first ECU of the communication network includes: at the first ECU, synchronizing a time of the first slave clock to a global time of the master clock; at the verifier, synchronizing a time of the second slave clock to the global time of the master clock; at the verifier, predicting a timestamp to be received from the first ECU in an actual communication cycle based on the determinism scheme of the communication standard used by the first ECU; and at the verifier, comparing the predicted timestamp with the actually received timestamp from the first ECU.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present invention relates to a method for determining, using a verifier, the correctness of an actually received timestamp provided by a first ECU of a communication network, and to a verifier configured to perform the method. BACKGROUND

[0002] With increasing complexity of autonomous or automatic vehicles, different electronic control units (ECUs) use multiple communication buses to ensure that autonomous or automatic driving functions meet safety requirements, for example, requirements needed to meet the so-called Automotive Safety Integrity Level (ASIL).

[0003] The Automotive Safety Integrity Level is a risk classification scheme defined by ISO 26262 - Functional Safety for road vehicles. The ASIL classification comprises five safety levels from QM with the lowest safety requirements to ASIL D with the highest safety requirements.

[0004] For example, in autonomous or automatic vehicle Ethernet, CAN-FD (Controller Area Network Flexible Data Rate) can be used together with Flexray.

[0005] Ethernet is a series of computer networking technologies that are widely used in local area networks (LANs), metropolitan area networks (MANs), and wide area networks (WANs). It was introduced commercially in 1980 and was standardized as IEEE (Institute of Electrical and Electronics Engineers) 802.3 in 1983. Flexray is an automotive network communication protocol developed by the Flexray Consortium for governing automotive computing on board vehicles. It was designed to be faster and more reliable than CAN (Controller Area Network) and TTP (Time-Triggered Protocol). The Flexray standard is now a set of ISO standards, ISO 17458-1 to 17458-5. CAN FD is a data communication protocol typically used to transfer sensor data and control information between different parts of an electronic instrument and a control system. The protocol is used in modern high-performance vehicles. CAN FD is an extension of the original CAN bus protocol specified in ISO 11898-1.

[0006] In the prior art, time synchronization of Ethernet buses is implemented according to IEEE 802.1 As for TSN (Time-Sensitive Networking) and IEEE 1588 for PTP (Precision Time Protocol). However, for time synchronization via PTP, several measures can be taken in addition to the respective standards, so that the integrity of the synchronization process, and thus of the distributed time base, can be ensured.

[0007] However, the internal clock of the Flexray bus lacks any safety integrity and is QM (Quality Management). QM guidelines imply that the measures required by a normal quality management system (ISO / TS16949) are sufficient in this case. Flexray messages need to be used in conjunction with corresponding messages from Ethernet and CAN-FD. If a Flexray message with a QM timestamp is used with the corresponding ASIL B or ASIL D timestamp from Ethernet (and / or CAN FD), it may result in non-compliance with the functional safety requirement of "Freedom from Interference" (ISO26262) for highly automated vehicles, according to ASIL D.

[0008] ISO 26262, “Independence from Interference,” demonstrates that a (sub)system with a less critical ASIL level (e.g., ASIL A) will not affect a system with a more critical ASIL level (e.g., ASIL C). The goal is to prevent a system with a higher error rate (e.g., ASIL A) from driving a system that requires a lower error rate (e.g., ASIL C).

[0009] Therefore, one of the most complex and challenging tasks for autonomous and automated vehicles is to synchronize multiple connected communication buses and their respective ECUs to meet these requirements. Summary of the Invention

[0010] In view of the prior art, the object of the present invention is to provide a method for evaluating the synchronization between multiple connected communication buses and their respective ECUs, the method providing a high level of safety (e.g., a safety level that meets ASIL D requirements) and meeting the functional safety requirements of "interference-free capability" according to ISO 26262.

[0011] More specifically, this objective is achieved through a method for determining the correctness of the actual received timestamps provided by the first ECU of the communication network using a verifier.

[0012] The communication network includes a master clock; a first ECU having a first slave clock; a verifier having a second slave clock; and a first communication bus connecting the first ECU, the verifier, and the master clock to each other.

[0013] The first ECU uses a first communication standard with a deterministic scheme. That is, it is sufficient if only the connection between the first ECU and the verifier has a deterministic transmission scheme. Moreover, it is possible and sufficient for the first standard to have static segments with time periods of a deterministic scheme.

[0014] The method for determining the correctness of an actually received timestamp at the verifier (the timestamp being provided by a first ECU of the communication network) comprises: at the first ECU, synchronizing a time of a first slave clock to a global time of a master clock; at the verifier, synchronizing a time of a second slave clock to the global time of the master clock; at the verifier, predicting a timestamp to be received from the first ECU in an actual communication cycle based on a determinism scheme of a communication standard used by the first ECU; and at the verifier, comparing the predicted timestamp with the actually received timestamp from the first ECU.

[0015] Comparing the predicted timestamp with the actually received timestamp provided by the first ECU of the communication network at the verifier can comprise: determining, at the verifier, a difference between the predicted timestamp and the actually received timestamp; comparing the difference with a predetermined threshold; and determining the correctness of the actually received timestamp if the difference is smaller than the predetermined threshold, preferably if the difference is within a certain range.

[0016] A fixed delay between a data acquisition task and a data transmission task of the first ECU can be taken into account for determining the difference between the global time of the predicted timestamp at the verifier and the global time of the actually received timestamp, wherein the actually received timestamp at the verifier is provided by the first ECU during the data acquisition task.

[0017] More specifically, the difference between the predicted timestamp and the actually received timestamp can be determined using the following formula:

[0018] GT2 - GT1 - Δ + δ

[0019] GT2 is the global time at which the actually received timestamp is provided by the first ECU. GT1 is the global reference time at the beginning of the actual communication cycle of the first ECU. Δ is a result received by multiplying a predetermined number of time slots of a determinism scheme of the first communication standard used by the first ECU with a fixed duration of a time slot. δ is the fixed delay between the data acquisition task and the data transmission task of the first ECU. The actually received timestamp is provided by the first ECU during the data acquisition task. Both Δ and δ have a determinism due to the determinism behavior of the communication bus connecting the first ECU and the verifier and can be determined at pre-compile.

[0020] Additionally or alternatively, the difference between the predicted timestamp and the actually received timestamp can be determined using the following formula:

[0021] GT_Current - (GT2 + δ)

[0022] GT2 is the global time at which the first ECU provides the actually received time stamp. δ is a fixed delay between a data acquisition task and a data transmission task of the first ECU. The actually received time stamp is provided by the first ECU during the data acquisition task. GT_Current is the global time at which the actually received time stamp is received at the verifier.

[0023] In general, this approach does not provide the same level of accuracy as the previous procedure, since the software interruption latency ε when querying the current global time (i.e. GT_Current) is taken into account when receiving the PDU carrying the time stamp to be verified. In addition, this solution generally requires more computational resources. However, this solution is simpler due to the fact that only one deterministic parameter δ has to be provided.

[0024] The global time of the actually received time stamp can be determined at the first ECU using the following formula:

[0025] GT2 = GT1 + 1t2 - 1t1

[0026] GT2 is the global time at which the first ECU provides the actually received time stamp. GT1 is the global reference time at the beginning of the actual communication cycle of the first ECU. 1t1 is the local time of the first slave clock of the first ECU at the beginning of the actual communication cycle. 1t2 is the local time of the first slave clock of the first ECU at the time the actually received time stamp is provided by the first ECU.

[0027] The communication network can further comprise a second ECU having a third slave clock; a gateway ECU comprising the verifier; and a second communication bus connecting the second ECU to the first ECU via the gateway ECU and the first communication bus.

[0028] The second ECU can use a second communication standard having a safety integrity level higher than a safety integrity level of the first communication standard used by the first ECU, or the second ECU can be verified by other means.

[0029] The integrity of the master clock can be sufficient to meet safety requirements of a second communication standard having a safety integrity level higher than the first communication standard.

[0030] The verifier can determine the correctness of the actually received time stamp provided by the first ECU according to safety requirements of the second communication standard.

[0031] Synchronizing the time of the first slave clock to the global time of the master clock at the first ECU can comprise, at the first ECU, receiving a synchronization message from the master clock such that the time of the first slave clock of the first ECU is synchronized to the global time of the master clock based on the received synchronization message.

[0032] Further, a verifier can be provided. The verifier can be configured to determine a correctness of the actually received time stamp provided by the first ECU of the communication network.

[0033] The communication network can comprise a master clock, a first ECU having a first slave clock, and a first communication bus configured to connect the first ECU, the verifier and the master clock to each other.

[0034] The first ECU can use a first communication standard having a deterministic scheme. The time of the first slave clock can be synchronized to the global time of the master clock.

[0035] The verifier can comprise a second slave clock, wherein the time of the second slave clock is synchronized to the global time of the master clock.

[0036] The verifier can be configured to predict the time stamp to be received from the first ECU in the actual communication cycle based on the deterministic scheme of the communication standard used by the first ECU and to compare the predicted time stamp with the actually received time stamp from the first ECU.

[0037] The above description with respect to the method also applies to the device, i.e. the verifier, and vice versa.

[0038] Moreover, the verifier can be configured to perform one of the above described methods.

[0039] In short, by comparing and predicting the time stamp of the first ECU, the verifier ensures that the time synchronization of the first ECU can achieve the highest possible security integrity level according to the security integrity of the verifier. Further, it is ensured that the security integrity level of the second ECU and the second communication bus will be inherited by the verifier and that the security integrity level of the first ECU having the first communication bus, the security integrity level of the verifier having the gateway ECU and the security integrity level of the second ECU having the second communication bus achieve a similar and / or the highest possible security integrity level. BRIEF DESCRIPTION OF DRAWINGS

[0040] In the following, reference is made to Figures 1 to 3 A description of embodiments of the invention is given.

[0041] Figure 1 A communication network for a vehicle having a plurality of communication buses is schematically depicted.

[0042] Figure 2 A flow chart of a method for determining a correctness of an actually received time stamp provided by Figure 1 a first ECU of a communication network using a verifier is schematically depicted.

[0043] Figure 3 A communication network for a vehicle having a plurality of communication buses is schematically depicted.Figure 1 The communication scheme between the first ECU and the verifier. Detailed Implementation

[0044] Figure 1 The communication network 1 shown is a network used to transmit data in autonomous vehicles or automatic vehicles (e.g., automobiles).

[0045] Network 1 includes two ECUs 2 and 3 using a first communication standard; two ECUs 4 and 5 using a second communication standard; a gateway ECU 6; an interconnect 7; a master clock 8; a first bus system (i.e., a first communication bus) 9 using the first communication standard; and a second bus system (i.e., a second communication bus) 10 using the second communication standard.

[0046] More specifically, network 1 includes a first ECU 2 and a second ECU 3 that use a first deterministic communication standard, such as the Flexray standard as defined in the entry section of the specification; a third ECU 4 and a fourth ECU 5 that use a second communication standard, such as the Ethernet standard (or CAN FD, where Ethernet will be used as an example of the second communication standard below, and CAN FD may also be used) as defined in the entry section of the specification; and a gateway ECU 6.

[0047] The first ECU 2 and the second ECU 3 are each connected to the master clock 8 via a first bus system 9. Furthermore, the first ECU 2 and the second ECU 3 are also each connected to the gateway ECU 6 via the first bus system 9. The first bus system 9 uses a first communication standard. In the above example, the first bus system 9 may be a deterministic Flexray bus system.

[0048] The third ECU 4 and the fourth ECU 5 are each connected to the interconnect 7 via the second bus system 10, which uses a second communication standard. In the example above, the second bus system 10 may be an Ethernet bus system. Furthermore, the third ECU 4 and the fourth ECU 5 are also connected to the gateway ECU 6 via the second bus system 10 and the interconnect 7.

[0049] Interconnection 7 may be an Ethernet interconnect (e.g., a switch) as in the example above, which is configured to connect the third ECU 4 and the fourth ECU 5 of network 1 to gateway ECU 6 respectively by using packet switching to receive data from gateway ECU 6 and / or forward data to gateway ECU 6.

[0050] The master clock 8 is connected to the first bus system 9 and the second bus system 10 via the interconnection 7. The master clock 8 is configured to provide a global time or master time to the ECUs 2, 3, 4, 5 each comprising a slave clock 21, 31, 41, 51, and also to the gateway ECU 6 comprising a slave clock 61. Thus, the master clock 8 is configured to provide a timing signal to synchronize the slave clocks 21, 31, 41, 51, 61 of the devices 2, 3, 6 using a first communication standard and the devices 4, 5, 6 using a second communication standard of the network 1.

[0051] The gateway ECU 6 can be a Flexray-Ethernet gateway ECU in the example, which is configured to provide interoperability between a first ECU 2 and a second ECU 3 using a first communication standard (herein the Flexray standard) and a third ECU 4 and a fourth ECU 5 using a second communication standard (herein the Ethernet standard). Thus, the gateway ECU 6 is configured to perform a unidirectional or bidirectional protocol conversion between the first communication standard and the second communication standard.

[0052] In the current case, the safety integrity level of the second communication standard is higher than the safety integrity level of the first communication standard. For example, the Ethernet standard used by the third ECU 4 and the fourth ECU 5 can be an ASIL D qualified, while the Flexray standard used by the first ECU 2 and the second ECU 3 is only QM.

[0053] As explained above, the first ECU 2 and the second ECU 3 and the third ECU 4 and the fourth ECU 5 can communicate with each other via the gateway ECU 6. However, due to the fact that they use communication standards with different safety integrity levels, this is not possible according to the functional safety requirement of the “immunity to disturbance” guideline (ISO 26262) which is used for highly automated vehicles according to ASIL D.

[0054] As explained in the introductory part of the description, by the ISO 26262 “immunity to disturbance” guideline, it can be proven that a (sub-)system with a less critical ASIL level (herein the first bus system 9 with the first ECU 2 and the second ECU 3) does not influence a system with a more critical ASIL level (herein the second bus system 10 with the third ECU 4 and the fourth ECU 5 and the interconnection 7). The goal is to prevent a system with a higher error rate from driving a system in which a lower error rate is required.

[0055] Thus, a method for determining the correctness of an actually received timestamp provided by a first ECU 2 and a second ECU 3 of a communication network 1 is provided. That is, the timestamps provided by the first ECU 2 and the second ECU 3 are capable of fulfilling a higher safety level, here ASIL D, by the gateway ECU 6.

[0056] Thus, the gateway ECU 6 comprises a verifier 62, in the present case a central verifier, which is configured to perform the method.

[0057] The following references are made to Figure 2 and Figure 3 The method is described in detail. Figure 2 A flow chart depicting the steps of the method is shown. Figure 3 A communication scheme is schematically depicted in which the first ECU 2 communicates with the verifier 62 on the gateway ECU 6 using a first communication standard, and a first possibility and a second possibility for determining the correctness of an actually received timestamp.

[0058] As explained above, the communication network 1 comprises a master clock 8; ECUs 2, 3, 4, 5, having slave clocks 21, 31, 41, 51, respectively; a verifier 6, having a slave clock 61 and a verifier 62; and a first communication bus system 9 connecting the first ECU 2 and the second ECU 3, the verifier 62 and the master clock 8 to each other.

[0059] The first communication standard used by the first ECU 2 and the second ECU 3 has a deterministic scheme. That is, the underlying communication protocol always goes through the same sequence of states at a predetermined and fixed time. Thus, it is possible to predict when a data packet transmitted from the first ECU 2 or the second ECU 3 using the first communication standard will arrive at a receiver, here the verifier 62 of the gateway ECU 6.

[0060] In case the Flexray standard is used, the communication on the first bus system 9 runs in cycles. Each of these cycles is divided into different segments comprising static segments and dynamic segments.

[0061] In the static segments, each ECU 2, 3 using the first communication standard has a certain time slot, i.e. a time window, in which it can transmit messages. It must not exceed the length of its time slot. If a message is too long, it has to be continued using another cycle assigned to the respective ECU or a dynamic segment.

[0062] This is the deterministic part of the protocol, i.e. the deterministic part of the first communication standard, which ensures that important messages, e.g. steering, braking, etc., are transmitted within a known time.

[0063] In order to predict when a data packet will arrive at the verifier 62, in a first step S1 of the method, the times of the slave clocks 21, 31, 41, 51, 61 of the ECUs 2, 3, 4, 5 and of the gateway ECU 6 are respectively synchronized to the global time of the master clock 8.

[0064] Synchronizing the times of the respective slave clocks 21, 31 at the first ECU 2 and at the second ECU 3 to the global time of the master clock 8 can comprise receiving a synchronization message at the first ECU 2 and at the second ECU 3 respectively from the master clock 8, such that the local times of the respective slave clocks 21, 31 of the first ECU 2 and of the second ECU 3 are synchronized to the global time of the master clock 8 based on the received synchronization message.

[0065] In a second step S2, the verifier 62 predicts the timestamps to be received from the first ECU 2 and / or from the second ECU 3 in the actual communication cycle based on the deterministic scheme of the first communication standard used by the first ECU 2 and by the second ECU 3.

[0066] Then, in a third step S3, the verifier 62 compares the predicted timestamps with the actually received timestamps from the first ECU 2 and / or from the second ECU 3.

[0067] Reference is now made to Figure 3 Steps S1 to S3 are explained in detail.

[0068] As mentioned above, Figure 3 Two possibilities for determining the correctness of the actually received timestamps are illustrated in Fig. 2. The two possibilities for determining the correctness of the timestamps can be used alternatively or in combination.

[0069] However, according to both possibilities, the third step S3 of comparing the predicted timestamps at the verifier 62 with the actually received timestamps comprises determining a difference between the predicted timestamps at the verifier 62 and the actually received timestamps; comparing the difference with a predetermined threshold; and if the difference is smaller than the predetermined threshold, preferably if the difference is within a certain range, determining the correctness of the actually received timestamps by a verification flag in which an integrity flag is set or any other means transparent to the recipient of the information.

[0070] More specifically, Figure 3 Two timelines are illustrated in Fig. 1. Figure 3 The left side of Fig. 1 illustrates the timeline of the first ECU 1 on which the local time lt of the slave clock 21 of the first ECU 1 is depicted; whereas Figure 3 The right side of Fig. 1 illustrates the timeline of the verifier 62 on which the local time LT of the slave clock 61 of the gateway ECU 6 is depicted.

[0071] Each synchronized ECU 2, 3, 4, 5, 6 has after synchronization the same available global time, which generally refers to the local instance of the global time, i.e. a local clock derived from its underlying local hardware counter (e.g. an oscillator), which maintains the synchronized time or global time, respectively. This means that the synchronized slave clock 21, 31, 41, 51, 61 is bound to the global time of the master clock 8.

[0072] At synchronization, a reference tuple lt1, GT1, LT1, GT1 is generated, which contains the local time It1, LT1 and the corresponding synchronized time GT1. This reference tuple lt1, GT1, LT1, GT1 is used to derive the current synchronized time at any desired point in time.

[0073] Thus, in the current case, the first step S1 of synchronizing the slave clock 21, 31, 41, 51, 61 only generates a reference, which can be used to convert from the local time It, LT to the synchronized time or global time GT.

[0074] For the first ECU 2, where in case of lt2 > lt1, the current synchronized time GT2 at the current local time lt2 is given by:

[0075] GT2 = GT1 + lt2 - lt1

[0076] GT2 can be the global time, which provides the measured data with the actual received timestamp read by the first ECU 2 from the local slave clock 21. GT1 can be the global time at the beginning of the actual communication cycle of the first ECU 2. lt1 can be the local time of the slave clock 21 of the first ECU 2 at the beginning of the actual communication cycle. lt2 can be the local time of the slave clock 21 of the first ECU 2 at the time of providing the actual received timestamp by the first ECU 2.

[0077] Similarly, for the gateway ECU 6, and thus for the verifier 62, where in case of LT2 > LT1, the current synchronized time GT2 at the current local time LT2 is given by:

[0078] GT2 = GT1 + LT2 - LT1

[0079] Moreover, as mentioned above, the communication scheme of the first communication standard comprises a deterministic or static part and a non-deterministic or dynamic part 11, the deterministic or static part comprising time slots si to sn, wherein each time slot has a fixed and predetermined duration.

[0080] During the data acquisition task of the first ECU 2, a time stamp, i.e. a time stamp originating from a local instance of the global time, is attached to the data transmitted in the static part of the data acquisition task and then transmitted from the first ECU 2 to the gateway ECU 6 via the first bus system 9 during the data transmission task.

[0081] Between the data transmission task and the data acquisition task, a fixed delay δ is provided according to the first communication standard.

[0082] Thus, considering the fixed delay δ between the data acquisition task and the data transmission task of the first ECU 2, it is possible to determine the difference between the global time of the predicted time stamp and the global time of the actually received time stamp, wherein the time stamp actually received by the verifier 62 is provided during the data acquisition task of the first ECU 2 for verification purposes. This is true for both possibilities of determining the correctness of the actually provided time stamp.

[0083] More specifically, according to the first possibility, the difference between the predicted time stamp and the actually received time stamp can be determined using the following formula:

[0084] GT2 - GT1 - Δ + δ

[0085] GT2 is the global time at which the actually received time stamp is provided by the first ECU 2. GT1 is the global reference time. In the present embodiment, GT1 is the global time at the beginning of the actual communication cycle of the first ECU 2. Δ is the result of multiplying the predetermined number n of time slots of the deterministic scheme of the first communication standard used by the first ECU 2 with the fixed duration I of a time slot Slot . Considering the scheduling of the messages, GT1 + Δ corresponds to the instance of the global time when the message is scheduled to be transmitted by the first ECU 2. As mentioned above, δ is the fixed delay between the data acquisition task and the data transmission task of the first ECU 2. The actually received time stamp is provided by the first ECU 2 during the data acquisition task. Thus, GT2 - δ corresponds to the instance of the global time when the message is scheduled to be transmitted by the first ECU 2. This formula exploits this fact by comparing the two instances to each other in time. Thereby, the integrity of the time stamp can be checked.

[0086] During the data acquisition task, the first ECU 2 can acquire data from an external unit, e.g. a sensor, and add the actually received time stamp to the acquired data. The time stamp is basically the global time at which the data is acquired from the first ECU 2.

[0087] During the data transmission task, the data acquired during the data acquisition task, plus the added timestamp of the actual reception, is sent from the first ECU 2 to the verifier 62.

[0088] The verifier then calculates the difference using the formula described above and compares it to a predetermined threshold. If the difference is less than the predetermined threshold, i.e., the jitter of the first ECU 2 is less than the threshold, the verifier 62 determines that the timestamp actually provided by the first ECU 2 is correct, i.e., it meets the security requirements of the second communication standard. Therefore, the verifier 62 is configured to recognize that the actually received timestamp meets the security level of the second communication standard, which is ASIL D in this document.

[0089] Alternatively or additionally, according to the second possibility, the difference between the predicted timestamp and the actual received timestamp can be determined using the following formula:

[0090] GT_Current-(GT2+δ)

[0091] As described above, GT2 is the global time of the actual reception timestamp provided by the first ECU 2, while δ is the fixed delay between the data acquisition task and the data transmission task of the first ECU 2. The actual reception timestamp is provided during the data acquisition task. GT_Current is the global time of the actual reception timestamp received at the verifier 62. From a conceptual point of view, these two solutions are the same; however, they may differ in the effort required to achieve a specific level of accuracy and the reliability required to achieve that specific level of accuracy.

[0092] Similar to the first possibility, verifier 62 compares the received difference with a predetermined threshold (uncertainty ε in this document), and if the difference is less than the threshold, i.e., the jitter of the first ECU 2 is less than the threshold, then verifier 62 determines that the timestamp actually provided by the first ECU 2 is correct, i.e., meets the security requirements of the second communication standard. Therefore, verifier 62 is configured to recognize that the actually received timestamp meets the security level of the second communication standard, which is ASIL D in this document.

[0093] Since the integrity of the master clock 8 is sufficient to meet the security requirements of the second communication standard, which has a higher security level than the first communication standard, the verifier 62 can determine the correctness of the actually received timestamp based on the security requirements of the second communication standard.

[0094] The above text is about Figure 3 The explanation given for the first ECU 2 is also valid for the second ECU 3; and if more than two ECUs 2 and 3 using the first communication standard are provided, it is also valid for these ECUs.

[0095] In summary, according to the above described embodiment, the Flexray bus 9 receives synchronization messages from the master clock 8. The Flexray bus 9 is internally synchronized based on a given synchronization message. The Ethernet communication bus 10 provides synchronization for the central validator 62 via IEEE 802.1 AS or similar protocol with ASILD. The central validator 62 on the gateway ECU 6 serves as a comparator between the Ethernet communication bus 10 and the Flexray communication bus 9, which compares the received timestamps with the expected values of these timestamps. The central validator 62 on the one hand ensures that the Ethernet communication is validated according to ASIL D and on the other hand takes the QM input from the Flexray bus 9 and validates it using the clock of the Ethernet. Since the Flexray bus 9 is inherently deterministic, the central validator 62 uses the deterministic schedule of the Flexray messages to validate the correctness of the Flexray timestamps provided as QM and acknowledges that a given timestamp fulfills ASIL D. The gateway ECU 6 (herein validator 62) can predict the timestamp of the next cycle that can come from the Flexray bus 9. The prediction of the timestamp is made based on the deterministic static message data including the fixed delay between the data acquisition task and the data transmission task of the Flexray standard. Thus, the predicted timestamp is compared with the received timestamp to ensure that the jitter in the Flexray communication bus 9 is not larger than the time synchronization threshold of a highly automated vehicle, i.e. 1 ms.

[0096] List of reference signs

[0097] 1 communication network

[0098] 2, 3 ECUs using a first communication standard

[0099] 4, 5 ECUs using a second communication standard

[0100] 6 gateway ECU with validator

[0101] 7 interconnect, e.g. switch

[0102] 8 time total master clock / master clock

[0103] 9 first bus system using a first communication standard

[0104] 10 second bus system using a second communication standard

[0105] 11 non-deterministic part of the first communication standard

[0106] 21 slave clock of the first ECU

[0107] 31 slave clock of the second ECU

[0108] 41 slave clock of the third ECU

[0109] 51 slave clock of the fourth ECU

[0110] 61 slave clock of the verifier

[0111] 62 verifier

[0112] GT global time

[0113] GT1 global time at the beginning of a cycle

[0114] GT2 global time at the time of providing / adding the actually received time stamp

[0115] GT_Current global time at the time of receiving the actually received time stamp at the verifier

[0116] 1t local time at the first ECU

[0117] 1t1 local time at the beginning of a cycle at the first ECU

[0118] 1t2 local time at the time of providing / adding the actually received time stamp at the first ECU

[0119] LT local time at the gateway ECU

[0120] LT1 local time at the beginning of a cycle at the gateway ECU

[0121] LT2 local time of the gateway ECU at the time of receiving the time stamp at the verifier

[0122] l Slot duration of one time slot of the first communication standard

[0123] N number of time slots

[0124] Δ by multiplying n by l Slot received result

[0125] δ fixed delay between the data acquisition task and the data transmission task

[0126] S1-S3 steps of the method

Claims

1. A method for using a verifier (62) to determine the correctness of a timestamp of actual reception provided by a first ECU (2) of a communication network (1), -The communication network (1) mentioned therein includes: -Master clock (8); The first ECU (2) has a first slave clock (21); The verifier (62) has a second slave clock (61); and the first communication bus (9), The first ECU (2), the verifier (62), and the master clock (8) are connected to each other. -The first ECU (2) uses a first communication standard with a deterministic scheme, - The method for determining at the verifier (62) the correctness of the timestamp of the actual received data provided by the first ECU (2) of the communication network (1) includes: - At the first ECU (2), the time of the first slave clock (21) is synchronized (S1) to the global time (GT) of the master clock (8). - At the verifier (62), the time of the second slave clock (61) is synchronized (S1) to the global time (GT) of the master clock (8). - At the verifier (62), based on the deterministic scheme of the communication standard used by the first ECU (2), the timestamp to be received from the first ECU (2) in the actual communication cycle is predicted (S2), and - At the verifier (62), the predicted timestamp is compared with the actual received timestamp from the first ECU (2) (S3), wherein at the verifier (62), the comparison of the predicted timestamp with the actual received timestamp provided by the first ECU (2) of the communication network (1) includes: - At the verifier (62), the difference between the predicted timestamp and the actual received timestamp is determined. - Compare the difference with a predetermined threshold, and If the difference is less than the predetermined threshold, then the correctness of the actual received timestamp is determined. -The difference between the global time (GT) of the predicted timestamp at the verifier (62) and the global time (GT) of the actual received timestamp is determined by taking into account a fixed delay (δ) between the data acquisition task and the data transmission task of the first ECU (2), wherein the actual received timestamp at the verifier (62) is provided by the first ECU (2) during the data acquisition task. -The difference between the predicted timestamp and the actual received timestamp is determined using the following formula: GT2-GT1-Δ+δ -in: -GT2 is the global time provided by the first ECU (2) for the actual received timestamp. -GT1 is the global reference time at the start of the actual communication cycle of the first ECU (2). -Δ is the result of dividing the predetermined number (n) of time slots of the deterministic scheme of the first communication standard used by the first ECU (2) by the fixed duration (l) of the time slots. Slot The result of multiplication, and -δ is the fixed delay between the data acquisition task and the data transmission task of the first ECU (2), wherein the timestamp of the actual reception is provided by the first ECU (2) during the data acquisition task.

2. The method according to claim 1, wherein the global time of the actually received timestamp is determined at the first ECU (2) using the following formula: GT2 = GT1 + lt2 - lt1 -in: -GT2 is the global time provided by the first ECU (2) for the actual received timestamp. -GT1 is the global reference time at the start of the actual communication cycle of the first ECU (2). -lt1 is the local time of the first slave clock (21) at the start of the actual communication cycle, and -lt2 is the local time of the first slave clock (21) when the actual received timestamp is provided by the first ECU (2).

3. The method according to claim 1 or 2, -The communication network (1) further includes: - Second ECU (4, 5) with a third slave clock (41, 45); Gateway ECU (6), including the verifier (62); and a second communication bus (10), which connects the second ECU (4, 5) to the first ECU (2) via the gateway ECU (6) and the first communication bus (9). -The second communication standard used by the second ECU (4, 5) has a higher security integrity level than the first communication standard used by the first ECU (2). -Where the integrity of the master clock (8) of the verifier (62) is sufficient to meet the security requirements of the second communication standard, which has a higher security integrity level than the first communication standard. - wherein the verifier (62) determines the correctness of the timestamp of the actual reception provided by the first ECU (2) according to the security requirements of the second communication standard.

4. The method according to claim 3, -Where, at the first ECU (2), synchronizing the time of the first slave clock (21) to the global time (GT) of the master clock (8) includes: - At the first ECU (2), a synchronization message is received from the master clock (8) such that the time of the first slave clock (21) of the first ECU (2) is synchronized to the global time (GT) of the master clock (8) based on the received synchronization message.

5. The method of claim 1, wherein determining the correctness of the actually received timestamp if the difference is less than the predetermined threshold comprises: If the difference is less than the predetermined threshold and the difference is within a certain range, then the correctness of the actually received timestamp is determined.

6. A verifier (62) configured to determine the correctness of a timestamp of actual reception provided by a first ECU (2) of a communication network (1), -The communication network (1) mentioned therein includes: -Master clock (8); The first ECU (2) has a first slave clock (21); and a first communication bus (9), configured to connect the first ECU (2), the verifier (62) and the master clock (8) to each other. -The first ECU (2) uses a first communication standard with a deterministic scheme, - wherein the time of the first slave clock (21) is synchronized to the global time (GT) of the master clock (8), -The verifier (62) includes a second slave clock (61), - wherein the time of the second slave clock (62) is synchronized to the global time (GT) of the master clock (8), -The verifier (62) is configured as follows: -Based on the deterministic scheme of the communication standard used by the first ECU (2), predict the timestamp to be received from the first ECU (2) in the actual communication cycle, and - Compare the predicted timestamp with the actual received timestamp from the first ECU (2). The comparison of the predicted timestamp with the actual received timestamp from the first ECU (2) at the verifier (62) includes: - At the verifier (62), the difference between the predicted timestamp and the actual received timestamp is determined. - Compare the difference with a predetermined threshold, and If the difference is less than the predetermined threshold, then the correctness of the actual received timestamp is determined. -The difference between the global time (GT) of the predicted timestamp at the verifier (62) and the global time (GT) of the actual received timestamp is determined by taking into account a fixed delay (δ) between the data acquisition task and the data transmission task of the first ECU (2), wherein the actual received timestamp at the verifier (62) is provided by the first ECU (2) during the data acquisition task. -The difference between the predicted timestamp and the actual received timestamp is determined using the following formula: GT2-GT1-Δ+δ -in: -GT2 is the global time provided by the first ECU (2) for the actual received timestamp. -GT1 is the global reference time at the start of the actual communication cycle of the first ECU (2). -Δ is the result of dividing the predetermined number (n) of time slots of the deterministic scheme of the first communication standard used by the first ECU (2) by the fixed duration (l) of the time slots. Slot The result of multiplication, and -δ is the fixed delay between the data acquisition task and the data transmission task of the first ECU (2), wherein the timestamp of the actual reception is provided by the first ECU (2) during the data acquisition task.

7. The verifier (62) according to claim 6, -The verifier (62) is configured to perform the method according to any one of claims 2 to 5.