Functional safety protection design method and device based on general precision time protocol, storage medium and vehicle

By applying a functional security protection design method based on the universal precision time protocol between Ethernet ECUs, the stability and reliability problems of GPTP time synchronization in network jitter and delay environments are solved, and high-precision full-link time synchronization functional security protection is achieved.

CN119996040APending Publication Date: 2025-05-13CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510269741.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

When GPTP time synchronization is performed between Ethernet ECUs, network jitter and delay cannot be effectively handled, which affects the stability and reliability of time synchronization, especially when the network environment is complex or there is a large network delay.

Method used

A functional safety protection design method based on the general precise time protocol is proposed. By determining the target safety level corresponding to the general precise time protocol, decomposing it into multiple target requirements based on the safety target, and identifying and analyzing the fault status based on the target requirements, and issuing the target safety requirements corresponding to the target safety level to the controller that has caused clock synchronization error based on the fault status.

Benefits of technology

It realizes safety protection of the time synchronization function of the full link, meets the requirements of high time synchronization accuracy, improves the stability and reliability of the system, and can maintain high accuracy of time synchronization in the face of network jitter and delay.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996040A_ABST
    Figure CN119996040A_ABST
Patent Text Reader

Abstract

The invention discloses a function safety protection design method and device based on a general precision time protocol, a storage medium and a vehicle, and the method comprises the steps: determining a target safety level corresponding to the general precision time protocol, decomposing the target safety level into a plurality of target demand items based on a safety target, and recognizing and analyzing a fault state based on the target demand items, and issuing a target security demand corresponding to the target security level to the controller causing the clock synchronization error based on the fault state. According to the method provided by the invention, the time synchronization function safety protection of the whole link can be realized, and the high time synchronization precision requirement is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of safety protection technology, and in particular to a functional safety protection design method based on a universal precision time protocol, a computer-readable storage medium, a vehicle, and a functional safety protection design device based on a universal precision time protocol. Background Art

[0002] With the increasing demand for time synchronization accuracy in network communications, particularly in audio and video streaming and industrial control, precise time synchronization has become an indispensable technical cornerstone. GPTP (Generalized Precision Time Protocol) provides high-precision clock synchronization, ensuring that all nodes in the network maintain highly consistent clocks within nanoseconds. This feature is crucial for many applications requiring precise time synchronization, such as industrial automation and intelligent driving systems. GPTP is essential for the following reasons: Ensuring Time Consistency: GPTP ensures highly accurate time consistency by synchronizing the clocks of all nodes in the network. This is crucial for systems requiring precise time control, such as industrial control systems and multimedia streaming. Improving System Stability: In AVB (Audio and Video Bridging) systems, GPTP ensures API (Application Programming Interface)-level compatibility, providing a stable and reliable foundation for multimedia streaming and real-time data exchange. Supporting High-Precision Applications: In intelligent driving systems, synchronizing data from multiple sensors using GPTP improves system responsiveness and accuracy, ensuring vehicle safety and efficiency. Meet industrial standards: GPTP complies with the IEEE 802.1AS standard, which requires that the time error of nodes in the network does not exceed 1 microsecond, which is necessary to meet time-sensitive applications in the field of industrial automation.

[0003] In summary, GPTP is essential because it provides high-precision clock synchronization, ensuring highly consistent clocks across all nodes in the network. This improves system stability, security, and efficiency, and meets the needs of various applications requiring precise time control. However, when implementing GPTP time synchronization between Ethernet ECUs (Electronic Control Units), network jitter and latency may not be effectively handled. These issues can affect the stability and reliability of time synchronization, especially in complex network environments or with significant network latency, making it impossible to provide the required high-precision time synchronization. Summary of the Invention

[0004] The present application aims to solve, at least to a certain extent, one of the technical problems in the related art. To this end, the first purpose of the present application is to propose a functional safety protection design method based on a universal precision time protocol, determine the target safety level corresponding to the universal precision time protocol, decompose the safety target into multiple target requirement items, identify and analyze fault conditions based on the target requirement items, and issue target safety requirements corresponding to the target safety level to controllers that cause clock synchronization errors based on the fault conditions. In this way, full-link time synchronization functional safety protection can be achieved to meet high time synchronization accuracy requirements.

[0005] A second object of the present application is to provide a computer-readable storage medium.

[0006] The third object of this application is to provide a vehicle.

[0007] The fourth objective of this application is to propose a functional safety protection design device based on a universal precision time protocol.

[0008] To achieve the above-mentioned objectives, the first embodiment of the present application proposes a functional safety protection design method based on a universal precision time protocol, the method comprising: determining a target safety level corresponding to the universal precision time protocol; decomposing the safety target into multiple target requirement items, and identifying and analyzing the fault state based on the target requirement items; and issuing the target safety requirement corresponding to the target safety level to the controller that causes clock synchronization errors based on the fault state.

[0009] According to the functional safety protection design method based on the Universal Precision Time Protocol (UPTP) in the embodiments of the present application, a target safety level corresponding to the UTP is determined, the safety goal is decomposed into multiple target requirement items, fault conditions are identified and analyzed based on the target requirement items, and based on the fault conditions, target safety requirements corresponding to the target safety level are issued to controllers that cause clock synchronization errors. Thus, the method can

[0010] In addition, the functional safety protection design method based on the universal precision time protocol according to the above embodiment of the present application may also have the following additional technical features:

[0011] According to one embodiment of the present application, the target security requirements include internal security requirements of the controller and communication security requirements between the controllers.

[0012] According to one embodiment of the present application, when the target security requirement is an internal security requirement of the controller, the method further includes: establishing a development process that meets the target security requirement for each controller based on preset standards, wherein the development process includes hardware design, software development, and testing and verification.

[0013] According to one embodiment of the present application, when the target security requirement is a communication security requirement between the controllers, the method further includes: adding an end-to-end protection mechanism in the message of the universal precision time protocol, wherein the end-to-end protection mechanism includes: building redundant links, rapid fault detection and recovery, traffic management, path selection and optimization, security and isolation, and at least one of protocol-level protection.

[0014] According to one embodiment of the present application, the method also includes: when the upper-layer application of the slave node does not need the end-to-end verification result of the master clock node, the slave node directly uses the time synchronization data, and the master clock node does not pass the end-to-end verification result to the slave node; when the upper-layer application of the slave node needs the end-to-end verification result of the master clock node, the master clock node encapsulates the end-to-end verification result and passes it to the slave node, wherein the end-to-end verification result includes at least one of a checksum, a counter and a timeout, and the encapsulating the end-to-end verification result and passing it to the slave node includes: encapsulating the verification result in the payload of the middleware protocol.

[0015] According to one embodiment of the present application, the method further includes: performing filtering processing on the upper-layer application of the slave node, wherein the filtering processing includes: processing the fault when an error is detected in the end-to-end verification result within a preset time, wherein the fault processing includes at least one of an alarm and switching a backup power supply.

[0016] According to one embodiment of the present application, determining the target security level corresponding to the universal precision time protocol includes: obtaining a target risk item; determining the target security level based on the target risk and a preset evaluation indicator, wherein the preset evaluation indicator is a single point failure indicator.

[0017] To achieve the above-mentioned objectives, the second embodiment of the present application proposes a computer-readable storage medium on which a program is stored. When the program is executed by a processor, it implements the above-mentioned functional safety protection design method based on the universal precision time protocol.

[0018] According to the computer-readable storage medium of the embodiment of the present application, by implementing the above-mentioned functional safety protection design method based on the universal precision time protocol during execution, full-link time synchronization functional safety protection can be achieved to meet high time synchronization accuracy requirements.

[0019] To achieve the above-mentioned purpose, a vehicle is proposed in an embodiment of the third aspect of the present application, comprising a memory, a processor, and a program stored in the memory and runnable on the processor. When the processor executes the program, the above-mentioned functional safety protection design method based on the universal precision time protocol is implemented.

[0020] According to the vehicle of the embodiment of the present application, by executing the above-mentioned functional safety protection design method based on the universal precision time protocol, it is possible to achieve full-link time synchronization functional safety protection and meet high time synchronization accuracy requirements.

[0021] To achieve the above-mentioned objectives, the fourth embodiment of the present application proposes a functional safety protection design device based on a universal precision time protocol, wherein the device includes: a first determination module for determining the target safety level corresponding to the universal precision time protocol; a second determination module for decomposing the safety target into multiple target requirement items, and identifying and analyzing the fault state based on the target requirement items; and a control module for issuing the target safety requirement corresponding to the target safety level to the controller that causes clock synchronization error based on the fault state.

[0022] According to the functional safety protection design device based on the Universal Precision Time Protocol (UPTP) in the embodiment of the present application, the first determination module is used to determine the target safety level corresponding to the UTP. The second determination module is used to decompose the safety target into multiple target requirement items and identify and analyze fault conditions based on the target requirement items. The control module is used to issue target safety requirements corresponding to the target safety level to controllers that cause clock synchronization errors based on the fault conditions. As a result, the device can achieve full-link time synchronization functional safety protection and meet high time synchronization accuracy requirements.

[0023] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 Flowchart of a functional safety protection design method based on a universal precision time protocol according to an embodiment of the present application;

[0025] Figure 2 This is a flowchart of a functional safety protection design method based on a universal precision time protocol according to a specific example of the present application;

[0026] Figure 3 is a block diagram of a vehicle according to an embodiment of the present application;

[0027] Figure 4 4 is a block diagram of a functional safety protection design device based on the universal precision time protocol according to an embodiment of the present application. DETAILED DESCRIPTION

[0028] The following describes in detail embodiments of the present application, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.

[0029] The following describes, with reference to the accompanying drawings, a functional safety protection design method based on a universal precision time protocol, a computer-readable storage medium, a vehicle, and a functional safety protection design device based on a universal precision time protocol proposed in an embodiment of the present application.

[0030] Figure 1 Flowchart of a functional safety protection design method based on a universal precision time protocol according to an embodiment of the present application.

[0031] like Figure 1 As shown, the functional safety protection design method based on the universal precision time protocol in the embodiment of the present application may include the following steps:

[0032] S1, determine the target security level corresponding to the Universal Precision Time Protocol.

[0033] S2, decomposes the safety goal into multiple target requirement items, and identifies and analyzes the fault status based on the target requirement items.

[0034] S3: Based on the fault status, a target safety requirement corresponding to the target safety level is issued to the controller that causes the clock synchronization error.

[0035] According to one embodiment of the present application, the target security requirements include internal security requirements of the controller and communication security requirements between controllers.

[0036] Specifically, based on the concept of functional safety, there must be no risk of inaccurate synchronization due to insufficient hardware or software system capabilities, including factors such as chip selection, protocol stack performance, and operating system impact. Risks such as inaccurate sensor data fusion and positioning errors caused by time asynchrony should be addressed. To mitigate this risk, functional safety level requirements should be established. This can be used to determine the target safety level for the universal precision time protocol. For example, a system risk assessment should be conducted to identify risk factors that could impact system safety, such as hardware failures, software defects, and environmental interference. Safety integrity levels (ASILs) can be determined for each risk item based on ISO 26262 (the International Organization for Standardization standard for functional safety of electrical and electronic systems in road vehicles) or other relevant standards. The entire system or its critical components can then be assigned a target safety level, such as ASIL A, B, C, or D. The determined safety level and assessment process should be documented in detail in the project documentation for the reference of the project team and auditors.

[0037] Decompose the safety goal into multiple target requirements and identify and analyze fault conditions based on these requirements. This means breaking down the overall safety goal into more specific safety requirements, such as time synchronization accuracy, data integrity, and fault detection time. Based on these requirements, identify fault conditions that could cause the safety goal to not be met. Use failure mode and effects analysis or fault tree analysis to systematically identify fault conditions. Analyze the impact of each fault condition on system functionality and safety goals, and determine which fault conditions need to be avoided or mitigated through design.

[0038] Then, according to the fault status, the target safety requirement corresponding to the target safety level can be issued to the controller that causes the clock synchronization error.

[0039] Controllers use the GPTP protocol to synchronize the time of various devices on the network. This includes a grandmaster (GM) and slaves (also known as slave nodes). Bridges, which connect to next-hop slave nodes, can also handle dwell time. Controllers may experience time synchronization errors due to hardware failures (such as unstable crystal oscillators), software defects, network latency, electromagnetic interference, and other factors. To address these potential causes of clock synchronization errors, target safety requirements corresponding to the target safety level must be issued to these controllers to ensure they can provide high-accuracy and high-reliability time synchronization services, meeting functional safety requirements, even in the face of various potential faults and error sources. Based on the identified fault conditions and the determined safety level, specific safety requirements can be issued for each controller. These requirements should include specific requirements for hardware design, software development, testing, and verification. During the controller design and development process, appropriate safety measures, such as redundancy, fault detection and recovery mechanisms, and data encryption, should be implemented to ensure that these measures meet the issued safety requirements and mitigate or avoid identified fault conditions. Controllers can be rigorously tested and verified to ensure they meet all issued safety requirements. Includes unit testing, integration testing, system testing and security testing to verify the security and reliability of the system.

[0040] In this way, the time synchronization function of the entire link can be safely protected and the requirements of high time synchronization accuracy can be met.

[0041] Specifically, target security requirements can include internal controller security requirements and inter-controller communication security requirements. For example, internal controller security requirements include hardware design security and software design security. Inter-controller communication security requirements include data transmission security, communication protocol security, and network architecture security. This comprehensive security protection design approach addresses both internal and inter-controller communication security requirements, encompassing hardware design, software development, testing and verification, data transmission security, communication protocol security, and network architecture security. The approach aims to improve the overall security and reliability of data transmission and meet the requirements of functional safety standards.

[0042] According to one embodiment of the present application, when the target safety requirement is an internal safety requirement of the controller, the functional safety protection design method based on the universal precision time protocol also includes: establishing a development process that meets the target safety requirement for each controller based on preset standards, wherein the development process includes hardware design, software development, and testing and verification.

[0043] Specifically, when the target safety requirements focus on internal controller security, it is necessary to ensure that the development process of each controller meets the specific safety requirements. This involves following pre-set industry standards, such as ISO 26262, to establish a comprehensive development process.

[0044] The development process may include hardware design, such as analyzing the safety integrity level (ASIL) that hardware components need to meet according to the ISO 26262 standard. Hardware redundancy, such as the use of multiple sensors or actuators, can be designed to improve the system's fault tolerance. Fault detection circuits, such as temperature sensors and voltage monitoring, can be integrated into the hardware to promptly detect potential failures. Hardware design also ensures that electromagnetic compatibility requirements are met to reduce the impact of electromagnetic interference on the system. Reliability design methods, such as derating and thermal design, can be implemented to improve hardware reliability.

[0045] The development process can include software development, such as analyzing the safety requirements the software needs to meet, including functional safety and information security requirements. A modular design approach can be adopted to break the software into manageable modules for easier development and maintenance. Fault-tolerance mechanisms, such as watchdog timers and error recovery strategies, can be implemented in the software. Coding standards and best practices can be followed to ensure code quality, and software safety certification can be obtained.

[0046] The development process may also include testing and verification, such as unit testing of each software module to ensure correct functionality, testing of all modules integrated together to ensure correct interfaces and interactions between modules, testing of the entire system, including functional testing, performance testing, and reliability testing, and security testing, such as penetration testing and fuzz testing, to identify potential security vulnerabilities. Verification activities, such as formal verification and model checking, ensure that communications meet all security requirements.

[0047] Therefore, by establishing a comprehensive development process, we ensure that the hardware, software, and testing and verification activities of each controller meet the target safety requirements. This approach helps improve the reliability and safety of the controller and meet the requirements of functional safety standards.

[0048] According to one embodiment of the present application, when the target security requirement is the communication security requirement between controllers, the functional safety protection design method based on the universal precision time protocol also includes: adding an end-to-end protection mechanism in the message of the universal precision time protocol, wherein the end-to-end protection mechanism includes: building redundant links, rapid fault detection and recovery, traffic management, path selection and optimization, security and isolation, and at least one of protocol-level protection.

[0049] Specifically, GPTP's algorithm incorporates unique protection mechanisms designed to enhance the accuracy and reliability of network time synchronization. It ensures accurate transmission of time information between the sender and receiver by detecting and compensating for variations in network transmission delay. This protection mechanism is implemented through the following methods: Bidirectional delay measurement: The sender sends a timestamp, the receiver records the reception time, and immediately returns a timestamp containing the reception time. The sender then records the return time. These timestamps can be used to calculate the bidirectional transmission delay, thereby correcting time synchronization errors. Frequency deviation correction: By continuously monitoring changes in network delay, frequency deviation (i.e., a missynchronization between the sender and receiver clock frequencies) can be detected, allowing for frequency correction. Path symmetry assumption: The E2E protection mechanism assumes that the network path is identical in both forward and reverse directions, meaning that the delay is equal in both directions. This assumption simplifies delay compensation calculations. Anomaly detection: The E2E protection mechanism also detects network anomalies, such as packet loss or sudden delays, and addresses these anomalies through redundant paths or resynchronization strategies, ensuring the continuity and stability of time synchronization. Through these mechanisms, the accuracy of time synchronization can be effectively improved and the impact of network fluctuations on time synchronization can be reduced. It is suitable for application scenarios with high requirements for time synchronization, such as industrial automation, power systems, and communication networks.

[0050] In addition, an end-to-end protection mechanism can be added to the GPTP message. That is, when the target security requirement is the communication security requirement between controllers, an end-to-end protection mechanism can be added to the General Precision Time Protocol message. For example, the end-to-end protection mechanism includes: building redundant links, that is, to avoid single points of failure, by establishing primary and backup links to ensure the continuity of communication. Including multiple physical paths in the network design, when the main link fails, it can seamlessly switch to the backup link to ensure uninterrupted data transmission. The end-to-end protection mechanism also includes: rapid fault detection and recovery, that is, quickly identifying communication failures and restoring services to minimize the impact on system performance, such as by deploying fault detection algorithms (such as heartbeat detection, timeout retransmission, etc.) and automatic recovery mechanisms (such as failover, rerouting, etc.) to ensure a rapid response when a fault is detected.

[0051] End-to-end protection mechanisms may also include traffic management, such as using traffic shaping and priority tagging to manage network traffic, prevent congestion and packet loss, optimize network resource utilization, and ensure the priority transmission of critical data packets. End-to-end protection mechanisms may also include path selection and optimization, utilizing routing protocols and path calculation algorithms to adjust data transmission paths in real time to improve transmission efficiency and reliability. This allows for the dynamic selection of optimal transmission paths based on network status and data transmission requirements, thereby improving data transmission efficiency.

[0052] End-to-end protection mechanisms can also include security and isolation. Security measures such as data encryption, access control lists, and firewalls, as well as network isolation technologies, ensure data security and network isolation during transmission. This ensures effective isolation between different network components to prevent fault propagation. End-to-end protection mechanisms can also include protocol-level protection. For example, the IEEE 802.1CB Time-Sensitive Networking protocol, which provides time synchronization, traffic shaping, and prioritization, further enhances the E2E protection capabilities of Industrial Ethernet. This leverages protocol-specific features to enhance communication protection.

[0053] Therefore, by adding end-to-end protection mechanisms to GPTP messages, a comprehensive inter-controller communication security solution is provided. These protection mechanisms include redundant links, rapid fault detection and recovery, traffic management, path selection and optimization, security and isolation, and protocol-level protection, which together ensure the reliability, stability, and security of data transmission. By implementing this application, the robustness of gPTP-based systems in the face of various faults and attacks can be significantly improved, meeting functional safety requirements.

[0054] According to one embodiment of the present application, a functional safety protection design method based on a universal precision time protocol also includes: when the upper-layer application of the slave node does not require the end-to-end verification result of the master clock node, the slave node directly uses the time synchronization data, and the master clock node does not pass the end-to-end verification result to the slave node; when the upper-layer application of the slave node requires the end-to-end verification result of the master clock node, the master clock node encapsulates the end-to-end verification result and passes it to the slave node, wherein the end-to-end verification result includes at least one of a checksum, a counter, and a timeout, and encapsulating the end-to-end verification result and passing it to the slave node includes: encapsulating the verification result in the payload of the middleware protocol.

[0055] Specifically, the requirements of the slave node's upper-layer applications for time synchronization data accuracy and reliability are analyzed to determine whether the applications require the master clock node's end-to-end verification results to ensure data integrity and correctness. If the slave node's upper-layer applications do not require end-to-end verification results, the master clock node directly sends the time synchronization data to the slave node without appending any verification results. This reduces data transmission overhead and improves efficiency. If the slave node's upper-layer applications do require end-to-end verification results, the master clock node encapsulates the verification results and transmits them to the slave node.

[0056] For example, the end-to-end verification result (including at least one of a checksum, a counter, and a timeout) can be encapsulated within the payload of a middleware protocol. This encapsulation method can be used in middleware protocols commonly used in automotive electronic systems, such as SOME / IP, CAN, and FlexRay. The encapsulation process ensures that the verification result is transmitted along with the time synchronization data, but does not affect the main content of the data. The encapsulated data is transmitted to the slave node via the vehicle network. After receiving the data, the slave node can parse and use the end-to-end verification result as needed. Checksums are another error detection method. By calculating a checksum of the data and appending this value to data transmission, the receiving end recalculates the checksum of the received data and compares it with the sent checksum value to detect errors. Counters record the order in which packets are sent and received. By comparing the counter values ​​at the sending and receiving ends, packet loss or duplication can be detected. A timeout mechanism verifies that a packet arrives within the expected time. If a packet is not received within the set timeout period, the system can assume that a timeout error has occurred. The purpose of end-to-end verification results is to ensure the reliability and integrity of data transmission. In time synchronization systems, these verification results are crucial to ensuring the accurate transmission of time information, because any data errors may cause time synchronization failure, which in turn affects the stability and performance of the entire system.

[0057] This improves the efficiency and reliability of the time synchronization system by flexibly handling end-to-end verification results. When verification results are not needed, the time synchronization data can be used directly, reducing overhead. When verification results are needed, they are encapsulated and transmitted to ensure data integrity and correctness.

[0058] Furthermore, according to ISO 26262, communication between components with high functional safety requirements requires the use of secure data transmission mechanisms. This means that mechanisms must be implemented to prevent communication errors; if errors cannot be completely prevented, they must be detected in real time. An end-to-end protection mechanism is a mechanism used to ensure the exchange of safety-related functional information between controllers. This safety-related information typically consists of a set of data, such as sensor values ​​and control command signals. To detect errors in communication and ensure the timeliness, correctness, and integrity of the data, extended information, such as checksums and counters, is appended to safety-related signals. The sender is the node that sends the protected data, and the receiver is the node that receives and checks the protected data.

[0059] The main types of failures involved in GPTP include the following: signal duplication: the receiver receives the same sequence ID information more than once; signal loss: all or part of the information in the information stream sent by the sender is lost, resulting in discontinuous sequence IDs; signal delay: the receiver does not receive the clock synchronization signal within the specified time; signal sequence error: the order of information in a series of transmitted information streams is modified; signal corruption: the information is altered; signal reception asymmetry: different receivers receive different information from the same sender; some receivers do not receive the expected signal: only some of the several receivers receive the information; signal channel blockage: access to the communication channel is blocked. End-to-end communication function security protection is designed to detect the causes of communication failures or reduce the impact of communication failures. These communication failures mainly include: system software errors, hardware errors, and transient errors caused by external factors, such as short-term system failures caused by radiation and electromagnetic interference.

[0060] Therefore, a CRC (Cyclic Redundancy Check) can be used to perform a CRC check using the selected CRC algorithm. If the check is correct, end-to-end protection is considered to be normal; otherwise, there is a problem. The counter counting function, which exists in the protected data, is used to count data transmission. The receiving end compares the counter value in the current data with the counter value in the last valid data received. If the count is repeated, it means that no new data has been received since the last call to the E2E library function; the data is repeated. Counter verification is normal: the counter increases by 1 (indicates no data loss); the counter increases by more than 1 but is within the allowed range (indicates partial data loss). Counter verification is incorrect: the counter increases by more than the allowed value (indicates a large amount of data loss). Timeout detection: The receiving end can use the counter to detect communication losses or timeouts. If the counter does not increase and exceeds the defined timeout period, an end-to-end timeout error is considered to have occurred.

[0061] According to one embodiment of the present application, a functional safety protection design method based on the Universal Precision Time Protocol further includes: performing filtering processing on upper-layer applications of slave nodes. The filtering processing includes: if an error in the end-to-end checksum result is detected for a continuous preset time period, handling the fault. The fault handling includes at least one of issuing an alarm and switching to a backup power supply. The preset time period can be determined based on actual conditions.

[0062] Specifically, filtering can also be performed on upper-layer applications on slave nodes. The goal of filtering is to reduce false alarms caused by occasional errors or transient interference, thereby improving system stability and reliability. In the GPTP system, end-to-end verification results are used to ensure the integrity and correctness of time synchronization data. However, in certain situations, such as transient network interference or hardware failures, occasional errors may occur. Filtering distinguishes these occasional errors from true system failures by continuously detecting errors over a certain period of time.

[0063] That is, the filtering process may include handling the fault if an error in the end-to-end verification result is detected for a continuous preset time. For example, a preset time window is defined, such as a preset time of 2 seconds, and the end-to-end verification result will be continuously monitored within this time window. If errors are detected in the end-to-end verification result within the preset time, these errors will be recorded. If errors are detected continuously within the preset time, it will be evaluated whether these errors indicate a continuous system failure. Once it is evaluated as a continuous error, fault handling measures may be executed, including but not limited to: Alarm: Trigger the alarm mechanism to notify the operator or system administrator of a potential system failure. Switch to the backup power supply: If the system design includes a backup power supply or redundant power supply, the system will automatically switch to the backup power supply to maintain the continuity of the time synchronization service.

[0064] If no errors are detected within the preset continuous time, the system assumes no errors. This prevents occasional errors in end-to-end verification due to factors such as varying controller sleep and wakeup times and hardware differences. This effectively distinguishes occasional errors from true system failures. This approach improves the reliability and stability of GPTP-based time synchronization systems, especially in applications with strict functional safety requirements. By implementing fault handling measures such as alarms and switching to backup power supplies, the system can quickly respond to potential failures, ensuring the continuity and accuracy of time synchronization services.

[0065] According to one embodiment of the present application, determining a target security level corresponding to a universal precision time protocol includes: obtaining a target risk item; and determining the target security level based on the target risk and a preset evaluation indicator, wherein the preset evaluation indicator is a single point failure indicator.

[0066] Specifically, based on the concept of functional safety, there must be no risk of inaccurate synchronization due to insufficient hardware or software system capabilities, including factors such as chip selection, protocol stack performance, and operating system impact. Risks such as inaccurate sensor data fusion caused by time asynchrony, leading to positioning errors, can arise. To avoid this risk, functional safety level requirements should be established. Specifically, when determining the target safety level for the General Precision Time Protocol (GPTP), target risk items can be identified. For example, first, the scope and boundaries of the GPTP time synchronization system must be clearly defined, including all relevant hardware components, software modules, and external interfaces. Potential failure modes must be identified, such as through failure mode and effects analysis (FMEA) or fault tree analysis, to identify all potential failure modes that the system may encounter. Finally, risk items are determined. For example, from the identified failure modes, those that could lead to loss of system functionality or performance degradation are identified.

[0067] After determining the target risk item, the target safety level can be determined based on the target risk and the preset evaluation index, where the preset evaluation index is the single point failure index. That is, each risk item can be evaluated to determine its impact on system safety. This includes evaluating the possibility of a failure and the severity of the consequences of the failure. In this embodiment, the single point failure index (SEC) is used as the preset evaluation index. The SEC is used to quantify the probability of a single point failure in the system, that is, the probability that a single failure point causes the loss of system function. By analyzing the failure mode of the system, the SEC value is calculated. The higher the SEC value, the greater the risk of single point failure in the system. The target safety level that the system needs to achieve can be determined based on the SEC value and the ISO 26262 standard or other relevant standards. For example, if the SEC value is high, it may be necessary to achieve a safety level of ASIL B or higher.

[0068] Therefore, by obtaining target risk items, assessing the risk, and using SEC as a preset evaluation indicator, a target safety level is determined for the GPTP-based time synchronization system. This approach ensures that the system can operate safely in the face of potential failures and meet functional safety requirements.

[0069] The following combination Figure 2 To describe the method of this application.

[0070] As a specific example, the functional safety protection design method based on the universal precision time protocol of the present application may include the following steps:

[0071] S101, obtaining target risk items.

[0072] S102, determining a target safety level based on target risk and a preset evaluation index, wherein the preset evaluation index is a single point failure index.

[0073] S103: Decompose the safety goal into multiple target requirement items, and identify and analyze the fault status based on the target requirement items.

[0074] S104: Establish a development process for each controller that meets target safety requirements based on preset standards. The development process includes hardware design, software development, and testing and verification.

[0075] S105, adding an end-to-end protection mechanism to the universal precision time protocol message, wherein the end-to-end protection mechanism includes: building redundant links, fast fault detection and recovery, traffic management, path selection and optimization, security and isolation, and at least one of protocol-level protection.

[0076] S106: Determine whether the upper layer application of the slave node requires the end-to-end verification result of the master clock node. If yes, execute step S107; if not, execute step S109.

[0077] S107, the master clock node encapsulates the end-to-end verification result and transmits it to the slave node, wherein the end-to-end verification result includes at least one of a checksum, a counter, and a timeout. Encapsulating the end-to-end verification result and transmitting it to the slave node includes: encapsulating the verification result in a payload of the middleware protocol.

[0078] S108 , when an error in the end-to-end verification result is detected for a continuous preset time, the fault is processed, wherein the fault processing includes at least one of an alarm and switching to a backup power supply.

[0079] S109 , the slave node directly uses the time synchronization data, the master clock node does not transmit the end-to-end verification result to the slave node, and the process proceeds to step S105 .

[0080] In summary, according to the functional safety protection design method based on the Universal Precision Time Protocol (UPTP) in the embodiments of this application, the target safety level corresponding to the UTP is determined, the safety goal is decomposed into multiple target requirements, fault conditions are identified and analyzed based on the target requirements, and based on the fault conditions, target safety requirements corresponding to the target safety level are issued to controllers that cause clock synchronization errors. As a result, this method can achieve full-link time synchronization functional safety protection and meet high time synchronization accuracy requirements.

[0081] Corresponding to the above embodiment, the present application also proposes a computer-readable storage medium.

[0082] The computer-readable storage medium of an embodiment of the present application stores a program thereon, which, when executed by a processor, implements the above-mentioned functional safety protection design method based on the universal precision time protocol.

[0083] According to the computer-readable storage medium of the embodiment of the present application, by executing the above-mentioned functional safety protection design method based on the universal precision time protocol, full-link time synchronization functional safety protection can be achieved to meet high time synchronization accuracy requirements.

[0084] Corresponding to the above embodiments, the present application also proposes a vehicle.

[0085] like Figure 3 As shown, the vehicle 200 of the embodiment of the present application may include: a memory 210, a processor 220, and a program stored in the memory 210 and executable on the processor 220. When the processor 220 executes the program, the above-mentioned functional safety protection design method based on the universal precision time protocol is implemented.

[0086] According to the vehicle of the embodiment of the present application, by executing the above-mentioned functional safety protection design method based on the universal precision time protocol, it is possible to achieve full-link time synchronization functional safety protection and meet high time synchronization accuracy requirements.

[0087] Corresponding to the above embodiments, the present application also proposes a functional safety protection design device based on a universal precision time protocol.

[0088] like Figure 4 As shown, the functional safety protection design device 100 based on the universal precision time protocol according to an embodiment of the present application includes: a first determination module 110 , a second determination module 120 and a control module 130 .

[0089] The first determination module 110 is configured to determine a target security level for the Universal Precision Time Protocol. The second determination module 120 is configured to decompose the security goal into multiple target requirements and identify and analyze fault conditions based on the target requirements. The control module 130 is configured to issue target security requirements corresponding to the target security level to controllers that cause clock synchronization errors based on the fault conditions.

[0090] According to one embodiment of the present application, the target security requirements include internal security requirements of the controller and communication security requirements between controllers.

[0091] According to one embodiment of the present application, when the target security requirement is an internal security requirement of the controller, the control module 130 is also used to: establish a development process that meets the target security requirement for each controller based on preset standards, wherein the development process includes hardware design, software development, and testing and verification.

[0092] According to one embodiment of the present application, when the target security requirement is the communication security requirement between controllers, the control module 130 is also used to: add an end-to-end protection mechanism in the message of the universal precision time protocol, wherein the end-to-end protection mechanism includes: building redundant links, rapid fault detection and recovery, traffic management, path selection and optimization, security and isolation, and at least one of protocol-level protection.

[0093] According to one embodiment of the present application, the control module 130 is also used for: when the upper-layer application of the slave node does not need the end-to-end verification result of the master clock node, the slave node directly uses the time synchronization data, and the master clock node does not pass the end-to-end verification result to the slave node; when the upper-layer application of the slave node needs the end-to-end verification result of the master clock node, the master clock node encapsulates the end-to-end verification result and passes it to the slave node, wherein the end-to-end verification result includes at least one of a checksum, a counter and a timeout, and encapsulating the end-to-end verification result and passing it to the slave node includes: encapsulating the verification result in the payload of the middleware protocol.

[0094] According to one embodiment of the present application, the control module 130 is also used to: perform filtering processing on the upper-layer application of the slave node, wherein the filtering processing includes: when an error is detected in the end-to-end verification result within a preset time, processing the fault, wherein the fault processing includes at least one of an alarm and switching the backup power supply.

[0095] According to an embodiment of the present application, the first determination module 110 determines a target security level corresponding to the universal precision time protocol, specifically for: obtaining a target risk item; and determining the target security level based on the target risk and a preset evaluation indicator, wherein the preset evaluation indicator is a single point failure indicator.

[0096] It should be noted that for details not disclosed in the functional safety protection design method based on the universal precision time protocol in the embodiment of the present application, please refer to the details disclosed in the functional safety protection design method based on the universal precision time protocol in the embodiment of the present application, and the details will not be repeated here.

[0097] According to the functional safety protection design device based on the Universal Precision Time Protocol (UPTP) in the embodiment of the present application, the first determination module is used to determine the target safety level corresponding to the UTP. The second determination module is used to decompose the safety target into multiple target requirement items and identify and analyze fault conditions based on the target requirement items. The control module is used to issue target safety requirements corresponding to the target safety level to controllers that cause clock synchronization errors based on the fault conditions. As a result, the device can achieve full-link time synchronization functional safety protection and meet high time synchronization accuracy requirements.

[0098] It should be noted that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic device), a portable computer disk cartridge (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and programmable read-only memory (EPROM or flash memory), fiber optic devices, and portable compact disc read-only memory (CDROM). Furthermore, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or processing it in another suitable manner if necessary, and then storing it in a computer memory.

[0099] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0100] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present application. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0101] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of such features. Throughout the description of this application, "plurality" means at least two, for example, two, three, etc., unless otherwise specifically defined.

[0102] In this application, unless otherwise specified or limited, the terms "installed," "connected," "connect," "fixed," etc. should be understood in a broad sense. For example, they can refer to fixed connection, detachable connection, or integration; mechanical connection or electrical connection; direct connection or indirect connection through an intermediate medium; internal communication between two elements or interaction between two elements, unless otherwise specified. Those skilled in the art will understand the specific meanings of the above terms in this application based on specific circumstances.

[0103] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A functional safety protection design method based on a universal precision time protocol, characterized in that: The method comprises: Determining a target security level corresponding to the universal precision time protocol; Decomposing the safety goal into a plurality of target requirement items, and identifying and analyzing the fault state based on the target requirement items; Based on the fault state, a target safety requirement corresponding to the target safety level is issued to the controller that causes the clock synchronization error.

2. The functional safety protection design method based on the universal precision time protocol according to claim 1 is characterized in that: The target security requirements include the internal security requirements of the controller and the communication security requirements between the controllers.

3. The functional safety protection design method based on the universal precision time protocol according to claim 2 is characterized in that: In the case where the target security requirement is an internal security requirement of the controller, the method further includes: A development process that meets the target safety requirements is established for each controller based on preset standards, wherein the development process includes hardware design, software development, and testing and verification.

4. The functional safety protection design method based on the universal precision time protocol according to claim 2 is characterized in that: In the case where the target security requirement is a communication security requirement between the controllers, the method further includes: An end-to-end protection mechanism is added to the message of the universal precision time protocol, wherein the end-to-end protection mechanism includes: building redundant links, fast fault detection and recovery, traffic management, path selection and optimization, security and isolation, and at least one of the protection at the protocol level.

5. The functional safety protection design method based on the universal precision time protocol according to claim 4 is characterized in that: The method further comprises: In the case where the upper layer application of the slave node does not need the end-to-end verification result of the master clock node, the slave node directly uses the time synchronization data, and the master clock node does not transmit the end-to-end verification result to the slave node; In the case that the upper-layer application of the slave node requires the end-to-end verification result of the master clock node, the master clock node encapsulates the end-to-end verification result and passes it to the slave node, wherein the end-to-end verification result includes at least one of a checksum, a counter and a timeout, and the encapsulating the end-to-end verification result and passing it to the slave node includes: encapsulating the verification result in the payload of the middleware protocol.

6. The functional safety protection design method based on the universal precision time protocol according to claim 5 is characterized in that: The method further comprises: Performing filtering processing on the upper layer application of the slave node, wherein the filtering processing includes: When an error is detected in the end-to-end verification result for a continuous preset time, the fault is processed, wherein the fault processing includes at least one of an alarm and switching a backup power supply.

7. The functional safety protection design method based on the universal precision time protocol according to claim 1 is characterized in that: Determining a target security level corresponding to the universal precision time protocol includes: Get target risk items; The target safety level is determined based on the target risk and a preset evaluation index, wherein the preset evaluation index is a single point failure index.

8. A computer-readable storage medium, characterized in that: A program is stored thereon, and when the program is executed by a processor, the functional safety protection design method based on the universal precision time protocol according to any one of claims 1 to 7 is implemented.

9. A vehicle, characterized in that: include: A memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, the functional safety protection design method based on the universal precision time protocol according to any one of claims 1 to 7 is implemented.

10. A functional safety protection design device based on a universal precision time protocol, characterized in that: The device comprises: A first determination module, configured to determine a target security level corresponding to the universal precision time protocol; A second determination module is used to decompose the safety target into a plurality of target requirement items, and identify and analyze the fault state based on the target requirement items; The control module is used to send the target safety requirement corresponding to the target safety level to the controller that causes the clock synchronization error based on the fault state.