Ethernet device with security function in physical layer and method for bidirectional data transmission between two Ethernet devices

By introducing Ethernet devices with security functions in the physical layer in automotive safety-critical applications, using redundant links and safety mechanism units to detect and deal with channel security issues, rapid fault detection and data rerouting are achieved, solving the problems of long fault detection and processing time in the prior art, and ensuring the reliability and security of data communication.

CN120092412AActive Publication Date: 2025-06-03SILICONALLY GMBH
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202280100127.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-09-16
Publication Date
2025-06-03
Estimated Expiration
2042-09-16

AI Technical Summary

Technical Problem

The prior art is difficult to detect and handle faults in Ethernet communication links within shorter fault detection time intervals and fault handling time intervals, especially in automotive safety-critical applications, which may lead to failure modes and safety issues in data transmission.

Method used

By introducing redundant links and security mechanism units into Ethernet devices with security functions in the physical layer, security issues for the channel are detected and security critical data is rerouted by switching to the second Ethernet channel when the problem is detected.

Benefits of technology

It realizes rapid fault detection and processing of Ethernet communication links in automotive safety-critical applications, ensures the reliability and security of data communication, and avoids data loss and communication interruption caused by failures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120092412A_ABST
    Figure CN120092412A_ABST
Patent Text Reader

Abstract

The invention relates to an Ethernet device (100, 200) having a security function in the physical layer and to a method for bidirectional data transmission between two Ethernet devices (100, 200), at least one of the two Ethernet devices (100, 200) being an Ethernet device (100, 200) having a security function in the physical layer according to the invention. If a security issue is detected in the first Ethernet channel (102), the Ethernet device (100, 200) may switch security critical traffic from the first Ethernet channel (120) to the second Ethernet channel (140).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to an Ethernet device having a security function at the physical layer. The present invention also relates to a method for bidirectional data transmission between two Ethernet devices, wherein at least one of the two Ethernet devices is an Ethernet device having a security function at the physical layer according to the present invention.

[0002] The present invention relates to the technical field of automotive Ethernet connections, as defined, for example, in IEEE Std.802.3TM-2018 (IEEE Ethernet standard). Specifically, the present invention relates to reliable communication links for automotive safety-critical applications. In such applications, fault modes of data transmission must be prevented, such as loss of communication peer, message corruption, unacceptable delay of messages, message loss, unexpected message duplication, incorrect message order, message insertion, message spoofing, incorrect message addressing, or similar faults (see, for example, ISO 26262-5:2018, Appendix D.1).

[0003] Faults should be detected within a short fault detection time interval (FDTI) and processed within a short fault handling time interval (FHTI) so that the system enters a safe state. The safe state is the desired safe operation, that is, in the event of a fault, data communication on the safety-critical communication link can still be carried out. This is very important for applications such as drive-by-wire or brake-by-wire.

[0004] It is known from the prior art that end-to-end protection of Ethernet data transmission can be provided at the OSI (Open System Interconnection model) application layer. For example, the AUTOSAR E2E protocol specification discloses that before sending payload data, a checksum generated by the application layer is appended to the payload data to achieve end-to-end data protection for sending data from one node to another. The receiving application receives the payload data including the checksum and checks the data integrity before using the data by calculating the checksum of the received payload data and comparing the calculated checksum with the received checksum appended to the payload data. The advantage of this method is that it can cover the entire data communication link between two applications. For example, if a data packet is corrupted within an ECU (Electronic Control Unit) or even within a processor due to the lack of a fault mechanism (such as ECC (Error Correction Code) memory), the application can check the integrity of each data packet. The disadvantage of this method is that the application can only detect integrity problems but not the reasons for the integrity problems. In addition, integrity problems can only be detected when the receiving node receives the data, and the sender has no knowledge of any information at all. For event-based messages, a security mechanism is simply impossible to implement because the application cannot predict when a message will be received.

[0005] In addition, random failures may also occur. The application cannot switch to the degraded mode after one or two data packets are corrupted, because this may be a random failure. For CAN (Controller Area Network)-based communication, it usually enters any degraded mode only after receiving up to 10 corrupted data packets. For messages received periodically with a cycle time of 50 ms, the degraded mode can be started as early as 500 ms later, which may pose a problem for safety-critical communication links.

[0006] It is also known from the prior art to provide data protection for Ethernet data transmission on the OSI transport layer. In this case, it is necessary to distinguish between connection-oriented and connectionless transport protocols because they have different data integrity capabilities.

[0007] Connection-oriented transport protocols (such as TCP) are generally not used for safety-related communications, even though they provide some interesting reliability features such as message confirmation and message retransmission. For real-time protocols, transport protocols have some drawbacks that also lead to uncertain reliability. Establishing a connection is a complex process involving many states. The state machine for handling the connection must be fully defined, and there must be no deadlocks or livelocks on both sides. Message confirmation and message retransmission may lead to undefined bus load conditions and even cause the bus to become completely congested. Critical information always requires an open connection. Either the connection must always be kept open, but this incurs unnecessary overhead and traffic, or the connection must be established before sending a message, but this is very dangerous. In addition, connection-oriented transport protocols generally only support point-to-point connections. The protocol complexity for unicast or broadcast scenarios is very high, so their implementation is not commonly used.

[0008] Connectionless transport protocols (such as UDP) are not as sufficient in terms of data reliability features, but they are easier to handle and also support multicast and broadcast, which is very interesting for state-of-the-art applications such as those using a proxy-free publish-subscribe architecture (such as OMG DDS). The main reliability feature that can be achieved by connectionless transport protocols is another data checksum above the OSI data link layer.

[0009] It can also be learned from the prior art to provide data protection for Ethernet data transmission on the OSI data link layer. The main function of the data link layer is to form data packets from the symbol stream and check their integrity. Therefore, data packets are usually extended by CRC (Cyclic Redundancy Check) at the sending end and the data integrity is checked by CRC at the receiving end. CRC can serve as a powerful function for data integrity. However, the check can only be performed when the receiving end receives the data. If the sender needs to know the failure situation at the receiving end (for example, for data rerouting), the data link layer will not support this function.

[0010] EP2460319B1 proposes a solution for implementing safety-critical Ethernet data transmission by using two redundant physical layers. The check of the channel health is done through loopback tests, where multi-level loopbacks are proposed at the MAC (Media Access Control) layer and physical layer levels. The disadvantage of this is that additional loopback data has to be sent and the link cannot operate during the loopback test.

[0011] SE2051061A1 discloses a redundant Ethernet data link, where a relay circuit on the MDI (Media Dependent Interface) of a transceiver is used to directly switch channels to provide a bypass path on the Ethernet physical layer.

[0012] According to EP3407546B1, errors within an Ethernet frame at the physical layer level can be detected by checking the CRC checksum generated by the MAC within the physical layer. However, EP3407546B1 does not define what "specified or specifiable actions" are to be performed in case of CRC check failure. Another method of checking the CRC within an Ethernet frame is disclosed in US6226771B1.

[0013] US8195989B1 proposes detecting faults in an Ethernet communication channel by generating and sending periodic test signals on the link. The disadvantage of this is that during the transmission of the test signals, payload signals cannot be sent through the link and the fault detection time interval is limited by the period of the test signal transmission. US8195989B1 only reports an indication of a link fault and does not address the reaction to it.

[0014] US7127669B2 discloses a redundant data link for packet transmission, where packets are transmitted from a first transceiver to a second transceiver through multiple routes and compared at the second transceiver. This mechanism does not work in the absence of a payload data stream.

[0015] The object of the present invention is to ensure reliable transmission of safety-critical Ethernet packets between two Ethernet devices. The safety-critical Ethernet packets must be rerouted between the two Ethernet devices through a redundant link and the solution must be compatible with existing Ethernet devices.

[0016] This object is solved by an Ethernet device having a safety function at the physical layer, the Ethernet device comprising:

[0017] A first Ethernet physical layer access device, which comprises:

[0018] A first PCS / PMA unit for accessing a first Ethernet channel;

[0019] A first media-independent interface port for Ethernet data communication;

[0020] A second media-independent interface port for Ethernet data communication;

[0021] A first media-independent interface switch that connects the first media-independent interface port to the PCS / PMA unit in a first operating state and connects the first media-independent interface port to a second media interface port in a second operating state;

[0022] A second Ethernet physical layer access device, comprising:

[0023] A second PCS / PMA unit for accessing a second Ethernet channel;

[0024] A third media-independent interface port for Ethernet data communication;

[0025] A fourth media-independent interface port for Ethernet communication;

[0026] A second media-independent interface switch that connects the second PCS / PMA unit to the third media-independent interface port in a first operating state and connects the second PCS / PMA unit to the fourth media-independent interface port in a second operating state;

[0027] wherein the second media-independent interface port of the first Ethernet physical layer access device is connected to the fourth media-independent interface port of the second Ethernet physical layer access device;

[0028] wherein the first Ethernet physical layer access device further includes a first physical layer security mechanism unit for detecting security problems in the physical layer of the first Ethernet channel, such as link loss, link quality degradation, or errors in received Ethernet data packets;

[0029] wherein the first physical layer security mechanism unit is connected to the first media-independent interface switch and the second media-independent interface switch, and when the first physical layer security mechanism unit detects a problem, it preferably switches both the first media-independent interface switch and the second media-independent interface switch from the first operating state to the second operating state simultaneously.

[0030] The Ethernet device according to the present invention includes a first Ethernet physical layer access device and a second Ethernet physical layer access device. The first Ethernet physical layer access device includes a first PCS / PMA (Physical Coding Sublayer / Physical Medium Attachment) unit for accessing a first Ethernet channel, and the second Ethernet physical layer access device includes a second PCS / PMA unit for accessing a second Ethernet channel. Therefore, by using the Ethernet device according to the present invention, data can be transmitted through the first Ethernet channel and the second Ethernet channel.

[0031] The first Ethernet physical layer access device includes a first media-independent interface port for Ethernet data communication, a second media-independent interface port for Ethernet communication, and a first media-independent interface switch. The first media-independent interface switch connects the first media-independent interface port to the PCS / PMA unit of the first Ethernet physical layer access device in the first operating state, and connects the first media-independent interface port to the second media interface port in the second operating state.

[0032] The second Ethernet physical layer access device includes a third media-independent interface port for Ethernet data communication, a fourth media-independent interface port for Ethernet communication, and a second media-independent interface switch. The second media-independent interface switch connects the second PCS / PMA unit of the second Ethernet physical layer access device to the third media-independent interface port in the first operating state, and connects the second PCS / PMA unit of the second Ethernet physical layer access device to the fourth media-independent interface port in the second operating state.

[0033] Therefore, in the first operating state, the first Ethernet data can be transmitted via the first Ethernet channel through the first media-independent interface port, the first media-independent interface switch, and the first PCS / PMA unit. In the first operating state, the second Ethernet data (simultaneously and independently of the first Ethernet data) can be transmitted via the second Ethernet channel through the third media-independent interface port, the second media-independent interface switch, and the second PCS / PMA unit. In this way, the first Ethernet data and the second Ethernet data are independent of each other and are transmitted in parallel on two independent Ethernet channels.

[0034] According to the present invention, the first Ethernet physical layer access device further includes a first physical layer security mechanism unit. The first physical layer security mechanism unit is used to detect security problems in the physical layer of the first Ethernet channel, such as link loss, link quality degradation, or errors in the received Ethernet data packets. The first physical layer security mechanism unit is connected to the first media-independent interface switch and the second media-independent interface switch. When the first physical layer security mechanism unit detects a problem, the first physical layer security mechanism unit switches the first media-independent interface switch and the second media-independent interface switch from the first operating state to the second operating state.

[0035] In this second operating state, the first media-independent interface port is connected to the second media interface port, and the second PCS / PMA unit is connected to the fourth media-independent interface port. Since the second media-independent interface port of the first Ethernet physical layer access device is connected to the fourth media-independent interface port of the second Ethernet physical layer access device, in the second operating state, the first Ethernet data that was previously transmitted via the first Ethernet channel on the first media-independent interface port, the first media-independent interface switch, and the first PCS / PMA unit is transmitted via the second Ethernet channel on the first media-independent interface port, the first media-independent interface switch, the second media-independent interface port, the fourth media-independent interface port, the second media-independent interface switch, and the second PCS / PMA unit in the second operating state. The second Ethernet data transmission stops in the second operating state.

[0036] Therefore, if the first physical layer security mechanism unit detects a security problem in the physical layer of the first Ethernet channel, the traffic that was previously transmitted via the first Ethernet channel will be rerouted via the second Ethernet channel, and the second Ethernet data transmission that was transmitted via the second Ethernet channel in the first operating state will stop transmitting in the second operating state.

[0037] The Ethernet device according to the present invention can detect a security problem in the physical layer of the first Ethernet channel and reroute security-critical Ethernet data via the second Ethernet channel. If other Ethernet devices connected to the first Ethernet channel and the second Ethernet channel are Ethernet devices with security functions at the physical layer according to the present invention, then those other Ethernet devices can also detect the security problem and reroute security-critical Ethernet data via the second Ethernet channel. If other Ethernet devices connected to the first Ethernet channel and the second Ethernet channel are Ethernet devices without security functions at the physical layer, then the rerouting of security-critical Ethernet data can be detected at the application layer, and the security-critical data can be reorganized at the application layer without changing the underlying Ethernet devices.

[0038] According to a variant of the present invention, the second Ethernet physical layer access device further includes a second physical layer security mechanism unit for detecting a security problem in the physical layer of the second Ethernet channel, such as a link loss, a link quality degradation, or an error in the received Ethernet data packet. Therefore, the Ethernet device can detect that there is a security problem in the second Ethernet channel, and thus it can no longer serve as an available backup link for the first Ethernet channel. For example, this information can be forwarded to a device or an application using the Ethernet device according to the present invention, such that the device or the application is aware that a further security problem in the first Ethernet channel will result in a communication loss because there is no available backup Ethernet channel.

[0039] In a variant of the present invention, an Ethernet device having a security function at the physical layer further includes a security controller, wherein when the first physical layer security mechanism unit and / or the second physical layer security mechanism unit detects a security problem in the corresponding first Ethernet channel and / or the second Ethernet channel, it sends a notification to the security controller. The security controller can issue a warning to the system using the Ethernet device, indicating that there is a security problem in the first Ethernet channel and / or the second Ethernet channel. Therefore, the security controller monitors the availability of the first Ethernet channel and the second Ethernet channel and can provide corresponding information to the system and / or application using the Ethernet device with security function at the physical layer.

[0040] According to a variant of the present invention, an Ethernet device having a security function at the physical layer further includes: a first media access controller (MAC) and a second media access controller (MAC). The first media access controller (MAC) is connected to the first media-independent interface port of the first Ethernet physical layer access device, and the second media access controller (MAC) is connected to the third media-independent interface port of the second Ethernet physical layer access device. Such MACs are well-known in the prior art and provide a connection from a higher OSI layer to the OSI physical layer.

[0041] According to an advantageous variant of the present invention, the first physical layer security mechanism unit and / or the second physical layer security mechanism unit includes an input interface for receiving an external security signal. The external security signal preferably relates to a security problem that cannot be directly detected by the first physical layer security mechanism unit and / or the second physical layer security mechanism unit but can affect the security of the first Ethernet channel and / or the second Ethernet channel.

[0042] In a variant of the present invention, the external security signal originates from the hardware of the Ethernet device having a security function at the physical layer. In particular, the external security signal refers to an abnormal power voltage range, an abnormal temperature range, the result of built-in self-check of hardware or software indicating a component failure during operation, or a similar security-critical problem of an external component. For example, an abnormal voltage range can be detected by a voltage sensor, and an abnormal temperature range can be detected by a temperature sensor.

[0043] According to a preferred variant of the present invention, the first physical layer security mechanism unit and / or the second physical layer security mechanism unit detects the loss of the corresponding link, the degradation of the corresponding link quality, or the presence of errors in the received Ethernet packets by monitoring the link state in the following ways:

[0044] - By performing CRC checksum calculation on the Ethernet frames received at the physical layer, evaluating and / or checking the link idle symbols,

[0045] - By using error correction codes, such as the RS encoder / decoder of 1000BASE-T1,

[0046] - By observing link quality metrics (such as SQI or MSI) and reporting cases of link quality degradation,

[0047] - By observing echo canceller weights for detecting cable performance degradation during operation,

[0048] - By running extended cable diagnostics during operation, and / or

[0049] - By fault classification.

[0050] For example, even if no payload data is transmitted through the corresponding Ethernet channel, security issues can be detected by observing link idle symbols.

[0051] According to an advantageous variant of the invention, if the first physical layer security mechanism unit or the second physical layer security mechanism unit respectively detects a security issue with the corresponding Ethernet channel, the first PCS / PMA unit for accessing the first Ethernet channel, and / or the second PCS / PMA unit for accessing the second Ethernet channel, transmits a predetermined pattern on the corresponding Ethernet channel. This predetermined pattern can be recognized by other Ethernet devices using the first Ethernet channel and / or the second Ethernet channel, thereby detecting that there is a security issue with the corresponding first Ethernet channel and / or the second Ethernet channel. If the other Ethernet device is an Ethernet device with security functions at the physical layer according to the invention, then if the other Ethernet device detects the predetermined pattern on the first Ethernet channel, it can directly switch from the first operating state to the second operating state. If the other Ethernet device detects the pattern on the second Ethernet channel, it can notify the device and / or application using the Ethernet device about the security issue with the backup Ethernet channel. This enables faults in the communication channel to be detected within a short time interval.

[0052] In a variant of the present invention, when the first media-independent interface switch and the second media-independent interface switch are in the first operating state, the first Ethernet channel is used for safety-critical data traffic, while the second Ethernet channel is used for non-safety-critical data traffic. When the first media-independent interface switch and the second media-independent interface switch are in the second operating state, the non-safety-critical data traffic on the second Ethernet channel is interrupted and replaced by the safety-critical data traffic of the damaged first Ethernet channel. Therefore, the first Ethernet channel is used for safety-critical data traffic, and as long as there are no safety issues with the first Ethernet channel, the second Ethernet channel serves as a backup for the first Ethernet channel and is used for non-safety-critical Ethernet traffic. In particular, in the second operating state, the non-safety-critical data traffic on the second Ethernet channel is immediately interrupted and replaced by safety-critical data traffic after a certain threshold is reached. Thus, other Ethernet devices on the second Ethernet channel can detect the interruption of the second Ethernet channel and do not expect further data communication. In addition, a clear transition from non-safety-critical data traffic to safety-critical data traffic can be ensured.

[0053] According to a preferred variant of the present invention, the Ethernet device retransmits the data traffic that has not been fully transmitted before the first media-independent interface switch and the second media-independent interface switch switch from the first operating state to the second operating state. This ensures that all Ethernet data traffic, especially safety-critical Ethernet data traffic, is transmitted, and data loss does not occur due to the need to retransmit damaged Ethernet frames caused by safety issues with the Ethernet channel. The retransmission can be initiated by an Ethernet device with a safety function on the physical layer according to the present invention or by the OSI application layer.

[0054] The object of the present invention is further achieved by a method for two-way data transmission between two Ethernet devices, wherein at least one of the two Ethernet devices is an Ethernet device with a safety function on the physical layer according to the present invention, and the method includes the following steps:

[0055] Provide a first Ethernet channel between the two Ethernet devices for two-way safety-critical data transmission;

[0056] Provide a second Ethernet channel between the two Ethernet devices for two-way non-safety-critical data transmission;

[0057] Use an Ethernet device with a safety function on the physical layer to detect safety issues with the physical layer of the first Ethernet channel, such as link loss, degraded link quality, or errors in the received Ethernet data packets;

[0058] If a safety issue is detected with the first Ethernet channel, the Ethernet device with a safety function on the physical layer switches from the first operating state to the second operating state to:

[0059] Interrupt the two-way non-safety-critical data transmission carried out on the second Ethernet channel;

[0060] Reroute the two-way safety-critical data traffic through the second Ethernet channel.

[0061] According to this method, the safety-critical data traffic is transmitted two-way through the first Ethernet channel, while the non-safety-critical data traffic is transmitted through the second Ethernet channel. If an Ethernet device with a security function at the physical layer detects a security problem with the first Ethernet channel, such as a link loss, a degraded link quality, or an error in the received Ethernet packet, the non-safety-critical data traffic through the second Ethernet channel will be interrupted, and the safety-critical data transmission will be rerouted from the first Ethernet channel to the second Ethernet channel. In this way, the second Ethernet channel is a backup for the first Ethernet channel, and when a security problem occurs with the first Ethernet channel, it can be compensated for through the second Ethernet channel. When the first Ethernet channel is operating normally and there are no security problems, the second Ethernet channel can be used for non-safety-critical data traffic.

[0062] The method according to a variant of the present invention includes the following steps: Reorganize the safety-critical data after rerouting through the second Ethernet channel at the physical layer or application of another Ethernet device. Thus, the safety-critical data is transmitted completely without losing any information. If both Ethernet devices for the safety-critical data transmission provide a security function at the physical layer according to the present invention, the safety-critical data can be reorganized at the physical layer. In this case, both Ethernet devices can detect the security problem and automatically reroute the traffic through the second Ethernet channel. If only one Ethernet device provides a security function at the physical layer, the safety-critical data must be reorganized at the application layer for the Ethernet device that does not have a security function at the physical layer, because this Ethernet device cannot detect the security problem and reroute through the second Ethernet channel. However, the application can detect this rerouting by checking the transmitted data and reorganize the safety-critical data accordingly.

[0063] The method according to a variant of the present invention further includes the following steps: Send a predetermined pattern on the corresponding Ethernet channel where a security problem has been detected. This predetermined pattern can be used by another Ethernet device on the first Ethernet channel or the second Ethernet channel to detect the security problem and initiate, for example, rerouting or other measures.

[0064] According to a variant of the present invention, the method comprises the steps of: if a security issue is detected on one of two Ethernet channels, in particular if security issues are detected on both Ethernet channels, sending a notification to the system using the Ethernet device. Thereby, the system using the Ethernet device for the transmission of safety-critical data will receive the following information: there is a security issue with the first Ethernet channel for the transmission of safety-critical data and the transmission of safety-critical data has been rerouted to the second Ethernet channel, or there is a security issue with the second Ethernet channel and it cannot be used as a backup Ethernet channel. In both cases, the reliability of the transmission of safety-critical data is threatened. If there are security issues with both the first Ethernet channel and the second Ethernet channel, a severe warning should be issued to the system using the Ethernet device because there is no reliable channel for the transmission of safety-critical data, and the system can take necessary measures, such as deactivating certain functions (such as autonomous driving).

[0065] The method according to a variant of the present invention comprises the steps of: receiving an external security signal regarding the first Ethernet channel and / or the second Ethernet channel. Preferably, the external security signal refers to an abnormal power supply voltage range, an abnormal temperature range, the result of a built-in self-test of hardware or software indicating a component failure during operation, or a similar safety-critical problem with an external component. Thus, the method takes into account not only the security issues at the physical layer but also external factors that may reduce the security of the Ethernet channel. This enhances the overall reliability and security of the method of the present invention.

[0066] In a variant of the present invention, the transmission of non-safety-critical data on the second Ethernet channel is immediately interrupted in the second operating state and converted to safety-critical data traffic after a certain threshold is reached. Thereby, other Ethernet devices on the second Ethernet channel can detect the interruption of the second Ethernet channel and do not expect further data communication. In addition, it can ensure a clear conversion from non-safety-critical data traffic to safety-critical data traffic.

[0067] The method according to a preferred variant of the present invention further comprises the step of: retransmitting the data traffic that has not been transmitted before switching from the first operating state to the second operating state.

[0068] The present invention will be further described below in conjunction with the embodiments shown in the accompanying drawings. Shown are:

[0069] Figure 1 A schematic diagram of an Ethernet device with a security function at the physical layer according to the present invention.

[0070] Figure 2 A schematic diagram of an Ethernet connection between two Ethernet devices with a security function at the physical layer according to the present invention, and

[0071] Figure 3 Schematic diagram of an Ethernet connection between an Ethernet device with security functions at the physical layer and an Ethernet device without security functions at the physical layer according to the present invention.

[0072] Figure 1 Schematic diagram showing Ethernet devices 100 and 200 with security functions at the physical layer according to the present invention. The Ethernet devices 100 and 200 include first Ethernet physical layer access devices 110 and 210 and second Ethernet physical layer access devices 130 and 230.

[0073] The first Ethernet physical access devices 110 and 210 include: first PCS / PMA units 111 and 211 for accessing a first Ethernet channel 120; first media-independent interface ports 112 and 212 for Ethernet data communication; second media-independent interface ports 113 and 213 for Ethernet data communication; and first media-independent interface switches 114 and 214 that connect the first media-independent interface ports 112 and 212 to the PCS / PMA units 111 and 211 in a first operating state and connect the first media-independent interface ports 112 and 212 to the second media interface ports 113 and 213 in a second operating state.

[0074] The second Ethernet physical layer access devices 130 and 230 include: second PCS / PMA units 131 and 231 for accessing a second Ethernet channel 140; third media-independent interface ports 132 and 232 for Ethernet data communication; fourth media-independent interface ports 133 and 233 for Ethernet communication; and second media-independent interface switches 134 and 234 that connect the second PCS / PMA units 131 and 231 to the third media-independent interface ports 132 and 232 in a first operating state and connect the second PCS / PMA units 131 and 231 to the fourth media-independent interface ports 133 and 233 in a second operating state.

[0075] The second media-independent interface ports 113 and 213 of the first Ethernet physical layer access devices 110 and 210 are connected to the fourth media-independent interface ports 133 and 233 of the second Ethernet physical layer access devices 130 and 230.

[0076] The first Ethernet physical layer access devices 110, 210 further include first physical layer security mechanism units 115, 215. The first physical layer security mechanism units 115, 215 are used to detect security problems in the physical layer of the first Ethernet channel 120, such as link loss, link quality degradation, or errors in the received Ethernet data packets. The first physical layer security mechanism units 115, 215 are connected to the first medium-independent interface switches 114, 214 and the second medium-independent interface switches 134, 234. When the first physical layer security mechanism units 115, 215 detect a problem, the first physical layer security mechanism units 115, 215 switch the first medium-independent interface switches 114, 214 and the second medium-independent interface switches 134, 234 from the first operating state to the second operating state.

[0077] The second Ethernet physical layer access devices 130, 230 further include second physical layer security mechanism units 135, 235. The second physical layer security mechanism units 115, 215 are used to detect security problems in the physical layer of the second Ethernet channel 140, such as link loss, link quality degradation, or errors in the received Ethernet data packets.

[0078] Figure 1 The Ethernet devices 100, 200 with security functions at the physical layer as shown further include security controllers 150, 250. Among them, when the first physical layer security mechanism units 115, 215 and the second physical layer security mechanism units 135, 235 detect security problems in the corresponding first Ethernet channel 120 or second Ethernet channel 140, they send notifications to the security controllers 150, 250. The security controllers 150, 250 can issue warnings to the systems 160, 170, 260, 270 using the Ethernet devices 100, 200, prompting that there are security problems in the first Ethernet channel 120 and / or the second Ethernet channel 140.

[0079] The first Ethernet physical layer access devices 110, 210 further include first media access controllers 116, 216. The first media access controllers 116, 216 are connected to the first medium-independent interface ports 112, 212; the second media access controllers 130, 230 include second media access controllers 136, 236. The second media access controllers 136, 236 are connected to the third medium-independent interface ports 132, 232. The first media access controllers 116, 226 and the second media access controllers 136, 236 are used by the systems 160, 170, for example, to access the physical layer to implement Ethernet communication.

[0080] According to Figure 1In the illustrated embodiments, the first physical layer security mechanism units 115, 215 and the second physical layer security mechanism units 135, 235 include input interfaces 117, 217, 137, 237 for receiving external security signals. The external security signals originate, for example, from the hardware of Ethernet devices 100, 200 having security functions at the physical layer, such as systems 160, 170. The external security signals refer to, for example, an abnormal power voltage range, an abnormal temperature range, the result of a built-in self-test of the hardware or software indicating a component failure during operation, or a similar security-critical problem with an external component.

[0081] The first physical layer security mechanism units 115, 215 and / or the second physical layer security mechanism units 135, 235 detect a loss of a corresponding link, a degradation of a corresponding link quality, or an error in a received Ethernet packet by monitoring the link state by evaluating and / or examining link idle symbols and by the following means:

[0082] - By performing CRC checksum calculation on the received Ethernet frames at the physical layer,

[0083] - By error correction codes, such as the RS encoder / decoder for 1000BASE-T1,

[0084] - By observing link quality metrics (such as SQI or MSI) and reporting a degradation of the link quality,

[0085] - By observing echo canceller weights for detecting a degradation of cable performance during operation,

[0086] - By extended cable diagnostics during operation, and / or

[0087] - By fault classification.

[0088] In a preferred embodiment, if the first physical layer security mechanism units 115, 215 or the second physical layer security mechanism units 135, 235 respectively detect a security problem with the corresponding Ethernet channels 120, 140, the first PCS / PMA units 111, 211 for accessing the first Ethernet channel 120 and / or the second PCS / PMA units 131, 231 for accessing the second Ethernet channel 140 send a predetermined pattern on the corresponding Ethernet channels 120, 140.

[0089] When the first media-independent interface switches 114, 214 and the second media-independent interface switches 134, 234 are in the first operating state, the first Ethernet channel 120 is used for safety-critical data traffic, and the second Ethernet channel 140 is used for non-safety-critical data traffic. And when the first media-independent interface switches 114, 214 and the second media-independent interface switches 134, 234 are in the second operating state, the non-safety-critical data traffic on the second Ethernet channel 140 is interrupted and replaced by the safety-critical data traffic of the damaged first Ethernet channel 120. Preferably, in the second operating state, the non-safety-critical data traffic on the second Ethernet channel 140 is immediately interrupted and replaced by the safety-critical data traffic after a certain threshold is reached.

[0090] In one embodiment of the present invention, the Ethernet devices 100, 200 retransmit the data traffic that has not been fully transmitted before the first media-independent interface switches 114, 214 and the second media-independent interface switches 134, 234 switch from the first operating state to the second operating state.

[0091] Reference Figure 2 Explain in more detail Figure 1 The use of the Ethernet devices 100, 200 having security functions at the physical layer as shown, Figure 2 FIG. shows a schematic diagram of an Ethernet connection between two Ethernet devices 100, 200 having security functions at the physical layer according to the present invention. The first Ethernet device 100 having security functions at the physical layer and the second Ethernet device 200 having security functions at the physical layer are both connected to Figure 1 the Ethernet device 100 as shown. Therefore, for the details of the first Ethernet device and the second Ethernet devices 100, 200 having security functions at the physical layer, please refer to the above content. The corresponding parts of the first and second Ethernet devices 100, 200 have corresponding reference numerals, only the first digit is different, representing the first Ethernet device 100 and the second Ethernet device 200 respectively.

[0092] According to Figure 2 , a first Ethernet channel 120 and a second Ethernet channel 200 are provided between two Ethernet devices 100, 200 having security functions at the physical layer according to the present invention. The first Ethernet channel 120 is accessed by the corresponding first Ethernet physical access devices 110, 210, while the second Ethernet channel 140 is accessed by the corresponding second Ethernet physical access devices 130, 230.

[0093] The first Ethernet channel 120 is used for two-way safety-critical data transmission, and the second Ethernet channel 140 is used for two-way non-safety-critical data transmission.

[0094] If the first Ethernet device and / or the second Ethernet devices 100, 200 detect a security problem in the physical layer of the first Ethernet channel 120, the first Ethernet device 100 and the second Ethernet device 200 switch from the first operating state to the second operating state. In the second operating state, the two-way non-security-critical data transmission on the second Ethernet channel 140 is interrupted, and the two-way security-critical data traffic is rerouted on the second Ethernet channel 140.

[0095] In particular, the non-security-critical data transmission on the second Ethernet channel 140 is immediately interrupted in the second operating state and replaced by the security-critical data traffic after a certain threshold is reached.

[0096] After the security-critical data is rerouted through the second Ethernet channel 140, it is reassembled at the physical layer of the corresponding Ethernet devices 100, 200 that have security functions at the physical layer. In a variant of the present invention, the data traffic that has not been transmitted before switching from the first operating state to the second operating state is retransmitted to avoid any data loss.

[0097] If one of the Ethernet devices 100, 200 detects a security problem on the first and / or second Ethernet channels 120, 140, a predetermined pattern is sent on the corresponding Ethernet channel 120, 140. This pattern can be recognized by other Ethernet devices 120, 140, so that the security problem on the corresponding Ethernet channel 120, 140 can also be detected. In many cases, one of the two Ethernet devices 100, 200 detects the security problem earlier, and the detected security problem can be notified to the other Ethernet device using the predetermined pattern.

[0098] If a security problem is detected in the first Ethernet channel 120 and / or the second Ethernet channel, a corresponding notification is sent to the systems 160, 260 that use the Ethernet devices 100, 200 for security-critical data transmission. A corresponding notification can also be sent to the systems 170, 270 that use the Ethernet devices 100, 200 for non-security-critical data transmission.

[0099] The Ethernet devices 100, 200 can also receive external security signals regarding the first Ethernet channel 120 and / or the second Ethernet channel 140 via the corresponding input interfaces 117, 137, 217, 237. The external security signals originate, for example, from the hardware of the Ethernet devices 100, 200 that have security functions at the physical layer, such as the systems 160, 170, 260, 270. The external security signals refer to, for example, an abnormal power voltage range, an abnormal temperature range, the result of a built-in self-test of the hardware or software indicating a failure of a component during operation, or a similar security-critical problem of an external component.

[0100] Figure 3 FIG. 1 shows a schematic diagram of an Ethernet connection between Ethernet devices 100, 200 having security functions at the physical layer and an Ethernet device 300 not having security functions at the physical layer according to the present invention.

[0101] The Ethernet devices 100, 200 having security functions at the physical layer correspond to Figure 1 the devices shown. For more details, please refer to the Figure 1 description above.

[0102] The Ethernet device 300 not having security functions at the physical layer includes a first Ethernet physical layer access device 310 and a second Ethernet physical layer access device 330. The first and second Ethernet physical layer access devices 310, 330 each include a PCS / PMA unit 311, 331, a media independent interface port 312, 332, and a media access controller 316, 336. Ethernet data traffic is routed through the corresponding PCS / PMA units 311, 331, media independent interface ports 312, 332, and media access controllers 316, 336 to systems 260, 2270 using the Ethernet device 300. Since the Ethernet device 300 does not provide security functions at the physical layer, the rerouting of security-critical data traffic performed by the Ethernet devices 100, 200 having security functions at the physical layer in the second operating state cannot be detected by the Ethernet device 300 not having security functions at the physical layer. However, at the application layer, the rerouting can be detected by performing data inspection on the transmitted data. Therefore, the Ethernet devices 100, 200 having security functions at the physical layer can work in cooperation with the Ethernet device 300 not having security functions at the physical layer. By implementing data inspection only at the application layer, the benefits of the physical layer security functions of another Ethernet device 100, 200 can be obtained without any changes to the underlying hardware.

[0103] Ethernet device having security functions at the physical layer and method for bidirectional data transmission between two Ethernet devices

[0104] List of reference numerals

[0105] 100 Ethernet device having security functions at the physical layer

[0106] 110 First Ethernet physical layer access device

[0107] 111 First PCS / PMA

[0108] 112 First media independent interface port

[0109] 113 Second media independent interface port

[0110] 114 First Media Independent Interface Switch

[0111] 115 Security Mechanism Unit (First Ethernet Physical Layer Access Device)

[0112] 116 Media Access Controller (First Ethernet Physical Layer Access Device)

[0113] 117 Input Interface (First Ethernet Physical Layer Access Device)

[0114] 120 First Ethernet Channel

[0115] 130 Second Ethernet Physical Layer Access Device

[0116] 131 Second PCS / PMA

[0117] 132 Third Media Independent Interface Port

[0118] 133 Fourth Media Independent Interface Port

[0119] 134 Second Media Independent Interface Switch

[0120] 135 Security Mechanism Unit (Second Ethernet Physical Layer Access Device)

[0121] 136 Media Access Controller (Second Ethernet Physical Layer Access Device)

[0122] 137 Input Interface (Second Ethernet Physical Layer Access Device)

[0123] 140 Second Ethernet Channel

[0124] 150 Ethernet Channel

[0125] 160 System Using Ethernet Devices

[0126] 170 System Using Ethernet Devices

[0127] 200 Ethernet Device with Security Function at Physical Layer

[0128] 210 First Ethernet Physical Layer Access Device

[0129] 211 First PCS / PMA

[0130] 212 First Media Independent Interface Port

[0131] 213 Second Media Independent Interface Port

[0132] 214 First Media Independent Interface Switch

[0133] 215 Security mechanism unit (first Ethernet physical layer access device)

[0134] 216 Media access controller (first Ethernet physical layer access device)

[0135] 217 Input interface (first Ethernet physical layer access device)

[0136] 230 Second Ethernet physical layer access device

[0137] 231 Second PCS / PMA

[0138] 232 Third media-independent interface port

[0139] 233 Fourth media-independent interface port

[0140] 234 Second media-independent interface switch

[0141] 235 Security mechanism unit (second Ethernet physical layer access device)

[0142] 236 Media access controller (second Ethernet physical layer access device)

[0143] 237 Input interface (second Ethernet physical layer access device)

[0144] 250 Ethernet channel

[0145] 260 System using Ethernet devices

[0146] 270 System using Ethernet devices

[0147] 300 Ethernet device without security function at the physical layer

[0148] 310 First Ethernet physical layer access device

[0149] 311 First PCS / PMA

[0150] 312 First media-independent interface port

[0151] 316 Media access controller (first Ethernet physical layer access device)

[0152] 330 Second Ethernet physical layer access device

[0153] 331 Second PCS / PMA

[0154] 332 Second media-independent interface port

[0155] 336 Media access controller (second Ethernet physical layer access device)

[0156] 380 Application Layer

Claims

1. An Ethernet device (100, 200) with security functions at the physical layer, which comprises: A first Ethernet physical layer access device (110, 210), which includes: A first PCS / PMA unit (111, 211) for accessing a first Ethernet channel (120); A first media-independent interface port (112, 212) for Ethernet data communication; A second media-independent interface port (113, 213) for Ethernet data communication; A first media-independent interface switch (114, 214) that connects the first media-independent interface port (112, 212) to the PCS / PMA unit (111, 211) in a first operating state and connects the first media-independent interface port (112, 212) to the second media interface port (113, 213) in a second operating state; A second Ethernet physical layer access device (130, 230), which includes: A second PCS / PMA unit (131, 231) for accessing a second Ethernet channel (140); A third media-independent interface port (132, 232) for Ethernet data communication; A fourth media-independent interface port (133, 233) for Ethernet communication; and A second media-independent interface switch (134, 234) that connects the second PCS / PMA unit (131, 231) to the third media-independent interface port (132, 232) in a first operating state and connects the second PCS / PMA unit (131, 231) to the fourth media-independent interface port (133, 233) in a second operating state; wherein the second media-independent interface port (113, 213) of the first Ethernet physical layer access device (110, 210) is connected to the fourth media-independent interface port (133, 233) of the second Ethernet physical layer access device (130, 230); wherein the first Ethernet physical layer access device (110, 210) further includes a first physical layer security mechanism unit (115, 215), and the first physical layer security mechanism unit (115, 215) is used to detect security problems at the physical layer of the first Ethernet channel (120), such as link loss, link quality degradation, or errors in received Ethernet data packets; wherein the first physical layer security mechanism unit (115, 215) is connected to the first media-independent interface switch (114, 214) and the second media-independent interface switch (134, 234), and when the first physical layer security mechanism unit (115, 215) detects a problem, the first physical layer security mechanism unit (115, 215) switches the first media-independent interface switch (114, 214) and the second media-independent interface switch (134, 234) from the first operating state to the second operating state.

2. The Ethernet device (100, 200) with security functions at the physical layer according to claim 1, wherein the second Ethernet physical layer access device (130, 230) further includes a second physical layer security mechanism unit (135, 235), and the second physical layer security mechanism unit (115, 215) is used to detect security problems in the physical layer of the second Ethernet channel (140), such as link loss, link quality degradation, or errors in the received Ethernet data packets.

3. The Ethernet device (100, 200) with security functions at the physical layer according to claim 1 or 2, further includes a security controller (150, 250), wherein, when the first physical layer security mechanism unit (115, 215) and / or the second physical layer security mechanism unit (135, 235) detect security problems in the corresponding first Ethernet channel (120) and / or the second Ethernet channel (140), they send notifications to the security controller (150, 250), and the security controller (150, 250) can issue a warning to the system (160, 170, 260, 270) using the Ethernet device (100, 200), prompting that there are security problems in the first Ethernet channel (120) and / or the second Ethernet channel (140).

4. The Ethernet device (100, 200) with security functions at the physical layer according to any one of claims 1 to 3, further includes a first media access controller (116, 216) and a second media access controller (136, 236), the first media access controller (116, 216) is connected to the first media-independent interface port (112, 212) of the first Ethernet physical layer access device (110, 210), and the second media access controller (136, 236) is connected to the third media-independent interface port (132, 232) of the second Ethernet physical layer access device (130, 230).

5. The Ethernet device (100, 200) with security functions at the physical layer according to any one of claims 1 to 4, wherein the first physical layer security mechanism unit (115, 215) and / or the second physical layer security mechanism unit (135, 235) includes an input interface (117, 217, 137, 237) for receiving external security signals.

6. The Ethernet device (100, 200) with security functions at the physical layer according to claim 5, wherein the external security signal originates from the hardware of the Ethernet device (100, 200) with security performance at the physical layer.

7. The Ethernet device (100, 200) with security functions at the physical layer according to claim 5 or 6, wherein the external security signal refers to an abnormal power supply voltage range, an abnormal temperature range, the built-in self-test results of hardware or software indicating component failures during operation, or similar security-critical problems of external components.

8. An Ethernet device (100, 200) having a security function at the physical layer according to any one of claims 1 to 7, wherein the first physical layer security mechanism unit (115, 215) and / or the second physical layer security mechanism unit (135, 235) detect the loss of the corresponding link, the degradation of the link quality, or the presence of errors in the received Ethernet packets through link state monitoring by the following means: by evaluating and / or checking link idle symbols; by performing CRC checksum calculation on the Ethernet frames received in the physical layer; by error correction codes such as RS encoder / decoder of 1000BASE-T1; by observing link quality metrics such as SQI or MSI and reporting the degradation of the link quality; by observing the echo canceller weights to detect the degradation of the cable performance during operation; by expanding cable diagnostics during operation; and / or by fault classification.

9. An Ethernet device (100, 200) having a security function at the physical layer according to any one of claims 1 to 8, if the first physical layer security mechanism unit (115, 215) or the second physical layer security mechanism unit (135, 235) respectively detects a security problem in the corresponding Ethernet channel (120, 140), the first PCS / PMA unit (111, 211) for accessing the first Ethernet channel (120) and / or the second PCS / PMA unit (131, 231) for accessing the second Ethernet channel (140) send a predetermined pattern on the corresponding Ethernet channel (120, 140).

10. An Ethernet device (100, 200) having a security function at the physical layer according to any one of claims 1 to 9, wherein when the first media-independent interface switch (114, 214) and the second media-independent interface switch (134, 234) are in the first operating state, the first Ethernet channel (120) is used for security-critical data traffic, the second Ethernet channel (140) is used for non-security-critical data traffic, and when the first media-independent interface switch (114, 214) and the second media-independent interface switch (134, 234) are in the second operating state, the non-security-critical data traffic on the second Ethernet channel (140) is interrupted and replaced by the security-critical data traffic of the damaged first Ethernet channel (120).

11. An Ethernet device (100, 200) having a security function at the physical layer according to claim 10, wherein the non-security-critical data traffic on the second Ethernet channel (140) is immediately interrupted in the second operating state and replaced by the security-critical data traffic after reaching a certain threshold.

12. An Ethernet device (100, 200) having a security function at the physical layer according to claim 10 or 11, wherein the Ethernet devices (100, 200) re - transmit data traffic that has not been fully transmitted before the first media - independent interface switch (114, 214) and the second media - independent interface switch (134, 234) switch from the first operating state to the second operating state.

13. A method for two - way data transmission between two Ethernet devices (100, 200), wherein at least one of the two Ethernet devices (100, 200) is an Ethernet device (100, 200) having a security function at the physical layer according to any one of claims 1 to 12, the method comprises the following steps: providing a first Ethernet channel (120) between the two Ethernet devices (100, 200) for two - way safety - critical data transmission; providing a second Ethernet channel (140) between the two Ethernet devices (100, 200) for two - way non - safety - critical data transmission; using an Ethernet device (100, 200) having a security function at the physical layer to detect security problems in the physical layer of the first Ethernet channel (120), such as link loss, link quality degradation, or errors in received Ethernet packets; if a security problem is detected in the first Ethernet channel (120), the Ethernet device (100, 200) having a security function at the physical layer switches from the first operating state to the second operating state to: interrupt the two - way non - safety - critical data transmission on the second Ethernet channel (140); re - route the two - way safety - critical data traffic through the second Ethernet channel (140).

14. The method for two - way data transmission between two Ethernet devices (100, 200) according to claim 13, comprises the following steps: re - organizing the safety - critical data after re - routing through the second Ethernet channel (140) at the physical layer or application layer of another Ethernet device (100, 200).

15. The method for two - way data transmission between two Ethernet devices (100, 200) according to claim 13 or 14, comprises the following steps: sending a predetermined pattern on the corresponding Ethernet channel (120, 140) where a security problem has been detected.

16. The method for two - way data transmission between two Ethernet devices (100, 200) according to any one of claims 13 to 15, comprises the following steps: if a security problem is detected on one of the two Ethernet channels (120, 140), especially if security problems are detected on both of the two Ethernet channels (120, 140), sending a notification to the system (160, 260) using the Ethernet devices (100, 200).

17. The method for two - way data transmission between two Ethernet devices (100, 200) according to any one of claims 13 to 16, comprises the following steps: receiving an external security signal regarding the first Ethernet channel (120) and / or the second Ethernet channel (140).

18. A method for two-way data transmission between two Ethernet devices (100, 200) according to claim 17, wherein the external security signal originates from the hardware of Ethernet devices (100, 200) having security performance at the physical layer.

19. A method for two-way data transmission between two Ethernet devices (100, 200) according to claim 17 or 18, wherein the external security signal refers to an abnormal power supply voltage range, an abnormal temperature range, a failure of a component during operation indicated by the built-in self-test result of hardware or software, or a similar safety-critical problem of an external component.

20. A method for two-way data transmission between two Ethernet devices (100, 200) according to any one of claims 13 to 19, wherein in the second operating state, the second Ethernet channel (140) is immediately interrupted and replaced by safety-critical data traffic after a certain threshold.

21. A method for two-way data transmission between two Ethernet devices (100, 200) according to any one of claims 13 to 20, comprising the following steps: Retransmitting data traffic that has not been transmitted before switching from the first operating state to the second operating state.

Citation Information

Patent Citations

  • Network device for a computer network and method for transmitting data with a network device

    EP3407546A1

  • Ethernet network node

    SE2051061A1

  • Method and apparatus for generating error detection data for encapsulated frames

    US6226771B1

  • Redundant path communication methods and systems

    US7127669B2

  • Detection of ethernet link failure

    US8195989B1