Ethernet device with security function in physical layer and method for bidirectional data transmission between two ethernet devices
By using Ethernet devices with security features at the physical layer to transmit data in parallel through dual Ethernet channels and automatically switch to the backup channel, the problem of untimely detection and response to Ethernet communication link failures in existing technologies is solved, and reliable transmission of security-critical data is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-16
- Publication Date
- 2026-04-07
AI Technical Summary
Existing technologies cannot effectively detect and quickly respond to Ethernet communication link failures in automotive safety-critical applications, resulting in incomplete and unreliable data transmission, especially in failure modes such as loss of communication peers or message corruption, where it is impossible to switch to a safe state in a short time.
An Ethernet device with physical layer security features is employed to transmit data in parallel through dual Ethernet channels. It automatically switches to a backup channel upon detecting a link problem, ensuring reliable transmission of security-critical data. The device includes first and second Ethernet physical layer access devices, connected via a PCS/PMA unit and a media-independent interface switch, respectively, and is equipped with a physical layer security mechanism to detect link problems and switch channels.
It enables rapid switching to a safe state within the fault detection time interval, ensuring the reliability of data communication in safety-critical communication links, avoiding data loss and delay, and is suitable for applications such as drive-by-wire and brake-by-wire.
Smart Images

Figure CN120092412B_ABST
Abstract
Description
[0001] The present invention relates to an Ethernet device with security functions at the physical layer. The present invention further relates to a method for bidirectional data transmission between two Ethernet devices, wherein at least one of the two Ethernet devices is an Ethernet device with security functions at the physical layer according to the present invention.
[0002] The present invention relates to the field of motor vehicle Ethernet connectivity technology, for example as defined in IEEE Std. 802.3™-2018 (IEEE Ethernet Standard). In particular, the present invention relates to a reliable communication link for automotive safety-critical applications. In such applications, failure modes of data transmission have to be prevented, for example loss of communication peer, message corruption, unacceptable delay of messages, loss of messages, unexpected message duplication, incorrect message sequencing, message insertion, message spoofing, incorrect message addressing or similar failures (see, for example, ISO 26262-5:2018, Annex D.1).
[0003] The failure has to be detected within a short failure detection time interval (FDTI) and has to be handled within a short failure handling time interval (FHTI) in order to bring the system into a safe state. The safe state is the desired safe operation, i.e. the data communication of the safety-critical communication link can still take place in case of a failure. This is very important for applications like drive-by-wire or brake-by-wire.
[0004] It is known from the prior art that an end-to-end protection of Ethernet data transmission can be provided on the OSI (Open Systems Interconnection model) application layer. For example, the AUTOSAR E2E protocol specification discloses that a checksum generated by the application layer is appended to the payload data before the payload data is transmitted in order to implement an end-to-end data protection of the data transmission from one node to another node. The receiving application receives the payload data including the checksum and checks the data integrity before using the data by calculating a checksum of the received payload data and comparing this calculated checksum with the received checksum appended to the payload data. The advantage of this approach is that the complete data communication link between the two applications can be covered. For example, if a data packet is corrupted within an ECU (Electronic Control Unit) or even within one processor due to a lack of failure mechanisms like ECC (Error Correcting Code) memory, the application can check the integrity of each data packet. The disadvantage of this approach is that the application can only detect the integrity problem but not the reason for the integrity problem. Furthermore, the integrity problem can only be detected when the receiving node receives the data, while the sender has no information at all. For event-based messages, a safety mechanism is not possible at all, because the application cannot predict when a message will be received.
[0005] In addition, random failures can occur. The application cannot switch to a degraded mode after one or two corrupted data packets, because this can be a random failure. For CAN (Controller Area Network) based communication, it is common to enter any degraded mode only after accepting up to 10 corrupted data packets. For messages received periodically with a period time of 50 ms, the degraded mode can be started at the earliest after 500 ms, which can cause problems for safety-critical communication links.
[0006] It is also known from the prior art to provide data protection for Ethernet data transmission on the OSI transport layer. In this case, a distinction must be made between connection-oriented and connectionless transport protocols, since they have different data integrity capabilities.
[0007] Connection-oriented transport protocols, such as TCP, are not usually used for safety-relevant communication, even though they offer some interesting reliability features, such as message acknowledgement and message retransmission. For real-time protocols, the transport protocol has some disadvantages that also lead to uncertain reliability. Establishing a connection is a complex process that involves many states. The state machine that handles the connection must be completely defined and there must be no deadlocks or livelocks on either side. Message acknowledgement and message retransmission can lead to undefined bus load situations and even to a complete bus congestion. Critical information always requires an open connection. Either the connection must always be kept open, but this creates unnecessary overhead and traffic, or the connection must be established before the message is sent, but this is very dangerous. In addition, connection-oriented transport protocols usually only support point-to-point connections. The protocol complexity for unicast or broadcast scenarios is very high, so implementations are not very common.
[0008] Connectionless transport protocols, such as UDP, are not as complete in terms of data reliability features, but are easier to handle and support multicast and broadcast, which is very interesting for state-of-the-art applications, for example using a proxy-less publish / subscribe architecture (e.g. OMG DDS). The main reliability feature that can be implemented with connectionless transport protocols is another data checksum above the OSI data link layer.
[0009] It is also known from the prior art to provide data protection for Ethernet data transmission on the OSI data link layer. The main function of the data link layer is to compose a stream of symbols into data packets and to check their integrity. Therefore, data packets are usually extended by a CRC (Cyclic Redundancy Check) at the sending end and checked for data integrity by a CRC at the receiving end. The CRC is a powerful feature for data integrity. However, the check can only be performed if the data is received at the receiving end. If the sender needs to know about failures at the receiving end (for example, in order to perform data rerouting), the data link layer does not support this feature.
[0010] EP2460319B1 proposes a solution for secure critical Ethernet data transmission by using two redundant physical layers. The check of the channel health status is done by loopback tests, where a multistage loopback is proposed at MAC (Media Access Control) layer and physical layer level. Disadvantages are that additional loopback data has to be transmitted and the link cannot be operated during loopback tests.
[0011] SE2051061A1 discloses a redundant Ethernet data link, where a relay circuit on the MDI (Media Dependent Interface) of the transceiver is used to directly switch the channel to provide a bypass path on the Ethernet physical layer.
[0012] According to EP3407546B1, errors within an Ethernet frame at physical layer level can be detected by checking the MAC generated CRC checksum within the physical layer. However, EP3407546B1 does not define what “specified or specifiable action” is to be performed in case of a CRC check failure. Another method of checking the CRC within an Ethernet frame is disclosed in US6226771B1.
[0013] US8195989B1 proposes to detect a failure of an Ethernet communication channel by generating and transmitting a periodic test signal on the link. Disadvantages are that no payload signal can be transmitted through the link during test signal transmission and that the failure detection time interval is limited to the period of test signal transmission. US8195989B1 only reports an indication of a link failure without addressing a reaction to it.
[0014] US7127669B2 discloses a redundant data link for packet transmission, where packets are transmitted from a first transceiver to a second transceiver by multiple routes and compared at the second transceiver. This mechanism does not work without a payload data stream.
[0015] It is an object of the present invention to ensure a reliable transmission of secure critical Ethernet packets between two Ethernet devices. Secure critical Ethernet packets have to be rerouted between two Ethernet devices by a redundant link and the solution has to be compatible with prior art Ethernet devices.
[0016] This object is solved by an Ethernet device with security functions at physical layer level, comprising:
[0017] a first Ethernet physical layer access device, comprising:
[0018] a first PCS / PMA unit for accessing a first Ethernet channel;
[0019] a first media independent interface port for Ethernet data communication;
[0020] The second medium-independent interface port is used for Ethernet data communication;
[0021] A first media-independent interface switch connects a first media-independent interface port to a PCS / PMA unit in a first operating state and connects the first media-independent interface port to a second media interface port in a second operating state.
[0022] The second Ethernet physical layer access device includes:
[0023] The second PCS / PMA unit is used to access the second Ethernet channel;
[0024] The third media-independent interface port is used for Ethernet data communication;
[0025] The fourth media-independent interface port is used for Ethernet communication;
[0026] The second media-independent interface switch connects the second PCS / PMA unit to the third media-independent interface port in the first operating state and connects the second PCS / PMA unit to the fourth media-independent interface port in the second operating state.
[0027] The second media-independent interface port of the first Ethernet physical layer access device is connected to the fourth media-independent interface port of the second Ethernet physical layer access device.
[0028] The first Ethernet physical layer access device also includes a first physical layer security mechanism unit, which is used to detect physical layer security problems of the first Ethernet channel, such as link loss, link quality degradation, or errors in the received Ethernet data packets.
[0029] The first physical layer security mechanism unit is connected to the first media-independent interface switch and the second media-independent interface switch. When the first physical layer security mechanism unit detects a problem, it preferably switches the first media-independent interface switch and the second media-independent interface switch from the first operating state to the second operating state at the same time.
[0030] The Ethernet device according to the present invention includes a first Ethernet physical layer access device and a second Ethernet physical layer access device. The first Ethernet physical layer access device includes a first PCS / PMA (Physical Coding Sublayer / Physical Medium Accessories) unit for accessing a first Ethernet channel, and the second Ethernet physical layer access device includes a second PCS / PMA unit for accessing a second Ethernet channel. Therefore, using the Ethernet device according to the present invention, data can be transmitted through the first Ethernet channel and the second Ethernet channel.
[0031] The first Ethernet physical layer access device includes a first medium-independent interface port for Ethernet data communication, a second medium-independent interface port for Ethernet communication, and a first medium-independent interface switch. In a first operating state, the first medium-independent interface switch connects the first medium-independent interface port to the PCS / PMA unit of the first Ethernet physical layer access device, and in a second operating state, connects the first medium-independent interface port to the second medium interface port.
[0032] The second Ethernet physical layer access device includes a third medium-independent interface port for Ethernet data communication, a fourth medium-independent interface port for Ethernet communication, and a second medium-independent interface switch. In a first operating state, the second medium-independent interface switch connects the second PCS / PMA unit of the second Ethernet physical layer access device to the third medium-independent interface port, and in a second operating state, connects the second PCS / PMA unit of the second Ethernet physical layer access device to the fourth medium-independent interface port.
[0033] Therefore, in the first operating state, the first Ethernet data can be transmitted via the first Ethernet channel through the first media-independent interface port, the first media-independent interface switch, and the first PCS / PMA unit. In the first operating state, the second Ethernet data (simultaneously and independently of the first Ethernet data) can be transmitted via the second Ethernet channel through the third media-independent interface port, the second media-independent interface switch, and the second PCS / PMA unit. In this way, the first Ethernet data and the second Ethernet data are independent of each other and are transmitted in parallel on two independent Ethernet channels.
[0034] According to the present invention, the first Ethernet physical layer access device further includes a first physical layer security mechanism unit, which is used to detect physical layer security problems of the first Ethernet channel, such as link loss, link quality degradation, or errors in received Ethernet packets. The first physical layer security mechanism unit is connected to a first media-independent interface switch and a second media-independent interface switch. When the first physical layer security mechanism unit detects a problem, it switches the first media-independent interface switch and the second media-independent interface switch from a first operating state to a second operating state.
[0035] In this second operating state, the first media-independent interface port is connected to the second media-independent interface port, and the second PCS / PMA unit is connected to the fourth media-independent interface port. Since the second media-independent interface port of the first Ethernet physical layer access device is connected to the fourth media-independent interface port of the second Ethernet physical layer access device, in the second operating state, the first Ethernet data previously transmitted via the first Ethernet channel on the first media-independent interface port, the first media-independent interface switch, and the first PCS / PMA unit is transmitted via the second Ethernet channel on the first media-independent interface port, the first media-independent interface switch, the second media-independent interface port, the fourth media-independent interface port, the second media-independent interface switch, and the second PCS / PMA unit. Second Ethernet data transmission ceases in the second operating state.
[0036] Therefore, if the first physical layer security mechanism unit detects a physical layer security problem in the first Ethernet channel, the traffic previously transmitted through the first Ethernet channel will be rerouted through the second Ethernet channel, and the second Ethernet data transmission transmitted through the second Ethernet channel in the first operating state will stop in the second operating state.
[0037] The Ethernet device according to the present invention can detect security issues at the physical layer of the first Ethernet channel and reroute security-critical Ethernet data through the second Ethernet channel. If other Ethernet devices connected to the first and second Ethernet channels are Ethernet devices with security functions at the physical layer according to the present invention, they can also detect security issues and reroute security-critical Ethernet data through the second Ethernet channel. If other Ethernet devices connected to the first and second Ethernet channels are Ethernet devices without security functions at the physical layer, the rerouting of security-critical Ethernet data can be detected at the application layer, and the security-critical data can be reassembled at the application layer without changing the underlying Ethernet devices.
[0038] According to a variation of the invention, the second Ethernet physical layer access device further includes a second physical layer security mechanism unit, which is used to detect physical layer security issues in the second Ethernet channel, such as link loss, link quality degradation, or errors in received Ethernet packets. Therefore, the Ethernet device can detect security issues in the second Ethernet channel and thus cease to serve as a usable backup link for the first Ethernet channel. For example, this information can be forwarded to a device or application using the Ethernet device according to the invention, making the device or application aware that further security issues in the first Ethernet channel would lead to communication loss because no backup Ethernet channel is available.
[0039] In a variation of the invention, the Ethernet device with security features at the physical layer further includes a security controller, wherein the first physical layer security mechanism unit and / or the second physical layer security mechanism unit send a notification to the security controller when a security problem is detected in a corresponding first Ethernet channel and / or second Ethernet channel. The security controller can issue a warning to the system using the Ethernet device, indicating that a security problem exists in the first Ethernet channel and / or the second Ethernet channel. Therefore, the security controller monitors the availability of the first Ethernet channel and the second Ethernet channel and can provide relevant information to the system and / or application using the Ethernet device with security features at the physical layer.
[0040] According to a variation of the present invention, the Ethernet device with security functions at the physical layer further includes: a first media access controller (MAC) and a second media access controller (MAC), wherein the first media access controller (MAC) is connected to a first media-independent interface port of the first Ethernet physical layer access device, and the second media access controller (MAC) is connected to a third media-independent interface port of the second Ethernet physical layer access device. Such MACs are well known in the prior art and provide connectivity from a higher OSI layer to the OSI physical layer.
[0041] According to an advantageous variation of the invention, the first physical layer security mechanism unit and / or the second physical layer security mechanism unit include an input interface for receiving external security signals. The external security signals preferably relate to security issues that the first physical layer security mechanism unit and / or the second physical layer security mechanism unit cannot directly detect, but which can affect the security of the first Ethernet channel and / or the second Ethernet channel.
[0042] In a variation of this invention, the external safety signal originates from hardware used in an Ethernet device with security features at the physical layer. Specifically, the external safety signal refers to an abnormal power supply voltage range, an abnormal temperature range, a hardware or software built-in self-test indicating a component failure during operation, or a similar safety-critical issue with an external component. For example, an abnormal voltage range can be detected by a voltage sensor, while an abnormal temperature range can be detected by a temperature sensor.
[0043] According to a preferred embodiment of the present invention, the first physical layer security mechanism unit and / or the second physical layer security mechanism unit detects the loss of a corresponding link, the degradation of the corresponding link quality, or the presence of errors in received Ethernet packets by monitoring the link status in the following manner:
[0044] - By performing CRC checksum calculations on the Ethernet frames received at the physical layer, the link free symbol is evaluated and / or checked.
[0045] - Through error correction codes, such as the RS encoder / decoder of 1000BASE-T1,
[0046] - By observing link quality metrics (such as SQI or MSI) and reporting link quality degradation,
[0047] - Echo canceller weight observation is used to detect cable performance degradation during operation.
[0048] -Diagnose via extended cable during operation, and / or
[0049] - By fault classification.
[0050] For example, even if payload data is not transmitted through the corresponding Ethernet channel, security issues can be detected by observing link idle symbols.
[0051] According to an advantageous variation of the invention, if either the first physical layer security mechanism unit or the second physical layer security mechanism unit detects a security problem in the corresponding Ethernet channel, the first PCS / PMA unit for accessing the first Ethernet channel and / or the second PCS / PMA unit for accessing the second Ethernet channel transmits a predetermined pattern on the corresponding Ethernet channel. This predetermined pattern can be recognized by other Ethernet devices using the first and / or second Ethernet channels, thereby detecting a security problem in the corresponding first and / or second Ethernet channels. If the other Ethernet device is an Ethernet device with physical layer security functions according to the invention, it can directly switch from a first operating state to a second operating state if it detects the predetermined pattern on the first Ethernet channel. If the other Ethernet device detects the pattern on the second Ethernet channel, it can notify the devices and / or applications using the Ethernet devices about a security problem in the backup Ethernet channel. This enables the detection of faults in the communication channel within a short time interval.
[0052] In a variant of the invention, when the first and second media-independent interface switches are in a first operating state, the first Ethernet channel is used for security-critical data traffic, while the second Ethernet channel is used for non-security-critical data traffic. When the first and second media-independent interface switches are in a second operating state, the non-security-critical data traffic on the second Ethernet channel is interrupted and replaced by security-critical data traffic from the corrupted first Ethernet channel. Therefore, the first Ethernet channel is used for security-critical data traffic, and as long as there are no security issues with the first Ethernet channel, the second Ethernet channel serves as a backup for the first Ethernet channel, used for non-security-critical Ethernet traffic. Specifically, in the second operating state, the non-security-critical data traffic on the second Ethernet channel is immediately interrupted and replaced by security-critical data traffic after reaching a certain threshold. Thus, other Ethernet devices on the second Ethernet channel can detect the interruption and do not expect further data communication. Furthermore, a clear transition from non-security-critical data traffic to security-critical data traffic is guaranteed.
[0053] According to a preferred embodiment of the invention, the Ethernet device retransmits data traffic that was not fully transmitted before the first and second media-independent interface switches switched from a first operating state to a second operating state. This ensures that all Ethernet data traffic, especially security-critical Ethernet data traffic, is transmitted, and that no data loss occurs due to the retransmission of corrupted Ethernet frames caused by security issues in the Ethernet channel. The retransmission can be initiated by an Ethernet device with security features at the physical layer according to the invention, or by an OSI application layer device.
[0054] The object of the present invention is further achieved by a method for bidirectional data transmission between two Ethernet devices, wherein at least one of the two Ethernet devices is an Ethernet device with physical layer security functions according to the present invention, the method comprising the following steps:
[0055] Provide a first Ethernet channel between the two Ethernet devices for bidirectional security-critical data transmission;
[0056] Provide a second Ethernet channel between two Ethernet devices for bidirectional, non-security-critical data transmission;
[0057] Use Ethernet devices with physical layer security features to detect physical layer security issues in the first Ethernet channel, such as link loss, link quality degradation, or errors in received Ethernet packets.
[0058] If a security issue is detected in the first Ethernet channel, the Ethernet device with physical layer security features switches from the first operating state to the second operating state to:
[0059] Interrupt bidirectional non-security-critical data transmission on the second Ethernet channel;
[0060] Bidirectional security-critical data traffic is rerouted via a second Ethernet channel.
[0061] According to this method, security-critical data traffic is transmitted bidirectionally through a first Ethernet channel, while non-security-critical data traffic is transmitted through a second Ethernet channel. If an Ethernet device with physical layer security features detects a security issue with the first Ethernet channel, such as link loss, link quality degradation, or errors in received Ethernet packets, the non-security-critical data traffic via the second Ethernet channel will be interrupted, and security-critical data transmission will be rerouted from the first Ethernet channel to the second Ethernet channel. Thus, the second Ethernet channel serves as a backup for the first Ethernet channel, compensating for security issues with the first channel. When the first Ethernet channel is operating normally and without security issues, the second Ethernet channel can be used for non-security-critical data traffic.
[0062] The method according to a variation of the invention includes the following steps: reconstructing security-critical data after rerouting via a second Ethernet channel at the physical layer or application layer of another Ethernet device. Therefore, the security-critical data is transmitted intact without any loss of information. If both Ethernet devices transmitting security-critical data provide security functions at the physical layer according to the invention, the security-critical data can be reconstructed at the physical layer. In this case, both Ethernet devices can detect the security issue and automatically reroute the traffic via the second Ethernet channel. If only one Ethernet device provides security functions at the physical layer, the security-critical data must be reconstructed at the application layer for the Ethernet device that does not have security functions at the physical layer, because that Ethernet device cannot detect the security issue and reroute via the second Ethernet channel. However, the application can detect this rerouting by examining the transmitted data and reconstruct the security-critical data accordingly.
[0063] The method according to a variation of the invention further includes the step of sending a predetermined pattern on the corresponding Ethernet channel where a security problem has been detected. This predetermined pattern can be used by another Ethernet device on either the first or second Ethernet channel to detect the security problem and initiate measures such as rerouting or other actions.
[0064] According to a variation of the invention, the method includes the following steps: if a security issue is detected on one of the two Ethernet channels, and particularly if a security issue is detected on both Ethernet channels, a notification is sent to the system using the Ethernet device. Thus, the system using the Ethernet device for safety-critical data transmission receives the following information: either a security issue exists on the first Ethernet channel used for safety-critical data transmission and the safety-critical data transmission has been rerouted to the second Ethernet channel, or a security issue exists on the second Ethernet channel and it cannot be used as a backup Ethernet channel. In both cases, the reliability of the safety-critical data transmission is compromised. If a security issue exists on both the first and second Ethernet channels, a serious warning should be issued to the system using the Ethernet device because there is no reliable channel for the transmission of safety-critical data, and the system can take necessary measures, such as disabling certain functions (e.g., autonomous driving).
[0065] A variation of the method according to the invention includes the step of receiving an external security signal regarding a first Ethernet channel and / or a second Ethernet channel. Preferably, the external security signal refers to an abnormal power supply voltage range, an abnormal temperature range, a hardware or software built-in self-test result indicating a component failure during operation, or a similar safety-critical issue with an external component. Therefore, this method considers not only physical layer security issues but also external factors that may reduce the security of the Ethernet channel. This enhances the overall reliability and security of the method of the invention.
[0066] In a variation of the invention, non-security-critical data transmission on the second Ethernet channel is immediately interrupted in the second operating state and, after reaching a certain threshold, is converted to security-critical data traffic. Thus, other Ethernet devices on the second Ethernet channel can detect the interruption and do not expect further data communication. Furthermore, a clear transition from non-security-critical data traffic to security-critical data traffic is guaranteed.
[0067] The preferred variant of the method according to the invention further includes the step of: retransmitting data traffic that has not been transmitted before switching from the first operating state to the second operating state.
[0068] The present invention will now be further described with reference to the embodiments shown in the accompanying drawings. The drawings illustrate:
[0069] Figure 1 This is a schematic diagram of an Ethernet device with security functions at the physical layer according to the present invention.
[0070] Figure 2 This is a schematic diagram of an Ethernet connection between two Ethernet devices with physical layer security functions according to the present invention, and
[0071] Figure 3 This is a schematic diagram of an Ethernet connection between an Ethernet device with security features at the physical layer and an Ethernet device without security features at the physical layer, according to the present invention.
[0072] Figure 1 A schematic diagram of Ethernet devices 100 and 200 with security functions at the physical layer according to the present invention is shown. Ethernet devices 100 and 200 include first Ethernet physical layer access devices 110 and 210 and second Ethernet physical layer access devices 130 and 230.
[0073] The first Ethernet physical access devices 110 and 210 include: first PCS / PMA units 111 and 211 for accessing the first Ethernet channel 120; first media-independent interface ports 112 and 212 for Ethernet data communication; second media-independent interface ports 113 and 213 for Ethernet data communication; and first media-independent interface switches 114 and 214, which connect the first media-independent interface ports 112 and 212 to the PCS / PMA units 111 and 211 in a first operating state, and connect the first media-independent interface ports 112 and 212 to the second media interface ports 113 and 213 in a second operating state.
[0074] The second Ethernet physical layer access devices 130 and 230 include: second PCS / PMA units 131 and 231, which are used to access the second Ethernet channel 140; third media-independent interface ports 132 and 232, which are used for Ethernet data communication; fourth media-independent interface ports 133 and 233, which are used for Ethernet communication; and second media-independent interface switches 134 and 234, which connect the second PCS / PMA units 131 and 231 to the third media-independent interface ports 132 and 232 in a first operating state, and connect the second PCS / PMA units 131 and 231 to the fourth media-independent interface ports 133 and 233 in a second operating state.
[0075] The second media-independent interface ports 113 and 213 of the first Ethernet physical layer access devices 110 and 210 are connected to the fourth media-independent interface ports 133 and 233 of the second Ethernet physical layer access devices 130 and 230.
[0076] The first Ethernet physical layer access devices 110 and 210 also include first physical layer security mechanism units 115 and 215. These units are used to detect physical layer security issues in the first Ethernet channel 120, such as link loss, link quality degradation, or errors in received Ethernet packets. The first physical layer security mechanism units 115 and 215 are connected to the first media-independent interface switches 114 and 214 and the second media-independent interface switches 134 and 234. When the first physical layer security mechanism units 115 and 215 detect a problem, they switch the first media-independent interface switches 114 and 214 and the second media-independent interface switches 134 and 234 from a first operating state to a second operating state.
[0077] The second Ethernet physical layer access devices 130 and 230 also include second physical layer security mechanism units 135 and 235. The second physical layer security mechanism units 115 and 215 are used to detect physical layer security problems of the second Ethernet channel 140, such as link loss, link quality degradation, or errors in the received Ethernet packets.
[0078] Figure 1 The Ethernet devices 100 and 200, which have physical layer security functions, also include security controllers 150 and 250. When the first physical layer security mechanism units 115 and 215 and the second physical layer security mechanism units 135 and 235 detect a security problem in the corresponding first Ethernet channel 120 or second Ethernet channel 140, they send a notification to the security controllers 150 and 250. The security controllers 150 and 250 can issue warnings to the systems 160, 170, 260, and 270 using the Ethernet devices 100 and 200, indicating a security problem in the first Ethernet channel 120 and / or the second Ethernet channel 140.
[0079] The first Ethernet physical layer access devices 110 and 210 further include first media access controllers 116 and 216, which are connected to first media-independent interface ports 112 and 212. The second media access controllers 130 and 230 include second media access controllers 136 and 236, which are connected to third media-independent interface ports 132 and 232. The first media access controllers 116 and 216 and the second media access controllers 136 and 236 are used, for example, by systems 160 and 170 to access the physical layer to implement Ethernet communication.
[0080] according to Figure 1In the illustrated embodiment, the first physical layer security mechanism units 115, 215 and the second physical layer security mechanism units 135, 235 include input interfaces 117, 217, 137, 237 for receiving external security signals. External security signals may originate, for example, from hardware used in Ethernet devices 100, 200 with physical layer security features, such as systems 160, 170. External security signals refer to, for example, abnormal power supply voltage ranges, abnormal temperature ranges, hardware or software built-in self-test results indicating component failure during operation, or similar safety-critical issues with external components.
[0081] First physical layer security mechanism units 115, 215 and / or second physical layer security mechanism units 135, 235 detect the loss of a link, the degradation of link quality, or errors in received Ethernet packets by evaluating and / or checking link idle symbols and by monitoring link status in the following ways:
[0082] - By performing CRC checksum calculations on the received Ethernet frames at the physical layer,
[0083] - Through error correction codes, such as the RS encoder / decoder of 1000BASE-T1,
[0084] - By observing link quality metrics (such as SQI or MSI) and reporting link quality degradation,
[0085] - Echo canceller weight observation is used to detect cable performance degradation during operation.
[0086] -Diagnose via extended cable during operation, and / or
[0087] - By fault classification.
[0088] In a preferred embodiment, if the first physical layer security mechanism unit 115, 215 or the second physical layer security mechanism unit 135, 235 detects a security problem in the corresponding Ethernet channel 120, 140, then the first PCS / PMA unit 111, 211 for accessing the first Ethernet channel 120 and / or the second PCS / PMA unit 131, 231 for accessing the second Ethernet channel 140 send a predetermined mode on the corresponding Ethernet channel 120, 140.
[0089] When the first media-independent interface switches 114 and 214 and the second media-independent interface switches 134 and 234 are in a first operating state, the first Ethernet channel 120 is used for security-critical data traffic, and the second Ethernet channel 140 is used for non-security-critical data traffic. When the first media-independent interface switches 114 and 214 and the second media-independent interface switches 134 and 234 are in a second operating state, the non-security-critical data traffic on the second Ethernet channel 140 is interrupted and replaced by security-critical data traffic from the corrupted first Ethernet channel 120. Preferably, in the second operating state, the non-security-critical data traffic on the second Ethernet channel 140 is immediately interrupted and replaced by security-critical data traffic after reaching a certain threshold.
[0090] In one embodiment of the present invention, Ethernet devices 100 and 200 retransmit data traffic that was not fully transmitted before the first medium-independent interface switch 114 and 214 and the second medium-independent interface switch 134 and 234 switched from a first operating state to a second operating state.
[0091] refer to Figure 2 Explain in more detail Figure 1 The illustrated use of Ethernet devices 100 and 200 with physical layer security features is shown. Figure 2 A schematic diagram of an Ethernet connection between two Ethernet devices 100 and 200, which have physical layer security functions according to the present invention, is shown. Both the first Ethernet device 100 and the second Ethernet device 200, which have physical layer security functions, are connected to... Figure 1 The Ethernet device 100 shown is identical. Therefore, for a detailed description of the first Ethernet device and the second Ethernet devices 100 and 200 having security functions at the physical layer, please refer to the above. Corresponding portions of the first and second Ethernet devices 100 and 200 have corresponding reference numerals, differing only in the first digit, respectively representing the first Ethernet device 100 and the second Ethernet device 200.
[0092] according to Figure 2 According to the present invention, a first Ethernet channel 120 and a second Ethernet channel 200 are provided between two Ethernet devices 100 and 200 that have physical layer security functions. The first Ethernet channel 120 is accessed by corresponding first Ethernet physical access devices 110 and 210, while the second Ethernet channel 140 is accessed by corresponding second Ethernet physical access devices 130 and 230.
[0093] The first Ethernet channel 120 is used for bidirectional safety-critical data transmission, and the second Ethernet channel 140 is used for bidirectional non-safety-critical data transmission.
[0094] If the first Ethernet device and / or the second Ethernet device 100, 200 detect a security issue at the physical layer of the first Ethernet channel 120, then the first Ethernet device 100 and the second Ethernet device 200 switch from a first operating state to a second operating state. In the second operating state, bidirectional non-security-critical data transmission on the second Ethernet channel 140 is interrupted, and bidirectional security-critical data traffic is rerouted on the second Ethernet channel 140.
[0095] Specifically, non-safety-critical data transmission on the second Ethernet channel 140 is immediately interrupted in the second operating state and replaced by safety-critical data traffic after a certain threshold is reached.
[0096] After being rerouted via the second Ethernet channel 140, security-critical data is reassembled at the physical layer of the corresponding Ethernet devices 100 and 200 that have security features at the physical layer. In a variation of the invention, data traffic that has not yet been transmitted before switching from the first operating state to the second operating state is retransmitted to avoid any data loss.
[0097] If one of the Ethernet devices 100 or 200 detects a security issue on the first and / or second Ethernet channels 120 or 140, a predetermined pattern is sent on the corresponding Ethernet channel 120 or 140. This pattern can be recognized by other Ethernet devices 120 or 140, thereby also detecting a security issue on the corresponding Ethernet channel 120 or 140. In many cases, one of the two Ethernet devices 100 or 200 detects a security issue earlier and can use the predetermined pattern to inform the other Ethernet device of the detected security issue.
[0098] If a security issue is detected in the first Ethernet channel 120 and / or the second Ethernet channel, a corresponding notification is sent to systems 160 and 260 that use Ethernet devices 100 and 200 for security-critical data transmission. A corresponding notification may also be sent to systems 170 and 270 that use Ethernet devices 100 and 200 for non-security-critical data transmission.
[0099] Ethernet devices 100 and 200 can also receive external security signals regarding the first Ethernet channel 120 and / or the second Ethernet channel 140 via corresponding input interfaces 117, 137, 217, and 237. These external security signals may originate, for example, from hardware using Ethernet devices 100 and 200 with physical layer security features, such as systems 160, 170, 260, and 270. External security signals refer to, for example, abnormal power supply voltage ranges, abnormal temperature ranges, hardware or software built-in self-test results indicating component failure during operation, or similar safety-critical issues with external components.
[0100] Figure 3 A schematic diagram of an Ethernet connection between an Ethernet device 100, 200 having security features at the physical layer and an Ethernet device 300 not having security features at the physical layer, according to the present invention, is shown.
[0101] Ethernet devices 100, 200 and 100 with security features at the physical layer Figure 1 The equipment shown corresponds to this. For more details, please refer to the above. Figure 1 The description.
[0102] Ethernet device 300, which lacks security features at the physical layer, includes a first Ethernet physical layer access device 310 and a second Ethernet physical layer access device 330. Each of the first and second Ethernet physical layer access devices 310 and 330 includes PCS / PMA units 311 and 331, media-independent interface ports 312 and 332, and media access controllers 316 and 336. Ethernet data traffic is routed to systems 260 and 2270 using Ethernet device 300 via the corresponding PCS / PMA units 311 and 331, media-independent interface ports 312 and 332, and media access controllers 316 and 336. Because Ethernet device 300 does not provide security features at the physical layer, rerouting of security-critical data traffic performed by Ethernet devices 100 and 200 with physical layer security features in the second operating state will not be detected by Ethernet device 300, which lacks physical layer security features. However, at the application layer, rerouting can be detected by performing data inspection on the transmitted data. Therefore, Ethernet devices 100 and 200 with physical layer security features can work together with Ethernet device 300 without physical layer security features. Data inspection can be implemented at the application layer to benefit from the physical layer security features of another Ethernet device 100 or 200 without any changes to the underlying hardware.
[0103] Ethernet devices with physical layer security features and methods for bidirectional data transmission between two Ethernet devices.
[0104] List of reference numerals
[0105] 100 Ethernet devices with security features at the physical layer
[0106] 110 First Ethernet Physical Layer Access Device
[0107] 111 First PCS / PMA
[0108] 112 First Medium Independent Interface Port
[0109] 113 Second Media Independent Interface Port
[0110] 114 First Media Independent Interface Switch
[0111] 115 Security Mechanism Unit (First Ethernet Physical Layer Access Device)
[0112] 116 Media Access Controller (First Ethernet Physical Layer Access Device)
[0113] 117 Input Interface (First Ethernet Physical Layer Access Device)
[0114] 120 First Ethernet Channel
[0115] 130 Second Ethernet Physical Layer Access Device
[0116] 131 Second PCS / PMA
[0117] 132 Third Media Independent Interface Port
[0118] 133 Fourth Media Independent Interface Port
[0119] 134 Second Media Independent Interface Switch
[0120] 135 Security Mechanism Unit (Second Ethernet Physical Layer Access Device)
[0121] 136 Media Access Controller (Second Ethernet Physical Layer Access Device)
[0122] 137 Input Interface (Second Ethernet Physical Layer Access Device)
[0123] 140 Second Ethernet Channel
[0124] 150 Ethernet Channels
[0125] 160 Systems using Ethernet devices
[0126] 170 Systems using Ethernet devices
[0127] 200 Ethernet devices with security features at the physical layer
[0128] 210 First Ethernet Physical Layer Access Device
[0129] 211 First PCS / PMA
[0130] 212 First Medium Independent Interface Port
[0131] 213 Second Medium Independent Interface Port
[0132] 214 First Media Independent Interface Switch
[0133] 215 Security Mechanism Unit (First Ethernet Physical Layer Access Device)
[0134] 216 Media Access Controller (First Ethernet Physical Layer Access Device)
[0135] 217 Input Interface (First Ethernet Physical Layer Access Device)
[0136] 230 Second Ethernet Physical Layer Access Device
[0137] 231 Second PCS / PMA
[0138] 232 Third Media Independent Interface Port
[0139] 233 Fourth Media Independent Interface Port
[0140] 234 Second Media Independent Interface Switch
[0141] 235 Security Mechanism Unit (Second Ethernet Physical Layer Access Device)
[0142] 236 Media Access Controller (Second Ethernet Physical Layer Access Device)
[0143] 237 Input Interface (Second Ethernet Physical Layer Access Device)
[0144] 250 Ethernet Channels
[0145] 260 Systems using Ethernet devices
[0146] 270 Systems using Ethernet devices
[0147] 300 Ethernet devices that do not have security features at the physical layer
[0148] 310 First Ethernet Physical Layer Access Device
[0149] 311 First PCS / PMA
[0150] 312 First Medium Independent Interface Port
[0151] 316 Media Access Controller (First Ethernet Physical Layer Access Device)
[0152] 330 Second Ethernet Physical Layer Access Device
[0153] 331 Second PCS / PMA
[0154] 332 Second Medium Independent Interface Port
[0155] 336 Media Access Controller (Second Ethernet Physical Layer Access Device)
[0156] 380 Application Layer
Claims
1. An Ethernet device with security functions at the physical layer, comprising: The first Ethernet physical layer access device includes: The first PCS / PMA unit is used to access the first Ethernet channel; The first medium-independent interface port is used for Ethernet data communication; The second medium-independent interface port is used for Ethernet data communication; A first media-independent interface switch connects the first media-independent interface port to the first PCS / PMA unit in a first operating state, and connects the first media-independent interface port to the second media-independent interface port in a second operating state. The second Ethernet physical layer access device includes: The second PCS / PMA unit is used to access the second Ethernet channel; The third media-independent interface port is used for Ethernet data communication; The fourth media-independent interface port is used for Ethernet communication; and The second media-independent interface switch connects the second PCS / PMA unit to the third media-independent interface port in a first operating state, and connects the second PCS / PMA unit to the fourth media-independent interface port in a second operating state. The second medium-independent interface port of the first Ethernet physical layer access device is connected to the fourth medium-independent interface port of the second Ethernet physical layer access device; The first Ethernet physical layer access device further includes a first physical layer security mechanism unit, which is used to detect security issues in the physical layer of the first Ethernet channel. The first physical layer security mechanism unit is connected to the first media-independent interface switch and the second media-independent interface switch. When the first physical layer security mechanism unit detects the security problem, the first physical layer security mechanism unit switches the first media-independent interface switch and the second media-independent interface switch from the first operating state to the second operating state. When the first medium-independent interface switch and the second medium-independent interface switch are in the first operating state, the first Ethernet channel is used for security-critical data traffic, and the second Ethernet channel is used for non-security-critical data traffic. When the first medium-independent interface switch and the second medium-independent interface switch are in the second operating state, the non-security-critical data traffic on the second Ethernet channel is interrupted and replaced by security-critical data traffic from the damaged first Ethernet channel.
2. The Ethernet device with security functions at the physical layer according to claim 1, The second Ethernet physical layer access device further includes a second physical layer security mechanism unit, which is used to detect security issues at the physical layer of the second Ethernet channel.
3. The Ethernet device with security functions at the physical layer according to claim 2, It also includes a safety controller, among which, When the first physical layer security mechanism unit and / or the second physical layer security mechanism unit detects a security problem in the corresponding first Ethernet channel and / or second Ethernet channel, they send a notification to the security controller, wherein the security controller can issue a warning to the system using the Ethernet device, indicating that there is a security problem in the first Ethernet channel and / or the second Ethernet channel.
4. The Ethernet device with security functions at the physical layer according to claim 1, It also includes a first media access controller and a second media access controller, wherein the first media access controller is connected to the first media-independent interface port of the first Ethernet physical layer access device, and the second media access controller is connected to the third media-independent interface port of the second Ethernet physical layer access device.
5. The Ethernet device with security functions at the physical layer according to claim 2, The first physical layer security mechanism unit and / or the second physical layer security mechanism unit include an input interface for receiving external security signals.
6. The Ethernet device with security functions at the physical layer according to claim 5, The external security signal originates from the hardware of an Ethernet device that has security features at the physical layer.
7. The Ethernet device with security functions at the physical layer according to claim 5, The external safety signals mentioned refer to abnormal power supply voltage range, abnormal temperature range, hardware or software built-in self-test results indicating that a component has failed during operation, or an external component has a safety-critical issue.
8. The Ethernet device with security functions at the physical layer according to claim 2, The first physical layer security mechanism unit and / or the second physical layer security mechanism unit detect the loss of the corresponding link, the degradation of link quality, or the presence of errors in the received Ethernet packets through link status monitoring in the following ways: by evaluating and / or checking the link idle symbols; by performing CRC checksum calculation on the received Ethernet frames in the physical layer; by using error correction codes; by observing link quality indicators and reporting link quality degradation; by observing echo canceller weights to detect cable performance degradation during operation; by extending cable diagnostics during operation; and / or by fault classification.
9. The Ethernet device with security functions at the physical layer according to claim 2, If the first physical layer security mechanism unit and / or the second physical layer security mechanism unit detects a security problem in the corresponding Ethernet channel, the first PCS / PMA unit for accessing the first Ethernet channel and / or the second PCS / PMA unit for accessing the second Ethernet channel will send a predetermined pattern on the corresponding Ethernet channel.
10. The Ethernet device with security functions at the physical layer according to claim 1, In the second operating state, non-security-critical data traffic on the second Ethernet channel is immediately interrupted and replaced by security-critical data traffic after a certain threshold is reached.
11. The Ethernet device with security functions at the physical layer according to claim 1, The Ethernet device retransmits data traffic that was not fully transmitted before the first and second media-independent interface switches switched from the first operating state to the second operating state.
12. A method for bidirectional data transmission between two Ethernet devices, wherein at least one of the two Ethernet devices is an Ethernet device with security features at the physical layer as claimed in claim 1, the method comprising the following steps: Provide a first Ethernet channel between the two Ethernet devices for bidirectional security-critical data transmission; Provide a second Ethernet channel between two Ethernet devices for bidirectional, non-security-critical data transmission; Use Ethernet devices with security features at the physical layer to detect security issues at the physical layer of the first Ethernet channel; If a security issue is detected in the first Ethernet channel, the Ethernet device with physical layer security features switches from the first operating state to the second operating state to: Interrupt bidirectional non-security-critical data transmission on the second Ethernet channel; Bidirectional security-critical data traffic is rerouted via a second Ethernet channel.
13. The method for bidirectional data transmission between two Ethernet devices according to claim 12, Includes the following steps: Reassemble security-critical data that has been rerouted via a second Ethernet channel at the physical or application layer of another Ethernet device.
14. The method for bidirectional data transmission between two Ethernet devices according to claim 12, Includes the following steps: Send the pre-defined pattern on the corresponding Ethernet channel where a security issue has been detected.
15. The method for bidirectional data transmission between two Ethernet devices according to claim 12. Includes the following steps: If a security issue is detected on one of the two Ethernet channels, or if a security issue is detected on both Ethernet channels, a notification is sent to the system using the Ethernet device.
16. The method for bidirectional data transmission between two Ethernet devices according to claim 12, Includes the following steps: Receive external security signals regarding the first Ethernet channel and / or the second Ethernet channel.
17. The method for bidirectional data transmission between two Ethernet devices according to claim 16. The external security signal originates from the hardware of an Ethernet device that has security features at the physical layer.
18. The method for bidirectional data transmission between two Ethernet devices according to claim 16. The external safety signals mentioned refer to abnormal power supply voltage range, abnormal temperature range, hardware or software built-in self-test results indicating that a component has failed during operation, or an external component has a safety-critical issue.
19. The method for bidirectional data transmission between two Ethernet devices according to claim 12, In the second operating state, the second Ethernet channel is immediately interrupted and replaced with security-critical data traffic after a certain threshold.
20. The method for bidirectional data transmission between two Ethernet devices according to claim 12, Includes the following steps: Retransmit data traffic that was not transmitted before switching from the first operating state to the second operating state.
Citation Information
Patent Citations
Network device for a computer network and method for transmitting data with a network device
EP3407546A1
Ethernet network node
SE2051061A1
Method and apparatus for generating error detection data for encapsulated frames
US6226771B1
Redundant path communication methods and systems
US7127669B2
Detection of ethernet link failure
US8195989B1