Method and system for error detection and correction

By inserting an error correction layer in the industrial automation system, using logical operations and cyclic redundancy checks, the problem of low error detection and correction efficiency in the transmission of secure messages and security-related data is solved, and transmission reliability and productivity are improved.

CN120238241APending Publication Date: 2025-07-01ABB (SCHWEIZ) AG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411775890.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-12-05
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In existing industrial automation systems, there is low error detection and correction efficiency in the transmission of security messages and security-related data, resulting in frequent CRC alarms and increased downtime of automation systems, affecting productivity and safety.

Method used

The error correction layer is inserted between the secure communication layer of the communication network and the lower communication layer. By generating error modes, applying logical operations and cyclic redundancy checks, the CRC alarm probability is reduced, and error detection and correction of data packets are realized.

Benefits of technology

It effectively reduces the frequency of CRC alarms, reduces downtime for automation applications and systems, improves the transmission reliability of security messages and security-related data, and reduces the risks caused by shutting down security functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238241A_ABST
    Figure CN120238241A_ABST
Patent Text Reader

Abstract

Embodiments of the invention relate to a method and system for error detection and correction. The invention relates to a method and a system for detecting and correcting errors in security messages and / or security-related data received by automation components of an industrial automation system via a digital communication network, which is a field bus communication system, wherein a security protocol implemented by means of a security communication layer is used for data transmission of security messages and / or security-related data, a cyclic redundancy check is applied to the security messages and / or security-related data, and wherein the security messages and / or security-related data are transmitted in the form of data packets. An error correction layer inserted on the receiver side between a secure communication layer and an underlying communication layer of the communication network is designed to perform steps to detect and correct errors in security messages and / or security-related data until a value of an error signal indicates that an updated data packet is error-free, or the number of repetitions of these steps reaches a predefined maximum number of repetitions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for detecting and correcting errors in safety messages and / or safety-related data received by automation components of an industrial automation system via a digital communication network, in particular a fieldbus communication system, wherein a safety protocol implemented by means of a safety communication layer is used for data transmission of safety messages and / or safety-related data, wherein a cyclic redundancy check is applied to the safety messages and / or safety-related data, and wherein the safety messages and / or safety-related data are transmitted in the form of data packets. Furthermore, the present invention relates to a system for performing an error detection and correction method in safety messages and / or safety-related data. Background Art

[0002] Today's industrial automation systems include many automation components, such as sensors, actuators, switches, valves, contactors, machines or machine components, controllers, communication gateways, computers, and network components, etc., to monitor, control, and regulate technical processes, especially in the fields of machine automation, robotics, process automation, and / or factory automation, or for the automation of drive systems and / or electrical systems. These automation components are networked together via digital communication networks to provide data collection, exchange, and analysis of data and messages. The digital communication networks used can be wired and / or wireless communication networks. Connecting the automation components enables companies to detect inefficiencies and problems more quickly. Data is collected from sensors, machines, or machine components that can be widely distributed within the automation system, transmitted via a digital communication network to a control unit for analysis, and after data processing in the control unit, command messages are passed back via the digital communication network to actuators, switches, valves, contactors, etc. This enables the operation of an automation system, the operation of which should be as autonomous as possible and independent of human intervention.

[0003] Since data communication within industrial automation systems is usually time-critical and requires high availability, fieldbus communication systems are typically used. Additionally, special communication protocols tailored for industrial automation are applied, such as the industrial Ethernet protocol, which includes PROFINET, POWERLINK, Ethernet / IP, EtherCAT, etc. These often standardized protocols are created based on the reference model ISO / OSI, wherein they typically use the physical layer (layer 1), data link layer (layer 2), and application layer (layer 7) of the seventh-layer architecture of the ISO / OSI model.

[0004] Although the use of communication protocols such as PROFINET, POWERLINK, Ethernet / IP, EtherCAT, etc. is necessary for seamless data exchange on fieldbus communication systems and control in industrial automation systems, these protocols alone are not suitable for the transmission of safety-critical data and / or safety messages. They cannot ensure the functional safety of an automation system, as defined, for example, by the international standard IEC 61508. Functional safety is part of the overall safety of a system such as an automation system, or part of a system (e.g., a machine, a drive system, or a transport track of an automation system). Functional safety depends on the automatic protection and safety applications operating correctly in a predictable manner (fail-safe) in response to inputs such as safety sensors or system failures. For example, functional safety should prevent or at least reduce the risk of harming people, damaging or destroying the system or its components. For example, the IEC 61508 series of specifications provides functional safety standards for the life cycle of electrical, electronic, or programmable electronic systems and devices, and also provides the definition of safety integrity level (SIL) as a relative level of risk reduction.

[0005] Safety protocols such as PROFIsafe, CIP safety, Safety over EtherCAT, openSAFETY, etc., which protect data or messages according to safety requirements, are typically used, for example, to ensure the functional safety of an automation system. For example, in accordance with the IEC 61508 specifications, they can be used in safety-related automation tasks and are used by safety applications that achieve safety integrity level 3. The safety-related data and safety messages transmitted are protected by the safety protocol against data errors, data loss, and / or transmission errors to ensure correct transmission. For this purpose, the safety protocol is equipped with appropriate mechanisms that enable at least the detection of possible transmission errors. Within the framework of the IEC 61508 series of specifications, the IEC 61784-3 standard, named "Industrial communication networks – Profiles – Part 3: Functional safety fieldbuses – General rules and profile definitions" describes the general principles and mechanisms that can be used to exchange safety-critical or safety-related data and / or safety messages between automation components (e.g., sensors, actuators, switches, machines, controllers, communication gateways, etc.) within a distributed automation system using a digital communication system such as a fieldbus communication system.

[0006] The principle of the IEC61784-3 standard is based on the so-called black channel principle, that is, a communication system containing one or more components without evidence of design or verification according to IEC61508 - for example, if a communication protocol such as Ethernet, Industrial Ethernet, etc. is used, it is impossible or almost impossible to verify compliance with the relevant safety requirements for this communication protocol. The black channel principle can be used to define a safety protocol, which can be used in various industrial communication systems. The safety measures of the safety protocol, such as those required for functional safety, are implemented as an upward extension application layer of the so-called safety communication layer. For example, the safety communication layer is usually inserted between the functional safety application of the corresponding automation component and the "non-safe" standard communication channel or communication layer for data and message transmission and exchange (for example, a fieldbus communication system using one of the industrial Ethernet protocols). For example, the safety communication layer corresponds to the safety level of the automation system, detects transmission errors in the lower communication layer, and can be used to check the integrity of the transmitted data and / or messages. This means that the "non-safe" standard communication channel ("black channel") is continuously monitored for integrity by a higher-level safety protocol or safety communication layer.

[0007] According to the actual safety protocol applied, different measures are provided to monitor the integrity of the transmission of safety-related data and safety messages. Such transmission can be, for example, counters, echoes, timeouts, unique transmitter and receiver IDs, or cross-checks. Among various existing safety protocols, cyclic redundancy check (abbreviated as CRC) is applied as a cornerstone to check the integrity of the transmitted data and messages at the receiver side. CRC is an error detection method commonly used in digital communication networks to detect whether there are any error bits in the messages or data received in the form of data packets. Error bits are detected by comparing the CRC code generated at the transmitter side and the CRC code generated at the receiver side. The CRC code is a check value for data verification. This error detection method is called CRC because the CRC code for data verification is a redundancy that extends the message without adding additional information, and the algorithm for generating the CRC code is based on cyclic codes, which are block codes where a cyclic shift of each codeword gives another codeword belonging to the code.

[0008] The message or data to be transmitted is appended with a CRC code by the transmitter. The CRC code is relatively short - it typically has a length of a predefined number of bits - and is based on the remainder of a polynomial division of the message or data to be transmitted using a so-called generator polynomial or CRC polynomial. When the message is received, the receiver repeats the calculation of the CRC code using the same CRC polynomial. The newly calculated CRC code is compared with the CRC code transmitted and appended to the message or data. In the case of a CRC code mismatch, action can be taken. For example, in an automation system, the received message or data will be discarded and should be retransmitted. In addition, an alarm (e.g., a CRC alarm) will be triggered. Then, the affected component or application or part of the automation system or the entire automation system will typically be transferred to a safe state or even stopped to ensure safety.

[0009] Although today's black channel principles, especially CRC, can ensure safety regardless of the underlying communication technology used, problems can occur, especially when these methods are used in industrial or automation systems. For example, if the underlying communication network used (e.g., a wireless network, a long cable connection using Ethernet APL, etc.) has low transmission quality and / or high sensitivity to interference (e.g., noise, burst errors, or other random interferences), this can result in bit errors in, for example, safety messages and / or safety-related data. Since CRC has a very strong error detection capability, errors in the transmitted safety messages and / or safety-related data are detected with a high probability. The detection of errors may lead to CRC alarms, resulting in frequent safety stops. As a result, the downtime of the automation system or at least a part of it will increase, leading to productivity problems. Therefore, the safety function of the automation system can be turned off by the operator to avoid the high downtime and reduced productivity due to frequent CRC alarms, but turning off the safety function may result in (as a consequence) significant safety problems.

[0010] In theory, CRC can also be used for error correction, but there is a lack of an effective decoding algorithm on the receiver side. Generally, so-called likelihood algorithms (especially the maximum likelihood algorithm) are used as error correction decoding algorithms. These algorithms attempt to find the transmitted message or data that maximizes the likelihood of the received message or data. Even though the performance of these algorithms may be relatively good, the high decoding complexity may be impractical for practical use, especially for error correction of safety messages and / or safety-related data in industrial automation systems. Summary of the Invention

[0011] The object of the present invention is to provide a method and a system for error detection and correction of secure messages and / or security-related data, which enhance the exchange of secure messages and / or security-related data between automation components in a simple manner and reduce the downtime of automation applications, automation components, and / or the entire automation system due to CRC alarms caused by incorrect secure messages and / or security-related data with less effort and cost.

[0012] These and other objects are solved by a method and a system for error detection and correction according to the independent claims. Advantageous embodiments of the present invention are described by the dependent claims.

[0013] According to the present invention, these and other objects are achieved by a method for detecting and correcting errors as described at the beginning, wherein an error correction layer inserted between the secure communication layer and the lower communication layer of the communication network on the receiving automation component side performs the following steps:

[0014] a) Retrieving a data packet from the receiving part of the communication layer of the communication network, the data packet being received by the automation component via the communication network;

[0015] b) Generating an error pattern;

[0016] c) Applying a logical operation to the received data packet and the generated error pattern, wherein the updated data packet is determined as the result of the logical operation;

[0017] d) Checking for errors in the updated data packet using a cyclic redundancy check according to a given CRC polynomial and setting an error signal to indicate whether there is at least one error in the updated data packet or whether the updated data packet is error-free;

[0018] e) Evaluating the value of the error signal and checking the number of repetitions of steps b) to e) performed on the received data packet; and

[0019] And repeating steps b) to e) until the value of the error signal indicates that the updated data packet is error-free or the number of repetitions of steps b) to e) has reached a predefined maximum number of repetitions.

[0020] A main aspect of the proposed solution is that the probability of CRC alarms is greatly reduced, especially when the underlying communication network has poor transmission quality and / or high sensitivity to errors caused by, for example, noise, bursts, etc. Thus, the downtime of automation applications, automation components, and / or the entire automation system can be reduced with little effort and cost. Due to the reduction of CRC alarms, the method can also reduce subsequent safety risks caused by turning off safety functions under productivity pressure. In addition, an error correction layer can be inserted without any modification to the existing secure communication layer and / or the underlying communication layer of the communication network. Thus, the error correction layer and the method performed by the error correction layer can be easily implemented in network structures or automation components of industrial automation systems (such as safety sensors, actuators, controllers, communication gateways, and other devices), and improve the transmission and exchange of safety messages and / or safety-related data within the automation system.

[0021] In an advantageous embodiment, when the value of the error signal indicates that the updated data packet is error-free or the number of repetitions of steps b) to e) reaches a predefined maximum number of repetitions, the current updated data packet is sent out, for example, to the secure communication layer for further processing, for example. The updated data packet after error correction can be used by a safety application in an automation component, where the probability of the data packet causing a CRC alarm is greatly reduced.

[0022] Furthermore, it can be advantageous that when the output signal is set to a first predefined value, when the updated data packet is error-free or the number of repetitions of steps b) to e) reaches a predefined maximum number of repetitions, and when the output signal is set to a second predefined value, as long as the value of the error signal indicates that at least one error is detected in the updated data packet and the predefined maximum number of repetitions has not been reached. Ideally, the output signal is set to the first predefined value or the second predefined value during step e) - when the value of the error signal is evaluated and the number of repetitions of steps b) to e) performed on the received data packet is checked. In a preferred embodiment of the present invention, the value 1 is used as the first predefined value, while the value 0 is used as the second predefined value.

[0023] In another preferred embodiment of the present invention, an error pattern is generated based on the principle of Guessing Random Additive Noise Decoding (or abbreviated as GRAND). Regardless of the coding structure, Guessing Random Additive Noise Decoding or GRAND is a decoding algorithm. Using GRAND, a sequence of coded symbols or data can be decoded based on the guessed noise or the influence of channel noise (especially the added noise), where the noise influence is sorted according to probability from the most likely to the least likely. Then, it is determined to include iteratively guessing the coded symbols or data of a new noise sequence and removing its influence from the received symbols or data. For example, GRAND is described in US2019 / 0199473A1 or in the paper “Guessing noise, not code-words,” by K.R. Duffy, J. Li, and M. Medard (IEEE Int. Symposium on Information Theory, pp. 671-675, 2018).

[0024] In another advantageous embodiment of the present invention, a logical inequality operation is used as the logical operation for determining the updated data packet. The logical inequality operation, also known as the Exclusive OR (abbreviated as XOR) operation, compares the retrieved data packet with the error pattern, for example, bit by bit, regardless of whether the corresponding bits are different or match. For example, if and only if the corresponding bits of the data packet and the error pattern are different, the corresponding bit is set to a first value (for example, value 1), and for example, if the corresponding bits of the data packet and the error pattern match, the corresponding bit is set to a second value (for example, value 0). This is how the updated data packet is determined bit by bit, for example.

[0025] Furthermore, it is advantageous if, for example, a given CRC polynomial is pre-implemented in the error correction layer based on the knowledge of the secure communication layer and the security protocol used. As an alternative, a given CRC polynomial can be configured during the startup phase of the automation component. In another advantageous embodiment, the CRC polynomial can be configured during the startup phase of the automation component and it can be reconfigured during the operation of the automation component, providing maximum flexibility for error detection and correction.

[0026] The above object is also achieved by a system for detecting and correcting errors, wherein an error correction layer is inserted on the receiving automation component side between the secure communication layer and the lower communication layer of a communication network, and wherein the error correction layer comprises functional units for performing the method according to the invention. The error correction layer at least comprises: an error pattern generator unit for generating an error pattern; a bit string calculator unit for retrieving a data packet from the receiving part of the communication layer of the communication network and for applying a logical operation to the retrieved data packet and the error pattern fed by the error pattern generator unit to determine an updated data packet; an error detector unit for detecting an error in the updated data packet using cyclic redundancy check according to a given CRC polynomial and for setting an error signal to indicate whether there is at least one error in the updated data packet or whether the updated data packet is error-free; and an error correction control unit for controlling error detection and correction in the received data packet by evaluating the value of the error signal and by monitoring whether a predefined maximum number of repetitions of the steps for detecting and correcting errors in the data packet is reached.

[0027] Furthermore, the error correction layer preferably comprises an output unit for sending out the updated data packet for further processing, in particular for sending to the secure communication layer. The updated data packet can be sent when the error correction control unit terminates error detection and correction of the received data packet, since the value of the error signal indicates that the updated data packet is error-free or the predefined maximum number of repetitions has been reached.

[0028] In an advantageous embodiment, the error correction layer is implemented by a field programmable gate array (or abbreviated as FPGA). An FPGA is an integrated circuit that can be programmed or reprogrammed very easily. It consists of an array of programmable logic blocks and interconnections that can be configured to implement various digital functions. FPGAs are typically used in applications that require flexibility, speed, and parallel processing capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Hereinafter, reference will be made to Figures 1 to 3 describe the present invention in more detail, Figures 1 to 3 illustrating exemplary, schematic and non-limiting advantageous embodiments of the present invention. In the drawings:

[0030] Figure 1 illustrates an exemplary system architecture of a secure communication system according to the present invention;

[0031] Figure 2 illustrates a possible design of the error correction layer of a secure communication system according to the present invention;

[0032] Figure 3A flowchart of a method for detecting and correcting errors in security messages and / or security-related data received in the form of data packets in an automated component is shown, which is executed by an error correction layer of a security communication system according to the present invention. DETAILED DESCRIPTION

[0033] In Figure 1 the basic idea of the present invention is shown. For the sake of convenience, Figure 1 the system architecture of a system for secure communication in an automation system having two exemplary automated components A1, A2 is schematically and exemplarily shown. The automated components A1, A2 (e.g., a sensor unit, an actuator unit, etc., which communicate with a control unit for controlling an automation task, etc.) typically use a standard communication protocol such as one of the industrial Ethernet protocols (e.g., PROFInet, etc.) to exchange messages and data, especially security-related messages in the form of data packets DP1, DP2, via a digital communication system such as a fieldbus communication system. As shown in the example of Figure 1 the automated components A1, A2 are designed as transceiver units. That is, they can send and receive messages and / or data DP1, DP2 via the fieldbus communication system. Thus, the first automated component A1 (e.g., a sensor unit, an actuator unit, etc.) sends a first message DP1 to the second automated component A2 (e.g., a control unit). The second automated component A2 sends a second message DP2 to the first automated component A2. For example, these two messages are sent as data packets DP1, DP2, where each data packet DP1, DP2 includes at least a data payload DAT1, DAT2 (e.g., security-related data) and a CRC code CC1, CC2 attached to the data payloads DAT1, DAT2. The corresponding CRC codes CC1, CC2 are generated using a CRC method at the automated components A1, A2 that send the corresponding data packets DP1, DP2. However, it is also possible that only one of the two automated components A1, A2 sends messages and / or data DP1, DP2, while the other of the two automated components A1, A2 only serves as a receiver of the messages and / or data DP1, DP2.

[0034] As previously mentioned, the communication protocol of the fieldbus communication system follows a known ISO / OSI model of a communication layer CL that uses the seventh layer architecture of the ISO / OSI model. Generally, the industrial Ethernet protocol (e.g., PROFInet) uses a physical layer PL (layer 1), a data link layer DLL (layer 2), and an application layer APL (layer 7), where the physical layer PL and the data link layer DLL are the same for all industrial Ethernet protocols. Software for accessing the fieldbus communication system runs in the application layer APL.

[0035] Since Figure 1The automation components A1, A2 shown by way of example in the figure are intended to transmit or exchange safety messages and / or safety-related data as data packets DP1, DP1, which are used or required by the corresponding functional safety applications APP1, APP2 of the automation components A1, A2, so that a safety protocol (e.g. PROFIsafe) is implemented for data transmission via a communication system, in particular a fieldbus communication system, in order to protect the data packets DP1, DP2 according to safety requirements. The safety protocol is implemented, for example, as an upward extension of the application layer APL and in Figure 1 The secure communication layer SCL is represented in the system architecture. The secure communication layer SCL is usually placed between the functional safety applications APP1, APP2 of the automation components A1, A2 and the communication layer CL in the system architecture. For example, the secure communication layer SCL monitors the communication layer CL for the integrity of the transmitted messages DP1, DP2 (the so-called "black channel").

[0036] The safety communication layer SCL is inserted, for example, between the functional safety applications APP1, APP2 of the respective automation components and the "non-safety" standard communication layer CL (so-called "black channel"), which is used by a fieldbus communication system using, for example, one of the industrial Ethernet protocols (e.g. PROFInet). The safety communication layer SCL corresponds, for example, to the safety level of the automation system and detects and controls transmission errors in the underlying communication layer CL. This means that the "non-safety" standard communication layer CL ("black channel") is continuously monitored for integrity by the safety communication layer SCL to ensure the functional safety communication FSC between the automation components A1, A2.

[0037] In the system architecture according to the invention, an error correction layer ECL is also provided for safe communication via the communication network of the automation system, in particular a fieldbus communication system. The error correction layer ECL is inserted between the safety communication layer SCL of the black channel and the underlying communication layer CL at the respective receiver side. Figure 1 Both automation components A1, A2 shown by way of example in FIG. 1 are designed as transceivers, for example, both automation components A1, A2 have an error correction layer ECL inserted in their architecture. The error correction layer ECL does not change the design of the safety communication layer SCL and the underlying communication layer CL of the black channel. The error correction layer ECL performs error correction operations to correct erroneous bits in received messages or data packets DP1, DP2 based on knowledge of the CRC polynomial CP of the safety communication layer SCL, e.g., with the aid of Figure 2 and 3The error correction layer ECL thus combines error detection and error correction in safety-related messages or data packets DP1, DP2 received by the automation components A1, A2. The error correction layer ECL receives as input the existing data stream, in particular the data packets DP1, DP2 received by the respective automation components A1, A2, from the receiving part REC of the communication layer CL of the black channel.

[0038] In addition to the existing data stream or received data packets DP1, DP2, the error correction layer ECL also needs information about the CRC polynomial CP from the safety communication layer SCL, which is used for error detection based on CRC (abbreviation for cyclic redundancy check). In one embodiment, the CRC polynomial CP can be pre-implemented in the error correction layer ECL based on information on the safety communication layer SCL or the safety protocol used in the digital communication network (especially the fieldbus communication system). Standard protocols for data transmission in communication systems, such as one of the industrial Ethernet protocols used by the communication system of the industrial automation system and / or a safety protocol for safety communication (such as PROFIsafe), can specify the CRC coding scheme to be used and certain CRC polynomial CPs, such as CRC-16 or CRC-32. The specified CRC polynomial CP of the specific safety protocol of the communication system can be pre-implemented in the error correction layer ECL. The CRC polynomial CP is then fixed during the execution of the error detection and correction process performed by the error correction layer ECL. In another embodiment, the CRC polynomial CP can be configured during the initialization phase of the automation components A1, A2, for example based on information provided by the safety communication layer SCL. That is, information about the used safety protocol and the CRC polynomial CP to be used can be collected, and the corresponding CRC polynomial CP can be configured in the error correction layer ECL during the initialization phase. In another very flexible embodiment, the CRC polynomial CP can be preconfigured during the initialization phase of the automation components A1, A2, for example based on information provided by the safety communication layer SCL. During the operation of the automation components A1, A2, the CRC polynomial CP can be reconfigured and adapted to the error detection and correction processes performed by the error correction layer ECL.

[0039] Figure 2 An exemplary design of an error correction layer ECL, which can be implemented in a field programmable gate array (or FPGA for short), is schematically shown. The error correction layer ECL comprises several functional building blocks or functional units for implementing the error correction layer ECL according to the following Figure 3A method is described, in which an error detection and correction process is performed for safety messages and / or safety-related data received by an automation component. The error correction layer ECL receives safety messages and / or safety-related data, which are transmitted as data packets DP via a digital communication network (e.g., a fieldbus communication system). For example, these data packets DP have the form of bit strings. The error correction layer ECL comprises a bit string calculator unit BSC, which retrieves one of the received data packets DP from the receiving part REC of the communication layer CL as input. In addition, the bit string calculator unit BSC is fed with an error pattern EP as another input by the error pattern generator unit EPG. For example, the error pattern EP also has the form of a bit string. The bit string calculator unit BSC applies a logical operation to the retrieved data packet DP and the error pattern EP to generate an updated data packet DP'. Therefore, the bit string calculator unit BSC uses a logical inequality operation (a so-called exclusive OR operation, also abbreviated as XOR operation) as a logical operation. The logical inequality operation compares the retrieved data packet DP and the error pattern EP bit by bit, regardless of whether the corresponding bits are different (e.g., the first bit of the data packet DP is different from or matches the first bit of the error pattern EP, etc.). The bit string calculator unit BSC then determines an updated data packet DP' as a result of the logical operation.

[0040] The error correction layer ECL includes an error pattern generator unit EPG to generate an error pattern EP, for example, in the form of a bit string. The error pattern generator unit EPG provides the generated error pattern EP to the bit string calculator unit BSC. The error pattern EP is generated based on the principle of guessing random additive noise decoding (abbreviated as GRAND), for example, by using the GRAND scheme given in the paper "noise error pattern generation based on Successive addition-subtraction for GRAND-MO" by M. Zhan, Z. Pang, K. Yu, J. Xu, F. Wu and M. Xiao (published in IEEE Communications Letters, Vol. 26, No. 4, pp. 743-747, April 2022).

[0041] Furthermore, the error correction layer ECL comprises an error detector unit ED, which is fed with the updated data packet DP' from the bit string calculator unit BSC. The error detector unit ED performs error detection on the updated data packet DP'. The error detector unit ED uses a cyclic redundancy check (or CRC) according to a given CRC polynomial CP as an error detection method. For example, the CRC polynomial CP can be pre-implemented in the error correction layer ECL, in particular in the error detector unit ED. Alternatively, it can be configured in the error correction layer ECL (in particular in the error detector unit ED) during an initialization phase, for example based on information from the secure communication layer SCL, or it can be reconfigured during execution. The error detector unit ED is also arranged to set the error signal CRC_E to a value indicating whether there is at least one error in the updated data packet DP'. The error signal CRC_E is an output signal of the error detector unit ED. If no error is detected in the updated data packet DP', the error detector unit ED can set the error signal CRC_E to a first value of 0. The error detector unit ED may set the error signal CRC_E to a second value 1 if at least one error is detected in the updated data packet DP′ fed from the bit string calculator unit BSC.

[0042] In addition, the error correction layer ECL includes an error correction control unit ECC. The error correction control unit is established to control the error detection and correction process within the error correction layer ECL. The error correction control unit ECC receives an error signal CRC_E from the error detector unit ED and evaluates the value of the error signal CRC_E. If the error signal CRC_E is set to a first value 0, the error correction control unit ECC sets its output signal F_S to a first predefined value, such as a value 1, to stop the error detection and correction process of the received data packet DP. In addition, the error correction control unit ECC also monitors the number of repetitions of the error detection and correction process that has been performed on the received data packet DP. Therefore, the error correction control unit ECC compares the current number of repetitions with a predefined maximum number of repetitions. If the current number of repetitions has reached the predetermined maximum number of times, the error correction control unit ECC also sets its output signal F_S to a first predefined value (e.g., 1) to stop the error detection and correction process performed on the received data packet DP.

[0043] If the error signal CRC_E received from the error detector unit ED is set to the first value 1, the error correction control unit ECC sets its output signal F_S to a second predefined value, for example the value 0. The error detection and correction process performed on the received data packet DP continues until the predefined maximum number of repetitions is reached or the error detector unit ED provides the error signal CRC_E with the value 0. As long as the predefined maximum number of repetitions is neither reached nor the value of the error signal is set to the second value 0, a new error pattern is generated by the error pattern generator unit EPG, the newly generated error pattern is fed to the bit string calculator unit BSC, which generates a new updated data packet DP' from the received data packet DP and the newly generated error pattern EP, and the new updated data packet DP' is checked by the error detector unit ED. Therefore, the error correction control unit ECC controls the error detection and correction process of the received data packet DP by setting its output signal F_S to the first predefined value or the second predefined value.

[0044] Furthermore, the error correction layer ECL comprises an output unit OUT for sending the updated data packet DP' to the secure communication layer when the output signal F_S of the error correction control unit ECC is set to a first predefined value, for example to the value 1. As long as the output signal F_S has a second predefined value, for example the value 0, the output unit OUT is prevented from sending out the updated data packet DP' via the error correction control unit ECC.

[0045] Figure 3 A flow chart of a method for error detection and correction in safety messages received in the form of data packets in an automation component is shown, the method being carried out by an error correction layer of the safety communication system according to the invention.

[0046] As Figure 3 In the example shown, the method shown starts with a receiving step 101. During the receiving step 101, the automation components A1, A2 receive safety messages or safety-related data in the form of data packets DP via the communication network. The bit string calculator unit BSC retrieves one of the received data packets DP, for example in the form of a bit string, from a receiving part REC of the communication layer CL of the black channel. The receiving step 101 can be performed using techniques known in the art to receive or retrieve data packets DP from a channel of a digital communication system, in particular a fieldbus communication system.

[0047] The method continues to a pattern generation step 102. The error pattern generator unit EPG generates an error pattern EP and feeds it to a bit string calculator unit BSC. The error pattern EP is generated by the error pattern generator unit EPG, for example, as a bit string. In addition, the error pattern generator unit EPG uses the GRAND principle to generate a new error pattern EP, which can be used to decode, for example, a linear block code based on a probabilistic guess of the channel noise effect according to the channel noise effect. For example, the error pattern generator unit EPG can in particular use the principle of GRAND as given in the paper "noise error pattern generation based on Successive addition-subtraction for GRAND-MO" by M. Zhan, Z. Pang, K. Yu, J. Xu, F. Wu and M. Xiao (published in IEEE Communications Letters, Vol. 26, No. 4, pp. 743-747, April 2022).

[0048] After having retrieved the data packet DP from the receiving part REC of the communication layer CL and after being fed with the error pattern EP, the bit string calculator unit BSC generates an updated data packet DP' in a calculation step 103. In the calculation step 103, the bit string calculator unit BSC generates an updated data packet DP' from the received data packet DP and the error pattern EP received from the error pattern generator unit EPG using a logical operation. The logical operation used by the bit string calculator unit BSC is a logical inequality operation (so-called exclusive OR operation or abbreviated as XOR). The received data packet DP and the error pattern EP are compared bit by bit, regardless of whether the corresponding bits are different. The result of the logical inequality operation used on the inputs DP, EP during the calculation step 103 is an updated data packet DP'.

[0049] The method then proceeds to the error detection step 104. In the error detection step 104, the error detector unit ED receives the updated data packet DP’ from the bit string calculator unit BSC and checks for errors in the updated data packet DP’. The error detector unit ED performs error detection on the updated data packet DP’ using CRC according to a given CRC polynomial CP. That is, the error detector unit ED uses the given CRC polynomial CP for polynomial division of the updated data packet DP’ to determine the CRC code of the updated data packet DP’, and compares the determined CRC code of the updated data packet DP’ with the CRC codes CC1, CC2 appended to the data packet DP’. In the case of a CRC code mismatch, the error detector unit ED identifies that there is at least one error in the updated data packet DP’, and sets the error signal CRC_E to a value (e.g., value 1) indicating the erroneous data packet DP’. In the case of a CRC code match, no error is detected in the updated data packet DP’, and the error detector unit ED sets the error signal CRC_E to a second value (e.g., value 0) indicating an error-free data packet DP’. At the end of the error detection step 104, the error signal CRC_E is forwarded as the output signal of the error detector unit ED to the error correction control unit ECC.

[0050] The error correction control unit ECC controls the error detection and correction processes within the error correction layer ECL, and in particular performs two decision steps 105, 106. In the first decision step 105, the error correction control unit ECC evaluates the value of the error signal CRC_E forwarded by the error detector unit ED. If the error correction control unit ECC determines in the first decision step 105 that the value of the error signal CRC_E indicates that no error is detected in the updated data packet DP’ (e.g., the value of the error signal CRC_E is 0), then the error correction control unit ECC sets its output signal F_S to a first predefined value, e.g., value 1. The first predefined value of the output signal F_S stops the error detection and correction processes being performed on the currently received data packet DP and triggers the output step 107. In the output step 107, the current updated data packet DP’ is sent to, for example, the secure communication layer SCL via the output unit OUT. Then, the error detection and correction processes can be started again using the next data packet DP received via the communication network and using the reception step 101.

[0051] If the error correction control unit ECC determines in the first decision step 105 that the value of the error signal CRC_E indicates that at least one error has been detected in the updated data packet DP' (e.g., the value of the error signal CRC_E is 1), the error correction control unit ECC sets its output signal F_S to a second predefined value (e.g., value 0). That is, the process continues with the second decision step 106. In the second decision step 106, the error correction control unit ECC checks whether the predefined maximum number of repetitions of the error detection and correction process has been reached. If the current number of repetitions has reached the predetermined maximum number, the error correction control unit ECC also sets its output signal F_S to a first predefined value (e.g., value 1) to stop the error detection and correction process being performed on the currently received data packet DP. The process ends with the output step 107. That is, for example, the currently updated data packet DP' is sent by the output unit OUT to the secure communication layer SCL, and the process starts again with the reception step 101, where the bit string calculator unit BSC retrieves the next data packet DP from the reception part REC of the communication layer CL for error detection and correction.

[0052] If the value of the error signal CRC_E indicates that at least one error exists in the updated data packet DP' (e.g., is 1) and the error correction control unit ECC determines in the second decision step 106 that the predefined maximum number of repetitions has not been reached, the error correction control unit ECC sets its output signal F_S to a second predefined value, e.g., value 0, thereby preventing the output step 107 and continuing the error detection and correction process for the currently received data packet DP. That is, the pattern generation step 102, calculation step 103, error detection step 104, and decision steps 105, 106 are repeated for the currently received data packet DP until the error signal CRC_E is set to the value 0 (i.e., no error has been detected in the currently examined updated data packet DP') or the predefined maximum number of repetitions has been reached. If either of these two criteria is met, the error detection and correction process for the currently received data packet DP is stopped by setting the output signal F_S of the error correction control unit ECC to a first predefined value (e.g., value 1) and by performing the output step 107. The error detection and correction process can start again, where the reception step 101 retrieves the next data packet DP received via the communication network.

Claims

1. A method for detecting and correcting errors in safety messages and / or safety-related data, which are received by automation components (A1, A2) of an industrial automation system via a digital communication network, in particular via a fieldbus communication system, wherein a safety protocol implemented by means of a safety communication layer (SCL) is used for the data transmission of the safety messages and / or safety-related data, wherein a cyclic redundancy check is applied to the safety messages and / or safety-related data, and wherein the safety messages and / or safety-related data are transmitted in the form of data packets (DP, DP1, DP2), characterized in that An error correction layer (ECL) inserted on the receiving automation component (A1, A2) side between the secure communication layer (SCL) and the underlying communication layer (CL) of the communication network performs the following steps: a) retrieving data packets (DP, DP1, DP2) from a receiving part REC of a communication layer (CL) of the communication network, the data packets being received (101) by the automation component (A1, A2) via the communication network; b) generating an error pattern (EP) (102); c) applying a logic operation to the received data packets (DP, DP1, DP2) and the generated error pattern (EP), wherein an updated data packet (DP') is determined as a result of said logic operation (103); d) checking the updated data packet (DP') for errors using a cyclic redundancy check according to a given CRC polynomial (CP) and setting an error signal (CRC_E) to a value indicating whether at least one error is present in the updated data packet (DP') or whether the updated data packet (DP') is error-free (104); e) evaluating said value of said error signal (CRC_E) and checking the number of repetitions (105, 106) of steps b) to e) performed on said received data packet (DP); And steps b) to e) are repeated until said value of said error signal (CRC_E) indicates that said updated data packet (DP') is error-free, or said number of repetitions of steps b) to e) reaches a predefined maximum number of repetitions.

2. The method according to claim 1, characterized in that When said value of said error signal (CRC_E) indicates that said updated data packet (DP') is error-free or the number of repetitions of steps b) to e) reaches said predefined maximum number of repetitions, the current updated data packet (DP') is sent for further processing (107).

3. The method according to any one of the preceding claims, characterized in that The output signal (F_S) is set to a first predefined value (105, 106) when the updated data packet (DP') is error-free or the number of repetitions of steps b) to e) reaches the predefined maximum number of repetitions, and the output signal (F_S) is set to a second predefined value (105, 106) as long as the value of the error signal (CRC_E) indicates that at least one error has been detected in the updated data packet (DP') and the predefined maximum number of repetitions has not been reached.

4. The method according to any one of the preceding claims, characterized in that The error pattern (EP) is generated based on the principle of guessing random additive noise decoding or GRAND.

5. The method according to any one of the preceding claims, characterized in that The updated data packet (DP') is determined using a logical inequality operation as a logical operation.

6. The method according to any one of the preceding claims, characterized in that The given CRC polynomial (CP) is pre-implemented in the error correction layer (ECL), or is configured during a startup phase of the automation component (A1, A2), or is reconfigured during operation of the automation component (A1, A2).

7. A system for detecting and correcting errors in safety messages and / or safety-related data, which are received by automation components (A1, A2) of an industrial automation system via a digital communication network, in particular via a fieldbus communication system, wherein a safety protocol implemented by means of a safety communication layer (SCL) is used for the data transmission of the safety messages and / or safety-related data, wherein a cyclic redundancy check is applied to the safety messages and / or safety-related data, and wherein the safety messages and / or safety-related data are transmitted in the form of data packets (DP, DP1, DP2), characterized in that An error correction layer (ECL) is inserted between the safety communication layer (SCL) and the underlying communication layer (CL) on the receiving automation component (A1, A2) side, wherein the error correction layer (ECL) comprises at least: - an error pattern generator unit EPG for generating an error pattern (EP); - a bit string calculator unit BSC for retrieving data packets (DP, DP1, DP2) from a receiving part REC of a communication layer (CL) of said communication network and for applying a logical operation on the retrieved data packets (DP, DP1, DP2) and on the error pattern (EP) fed by said error pattern generator unit EPG in order to determine an updated data packet (DP'); an error detector unit (ED) for detecting errors in the updated data packet (DP') using a cyclic redundancy check according to a given CRC polynomial (CP) and for setting an error signal (CRC_E) to a value indicating whether at least one error is present in the updated data packet (DP') or whether the updated data packet (DP') is error-free; and - an error correction control unit (ECC) for controlling the detection and correction of errors in the received data packets (DP, DP1, DP2) by evaluating the value of the error signal (CRC_E) and by monitoring whether a predefined maximum number of repetitions of the steps for detecting and correcting errors in the data packets (DP, DP1, DP2) is reached.

8. The system according to claim 7, characterized in that The error correction layer (ECL) further comprises an output unit (OUT) for sending out updated data packets (DP').

9. The system according to any one of claims 7 to 8, characterized in that The error correction layer (ECL) is implemented by a field programmable gate array.

Citation Information

Patent Citations

  • Decoding Signals By Guessing Noise

    US20190199473A1