Method for testing communication bus
By monitoring the data bit sequence and time window on the shared communication medium, identifying and evaluating the amount of data in the transmission cycle, the problem of communication integrity monitoring in communications of multiple network devices is solved, and the rapid identification and response errors are realized in network devices with limited computing capabilities is achieved, and the system's work safety and reliability are improved.
Patent Information
- Application Number
- CN202380083496.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-13
- Filing Date
- 2023-12-01
- Publication Date
- 2025-07-04
AI Technical Summary
When multiple network devices communicate through shared communication media, the prior art cannot effectively monitor and ensure the integrity of communication, especially in network devices with limited computing capabilities, and cannot identify physical errors and interference, resulting in the impact of communication reliability and security.
By listening to the data bit sequence and time window on the shared communication medium, identify the start and end of the transmission cycle, evaluate the transmission status of the network device, determine the duration and data volume of the transmission cycle, compare the actual and expected data volumes to monitor communication integrity, and switch to safe mode or adjust the access control method when an error is detected.
It realizes simple and reliable integrity control of communication in network devices with limited computing capabilities, can quickly identify and respond to errors, improves the working safety and reliability of the system, and is suitable for high-demand communication systems such as highly autonomous vehicles.
Smart Images

Figure CN120266456A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to communications via a communication medium shared by multiple network devices, and in particular to monitoring the integrity of communications.
[0002] Term Definitions
[0003] In this document, the term "communication medium" is used to denote a wireless or wired or other media-based transmission medium, i.e., synonymous with an acoustic signal, light wave, radio wave, or an electrical signal carried via an electrical conductor, unless the context necessarily dictates the use of one of these communication media. Background Art
[0004] Secure communication between multiple network devices is required in many technical fields. The communication can be implemented via point-to-point connections through routers and switches (as, for example, in most Ethernet and Internet Protocol (IP)-based networks), or via a communication channel shared by multiple network devices (including wireless connections or wired bus connections).
[0005] In the field of industrial automation, various field buses are used, such as EtherCAT, RS-485, UART, etc. In the automotive field, MOST, CAN, LIN, and other networks are used, which require complex gateway devices to communicate with other domains. In the computer server market, I2C, GPIO, SPI, and even CAN from the automotive industry are used to manage various subsystems.
[0006] Each of these subsystems uses its own respective hardware interface with different EMV behaviors and uses different software stacks for this purpose. In contrast, an Ethernet-based end-to-end network architecture has many advantages because it always operates using the same protocol regardless of the physical layer. Regardless of whether the transmission rate of the data frame is 10 Mbps or 10 Gbps, the data frame always looks the same. Bandwidth expansion for a particular application does not require a complex gateway. A single switch can typically be equipped with multiple corresponding interfaces to enable communication at different speeds. Then, through appropriate caching, the data frame can be switched from one domain to another without modifying the data.
[0007] In many applications, it is not feasible to use a conventional Ethernet connection due to complexity, space, weight, cost, or other reasons. For example, an electrical Ethernet connection designed as a point-to-point connection between two network devices or between a network device and a switch via a line requires a dedicated physical interface (commonly referred to as a PHY) at each end of the line, which is responsible for encoding and decoding data between the digital system side and the propagation or transmission medium. The switch needs to provide a separate PHY for each network device connected to the switch, so a large number of ports are required in the network. Figure 1 FIG. 16 illustrates by way of example a system 10 having four network devices 12, 14, 18, and 20 connected via a switch 16. These four point-to-point connections require a total of eight physical interfaces so that all five network devices can communicate with each other.
[0008] Ethernet systems using a bus topology (10BASE2, 10BASE5) have been known since the early days of Ethernet. Figure 2 An example of such a topology is shown in FIG. 17. A coaxial cable 22 connects the five network devices 12, 14, 16, 18, and 20. Each of the network devices 12, 14, 16, 18, and 20 is connected to the coaxial cable 22 via a spur and a junction box 12a, 14a, 16a, 18a, and 20a. In the junction boxes 12a, 14a, 16a, 18a, and 20a, in the case of 10BASE5 Ethernet, the outer conductor of the coaxial cable 22 is perforated, and contact pins are brought into contact with the inner conductor of the coaxial cable 22 without contacting the outer conductor. In the case of 10BASE2, the spurs are connected via a T-connector having a BNC port. Although the number of physical interfaces to the bus line is reduced to five, the known Ethernet bus topologies require a coaxial cable in each case, which has significant disadvantages especially in terms of cost, handling / carrying, and weight compared to twisted wire pairs when necessary. Additionally, connecting each network device to the bus line requires special junction boxes or at least T-connectors for the coaxial cable, which in turn incurs significant costs.
[0009] To make the use of Ethernet connections more attractive in other application areas, new variants of the Ethernet standard have been developed that provide a bandwidth of 10 Mbps over a single wire pair at the physical layer: IEEE standard 802.3cg-2019. One of the variants specified under this IEEE standard is called 10BASE-T1S, where S stands for short distance (short reach), and it can use a multi-point or bus topology in which all nodes are connected via a single two-core twisted pair. This eliminates the need to use switches, i.e., the number of physical interfaces is less than that of a system with switches, and coaxial cables are not required. The connection of the drop to the twisted pair cable can similarly be implemented passively in a simple and cost-effective manner. A variant with a long reach has been defined for distances up to 1 km - called 10BASE-T1L (L stands for long distance). This long-reach variant also uses point-to-point connections.
[0010] The 10BASE-T1S bus system can be used to interconnect at least eight network devices, where the maximum bus length is 25 m. A single network device can be connected to the bus line using a drop, with a maximum length of 10 cm for each drop. All nodes share a 10 Mbps bandwidth. Figure 3 A corresponding 10BASE-T1S network is illustrated by way of example, which has five network devices 12, 14, 16, 18, 20 connected via a shared communication medium 24 (such as a bus line formed by a twisted pair of cores). The dashed lines indicate the logical connections between the network devices, and the solid lines indicate the physical connections.
[0011] To ensure regulated access of individual network devices to the CBUS, the standard specifies an arbitration scheme that allows for the full utilization of the available bandwidth while reducing latency and improving quality of service (QoS). One possible arbitration scheme is called physical layer collision avoidance (PLCA), while another arbitration scheme called carrier sense multiple access / collision detection (CSMA / CD) can have a lower bus capacity utilization and can be used as a backup option, for example.
[0012] The CSMA / CD access method allows each network device to access the network in a transmission mode when no other network device is transmitting. The CSMA / CD access method does not include control measures to ensure that each network device in the network has the opportunity to transmit data within a specified time period, and this control measure must be carried out at a higher protocol level.
[0013] The PLCA access method is conceptually similar to the token ring method or time division multiple access (TDMA). The PLCA access method configures a node ID for each network device and sets the network device with node ID 0 as the PLCA coordinator. The coordinator initiates a communication cycle by transmitting an agreed sequence of data bits or octets (also called a beacon message or beacon frame). Other nodes use this beacon message to coordinate their clocks / clocks generators. The terms beacon message and beacon frame are used synonymously in this specification.
[0014] To determine when data transmission is allowed in the PLCA access method, each network device on the bus line "listens" and waits until the network device with a node ID one lower than its own finishes transmitting. The period following each transmission process of a network device is called the transmission opportunity or TO time window, and this transmission process can be marked as completed at the end of the transmission by an agreed sequence of data bits or octets. For example, the length of the TO time window can be 20 bits, that is, it can correspond to a period during which 20 bits can be transmitted at the nominal data rate of the data bus. Within this TO time window, the network device with a node ID one higher than the node ID of the network device that has just finished its transmission can start transmitting. Each node is allowed to send all its data, where each network device typically only sends one frame. However, a network device can also send multiple consecutive data frames in a so-called burst mode, where the communication medium is marked as still being occupied by the currently transmitting network device through a commit message sent between the corresponding data frames. If a network device is not transmitting and allows the TO time window reserved for it to elapse, then the next network device's TO time window follows. Thus, even in a cycle where not all network devices are transmitting, the coordinator can identify or assume the end of the cycle and can start a new cycle.
[0015] After the last network device has received and, if necessary, used the data transfer opportunity, the PLCA coordinator initiates the next cycle with another beacon message.
[0016] Access through PLCA achieves higher throughput than TDMA or token ring because network devices do not have to split their messages into multiple time slots. Additionally, the 20-bit transmission opportunity phase is shorter than a token packet. Since the nodes on the bus may or may not utilize their transmission opportunities, the duration of a complete transmission cycle cannot be accurately determined in advance.
[0017] Figure 4An example representation of messages sent by network devices in order of their node IDs via a shared communication medium is shown. The start of a transmission cycle is initiated by a corresponding bit sequence B (also referred to as a beacon). This is followed immediately by a TO time window during which the network device with the lowest node ID (node ID with value 0 in this example) that has also sent the beacon bit sequence can start sending its message. The TO time window is shaded in the figure. The TO time window of the next network device opens after the transmission of the current network device has ended. The network devices permitted to transmit can start transmitting immediately at the start of the TO time window or at any point within the TO time window. The TO time window can be started, for example, by a signal indicating the end of the transmission of a network device. This signal can be, for example, a frame end (EOF) signal. The end of the TO time window can be determined by a counter or a timer. If the network device permitted to transmit has not started transmitting within an agreed period (which corresponds to an agreed number of data bits sent at the nominal data rate of the shared communication medium), the TO time window ends. If the start of a transmission is recognized before the TO time window expires, signaled, for example, by a start of frame signal (SOF), the counter of the TO time window can be stopped. This process is repeated until the last network device has sent its message or its TO time window has been allowed to elapse. Then a new beacon bit sequence is sent, and a new transmission cycle is started using this new beacon bit sequence. The length or duration of each transmission cycle results from the length of the beacon bit sequence, the lengths of the messages sent by the individual network devices, and / or the TO time windows that are completely or partially unused, and can vary for different transmission cycles.
[0018] Although the network devices always listen to the communication on the CBUS to determine when they are permitted to transmit, no further checks are performed to determine whether the communication on the CBUS is operating error - free. Errors caused by an interruption of the communication medium or by transient faults that may interfere with the transmission of individual data packets cannot be recognized. Such errors can occur when the network is operating, for example, in a harsh environment with many sources of interference, due to an attack or due to a connection fault between the physical interface (PHY) and the microcontroller attempting to communicate via the interface.
[0019] Figure 5 is shown Figure 3 the network in which there is a fault in the connection between the processor and the network interface of network device 16. The physical connection between the network interface and the bus line 24 is fault - free. However, the data transmission of network device 16 may be incomplete or may fail completely. Figure 6 An example illustration of an error in the sequence of messages transmitted by individual network devices in order of their node IDs via a shared communication medium is shown. Except for an error in the message from node 2, this illustration basically corresponds to Figure 4The illustration in. This error can be, for example, that node 2 does not send at all, sends incompletely, or sends a random bit sequence due to a fault in the connection between the processor and the network interface. Such an error cannot be recognized at the access control level during normal operation and can only be recognized at a higher protocol level. In particular, this ability cannot always be provided in sensor networks where individual network devices offer little computing power and memory and must in addition be particularly cost-effective.
[0020] Figure 7 shows a network from Figure 3 that has an error affecting bus line 24, for example a temporary interference caused by an electromagnetic interference pulse. Here, the physical connection between the network interface and bus line 24 is also fault-free. Although the interference is shown as local in the figure, due to the short bus line length and low attenuation, the interference occurs more or less simultaneously at all interfaces, thus disturbing the correct reception of the data bits or octets of the message, for example in such a way that the signal level changes in a way that causes the value of one or more data bits to change, or in such a way that an overloading voltage level is applied to the receiver of the interface. Figure 8 shows an example illustration of an error in the message sequence sent by each network device in order of its node ID via a shared communication medium. In addition to the Figure 8 example illustration in which the beacon bit sequence is disturbed, for example by an electrical interference pulse or an electromagnetic interference pulse when the coordinator has sent the beacon bit sequence, this illustration is basically the same as the Figure 4 illustration in. Thus, network devices with a node ID greater than 0 may not recognize the start of a new transmission cycle and will not send their messages. Therefore, the coordinator may subsequently only recognize a TO time window unused by other network devices, and if the number of elapsed unused TO time windows is equal to the number of network devices connected via the shared communication medium, it will start a new transmission cycle. For the coordinator, Figure 8 the shown transmission cycle x + 1 is very short, but for other network devices, transmission cycle x is longer than that of the coordinator. Such a change cannot be reliably recognized at the OSI layers 1 and 2 of the communication link during normal operation, and as in the error example described in reference Figure 5 this change must be recognized at a higher protocol level and corrected if necessary. SUMMARY OF THE INVENTION
[0021] If the above-described type of network is used in a system that places high demands on the reliability and security of communication, such as a system having a plurality of network devices that communicate with each other in the context of partial or highly automated driving (wherein the plurality of network devices are interconnected via a shared communication medium), then frequent and ideally continuous integrity control of the communication is essential. In the context of this specification, the term "network device" encompasses all possible types of network devices, including networked sensors and network devices that process signals from networked sensors).
[0022] In order to be able to perform such integrity control even in the event of a severe error anywhere in the network, it is also desirable to be able to perform such integrity control independently of each other in as many network devices as possible, so that, for example, a switch to a safe mode can be made in response to an error. Since the hardware and computing power in many network devices are insufficient to continuously or quasi-continuously run complex control routines, and using a communication protocol with acknowledgment messages for received data reduces the available bandwidth for data transmission and causes additional latency, there is an urgent need for a simple but reliable integrity control of communication in a network in which a plurality of network devices communicate via a shared medium.
[0023] Accordingly, an object of the present invention is to provide a method for integrity control of communication in a network, which method has low requirements for computing power and can be executed in a decentralized manner.
[0024] This object is achieved by the method as defined in independent claim 1. Design options and improvement options of the method are specified in the dependent claims.
[0025] Another object of the present invention specifies a network device configured to execute the method according to the present invention or a design option or improvement option thereof. Further objects of the present invention relate to creating a system having at least one network device according to the present invention, as well as a computer program product and a computer-readable medium, which computer-readable medium provides the computer program product in a callable manner.
[0026] According to a first aspect of the present invention, a method for monitoring the communication integrity between a plurality of network devices, the plurality of network devices being connected via a shared communication medium and being able to send messages via the shared communication medium respectively within a transmission cycle initiated and ended by a first network device (also referred to as a coordinator), the method comprising listening to at least some parts of the communication on the communication medium within the transmission cycle.
[0027] A message sent by a corresponding network device can have any length, i.e., it can include one or more Ethernet frames, where the length of the one or more Ethernet frames can be between 64 bytes and 1518 bytes. In principle, so-called jumbo frames with a larger length can also be sent, where, in this case, all network devices networked via the communication medium must support these jumbo frames. If a network device sends multiple consecutive frames (also called burst mode), the network device can send a commit signal after sending one frame to signal to other network devices that another frame will follow immediately.
[0028] The start of a transmission cycle is marked by a sequence of data bits. The end of a transmission cycle can be indicated, for example, by a sequence of data bits marking the start of the next transmission cycle. Alternatively, the end of a transmission cycle can also be indicated by a sequence of data bits marking the end of the transmission of the last network device. The latter may require all network devices executing the method to know at least the number of network devices in the network, for example, through corresponding parameterization or through independent learning during operation.
[0029] Accordingly, listening includes at least identifying and / or evaluating data bits or sequences of data bits indicating the start and end of a transmission cycle, as well as identifying and / or evaluating data bits or sequences of data bits or octet / octet sequences indicating the start and end of the transmission of a network device. The start of the transmission of a network device can be identified by sending initial data bits within a TO time window. The protocol used can ensure that only one network device that is actually just due is transmitting. Listening also includes identifying and / or evaluating unused transmission opportunities of a network device within a transmission cycle. If at least one of the network devices in the network transmits messages in burst mode, listening also includes identifying and / or evaluating the sequence of data bits representing the commit signal. Network devices that also send messages in burst mode can, for example, inform this at network initialization, or if the number and type of network devices using the network of the system are known from the start and remain unchanged, corresponding configuration can be made in advance in the network devices.
[0030] Each network device on the network is assigned a unique node ID, typically a number in the range starting from 0 and ending with the number n of network devices on the network. The network device with the lowest node ID (i.e., node ID 0) is the first network device to initiate a transmission cycle (i.e., the coordinator), and moreover is the first network device allowed to transmit its data. Each network device implements a node ID counter that is reset to 0 at the start of each transmission cycle. The node ID counter can be a simple counter implemented in software. For each transmission made by a network device on a shared communication medium, e.g., at the end of the transmission, each network device increments its node ID counter by 1 and compares the counter value of the node ID counter with its own node ID. If the counter value of the node ID counter coincides with a network device's own node ID, then the network device itself is allowed to transmit via the shared communication medium after the previous transmission ends.
[0031] As previously mentioned, network devices do not necessarily have to transmit within a transmission cycle. Thus, identifying and evaluating unused transmission opportunities for network devices can include, for example, identifying and evaluating TO time windows. The TO time window has a predetermined duration, e.g., the duration required to transmit a predetermined number of data bits at the nominal data rate of the shared communication medium. After a transmission ends, e.g., after a sequence of data bits indicating the end of a data frame, there is a TO time window. Once no data bits indicating the start of a transmission of the currently allowed transmitting network device are identified throughout the entire duration of the TO time window (i.e., until the TO time window expires), each network device increments its node ID counter and waits during the new TO time window to see if it receives data bits, or if the value of the node ID counter corresponds to its node ID, to see if it itself makes a transmission via the communication medium.
[0032] For example, if a network device is not yet ready to send a message but is about to be ready, the network device can also send a submission message during the TO time window. In this case, other network devices wait until the end of the TO time window until the network device that has sent the submission signal has finished sending its message. The next network device with a node ID that coincides with the counter value can then make a transmission in the next TO time window.
[0033] According to the present invention, the method further includes determining the duration of a transmission cycle. The duration of the transmission cycle can be determined, for example, by measuring the time elapsed between two consecutive sequences of data bits indicating the start of the transmission cycle. If the end of the transmission cycle is signaled by a sequence of data bits marking the end of the transmission of the last network device, the time elapsed between the start of the transmission cycle and this sequence can be measured. Since the length of the transmission cycle can fluctuate depending on the number of network devices actually transmitting data and the number of data bits or octets transmitted by each network device, the duration of each individual transmission cycle is determined individually.
[0034] Further according to the present invention, the amount of data transmitted within the transmission cycle is determined, and the expected amount of data within the transmission cycle is calculated. Then the determined amount of data is compared with the calculated amount of data. Alternatively, the data rate can be determined using the measured duration of the transmission cycle and the amount of data transmitted via the communication medium during the transmission cycle, and this data rate is compared with the nominal data rate of the network. If the determined amount of data is in agreement with the calculated amount of data or the determined data rate is in agreement with the nominal data rate within a tolerance window, the method is repeated in subsequent transmission cycles. Otherwise, at least one of the network devices that has executed the method will switch to an error mode.
[0035] In error mode, the network device can take different measures according to the type and severity of the error. For example, error-related information can be stored locally in the network device, stored in a tamper-proof memory having a communication connection with the network device, and / or stored in the cloud. The log level (i.e., for example, the amount of data and the level of detail of the stored information) can also be increased as the case may be, such that additional data is available for error finding. Alternatively or additionally, the network device can establish its own communication via a shared communication medium, or notify the network device with the lowest node ID (which acts as a coordinator), such that the network device with the lowest node ID blocks further communication on the data bus if necessary. It is also feasible that if other network devices communicating via the shared communication medium do not themselves monitor the integrity of the communication via the shared communication medium, they can be notified of the existence of the error, such that these network devices can adjust their functions according to the error if necessary. It is also possible to fallback to another access mode (such as the CSMA / CD access mode of the shared communication medium) in response to the error. In the case of CSMA / CD (Carrier Sense Multiple Access / Collision Detection), communication is no longer carried out in the cycle initiated by the coordinator, and no beacon frames are sent. Instead, all network devices listen for possible communication on the communication medium, and if no other network device is transmitting at this time, they attempt to transmit. If a collision occurs, the network device will wait for a period of time, which is randomly generated, and then attempt to transmit again. This reduces the net data rate, but purely statistically, all participants still have a chance to transmit data. This transformation of access control must be communicated to all bus participants in an appropriate manner. For example, the network device with the lowest node ID can be notified for this purpose, and this network device then sends a corresponding message to other network devices. It is easy to understand that after switching to the error mode, monitoring using the method according to the present invention may no longer be possible, for example, if the CSMA / CD access method has been switched to.
[0036] If this method is executed for each transmission cycle, the integrity of the communication can be monitored continuously or quasi-continuously. If the end of the transmission cycle is signaled by the start of the subsequent transmission cycle, then listening has been initiated for the new transmission cycle, and the amount of data transmitted in the new transmission cycle is determined, while the expected amount of data for the previous cycle is calculated, and the determined amount of data is compared with the expected amount of data for the completed transmission cycle. Depending on the application scenario, sampling monitoring performed periodically or at irregular intervals may also be sufficient.
[0037] The method can also be performed over multiple transmission cycles, i.e., the amount of data transmitted and the expected amount of data can be determined over multiple transmission cycles. Similarly, the method can be performed over a time period shorter than one transmission cycle, even over parts of two consecutive transmission cycles. For example, the integrity of the communication can be monitored only for selected network devices. In this case, the "shortened transmission cycle" can be determined by a node ID counter. In principle, the determination of the amount of data transmitted can thus start within one transmission cycle and also end within that transmission cycle, or start within the first transmission cycle and end within a later, subsequent transmission cycle, i.e., not necessarily at the start and end of the transmission cycle.
[0038] Obviously, the data addressed to the network device executing the method and transmitted via the communication medium is not only used to determine the amount of data transmitted, but is also forwarded to a higher software layer for further processing.
[0039] According to one or more embodiments, determining the amount of data transmitted within a transmission cycle or determining the data rate includes counting all data bits or octets transmitted via the communication medium within the transmission cycle, including, if necessary, the data bits or octets transmitted by the network device itself executing the method, provided that the network device has sent a message within the transmission cycle. For example, if the network device executing the method is not configured to evaluate the communication at a higher layer of the OSI layer model, this embodiment can be used at layer 1 of the OSI layer model.
[0040] According to one or more embodiments, determining the amount of data transmitted within a transmission cycle or determining the data rate includes identifying the start and end of the transmission by the network device. The amount of data transmitted by the respective network device can be calculated by multiplying the time period between the start and end of the transmission by the nominal data rate of the shared communication medium. The calculated amounts of data of all network devices that have transmitted during the transmission cycle are added together.
[0041] According to one or more embodiments, determining the amount of data transmitted within a transmission cycle or determining the data rate includes evaluating the information contained in the individual transmissions of the transmission cycle, which is related to the number of data bits or octets transmitted in the respective transmission. If the network device executing the method has sent a message within the transmission cycle, the data bits or octets transmitted in the respective transmission may also include the data bits or octets transmitted by the network device itself. Depending on whether the information indicates the total number of data bits or octets transmitted or only the number of data bits or octets transmitted as payload, the number of data bits or octets can be corrected with the data bits or octets required by the communication protocol, including the data bits or octets sent to initiate and, if necessary, end the transmission cycle.
[0042] To determine the amount of data transmitted within a transmission cycle or to determine the data rate, it may be necessary to place the network interface of the network device performing the method in a special mode, in which the content of the transmission that is not sent to the network device is also evaluated. This mode is also referred to as the "promiscuous mode". Then, determining the number of data bits or octets transmitted may include evaluating the profile data transmitted in a higher protocol layer that is related to the amount of data sent during the transmission.
[0043] For example, the method for determining the amount of data transmitted within a transmission cycle or for determining the data rate or the type of data collected therefor may be selected based on the number of network devices interconnected via a shared communication medium, the maximum duration of the TO time window, and / or the duration of the data bit sequence or octet sequence indicating the start and end of the transmission cycle. For example, in one method, the explicit collection of one or more signal components (i.e., for example, the data bit sequence or octet sequence indicating the start and end of the transmission cycle, the duration of the unused TO time window, or the submission signal) may be excluded, while in another method, one or more of these signal components are explicitly collected together. Especially in the case where the number of network devices interconnected via a shared communication medium is small, it may be possible to select to collect only the data sent by the network device to determine the amount of data transmitted within the transmission cycle or to determine the data rate, because the maximum number of unused TO time windows or the number of data bits or octets that may have been sent during their time periods does not reach the shortest possible length of the transmission of the network device. However, if the number of network devices connected via a shared communication medium is large, or if one or more network devices send multiple data frames connected by a submission signal, it may also be necessary to collect the said signal components.
[0044] According to one or more embodiments, determining the amount of data transmitted within a transmission cycle or determining the data rate includes replacing the time period that has elapsed before the start of the transmission of the TO time window or the unused transmission opportunity of the network device with the number of data bits or octets that could have been transmitted during the elapsed time period or the duration of the TO time window. The number of bits that could have been transmitted theoretically before the network device actually starts transmitting or the number of data bits or octets that could have been transmitted during the TO time window can be calculated, for example, from the nominal transmission speed of the shared communication medium and the elapsed time. This number may also correspond to a predefined number of data bits that are considered as unused transmission opportunities for determining the amount of data transmitted within the transmission cycle, because it is during the unused TO time window that no data bits or octets are sent.
[0045] In one or more designs of the method, the node ID is permanently assigned to the network device before or during system debugging. However, it is also possible to reassign the node ID during operation, for example, periodically at fixed time intervals, so that network devices newly added to the network can be accessed, or to obtain an uninterrupted sequence of node IDs, for example, in the case where a network device has been removed from the network. The latter can be notified by the network device in the corresponding message, but can also be recognized, for example, if the network device has not used a predetermined number of TO time windows in consecutive transmission cycles. Instead of reassigning the node ID in the case where the network device has not used a predetermined number of TO time windows in consecutive transmission cycles, it is also possible to switch at least the network device executing the method to an error mode. The predetermined value can be different for each network device and can be notified by a broadcast message when the system is being debugged, or can be stored in a memory accessible by the network device executing the method.
[0046] According to one or more embodiments, calculating the expected data volume within a transmission cycle includes multiplying the cycle duration by the nominal data rate of the communication medium. This embodiment can be used especially in cases where the transmission cycles follow each other without significant delay.
[0047] According to a second aspect of the present invention, a network device includes one or more processors, volatile and non-volatile memories assigned to the processors, and a physical network interface communicatively connected to the one or more processors, the physical network being configured for transmitting and / or receiving via a communication medium shared by a plurality of network devices. The elements of the network device are interconnected by one or more data lines or data buses for communication. The non-volatile memory stores computer program instructions that, when executed by at least one processor, configure the network device to implement one or more embodiments of the method according to the present invention.
[0048] According to a third aspect of the present invention, a system, especially a vehicle system, includes two or more network devices interconnected via a communication medium shared by a plurality of network devices. According to the present invention, at least one of the network devices is configured to implement at least one embodiment of the method according to the present invention described above.
[0049] According to a fourth aspect of the present invention, a computer program product contains instructions that, when executed by a computer, cause the computer to implement one or more designs and improvements of the method described above.
[0050] The computer program product can be stored on a computer-readable medium or data carrier. The medium or data carrier can be physically embodied as, for example, a hard disk, CD, DVD, flash memory, etc.; however, the medium or data carrier can also include a modulated electrical signal, electromagnetic signal, or optical signal, which can be received by a computer through a corresponding receiver and can be stored in the computer's memory.
[0051] The method described above and the network device for executing the method can be advantageously implemented without changing the existing hardware and can be correspondingly integrated into the existing network, because the protocols already used do not need to be changed and the functions of the network are not affected by higher utilization or latency / jitter / waiting time.
[0052] Since the integrity of the communication channel is monitored during continuous operation, the operating safety of systems such as sensor networks and control units that control and execute actions based on sensor data can be improved, for example, in vehicles with high driver support or autonomous vehicles. Errors can be quickly identified and appropriate measures can be taken more quickly to resume safe operation or switch to a safe mode.
[0053] The method described above and the network device for executing the method can be independent of the platform and thus be used flexibly due to its simple and refined implementation. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] The present invention will be explained below by way of example with reference to the drawings. In the drawings:
[0055] Figure 1 An example of a network known from the prior art having four network devices connected via a switch is shown,
[0056] Figure 2 An example of a network known from the prior art having five network devices connected via 10BASE2 or 10BASE5 is shown,
[0057] Figure 3 An example of a network known from the prior art having five network devices connected via twisted pair / stranded wire cores is shown,
[0058] Figure 4 An exemplary illustration of messages sent in order of their node IDs by each network device via a shared communication medium is shown,
[0059] Figure 5 Shows a network from Figure 3 where an error has occurred in the network interface of one network device,
[0060] Figure 6Shows an exemplary illustration of an error in one network device in a sequence of messages sent by network devices via a shared communication medium in the order of their node IDs,
[0061] Figure 7 Shows a network from Figure 3 with an error affecting the bus line,
[0062] Figure 8 Shows an exemplary illustration of a transient interference affecting the bus line in a sequence of messages sent by respective network devices via a shared communication medium in the order of their node IDs,
[0063] Figure 9 Shows a schematic flowchart of the basic flow of the method,
[0064] Figure 10 Shows an exemplary schematic flowchart of listening to communications on a shared communication medium,
[0065] Figure 11 Shows an exemplary schematic flowchart of selecting one of two possibilities for determining the amount of data transmitted via a shared communication medium during a transmission cycle based on parameters of the shared communication medium and the network,
[0066] Figure 12 Shows an exemplary schematic flowchart of an alternative method of selecting one of two measurement methods for determining the amount of data transmitted via a shared communication medium during a transmission cycle based on parameters of the shared communication medium and the network when at least one network device sends messages in burst mode,
[0067] Figure 13 Shows an exemplary schematic flowchart of determining the integrity of communications during a transmission cycle,
[0068] Figure 14 Shows the first part of an exemplary schematic flowchart of a method for determining data bits or octets transmitted during a transmission cycle at the physical layer,
[0069] Figure 15 Shows the second part of an exemplary schematic flowchart of a method for determining the amount of data transmitted during a transmission cycle at the physical layer, and
[0070] Figure 16 Shows an exemplary block diagram of a network device configured to perform one or more aspects of the method according to the present invention.
[0071] In the drawings, the same or similar elements may be denoted by the same reference numerals.
[0072] The foregoing has been described Figures 1 to 8, so it will not be discussed further below. Detailed implementation manner
[0073] Figure 9 FIG. shows a schematic flowchart of the basic process of method 100. In step 110, the communication on the shared communication medium is listened to or monitored, wherein at least the data bit sequence or octet sequence indicating the start and end of the transmission of the network device is identified and evaluated, and the transmission opportunities not used by the network device within one transmission cycle are also identified and evaluated. Once the start of the transmission cycle is identified, the determination of its duration begins in step 120. For this purpose, for example, the time elapsed between two consecutive sequences of data bits indicating the start of the transmission cycle can be measured.
[0074] In parallel therewith, in step 130, the amount of data transmitted via the shared communication medium during the transmission cycle is determined, for example by counting the data bits or octets transmitted via the shared communication medium or in other ways. The data from the monitoring in step 110 can also be used here, as indicated by the separate arrow, for example, a special sequence of data bits or octets identified during the monitoring, which is used to control the transmission. In step 140, the expected amount of data within the transmission cycle is calculated. This can be done in particular based on the duration of the transmission cycle, the nominal data rate of the shared communication medium, and the number of network devices connected via the shared communication medium. For this purpose, the duration of the transmission cycle determined in step 120 is input, as indicated by the arrow.
[0075] In step 150, the integrity of the communication via the shared communication medium is checked. For example, the integrity is determined by comparing the calculated expected amount of data with the amount of data determined by monitoring the communication. The data rate can also be calculated based on the amount of data determined by monitoring the communication and the duration of the transmission cycle, and the data rate is compared with the nominal data rate of the shared communication medium. Here, a tolerance range can be used to suppress the inevitable measurement inaccuracies due to the lack of synchronization between network devices and the possibly slightly deviated transmission data rates of different network devices when determining the integrity.
[0076] Figure 10An exemplary schematic flowchart showing the listening or monitoring of communications on a shared communication medium in step 110 is shown. Between two sequences of data bits indicating the start and end of a transmission cycle, only useful data / payload data and signals for controlling the normal flow of communications of network devices are expected. A network device that can operate in a so-called promiscuous mode can not only listen to the address data of data packets not addressed to these network devices, but also listen to further content of the transmission, and at least count the number of data bits or octets of the transmission from transmissions not directed to these network devices. In step 111, data from the transmission is accordingly received, and in step 112, the length of the transmission, i.e., the number of data bits or octets, is determined or extracted. If the network device executing this method can also evaluate the content of transmissions not directed to this network device, such as information related to the transmission length contained in the header, then it is not necessary to count all the data bits or octets of the transmission. In this case, it is sufficient if the network device can identify the end of the transmission, for example, by receiving a signal indicating the end of the data frame (EOF) or another signal agreed upon in the protocol being used. If the transmission is directed to the network device executing this method (which is determined by the check in step 113), then in step 114, the received data bits or octets are also forwarded for further processing at a higher protocol layer. Otherwise, in step 115, data not required for determining the amount of data transmitted can be discarded, unless this data is used by the network device executing this method for other purposes. The listening or monitoring of communications on the shared communication medium is repeated at least until a signal indicating the end of the transmission cycle, i.e., the corresponding sequence of data bits, is received.
[0077] Figure 11Shows an exemplary schematic flowchart for selecting one of two possibilities for determining the amount of data to be transmitted via a shared communication medium during a transmission cycle based on parameters of the shared communication medium and the network. First, in step 1301, the number of network devices connected via the shared communication medium is determined. In step 1302, the number of data bits or octets in the data bit sequence representing the start of the transmission cycle and, if necessary, also the end of the transmission cycle is determined. And in step 1303, the number of data bits or octets corresponding to the TO time window is determined. For example, information related to the parameters (also referred to as signal components) of the protocol used for communication can be read from a configuration file that is accessible locally or via the network to all network devices executing the method. In step 1305, it is checked whether the total number of data bits or octets of the signal components is equal to or greater than the number of data bits or octets of the shortest possible transmission of the network device (e.g., the shortest length of a data frame). The total number is obtained from the sum of the number of data bits or octets in the data bit sequence representing the start of the transmission cycle and, if necessary, also the end of the transmission cycle, the product of the number of network devices connected via the shared communication medium and the number of data bits or octets representing the TO time window, plus the measurement inaccuracy. If the maximum possible total number of data bits or octets of the signal components is equal to or greater than the number of data bits or octets of the shortest possible transmission of the network device, then in step 1306, in addition to determining the number of data bits or octets transmitted in the message of the network device in step 1307, the number of data bits or octets of the signal components is also obtained.
[0078] Figure 12 Shows an alternative method of an exemplary schematic flowchart for selecting one of two measurement methods for determining the amount of data to be transmitted via a shared communication medium during a transmission cycle based on parameters of the shared communication medium and the network when at least one network device sends messages in burst mode. Steps 1301, 1302, and 1303 correspond to reference Figure 11The steps described. Additionally, in step 1304, the number of network devices that send multiple consecutive data frames in a message in burst mode is determined. If at least one network device sends in burst mode, a relatively large number of data bits or octets for signal components may occur within a single transmission cycle, especially since a network device can send up to 255 data frames consecutively in burst mode and sends an acknowledgment signal in response to each data frame sent, which notifies other network devices in the network that the network device currently actively accessing the communication medium will send additional data frames. The more additional data bits or octets for signal components are sent by network devices, the faster the sum of the data bits or octets of the signal components alone can reach or exceed the number of data bits or octets in the shortest possible message of a network device, making it necessary to also obtain the data bits or octets of the signal components and allow them to be included in the calculation of the number of data bits or octets transmitted or the data rate of the transmission cycle. In the check in step 1305, when determining the number of data bits or octets of the signal components, the product of the number of network devices sending in burst mode, the number of data bits or octets of the additional TO time window, and the maximum number of data packets in burst mode (i.e., 255) is added to the reference Figure 11 sum described in step 1305 thereof. If the extended sum minus the measurement inaccuracy is equal to or greater than the number of data bits or octets of the shortest possible transmission of a network device, then, as in the example described in reference Figure 11 , in step 1306, in addition to determining the number of data bits or octets transmitted in the message of the network device in step 1307, the number of data bits or octets of the signal components is also obtained.
[0079] Figure 13An exemplary schematic flowchart showing the steps of method 150 for determining the integrity of communication during a transmission cycle is presented. To this end, first, in step 151, the "actual bus load" is determined by subtracting the number of data bits or octets actually transmitted via the shared communication medium from the maximum number of data bits or octets that can be transmitted at the nominal data rate during the transmission cycle duration. In step 152, it is checked whether the actual bus load is positive. If not, that is, if more data bits or octets are transmitted during the period under consideration than theoretically possible, there must be an error of the first type, and the method follows the "no" branch into step 156, where the error is signaled and / or otherwise processed. Such an error may occur, for example, due to failure to recognize the end of the transmission cycle. If the actual bus load is positive, the method follows the "yes" branch, and next in step 153, it is checked whether the number representing the actual bus load is greater than the number of data bits or octets of the shortest possible transmission of the network device (e.g., the shortest length of a data frame). If not, the method follows the "no" branch into step 154, which may include, for example, waiting to determine the integrity of communication for the next transmission cycle. If the number representing the actual bus load is greater than the number of data bits or octets of the shortest possible transmission of the network device, at least one data frame has been lost, and the method follows the "yes" branch into step 155. In step 155, the second type of error is signaled and / or otherwise processed.
[0080] Figure 14 A first part of an exemplary schematic flowchart showing method 1100 for listening and method 1300 for determining the data bits or octets transmitted during a transmission cycle at the physical layer (i.e., layer 1 of the OSI layer model) is presented. For example, this method can be used if a network device executing the method according to the present invention does not support listening at layer 2 for communication not intended for the network device itself, i.e., cannot analyze layer 2 frames. In this method, the data bits or octets used for signaling are also directly obtained, i.e., for example, the start of the transmission cycle (beacon), the start of transmission (SOF), or the end of transmission (EOF) and the sequence of data bits or octets of continued occupancy (commit) are signaled.
[0081] If necessary, the network device executing the method can be initialized before the start of the method, where, for example, the number of data bits or octets of the message indicating the start or end of the transmission cycle, the number of network devices, and their characteristics are read from a database (not shown in the figure).
[0082] First, in step 1101, it is checked whether a data bit sequence or octet sequence indicating the start of a new transmission cycle has been received. If not, the method branches into the "No" branch of step 1101, and this check is repeated.
[0083] If a data bit sequence or octet sequence indicating the start of a new transmission cycle has been received, the method branches into the "Yes" branch on the one hand to the methods represented by steps 140 and 150, in which the expected data volume in the previous transmission cycle is calculated and the communication integrity of the previous cycle is checked. The following refers to Figure 15 the flowchart of an exemplary method 150 that can be used in the analysis on layer 1 of the OSI layer model. In step 1301a, the number of data bits or octets that may have been transmitted during the waiting for a data bit sequence or octet sequence indicating the start of a new transmission cycle is determined or obtained, and it is taken into account accordingly when checking the integrity of the communication, as indicated by the dashed arrow from step 1301a to step 140.
[0084] In parallel with the check of communication integrity, in step 1102, the corresponding counters for the network devices allowed to transmit next, the unused TO time window of the network devices, and the number of data bits or octets transmitted during the current transmission period are reset and started, and in step 1103, the timeout counter of the current TO time window is reset and started. In step 1104, it is checked whether all network devices have had the opportunity to transmit in the current transmission cycle, that is, whether the counter of the network devices allowed to transmit next has reached the value corresponding to the last network device in a group of network devices connected via a shared communication medium. If so, that is, if all network devices have had the opportunity to transmit messages during the current transmission cycle, the method follows the "Yes" branch from step 1104 back to step 1101, waiting for the start of the next transmission cycle. Otherwise, the method follows the "No" branch from step 1104 to step 1301, receiving and counting all data bits or octets transmitted on the shared communication medium.
[0085] In step 1302, the received sequence of data bits or octets is examined to determine whether they indicate the start of a transmission by the network device, e.g., whether they form a frame start signal, etc. If so, the method follows the "Yes" branch of step 1302, and in step 1303, it waits for a sequence of data bits or octets indicating the end of the transmission by the network device. In parallel with this, in step 1304, the received data bits or octets are examined to determine whether a sequence of data bits or octets indicating the start of a new transmission cycle has been received, rather than determining whether a sequence of data bits or octets indicating the end of the transmission has been received. If so (corresponding to the "Yes" branch of step 1304), an error must exist, and the method proceeds to step 1305. In step 1305, for example, the network device executing the method can switch to an error mode and / or the network device can report the identified error via the network.
[0086] In step 1303, if a sequence of data bits or octets indicating the end of the transmission by the network device is received (corresponding to the "Yes" branch of step 1303), then in step 1306, the counter of the network device allowed to transmit next is incremented, and the method proceeds to step 1104. As already described above, in step 1104, a check is performed to determine whether all network devices have had the opportunity to transmit in the current transmission cycle. If not, the method part starting from step 1301 for the next network device is continued.
[0087] If the check in step 1302 does not find a data bit sequence or octet sequence indicating the start of transmission of a network device, the method follows the "No" branch of step 1302 and checks in step 1307 whether the received data bit sequence or octet sequence indicates the start of a transmission cycle. If so (corresponding to the "Yes" branch of step 1304), there must be an error because not all network devices connected via the shared communication medium have had the opportunity to send a message or at least allow their respective TO time windows to elapse, and the method proceeds to step 1305. In step 1305, as already described above, the network device executing the method can switch to, for example, an error mode and / or the network device can report the identified error via the network. If no data bit sequence or octet sequence indicating the start of a transmission cycle is recognized in step 1307 (corresponding to the "No" branch of step 1304), then in step 1308 it is checked whether the timeout counter for the current TO time window has expired / run out. If not (corresponding to the "No" branch of step 1308), then continue to receive or wait during the period when the shared communication medium is not in use (i.e., idle) until the timeout counter has expired to see whether a data bit or data bit sequence or octet sequence marking the start of transmission has been recognized (i.e., whether a network device has started transmitting).
[0088] If the timeout counter for the current TO time window has expired (corresponding to the "Yes" branch of step 1308), then in step 1309, increment the counter for the unused TO time window of the network device, and the method proceeds to step 1308.
[0089] All data bits or octets received during this period (including data bit sequences or octet sequences indicating the start or end of transmission) are counted by step 1301, which runs in parallel with the check of the received data bits or octets. The number of data bits or octets that may have been sent by the network device between the start of the TO time window and the start of transmission is added at this time to the number of data bits or octets sent via the shared communication medium, or is added to that number later when checking the integrity of the communication.
[0090] The data bits or octets determined for the network device executing the method are forwarded to a higher protocol layer (not shown in the figure).
[0091] The amount of data sent or determined for the network device currently allowed access to the shared communication medium using the method described above is added to the amount of data that has been sent or determined for other network devices during the current transmission cycle.
[0092] Figure 15An exemplary flowchart showing steps for determining the duration of a transmission cycle and for checking communication integrity within the transmission cycle is shown. In step 120, the time elapsed between receiving a data bit sequence or octet sequence indicating the start of a transmission cycle and receiving a data bit sequence or octet sequence indicating the end of the transmission cycle is calculated. As already mentioned above, the end of a transmission cycle can also be signaled by the start of the next transmission cycle. For example, for the calculation, a timer can be used which starts at the start of the transmission cycle and stops at the end of the transmission cycle. It is also possible to write the system time into memory at the start and end of the transmission cycle and calculate the duration of the transmission cycle therefrom. Other ways known to those skilled in the art for determining the duration of a transmission cycle are also conceivable and are not explained in detail here.
[0093] Then, in step 140, the expected data volume within the transmission cycle is calculated. This can be done, for example, based on the duration of the transmission cycle and the nominal data rate of the shared communication medium.
[0094] In step 150, the data volume transmitted via the shared communication medium during the transmission cycle, which was determined in step 130 running in parallel with the determination of the duration of the transmission cycle, is compared with the expected data volume calculated in step 140. If the data bits or octets that could theoretically be transmitted during the unused TO time window were not taken into account when determining the transmitted data bits or octets, they are determined in step 1399 by multiplying the number of network devices that have not yet transmitted by the number of data bits or octets that could theoretically be transmitted during the TO time window and added to the actually received data bits or octets. If the comparison shows that the expected data volume within the transmission cycle is consistent with the actually transmitted data volume (within the specified tolerance window if necessary) (corresponding to the "yes" branch of step 150), the communication integrity during the checked transmission cycle is confirmed and the method can be repeated for the next transmission cycle. If the comparison shows that more or fewer data bits or octets are transmitted within the transmission cycle than could theoretically be transmitted (corresponding to the "no" branch of step 150), the integrity of the communication via the shared communication medium is not confirmed and the network device executing the method can be switched to an error mode and / or the check result can be forwarded to other network devices. Depending on whether more or fewer data bits or octets were transmitted than expected, the network device can be switched to different error modes. Possible error modes can include using different methods to access the shared communication medium (such as CSMA / CD), extended logging of communication via the shared communication medium, switching the system to secure operation, transmitting one or more messages to a remotely located system, etc.
[0095] Figure 16An exemplary block diagram of a network device 400 configured to perform one or more aspects of the method according to the present invention is shown. In addition to the microprocessor 402, the network device 400 further includes a volatile memory 404, a non-volatile memory 406, and a communication interface 408. The elements of the network device are communicatively interconnected via one or more data links or data buses 410. The non-volatile memory 406 contains computer program instructions that, when executed by the microprocessor 402, configure the network device to implement at least one design of the method according to the present invention.
[0096] List of reference numerals:
[0097]
Claims
1. A method (100) for monitoring the integrity of communications between a plurality of network devices (12, 14, 16, 18, 20) connected via a shared communication medium (24), the plurality of network devices being capable of transmitting messages via the shared communication medium (24) respectively within a transmission cycle initiated by a first network device, the method comprising: - Monitoring (110) at least some parts of the communications on the communication medium within a transmission cycle, wherein the monitoring (110) at least includes identifying and / or evaluating data bits or sequences of data bits or sequences of octets indicating the start and end of the transmission cycle, and wherein the monitoring further includes identifying and / or evaluating transmission opportunities not used by the network devices within a transmission cycle, wherein the method is characterized by the following steps: - Determining (120) the duration of a transmission cycle, - Determining (130) the amount of data transmitted within the transmission cycle or the data rate achieved by the transmission cycle, - Calculating (140) the expected amount of data within the transmission cycle, - Comparing the determined amount of data with the expected amount of data or comparing the determined data rate with the nominal data rate of the communication medium (150), wherein if the determined amount of data is consistent with the expected amount of data within a predetermined tolerance or the determined data rate is consistent with the nominal data rate within a predetermined tolerance, the method is re-executed for the next transmission cycle, otherwise at least one network device executing the method is switched to an error mode.
2. The method (100) according to claim 1, wherein, Determining (130) the amount of data or data rate transmitted within a transmission cycle includes: counting all data bits or octets transmitted via the communication medium (24) within a transmission cycle, especially including the data bits or octets transmitted by a network device itself executing the method.
3. The method (100) according to claim 1, wherein, Determining (130) the amount of data or data rate transmitted within a transmission cycle includes: identifying the start and end of a transmission of a network device, wherein the amount of data transmitted by a corresponding network device is calculated by multiplying the time period between the start and end of the transmission by the nominal data rate of the shared communication medium, and wherein the calculated amounts of data of all network devices that have made transmissions during a transmission cycle are added together.
4. The method (100) according to claim 1, wherein, Determining (130) the amount of data or data rate transmitted within a transmission cycle includes: evaluating information related to the number of data bits or octets transmitted in respective transmissions within a transmission cycle, and the data bits or octets transmitted in the respective transmissions especially include the data bits or octets transmitted by a network device itself executing the method.
5. The method (100) according to one of the preceding claims, wherein, Determining the amount of data or data rate transmitted within a transmission cycle includes: replacing the time period of the TO time window elapsed before the start of a transmission or a transmission opportunity not used by a network device with the number of data bits or octets that could be transmitted during the elapsed time period or the duration of the TO time window.
6. The method (100) according to one of the preceding claims, wherein, Calculating the expected amount of data within a transmission cycle includes multiplying the cycle duration by the nominal data rate of the communication medium.
7. A network device (400) configured to communicate via a communication medium (24) shared by a plurality of network devices, the network device having at least one processor (402), volatile memory (404), non-volatile memory (406), and a network interface (408), wherein, The non-volatile memory (406) stores computer program instructions that are callable and, when executed by the at least one processor, configure the network device (400) to perform the method according to any one of claims 1 to 6 for monitoring communication integrity.
8. A system, in particular a vehicle system, having two or more network devices interconnected via a communication medium shared by the plurality of network devices, wherein, At least one of these network devices is a network device according to claim 7.
9. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the method according to one or more of claims 1 to 6.
10. A computer-readable medium having stored thereon the computer program product according to claim 9.