Data transmission method based on high-integrity AFDX network
By adding MIH fields and CRC fields to the AFDX network, data integrity verification from the transmission layer to the data link layer is achieved, solving the problem of untrustworthy data transmission in the AFDX network, and improving the integrity and reliability of data transmission.
Patent Information
- Application Number
- CN202510505652.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-07-25
AI Technical Summary
The standard AFDX network protocol cannot provide the guarantee of trusted data transmission between the application layer and the data link layer, and there is a possibility of data exchange errors, resulting in system errors.
Add message integrity header MIH field and two 16-bit CRC fields to the transmission layer of the AFDX network. Through source integrity, bit integrity, sequential integrity and time integrity design, the error correction capability of data transmission is improved and the trusted transmission of data is ensured.
It improves the integrity of data transmission, reduces the probability of error data, provides high integrity AFDX data transmission capabilities, and only requires modification of existing protocols through software, with low cost and good compatibility.
Smart Images

Figure CN120378052A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of system network design, and particularly relates to a data transmission method based on a high-integrity AFDX network. Background Art
[0002] AFDX (Avionics Full Duplex Switched Ethernet) is a deterministic network dedicated to data exchange between avionics subsystems specified by a bus communication protocol specification based on a mature commercial Ethernet. It enhances the adaptability to different environments and devices on the basis of the original protocol, introduces concepts such as virtual link (Virtual Link) and BAG to establish a logically one-way connection from a source terminal to one or more destination terminals. By effectively dividing bandwidth resources, it realizes time-division multiplexing of bandwidth and the real-time and deterministic nature of data transmission, and has greatly improved performance compared with traditional Ethernet. More and more avionics systems of various models adopt the AFDX network as the main data transmission network.
[0003] The standard AFDX network protocol provides the ability to transmit general integrity data by adding CRC checks in the MAC frames of the data link layer, but it cannot provide the guarantee of trustworthy data transmission between the application layer and the data link layer in the protocol stack. The data exchange between layers is un-checked raw data, which may introduce errors, and ultimately there may be undetected errors between the AFDX data communication end systems, causing system errors. Summary of the Invention
[0004] The present invention proposes a data transmission method based on a high-integrity AFDX network. By designing around the source integrity, bit integrity, sequence integrity, and time integrity of the data integrity of the entire protocol stack for end-to-end communication of AFDX, the error correction ability of the entire data transmission path is improved, and the probability of occurrence of error data is reduced, thereby providing a high-integrity AFDX data transmission ability for the system.
[0005] The first aspect of the present invention proposes a data transmission method based on a high-integrity AFDX network, including:
[0006] Step 1: Generate application data to be sent;
[0007] Step 2: At the transport layer, add a message integrity header MIH field at the front end of the application data and add two 16-bit CRC fields at the end of the application data to obtain a high-integrity data packet;
[0008] Step 3: The data link layer sends the high-integrity data packet;
[0009] Among them, the MIH field includes: a 2-byte message sequence number MSN and a 6-byte source timestamp STS. The MSN identifies the transmission sequence number of the current frame at the application layer; the STS field identifies the local time RLT of the end system when the data frame is sent at the physical layer interface; two 16-bit CRC fields are calculated using two different polynomials; the two 16-bit CRC fields carry the source identifier SID.
[0010] Optionally, among the 48 bits of the source timestamp STS, the lower 47 bits are valid, and the highest bit is reserved and set to 0.
[0011] Optionally, before step one, the method further includes:
[0012] At the sending host, add CRC-A check bits to the unencapsulated application data, perform CRC-A calculation by the application data sending port, perform CRC-A check on the sending end system, and only continue the subsequent sending process for the application data that passes the check;
[0013] At the receiving host, add CRC-B check bits to the decapsulated application data, perform CRC-B calculation by the end system, perform CRC-B check at the application data receiving port, and only submit the data that passes the check to the application layer.
[0014] The second aspect of the present invention provides a data transmission method based on a high-integrity AFDX network, including:
[0015] Receive a data packet at the link layer and unpack it at the UDP layer to obtain a high-integrity data packet to be checked;
[0016] Obtain the MSN, STS, CRC, and application data fields in the high-integrity data packet;
[0017] Perform source, sequence, and time integrity checks based on the MSN, STS, CRC, and application data fields, and the pre-configured source ID to obtain the application data.
[0018] Optionally, performing sequence integrity check based on the MSN, STS, CRC, and application data fields, and the pre-configured source ID includes:
[0019] S1. Determine whether the source timestamp STS of the data frame received this time is greater than the source timestamp PSTS of the data frame received last time; if so, go to S7; if so, go to S2;
[0020] S2. Determine whether the source timestamp STS of the data frame received this time is equal to the source timestamp PSTS of the data frame received last time; if so, go to S3; if not, go to S4;
[0021] S3. Determine whether the MSN is within a valid time window; if so, go to S7; if not, go to S4;
[0022] S4. Determine whether the TOS is known; if so, go to S5; if not, go to S6;
[0023] S5. The sequential integrity check fails, discard the data frame;
[0024] S6. The sequential integrity check fails, discard the data frame, and update the PSTS and PMSN;
[0025] S7. The sequential integrity check passes, update the PSTS and PMSN;
[0026] Wherein, TOS represents the time deviation between the receiving end and the sending end.
[0027] Optionally, determining whether the MSN is within a valid time window includes:
[0028] Determine whether the MSN is within [PMSN + 1, PMSN + 8].
[0029] Optionally, the TOS is obtained from a time deviation list sent by the management end in the system;
[0030] The time deviation list contains the time deviations between each agent end and the management end;
[0031] The management end is used to calculate the deviation by sending a processing time request to each agent end and receiving the response feedback from the agent end.
[0032] Optionally, time integrity check is performed according to MSN, STS, CRC, and the application data field, and the pre-configured source ID, including:
[0033] S81. Determine whether the TOS is known; if so, go to S82; if not, go to S87;
[0034] S82. Obtain the Age of the high-integrity data packet according to STS, TOS, and the local time DTS;
[0035] S83. Determine whether the Age is greater than Dmin; if not, go to S87; if so, go to S84;
[0036] S84. Determine whether the Age is greater than Dmax; if not, go to S85; if so, go to S86;
[0037] Wherein, Dmin is the preset minimum message Age; Dmax is the preset maximum message Age;
[0038] S85. Confirm that the time integrity check passes and obtain the application data;
[0039] S86. Confirm that the time integrity check fails and discard the data frame;
[0040] S87. Confirm that the time integrity check passes, set the Age of the high-integrity data packet to 0, and obtain the application data.
[0041] The present invention provides a data transmission method based on a high-integrity AFDX network. By adding a message integrity header MIH field and two 16-bit CRC fields to the data transmitted between the application layer and the data link layer, where the MIH field is composed of a 2-byte message sequence number MSN and a 6-byte source timestamp STS. The MSN identifies the transmission sequence number of the current frame at the application layer, completes the verification of data source integrity and bit integrity, and provides the credibility of the data. By referring to the IEEE1588PTP protocol to solve the time synchronization requirement, it provides the verification ability of packet time integrity and sequence integrity, thus providing guarantee for the high data security requirement of the system. This method only needs to modify the existing standard AFDX protocol through software, and has the characteristics of low cost and good compatibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 Design of high-integrity application data format;
[0043] Figure 2 Implicit transmission of source ID identification (source integrity);
[0044] Figure 3 Schematic diagram of bit integrity design;
[0045] Figure 4 Design of sequence integrity function;
[0046] Figure 5 Basic idea of time synchronization;
[0047] Figure 6 Design of time integrity function;
[0048] Figure 7 Receiving of high-integrity data;
[0049] Figure 8 Receiving process of high-integrity data;
[0050] Figure 9 Redundancy management of high-integrity data. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0052] The features and illustrative embodiments of various aspects of the present invention will be described in detail below. In the following detailed description, numerous specific details are set forth in order to provide a comprehensive understanding of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced without some of these specific details. The description of the embodiments is merely provided to better understand the present invention by way of illustrating examples of the present invention. The present invention is in no way limited to any specific arrangements and methods set forth below, but covers any improvements, substitutions and modifications of structures, methods and devices without departing from the spirit of the present invention. Well-known structures and technologies are not shown in the drawings and the following description to avoid unnecessarily obscuring the present invention.
[0053] It should be noted that, without conflict, the embodiments of the present invention and the features in the embodiments may be combined with each other, and the various embodiments may refer to and cite each other. The present invention will be described in detail below with reference to the drawings and in combination with the embodiments.
[0054] The present invention will be further described in detail below in combination with the embodiments and the accompanying drawings, but the embodiments of the present invention are not limited thereto.
[0055] Please refer to Figures 1-9 , the present invention provides a data transmission method based on a high-integrity AFDX network.
[0056] The present invention focuses on four aspects of the source integrity, bit integrity, sequence integrity and time integrity of the high integrity of the end system, and conducts specific designs on the high-integrity communication mode, frame format, time synchronization algorithm and integrity check, etc., to ensure the realization of the integrity function of the end system. The specific contents include the following:
[0057] a) High-integrity frame format
[0058] The present invention first redefines the AFDX network application data format, adds relevant fields to the application data to protect the data to improve data integrity, and the high-integrity application data format design is as Figure 1 shown.
[0059] As Figure 1As shown, for a standard AFDX network, the maximum length of its application data is 8192 bytes. For a high-integrity AFDX network, a Message Integrity Header (MIH) field and two 16-bit CRC fields are added to the application data. The MIH field consists of a 2-byte Message Sequence Number (MSN) and a 6-byte Source Timestamp (STS). The MSN identifies the transmission sequence number of the current frame at the application layer.
[0060] The STS field identifies the Local Time (RLT) of the end system at the physical layer interface when the data frame is sent. The lower 47 bits of the 48-bit STS are valid, and the highest bit is reserved and set to 0. The two 16-bit CRCs, CRC-X and CRC-Y, are calculated from two different polynomials to ensure the bit correctness of the application message.
[0061] As Figure 1 shown, since an additional 12-byte overhead is added to the application data, the maximum length of the application data for high-integrity network data communication becomes 8180 bytes. For sampling ports, since IP fragmentation is not supported, the maximum application data length is 1459 bytes.
[0062] b) Source Integrity Design
[0063] Source integrity ensures the correctness of the data source in the network. For a high-integrity AFDX network, a unique 32-bit Source ID (SID) is defined for each end system during configuration. The SID is implicitly transmitted and included in the CRC field. This implicit transmission mechanism is used to ensure the source integrity of message transmission. The implicit transmission mechanism of the SID for source integrity is as Figure 2 shown.
[0064] As Figure 2 shown, the 32-bit SID is not included in the message transmission frame format. However, when calculating the CRC of the message transmission frame, the SID field needs to be included in the calculation to ensure that both CRC-X and CRC-Y contain the SID information. At the message receiving end, the CRC needs to be verified by combining the source ID of the message known locally with the received message MSN, STS, and application data fields. If the verification is successful, it proves that the message comes from the correct source end. If the verification fails, the receiving end system considers that the received message SID does not match the local configuration, and the source integrity verification fails.
[0065] c) Bit Integrity Design
[0066] Bit integrity design ensures the correctness of application data during the entire transmission process from the sending host to the receiving host, mainly achieved by adding CRC checks to the application message fields. To ensure message integrity throughout the process, CRC is added at each stage to ensure message correctness. The preliminary design of bit integrity for end systems is as Figure 3 shown.
[0067] Figure 3 In it, CRC-A and CRC-B are not included in the data frame format. CRC-A ensures the correctness of application data during the copying process from the application data sending port to the sending end system. The CRC is calculated by the sending port and copied to the sending end system together with the application message. CRC verification is performed on the sending end system, and only the data that passes the verification continues the subsequent sending process;
[0068] CRC-B ensures the correctness of application data during the copying process from the receiving end system to the application data receiving port.
[0069] The bit integrity of physical link data is ensured by highly integrity CRC-X / CRC-Y and the FCS field check at the link layer.
[0070] d) Sequential integrity
[0071] Sequential integrity ensures the correct order of data transmission in the network, implemented at the receiving end through the timestamp STS and sequence number MSN included in the data frame format in the highly integrity design. The sequential integrity function is implemented through sequential integrity checks. The sequential integrity check process is as Figure 4 shown.
[0072] As Figure 4 shown, the sequential integrity function needs to maintain the source timestamp PSTS and sequence number MSN information of the last received data frame. Only highly integrity data frames that meet any one of the following two conditions can pass the sequential integrity function check, update PSTS and MSN, and correctly receive the data:
[0073] 1) The source timestamp of the data is greater than the timestamp of the previous frame of data (STS > PSTS);
[0074] 2) The source timestamp of the data is equal to the timestamp of the previous frame of data, and the data sequence number is within the valid time window ([PMSN + 1, PMSN + 8]);
[0075] For other data frames that do not meet the above conditions, the sequence integrity check fails and the data frames are discarded. For the case where TOS (time offset between the end system and other end systems in the network: Time Offsets, which needs to be obtained through the time synchronization function) is unknown, PSTS and PMSN are updated. For the case where TOS is known, the currently received data frame is directly discarded.
[0076] e) Time synchronization design
[0077] The time synchronization algorithm draws on the idea of IEEE1588 PTP protocol and calculates the time deviation of different nodes in the network through interactive message transmission to achieve relative time synchronization of nodes in the network. Its basic idea is shown in the figure.
[0078] like Figure 5 As shown in the figure, the time synchronization algorithm consists of a time agent and a time management end. The management end initiates a time request, and the agent end responds to the time. Through the request and response mechanism, the management end can obtain four time points T1-T4. Through the four time points, the time deviation and transmission delay of the agent and the management end can be calculated according to the formula in the figure. The management end calculates the time deviation of all time agents and sends it back to each agent. After receiving the time deviation list, the agent calculates the time deviation TOS between itself and other agents based on the time deviation of all agents with the management end, which serves as the basis for time integrity judgment.
[0079] f) Time integrity design
[0080] pass Figure 5 The time synchronization algorithm shown in the figure establishes relative time synchronization between each end system in the network and other end systems, and maintains the time deviation TOS with other end systems in the network. Based on TOS, the time integrity of the end system is judged. The time integrity check function is as follows: Figure 6 shown.
[0081] The time integrity check is performed after the sequence integrity check. The time integrity function ensures that network data reaches the receiving end within the specified delay range. Therefore, during configuration, it is necessary to configure the maximum acceptable message transmission delay Dmax for high-integrity data communication, and perform a time integrity check using the data life cycle Age (DTS-STS+TOS) and Dmax. As shown in the figure, for data with Age greater than Dmax, the time integrity check fails and the data frame is discarded; for data with Age not greater than Dmax, the time integrity check succeeds and the data is received; if Dmax is not configured or the time offset TOS has not been calculated, the data is received, but its message Age needs to be set to unknown.
[0082] High-integrity data receiving process of the present invention:
[0083] As Figure 7 shown, the integrity check and redundancy management of high-integrity data reception are completed after unpacking at the UDP layer. The integrity check of high-integrity data includes four aspects: bit, source, sequence, and time, while the reception of ordinary integrity data mainly performs sequence integrity check based on the SN number at the link layer. The high-integrity data receiving process is as Figure 8 shown.
[0084] As Figure 8 shown, after the link layer processing is completed in high-integrity data reception, a reception timestamp is set for each data, and this timestamp is used for time integrity check of the data. The integrity check of high-integrity data is based on the application port, and integrity check and redundancy management work are carried out at the application layer. The redundancy management of high-integrity data is similar to that of ordinary integrity, but with certain extensions, and its process is as Figure 9 shown.
[0085] As mentioned above, it is only a further embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the scope disclosed by the present invention, according to the technical solution and its concept of the present invention, makes equivalent substitutions or changes, all belong to the protection scope of the present invention.
Claims
1. A data transmission method based on a high-integrity AFDX network, characterized in that, It includes: Step 1: Generate the application data to be sent; Step 2: At the transport layer, add a Message Integrity Header (MIH) field at the front end of the application data and add two 16-bit CRC fields at the end of the application data to obtain a high-integrity data packet; Step 3: The data link layer sends the high-integrity data packet; Among them, the MIH field includes: a 2-byte Message Sequence Number (MSN) and a 6-byte Source Timestamp (STS). The MSN identifies the transmission sequence number of the current frame at the application layer; the STS field identifies the local time (RLT) of the end system when the data frame is sent at the physical layer interface; the two 16-bit CRC fields are calculated using two different polynomials; the two 16-bit CRC fields carry the Source Identifier (SID).
2. The data transmission method based on a high-integrity AFDX network according to claim 1, wherein Among the 48 bits of the source timestamp STS, the lower 47 bits are valid, and the highest bit is reserved and set to 0.
3. The data transmission method based on a high-integrity AFDX network according to claim 1, characterized in that Before Step 1, the method further includes: At the sending host, add CRC-A check bits to the unencapsulated application data, perform CRC-A calculation by the application data sending port, perform CRC-A check on the sending end system, and only continue the subsequent sending process for the application data that passes the check; At the receiving host, add CRC-B check bits to the decapsulated application data, perform CRC-B calculation by the end system, perform CRC-B check at the application data receiving port, and only submit the data that passes the check to the application layer.
4. A data transmission method based on a high-integrity AFDX network, characterized in that, It includes: Receive the data packet at the link layer and unpack it at the UDP layer to obtain the high-integrity data packet to be checked; Obtain the MSN, STS, CRC, and application data fields in the high-integrity data packet; Perform source, sequence, and time integrity checks based on the MSN, STS, CRC, and application data fields, and the pre-configured source ID to obtain the application data.
5. The data transmission method based on a high-integrity AFDX network according to claim 4, wherein Performing sequence integrity check based on the MSN, STS, CRC, and application data fields, and the pre-configured source ID includes: S1: Determine whether the source timestamp STS of the data frame received this time is greater than the source timestamp PSTS of the data frame received last time; if so, go to S7; if not, go to S2; S2: Determine whether the source timestamp STS of the data frame received this time is equal to the source timestamp PSTS of the data frame received last time; if so, go to S3; if not, go to S4; S3: Determine whether the MSN is within the valid time window; if so, go to S7; if not, go to S4; S4: Determine whether the TOS is known; if so, go to S5; if not, go to S6; S5: The sequence integrity check fails, discard the data frame; S6: The sequence integrity check fails, discard the data frame, and update PSTS and PMSN; S7: The sequence integrity check passes, update PSTS and PMSN; Among them, TOS represents the time deviation between the receiving end and the sending end.
6. The data transmission method based on a high-integrity AFDX network according to claim 5, wherein Determining whether the MSN is within the valid time window includes: Determining whether the MSN is within [PMSN + 1, PMSN + 8].
7. The data transmission method based on a high-integrity AFDX network according to claim 5, characterized in that The TOS is obtained through the time deviation list sent by the management end in the system; The time deviation list contains the time deviations between each agent end and the management end. The management terminal is used to calculate the deviation by sending a processing time request to each agent terminal and receiving the response feedback from the agent terminal.
8. The data transmission method based on a high-integrity AFDX network according to claim 6, characterized in that Time integrity check is performed according to the MSN, STS, CRC, and application data fields, as well as the pre-configured source ID, including: S81. Determine whether the TOS is known. If so, proceed to S82; if not, proceed to S87. S82. Obtain the Age of the high-integrity data packet based on the STS, TOS, and local time DTS. S83. Determine whether the Age is greater than Dmin. If not, proceed to S87; if so, proceed to S84. S84. Determine whether the Age is greater than Dmax. If not, proceed to S85; if so, proceed to S86. Among them, Dmin is the preset minimum message Age; Dmax is the preset maximum message Age. S85. Confirm that the time integrity check passes and obtain the application data. S86. Confirm that the time integrity check fails and discard the data frame. S87. Confirm that the time integrity check passes and set the Age of the high-integrity data packet to 0 to obtain the application data.