Clock synchronization method and device, electronic equipment and storage medium
By moving the clock synchronization algorithm to the first node in the vehicle network system and providing precision calibration agent services, the problems of hardware dependence and insufficient security in the existing technology are solved, and high-precision and secure clock synchronization is achieved. It is suitable for cross-chip and cross-board clock synchronization in vehicle network systems.
Patent Information
- Application Number
- CN202510942986.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-09-16
AI Technical Summary
In existing vehicle network systems, clock synchronization methods based on IEEE1588 or IEEE802.1AS protocols rely on hardware support, resulting in reduced synchronization accuracy in hybrid network environments and a lack of security mechanisms, making it difficult to achieve high-precision clock synchronization across chips and boards.
Move the clock synchronization algorithm to the first node, provide precision calibration agent services, generate clock information and precision calibration information that match the second node, reduce dependence on hardware, and ensure the security and accuracy of the synchronization process through identity authentication and calibration modules.
It achieves high-precision clock synchronization across chips and boards, reduces functional abnormalities caused by clock deviation, and improves the clock synchronization accuracy and security of the entire vehicle system.
Smart Images

Figure CN120658343A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle-mounted communication technology, and in particular to a clock synchronization method, device, electronic device, and storage medium. Background Art
[0002] With the continuous development of intelligent and networked vehicles, the proportion of vehicles equipped with Ethernet technology has gradually increased. In the vehicle network system, especially the assisted driving system, the synchronization and real-time performance of the clocks of each controller in the network are relatively high. At present, the clock synchronization between the controllers in the vehicle is usually based on the IEEE1588 or IEEE802.1AS protocol (also known as gPTP, generalized Precision Time Protocol). However, in the application scenario of automotive hybrid networks, as the number of transmission links increases, the synchronization accuracy gradually decreases, and it is necessary to rely on the hardware of each controller passing through the link to support the IEEE1588 or IEEE802.1AS protocol. Summary of the Invention
[0003] The embodiments of the present application provide a clock synchronization method, device, electronic device and storage medium, aiming to improve the technical problem that the clock synchronization method provided in the related art needs to rely on hardware support.
[0004] In a first aspect, an embodiment of the present application provides a clock synchronization method, which is applied to a first node in an in-vehicle network system, wherein the in-vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources, the multiple master clock nodes being sorted according to clock priority, and the first node being the node with the highest clock priority among the multiple master clock nodes; the method comprising:
[0005] Receive a clock subscription request sent by a second node, where the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node;
[0006] In response to the clock subscription request, acquiring clock information, and determining, based on the node information, precision calibration information matching the second node;
[0007] The clock information and the precision calibration information are sent to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
[0008] In a second aspect, an embodiment of the present application further provides a clock synchronization method, which is applied to a second node in an in-vehicle network system, wherein the in-vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources, the multiple master clock nodes are sorted according to clock priority, the node with the highest clock priority among the multiple master clock nodes is the first node, and the second node is any node among the multiple nodes except the first node, the method comprising:
[0009] Sending a subscription clock request to the first node, where the subscription clock request carries node information corresponding to the second node;
[0010] Receiving clock information and precision calibration information matching the second node sent by the first node, wherein the precision calibration information is determined by the first node based on node information corresponding to the second node;
[0011] The self-clock information is adjusted based on the clock information and the precision calibration information.
[0012] In a third aspect, an embodiment of the present application further provides a clock synchronization device, which is applied to a first node in an in-vehicle network system, wherein the in-vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources, the multiple master clock nodes being sorted according to clock priority, and the first node being the node with the highest clock priority among the multiple master clock nodes; the device includes:
[0013] A first receiving module is configured to receive a clock subscription request sent by a second node, wherein the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node;
[0014] A first determining module is configured to obtain clock information in response to the clock subscription request, and determine precision calibration information matching the second node based on the node information;
[0015] The first sending module is configured to send the clock information and the precision calibration information to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
[0016] In a fourth aspect, an embodiment of the present application further provides a clock synchronization device, which is applied to a second node in an in-vehicle network system, wherein the in-vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources, the multiple master clock nodes are sorted according to clock priority, the node with the highest clock priority among the multiple master clock nodes is the first node, and the second node is any node among the multiple nodes except the first node, the device includes:
[0017] A second sending module is configured to send a subscription clock request to the first node, wherein the subscription clock request carries node information corresponding to the second node;
[0018] a second receiving module, configured to receive clock information and precision calibration information sent by the first node that matches the second node; wherein the precision calibration information is determined by the first node based on node information corresponding to the second node;
[0019] An adjustment module is configured to adjust its own clock information based on the clock information and the precision calibration information.
[0020] In the fifth aspect, an embodiment of the present application also provides an electronic device, which includes a processor, a memory, and a computer program stored in the memory and runnable on the processor, and when the computer program is executed by the processor, it implements the clock synchronization method described in the first or second aspect above.
[0021] In a sixth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the clock synchronization method described in the first or second aspect above is implemented.
[0022] The embodiments of the present application include at least the following technical effects:
[0023] The technical solution of the embodiment of the present application, by moving the clock synchronization algorithm to the first node and providing external precision calibration agent services, can generate clock information and precision calibration information matching the second node when receiving the clock subscription request sent by the second node, and provide it to the second node, so that the second node can directly perform clock synchronization based on the clock information and precision calibration information sent by the first node, reducing the second node's dependence on hardware selection, and thus achieving high-precision clock synchronization across chips and boards without relying on hardware support, thereby improving the clock synchronization accuracy between vehicle systems and reducing functional abnormalities caused by clock deviations. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art.
[0025] Figure 1 This is one of the flow charts of the clock synchronization method provided in the embodiment of the present application;
[0026] Figure 2 This is the second flow chart of the clock synchronization method provided in the embodiment of the present application;
[0027] Figure 3 This is the third flow chart of the clock synchronization method provided in the embodiment of the present application;
[0028] Figure 4 This is a schematic diagram of the structure of the clock synchronization system provided in an embodiment of the present application;
[0029] Figure 5 This is the fourth flow chart of the clock synchronization method provided in the embodiment of the present application;
[0030] Figure 6 This is one of the structural diagrams of the clock synchronization device provided in the embodiment of the present application;
[0031] Figure 7 This is the second structural diagram of the clock synchronization device provided in an embodiment of the present application;
[0032] Figure 8 This is a block diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0033] In order to make the technical problems, technical solutions and beneficial effects solved by this application more clearly understood, this application is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0034] In related technologies, with the continuous development of intelligent connectivity and networking, the proportion of vehicles equipped with Ethernet technology has gradually increased. In the vehicle network system, especially the intelligent driving system, the synchronization and real-time requirements of the clocks of each controller in the network are relatively high, so it is necessary to synchronize the clocks of each controller in the vehicle. At present, the clock synchronization between the controllers in the vehicle is usually based on the IEEE1588 or IEEE802.1AS protocol (also known as gPTP, generalized Precision Time Protocol). In the presence of multi-level Ethernet or PCIe switches, the clock synchronization accuracy of the overall Ethernet system can achieve better results.
[0035] Ethernet forms include point-to-point, point-to-multipoint (such as PON networks), and multipoint (such as 10BASE-T1S). The IEEE802.1AS gPTP protocol has corresponding implementation solutions for all three forms, but currently there are few automotive-grade chips in the automotive industry that comply with IEEE 802.1AS and support all three forms. The IEEE802.1AS gPTP protocol is currently recognized by the industry as a solution with high synchronization accuracy and comprehensive support for different forms of Ethernet, but this protocol has development requirements for both hardware chips and underlying software. Currently, the industry lacks a clock synchronization implementation solution based on the gPTP protocol for hybrid automotive networks (which exist simultaneously in point-to-point, point-to-multipoint, and multipoint types). At the same time, the gPTP protocol itself does not provide identity authentication and verification capabilities for the master clock. The current implementation does not consider the possibility of failures and attacks, and lacks functional safety and information security mechanisms to ensure the reliability of the clock synchronization system. In addition, when using PCIe switches to connect multiple SoCs (System on chip), clock synchronization between SoCs often relies on support for the PTM (Precision Time Management) protocol, which also faces stringent hardware selection conditions.
[0036] In summary, the existing clock synchronization between automotive controllers based on IEEE1588 or IEEE802.1AS gPTP protocols has the following shortcomings:
[0037] 1. Hardware Dependence. Achieving high precision (nanosecond level) with the gPTP protocol requires specialized hardware (such as Ethernet / PCIe switches, transceivers, or SOC / module chips that support gPTP or PTM). However, the chips used may not always support gPTP, making implementation difficult. PON fiber and 10BASE-T1S are particularly in the early stages of research and development, and chip or PTM manufacturers do not yet have mature solutions. Furthermore, the master and slave clocks traverse multiple networks, requiring hardware support for gPTP or PTM on every controller along the network to ensure clock synchronization accuracy. Furthermore, the three parameters acquired by the gPTP protocol in real time have been verified in mass production and proven to be relatively stable through effective design. Configuring static algorithms in local controllers can reduce the implementation complexity for other controllers, thus filling the gap in clock synchronization solutions in existing hybrid networks. The PTM protocol, similar to gPTP, maintains time consistency by compensating for clock deviation and link latency.
[0038] 2. Real-time deviation adjustment. The gPTP protocol obtains the offset from the master clock by real-time acquisition of clock frequency error, link delay between the master clock and the slave clock, and the dwell time of bridge device forwarding, thereby adjusting the local clock to ensure high-precision clock synchronization. However, the principles are different for point-to-point, point-to-multipoint, and multipoint Ethernet networks. For example, in point-to-point networks, the calculation of gPTP link delay is based on bidirectional symmetry, while PON optical fiber uses different wavelengths for upstream and downstream transmission, and the bidirectional link is asymmetric. The point-to-point calculation principle cannot be applied, making the system complex to implement and difficult to develop.
[0039] 3. Lack of data source and validity verification. The gPTP protocol itself lacks inherent security mechanisms. For example, there is no validity verification of the master clock's identity, leaving it vulnerable to spoofing attacks through forged master clocks. Furthermore, the time information transmitted by the master clock lacks information about whether the time source is currently valid. For example, in locations like garages where network signals are poor and the controller has experienced a power outage, an invalid time source can lead to significant time deviations. Through the gPTP protocol, this can cause significant time deviations across the entire network.
[0040] Based on this, the present application provides a clock synchronization method, device, electronic device and storage medium. By moving the clock synchronization algorithm to the first node and providing external precision calibration agent services, when receiving the subscription clock request sent by the second node, clock information and precision calibration information matching the second node can be generated and provided to the second node, so that the second node can directly perform clock synchronization based on the clock information and precision calibration information sent by the first node, reducing the second node's dependence on hardware selection, and thus achieving high-precision clock synchronization across chips and boards without relying on hardware support, thereby improving the clock synchronization accuracy between vehicle systems and reducing functional abnormalities caused by clock deviations.
[0041] The relevant terms in the embodiments of this application are explained as follows:
[0042] ECU: Electrical Control Unit, electronic controller;
[0043] gPTP: generalized Precision Time Protocol, which is used for time synchronization;
[0044] PON: Passive Optical Network, a fiber-based access technology. Its core feature is that it does not require active devices (such as amplifiers and repeaters) in the network. It only uses passive optical splitters to distribute signals and supports point-to-multipoint topology.
[0045] 100BASE-T1: A 100M Ethernet physical layer technology based on IEEE802.3bw and over a single twisted pair cable, supporting point-to-point topology.
[0046] 1000BASE-T1: Gigabit Ethernet physical layer technology based on single twisted-pair cabling, based on IEEE802.3bp, supporting point-to-point topology;
[0047] Multi-G BASE-T1: A multi-gigabit Ethernet physical layer technology based on IEEE802.3ch over a single twisted pair, supporting point-to-point topology;
[0048] 10BASE-T1S: 10M Ethernet physical layer technology based on single twisted-pair cabling, based on IEEE802.3cg, supporting multi-point bus topology;
[0049] SOC: system on chip;
[0050] PCIe (Peripheral Component Interconnect Express) is a high-speed serial computer expansion bus standard used to connect computer motherboards to various high-performance peripherals (such as graphics cards, network cards, and SSDs). It is an upgraded version of the traditional PCI and PCI-X buses, offering core advantages such as high bandwidth, low latency, and point-to-point transmission.
[0051] The embodiment of the present application provides a clock synchronization method, which is applied to a first node in an in-vehicle network system, wherein the in-vehicle network system includes a plurality of nodes, wherein the plurality of nodes include a plurality of master clock nodes configured with clock sources and a plurality of slave clock nodes not configured with clock sources, wherein the plurality of master clock nodes are sorted according to clock priority, and the first node is the node with the highest clock priority among the plurality of master clock nodes; please refer to Figure 1 , including the following steps:
[0052] Step 101: Receive a clock subscription request sent by a second node, where the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node.
[0053] Specifically, the vehicle network system to which the clock synchronization method provided in the embodiment of the present application is applied includes two types of nodes, a master clock node and a slave clock node. The master clock node is configured with an independent clock source (such as GNSS, NTP, NITZ) and has autonomous timing capabilities. The number of master clock nodes can be multiple, and these multiple master clock nodes are sorted according to clock priority, such as the clock priority of GNSS is higher than that of NTP, and the clock priority of NTP is higher than that of NITZ. The first node here is the node with the highest clock priority among the multiple master clock nodes. The slave clock node is not configured with an independent clock source, such as an on-board camera, a radar sensor, etc., and needs to use the master clock node to complete clock synchronization. The number of slave clock nodes is usually multiple. The second node here is any node other than the first node among the multiple nodes included in the vehicle network system. The first node is a timing node, and the second node is a timed node. The first node is a master clock node, and the second node can be a master clock node or a slave clock node.
[0054] After the vehicle is powered on, the second node will determine the node with the highest clock priority based on the statically configured clock priority, that is, the first node, and send a subscription clock request to the first node. At this time, the first node will receive the subscription clock request sent by the second node, which carries the node information corresponding to the second node.
[0055] The node information here includes but is not limited to the following:
[0056] ECUID, used to identify the receiver, i.e. the first node;
[0057] Hlength (harness length), used to calculate link delay, in meters;
[0058] EthType (communication mode): point-to-point, point-to-multipoint, or bus. Select one of these three types for calculating link latency.
[0059] EthTech, electrical Ethernet / optical Ethernet / PCIe, choose one;
[0060] ConnectECU (direct connection to ECU), used to calculate the transmission link length, in meters;
[0061] ConnectPort (connection port number), hardware connection port number, used to confirm the connection link;
[0062] Chip (PHY chip model), used to determine the asymmetry between transmit and receive and find the corresponding compensation parameters;
[0063] Crystaloscillator (crystal oscillator model), used to determine the frequency offset;
[0064] FT (factory time of crystal oscillator), used to calculate aging time (year, month, day);
[0065] TD (crystal temperature drift) is used to determine the frequency offset caused by temperature, in ppm.
[0066] CT (Crystal Calibration Tolerance), used to determine the offset between the factory frequency accuracy and the nominal frequency, in ppm;
[0067] AD (crystal aging drift) is used to determine the frequency offset caused by crystal aging, in ppm / year;
[0068] CyclicTime (clock transmission cycle requirement), how often the master clock is expected to send clock information, unit: seconds;
[0069] TargetPrecision (clock synchronization accuracy requirement) is used to provide the clock synchronization accuracy requirement to the master clock node, in us.
[0070] Step 102: In response to the clock subscription request, obtain clock information, and determine the precision calibration information matching the second node based on the node information.
[0071] In an embodiment of the present application, the first node serves as a master clock node, in which at least a precision calibration module, a security module and a time reference module are deployed.
[0072] The precision calibration module is mainly used to implement the precision calibration proxy service. The controller deployed with the precision calibration module is the timing node. During operation, it obtains the relevant parameter information of the proxy controller, the timing node. Through the clock synchronization algorithm, it calculates the specific precision value to be calibrated by the proxy controller and then sends it to the proxy controller to compensate for clock deviation and link delay.
[0073] The security module is mainly used for master clock identity authentication before timing service to prevent illegal modification of the controller's local clock.
[0074] The time reference module is primarily used by the master clock controller to manage clock information and the vehicle's global clock. It obtains external time through NTP / GNSS / NITZ and implements arbitration logic for multiple clock sources based on priority to maintain highly accurate absolute time. Furthermore, it maintains regular synchronization with the external time when the vehicle is in sleep mode, preventing jitter in the RTC (Real-Time Clock) when synchronizing with the external time.
[0075] It should be noted that the time reference module can be deployed on multiple components within the vehicle, such as the onboard computing platform and gateway, forming multiple master clock nodes. When deployed simultaneously on multiple components, the priority of each time reference module can be set to achieve a multi-level time redundancy backup solution for the entire vehicle. If a higher-priority time reference module cannot provide clock information and accuracy calibration services for various reasons, the system switches to a lower-level time reference module to obtain time.
[0076] Specifically, after receiving the subscription request, the first node extracts the information in the subscription request, namely the node information of the second node, which includes CyclicTime (clock transmission cycle requirement), and the first node calls the clock information of the time reference module according to the clock transmission cycle requirement.
[0077] Specifically, the clock information includes but is not limited to the following:
[0078] ClockID, used to identify the clock ID provided by itself;
[0079] Valuevalid indicates whether the current clock source is valid. 0 represents invalid and 1 represents valid.
[0080] Priority, clock priority, used for arbitration when the vehicle has multiple clocks;
[0081] SequenceID, identifies the frame sequence number;
[0082] TimeStampeSeconds, identifies a specific clock, in seconds;
[0083] TimeStampeNanoseconds, identifies a specific clock, in nanoseconds.
[0084] The first node is also equipped with a clock synchronization algorithm that determines precision calibration information matching the second node based on the node information. This precision calibration information includes clock frequency error, link latency, and dwell time. The first node extracts the node information corresponding to the second node contained in the clock subscription request and sends it to the precision calibration module. The precision calibration module then calculates precision calibration information matching the second node based on the node information.
[0085] Step 103: Send the clock information and the precision calibration information to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
[0086] After determining the clock information and precision calibration information, the first node sends it to the second node. The precision calibration proxy solution in the embodiment of the present application allows the receiving node, i.e., the second node, to achieve highly accurate clock synchronization without integrating the expensive gPTP protocol stack. The second node can directly adjust its own clock information based on the received clock information and precision calibration information. Adjusting its own clock information here also includes compensating for the crystal oscillator frequency to reduce clock drift and improve synchronization accuracy.
[0087] In an embodiment of the present application, by moving the clock synchronization algorithm to the first node and providing external precision calibration agent services, when receiving a clock subscription request sent by the second node, clock information and precision calibration information matching the second node can be generated and provided to the second node, so that the second node can directly perform clock synchronization based on the clock information and precision calibration information sent by the first node, reducing the second node's dependence on hardware selection, and further achieving high-precision clock synchronization across chips and boards without relying on hardware support, thereby improving the clock synchronization accuracy between vehicle systems and reducing functional abnormalities caused by clock deviations.
[0088] The process of determining the accuracy calibration information is described below. In an optional embodiment of the present application, determining the accuracy calibration information matching the second node based on the node information includes:
[0089] determining a clock frequency deviation according to the node information;
[0090] Determine, based on the node information, a link length between the first node and the second node, and determine a link delay based on the link length;
[0091] determining, based on the node information, whether a bridge device exists between the first node and the second node, and determining a residence time if the bridge device exists;
[0092] The precision calibration information is determined according to the clock frequency deviation, the link delay, and the dwell delay.
[0093] When determining the precision calibration information that matches the second node, the precision calibration module in the first node calculates the clock frequency error, link delay and residence time included in the precision calibration information in real time based on the node information of the second node.
[0094] When calculating the clock frequency error, extract the crystal oscillator (crystal model), TD (crystal temperature drift), CT (crystal calibration tolerance), AD (crystal aging drift), and FT (crystal factory time) from the node information corresponding to the second node. According to the crystal oscillator model, the basic frequency deviation is obtained by looking up the table. Different crystal oscillators correspond to different basic frequency deviations. According to the crystal oscillator factory time, the aging time is determined. Finally, the clock frequency error is calculated according to the following formula:
[0095] Δ1 = basic frequency deviation + TD + CT + AD * aging time; where Δ1 is the clock frequency error.
[0096] When calculating the link delay, extract H length (harness length), EthTech, ConnectECU (direct connection ECU), ConnectPort (connection port number), and Chip (PHY chip model) from the node information corresponding to the second node. According to the PHY chip model, the asymmetric compensation parameters are determined by looking up the table. Different PHY chip models correspond to different asymmetric compensation parameters. Based on EthTech, ConnectECU (direct connection ECU), and ConnectPort (connection port number), calculate the harness length. Finally, calculate the link delay according to the following formula:
[0097] Δ2 = actual harness transmission time + compensation = Hlength ÷ harness average transmission rate + chip asymmetry compensation parameter; where Δ2 is the link delay and the harness average transmission rate is the propagation speed of electromagnetic waves, that is, the speed of light.
[0098] It should be noted that for point-to-point communication, the average transmission rate for PCIe and Ethernet cables is 5ns / m, and the average transmission rate for fiber-optic Ethernet is 4ns / m. The transceiver asymmetry compensation parameters are derived from the chip manual. For example, if the Marvell 88Q2xxx transceiver asymmetry reaches 4us, the compensation parameter is calculated as half of the asymmetry, or 2us.
[0099] When calculating the dwell time, the first step is to determine whether there is a bridge device between the first and second nodes. A bridge device is a device used to connect different Ethernet segments or different types of networks, and is used to implement functions such as data forwarding and protocol conversion. For example, when sending data from one communication link to another, a bridge device is required to forward the data, and the forwarding process has a dwell time. Bridge devices that support gPTP can read this dwell time in real time. Bridge devices that do not support gPTP can statically configure the dwell time value corresponding to the chip model.
[0100] It should be noted that the embodiment of the present application configures a precision calibration module for the timing node, i.e., the master clock node, and provides external precision calibration agent services. The calibration of time synchronization precision due to frequency deviation, link delay, and dwell time is placed on the timing node. The clock information and precision calibration information are made into standard service interface data and provided to the timing node for calling. The clock synchronization protocol implementation algorithm is moved up, reducing the difficulty of implementing high-precision clock synchronization for chips, controllers, etc. in the existing protocol and the degree of dependence on hardware selection. The difficulty of implementing clock synchronization for the timing node is reduced, and a unified, standardized, and modular implementation solution is provided for the heterogeneous and complex network of the entire vehicle.
[0101] The above implementation scheme of the present application reduces dependence on dedicated hardware by incorporating frequency deviation, link delay and bridge device residence delay into the dynamic calibration model. It can adapt to changes in hybrid network topology and significantly reduce hardware costs while ensuring high-precision synchronization. It enhances system fault tolerance, reduces network load and computing overhead, and provides key support for the evolution of in-vehicle networks to a central computing architecture. It is especially suitable for scenarios with strict requirements on timing consistency, such as assisted driving sensor fusion.
[0102] The following describes how to send the clock information and the precision calibration information to the second node. In an optional embodiment of the present application, sending the clock information and the precision calibration information to the second node includes:
[0103] Obtaining the sending period carried in the subscription clock request;
[0104] The clock information and the precision calibration information are sent to the second node according to the sending cycle.
[0105] Specifically, the second node actively declares the sending period in the subscription clock request, and the sending period matches the application scenario of the second node itself. For example, the assisted driving sensor usually requests a high-frequency sending period of 1 millisecond because it requires nanosecond-level synchronization accuracy, while the in-vehicle entertainment system can set a low-frequency period of 100 milliseconds because it has lower timing requirements.
[0106] When the first node sends the clock information and precision calibration information to the second node, it obtains the sending cycle carried in the subscription clock request, that is, extracts CyclicTime (clock sending cycle requirement) from the node information corresponding to the second node. The clock information and precision calibration information are then sent to the second node according to the sending cycle. Specifically, the clock information and precision calibration information can be packaged periodically by the time scheduler, so that the first node can dynamically adjust the sending frequency of clock synchronization messages according to the precision requirements of different nodes to achieve a dynamic balance between precision and resource consumption. This ensures that the second node obtains the required precision time synchronization without occupying too much network bandwidth and computing resources due to excessively frequent message transmission.
[0107] The above implementation scheme of the present application dynamically controls the sending frequency of clock information and precision calibration information by obtaining the sending period in the subscription clock request, and can achieve on-demand synchronization according to the application scenario and precision requirements of the second node. It can provide high-frequency synchronization for high-precision requirement nodes such as assisted driving sensors to ensure timing consistency, and can reduce the synchronization frequency for low-precision requirement nodes such as entertainment systems to reduce network load and computing overhead. It can also adaptively adjust the period in the event of network congestion or failure to ensure that the synchronization of critical tasks is not affected, thereby achieving optimal allocation and efficient utilization of system resources while meeting the synchronization requirements of different nodes.
[0108] The following describes the process of security verification before clock synchronization. In an optional embodiment of the present application, before receiving the clock subscription request sent by the second node, the method further includes:
[0109] receiving a security authentication request sent by the second node and carrying a key, where the key is calculated by the second node according to the node identity of the second node;
[0110] In response to the security authentication request, verify the key and determine a verification result; the verification result is verification pass or verification fail;
[0111] Sending the verification result to the second node;
[0112] When the verification result is that the verification is passed, the second node sends the clock subscription request to the first node.
[0113] In an embodiment of the present application, a security module is deployed in the first node to authenticate the master clock before timing and prevent illegal modification of the controller's local clock.
[0114] Before sending a clock subscription request, the second node sends a security authentication request to the first node. Therefore, the first node receives the security authentication request from the second node before receiving the clock subscription request. This security authentication request carries a key calculated by the second node based on its node identity. For example, the second node can generate a key based on its own node identity, such as a MAC address plus a production serial number, using a hash algorithm or a key derivation function to ensure a strong binding between the key and the node identity. The key can also be embedded with a timestamp or random number to prevent replay attacks.
[0115] The first node extracts the key from the security authentication request, recalculates the expected key through the pre-stored node identity mapping table or the same algorithm, compares the consistency of the two to verify the key, and determines the verification result, which is verification passed or verification failed.
[0116] After obtaining the verification result, the verification result is sent to the second node. If the verification result is verified, the second node triggers the subsequent subscription process, that is, sends a subscription clock request to the first node. If the verification result is verified failed, the subsequent subscription process is not triggered, that is, no subscription clock request is sent to the first node.
[0117] The above implementation scheme of the present application embeds a security authentication mechanism based on node identity before subscribing to the clock request, converts the node identity into a key and performs two-way verification, ensuring that only legally authorized nodes can access the clock synchronization network, effectively preventing malicious nodes from forging requests or injecting erroneous time information, and building a trusted access barrier for the vehicle network. At the same time, through the linkage between authentication results and synchronization permissions, multiple guarantees are achieved, including trusted node identity, secure synchronization process, and effective fault isolation, thereby improving the information security and functional safety level of the entire vehicle clock synchronization system.
[0118] The following describes the processing of the subscription result in the clock subscription process. In an optional embodiment of the present application, after receiving the subscription clock request sent by the second node, the method further includes:
[0119] Determining a subscription result based on the local resource information and local clock information corresponding to the first node and the node information corresponding to the second node; the subscription result is a subscription success or a subscription failure, wherein when the subscription result is the subscription failure, the subscription result carries a subscription failure reason;
[0120] Sending the subscription result to the second node;
[0121] Wherein, when the subscription result is that the subscription is successful, the second node waits to receive the clock information and the precision calibration information sent by the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the first node, the second node sends a subscription clock request to a third node, and the third node is the node with the highest clock priority among the multiple master clock nodes except the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the second node, the second node regenerates the subscription clock request based on the reason for the subscription failure and sends it to the first node.
[0122] In this embodiment of the present application, after receiving a subscription clock request from a second node, a first node needs to determine the subscription result and return the subscription result to the second node, completing the response to the subscription clock request. The subscription result here can be either a successful subscription or a failed subscription. If the subscription result is a failed subscription, the subscription result includes the reason for the subscription failure. If the second node receives a successful subscription result, it waits to receive clock information and precision calibration information from the first node based on the subscription clock request, and then adjusts its own clock information based on the clock information and precision calibration information. If the second node receives a failed subscription result, it needs to first determine the reason for the subscription failure. If the subscription failure reason is the first node, it indicates that the first node cannot synchronize its clock with the second node. In this case, the second node should resend the subscription clock request to another master clock node, specifically a third node, which is the node with the highest clock priority among the multiple master clock nodes, excluding the first node. If the subscription failure reason is the second node, it indicates that the first node can synchronize its clock with the second node, but the information provided by the second node is incorrect. In this case, the second node can correct the information contained in the subscription clock request based on the subscription failure reason and resend the subscription clock request to the first node.
[0123] When determining a subscription result, the first node can generate a subscription result using a decision algorithm based on local resource information, local clock information, and node information of the second node. Local resource information typically refers to the first node's current operating status and available resources to ensure it can reliably process the second node's subscription request and return data. This information includes at least the following: 1. Resource availability, such as CPU load; 2. Communication resource availability, such as sufficient socket resources; and 3. Local status, including whether the communication middleware and underlying Ethernet TCP / IP protocol stack have been initialized and are available. Local clock information includes the validity of the local clock source, which includes real-time clock (RTC) time and GNSS time. GNSS time can become temporarily invalid when GNSS signal loss occurs in tunnels or urban canyons, or when a GNSS receiver fails to complete a cold start. RTC time (Real-time clock) is maintained by the hardware clock chip in the gateway / vehicle computing platform. If the RTC hardware clock chip loses power during long-term storage, resulting in malfunction, such as in vehicle power supply, the RTC time can become inaccurate and invalid. According to the node information of the second node, it is determined whether the subscription clock request sent by the second node is incorrect, for example, whether the sending period is out of range.
[0124] It should be noted that when multiple master clock nodes coexist, the vehicle network system maintains a dynamic priority list. This implements a security strategy for redundant backup of multiple clock sources throughout the vehicle. When a high-priority clock fails, timing is dynamically switched to a lower-level clock source, reducing the risk of single-point failure leading to loss of the vehicle's clock source.
[0125] The above-mentioned implementation scheme of this application intelligently determines subscription results based on the local resources and clock status of the first node and the needs of the second node, accurately attributing and classifying subscription failures. If the failure is caused by insufficient resources or clock source failure of the first node, the second node is automatically guided to switch to the master clock node with the next highest priority to ensure service continuity. If the failure is caused by problems such as parameter errors on the second node itself, it is prompted to correct and retry, achieving self-repair. This effectively improves the availability and robustness of clock synchronization services, optimizes the efficiency of system resource allocation, enhances the ability to resist malicious attacks, ensures the stable operation of safety-critical functions, and provides reliable and intelligent clock synchronization for in-vehicle networks.
[0126] The embodiment of the present application provides a clock synchronization method, which is applied to a second node in an in-vehicle network system. The in-vehicle network system includes multiple nodes, and the multiple nodes include multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources. The multiple master clock nodes are sorted according to clock priority. The node with the highest clock priority among the multiple master clock nodes is the first node. The second node is any node among the multiple nodes except the first node. Please refer to Figure 2 , the method comprising:
[0127] Step 201: Send a clock subscription request to a first node, where the clock subscription request carries node information corresponding to the second node.
[0128] Specifically, the vehicle network system to which the clock synchronization method provided in the embodiment of the present application is applied includes two types of nodes, a master clock node and a slave clock node. The master clock node is configured with an independent clock source (such as GNSS, NTP, NITZ) and has autonomous timing capabilities. The number of master clock nodes can be multiple, and these multiple master clock nodes are sorted according to clock priority, such as the clock priority of GNSS is higher than that of NTP, and the clock priority of NTP is higher than that of NITZ. The first node here is the node with the highest clock priority among the multiple master clock nodes. The slave clock node is not configured with an independent clock source, such as an on-board camera, a radar sensor, etc., and needs to use the master clock node to complete clock synchronization. The number of slave clock nodes is usually multiple. The second node here is any node other than the first node among the multiple nodes included in the vehicle network system. The second node is the time-served node, and the first node is the time-serving node. The second node can be a master clock node or a slave clock node, and the first node is the master clock node.
[0129] After the vehicle is powered on, the second node will determine the node with the highest clock priority, that is, the first node, according to the statically configured clock priority, and send a clock subscription request to the first node.
[0130] The node information here includes but is not limited to the following:
[0131] ECU ID, used to identify the receiver, i.e. the first node;
[0132] Hlength (harness length), used to calculate link delay, in meters;
[0133] EthType (communication mode): point-to-point, point-to-multipoint, or bus. Select one of these three types for calculating link latency.
[0134] EthTech, electrical Ethernet / optical Ethernet / PCIe, choose one;
[0135] ConnectECU (direct connection to ECU), used to calculate the transmission link length, in meters;
[0136] ConnectPort (connection port number), hardware connection port number, used to confirm the connection link;
[0137] Chip (PHY chip model), used to determine the asymmetry between transmit and receive and find the corresponding compensation parameters;
[0138] crystaloscillator (crystal oscillator model), used to determine the frequency offset;
[0139] FT (factory time of crystal oscillator), used to calculate aging time (year, month, day);
[0140] TD (crystal temperature drift) is used to determine the frequency offset caused by temperature, in ppm.
[0141] CT (Crystal Calibration Tolerance), used to determine the offset between the factory frequency accuracy and the nominal frequency, in ppm;
[0142] AD (crystal aging drift) is used to determine the frequency offset caused by crystal aging, in ppm / year;
[0143] CyclicTime (clock transmission cycle requirement), how often the master clock is expected to send clock information, unit: seconds;
[0144] TargetPrecision (clock synchronization accuracy requirement) is used to provide the clock synchronization accuracy requirement to the master clock node, in us.
[0145] Step 202: Receive clock information and precision calibration information sent by the first node that matches the second node; wherein the precision calibration information is determined by the first node based on node information corresponding to the second node.
[0146] Specifically, after receiving the subscription request, the first node extracts the information in the subscription request, namely the node information of the second node, which includes CyclicTime (clock transmission cycle requirement), and the first node calls the clock information of the time reference module according to the clock transmission cycle requirement.
[0147] Specifically, the clock information includes but is not limited to the following:
[0148] ClockID, used to identify the clock ID provided by itself;
[0149] Valuevalid indicates whether the current clock source is valid. 0 represents invalid and 1 represents valid.
[0150] Priority, clock priority, used for arbitration when the vehicle has multiple clocks;
[0151] SequenceID, identifies the frame sequence number;
[0152] TimeStampeSeconds, identifies a specific clock, in seconds;
[0153] TimeStampeNanoseconds, identifies a specific clock, in nanoseconds.
[0154] At the same time, the first node is configured with a clock synchronization algorithm, which can determine the precision calibration information that matches the second node based on the node information. The precision calibration information includes clock frequency error, link delay, and dwell time.
[0155] After the first node determines the clock information and the precision calibration information, the second node will receive the clock information and the precision calibration information sent by the first node.
[0156] Step 203: Adjust the own clock information based on the clock information and the precision calibration information.
[0157] After receiving the clock information and precision calibration information sent by the first node, the second node can directly adjust its own clock information based on the received clock information and precision calibration information. Adjusting its own clock information here also includes compensating for the crystal oscillator frequency to reduce clock drift and improve synchronization accuracy. The precision calibration proxy solution of the embodiment of the present application allows the timing node, that is, the second node, to achieve high-precision clock synchronization without integrating the expensive gPTP protocol stack.
[0158] In an embodiment of the present application, by moving the clock synchronization algorithm to the first node and providing external precision calibration agent services, a clock subscription request can be sent to the first node, and the first node generates clock information and precision calibration information that matches the second node, and provides it to the second node, so that the second node can directly perform clock synchronization based on the clock information and precision calibration information sent by the first node, reducing the second node's dependence on hardware selection, and thus achieving high-precision clock synchronization across chips and boards without relying on hardware support, thereby improving the clock synchronization accuracy between vehicle systems and reducing functional abnormalities caused by clock deviations.
[0159] The following describes the identity verification process before subscribing to the clock. In an optional embodiment of the present application, before sending the subscription clock request to the first node, the method further includes:
[0160] Calculating a key according to the node identity of the second node;
[0161] Sending a security authentication request carrying the key to the first node; wherein the first node verifies the key and determines a verification result;
[0162] Receive the verification result sent by the first node, and when the verification result is verification passed, send the subscription clock request to the first node.
[0163] Before sending a clock subscription request, the second node sends a security authentication request to the first node. This security authentication request carries a key calculated by the second node based on its node identity. For example, the second node can generate a key based on its own node identity, such as a MAC address combined with a production serial number, using a hash algorithm or a key derivation function to ensure a strong binding between the key and the node identity. The key can also be embedded with a timestamp or random number to prevent replay attacks.
[0164] The first node extracts the key from the security authentication request, recalculates the expected key through the pre-stored node identity mapping table or the same algorithm, compares the consistency of the two to verify the key, determines the verification result, and sends the verification result to the second node; the verification result is verification passed or verification failed.
[0165] After receiving the verification result, if the verification result is passed, the second node triggers the subsequent subscription process, that is, sends a subscription clock request to the first node. If the verification result is failed, the subsequent subscription process is not triggered, that is, no subscription clock request is sent to the first node.
[0166] The above implementation scheme of the present application embeds a security authentication mechanism based on node identity before subscribing to the clock request, uses cryptographic algorithms to convert the node identity into a key and performs two-way verification, ensuring that only legally authorized nodes can access the clock synchronization network, effectively preventing malicious nodes from forging requests or injecting erroneous time information, and building a trusted access barrier for the vehicle network. At the same time, through the linkage between authentication results and synchronization permissions, multiple guarantees are achieved, including trusted node identity, secure synchronization process, and effective fault isolation, thereby improving the information security and functional safety level of the entire vehicle clock synchronization system.
[0167] In an optional embodiment of the present application, after sending the clock subscription request to the first node, the method further includes:
[0168] receiving a subscription result fed back by the first node; wherein the subscription result is determined by the first node based on local resource information and local clock information corresponding to the first node and node information corresponding to the second node, the subscription result being a subscription success or a subscription failure; and when the subscription result is a subscription failure, the subscription result carries a reason for the subscription failure;
[0169] When the subscription result is that the subscription is successful, waiting to receive the clock information and the precision calibration information sent by the first node;
[0170] When the subscription result is that the subscription fails and the reason for the subscription failure is the first node, sending a subscription clock request to a third node, where the third node is a node with the highest clock priority among the multiple master clock nodes except the first node;
[0171] When the subscription result is the subscription failure and the subscription failure reason is the second node, a subscription clock request is regenerated based on the subscription failure reason and sent to the first node.
[0172] In the embodiment of the present application, after the second node sends a subscription clock request to the first node, it will receive a subscription result fed back by the first node. The subscription result here is subscription success or subscription failure. When the subscription result is subscription failure, the subscription result carries the reason for subscription failure.
[0173] If the subscription result received by the second node is a successful subscription, the second node waits to receive the clock information and precision calibration information fed back by the first node based on the subscription clock request, so as to adjust its own clock information based on the clock information and precision calibration information.
[0174] If the subscription result received by the second node is a subscription failure, it is necessary to first determine the reason for the subscription failure. If the subscription failure reason is the first node, it indicates that the first node cannot synchronize the clock with the second node. At this time, the second node should resend the subscription clock request to another master clock node. The other master clock node here is the third node. The third node is specifically the node with the highest clock priority among multiple master clock nodes except the first node.
[0175] If the subscription failure reason is the second node, it means that the first node can synchronize the clock with the second node, but the information provided by the second node is incorrect. At this time, the second node can make corrections based on the subscription failure reason and resend the subscription clock request to the first node.
[0176] It should be noted that when multiple master clock nodes coexist, the vehicle network system maintains a dynamic priority list. If the first node fails, the second node automatically switches to the third node in order of priority to ensure service continuity.
[0177] The above-mentioned implementation scheme of this application intelligently determines subscription results based on the local resources and clock status of the first node and the needs of the second node, accurately attributing and classifying subscription failures. If the failure is caused by insufficient resources or clock source failure of the first node, the second node is automatically guided to switch to the master clock node with the next highest priority to ensure service continuity. If the failure is caused by problems such as parameter errors on the second node itself, it is prompted to correct and retry, achieving self-repair. This effectively improves the availability and robustness of clock synchronization services, optimizes the efficiency of system resource allocation, enhances the ability to resist malicious attacks, ensures the stable operation of safety-critical functions, and provides reliable and intelligent clock synchronization for in-vehicle networks.
[0178] The following is an introduction to the overall implementation process of the embodiment of this application. Figure 3 As shown, including:
[0179] Step 301: When the vehicle is powered on, the controller sends a security authentication request to the gateway / vehicle computing platform where the highest-priority clock source resides, based on the statically configured priorities of the multiple clock sources, completing security authentication. The controller is the second node in the above embodiment, and the gateway / vehicle computing platform is the first node.
[0180] Step 302: The gateway / vehicle computing platform determines whether the authentication is successful. If so, the process proceeds to step 303; otherwise, the process returns to step 301.
[0181] Step 303: The controller sends a subscription message packet1 to the gateway / vehicle computing platform.
[0182] The subscription message packet1 includes but is not limited to the following:
[0183] ECUID, used to identify the receiver, i.e. the first node;
[0184] Hlength (harness length), used to calculate link delay, in meters;
[0185] EthType (communication mode): point-to-point, point-to-multipoint, or bus. Select one of these three types for calculating link latency.
[0186] EthTech, electrical Ethernet / optical Ethernet / PCIe, choose one;
[0187] ConnectECU (direct connection to ECU), used to calculate the transmission link length, in meters;
[0188] ConnectPort (connection port number), hardware connection port number, used to confirm the connection link;
[0189] Chip (PHY chip model), used to determine the asymmetry between transmit and receive and find the corresponding compensation parameters;
[0190] crystaloscillator (crystal oscillator model), used to determine the frequency offset;
[0191] FT (factory time of crystal oscillator), used to calculate aging time (year, month, day);
[0192] TD (crystal temperature drift) is used to determine the frequency offset caused by temperature, in ppm.
[0193] CT (Crystal Calibration Tolerance), used to determine the offset between the factory frequency accuracy and the nominal frequency, in ppm;
[0194] AD (crystal aging drift) is used to determine the frequency offset caused by crystal aging, in ppm / year;
[0195] CyclicTime (clock transmission cycle requirement), how often the master clock is expected to send clock information, unit: seconds;
[0196] TargetPrecision (clock synchronization accuracy requirement) is used to provide the clock synchronization accuracy requirement to the master clock node, in us.
[0197] Step 304: The gateway / vehicle computing platform extracts information from the subscription message packet1.
[0198] Step 305: The gateway / vehicle computing platform confirms the local resource status, the validity of the local clock source, and the quality of service required by the other party, and determines whether the subscription is successful. If the subscription is successful, step 306 is executed; otherwise, step 310 is executed.
[0199] Step 306: The gateway / vehicle computing platform sends a response message packet2 indicating successful subscription.
[0200] The response message packet2 includes but is not limited to the following:
[0201] ECU ID, identifies the data receiver that needs to respond;
[0202] ClockID, identifies the clock ID provided by itself;
[0203] CyclicTimeACK: indicates whether the message can be sent according to the cycle required by the data receiver.
[0204] TargetPrecisionACK: Indicates whether clock synchronization can be performed according to the accuracy required by the data receiver;
[0205] Return code: indicates the success or failure of the subscription response. A successful response is 0x00, and a failed response indicates the specific reason for the failure, such as 0x01 = insufficient resources, please subscribe to other clock information; 0x02 = incorrect subscription message information, unable to respond normally, please confirm the information and resubscribe; 0x03 = invalid clock information, etc.
[0206] Step 307: The gateway / vehicle computing platform calls the clock information of the time reference module according to the message period required in the subscription message packet1 sent by the controller, determines the clock information message packet3 and sends it to the controller.
[0207] The clock information packet 3 includes but is not limited to the following:
[0208] ClockID, used to identify the clock ID provided by itself;
[0209] Valuevalid indicates whether the current clock source is valid. 0 represents invalid and 1 represents valid.
[0210] Priority, clock priority, used for arbitration when the vehicle has multiple clocks;
[0211] The Sequence ID identifies the frame sequence number and is used to represent the message sequence. It increments by 1 with each clock message transmission and identifies the order of management messages. This sequence number allows the receiver to determine the order of messages and process them in the correct sequence. The receiver can use the Sequence ID to detect message loss or duplication. If the receiver detects discontinuous Sequence IDs, this may indicate message loss. If messages with the same Sequence ID are received, this may indicate duplicate messages and require appropriate processing.
[0212] Time Stampe Seconds, identifies the specific clock, in seconds;
[0213] Time Stampe Nanoseconds, identifies a specific clock, in nanoseconds.
[0214] Step 308: The gateway / on-vehicle computing platform completes the real-time calculation of the clock frequency error, link delay, and dwell time, determines the accuracy calibration message packet4, and sends it to the controller.
[0215] The precision calibration proxy solution provided in this application allows the receiving node controller to achieve high-precision clock synchronization without integrating the complex and expensive gPTP protocol stack.
[0216] The precision calibration module in the gateway / vehicle computing platform calculates the clock frequency error, link delay, and dwell time in real time based on the parameters in packet1.
[0217] When calculating the clock frequency error, extract the crystal oscillator (crystal model), TD (crystal temperature drift), CT (crystal calibration tolerance), AD (crystal aging drift), and FT (crystal factory time) from the node information corresponding to the second node. According to the crystal oscillator model, the basic frequency deviation is obtained by looking up the table. Different crystal oscillators correspond to different basic frequency deviations. According to the crystal oscillator factory time, the aging time is determined. Finally, the clock frequency error is calculated according to the following formula:
[0218] Δ1 = basic frequency deviation + TD + CT + AD * aging time; where Δ1 is the clock frequency error.
[0219] When calculating the link delay, extract H length (harness length), Eth Tech, Connect ECU (direct connection to ECU), Connect Port (connection port number), and Chip (PHY chip model) from the node information corresponding to the second node. Based on the PHY chip model, look up the table to determine the chip asymmetry compensation parameters. Different PHY chip models correspond to different asymmetry compensation parameters. Calculate the harness length based on Eth Tech, Connect ECU (direct connection to ECU), and Connect Port (connection port number). Finally, calculate the link delay using the following formula:
[0220] Δ2 = actual bundle transmission time + compensation = H length ÷ bundle average transmission rate + chip asymmetry compensation parameter; where Δ2 is the link delay and the bundle average transmission rate is the propagation speed of electromagnetic waves, that is, the speed of light.
[0221] It should be noted that for point-to-point communication, the average transmission rate for PCIe and Ethernet cables is 5ns / m, and the average transmission rate for fiber-optic Ethernet is 4ns / m. The transceiver asymmetry compensation parameters are derived from the chip manual. For example, if the Marvell 88Q2xxx transceiver asymmetry reaches 4us, the compensation parameter is calculated as half of the asymmetry, or 2us.
[0222] When calculating the dwell time, the first step is to determine whether there is a bridge device between the first and second nodes. A bridge device is a device used to connect different Ethernet segments or different types of networks, and is used to implement functions such as data forwarding and protocol conversion. For example, when sending data from one communication link to another, a bridge device is required to forward the data, and the forwarding process has a dwell time. Bridge devices that support gPTP can read this dwell time in real time. Bridge devices that do not support gPTP can statically configure the dwell time value corresponding to the chip model.
[0223] Step 309: The controller adjusts its own clock information according to the received clock information packet 3 and precision calibration packet 4. Adjusting its own clock information includes compensating the crystal oscillator frequency.
[0224] The controller adjusts the clock and compensates the crystal oscillator frequency based on the clock information message packet3 and the precision calibration message packet4:
[0225] The clock is changed to TimeStampeSeconds+TimeStampeNanoseconds+Δ2+Δ3;
[0226] Crystal oscillator frequency compensation Δ1.
[0227] Step 310: The gateway / vehicle computing platform sends a response message packet2 indicating subscription failure.
[0228] Step 311: The controller determines whether the return code in the response message packet2 is 0x01. If so, the controller executes step 313; otherwise, the controller executes step 312.
[0229] Step 312: Record the abnormal status and try to resubscribe.
[0230] Step 313: Change the subscription direction to the gateway / vehicle computing platform where the clock with a lower priority is located.
[0231] The above implementation scheme can be applied to the clock synchronization system of a hybrid network, which includes various controllers in the vehicle, Ethernet links (such as 100 / 1000BASE-T1, multi-G BASE-T1, 10BASE-T1S, PON fiber and PCIe, etc.) connecting them, and precision calibration modules, security modules and time base modules deployed in the gateway and master clock controller. Specifically, Figure 4 As shown, the clock synchronization system includes an onboard computing platform and multiple gateways. The following description focuses on three gateways: ECU1, ECU2, and ECU3. Both the onboard computing platform and the three gateways include a precision calibration module, a security module, a time base module, and a timing protocol stack. This means that both the onboard computing platform and the three gateways can function as timing nodes. The onboard computing platform also includes a GPS module, NTP, and an internal RTC, while the three gateways also include internal RTCs. Gateways 1 and 2 are each connected to a PON optical fiber. ECU1 connects to ECU1.1, ECU1.2, ECU1.3, and ECU1.4 via 10BASE-T1S. ECU2 connects to ECU2.1, ECU2.2, ECU2.3, and ECU2.4 via 10BASE-T1S. ECU3 connects to ECU3.1, ECU3.2, ECU3.3, and ECU3.4 via 10BASE-T1S. The vehicle computing platform and the three gateways are connected via 100 / 1000 / Multi-GBASE-T1 Ethernet. Each timing node is sorted according to clock priority.
[0232] The following is an introduction to the interaction process between the timing node and the timing node. Figure 5As shown, the timing node and the security module of the timing node perform security authentication. Specifically, the timing node sends a security authentication request to the security module, which responds with a security authentication response. The timing node sends a key, which the security module verifies. If the authentication is successful, the timing node sends a verification response to the timing node. After receiving the verification response, the timing node sends a subscription message packet 1 to the timing node. The timing protocol stack of the timing node receives the subscription message packet 1, and the time base module of the timing node confirms the clock validity and resource availability. Based on the clock validity and resource availability replied by the time base module, the timing protocol stack determines the response message packet 2 and sends it to the timing node. At the same time, if the response message packet 2 indicates a successful subscription, the time base module receives the clock information feedback from the time base module, determines the clock information message packet 3, and sends a precision calibration agent service request to the precision calibration module of the timing node, inputting the parameters of packet 1. The precision calibration module completes the parameter value calculation, and the precision calibration outputs the parameters to the timing protocol stack, which then determines the precision calibration message packet 4. Based on the clock transmission requirements in the subscription message packet 1, the timing protocol stack sends the clock information message packet 3 and the precision calibration message packet 4 to the timing node. The timing node updates its own clock system based on packets 3 and 4. Furthermore, if the response message packet 2 indicates a subscription failure, for example, due to invalid absolute time or unavailable resources, the timing node can switch clock sources, such as sending a subscription message to a timing node with a lower clock priority, to achieve greater vehicle safety and interference resistance.
[0233] Please refer to Figure 6 The embodiment of the present application further provides a clock synchronization device 60 applied to a first node. The vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources. The multiple master clock nodes are sorted according to clock priority, and the first node is the node with the highest clock priority among the multiple master clock nodes. The device includes:
[0234] A first receiving module 601 is configured to receive a clock subscription request sent by a second node, where the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node;
[0235] A first determining module 602 is configured to obtain clock information in response to the clock subscription request, and determine precision calibration information matching the second node based on the node information;
[0236] The first sending module 603 is configured to send the clock information and the precision calibration information to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
[0237] Optionally, the first determining module includes:
[0238] A first determining submodule, configured to determine a clock frequency deviation based on the node information;
[0239] a second determining submodule, configured to determine a link length between the first node and the second node according to the node information, and determine a link delay according to the link length;
[0240] a third determining submodule, configured to determine, based on the node information, whether a bridge device exists between the first node and the second node, and determine a resident delay if the bridge device exists;
[0241] A fourth determining submodule is configured to determine the precision calibration information according to the clock frequency deviation, the link delay, and the residence delay.
[0242] Optionally, the first sending module includes:
[0243] A first acquisition submodule is configured to acquire a sending period carried in the subscription clock request;
[0244] The first sending submodule is configured to send the clock information and the precision calibration information to the second node according to the sending period.
[0245] Optionally, before receiving the clock subscription request sent by the second node, the apparatus further includes:
[0246] a third receiving module, configured to receive a security authentication request carrying a key sent by the second node, where the key is calculated by the second node according to the node identity of the second node;
[0247] a verification module, configured to verify the key in response to the security authentication request and determine a verification result; the verification result being a verification pass or a verification fail;
[0248] A third sending module, configured to send the verification result to the second node;
[0249] When the verification result is that the verification is passed, the second node sends the clock subscription request to the first node.
[0250] Optionally, after receiving the clock subscription request sent by the second node, the apparatus further includes:
[0251] A second determining module is configured to determine a subscription result based on the local resource information and local clock information corresponding to the first node and the node information corresponding to the second node; the subscription result is a subscription success or a subscription failure, wherein when the subscription result is the subscription failure, the subscription result carries a subscription failure reason;
[0252] A fourth sending module, configured to send the subscription result to the second node;
[0253] Wherein, when the subscription result is that the subscription is successful, the second node waits to receive the clock information and the precision calibration information sent by the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the first node, the second node sends a subscription clock request to a third node, and the third node is the node with the highest clock priority among the multiple master clock nodes except the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the second node, the second node regenerates the subscription clock request based on the reason for the subscription failure and sends it to the first node.
[0254] Please refer to Figure 7 The embodiment of the present application further provides a clock synchronization device 70 applied to a second node. The vehicle network system includes multiple nodes, the multiple nodes including multiple master clock nodes configured with clock sources and multiple slave clock nodes not configured with clock sources. The multiple master clock nodes are sorted according to clock priority. The node with the highest clock priority among the multiple master clock nodes is a first node. The second node is any node among the multiple nodes except the first node. The device includes:
[0255] The second sending module 701 is configured to send a clock subscription request to the first node, where the clock subscription request carries node information corresponding to the second node;
[0256] A second receiving module 702 is configured to receive clock information and precision calibration information sent by the first node that matches the second node; wherein the precision calibration information is determined by the first node based on node information corresponding to the second node;
[0257] The adjustment module 703 is configured to adjust its own clock information based on the clock information and the precision calibration information.
[0258] Optionally, before sending the clock subscription request to the first node, the apparatus further includes:
[0259] a calculation module, configured to calculate a key according to the node identity of the second node;
[0260] a fifth sending module, configured to send a security authentication request carrying the key to the first node; wherein the first node verifies the key and determines a verification result;
[0261] The fourth receiving module is configured to receive the verification result sent by the first node, and when the verification result is verification passed, send the subscription clock request to the first node.
[0262] Optionally, after sending the clock subscription request to the first node, the apparatus further includes:
[0263] a fifth receiving module, configured to receive a subscription result fed back by the first node; wherein the subscription result is determined by the first node based on local resource information and local clock information corresponding to the first node and node information corresponding to the second node, the subscription result being a subscription success or a subscription failure; and when the subscription result is a subscription failure, the subscription result carries a reason for the subscription failure;
[0264] A first processing module, configured to, when the subscription result is that the subscription is successful, wait to receive the clock information and the precision calibration information sent by the first node;
[0265] A sixth sending module is configured to send a clock subscription request to a third node when the subscription result is the subscription failure and the subscription failure reason is the first node, the third node being a node with the highest clock priority among the multiple master clock nodes except the first node;
[0266] The seventh sending module is configured to, when the subscription result is the subscription failure and the subscription failure reason is the second node, regenerate a subscription clock request based on the subscription failure reason and send the request to the first node.
[0267] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0268] The clock synchronization device provided in the embodiment of the present application moves the clock synchronization algorithm to the first node and provides an external precision calibration agent service. When receiving a clock subscription request sent by the second node, it can generate clock information and precision calibration information that match the second node and provide it to the second node, so that the second node can directly synchronize the clock based on the clock information and precision calibration information sent by the first node, reducing the second node's dependence on hardware selection, and further realizing high-precision clock synchronization across chips and boards without relying on hardware support, thereby improving the clock synchronization accuracy between vehicle systems and reducing functional abnormalities caused by clock deviations.
[0269] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0270] An embodiment of the present application also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and runnable on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned clock synchronization method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0271] For example, Figure 8 FIG. 1 shows a schematic diagram of the physical structure of an electronic device. Figure 8 As shown, the electronic device 80 may include: a processor 810, a communication interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communication interface 820, and the memory 830 communicate with each other via the communication bus 840. The processor 810 may call logic instructions in the memory 830.
[0272] Among them, when the electronic device is the first node, the processor 810 is used to perform the following steps: receiving a subscription clock request sent by the second node, the subscription clock request carrying node information corresponding to the second node; the second node is any node among the multiple nodes except the first node; in response to the subscription clock request, obtaining clock information, and determining the precision calibration information matching the second node based on the node information; sending the clock information and the precision calibration information to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
[0273] When the electronic device is a second node, the processor 810 is used to perform the following steps: sending a subscription clock request to the first node, wherein the subscription clock request carries the node information corresponding to the second node; receiving clock information and precision calibration information sent by the first node that match the second node; wherein the precision calibration information is determined by the first node based on the node information corresponding to the second node; and adjusting its own clock information based on the clock information and the precision calibration information.
[0274] The processor 810 can also execute other solutions in the embodiments of the present application, which will not be further elaborated here.
[0275] In addition, the logic instructions in the above-mentioned memory 830 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
[0276] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned clock synchronization method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0277] In this embodiment, the storage medium may include but is not limited to: a USB flash drive, a read-only memory ( Various media that can store computer programs, such as random access memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk or optical disk, etc.
[0278] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0279] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0280] In this application, a plurality refers to two or more.
[0281] In this application, unless otherwise expressly defined, the terms "mounted," "connected," and "connected" should be interpreted broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediary; and internal communication between two components. A person of ordinary skill in the art will understand the specific meanings of these terms in this application.
[0282] The terms "first," "second," "third," "fourth," etc. (if any) in this application are used to distinguish similar objects and are not necessarily used to describe a particular sequential order.
[0283] The term "and / or" in this application simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this application generally indicates that the related objects are in an "or" relationship.
[0284] Unless otherwise specified, all steps of the present application may be performed sequentially or randomly. For example, a statement that the method includes steps A and B indicates that the method may include steps A and B performed sequentially, or steps B and A performed sequentially. For example, a statement that the method may also include step C indicates that step C may be added to the method in any order, for example, the method may include steps A, B, and C, or steps A, C, and B, or steps C, A, and B, etc.
[0285] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A clock synchronization method, characterized in that: A method is applied to a first node in an in-vehicle network system, the in-vehicle network system including a plurality of nodes, the plurality of nodes including a plurality of master clock nodes configured with clock sources and a plurality of slave clock nodes not configured with clock sources, the plurality of master clock nodes being sorted according to clock priority, the first node being a node with the highest clock priority among the plurality of master clock nodes; the method comprising: Receive a clock subscription request sent by a second node, where the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node; In response to the clock subscription request, acquiring clock information, and determining, based on the node information, precision calibration information matching the second node; The clock information and the precision calibration information are sent to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
2. The clock synchronization method according to claim 1, wherein: Determining, according to the node information, precision calibration information matching the second node, including: determining a clock frequency deviation according to the node information; Determine, based on the node information, a link length between the first node and the second node, and determine a link delay based on the link length; determining, based on the node information, whether a bridge device exists between the first node and the second node, and determining a residence time if the bridge device exists; The precision calibration information is determined according to the clock frequency deviation, the link delay, and the dwell delay.
3. The clock synchronization method according to claim 1, wherein: Sending the clock information and the precision calibration information to the second node includes: Obtaining the sending period carried in the subscription clock request; The clock information and the precision calibration information are sent to the second node according to the sending cycle.
4. The clock synchronization method according to claim 1, wherein: Before receiving the clock subscription request sent by the second node, the method further includes: receiving a security authentication request sent by the second node and carrying a key, where the key is calculated by the second node according to the node identity of the second node; In response to the security authentication request, verify the key and determine a verification result; the verification result is verification pass or verification fail; Sending the verification result to the second node; When the verification result is that the verification is passed, the second node sends the clock subscription request to the first node.
5. The clock synchronization method according to claim 1, wherein: After receiving the clock subscription request sent by the second node, the method further includes: Determining a subscription result based on the local resource information and local clock information corresponding to the first node and the node information corresponding to the second node; the subscription result is a subscription success or a subscription failure, wherein when the subscription result is the subscription failure, the subscription result carries a subscription failure reason; Sending the subscription result to the second node; Wherein, when the subscription result is that the subscription is successful, the second node waits to receive the clock information and the precision calibration information sent by the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the first node, the second node sends a subscription clock request to a third node, and the third node is the node with the highest clock priority among the multiple master clock nodes except the first node; when the subscription result is that the subscription fails and the reason for the subscription failure is the second node, the second node regenerates the subscription clock request based on the reason for the subscription failure and sends it to the first node.
6. A clock synchronization method, characterized in that: A method for implementing a second node in an in-vehicle network system, wherein the in-vehicle network system includes a plurality of nodes, the plurality of nodes including a plurality of master clock nodes configured with clock sources and a plurality of slave clock nodes not configured with clock sources, the plurality of master clock nodes being sorted according to clock priority, the node with the highest clock priority among the plurality of master clock nodes being a first node, and the second node being any node among the plurality of nodes except the first node, wherein the method includes: Sending a subscription clock request to the first node, where the subscription clock request carries node information corresponding to the second node; Receiving clock information and precision calibration information matching the second node sent by the first node, wherein the precision calibration information is determined by the first node based on node information corresponding to the second node; The self-clock information is adjusted based on the clock information and the precision calibration information.
7. The clock synchronization method according to claim 6, wherein: Before sending the clock subscription request to the first node, the method further includes: Calculating a key according to the node identity of the second node; Sending a security authentication request carrying the key to the first node; wherein the first node verifies the key and determines a verification result; Receive the verification result sent by the first node, and when the verification result is verification passed, send the subscription clock request to the first node.
8. The clock synchronization method according to claim 6, wherein: After sending the clock subscription request to the first node, the method further includes: receiving a subscription result fed back by the first node; wherein the subscription result is determined by the first node based on local resource information and local clock information corresponding to the first node and node information corresponding to the second node, the subscription result being a subscription success or a subscription failure; and when the subscription result is a subscription failure, the subscription result carries a reason for the subscription failure; When the subscription result is that the subscription is successful, waiting to receive the clock information and the precision calibration information sent by the first node; When the subscription result is that the subscription fails and the reason for the subscription failure is the first node, sending a subscription clock request to a third node, where the third node is a node with the highest clock priority among the multiple master clock nodes except the first node; When the subscription result is the subscription failure and the subscription failure reason is the second node, a subscription clock request is regenerated based on the subscription failure reason and sent to the first node.
9. A clock synchronization device, characterized in that: A first node applied to an in-vehicle network system, the in-vehicle network system comprising a plurality of nodes, the plurality of nodes comprising a plurality of master clock nodes configured with clock sources and a plurality of slave clock nodes not configured with clock sources, the plurality of master clock nodes being sorted according to clock priorities, the first node being a node having the highest clock priority among the plurality of master clock nodes; The device comprises: A first receiving module is configured to receive a clock subscription request sent by a second node, wherein the clock subscription request carries node information corresponding to the second node; the second node is any node among the multiple nodes except the first node; A first determining module is configured to obtain clock information in response to the clock subscription request, and determine precision calibration information matching the second node based on the node information; The first sending module is configured to send the clock information and the precision calibration information to the second node, so that the second node adjusts its own clock information based on the clock information and the precision calibration information.
10. A clock synchronization device, characterized in that: A second node in an in-vehicle network system is applied, the in-vehicle network system including a plurality of nodes, the plurality of nodes including a plurality of master clock nodes configured with clock sources and a plurality of slave clock nodes not configured with clock sources, the plurality of master clock nodes being sorted according to clock priority, the node with the highest clock priority among the plurality of master clock nodes being the first node, and the second node being any node among the plurality of nodes except the first node, the device including: A second sending module is configured to send a subscription clock request to the first node, wherein the subscription clock request carries node information corresponding to the second node; a second receiving module, configured to receive clock information and precision calibration information sent by the first node that matches the second node; wherein the precision calibration information is determined by the first node based on node information corresponding to the second node; An adjustment module is configured to adjust its own clock information based on the clock information and the precision calibration information.
11. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the computer program is executed by the processor, the clock synchronization method according to any one of claims 1 to 5 or claims 6 to 8 is implemented.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the clock synchronization method according to any one of claims 1 to 5 or claims 6 to 8 is implemented.