Transceiver and system with transceivers

DE102018110252B4Active Publication Date: 2026-07-23INFINEON TECHNOLOGIES AG
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
INFINEON TECHNOLOGIES AG
Filing Date
2018-04-27
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Unauthorized communication devices can manipulate vehicle systems by interfering with communication buses like CAN, FlexRay, or LIN, necessitating a method to detect and prevent such tampering.

Method used

A transceiver system that superimposes a cryptographic datum onto a physical communication protocol signal, allowing authorized devices to authenticate and detect unauthorized access by processing the superimposed signal for cryptographic data.

Benefits of technology

Ensures secure communication by authenticating legitimate devices and detecting unauthorized access attempts, maintaining the integrity of vehicle systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Transceiver (41) comprising: a transmitter (42) configured to: - provide at an output a first signal (s1) according to a physical communication protocol for a bus, wherein the physical communication protocol defines a first voltage level within a first voltage range corresponding to a logical 1 and a second voltage level within a second voltage range corresponding to a logical 0, and - provide at the output a second signal (s2) comprising at least one cryptographic datum (14), wherein the first (s1) and the second (s2) signals are superimposed at the output as a superposition signal (s), wherein during superposition the voltage levels of the superposition signal remain within the first or second voltage range such that the superposition signal satisfies the physical communication protocol, wherein the transmitter (42) comprises a driver circuit (50),which is set up to provide the superposition signal, wherein the driver circuit (50) comprises a first series circuit of a first switch (56, 54) and a first resistor (55, 53) coupled between a supply voltage and the output, wherein the first switch (56, 54) is controllable depending on the first signal (s1), and the driver circuit has a second series circuit of a second switch (52) and a second resistor (51) coupled between the supply voltage and the output, wherein the second switch (52) is controllable depending on the cryptographic data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL AREA

[0001] The present application relates to transceivers, systems with such transceivers, corresponding signals and corresponding methods. BACKGROUND

[0002] Many devices contain a variety of components that communicate with each other to exchange data. Vehicles are one example of such devices, where numerous control units, such as microcontrollers, communicate with each other to control various vehicle functions. Additionally, sensors in vehicles detect physical quantities and communicate with the aforementioned control units to report the measured values. Examples of such control units in vehicles include engine control units, transmission control units, anti-theft control units, and the like. Examples of sensors include cameras, speed sensors, radar sensors, temperature sensors, and the like.

[0003] Communication between the various components can be wireless or wired, with wired communication being used in many applications. In vehicles, the CAN (controller area network) bus, standardized according to ISO 11898, is frequently used. Other bus systems, such as the FlexRay bus (ISO 17458-1 to ISO 17458-4) or the LIN bus (future ISO 17987-1), can also be used.

[0004] With such devices, it is possible that a communication device might attempt to illicitly participate in the communication between the components. For example, an external communication device could be connected to a vehicle's CAN bus to manipulate the vehicle, such as altering the odometer reading or disabling the vehicle's anti-theft measures. Therefore, it is desirable to be able to detect such communication devices attempting unauthorized interference. SUMMARY

[0005] Transceivers and a signal as defined in the independent claims are provided. The dependent claims define further embodiments and a system with such transceivers.

[0006] According to one embodiment, a transceiver is provided, comprising: a transmitter that is designed to - to provide an initial signal at an output according to a physical communication protocol, and - to provide at the output a second signal comprising at least one cryptographic datum, wherein the first and second signals are superimposed at the output as a superposition signal, and wherein the superposition signal satisfies the physical communication protocol.

[0007] According to another embodiment, a transceiver is provided, comprising: a receiver who is trained to - to receive a received signal which is a superposition of a first signal according to a physical communication protocol with a second signal which includes cryptographic data, - to process the received signal according to the physical communication protocol in order to obtain the information transmitted in the first signal, and - to extract the cryptographic data from the received signal.

[0008] According to another embodiment, a signal is provided comprising a superposition of: - a first signal according to a physical communication protocol, and -a second signal comprising at least one cryptographic datum, wherein the signal fulfills the physical communication protocol. List of characters Fig. Figure 1 is a block diagram of a system according to some embodiments. Fig. Figure 2 is a flowchart of a process according to some exemplary embodiments. Fig. Figure 3 shows a system according to some exemplary embodiments. Fig. Figure 4 shows a communication circuit with a transceiver according to some embodiments. Fig. Figure 5 shows a driver circuit for generating different signal levels, which can be used in some embodiments. Fig. Figures 6-9 show examples of signals according to some embodiments. Fig. Figure 10 shows part of a transmitter for a CAN bus. Fig. 11 shows curves for the circuit of the Fig. 10 when varying different parameters. Fig. 12 shows curves for the circuit of the Fig. 10 when varying different parameters. Fig. Figure 13 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 14 shows curves to illustrate some exemplary embodiments. Fig. Figure 15 shows a communication circuit according to some embodiments. Fig. Figure 16 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 17 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 18 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 19 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 20 shows a communication circuit for transceivers according to some embodiments. Fig. Figure 21 shows curves to illustrate some exemplary embodiments. Fig. 22 and Fig. Figure 23 shows diagrams illustrating the influence of electromagnetic interference. Fig. Figure 24 shows a system according to some embodiments. Fig. Figure 25 shows a flowchart to illustrate a procedure according to some embodiments. Fig. Figures 27-36 show communication circuits for transceivers according to some embodiments. Fig. Figure 37 shows a physical communication protocol and a logic protocol layer according to some embodiments. DETAILED DESCRIPTION

[0009] The following section describes various exemplary implementations in detail. It should be noted that these examples serve only as illustrations and are not to be interpreted as restrictive. Thus, a description of an exemplary implementation with a large number of features (e.g., components, properties, processes, etc.) should not be interpreted to mean that all of these features are necessary for the implementation of the respective exemplary implementation. Rather, some features can be replaced by alternative features or omitted. In addition to the features explicitly described, further features, such as those used in conventional communication circuits, can also be provided.

[0010] Features of different embodiments can be combined unless otherwise specified. Variations and modifications described for one embodiment are also applicable to other embodiments and are therefore not described again.

[0011] The following section details various implementation examples of communication circuits and arrangements of such circuits. Although the communication circuits are sometimes described with reference to specific communication media, particularly certain bus systems such as a CAN bus, the techniques presented are also applicable to other communication media, for example, wired communication media, wireless communication media, or optical communication media such as fiber optics. The use of specific examples here serves only for illustration.

[0012] The description refers in part to a physical communication protocol and a logic protocol layer. The physical communication protocol defines functions according to the physical layer of the OSI model and defines how data to be sent, e.g., a bitstream, is converted into physical signals on a transmission medium. The logic protocol layer is superior to the physical communication protocol and, in contrast, concerns, for example, higher layers of the OSI model or even layers above the OSI model (applications). It can, in particular, determine which data is transmitted, including data encoding or encryption. This is explained in Fig. 37 with a physical communication protocol 370 and a higher-level logic protocol layer 371 illustrated.

[0013] Fig. Figure 1 is a schematic representation of a system 10 according to some embodiments with a first communication circuit 11 , which in the example shown serves as a transmitter, i.e. as a sender, and a second communication circuit 12 , which in the illustrated example serves as the receiver, i.e., the receiving device. The system 10 It can be part of a device such as a vehicle, and the communication circuits 11 , 12 They can be arranged in components of this device to enable communication between the components.

[0014] The communication circuit 11 sends via a communication medium 13 Signals to the communication circuit 12 The communication medium 13It can be a wireless communication medium, a wired communication medium, or an optical communication medium. In the case of a wired communication medium, it can be, in particular, a bus system such as a CAN bus, a FlexRay bus, or a LIN bus, but is not limited to these.

[0015] While in Fig. 1 the communication circuit 11 as transmitter and the communication circuit 12 represented as a receiver, the communication circuit 11 also additional circuit components for receiving signals and / or the communication circuit 12 additionally include circuit components for sending signals to enable bidirectional communication, so that the communication circuits 11 , 12 Both are designed as transceivers (transmitting receivers).

[0016] Communication via the communication medium 13This occurs according to a physical communication protocol. Such physical communication protocols are defined for various types of communication and, as explained above, define in particular how information to be sent (user data, control data, and the like) is to be converted into physical signals (on a communication medium or wirelessly). For example, voltage levels are defined for the CAN bus and similar bus systems, which define two different states corresponding to a logical 1 and a logical 0, and signals are sent as a sequence of such voltage levels. However, other types of signals are also possible, e.g., frequency-modulated signals, AC signals, quadrature amplitude (QAM)-modulated signals, and the like.

[0017] For this purpose, a signal generation circuit receives the signal. 15a piece of information to be sent, e.g. user data or control data, and generates a first signal s1 according to the physical communication protocol. The information to be sent can be received as a logic signal from a logic protocol layer arranged above the physical communication protocol, according to a logic protocol. This first signal s1 As explained, it can, for example, have two or more different voltage or current levels to convert the information into a signal. This signal generation can be done in any conventional way for the respective physical communication protocol.

[0018] Furthermore, a modulation circuit is used. 16 the first signal s1 with a second signal s2 , which is a cryptographic date 14encompasses, overlaid. A cryptographic data is, in particular, a code or other data that authenticates a communication via the communication medium. 13 The transmitted signal is deemed to originate from an authorized communication participant (i.e., communication participants who are permitted to communicate with each other). For example, the cryptographic data may be a predefined bit sequence known only to, or determinable by, authorized communication participants. An unauthorized communication participant, such as a communication device that illicitly interacts with the communication medium, is considered to be an unauthorized communication participant. 13As explained at the beginning, the cryptographic data is not known to the sender, for example, because no corresponding key is provided. The cryptographic data can be generated using conventional cryptographic methods, for example, based on a cryptographic key provided by the transmitter. 11 from a higher authority, as will be explained later. The term "cryptographic" here is therefore not to be understood in the narrow sense of encryption, but in a broader sense as an element that contributes to the security of the system. 10 to make it resistant to manipulation. The cryptographic data can, in particular, be a security code of the transmitter. 11 represent which transmitter 11 Identified as the source of a transmitted signal, thus enabling authentication.

[0019] In the modulation circuit 16will be the second signal s2 with the cryptographic data at the physical level to that of the signal generation circuit 15 generated first signal s1 modulated, e.g. by modifying the signal levels of the first signal s1 , in order to form a superposition signal s. This differs from approaches in which the information to be transmitted is encrypted, which corresponds to encryption at a logic protocol layer. As will be explained later, however, such encryption or other encoding can additionally be performed at the logic protocol layer.

[0020] In some implementations, the communication protocol defines tolerances for the levels to be used. For example, the communication protocol may specify that a level corresponding to a logic 1 must lie within a first voltage range and / or that a level corresponding to a logic 0 must lie within a second voltage range in order to be validly recognized as a 1 or 0, respectively. In some implementations, the modulation circuit then modulates the first signal by superimposing it with the second, ensuring that the signal levels remain within the specified ranges. Other types of communication protocols may also specify tolerances for the amplitudes of the second signal. s2 be so small that the superposition signal s fulfills the physical communication protocol, i.e., that the superposition signal s is processable according to the physical communication protocol in order to obtain the information of the first signal s1to recover. In some embodiments, this can ensure backward compatibility, i.e., also receivers that are not used for the receiving circuit as later on. 12 Devices equipped with the necessary equipment can receive the signal correctly. Examples of such signal overlaps will be explained in more detail later.

[0021] It should also be noted that the signal generation circuit 15 and the modulation circuit 16 Although the circuits are depicted as blocks connected in series for illustrative purposes, as will be explained later, modulation and signal generation can also occur simultaneously. The arrangement shown therefore serves only to illustrate the different functions.

[0022] The superposition signal s, modulated in this way, is then transmitted via the communication medium. 13 to the communication circuit 12 sent. The communication circuit 12includes a signal receiving circuit 17 , which contains the information from the signal generation circuit 15 into the first signal s1 was implemented, regained. In addition, the communication circuit indicates 12 a code receiving circuit 18 on, which is in the modulation circuit 16 modulated second signal s2 Recovers contained cryptographic data. If the cryptographic data recovered in this way does not match an expected cryptographic data (e.g., one in the communication circuit) 12If the signal matches the stored cryptographic data (or cryptographic data derived from a provided key), appropriate action can be taken. For example, the received signal and the information derived from it can be discarded, a corresponding signal can be generated to inform other components of the unauthenticated signal, and / or a user can be notified. In this way, unauthorized access attempts can be detected in some implementations, and countermeasures can be taken.

[0023] The signal receiving circuit 17 It can be designed in the conventional manner for the respective physical communication protocol. Examples of the code receiver circuit 18 and in particular calibration options for the code receiving circuit 18 will be explained in more detail later. It should be noted that the communication circuit12 It can also process received signals that contain only the first signal, or where the second signal cannot be processed, for example, due to interference. In this case, only the signal receiving circuit is used. 17 processed.

[0024] Fig. Figure 2 shows a flowchart to illustrate procedures according to some embodiments. To avoid repetition, the procedure of Fig. 2 with reference to the Fig. 1 explained. The procedure of Fig. However, 2 is also independent of the device of Fig. 1 usable.

[0025] At 20 The information to be transmitted is converted into an initial signal. As already mentioned for the signal generation circuit. 15As explained, this can be done on the basis of a physical communication protocol, so that a signal is generated which has levels that can represent a logical 1 and a logical 0, or transmits the information to be sent in another way.

[0026] At 21 The transmitted signal is modulated according to a second signal, which includes cryptographic data, as for the modulation circuit. 16 in Fig. 1. The cryptographic data can be generated based on a key. This generates a superposition signal that fulfills the physical communication protocol, as described above. As for the signal generation circuit 15 and the modulation circuit 16 the Fig. 1. The implementation must also be described at 20 and modulation at 21 They do not need to take place one after the other, but can also be carried out simultaneously, for example.

[0027] On the receiving side, then at 22 The information from the superposition signal is recovered, as for the signal receiving circuit. 17 described, and at 23 The cryptographic data is recovered from the superposition signal, as for the code reception circuit. 18 the Fig. 1 described. Also, the acquisition of information at 22 and obtaining the cryptographic data at 23 do not have to be like in Fig. 2. These events do not occur sequentially, but can also occur simultaneously or in a different order. This corresponds to... 23 If the cryptographic data obtained does not match the expected cryptographic data, appropriate measures can be taken, as already mentioned with reference to the Fig. 1 explained.

[0028] The Fig. Figure 3 shows a communication circuit arrangement according to some embodiments, in which a CAN bus is used as the communication medium. 36 is used. In the exemplary embodiment of the Fig. 3 serves as a communication circuit 30 , 35 as a transmitter, and a communication circuit 31 , 37 as recipient. The reference mark 30 This refers to a transmitting node that has a transceiver 35 supplied with data to be transmitted and a security code. The transceiver 35 It can also be used to receive data, which is in Fig. 3 is not explicitly shown. The transmitting node 30 It can be implemented using a microcontroller.

[0029] Data to be sent is placed in a send buffer. 33 of the transmitting node 30 written in the conventional manner. This data to be transmitted is sent via a transmit circuit. 34converted into a bit sequence to be sent, i.e., a sequence of logical ones and zeros, since it then serves as a signal Tx to the transceiver 35 is being sent.

[0030] A security code generator 32 It receives a key and, based on this key, generates a security code as cryptographic data. The key can be received by a specially protected key management device, in particular a hardware security module (HSM), as will be explained in more detail later.

[0031] The security code generator 32Furthermore, it receives information about the data to be sent and the position of so-called dominant transmit bits, and generates the security code in the illustrated CAN protocol example such that the security code is modulated only onto dominant bits of a data portion of the transmission. With other physical communication protocols as well, specific levels can be selected onto which the second signal containing the cryptographic data is modulated.

[0032] Dominant bits are bits at which a bus such as the CAN bus 36A bit is actively driven to a certain level, while in the case of recessive bits, it is passively pulled to a different level by resistors. In CAN transmission, bits representing a logical 0 are dominant bits, and bits representing a logical 1 are recessive bits. This can differ in other communication standards, where, for example, all bits can be actively driven. "Only on one data part" refers to the fact that transmission in CAN and other communication protocols takes place in so-called data frames, which have a header followed by the data part containing the user data. In some implementations, the security code is modulated only onto this data part. This can be advantageous in the CAN protocol because multiple transmitters can transmit simultaneously on the CAN bus during the header.In other embodiments, particularly other physical communication protocols, header bits can also be used for modulation with the security code.

[0033] The transceiver 35 The amplitudes of the dominant bits are then modulated according to the security code, which in this embodiment corresponds to the superposition of the second signal. Knowing the data and the bit positions, the security code generator can generate the security code in such a way that bit transitions of the security code (from 0 to 1 or from 1 to 0) only occur on dominant bits. An example of this will be explained later. Here, the second signal is a pulsed signal with two states, corresponding to 0 and 1. In other embodiments, other types of second signals, such as AC signals like QAM-modulated signals, can also be used, as long as cryptographic data can be transmitted.

[0034] On the receiver side, a CAN transceiver decodes the data. 37 extracts the security code from the transmitted signal and sets up a receiving circuit. 38 a receiving node 31 It also provides a received signal based on the received levels according to the CAN communication protocol. The receiving circuit 38 This is done from the signal Rx received data, which is stored in a receive buffer. 39 be saved.

[0035] The recovered security code, the position of received bits, and the received data are passed to a verification circuit. 310 provided. The verification circuit 310 receives the key, based on which the security code generator 32 The security code has been generated. Based on the key, the received data, and the received bit position, the verification circuit can... 310Determine an expected security code according to the same rules used by the security code generator. 32 The security code is determined from the key, the transmission data, and the transmission bit position. Examples of this will be explained later. This expected security code is then compared with the received security code. If they match, authentication is successful and the received data can be used. If they do not match, authentication fails, and further action can be taken as already described in the following sections. Fig. 1 explains the measures that will be taken.

[0036] An example of the construction of CAN transceivers according to exemplary implementations, for example the CAN transceivers 35 , 37 the Fig. 3, are now referred to in the Fig. 4 and Fig. 5 explained.

[0037] Fig. Figure 4 shows a CAN transceiver 41according to one embodiment which uses a microcontroller 40 communicates. The microcontroller 40 This can particularly include the one for the transmission node 30 the Fig. 3 and / or the receiving node 31 the Fig. 3. Perform the functions described above, in particular provide a second signal and cryptographic data, such as a security code, and a first signal to be sent.

[0038] In Fig. 4 are the first signal to be sent, labeled Tx, the first signal is the transmitted data, the second signal is the received data, labeled Rx, the second signal is the security code, labeled sc_send, and the received security code is labeled sc_empf.

[0039] The first transmission data to be sent Tx , which determine the first signal, and the security code to be sent as the second signal are transmitted to a transmitter 42 of the transceiver 41This is transmitted. It generates a corresponding superposition signal on CAN lines CANH and CANL, according to the CAN communication protocol, which is modulated by the security code. The CANH and CANL lines are connected to a resistor as specified by the aforementioned CAN standards. 45 of about 60 Ohm connected. For recessive bits, the potential of the CANH and CANL lines is equalized via the resistor. 45 They are connected to each other, so that there is essentially no potential difference between the lines. For dominant bits, the CANH and CANL lines are activated by the transmitter. 42 actively driven towards a voltage difference.

[0040] Examples of transmitter implementation 42 This will be explained in more detail later. For receiving, the CANH and CANL lines are connected to a receiver. 43 connected, which sent the first signal s1recovered. Furthermore, the lines are equipped with a monitoring circuit. 44 The system is connected and recovers the security code from the differential voltage between the voltages on the CANH and CANL lines. This differential voltage can be compared to a threshold value, as will be explained in more detail later.

[0041] The Fig. Figure 5 shows part of a transmitter, in particular a driver, as an example of a possible implementation of the transmitter. 42 the Fig. 5. Generally, in the dominant phase, the CANH line is connected via a resistor to a positive voltage (for example, VDD, VCC, or another supply voltage Vs), and the CANL line is connected via a resistor to a lower voltage (for example, VSS, ground, or the like). This connection can be made stepwise using several resistors. Fig. Figure 5 shows a corresponding circuit for the CANH line. A corresponding circuit can also be provided for the CANL line.

[0042] The driver of the Fig. 5 includes a parallel circuit 50 a multitude of resistors 55 , 53 , 51 , each with an associated switch 56 , 54 , 52 The resistors are connected in series. The switches can be implemented using transistors. A first connection of the resistors... 55 , 53 51 is connected to a supply voltage Vs, and a respective second terminal is connected to a first terminal of the respective associated switch. Second terminals of the switches 56 , 54 , 52 are via a diode 57connected to the CANH line. The number of three resistors and three associated switches is just an example; any number of resistors with their respective associated switches can be provided.

[0043] With a recessive bit, all switches 56 , 54 , 52 opened, and over the resistance 45 the Fig. 4. A voltage difference between CANH and CAN1 is balanced. When a bit is dominant, the switches are activated. 56 , 54 , 52 successively closed, so that the voltage level on the CANH line is ultimately determined by the supply voltage Vs the value of the resistances 55 , 53 , 51 , the value of the resistance 45 as well as the value of corresponding resistors of a corresponding circuit connected to the CANL line.

[0044] During the transmission circuit 42the Fig. 4. The security code determines how many switches are activated when a dominant bit is selected, e.g., when switching between... Tx in Fig. 4 from 1 to 0, will be closed. For example, some of the switches will be 56 , 54 , 52 e.g. all switches except the switch 52 , always closed in the dominant case. Another part of the switches, for example the switch 52 In the dominant case, this is controlled depending on the security code. For example, closing the switches... 56 , 54 the level for a dominant bit of the CAN transmission is generated, and by selectively closing the switch 52 The security code is modulated. The resistance 51 In this example, it is dimensioned such that opening and closing the switch 52The voltage level on the CANH line does not deviate from the voltage range specified by the communication protocol, in this case the CAN protocol, for the dominant level. This can ensure backward compatibility in some implementations. In other implementations, more than one switch can be used to modulate the security code onto the signal.

[0045] To further illustrate, the Fig. 6 Examples of signals from the embodiment of the Fig. 4. It should be noted that these and other signal forms shown in this application are for illustrative purposes only and that the exact signal forms may change depending on the implementation, the information to be transmitted and a chosen security code or other cryptographic data, the communication protocols used, and external circumstances such as temperature.

[0046] With 60 are the transmission data Tx in Fig. 4 denotes, i.e., the one controlled by the microcontroller 40 in the transceiver 41 The received data to be sent determines the first signal. The data represents a sequence of logical ones and zeros.

[0047] With 61 The security code to be sent, which determines the second signal, is designated. 62 This represents a superposition signal ultimately transmitted on the CAN bus, where the difference between the voltages on the CANH and CANL lines, also known as Vdiff, is shown. A logical 1 in the transmitted data 60 The bus is in a recessive state, meaning the CANH and CANL lines are not actively driven, and the resistance... 45 The potential of lines CANH and CANL equalizes. The superposition signal 62The voltage difference Vdiff, which reflects the differential voltage, is therefore at or near 0. At a logical 0 (low level) of the signal... 60 The lines CANH and CANL are each connected to voltages via resistors, as described in reference to Fig. 5 explains, resulting in a differential voltage. During these dominant phases, the security code is displayed. 61 modulated as a second signal. As seen in the superposition signal. 62 As can be seen, the tension is high during the dominant phases. Vdiff slightly higher, at a level 65 , if the signal 61 at logic 1 (high level), and somewhat lower, at a level 66 , if the security code 61 is at logic 0 (low level). This can be described as follows: Fig. 5 explained by optionally closing the switch as well as the switch 52 can be achieved.

[0048] With 63are those from the signal 62 recovered reception data Rx This is called the signal. 60 with a delay that depends on the choice of sampling times. 64 The recovered security code is designated as such. This code, with a slight delay, corresponds to the transmitted security code. 61 To make this possible, signal changes, as briefly explained above, are used to change the security code. 61 chosen so that they fall during dominant phases, for example as in Fig. 6 shown, coinciding with the beginning of dominant phases, for which, as already mentioned with reference to the Fig. 3 explains how a security code generator receives information about the data to be sent. A changing edge of the signal. 61 However, during a recessive phase, this would not be immediately reflected in the signal. 62not reflected, but possibly only at the next dominant bit, which leads to a change in the signal. 64 compared to the signal 61 would lead to this.

[0049] It should be noted that, depending on the data being transmitted, a relatively large number of recessive bits can be sent successively. However, depending on the physical communication protocol used, a certain number of dominant phases are ensured, so that the security code, or more generally a second signal containing cryptographic data, can be modulated onto the signal.

[0050] As explained above, the choice of sampling times (and possibly other effects such as signal propagation times) creates a delay between the transmitted data. Tx , which are to be sent, and the recovered received data Rx This will now be discussed with reference to the Fig. 7 and Fig. 8 explained in more detail. Fig. 7 and Fig. 8 relate in particular to the recovery of the security code and the selection of sampling times for this purpose, i.e. the selection of times at which the voltage difference Vdiff is evaluated to recover the security code.

[0051] The Fig. 7 shows as a progression 70 the transmission data Tx , as a superposition signal 71 the voltage Vdiff, as a curve 72 the reception data Rx and as a course 73 the recovered security code. In this example, the voltage Vdiff regarding the security code on the falling edge of the signal Rx evaluated. In other words, as soon as a falling edge of the signal occurs, it is evaluated. Rx And thus, when a transition to a dominant phase is detected, the voltage difference Vdiff is evaluated to recover a value for the security code. This can be done by comparing the voltage difference Vdiff with a threshold value that lies between the two possible signal levels in the dominant case (see the two in Fig. 6 levels shown 65 , 66 (A voltage between these levels is then chosen as the threshold), as will be explained later. In this case, the recovered security code is... 73 to the reception data 72 Synchronous with respect to edge transitions. This requires that the superposition signal is present at that time. 71 for sampling to recover the security code, it is "valid", i.e., it has reached its steady-state value. This is the case, for example, when the loop delay is less than the time it takes to process a bit at the highest bit rate (for example, at 5 megabits per second). 200 nanoseconds), because otherwise the bit state might have changed again.

[0052] One alternative is in Fig. 8 shown. Fig. 8 shows transmission data Tx , a superposition signal 81 as a voltage difference Vdiff on the bus, reception data Rx and a recovered security code 83 Here, the differential voltage is measured. Vdiff a predetermined time dt after the falling edge of transmitted data 80 , where the time dt is chosen to be less than the duration of a bit at the highest occurring bit rate. This ensures that the bit has not changed again at the sampling time. In this case, the recovered security code is 83 Regarding edge changes, not synchronized with the received data 82 .

[0053] These sampling times are merely examples, and sampling times can generally be chosen at which the signal has reached the signal levels to be sampled to such an extent that the different levels of the modulated security code are distinguishable.

[0054] In some implementations, such as certain communication protocols, it may be desirable for signals to always behave identically with respect to their rising and falling edges. However, due to the superimposition of a second signal, e.g., modulating the security code, this consistency may not be guaranteed in some implementations. For illustration, see in Fig. 9 transmission data Tx , which represent a bit sequence to be transmitted, is shown. A curve 91This shows a case for the transmitted superposition signal when a logically high level of the security code is modulated onto it. A dashed curve. 92 shows the case of the superposition signal, in which a logically low level of the security code is modulated, with the curves being used in the example. 91 , 92 Switches are closed successively, as referred to in the Fig. Figure 5 explains this. As can be seen, the rising edges are identical in both cases until the respective signal level is reached. However, the falling edges can be offset in time. If a certain sampling threshold is used to sample the signal... 91 or 92 When used, this can be done as if through curves. 93 , 94 indicated by various reception data Rx This results in edges whose flanks are slightly offset from each other. This can be disadvantageous in some applications with high bit rates.

[0055] In such a case, switching to a higher level for a logical 1 of the security code can occur with a time delay, as is done in a lower part of the Fig. Figure 9 is shown. This again includes transmission data. Tx shown, and a course 96 shows a delayed version of the transmission data 95 In this case, the superposition signal is generated. 97 without the modulated security code based on the delayed signal 96 The modulation of the security code, however, ends with the rising edge of the signal. 95 , so that the security code is modulated at a distance from the edges of the signal, as by the signal 97shown. In other words, the second signal is superimposed according to the security code after the first signal has not changed level for a certain period of time and will not change level for a certain period of time. A threshold voltage 98 The signal change of the received signal, on the basis of which the signal change of the received signal occurs, is therefore always crossed at the same time, regardless of the modulated security code. The rising edge of the transmitted data 95 It can also be used to scan the security code (see the explanations for the Fig. 7 and Fig. 8 regarding the scanning of the security code).

[0056] By modulating the security code as in the superimposed signal 97 The loop delay will be slightly increased because of the delayed transmission data. 96as the basis for generating the signal, however, in some embodiments the behavior with regard to rising and falling edges remains independent of the modulated security code.

[0057] As explained above, the security code can be recovered by comparing the received signal (in the case of a CAN bus, the differential voltage) with a threshold value (e.g., threshold voltage). This threshold value is conveniently located between the two possible levels of the security code, for example, between the levels... 65 and 66 the Fig. 6. In some embodiments, these two levels are relatively close together, for example, to ensure that both levels are within a tolerance range for a corresponding signal level of the signal according to the communication protocol, as explained. In some implementations, the levels may also fluctuate depending on circumstances such as temperature, supply voltage, manufacturing tolerances of components, and the like, which in some embodiments can complicate the appropriate selection of the threshold voltage. This will now be addressed with reference to the Fig. 10 and Fig. 11 is explained using the example of a CAN bus, and then various calibration options are explained which make it possible to determine a suitable threshold voltage even in implementations where such variations occur.

[0058] Fig. Figure 10 schematically shows a driver of a transmitter for a CAN bus in the dominant state. Fig. Figure 10 shows the two previously discussed lines CANH and CANL of a CAN bus, which are connected via a load resistor. 100 according to the load resistance 45 the Fig. 4 are connected. The load resistance 100 CAN buses exhibit a value of 60 Ohms, where tolerances are in a range of approximately 50 Ohm to 75 Ohms are permitted. The CANH line is connected via a resistor. 101 with a resistance value RH and a diode 102 connected to a positive supply voltage VCC, and the CANL line is connected via a diode 103 and a resistance 104 connected to ground with a resistance value RL. The resistor 101 This corresponds, for example, to those resistances 55 , 53 , 51 the Fig. 5, whose switches are closed in the dominant state, is therefore an equivalent circuit diagram for the parallel switches and resistors of the Fig. 5 in the dominant state, and the diode 102 corresponds to the diode 57 the Fig. 5. The diode 103 and the resistance 104 corresponding components between CANL and ground. The differential voltage Vdiff between CANH and CANL is calculated as follows: Vdiff = ( VCC − 2 Ud ) * Rload / ( RH + RL + Rload ) , where Rload is the resistance value of the resistance value 100 and Ud is the diode voltage of the diodes 102 , 103 in the direction of passage.

[0059] RH and RL vary between the two levels used in the security code shown. To give a numerical example, RH=RL=20 ohms for one level of the security code and RH=RL=15 ohms for the other. With example values ​​VCC=5 volts, Rload=60 ohms, and Ud=0.7 volts, the formula above yields Vdiff,low=2.16 volts and Vdiff,high=2.4 volts for the two possible levels used to modulate the security code. The voltage difference between these two levels is therefore slightly over 200 mV in this example.

[0060] As can be seen from the equation above, the voltage Vdiff depends on the supply voltage VCC and the load resistance. 100 Furthermore, the quantities in the equation, for example the diode voltage Ud, also depend on the temperature. The dependence on the supply voltage and on Rload is shown in the Fig. 11 schematically represented. Fig. Figure 12 also illustrates a dependence on temperature.

[0061] In the Fig. 11 show curves 110 - 115 The voltage Vdiff across the load resistance Rload is calculated according to the equation above. Rload varies between 50 and 75 Ohm, which, for example, can correspond to an allowed variation range for CAN buses. In Fig. Figure 12 shows the voltage Vdiff plotted against the temperature.

[0062] The curves 110 - 115 The figures show the voltage Vdiff for different supply voltages and for a high level (corresponding to Vdiff,high above) and a low level (corresponding to Vdiff,low above) for the example values ​​for RH, RL. 15 or 20 Ohm as explained above. In particular, the curve shows 110 Vdiff,high for VCC=5.25 Volts, the curve 1111 Vdiff,high for VCC=5, the curve 112 Vdiff,low for VCC=5.25 Volts, the curve 113Vdiff,high for VCC=4.75 Volts, the curve 114 Vdiff,low for VCC=5 Volts and the curve 115 Vdiff,low for VCC=4.75 Volts. Fig. 12 shows the curve 120 Vdiff,high for VCC=5 volts and Rload=75 ohms, the curve 121 Vdiff,high for VCC=5 volts and Rload=60 ohms, the curve 122 Vdiff,low for VCC=5 volts and Rload=75 ohms, the curve 123 Vdiff,high for VCC=5 Volts and Rload=50 Ohms, the curve 124 Vdiff,low for VCC=5 volts and Rload=60 ohms and the curve 125 Vdiff,low for VCC=5 Volts and Rload=50 Ohms.

[0063] The external load resistor 100 The voltage is not known a priori and can vary as explained. The supply voltage can also vary, for example between 4.75 volts and 5.25 volts as in... Fig. 11 indicated. As can be seen from the Fig. 11 and Fig. 12. It is evident that in such implementations, where such variations can occur, no single threshold value (i.e., in this case, a threshold voltage) can be defined that distinguishes between Vdiff,high and Vdiff,low for all occurring load resistances, voltages, and temperatures. For example, with a threshold value of 2.30 volts as in Fig. 4 is evident when there is a resistance Rload above 60 Ohm and a supply voltage of 5.75 volts both Vdiff,high (curve 110 ) as well as Vdiff,low (curve 112 ) are above this threshold, making differentiation impossible. The same applies to other possible thresholds.

[0064] Therefore, in some embodiments where such variations can occur, calibration is performed, for which various possibilities are discussed below. In embodiments where such variations do not occur or occur only to a small extent, a single threshold value can be chosen, and calibration can be omitted.

[0065] The Fig. Figure 13 shows a circuit used for such calibration according to some embodiments. In the embodiment of Fig. 13 will be a replica of the one in Fig. The driver shown in Figure 10 is provided to obtain a reference voltage Vref. A simulation of a circuit section is a circuit that generally contains components corresponding to the circuit section, which may be scaled with respect to the circuit section (for example, they may have an area reduced by a scaling factor, a resistance increased by a scaling factor, and the like). The simulation in the exemplary embodiment of Fig. 13 includes a resistor 131 according to the resistance 101 , a diode 132 corresponding to the diode 102 , a diode 133 corresponding to the diode 103 and a resistance 134 according to the resistance 104 As in Fig. The resistances are indicated in point 13. 133 , 134 regarding the resistances 101 , 104 scaled by a factor n, in particular by a factorn higher, which limits the current flow through the replica. The diodes 132 , 133 compared to the diodes 102 , 103 The area is reduced by the scaling factor n, which decreases the area required for the simulation and thus the current draw. For typical values, n > 30 can be used to keep the current draw of the simulation below 1 mA. Significantly higher values ​​of n would further reduce the current draw, but depending on the implementation, they could affect the matching of the simulation to the original. Fig. The 10 drivers shown deteriorate. For the resistors 131 , 134 An intermediate value between n*RH and n*RL can be used for the high and low levels of the security code. Above the resistor 130A voltage drop then occurs, which is used as a reference voltage in some embodiments. With such a circuit, fluctuations in the supply voltage VCC and the temperature affect the voltage Vdiff and the reference voltage Vref obtained through the simulation in the same way, thus compensating for the influence of fluctuating reference voltages and temperatures.

[0066] However, this does not yet account for fluctuations in the resistance value Rload of the resistor. 100 balanced. Since the resistance 100 Since many implementations involve external resistance, this is often not known a priori.

[0067] In embodiments where such variations of a load resistance occur, which affect the levels of the modulated second signal, e.g. based on the discussed security code (in this case the voltage Vdiff), the resistance can additionally be 130 , which increases resistance 100 It can be modeled, adjusted, and calibrated to a value RL_RF=n*Rload, where n is the scaling. Methods for performing such a calibration will be explained in more detail later. The result of such a calibration is shown in Fig. 14 shown. Fig. 14 shows a curve 140 The voltage Vdiff,high for a supply voltage of 5 volts and a load resistance Rload of 55 Ohms versus temperature, and a curve 142 shows the voltage Vdiff,low for the supply voltage and the load resistance of 55 Ohm. A curve 141shows a reference voltage Vref versus temperature, which is connected to a resistor. 130 was won, whose resistance value RL RF was at 55 The resistances were set to ohms. 131 , 134 The values ​​were each n*17 ohms, i.e., a value between the example values ​​mentioned above. 20 Ohm and 15 Ohm values ​​represent low and high levels of the security code.

[0068] Similar results are obtained with other values ​​of Rload. Thus, by calibrating the resistance value RL RF, a reference voltage can be generated in some embodiments, which can be used as a threshold voltage to distinguish the two levels.

[0069] Fig. Figure 15 shows a calibration circuit according to some embodiments, with which such calibration of a simulated resistance can be carried out to determine a suitable threshold voltage (reference voltage) as a threshold value. Fig. 15 includes the part of the transmitter driver with the reference numerals 100 - 104 , which already refers to the Fig. As described in section 10. As already explained, the resistors can 101 , 104 each of two different values ​​(e.g. 15 Ohm and 20 Ohm) assume, and these are in Fig. 15 with R1 and R2 designated. R1 This corresponds to the resistance value for the low level ( 20 Ohm in the above example) and R2 for the high level ( 15 Ohm in the example above), i.e. R2 < R1 .

[0070] The circuit of the Fig. 15 comprises two simulations of this driver. A first simulation includes a resistor. 153 , according to the resistance 101 , a diode 154 corresponding to the diode 102 , an adjustable resistance 155 according to the resistance 100 , a diode 156 corresponding to the diode 103 and a resistance 157 corresponding to the diode 104 The diodes 154 , 156 are regarding the diodes 102 , 103 scaled by a factor of n (for example, by n smaller area) and the resistance values ​​of the resistors 153 , 157 n*R2, i.e., with respect to the resistance value of the resistors 101 , 104 Scaled for the high level of the security code.

[0071] A second replica includes a resistor. 158 according to the resistance 101 , a diode 159 corresponding to the diode102 , an adjustable resistance 1510 according to the load resistance 100 , a diode 1511 corresponding to the diode 103 and a resistance 1512 according to the resistance 104 The diodes 159 , 1511 are in turn related to the diodes 102 , 103 Scaled by a factor of n, for example, they have an area n times smaller. The resistors 158 , 1512 are with regard to the resistance value R1 scaled by n, i.e., with respect to the resistance value for the low level.

[0072] A calibration circuit 152 measures the differential voltage Vdiff across the resistor 100 For calibration purposes, for example, the transmitting circuit can first measure the resistance at the beginning of a CAN telegram or during a calibration phase. R1 for the resistors 101 , 104 adjust and then the resistance R2or vice versa.

[0073] In addition, the calibration circuit measures 152 the voltage drop across the resistor 155 , in Fig. 15, designated as Vref2, and the voltage drop across the resistor 1510 , in Fig. 15 is designated as Vref1, where the resistors 155 , 1510 are set to the same resistance value.

[0074] During the calibration phase, the calibration circuit 152 during the phase in which the resistances 101 , 104 on R1 are set to the resistance 1510 and the resistance 155 such that Vref1 = Vdiff. Since the resistances 158 and 1512 equal to nx R1 According to this setting, the value of the resistances is... 1510 , 155 equal to nx Rload. In this way, the resistors are thus determined. 155 and 1510The resistance value Rload of the resistor is adjusted so that the reference voltages Vref1 , Vref2 the two possible values ​​of the signal Vdiff for high and low levels of the security code. From the values Vref1 , Vref2 A threshold value Vref for recovering the security code can then be determined by setting Vref to a value between Vref1 and Vref2 is set.

[0075] In the exemplary embodiment of the Fig. 16 is in addition to the two replicas of the Fig. 15 a third replica comprising a resistance 160 according to the resistance 101 , a diode 161 corresponding to the diode 102 , an adjustable resistance 162 according to the load resistance 100 , a diode 163 corresponding to the diode 103 and a resistance 164 according to the resistance 104provided. The resistance 160 and the resistance 164 are with respect to a resistor with a resistance value that is between R1 and R2 The resistance is scaled by a factor of n. If, as in the numerical example, R1 = 20 ohms and R2 = 15 ohms, then the resistance values ​​of the resistors can be... 160 and 164 for example n*17 ohms or n times another value between R1 and R2 be. The diodes 161 and 163 are compared to the diodes 102 and 103 Also scaled by a factor of n, for example, they have an area n times smaller.

[0076] In this case, the resistances 155 , 1510 and 162 simultaneously set as explained above, e.g. so that Vref1 = Vdiff in a phase in which the resistances 101 , 104 on R1 are, applies. By choosing the resistors 160 , 164then falls at the resistance 162 A reference voltage Vref is applied, which lies between Vdiff,high and Vdiff,low and can therefore be used as a threshold for obtaining the security code from the received signal.

[0077] Another way to determine a voltage Vref, which can serve as a threshold, is in Fig. 17 shown. Compared to the Fig. 15 are in the exemplary embodiment of the Fig. 17 additional resistors 170 , 171 , 172 , 173 provided, which as in Fig. 17 shown with the resistors 1510 , 155 are interconnected. In some embodiments, all resistors have 170 - 173 an equal resistance value R on. Between a first node, which is located between the resistors 170 , 171 lies and a second node, which is located between the resistors 172, 173 If the voltage is within the specified range, a voltage Vref, which can serve as a threshold, can then be measured. Do all resistors exhibit this? 170-173 If the resistance values ​​are the same, then Vref = (Vref1 + Vref2) / 2. By changing the resistance values 170-173 This can be changed, for example, Vref can be moved closer to Vref1 or closer to Vref2 can be pushed. In exemplary embodiments, the resistors exhibit 170-173 higher resistance values ​​than the resistances 153 , 157 , 158 and 1512 In some embodiments, this can reduce the error in determining the reference voltage Vref.

[0078] In some implementations, interference can occur on communication lines, such as bus lines, or in the case of a CAN bus, the CANH and CANL lines. Examples of such interference include high-frequency interference (RF interference), which can be caused, for example, by electromagnetic interference (EMI).

[0079] If such disturbances occur during the described calibration processes, they can distort the calibration result. To avoid this, measures can be taken in some embodiments. For example, in the embodiment of Fig. 16 an additional voltage monitoring 1513Optionally, a device can be provided that monitors the voltage on the CANH and CANL bus lines and checks whether it is within a permissible range. For a CAN bus, the permissible range might be between 1 and 4 volts, for example. Other communication media may have different permissible ranges.

[0080] A calibration, i.e., an adjustment of the resistances. 1510 , 155 , in order to adjust according to the measured voltage Vdiff This calibration is only valid if the voltages on the CANH and CANL lines of the buses are within the permitted range. If they are outside the permitted range, the calibration is invalid and must be repeated.

[0081] In another embodiment, which is in the Fig. As shown in 18, the resistors can 1510 and 155 They can be set independently of each other by two calibration circuits. Accordingly, compared to the Fig. 15 in the Fig. 18 the calibration circuit 152 through a first calibration circuit 180 to adjust the resistance 155 and a second calibration circuit 181 to adjust the resistance 1510 replaced. The calibrations can be performed at different times. A comparison circuit. 182 Compare the calibration results. With correct calibration, the values ​​for the resistors should be... 155 and 1510 The set resistance values ​​must be at least approximately the same. If they differ by more than a predefined threshold, the resistance settings will be adjusted in some embodiments. 155 , 1510 The calibration is discarded, and the calibration is repeated. These measures to ensure a successful calibration, which can also be referred to as calibration validation, are carried out with reference to the Fig. 16 and Fig. The points explained in section 18 are also applicable to other embodiments, for example the embodiment of Fig. 17.

[0082] In some implementations, the calibration described above is only performed during certain phases of communication. For example, a CAN bus has communication phases such as an arbitration phase at the beginning of communication, during which many senders may be in a dominant state. Calibration at such a time could, in some cases, distort the calibration result. Therefore, in some implementations, calibration is only performed outside of such an arbitration phase.

[0083] In some implementations, calibration can be activated by a separate signal from a microcontroller or other control system. An example of this is in Fig. 19 shown. The exemplary embodiment of the Fig. 19 is a variation of the embodiment of the Fig. 4, and identical components have the same reference symbols and are not explained again.

[0084] In addition to the in Fig. The 4 components shown can be used to identify the microcontroller 40 by an arrow 190 This is represented by a signal calibration_en, which activates and deactivates the calibration. This allows the microcontroller to... 40 For example, deactivate calibration during the arbitration phase mentioned above.

[0085] Above, various possibilities were explained for dealing with variable external resistance such as the load resistance. 100 A calibration can be performed to obtain a reference voltage Vref as a threshold value.

[0086] In other embodiments, the difference between voltage levels for the security code can be chosen such that a uniform reference voltage can be used across the entire permissible range of load resistances, thus eliminating the need for calibration. This can be considered a calibration of the driver on the transmitter side. A corresponding embodiment is described in Fig. 20 shown.

[0087] The Fig. Figure 20 again shows the described part of the transmitting circuit with the reference symbols. 100-104 Furthermore, a replica is provided in which a resistor 201 the resistance 101 , a diode 202 the diode 102 , a resistance 200 the resistance 100 , a diode 203 the diode 103 and a resistance 204 the resistance 104 This corresponds to the diodes. 202 and 203 are regarding the diodes 102 and103 Scaled by a scaling factor n, they have, for example, an n times smaller area. The resistance 200 is with respect to an average resistance value of the load resistance 100 scaled by a factor of n. In the case of a CAN bus, the resistance can be 200 for example, have a resistance value of n*60 ohms. The resistors 201 and 204 are with respect to an average value of the resistances 101 , 104 scaled by the scaling factor n. As already explained, the resistors can 101 , 104 To generate two levels for modulating the security code, two different values ​​must be assumed, and the resistors 201 , 204 are scaled with respect to an intermediate value.

[0088] To give a numerical example, in the exemplary implementation of the Fig. 20 the resistances 101 , 104 either on 10Ohm for a high level or on 20 Ohm is set for a low level, which corresponds to a difference of approximately 500 mV between the levels in the numerical examples used above. The resistances 201 , 204 They can then have a value of n*15 ohms, or n * any other value between 10 Ohm and 20 The voltage drop across the resistor is, for example, n*14 ohms. 200 This voltage is then used as a reference voltage to recover the security code. In such embodiments, no calibration of the resistor is required. 200 necessary. However, in some embodiments, the area requirement is greater due to the larger difference between the two resistance values. 101 , 104higher. Furthermore, the difference between the levels cannot be chosen arbitrarily high, depending on the communication protocol used, if the backward compatibility explained above, in which the levels are kept within specified ranges, is to be maintained.

[0089] The Fig. Figure 20 shows simulation results for a circuit as described above. Fig. 20 explained. Fig. Figure 20 shows, in particular, the voltages Vdiff,high and Vdiff,low as a function of temperature in degrees Celsius for various load resistances Rload and a constant supply voltage VCC = 5 volts. A curve 210 Vdiff,high shows a curve for Rload=75 Ohm. 211 Vdiff,high shows a curve for Rload=50 Ohm. 213 shows Vdiff,low for Rload=75 Ohm and a curve 214 shows Vdiff,low for Rload=50 ohms. A curve 212 indicates the reference voltage across the resistor 200 the Fig. 20 for a resistance value of n*60 ohms. As can be seen, this can be applied to the entire range of Rload from 50 Ohm to 75 Ohm using the reference voltage 212 according to the curve 212 A distinction is made between Vdiff,high and Vdiff,low.

[0090] Therefore, an embodiment without the calibration described above is also possible, for example by referring to Fig. Section 20 explains the possible resistance values ​​for the resistors. 101 , 104 should be chosen so that the distance between Vdiff,high and Vdiff,low is sufficiently large.

[0091] As explained above, the difference between Vdiff,low and Vdiff,high is generally relatively small, for example, approximately 200 mV or approximately 500 mV in the examples above. This signal can be affected by electromagnetic interference. To improve electromagnetic compatibility (EMC), measures can be taken in some implementations to at least reduce the effects of electromagnetic interference on the signal. This will now be discussed with reference to the Fig. 22 and Fig. 23 explained. Fig. 22 and Fig. Figures 23 each show an equivalent circuit diagram for an output stage of a CAN bus with lines CANH, CANL under the influence of an electromagnetic disturbance.

[0092] Both in Fig. 22 as well as in Fig. 23 is with the reference numeral 220 the output resistance (corresponding to the resistance 100 (in previous figures), which is about 60The resistance is measured in ohms. Each line CANH, CANL is connected to a line with a resistance of ohms. 221 , 222 The resistance shown is approximately 120 ohms in the example. Additionally, there is a capacitance. 223 or 224 provided with a capacitance value of 4.7 nanofarads. The resistors 221 , 222 and the capacities 223 , 224 represent a coupling network through which disturbances are coupled into the bus lines CANH, CANL.

[0093] In the case of the Fig. 22 and Fig. 23. An electromagnetic disturbance is caused by a source of disturbance. 226 , with alternating current source 228 and resistance 227 shown, via the coupling network ( 221 - 224) coupled into the CANH and CANL lines. In the event of such a fault, Vdiff is provided by a short-circuit current corresponding to the maximum possible current flow, since in this case current limiting occurs on the CANH-coupled side or the CANL-coupled side of a driver. This driver is in Fig. 22 by a power source 229 and in the case of Fig. 23 by a power source 230 represented. At high voltages (e.g., due to disturbances), current-limiting drivers behave like a current source. The current sources 229 or 230 They therefore also represent the short-circuit current in the case of Fig. 22 to a positive voltage, such as VCC, and in the case of the Fig. 23 flows to ground. Such a current limit can be achieved, for example, by a maximum current flow through a switch implemented by one or more transistors, such as the switch 56 ,54 , 52 the Fig. 5 occur.

[0094] In both cases, the short-circuit current flows equally through both lines CANH and CANL, as indicated by the arrows. 2210 , 2211 in the Fig. 22 and Fig. 23 indicated.

[0095] The resulting differential voltage Vdiff is in this case Vdiff=Rload*ishort / 2, where ishort is the short-circuit current.

[0096] By appropriately selecting the current limit for this short-circuit current, it can be ensured that the voltage Vdiff remains essentially unchanged even in the presence of electromagnetic disturbances. In particular, the short-circuit current ishort can be set to be twice the current flowing under normal conditions (i.e., the current flowing in the dominant state). Such current limiting can be achieved in any conventional manner, for example, by means of a current mirror.

[0097] As explained above (in the case without electromagnetic interference) Vdiff=(VCC-2Ud)*Rload / (RH+RL+Rload).

[0098] With the aforementioned condition that the short-circuit current is twice the current flowing under normal conditions, one obtains ishort = 2 ∗ ( VCC − 2 Ud ) / ( RH + RL + Rload ) .

[0099] This means that the voltage Vdiff,en is under the influence of an electromagnetic disturbance. Vdiff ,en = Rload*ishort / 2 = Rload* ( VCC − 2 Ud ) ( RH + RL + Rload ) and thus equal to the above value of Vdiff without the influence of electromagnetic interference. Therefore, by limiting the short-circuit current as described above, the influence of electromagnetic interference on the differential voltages Vdiff can at least be reduced, if not eliminated, in some embodiments. The current limiting value ishort can be changed according to the changes in RH and RL for the different levels of the second signal. In other embodiments, an average value for ishort can also be calculated for the different values ​​of RH and RL.

[0100] Many examples of implementation have been discussed above, in which a first signal containing cryptographic data is modulated onto a signal at a physical layer. In addition to this security code, encoding can also take place at a logic protocol layer; that is, the information to be transmitted is encrypted using a (secret) key, which can be identical to or different from the key used to generate the cryptographic data. As explained below, this provides redundancy with simultaneous diversity (different security procedures, encryption at the logic protocol layer, and superimposition with the second signal containing the cryptographic data). Such key-based encryption can be implemented in various forms using conventional methods.

[0101] The Fig. 24 shows a corresponding communication circuit arrangement according to an embodiment with a first communication circuit 241 , which serves as a transmitter, and a second communication circuit 242 , which serves as a receiver. The exemplary embodiment of the Fig. 24 is based on the embodiment of the Fig. 1, and corresponding elements bear the same reference symbols. In particular, the modulation of a second signal with cryptographic data takes place at the physical level, as with reference to the Fig. 1 described, where all references to the Fig. The variants and implementation options described in 1-23 are applicable.

[0102] Therefore, only the differences between the communication circuit arrangement will be discussed below. 240 and the communication circuit arrangement 10 the Fig. 1 explained.

[0103] In the communication circuit 241 This information to be sent is from a signal generation and coding circuit. 245 The signal generation and encoding circuit encrypts the information based on a key on a logic protocol layer that operates according to a logic protocol. A transmission signal is then generated based on this encrypted information, similar to how a signal is generated by the signal generation circuit. 15 the Fig. As described in section 1, the difference is that the encrypted information now serves as the basis. This signal is then used in the modulation circuit. 16 as described, the second signal with the cryptographic data 14 modulated and the signal is transmitted via the communication medium 13 transmitted.

[0104] In the communication circuit 242 This is achieved, firstly, by the code reception circuit already described.18 the one in the modulation circuit 16 The modulated security code is recovered. Secondly, a signal reception and decoding circuit is used. 247 Firstly, the encrypted information is recovered from the received signal, and then the encrypted information is decrypted in a logic protocol layer. For this purpose, the signal reception and decoding circuit has the key used for encryption or a corresponding decryption key.

[0105] This encryption and decryption can be done in any conventional way.

[0106] Does this correspond to the code reception circuit? 18If the cryptographic data obtained does not match the expected security code, measures can be taken as described. These measures may correspond to those already described. Furthermore, if the decryption fails in the signal reception and decoding circuit... 247 If the process proceeded correctly, only a warning may be issued, or no action may be taken if authentication based solely on successful decryption at the logic protocol layer is acceptable. This approach thus provides redundancy with two different security mechanisms (encryption at the logic protocol layer and modulation of a second signal with cryptographic data at the physical layer) while simultaneously offering diversity (two different measures).

[0107] In the Fig. 25 describes a corresponding method according to some embodiments. The method of Fig. 25 can be used in the communication circuit arrangement 240 the Fig. 24 is implemented and is described with reference to these to avoid repetition, but can also be implemented independently of the communication circuit arrangement. 240 be used.

[0108] As already for the procedure of Fig. The following procedural steps must be carried out: 2. Fig. 25. The processes do not necessarily have to be carried out in the order shown, and in particular, different processes can also be carried out simultaneously.

[0109] At 250 Information is encrypted, for example based on a key, as for the signal generation and coding circuit. 215 described. At 251We converted the encrypted information into an initial signal, in particular based on a physical communication protocol, such as the CAN protocol discussed or another communication protocol.

[0110] At 252 The first signal is superimposed by a second signal containing cryptographic data. This cryptographic data can be a key used for encryption. 250 The data used could be a derived date or another cryptographic date.

[0111] The resulting superposition signal is sent to a receiver, and at 253 The encrypted information is recovered from the transmitting signal. At 254 The encrypted information is then decrypted. At 255 Furthermore, the cryptographic data is recovered from the superimposed signal. Depending on whether the decryption at 254and / or the cryptographic data that is used at 255 If the information obtained matches an expected cryptographic date, the information can be considered authenticated, i.e., sent by an authorized recipient, as has also been described previously.

[0112] The described functionalities can be implemented in various ways. In particular, some of the functionalities, such as providing the security code adapted to the data to be sent, can be provided in a microcontroller, as is the case for the microcontroller. 40 the Fig. 19 described, which then sends corresponding information to a CAN transceiver such as the CAN transceiver 41 the Fig. 19 gives and receives from this. Details of such implementation possibilities will now be discussed with reference to the Fig. 26-36 explained.

[0113] The Fig. Figure 26 shows a block diagram of a microcontroller. 260 according to an exemplary embodiment.

[0114] The microcontroller 260 This could be, for example, a vehicle's control unit (MCU, microcontrol unit), such as an engine control unit, transmission control unit, or other control unit. Vehicles often contain a large number of such control units.

[0115] In addition to the functions of the microcontroller explicitly described below 260 and the microcontroller described below can also perform other conventional functions. 260 be implemented.

[0116] The microcontroller 260 It features a hardware security module (MSM) 261on which keys are stored that can serve as cryptographic data in the methods and devices described above, or from which such cryptographic data, e.g., the described security code, can be generated. The hardware security module 261 It is protected against access and interference, such as interference from particles, electromagnetic radiation, and the like, by additional, individually known measures. It is also more resistant to attacks and unauthorized access than the rest of the microcontroller. 260 protected. Hardware security module software 261 For example, it can run in separate memory areas, and algorithms can be side-channel resistant.

[0117] The microcontroller 260 It also contains one or more circuit components designated as SPAD (safe physical anomaly detection). 263A-263D which implement the described techniques. In particular, any SPAD can 263A-263D (hereinafter collectively referred to as SPAD) 263 (designated) provide a security code to be modulated for a transceiver such as a CAN transceiver, as is described by reference to the Fig. 4 has been explained. The number of four SPADs 263 in Fig. 26 is merely an example, and any required number of SPADs can be chosen.

[0118] The SPADs 263 receive control and data information via an internal bus 262 of the microcontroller. For example, the data and information to be sent regarding the position of transmit and receive bits can be specified, such as with reference to the Fig. 3 will be explained and provided. Additionally, the SPADs will receive 263 Key from the hardware security module 261 This can also be done via the control and data bus. 262or via a separate connection, as indicated by dashed lines. These keys can then be used as cryptographic data in the techniques described above, or a cryptographic data set, such as the security code discussed, can be generated from the keys according to a predefined algorithm.

[0119] Each SPAD can be assigned a communication interface. This is shown schematically in the Fig. 27 is shown. Here, a microcontroller comprises 270 SPADs 273A -274D and the hardware security module 261 the Fig. 27. The SPADs 273A-273D are hereinafter collectively referred to as SPADs 273 designated, where the number is four SPADs 273 This is again only to be understood as a non-limiting example. Each of the SPADs 273 is a respective communication interface 274A , 274B , 274C or 274C(summarized as communication interfaces) 274 (designated) assigned. The communication interfaces 274 They can be coupled with CAN transceivers as described, or with transceivers for other types of buses, but are not limited to this.

[0120] In the exemplary embodiment of the Fig. 27 is every SPAD 273 a respective communication interface 274 assigned. In other embodiments, a SPAD can be assigned to multiple communication interfaces. One such embodiment is a microcontroller. 280 in Fig. 28 shown. Fig. 28 shows a microcontroller 280 with the hardware security module already described 261 and the internal bus 262 The bus has communication interfaces. 262A - 262C , summarized as communication interfaces 282Designated, arranged. The communication interfaces 282 can be seen as submodules of a single communication interface, belonging to a single SPAD 281 is assigned. The SPAD 281 The described techniques are used for all communication interfaces. 282A-282C The number of three communication interfaces shown is shown. 282 in Fig. 28 is just one example. Thus, the Fig. 27 and Fig. 28, that SPADs can be assigned communication interfaces in various ways. Hybrid forms between Fig. 27 and Fig. 28 are possible, where some SPADs are assigned to multiple communication interfaces and other SPADs are assigned to only a single communication interface.

[0121] The Fig. Figure 29 shows a block diagram of a SPAD. 290 , as he is known, for example, as SPAD in the Fig. 26, Fig. 27 and Fig. 28 usable.

[0122] The SPAD 290 a module includes 291 for key exchange with a hardware security module such as the hardware security module described 261 the Fig. 26-28. Based on a received key, a module represents 293 A security code is provided for modulating a signal at a physical level, as described. A module 294 receives a security code derived from a received signal and executes it in a module 292 Authentication is based on a received key that specifies an expected security code, as described. Authentication at 292This can be done redundantly. For example, as described, the transmitted information can be encoded on a logic protocol layer, or the verification of the received security code can be performed redundantly in multiple circuit sections. Depending on the success of the authentication, a signal can then be output indicating successful or failed authentication, and in the event of failed authentication, measures can be taken as described.

[0123] As explained above, a device such as a vehicle can contain a large number of microcontrollers. In some embodiments, information about successful or failed authentications from multiple microcontrollers can be collected, and actions can then be taken based on this information. This is demonstrated in Fig. 30 schematically represented.

[0124] Fig. Figure 30 shows a variety of microcontrollers 300A , 300B , 300C (The number three microcontrollers is again only an example), each containing a SPAD as described above for authentication and connected to a communication medium, such as a shared bus. Each of the microcontrollers 300 performs authentication measurements (e.g., the described checks of a received cryptographic data) on the bus and reports information about the authentications (e.g., about failed authentications) to an aggregation unit. 301 The aggregation unit 301The system evaluates the received information and triggers further actions. For example, if only one MCU fails to authenticate a signal, no action may be taken in some implementations, as this could also be due to a transmission error. If multiple microcontrollers receive unauthenticable messages, this can be interpreted as an intrusion attempt, and action can be taken as described. This also provides redundancy in the detection of unauthorized communication devices and can thus help meet security requirements.

[0125] A SPAD can receive signals from a transmission medium such as the transmission medium 13 the Fig. 1 received in various ways. This will now be discussed with reference to the Fig. 31- Fig. 35 explained in more detail.

[0126] In the Fig. 31 is a SPAD312 and an associated communication interface 311 in a microcontroller 310 arranged. Further elements, as described above, may be present in the microcontroller, in particular a hardware security module and further communication interfaces and / or further SPADs. The communication interface 311 is with a transceiver 313 , which implements a physical layer of communication, connected, for example, to a CAN transceiver as described. The transceiver 313 then communicates via a physical medium 315 , for example a CAN bus.

[0127] In arranging the Fig. SPAD receives 31 312 direct signals from the physical medium 315 via an intermediate protective circuit 314 , for example, to recover the security code. The protection circuit 314It can include common protective elements such as electrostatic discharge (ESD) protection elements, overcurrent protection elements, or overvoltage protection elements. The exemplary embodiment of Fig. 31 can use a conventional transceiver, but requires an additional protection circuit. 314 .

[0128] Another arrangement is in the Fig. 32 is shown here again. Here is another communication interface. 321 and a SPAD 322 in a microcontroller 322 arranged. The communication interface 321 communicates with a transceiver 322 , which in the case of the Fig. 32 in more detail with a driver circuit 327 , a broadcaster 326 , a recipient 325 and a protection circuit 324 is shown. In contrast to the Fig. 31 uses the SPAD here as a protection circuit 324of the transceiver 323 with, i.e., it receives from the protection circuit 324 Filtered signals. The exemplary implementation of the Fig. 32 does not require an additional protection circuit, but it does require a suitably designed transceiver. 323 , which is protected by the protection circuit 324 the signal goes directly to the SPAD.

[0129] Another arrangement is in Fig. 33 shown. A microcontroller 330 includes a communication interface 331 and a SPAD 332 The communication interface 331 is with a transceiver 334 connected, which, like the transceiver of the Fig. 32 a driver circuit 335 , a transmitter 336 , a recipient 337 and a protection circuit 338 It contains. From the protection circuit 338 signals from a measuring circuit 339supplied, which can, for example, recover the security code and transmit the recovered security code via an interface 3310 to a corresponding interface 333 in the microcontroller 330 and from there to SPAD 332 sends. Here, recovery takes place – as also, for example, in… Fig. 4 shown - in the transceiver.

[0130] The exemplary embodiment of the Fig. 33 requires a more complex transceiver 334 with the measuring circuit 339 However, on the other hand, it allows for more precise measurements.

[0131] In another embodiment, which is in Fig. As shown in 34, a measuring unit can be used. 349 according to the unit of measurement 339 outside of a transceiver 344 and outside of a microcontroller 340 together with an interface 3410be arranged, for example in a separate module, to be directly connected to the medium 315 To perform measurements. The transceiver 344 contains a driver circuit 345 , a transmitter 346 , a recipient 347 and a protection circuit 348 The microcontroller 340 contains a SPAD 342 , a communication interface 341 and an interface 343 Here is an additional unit with the unit of measurement. 349 and the interface 3410 necessary, which may require its own protection circuit. Otherwise, the functionality is the same as in the exemplary embodiment of the Fig. 33.

[0132] The Fig. Figures 31-34 thus show that different divisions and implementations of the discussed functionalities are possible.

[0133] The functionalities of a SPAD can also be provided centrally in a switched network. Fig. Figure 35 shows such a network with a switch 352 , which includes various communication participants, in the example of the Fig. 35 a first microcontroller 350 with a first transceiver 351 , a second microcontroller 3511 with a second transceiver 359 and a third microcontroller 3512 with a third transceiver 3510 optionally connects them together. The switch indicates this option. 352 Transceiver 353 , 358 and 357 up, to use the transceivers as shown 351 , 359 and 3510 to communicate. Furthermore, the switch has 352 via a processor unit 355 with a SPAD 356 , which means that the microcontrollers 350 , 3511 , 3512via the respective transceivers 351 , 359 , 3510 The transmitted signals must be authenticated. In this case, not every microcontroller needs to have a SPAD; instead, the authentication (verification of the modulated cryptographic data and / or additional encryption at the logic protocol layer) can be performed centrally in the switch.

[0134] Even with a transceiver that handles multiple channels, for example, multiple channels on one or more CAN buses, the provision and verification of a security code for all channels can be performed in a single unit. An example is given in Fig. 36 schematically represented.

[0135] In the exemplary embodiment of the Fig. 36 transmit / receive nodes 361A , 361B , 361C a transmission signal TX for a respective assigned CAN bus 362A , 362B or 362CThey are ready and receive a corresponding received signal RX. In this respect, the function of the CAN nodes corresponds to this. 361A , 361B , 361C the elements 33 , 34 , 39 and 38 the Fig. 3.

[0136] The provision of a security code is carried out in a time-division multiplexed manner based on a time control by a time-division multiplexer, which acts like an arrow. 356 hinted at the security code for a multi-channel transceiver 364 provides and controls which CAN bus 362A , 362B , 362C Each node is served. 361A , 361B , 361D deliver, also with reference to Fig. 3 described the data and the bit positions at the time multiplexer 360 so that it can generate a suitable security code for modulating onto dominant bits of the respective CAN bus. The transceiver364 The security code is then modulated onto the signals on the respective CAN bus as described previously, with the difference that this is done alternately for the CAN buses using a time-division multiplexing method. In this way, in some implementations, a system for multiple CAN buses can be realized with a comparatively small number of components.

[0137] As can be seen from the figures described above, there are numerous ways to implement the described techniques. Therefore, the application of these techniques is not limited to a single, specific implementation method.

[0138] The following examples define at least some of the implementation examples.

[0139] Example 1. Having a transceiver: a transmitter that is designed to - to provide an initial signal at an output according to a physical communication protocol, and - to provide at the output a second signal comprising at least one cryptographic datum, wherein the first and second signals are superimposed at the output as a superposition signal, and wherein the superposition signal satisfies the physical communication protocol.

[0140] Example 2. Transceiver according to Example 1, where the second signal is a pulsed signal or an alternating current signal.

[0141] Example 3. Transceiver according to one of Examples 1 to 2, wherein the second signal is superimposed on the first signal only on one of at least two levels of the first signal according to the physical communication protocol.

[0142] Example 4. Transceiver according to one of Examples 1 to 3, wherein the second signal is superimposed if no level change of the first signal has occurred for a certain period of time or will occur for a certain period of time.

[0143] Example 5. Transceiver according to one of Examples 1 to 4, wherein a logic protocol layer superior to the physical communication protocol provides a logic signal, and the logic signal is used to generate the first signal.

[0144] Example 6. Transceiver according to Example 5, wherein the logic protocol layer is configured to encrypt data to be sent in order to provide the logic signal.

[0145] Example 7. Transceiver according to one of the preceding examples, where the cryptographic data is a security code of the transceiver.

[0146] Example 8. Transceiver according to one of the preceding examples, wherein a key for generating the cryptographic data is provided to the transceiver.

[0147] Example 9. Transceiver according to Example 8, where the key is provided by a key instance superior to the transceiver.

[0148] Example 10. Transceiver according to any of the preceding examples, wherein the transmitter includes a driver circuit configured to provide the superposition signal, and wherein the transmitter is configured to calibrate the driver circuit.

[0149] Example 11. Transceiver according to Example 10, wherein the driver circuit comprises a first series circuit of a first switch and a first resistor coupled between a supply voltage and the output, wherein the first switch is controllable depending on the first signal, and the driver circuit has a second series circuit of a second switch and a second resistor coupled between the supply voltage and the output, wherein the second switch is controllable depending on the cryptographic data.

[0150] Example 12. Having a transceiver: a receiver who is trained to - to receive a received signal which is a superposition of a first signal according to a physical communication protocol with a second signal which includes cryptographic data, - to process the received signal according to the physical communication protocol in order to obtain the information transmitted in the first signal, and - to extract the cryptographic data from the received signal.

[0151] Example 13. Transceiver according to Example 12, wherein the second signal is a pulsed signal or an alternating current signal.

[0152] Example 14. Transceiver according to one of examples 12 or 13, wherein the receiver is configured to obtain the cryptographic data from the superposition of the second signal over the first signal only on one of at least two levels of the first signal according to the physical communication protocol.

[0153] Example 15. Transceiver according to any of Examples 1 to 3, wherein the receiver is configured to obtain the cryptographic data from the superposition of the second signal over the first signal if no level change of the first signal has occurred or will occur for a certain period of time.

[0154] Example 16. Transceiver according to one of Examples 12 to 15, wherein the information obtained from the first signal is provided as a logic signal to a logic protocol layer that is superior to the physical communication protocol.

[0155] Example 17. Transceiver according to Example 16, wherein the logic protocol layer is configured to obtain data transmitted from the logic signal by decryption.

[0156] Example 18. Transceiver according to any of the preceding examples, wherein the cryptographic data is a security code of another transceiver from which the receive signal is received, and wherein the transceiver is configured to compare the cryptographic data with an expected cryptographic data in order to authenticate the other transceiver.

[0157] Example 19. Transceiver according to Example 18, wherein the transceiver is provided with a key to generate the expected cryptographic data.

[0158] Example 20. Transceiver according to Example 19, where the key is provided by a key instance superior to the transceiver.

[0159] Example 21. Transceiver according to any of Examples 12-20, wherein the receiver includes a receiving circuit configured to obtain the cryptographic data, and wherein the receiver is configured to calibrate the receiving circuit.

[0160] Example 22. Transceiver according to Example 21, wherein calibration includes determining a reference voltage to obtain the cryptographic data.

[0161] Example 23. Transceiver according to Example 22, wherein the communication circuit includes a calibration circuit configured to determine the reference voltage as a function of a supply voltage and / or a temperature.

[0162] Example 24. Transceiver according to Example 23, wherein the calibration circuit comprises a scaled replica of at least part of a transmit path for transmitting the receive signal, wherein the calibration circuit is configured to determine the reference voltage based on a voltage drop across part of the replica.

[0163] Example 25. Transceiver according to Example 24, wherein the part of the simulation includes a resistor that simulates a resistor coupled to at least one transmission line through which the received signal can be received.

[0164] Example 26. Transceiver according to Example 24 or 25, wherein the part of the simulation is adjustable, wherein the calibration circuit is set up to adjust the part of the simulation to match a corresponding part of the transmit path.

[0165] Example 27. Transceiver according to Example 26, wherein the calibration circuit is set up to adjust the part of the simulation based on variations of the at least two signal levels during a calibration phase.

[0166] Example 28. Transceiver according to Example 26 or 28, wherein the calibration circuit is set up to validate the setting of the part of the emulation.

[0167] Example 29. Transceiver according to one of Examples 12-28, wherein the receiver is configured to process only the received signal according to the physical communication protocol in order to obtain information transmitted in the first signal when the received signal does not contain a second signal and / or the cryptographic data cannot be obtained from the received signal.

[0168] Example 30. System, comprehensive: a first transceiver according to one of the examples 1-11, and a second transceiver coupled to the first transceiver via a communication medium according to one of the examples 12-29.

[0169] Example 31. System according to Example 30, wherein the first transceiver and / or the second transceiver is part of a vehicle control unit.

[0170] Example 32. Signal comprising a superposition of: - a first signal according to a physical communication protocol, and -a second signal comprising at least one cryptographic datum, wherein the signal fulfills the physical communication protocol.

[0171] Example 33. Signal according to Example 32, where the second signal is a pulsed signal or an alternating current signal.

[0172] Example 34. Signal according to one of Examples 32 or 33, wherein the second signal is superimposed on the first signal only at one of at least two levels of the first signal according to the physical communication protocol.

[0173] Example 35. Signal according to one of Examples 32 and 33, wherein the second signal is superimposed on the first signal if no level change of the first signal has occurred or will occur for a certain period of time.

[0174] Example 36. Signal according to one of Examples 32 to 35, wherein the first signal comprises logically encrypted data.

[0175] Although specific embodiments have been illustrated and described in this description, persons with ordinary technical knowledge will recognize that a multitude of alternative and / or equivalent implementations can be chosen as substitutions for the specific embodiments shown and described in this description without departing from the scope of the invention shown. It is intended that this application cover all adaptations or variations of the specific embodiments discussed herein. Therefore, it is intended that this invention is limited only by the claims and the equivalents of the claims. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited non-patent literature

[0000] ISO 11898

[0003] ISO 17458-1

[0003] ISO 17458-4

[0003]

Claims

[1] Transceiver (41) comprising: a transmitter (42) designed to - to provide a first signal (s1) at an output according to a physical communication protocol, and - to provide at the output a second signal (s2) comprising at least one cryptographic datum (14), wherein the first (s1) and second (s2) signals are superimposed at the output as a superposition signal (s), and wherein the superposition signal satisfies the physical communication protocol. [2] Transceiver (41) according to claim 1, wherein the second signal (s2) is a pulsed signal or an alternating current signal. [3] Transceiver according to one of claims 1 to 2, wherein the second signal (s2) is superimposed on the first signal (s1) only on one of at least two levels of the first signal according to the physical communication protocol. [4] Transceiver according to any one of claims 1 to 3, wherein the second signal (s2) is superimposed if no level change of the first signal (s1) has occurred for a certain time or will occur for a certain time. [5] Transceiver according to any one of claims 1 to 4, wherein a logic protocol layer which is superior to the physical communication protocol provides a logic signal and the logic signal is used to generate the first signal (s1). [6] Transceiver according to claim 5, wherein the logic protocol layer is configured to encrypt data to be transmitted in order to provide the logic signal. [7] Transceiver according to any of the preceding claims, wherein the cryptographic data (14) is a security code of the transceiver. [8] Transceiver according to any of the preceding claims, wherein a key for generating the cryptographic data (14) is provided to the transceiver. [9] Transceiver according to claim 8, wherein the key is provided by a key instance (261) superior to the transceiver (41). [10] Transceiver according to any of the preceding claims, wherein the transmitter (42) comprises a driver circuit (50) configured to provide the superposition signal, and wherein the transmitter (42) is configured to calibrate the driver circuit. [11] Transceiver according to claim 10, wherein the driver circuit (50) comprises a first series circuit of a first switch (56, 54) and a first resistor (55, 53) coupled between a supply voltage and the output, wherein the first switch (56, 54) is controllable depending on the first signal (s1), and the driver circuit comprises a second series circuit of a second switch (52) and a second resistor (51) coupled between the supply voltage and the output, wherein the second switch (52) is controllable depending on the cryptographic data. [12] Transceiver (41) comprising: a receiver (43) who is trained to - to receive a received signal (s) which is a superposition of a first signal according to a physical communication protocol with a second signal which includes a cryptographic datum (14), - to process the received signal according to the physical communication protocol in order to obtain the information transmitted in the first signal, and - to extract the cryptographic data from the received signal. [13] Transceiver according to claim 12, wherein the second signal is a pulsed signal or an alternating current signal. [14] Transceiver according to one of claims 12 or 13, wherein the receiver (43) is configured to obtain the cryptographic data from the superposition of the second signal over the first signal only on one of at least two levels of the first signal according to the physical communication protocol. [15] Transceiver according to any one of claims 1 to 3, wherein the receiver (43) is configured to obtain the cryptographic data from the superposition of the second signal over the first signal if no level change of the first signal has occurred or will occur for a certain period of time. [16] Transceiver (41) according to one of claims 12 to 15, wherein the information obtained from the first signal is provided as a logic signal to a logic protocol layer which is superior to the physical communication protocol. [17] Transceiver (41) according to claim 16, wherein the logic protocol layer is configured to obtain data transmitted from the logic signal by decryption. [18] Transceiver (41) according to one of the preceding claims, wherein the cryptographic data is a security code of another transceiver from which the receive signal is received, and wherein the transceiver (41) is configured to compare the cryptographic data with an expected cryptographic data in order to authenticate the other transceiver. [19] Transceiver (41) according to claim 18, wherein a key for generating the expected cryptographic data is provided to the transceiver (41). [20] Transceiver (41) according to claim 19, wherein the key is provided by a key instance (261) superior to the transceiver (41). [21] Transceiver (41) according to one of claims 12-20, wherein the receiver (43) comprises a receiving circuit (44) configured to obtain the cryptographic data, and wherein the receiver (43) is configured to calibrate the receiving circuit. [22] Transceiver according to claim 21, wherein the calibration comprises determining a reference voltage to obtain the cryptographic data. [23] Transceiver (41) according to one of claims 12-21, wherein the receiver (43) is configured to process only the received signal according to the physical communication protocol in order to obtain information transmitted in the first signal if the received signal does not contain a second signal and / or the cryptographic data cannot be obtained from the received signal. [24] System (10), comprising: a first transceiver according to any one of claims 1-11, and a second transceiver coupled to the first transceiver via a communication medium (13) according to one of claims 12-23. [25] System according to claim 24, wherein the first transceiver and / or the second transceiver is part of a control unit of a vehicle. [26] Signal comprising a superposition of: - a first signal (s1) according to a physical communication protocol, and -a second signal (s2) comprising at least one cryptographic datum, wherein the signal satisfies the physical communication protocol. [27] Signal according to claim 26, wherein the second signal (s2) is a pulsed signal or an alternating current signal. [28] Signal according to one of claims 26 or 27, wherein the second signal (s2) is superimposed on the first signal (s1) only on one of at least two levels of the first signal (s1) according to the physical communication protocol. [29] Signal according to one of claims 26 to 28, wherein the second signal (s2) is superimposed on the first signal (s1) when no level change of the first signal (s1) has occurred for a certain time or will occur for a certain time. [30] Signal according to any one of claims 26 to 29, wherein the first signal (s1) comprises logically encrypted data.