METHOD AND DEVICE FOR ERROR-TOLERANT ETHERNET TIME SYNCHRONIZATION
The method and system for fault-tolerant Ethernet time synchronization in vehicles address timing issues by using multiple time domains and dynamic port switching to maintain synchronization, ensuring reliable communication and operation in error modes, particularly for advanced driver assistance systems and Level 4 autonomous vehicles.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- GM GLOBAL TECHNOLOGY OPERATIONS LLC
- Filing Date
- 2021-03-09
- Publication Date
- 2026-05-28
AI Technical Summary
The Ethernet protocol in vehicle environments faces challenges with fault tolerance in the presence of hardware or link failures, leading to timing issues and data rate limitations, especially with the increasing complexity of vehicle systems and the need for reliable communication between subsystems.
A method and system for fault-tolerant Ethernet time synchronization that utilizes multiple time domains and a startup protocol with multiple grandmasters to maintain a common time base, ensuring no time jumps occur even in the event of link failures, by configuring network switches and edge nodes to switch between master and slave ports dynamically.
Ensures consistent timing across vehicle systems, enabling reliable communication and operation in error modes, particularly for advanced driver assistance systems and Level 4 autonomous vehicles, by preventing time jumps and maintaining synchronization through redundant clock trees and secondary grandmasters.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
INTRODUCTION
[0001] The subject matter of the disclosure relates generally to data distribution in a motor vehicle and in particular to a method and a device for providing fault-tolerant Ethernet timing in a system with multiple time domains in the presence of one or more hardware link failures.
[0002] Modern vehicles comprise numerous systems and subsystems for vehicle control, monitoring, and passenger comfort. As the complexity of these subsystems increases, for example, with the implementation and performance of advanced driver assistance systems (ADAS), the need for reliable communication and monitoring between subsystems grows. Communication between vehicle subsystems has been implemented to enable the sharing of sensor data, thereby reducing the need for redundant sensors. This communication is traditionally handled via a Controller Area Network (CAN) bus. One challenge is that many vehicle subsystems have electronic control units (ECUs) and other components that generate and utilize their own timing structures and time ranges, complicating communication between them.The CAN bus requires excessive clock and bit synchronization, which severely limits the data rate of the CAN bus for advanced applications.
[0003] To overcome the data rate limitations of the CAN bus, Ethernet is being used as a vehicle communication system, as vehicle control systems scale towards higher levels of automated driving, increasing the need for a fault-tolerant time synchronization method over Ethernet. The IEEE has defined a standard (802.1AS) for multiple time domains over Ethernet, but no protocol to achieve fault tolerance in the event of link or hardware failures. It would be desirable to provide a multi-time domain configuration and algorithms to maintain a common time base without time jumps in the presence of one or more hardware or link failures. Addressing these issues and overcoming their associated limitations would be desirable to resolve the timing problems posed by the Ethernet protocol in a vehicle environment, while simultaneously overcoming the aforementioned problems.
[0004] US 2004 / 0213295A1 describes an independent broadcast medium for transmitting a time reference to each element. The broadcast medium comprises a switching element, an active element, or a passive element of an in-vehicle network. Each element in the network accepts the time information, i.e., a time reference, from the source.
[0005] US 2006 / 0020717A1 describes an active vehicle network for the communicative coupling of devices within a vehicle. Device operation is independent of the device's interface with the active network. Additionally, the architecture of the active network provides one or more communication redundancy levels.
[0006] US 2016 / 0127118A1 describes a method for providing network time synchronization using a redundant grandmaster. The method includes detecting a loss of the grandmaster. A sync message is generated based on the detected result. The generated sync message is transmitted via a clock master port.
[0007] CN 1 08 173 614 A refers to a type of time synchronization and transmission procedure for vehicle-mounted Ethernet. DESCRIPTION
[0008] The object of the invention is to solve the timing problems presented by the Ethernet protocol in a vehicle environment.
[0009] The problem is solved by the subject matter of independent claim 1.
[0010] This document discloses methods and systems for object detection and the associated control logic for providing vehicle sensor and control systems, methods for manufacturing and operating such systems, as well as motor vehicles equipped with on-board sensor and control systems. As an example, and not as a limitation, various embodiments of network timing configuration techniques are disclosed here.
[0011] In one embodiment, a method for providing fault-tolerant network time synchronization in a motor vehicle communication network comprises generating a time synchronization signal, transmitting the time synchronization signal from a first switch to a second switch via a first connection and from the first switch to a third switch via a second connection, detecting a connection failure of the first connection and transmitting the time synchronization signal from the second switch to the third switch via a third connection in response to the connection failure.
[0012] In accordance with various embodiments, the connection error is detected as a reaction to the third switch not receiving the time synchronization signal via the second connection.
[0013] In accordance with various embodiments, the connection error is detected as a reaction to the third switch not receiving the time synchronization signal via the second connection for a multitude of time synchronization intervals.
[0014] In accordance with various embodiments, the second switch is able to activate a master port in response to a connection failure.
[0015] In accordance with various embodiments, the third switch is capable of coupling the time synchronization signal from the second switch to an edge node, and the edge node is capable of synchronizing a clock generator in response to the time synchronization signal.
[0016] In accordance with various embodiments, the time synchronization signal is generated by an edge node referred to as the Grandmaster.
[0017] In accordance with various embodiments, the time synchronization signal is generated by a radar controller coupled to the first switch, wherein a first radar sensor is coupled to the second switch and a second radar sensor is coupled to the third switch.
[0018] In accordance with various embodiments, a method for generating a follow-up frame with a timestamp for determining a latency between the first switch and the second switch.
[0019] In accordance with various embodiments, a fourth switch is able to receive the time synchronization signal from the third switch.
[0020] According to an unclaimed embodiment, a device comprises a first network node with a first switch for transmitting a first time synchronization signal, a second network node with a second switch for receiving the first time synchronization signal from the first switch and for transmitting a second time synchronization signal to the third switch, and a third network node comprising the third switch for receiving the first time synchronization signal from the first switch and the second time synchronization signal from the second switch, wherein the third node is further capable of synchronizing an internal clock with the first synchronization signal in response to the reception of the first time synchronization signal and of synchronizing the internal clock with the second synchronization signal in response to the non-reception of the first time synchronization signal.
[0021] According to various embodiments, the internal clock is synchronized to the second time synchronization signal in response to the detection of a connection failure between the first switch and the third switch.
[0022] According to various embodiments, the internal clock is synchronized to the second time synchronization signal in response to a detection of a connection failure between the first switch and the third switch, wherein the connection failure is determined in response to the third switch not receiving the first time synchronization signal for a plurality of time synchronization intervals.
[0023] In accordance with various implementations, the first network node is referred to as the Grandmaster.
[0024] In accordance with various embodiments, the third switch is able to redefine a port role from a slave port to a master port in response to a connection failure.
[0025] In accordance with various embodiments that include a fourth switch, the third switch is ready to transmit the second time synchronization signal to the fourth switch in response to the connection failure.
[0026] In accordance with various embodiments, the first network node is a lidar controller, the third network node is a lidar sensor.
[0027] In accordance with various embodiments, the second network node is able to initiate a master port in response to the connection failure.
[0028] In accordance with various embodiments, the first node is ready to generate a follower frame indicating a first latency, and the second node is ready to update the follower frame in response to the first latency and a second latency.
[0029] According to another embodiment, a vehicle network comprises a vehicle controller with a first network switch and a master clock, wherein the vehicle controller is capable of generating a first time synchronization frame in response to the master clock and coupling the first time synchronization from the first network switch to a second network switch via a first data link and coupling the first time synchronization from the first network switch to a third network switch via a second data link, a first vehicle sensor with the second network switch configured to receive the first time synchronization frame via the first data link, generating a second time synchronization frame in response to the first time synchronization frame and transmitting the second time synchronization frame to the third network switch via a third data link,and a second vehicle sensor with the third network switch and an internal clock, wherein the second vehicle sensor is effective to synchronize the internal clock with the master clock according to the first time synchronization signal in response to the reception of the first time synchronization frame, wherein the second vehicle sensor is further effective to synchronize the internal clock with the master clock according to the second time synchronization signal in response to the non-reception of the first time synchronization frame.
[0030] In accordance with various embodiments, the second vehicle sensor is operational to synchronize the internal clock with the master clock according to the second time synchronization signal in response to the non-reception of the first time synchronization frame for a multitude of time synchronization intervals.
[0031] The above advantage and other advantages and features of the present disclosure will be evident from the following detailed description of the preferred embodiments when considered in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The exemplary embodiments are described below in conjunction with the following drawing figures, where identical numbers denote identical elements, and where: Fig. Figure 1 shows an exemplary application of the method and device for fault-tolerant Ethernet time synchronization in a motor vehicle according to an embodiment of the present disclosure; Fig. Figure 2 shows a block diagram illustrating an exemplary system for fault-tolerant Ethernet time synchronization in a motor vehicle according to an embodiment of the present disclosure; Fig. Figure 3 shows a flowchart illustrating an exemplary method for fault-tolerant Ethernet time synchronization according to an embodiment of the present disclosure; Fig. Figure 4 shows a block diagram illustrating another exemplary system for fault-tolerant Ethernet time synchronization in a motor vehicle according to an embodiment of the present disclosure; Fig. Figure 5 shows a flowchart illustrating another exemplary method for fault-tolerant Ethernet time synchronization according to an embodiment of the present disclosure; and
[0033] The examples shown here illustrate preferred embodiments of the invention, and such examples are not to be understood as limiting the scope of the invention in any way. DETAILED DESCRIPTION
[0034] The following detailed description is merely exemplary and is not intended to limit the disclosure or its application and use. Furthermore, there is no intention to be bound by the theory set forth in the preceding introduction or the following detailed description. For example, the communication network and communication network protocol have a particular application for use in a vehicle. However, as will be recognized by those skilled in the art, the network configuration and methods described herein may also have other applications in systems outside of vehicles.
[0035] Now to Fig. Figure 1, a diagram showing a system 100 for an exemplary application of the method and device for fault-tolerant Ethernet time synchronization in a motor vehicle 105 according to an embodiment of the present disclosure. The exemplary system 100 comprises a video controller 115 coupled to a first camera 110 and a second camera 175, a lidar controller 125 coupled to a first lidar transceiver 130 and a second lidar transceiver 120, a radar controller 145 coupled to a first radar transceiver 140 and a second radar 150, a processor 160, a user interface 165, a vehicle controller 155, and a trailer interface 170.
[0036] In this exemplary embodiment, the lidar controller 125, the video controller 115, and the radar controller 145 are each capable of receiving and processing data from their respective sensors. The video controller 115 is capable of receiving images from the first camera 110 and the second camera 175 and processing the images to generate image data for use in creating an object map around the vehicle 105. The lidar controller 125 can be operated to receive direction and distance data from each of the first lidar transceivers 130 and the second lidar transceiver 120. Likewise, the radar controller 145 can be operational to receive direction and distance data from each of the first radar transceivers 140 and the second radar 150.The image, lidar, and radar data can be combined using sensor fusion techniques or similar methods to generate a three-dimensional object map of the vehicle 105's surroundings. This three-dimensional map can then be coordinated with high-resolution road maps received via wireless transmission and stored in a memory.
[0037] The processor 160 can use the three-dimensional object map, high-resolution road maps, vehicle sensor data, and user data received via the user interface 165 as inputs to an ADAS algorithm, such as adaptive cruise control, lane centering, autonomous lane changes, obstacle avoidance, or similar functions. In response to the ADAS algorithm, the processor 160 can then generate control signals that are coupled to the vehicle control unit 155 to control vehicle operation. For example, the vehicle control unit 155 can generate steering control signals for coupling to a steering controller, throttle control signals for coupling to a throttle valve controller, and brake control signals for coupling to a brake controller.
[0038] Timing is a crucial aspect for each control unit 155 and the processor 160 to coordinate data. For example, radar, lidar, and image data are useless if they cannot be accurately provided to the processor 160 to deliver precise control signals to the vehicle control unit 155. Furthermore, in a vehicle environment, it is critical that this timing data and the associated communication between systems can be transmitted accurately even in the event of system errors or communication channel failures. To address this issue, the example system incorporates a timing start protocol to prevent time jumps by using an agreement protocol that considers multiple time domains and multiple error conditions. This time synchronization in the presence of errors enables operational applications that rely on a global time concept, such as...Level 4 autonomous vehicles.
[0039] In an exemplary embodiment, the system 100 uses a communication bus 190, where each controller is connected to two other controllers in a ring configuration. The data transmitted over the network can be unidirectional or bidirectional. The use of multiple clock trees can be employed to create multiple time domains. The exemplary startup protocol can be used to select the time domain in normal operating mode and in all error modes to ensure consistency between all endpoints in the system, regardless of the error mode. In an exemplary embodiment, the startup protocol can be used for multiple grand masters, guaranteeing that no time jumps occur if grand masters fail at runtime. The startup protocol can switch between multiple clock trees (multiple time domains) to guarantee the absence of time jumps in error modes.
[0040] System 100 can provide a protocol that enables time synchronization for multiple systems across multiple time domains in both normal and fault modes. In this example, an end node within a first time domain can be selected as the grandmaster to provide a root time reference for that domain. The grandmaster end node can periodically transmit synchronization information to the clocks within the first time domain. The grandmaster end node can also transmit a follow-up frame, which is used to track the propagation delays of each node in the network. Using the follow-up frame, a node can use the sync frame and the follow-up frame to synchronize with the grandmaster.Furthermore, systems with clocks within the first time domain can then relay the precise time to the other time domains to which they are also connected. The example system can then guarantee consistency between all endpoints in the system, regardless of the failure mode.
[0041] In the example system 100, the video controller 115, the lidar controller 125, the radar controller 145, the processor 160, and the vehicle controller 155 can be configured to form a time domain. In normal mode, the processor 160 can be selected to have the grandmaster clock and be able to send sync packets to the other nodes in the time domain in response to the grandmaster clock. In this example, the processor 160 has a master port and the radar controller 145 has a slave port. The radar control unit 145 sends a time synchronization signal via a master port to a slave port on the lidar controller 125. The lidar controller 125 sends a time synchronization signal via a master port to a slave port on the video controller 115, which in turn sends a time synchronization signal via a master port to a slave port on the vehicle controller 155.Each node within the time domain is able to synchronize with the synchronization frame received from its respective master port and to discard other received time frames.
[0042] In the event of a connection failure, a node within the time domain may cease receiving sync frames from the designated node's master port via its slave port. For example, if a connection failure occurs between the lidar controller 125 and the video controller 115, the video controller will no longer receive sync frames from the lidar controller 125. Additionally, the video controller 115 will cease generating sync signals to be transmitted, and consequently, the vehicle controller 155 will cease receiving sync signals from the video controller 115. In response to not receiving a number of sync signals from a designated node, a node may detect that a fault mode is present and fall back to an alternative designated node master port. In this example, the processor 160 would then transmit sync signals to the vehicle controller 155, and the vehicle controller 155 would transmit sync signals to the video controller 115.In error mode, the video controller 115 would then synchronize its clock with the sync frame and follow-up frame received from the vehicle control unit 155. Likewise, the vehicle control unit 155 would synchronize its clock with the sync frame and follow-up frame received from the processor 160.
[0043] In this example time domain, each node would only require one alternative node for receiving time synchronization signals if a failure mode is detected. For example, in the example time domain, the lidar controller 125 would synchronize with a sync frame from the radar controller 145 unless there is a connection failure between the processor 160 and the radar controller 145, or between the radar controller 145 and the lidar controller 125. In the event of any other connection failure, the lidar controller 125 would still receive a sync frame from the radar controller 145. If the lidar controller 125 no longer receives sync frames from the radar controller 145, it would then switch to the video controller 155 as the master.
[0044] In Fig. Figure 2 shows a block diagram illustrating an exemplary System 200 for fault-tolerant Ethernet time synchronization in a motor vehicle. In this exemplary embodiment, the System 200 can comprise an Ethernet protocol network configured in a ring configuration. The exemplary network can include switches S1 220, S2 240, S3 260, S4 270 and edge nodes or endpoints E1 210, E2 230, E3 250, E4 280. In some configurations, a switch S1 220, S2 240, S3 260, or S4 270 can be integrated with an edge node E1 210, E2 230, E3 250, or E4 280. For example, a lidar sensor can be an edge node in the network with an integrated switch. In normal operation, E1 210 can be designated as the grandmaster clock and S1 220 is a slave to E1 210. S1 220 is then a master for S2 240 and S3 260, with E2 230 being a slave for S2 240 and E3 250 being a slave for S3 260.In this exemplary embodiment, S4 270 is then a slave to S2 240 and the connection between S3 260 and S5 is deactivated for clock synchronization.
[0045] A connection failure can be detected as a reaction when an edge node does not receive an expected sync packet from the master node. For example, if a connection failure occurs between S1 220 and S3 260, E3 250 will no longer receive sync packets from E1 210. E3 250 would then switch to an alternate configuration or domain, in which S4 270 would become the alternate master to S3 260, and E2 230 would receive sync packets from E4 280. When a connection failure occurs between S1 220 and S3 260, S3 260 becomes the slave of S4 270, and the connection between S1 220 and S3 260 is disabled. Similarly, if a connection error occurs between S1 220 and S2 240, S4 270 becomes a slave of S3 260 and S2 240 becomes a slave of S4 270, whereby the connection between S1 220 and S2 240 is deactivated.Should a connection error occur between S2 240 and S4 270, S3 260 will become the master for S4 270, with S1 220 being a master for both S2 240 and S3 260, and the connection between S2 240 and S4 270 being disabled. In the event of any connection error, nodes not receiving sync packets would switch to an alternative master node.
[0046] To compensate for a link failure that would isolate the designated grandmaster node, or a runtime failure of a grandmaster, a startup protocol for multiple grandmasters is provided to guarantee the absence of time jumps. To avoid these problems, a secondary grandmaster is designated for each time domain. Upon startup, the secondary grandmaster initializes its own clock. The secondary grandmaster is the one that attempts to receive the sync frame from the primary grandmaster via the normal master node. If the sync frame is not received via the normal master node, the secondary grandmaster attempts to receive the sync frame from the alternate master node. If the sync frame is not received from the alternate master node within a predetermined time interval, the second grandmaster is then ready to generate and send a sync packet in response to its own clock as the primary grandmaster.When a sync frame is received from the Grandmaster at startup, the secondary Grandmaster is ready to synchronize its own clock with that of the Grandmaster. If a connection failure occurs later and no further sync packets are received from the Grandmaster via the normal master node or the alternate master node, the secondary Grandmaster generates a sync frame from its own previously synchronized clock and transmits this sync frame across the time domain network. This startup protocol guarantees the absence of time jumps in failure modes, as the secondary Grandmaster's clock is synchronized with the primary Grandmaster's.
[0047] In Fig. Figure 3 shows a flowchart illustrating an exemplary method 300 for fault-tolerant Ethernet time synchronization in a motor vehicle. In this exemplary embodiment, an edge node executes the exemplary method 300. The exemplary method 300 first serves to initialize 310 an internal clock. After the initialization of the internal clock, the method then operates with timing according to the internal clock at 320. The exemplary edge node could, for example, be a radar controller that executes a vehicle radar algorithm. The radar controller can further operate by cascading its internal clock to the radar sensors via a synchronization signal, thus forming another time domain with the radar sensors.
[0048] The procedure next determines at 330 whether a synchronization signal has been received from a primary grandmaster node. If the synchronization signal from the primary grandmaster node has been received, procedure 300 next synchronizes the internal clock at 340 and returns to operation with the internal clock at 320. If the synchronization signal from the primary grandmaster node has not been received for a predetermined number of clock cycles, for example, eight clock cycles, procedure 300 then determines at 350 whether a synchronization signal has been received at a switching section of the edge node from an alternate master. If the synchronization signal from the alternate master has been received at 350, procedure 300 is then able to synchronize the internal clock with the synchronization signal from the alternate master at 340 and return to operation with the internal clock at 320.In one exemplary embodiment, the alternative master can become the primary master, with the previous primary master becoming the alternative master depending on the design criteria. Alternatively, the alternative primary master can remain the alternative primary master, and the edge node continues to check for synchronization signals from the primary master before synchronizing to a synchronization signal from the alternative master.
[0049] If no synchronization signal is received from the alternate master a t350, procedure 300 next determines whether the current edge node executing the procedure has been designated as the alternate grandmaster at 360. If the current edge node has not been designated as the alternate grandmaster at 360, procedure 300 can then operate by generating an error signal at 380 indicating a loss of synchronization and coupling this error signal to a system controller, vehicle controller, or other higher-level controller. The procedure can then return to operation at 320 with the current clock. Alternatively, in response to a loss of synchronization, the current node can be shut down (390), enter a standby state, or enter an alternate operating state.
[0050] If the current node is designated as the alternate grandmaster at 360, the procedure can then generate a sync signal and transmit it to the other nodes over the Ethernet network at 370. The procedure can also generate a follow-up frame indicating accumulated propagation delays or similar information. After transmitting the sync signal at 370, the procedure can then return to operation at 320 with the current clock signal.
[0051] In Fig. Figure 4 shows a block diagram illustrating an example System 400 for fault-tolerant Ethernet time synchronization in a motor vehicle network. The example System 400 can include a first network node 410 and a first switch 415, a second network node 420 and a second switch 425, and a third network node 430 and a third switch 435. The first network switch can be connected to the second network switch via a first link 475. The first network switch 415 can be connected to a third network switch via a second link 480. The second network switch 425 can be connected to the third network switch 435 via a third link 485.
[0052] In the exemplary embodiment, the first network node 410, which is coupled to a first switch 415, is configured to generate and transmit a first time synchronization signal in response to a first internal clock of the first network node 410. The first switch 415 can be integrated into the first network node and is configured to transmit data into an Ethernet network via a master port and to receive data from the Ethernet network via a slave port. These ports are configurable and can be switched from master to slave or vice versa in response to a network connection failure, a control signal from the first network node 410, or similar events. In an exemplary embodiment, the first clock can be designated as a grandmaster clock, which is used as a time reference for all nodes with the time domain of the Ethernet network.The first network node 410 can further be configured to generate a follow-up frame indicating an initial latency resulting from the processing of the initial time synchronization signal by the first switch 415, and the second network node 420 is ready to update the follow-up frame in response to the initial latency and a second latency resulting from the processing of the initial time synchronization signal by the second switch 425.
[0053] The second network node 420, with the second switch 425, can be configured to receive the first time synchronization signal from the first switch 415 and send a second time synchronization signal to the third switch 435. In an example application, the first network node 410 could be a lidar controller and the second network node 420 a lidar sensor. In response to a network connection failure, the second network node 420 can initiate a master port.
[0054] In this exemplary embodiment, the third network node 430, including the third switch 435, is configured to receive the first time synchronization signal from the first switch 415 and the second time synchronization signal from the second switch 425. The third network node 430 can further be operational to synchronize an internal clock of the third node to the first synchronization signal in response to the reception of the first time synchronization signal from the first switch 415 via the second connection 480. The third network node 430 can further be operational to synchronize its internal clock to the second synchronization signal in response to the failure to receive the first time synchronization signal from the first switch 415 via the second connection 480.In an exemplary embodiment, the internal clock can be synchronized to the second time synchronization signal in response to the detection of a connection fault between the first switch 415 and the third switch 435, the connection fault being determined as a response to the third switch 435 not receiving the first time synchronization signal for a plurality of time synchronization intervals. In an exemplary application, the third switch 435 can be operational to redefine a port role from a slave port to a master port in response to the connection fault. The exemplary system can further include a fourth switch, wherein the third switch 435 can be operated to transmit the second time synchronization signal to the fourth switch in response to the connection fault.
[0055] In an exemplary embodiment, the exemplary system 400 can be a vehicle communication network comprising a vehicle controller with a first network switch and a grandmaster clock, wherein the vehicle controller operates such that, in response to the grandmaster clock, it generates a first time synchronization frame and couples the first time synchronization from the first network switch to a second network switch via a first data link and couples the first time synchronization from the first network switch to a third network switch via a second data link.Exemplary System 400 further comprises a first vehicle sensor with the second network switch, configured to receive the first time synchronization frame over the first data link, to generate a second time synchronization frame in response to the first time synchronization frame, and to transmit the second time synchronization frame to the third network switch over a third data link. Exemplary System 400 further comprises a second vehicle sensor with the third network switch and an internal clock, wherein the second vehicle sensor is operational to synchronize the internal clock with the grandmaster clock according to the first time synchronization signal in response to the reception of the first time synchronization frame, and to synchronize the internal clock with the grandmaster clock according to the second time synchronization signal in response to the failure to receive the first time synchronization frame.Additionally, the second vehicle sensor can be configured to synchronize the internal clock with the Grandmaster clock according to the second time synchronization signal in response to the failure to receive the first time synchronization frame for a variety of time synchronization intervals.
[0056] In Fig.Figure 5 shows a block diagram illustrating an exemplary method 500 for fault-tolerant Ethernet time synchronization in the event of a grandmaster failure in a motor vehicle. The exemplary method first serves to generate 510 a time synchronization signal for synchronizing multiple nodes in a network configuration with multiple time domains. The time synchronization signal can be generated by an edge node designated as the grandmaster. For example, the time synchronization signal can be generated by the radar controller, which is coupled to a first radar sensor and a second radar sensor. In an exemplary embodiment, each of the radar sensors can be an edge node with an integrated switching node having at least one port configured in slave mode.The procedure can also be used to generate a follow-up frame with a timestamp in order to determine any latency that has accumulated during propagation through one or more switching nodes and a terminal node.
[0057] The method can include the transmission of the time synchronization signal from a first switch to a second switch via a first connection and from the first switch to a third switch via a second connection. In an exemplary embodiment, there can be a third connection between the second switch and the third switch, which is disabled for network synchronization purposes.
[0058] The method then serves to detect a connection failure of the second connection, wherein the connection failure is detected as a reaction to the third switch not receiving the time synchronization signal via the second connection. In an exemplary embodiment, the connection failure can be detected as a reaction to the third switch not receiving the time synchronization signal via the second connection for a plurality of time synchronization intervals.
[0059] In response to the detection of the connection failure, the method 500 is configured to transmit the time synchronization signal 540 from the second switch to the third switch via a third connection. The second switch can activate a master port in response to the connection failure, a port that was previously configured as a slave port. The third switch can receive the time synchronization signal from the second switch and then couple the time synchronization signal to an edge node. In response, the edge node can synchronize an internal clock in response to the time synchronization signal. Furthermore, the exemplary system can include a fourth switch that receives the time synchronization signal from the third switch. In this exemplary embodiment, the third switch can activate a master port to transmit the time synchronization signal to the fourth switch.
[0060] It should be emphasized that many variations and modifications can be made to the embodiments described herein, the elements of which are to be understood as further acceptable examples. All such modifications and variations are hereby included within the scope of this disclosure and are protected by the following claims. Furthermore, each of the steps described herein can be carried out simultaneously or in a different order than that presented herein. Moreover, as should be evident, the features and characteristics of the specific embodiments disclosed herein can be combined in various ways to form additional embodiments, all of which fall within the scope of this disclosure.
[0061] The conditional language used here, such as "may," "could," "might," "could," "e.g.," and similar expressions, is generally intended to convey that certain embodiments include certain features, elements, and / or states, while other embodiments do not, unless explicitly stated otherwise or understood differently in context. Therefore, such conditional language is generally not intended to imply that features, elements, and / or states are in any way required for one or more embodiments, or that one or more embodiments necessarily contain logic to decide, with or without input or prompting from the author, whether these features, elements, and / or states are included or executed in a particular embodiment.
[0062] Furthermore, the following terminology may have been used here. The singular forms "ein," "ein," and "die" include plural references unless the context clearly indicates otherwise. For example, a reference to an article includes a reference to one or more articles. The term "eins" refers to one, two, or more and generally refers to the selection of part or all of a quantity. The term "mehrere" refers to two or more of an article. The term "ungefähr" or "annähend" means that quantities, dimensions, sizes, formulations, parameters, shapes, and other characteristics need not be exact but may be approximate and / or larger or smaller as desired, taking into account acceptable tolerances, conversion factors, rounding, measurement errors, and the like, as well as other factors known to a person skilled in the art.The term “essentially” means that the specified feature, parameter or value does not have to be achieved exactly, but that deviations or variations, including, for example, tolerances, measurement errors, limitations of measurement accuracy and other factors known to the person skilled in the art, may occur on an order of magnitude that does not preclude the intended effect of the feature.
[0063] The processes, methods, or algorithms disclosed herein may be supplied to or implemented by a processing device, controller, or computer, which may include any existing programmable electronic control unit or dedicated electronic control unit. Likewise, the processes, methods, or algorithms may be stored as data and instructions that can be executed by a controller or computer in many forms, including, but not limited to, information permanently stored on non-writable storage media such as ROM devices, and information modifiably stored on writable storage media such as floppy disks, magnetic tapes, CDs, RAM devices, and other magnetic and optical media. The processes, methods, or algorithms may also be implemented in an executable software object.Alternatively, the processes, methods, or algorithms can be embodied wholly or partially by suitable hardware components, such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), state machines, controllers, or other hardware components or devices, or a combination of hardware, software, and firmware components. Such example devices can be onboard as part of a vehicle computer system or located outside the vehicle and perform remote communication with devices in one or more vehicles.
[0064] While exemplary embodiments are described above, it is not intended that these embodiments describe all possible forms encompassed by the claims. The words used in the description are descriptive rather than limiting, and it is understood that various modifications may be made without departing from the spirit and scope of the disclosure. As previously described, the features of different embodiments may be combined to form further exemplary aspects of the present disclosure that may not be explicitly described or illustrated.While various embodiments may have been described as advantageous or preferred over other embodiments or implementations of the prior art with respect to one or more desired properties, those skilled in the art recognize that one or more features or properties may be compromised to achieve desired overall system attributes, which depend on the specific application and implementation. These properties may include, but are not limited to, cost, strength, durability, life-cycle costs, marketability, appearance, packaging, size, ease of maintenance, weight, manufacturability, ease of assembly, etc.As such, embodiments that are described as less desirable than other embodiments or implementations of the prior art with respect to one or more properties are not outside the scope of the disclosure and may be desirable for certain applications.
Claims
[1] Method (300) for providing fault-tolerant network time synchronization in a motor vehicle communication network (100), wherein the motor vehicle communication network (100) comprises: a video controller (115) coupled with a first camera (110) and a second camera (175), a lidar controller (125) coupled with a first lidar transceiver (130) and a second lidar transceiver (120), a radar controller (145) coupled with a first radar transceiver (140) and a second radar (150), a processor (160), a user interface (165), a vehicle controller (155) and a trailer interface (170) the procedure includes the following: Generation of a time synchronization signal; Transmission of the time synchronization signal from a first switch (415) to a second switch (425) via a first connection and from the first switch (415) to a third switch (435) via a second connection; Detecting a connection error on the second connection; and Transmitting the time synchronization signal from the second switch to the third switch (435) via a third connection in response to the connection fault, wherein the time synchronization signal is generated by a radar controller coupled to the first switch, and wherein a first radar sensor is coupled to the second switch and a second radar sensor is coupled to the third switch, wherein the lidar controller (125), the video controller (115) and the radar controller (145) are each configured to receive and process data from their respective sensors, and the video controller (115) is set up to receive images from the first camera (110) and the second camera (175) and to process the images to generate image data for use in creating an object map around the vehicle (105). [2] Method (300) according to claim 1, wherein the connection error is detected as a reaction to the fact that the third switch (435) does not receive the time synchronization signal via the second connection. [3] Method (300) according to claim 2, wherein the connection fault is detected in response to the fact that the third switch (435) does not receive the time synchronization signal via the second connection for a plurality of time synchronization intervals. [4] Method (300) according to claim 1, wherein the second switch (425) operates such that it activates a master port in response to the connection error. [5] Method (300) according to claim 1, wherein the third switch (435) is operational to couple the time synchronization signal from the second switch (425) to an edge node, and wherein the edge node is operational to synchronize a clock generator in response to the time synchronization signal. [6] Method (300) according to claim 1, wherein the time synchronization signal is generated by an edge node designated as Grandmaster. [7] Method (300) according to claim 1, further serving to generate a follow-up frame with a timestamp in order to determine a latency between the first switch (415) and the second switch (425). [8] Method (300) according to claim 1, further comprising a fourth switch which receives the time synchronization signal from the third switch (435).