Method for monitoring an application for providing at least one safety-critical function for a vehicle
A monitoring method for safety-critical vehicle applications generates and analyzes standardized signals based on runtime characteristics, addressing the limitations of existing techniques by enabling effective monitoring without requiring internal application knowledge.
Patent Information
- Application Number
- DE102023212765
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-18
AI Technical Summary
Existing monitoring techniques for safety-critical software applications in vehicles, such as software-defined vehicles, are limited in their ability to detect deviations from expected behavior due to the lack of detailed knowledge of the applications' internal structures and functionalities, especially in multi-tiered systems where applications are developed by multiple third-party developers.
A method involving a monitoring function that generates a defined signal based on runtime characteristics of the application, allowing monitoring without requiring knowledge of the application's internal functionality, and a monitoring component that analyzes this signal to detect deviations, enabling actions such as process termination or access restrictions.
Enables comprehensive monitoring of safety-critical applications in vehicles without needing internal application knowledge, detecting deviations and ensuring reliable operation by allowing external monitoring of runtime characteristics.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for monitoring an application for providing at least one safety-critical function for a vehicle. Furthermore, the invention relates to a computer program, a device, and a storage medium for this purpose. State of the art
[0002] Safety-critical software-controlled systems such as vehicles, especially software-defined vehicles (SdVs), require comprehensive application monitoring to ensure reliable and trustworthy operation. More specifically, software applications must be monitored to quickly detect any behavior that deviates from the expected behavior, whether as a result of a random error or a deliberate cyberattack.
[0003] However, implementing comprehensive application monitoring for systems such as vehicles is challenging and cannot be adequately realized with established solutions, since the applications in such systems are written by different software companies or independent developers and an integrator, e.g. an OEM, does not know the exact expected behavior of these applications.
[0004] As a result, existing techniques only allow for historical monitoring, not detailed monitoring. More importantly, existing techniques require detailed knowledge of the internal structure and functionality of the corresponding software application. This is challenging in multi-tiered systems such as vehicles, where applications are created by numerous third-party developers and then run on the platform of the integrator, e.g., an OEM, who has no control over these third-party developers.
[0005] Existing monitoring techniques, for example, are based on hardware- or software-based monitoring, usually through a watchdog. These techniques can be used for history monitoring. For example, a watchdog can be configured to interrupt an application if it does not terminate after a certain period of time. However, such techniques are very restricted and therefore limited in their effectiveness. For example, these techniques cannot detect an erroneous computation result or a change in control streams. State-of-the-art approaches are also limited in terms of the required internal knowledge of the respective application. For example, configuring a watchdog to interrupt an application after a certain period of time requires detailed knowledge of the application's internals, i.e., the implementation details. Disclosure of the invention
[0006] The invention relates to a method having the features of claim 1, a computer program having the features of claim 11, a device having the features of claim 12, and a computer-readable storage medium having the features of claim 13. Further features and details of the invention emerge from the respective subclaims, the description, and the drawings. Features and details described in connection with the method according to the invention naturally also apply in connection with the computer program according to the invention, the device according to the invention, and the computer-readable storage medium according to the invention, and vice versa, so that with regard to the disclosure of the individual aspects of the invention, reference is or can always be made to each other.
[0007] The invention particularly relates to a method for monitoring an application for providing at least one safety-critical function for a vehicle, comprising the following steps, wherein the steps can be carried out repeatedly and / or sequentially. In the context of the present invention, an application is in particular a software application. The safety-critical function is particularly critical for the safety of the vehicle with regard to system damage and / or personal injury. The method can be particularly advantageous for vehicles, since the vehicle-specific applications are important for the correct functioning of the vehicle. In particular for safety-critical applications, it can therefore be important to provide monitoring of the respective application.
[0008] In a first step, at least one monitoring function of the application is preferably provided. The at least one monitoring function generates a defined signal, in particular based on at least one runtime characteristic of the application, in order to specify the at least one runtime characteristic via the defined signal. The runtime characteristic preferably describes at least a course of one or more runtime events. The defined signal is in particular a specific message with respective information relating to the at least one runtime characteristic, such as a current value or an average value of the last hundred values. A structure or a data schema of such a message or of the defined signal can be described in corresponding documentation.After generation, the monitoring function can write the defined signal to a specific target or resource, such as a file, a socket, or a RESTful API. Within the scope of the present invention, the monitoring function can also be understood and referred to as a signaling function.
[0009] In a further step, the generated defined signal is preferably read by a monitoring component. The reading can be performed via a corresponding connection to the aforementioned target or resource, i.e., for example, the monitoring component can read the file into which the defined signal was written. The monitoring component can be a software module and can be implemented in the technical system, preferably as a software module independent of the application.
[0010] Alternatively, the monitoring component may also be implemented on an external data processing device such as a server.
[0011] In a further step, the application is preferably monitored by the monitoring component based on an analysis of the read-out, generated, defined signal. Thus, the method according to the present invention advantageously allows the application of the technical system to be monitored without knowledge of its internal functionality and without, for example, having access to the application's source code. The monitoring particularly includes analyzing values or information from the read-out, generated, defined signal with regard to specific specifications or requirements of a respective application.
[0012] The defined signal is preferably a standardized message that includes current information about the at least one runtime characteristic. The standardized message can be standardized in that a structure of the message can be specified depending on a respective runtime characteristic in order to standardize it. This allows the method to be advantageously used in various applications and vehicles without knowledge of the functionality of the respective application.
[0013] The at least one monitoring function can record the one or more runtime events and reproduce them through the at least one runtime characteristic via the defined signal. The one or more runtime events are particularly specific to a current functionality of the application. The runtime events can be, for example, a runtime of functions, calculation results of functions, and / or specific memory accesses.
[0014] In a further possibility, the method may further comprise the following step: - Carrying out an additional analysis of the at least one runtime characteristic by the monitoring function in order to additionally generate the defined signal taking into account the additional analysis.
[0015] The additional analysis can, for example, be a calculation of an average value or a determination of a minimum or maximum value. Furthermore, the application's monitoring function can already evaluate whether a value of at least one runtime characteristic exceeds a certain threshold during the additional analysis. The result of the steps described above can then be communicated using the defined signal.
[0016] According to a further advantage, the method may further comprise the following step: - Carrying out at least one action based on a result of the analysis of the read-out generated defined signal.
[0017] The result may, for example, indicate that the read-out, generated, defined signal deviates from an expected value or an expected pattern. If this is the case, provision may be made for the at least one measure to be carried out. The at least one measure may, for example, be terminating at least one process of the application, terminating the application, adjusting at least one access restriction of the application to the technical system, closing at least one port of the technical system, and / or adjusting at least one filter rule with regard to data exchange of the application, or may comprise at least one of these steps.
[0018] Furthermore, it is optionally possible for the monitoring function to be executed with a defined periodicity. This advantageously allows for the individual and specific application-specific determination of when and how often the monitoring function is executed. Executing the monitoring function includes, in particular, generating the defined signal.
[0019] Furthermore, within the scope of the invention, it is optionally possible for the at least one runtime characteristic to be an execution time of at least one function of the application and / or an execution time of the entire application. Thus, based on the execution time of the at least one function and / or the application, it is advantageously possible to infer whether the application's behavior is faulty or has been altered by external influences. The external influence can, for example, be a hacking attack on the technical system.
[0020] Furthermore, within the scope of the invention, it is conceivable that the at least one runtime characteristic is an access pattern of the application to at least one system resource of the technical system, wherein the method further comprises the following steps: - Defining a default access pattern, - Comparing the application's access pattern with the defined access pattern specification, whereby the defined signal is generated taking into account a result of the comparison.
[0021] The access pattern can, for example, comprise a number of accesses and / or a sequence of accesses to the at least one system resource of the technical system. A system resource can, for example, be a peripheral, a bus or bus system, a network such as Ethernet, a register, or a comparable software and / or hardware resource of the technical system.
[0022] It may further be possible for the method to further comprise the following step: - Testing the application and the monitoring component based on a bidirectional interaction between the application and the monitoring component with a defined message structure.
[0023] This advantageously ensures that both the application and the monitoring component behave as expected. For example, a valid response from the application may depend on a previous message from the monitoring component. The bidirectional interaction is preferably performed using the application's monitoring function. As an example, a monitoring function and the monitoring component could implement a finite state machine that accepts a language L. Based on previous messages, the monitoring function and the monitoring component could alternately generate a next message, resulting in the word in the language L.
[0024] Advantageously, within the scope of the invention, the method may further comprise the following steps: - Checking whether the application already has the at least one monitoring function and / or at least one alternative monitoring function, wherein in the case of an already existing monitoring function the application is adapted on the basis of the already existing at least one monitoring function and / or the at least one alternative monitoring function.
[0025] This advantageously allows for determining whether the application is safe for use in the technical system, as monitoring is possible using the existing monitoring function. The application can be adapted based on the existing monitoring function by configuring it to generate the defined signal. An alternative suitable monitoring function can also be modified accordingly.
[0026] In a further possibility, it can be provided that the vehicle is a software-defined vehicle and the application is a vehicle-specific application. A software-defined vehicle (SDV) is in particular a concept that refers to vehicles in which software and digital technologies play a central role in the functioning and functions of the vehicle. In a software-defined vehicle, the software is in particular a main driver for innovations, performance improvements and new functions. The monitoring component can, for example, be part of the vehicle or part of an external data processing device. If at least two monitoring components are provided, one of them can, for example, be part of the vehicle and the other part of the external data processing device. The external data processing device can, for example, be a server such as a cloud server.
[0027] It is thus possible for the method according to the invention to be used in a vehicle. The vehicle can be designed, for example, as a motor vehicle and / or passenger vehicle and / or an autonomous or at least partially automated vehicle. The vehicle can have a vehicle device, for example for providing an autonomous driving function and / or a driver assistance system. The vehicle device can be designed to control the vehicle at least partially automatically and / or to accelerate and / or decelerate and / or steer it.
[0028] The invention also relates to a computer program, in particular a computer program product, comprising instructions that, when executed by a computer, cause the computer to execute the method according to the invention. Thus, the computer program according to the invention provides the same advantages as those described in detail with reference to a method according to the invention.
[0029] The invention also relates to a data processing device configured to carry out the method according to the invention. The device can be, for example, a computer that executes the computer program according to the invention. The computer can have at least one processor for executing the computer program. A non-volatile data memory can also be provided, in which the computer program is stored and from which the computer program can be read by the processor for execution.
[0030] The invention may also provide a computer-readable storage medium that has the computer program according to the invention and / or includes instructions that, when executed by a computer, cause the computer to carry out the method according to the invention. The storage medium is designed, for example, as a data storage device such as a hard disk and / or a non-volatile memory and / or a memory card. The storage medium can, for example, be integrated into the computer.
[0031] Furthermore, the method according to the invention can also be implemented as a computer-implemented method.
[0032] Further advantages, features, and details of the invention will become apparent from the following description, which describes exemplary embodiments of the invention in detail with reference to the drawings. The features mentioned in the claims and in the description may be essential to the invention individually or in any combination. They show: Fig. 1 a schematic visualization of a method, a technical system with a system resource, an external data processing device, a device, a storage medium and a computer program according to embodiments of the invention, Fig. 2 a schematic representation of a sequence of the method according to embodiments of the invention, Fig. 3 a schematic representation of an alternative sequence of the method according to embodiments of the invention.
[0033] In Fig. 1, a method 100, a technical system 6 with a system resource 7, an external data processing device 8, a device 10, a storage medium 15 and a computer program 20 according to embodiments of the invention are schematically shown.
[0034] Fig. 1 shows in particular an embodiment of a method 100 for monitoring an application 1 for providing at least one safety-critical function for a vehicle 6. In a first step 101, at least one monitoring function 2 of the application 1 is provided, wherein the at least one monitoring function 2 generates a defined signal based on at least one runtime characteristic 4 of the application 1 in order to specify the at least one runtime characteristic 4 via the defined signal. The runtime characteristic 4 describes at least a course of one or more runtime events. In a second step 102, the generated defined signal is read out by a monitoring component 5. In a third step 103, the application 1 is monitored by the monitoring component 5 based on an analysis of the read out generated defined signal.
[0035] Within the scope of the present invention, particular use is made of monitoring functions 2 that can be added to applications 1, i.e., in particular software applications. These monitoring functions 2 can then be configured and designed by application developers, in particular third parties, to send a standardized signal, e.g., a message described in a technical specification, to a specific standardized endpoint, such as a file, a socket, or a port. A monitoring component 5 can then be used to collect these signals and respond to them, e.g., based on a previously defined set of rules.
[0036] Fig. Figure 2 shows an embodiment of the present invention. In particular, one or more monitoring functions 2 are added to an application 1, in particular a software application.
[0037] The monitoring functions 2 preferably determine one or more runtime characteristics 4 of the application 1, optionally pre-process them and report the runtime characteristics 4 to a predetermined target 3 or resource, such as a file, a socket or a Restful API.
[0038] A monitoring component 5 preferably reads the target 4, in particular regularly, in order to monitor the application 1. The monitoring component 5 according to embodiments advantageously does not require any knowledge about the application 1. The runtime characteristics 4 can, according to embodiments, be calculated and / or determined by the application 1 itself. The monitoring component 5 then in particular only needs to read the target 3. If the runtime characteristics 4 originate from a standard set of application monitoring features, the monitoring component 5 can also apply a predefined or dynamic set of rules, wherein this last step in Fig. 2 is not shown.
[0039] The monitoring function 2 can signal various events of the runtime characteristics 4, including, but not limited to, the following: An access or access time and / or access frequency to peripheral devices, buses such as CAN, networks such as Ethernet, CPU registers, or other operating system or CPU resources. One or more network messages, e.g., CAN messages, or a pattern or structure of network messages such as CAN messages transmitted on the bus or over the network. A specific message or pattern or structure of messages received or sent by the application 1.
[0040] Alternatively or additionally, the monitoring function 2 can generate the defined signal in a reverse mode if such an event does not occur. In other words, the monitoring function 2 can observe the behavior of the application 1 based on one of the above-mentioned or similar metrics and issue a signal if the observed behavior does not match the expected behavior.
[0041] According to a possible alternative, the monitoring functions 2 are provided in the form of a library, so that an app store or a runtime environment, e.g. in an SdV, checks whether an application 1 uses a certain set of monitoring functions 2 before allowing the download or execution of that application 1.
[0042] According to another alternative, the monitoring functions comprise 2 probes triggered every n microseconds or with a certain periodicity.
[0043] According to another alternative, the monitoring functions 2 write the execution times of one or more functions comprising the application 1 to the target 3. In this way, the monitoring component 5 can detect deviations from the expected behavior of the application 1, even if the output of the application 1 is correct. For example, if sophisticated malware were to alter the control flow of the application 1, such monitoring functions 2 could detect this event even if the malware was careful not to alter the output of the application 1. Conventional techniques such as comparing the output with a predetermined threshold or checking an invariant of the output would not detect the malware.
[0044] According to a further alternative, the monitoring functions 2 observe the access of application 1 to system resources, e.g., memory locations or lines, and compare it with a specific, previously defined pattern. A specific monitoring function 2 then preferably writes to the target 3 whether the previously defined pattern was observed or not. This advantageously allows for determining whether selected functions of application 1 were called in a specific order.
[0045] Fig.Figure 3 shows another possible alternative. For example, if application 1 is being developed internally, application 1 and monitoring component 5 can interact to ensure that both application 1 and monitoring component 5 behave as expected. A valid response from application 1 can depend on a previous request or message from monitoring component 5. As an example, a monitor function 2, which monitors application 1, and monitoring component 5 could implement a finite automaton that assumes a language L. Starting from previous symbols or messages, monitoring component 5 and application 1 can alternately generate the next symbol or message, so that the resulting message is in language L.
[0046] The present invention according to embodiments advantageously does not require any knowledge of the internal functioning of applications 1. While existing techniques monitor the application 1, the invention according to embodiments describes a concept for semi-self-monitoring applications 1 in the sense that the monitoring logic is integrated into the applications 1, but an external, system-wide monitoring component 5 can be used to collect the data and react to this data.
[0047] The above explanation of the embodiments describes the present invention exclusively within the scope of examples. Of course, individual features of the embodiments can be freely combined with one another, provided they are technically feasible, without departing from the scope of the present invention.
Claims
[1] Method (100) for monitoring an application (1) for providing at least one safety-critical function for a vehicle (6), comprising the following steps: - Providing (101) at least one monitoring function (2) of the application (1), wherein the at least one monitoring function (2) generates a defined signal based on at least one runtime characteristic (4) of the application (1) in order to specify the at least one runtime characteristic (4) via the defined signal, wherein the runtime characteristic (4) describes at least a course of one or more runtime events, - reading (102) the generated defined signal by a monitoring component (5), - Monitoring (103) the application (1) on the basis of an analysis of the read-out generated defined signal by the monitoring component (5). [2] Method (100) according to claim 1, characterized by , that the defined signal is a standardized message which comprises current information about the at least one runtime characteristic (4), wherein the one or more runtime events are recorded by the at least one monitoring function (2) and reproduced by the at least one runtime characteristic (4) by the defined signal, where the one or more runtime events are specific to a current functionality of the application. [3] Method (100) according to claim 1 or 2, characterized by that the method (100) further comprises the following step: - Carrying out an additional analysis of the at least one runtime characteristic (4) by the monitoring function (2) in order to additionally generate the defined signal taking into account the additional analysis. [4] Method (100) according to one of the preceding claims, characterized bythat the method (100) further comprises the following step: - Carrying out at least one measure based on a result of the analysis of the read-out generated defined signal, wherein the at least one measure comprises terminating at least one process of the application (1), terminating the application (1), adapting at least one access restriction of the application (1) to the vehicle (6), closing at least one port of the vehicle (6) and / or adapting at least one filter rule with regard to a data exchange of the application (1). [5] Method (100) according to one of the preceding claims, characterized by that the monitoring function (2) is executed with a defined periodicity. [6] Method (100) according to one of the preceding claims, characterized bythat the at least one runtime characteristic (4) is an execution time of at least one function of the application (1) and / or an execution time of the entire application (1). [7] Method (100) according to one of the preceding claims, characterized by that the at least one runtime characteristic (4) is an access pattern of the application (1) to at least one system resource (7) of the vehicle (6), wherein the method (100) further comprises the following steps: - Defining a default access pattern, - comparing the access pattern of the application (1) with the defined specification for the access pattern, wherein the defined signal is generated taking into account a result of the comparison. [8] Method (100) according to one of the preceding claims, characterized by that the method (100) further comprises the following step: - Testing the application (1) and the monitoring component (5) based on a bidirectional interaction between the application (1) and the monitoring component (5) with a defined message structure. [9] Method (100) according to one of the preceding claims, characterized by that the method (100) further comprises the following steps: - Checking whether the application (1) already has the at least one monitoring function (2) and / or at least one alternative monitoring function, wherein in the case of an already existing monitoring function (2) the application (1) is adapted on the basis of the already existing at least one monitoring function and / or the at least one alternative monitoring function. [10] Method (100) according to one of the preceding claims, characterized bythat the vehicle (6) is a software-defined vehicle and the application (1) is a vehicle-specific application, wherein the monitoring component (5) is part of the vehicle (6) or part of an external data processing device (8). [11] Computer program (20) comprising instructions which, when the computer program (20) is executed by a computer (10), cause the computer (10) to carry out the method (100) according to one of the preceding claims. [12] Device (10) for data processing which is arranged to carry out the method (100) according to one of claims 1 to 10. [13] A computer-readable storage medium (15) comprising instructions which, when executed by a computer (10), cause the computer (10) to carry out the steps of the method (100) according to any one of claims 1 to 10.
Citation Information
Patent Citations
Control of a motor vehicle
DE102020131998A1
Processor system and method for monitoring processors
EP3291094A1