Method for securing the transmission of user data, as well as a transmitter device and motor vehicle set up for this purpose.
By calculating user data and a test value in parallel paths within a transmitter and combining them for error detection, the method simplifies and secures data transmission, reducing complexity and costs without compromising safety.
Patent Information
- Application Number
- DE102024126963
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2025-12-31
- Estimated Expiration
- 2044-09-19
AI Technical Summary
Current data transmission methods require significant effort, hardware, and complexity to ensure security and reliability, particularly in safety-critical applications, without providing a cost-effective solution.
A method where user data is calculated in a primary and secondary path within a transmitter, with a test value generated in the secondary path, combined into a single data set, and transmitted to a receiver for error detection, eliminating the need for redundant connections and simplifying verification.
This approach enhances communication integrity and reduces system complexity by allowing error detection in a single message transmission, maintaining safety levels while minimizing processing load and costs.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a method for securing the transmission of user data and to a control unit configured for this purpose, for example for a motor vehicle. The invention further relates to a correspondingly configured motor vehicle.
[0002] Nowadays, data needs to be transferred for a wide variety of applications and functions, for example, between different control units, computers, or similar devices. In principle, errors can occur during the calculation and / or transmission of this data. Since this can have undesirable consequences, safeguards against undetected errors or the further processing of faulty data are desirable. Depending on the application, there may be different requirements, and thus various solutions already exist.
[0003] As one approach, DE 10 2019 106410 A1 describes a device and a method for data transmission that are particularly suitable for communication between components of a redundantly implemented system group. In this approach, the components of the system group are not connected by separate physical lines, but rather by a common physical connection that links all redundantly implemented system groups. The required transmission reliability with regard to data integrity is achieved through CRC coding, in which sequentially arranged data packets are assigned an incrementing counter value, so that the resulting CRC code reliably detects static errors over time.
[0004] DE 103 43 172 A1 describes a data transmission link with a device for checking the data integrity of data transmitted from the sender to the receiver side of the data transmission link, particularly in a motor vehicle. The link includes a first, sender-side, and a second, receiver-side data modification device, each with the same transmission function. The data transmission link also includes a comparator that compares the output data of the data modification devices. Input data is processed into output data on the sender side and transmitted to the receiver side, and identical input data is transmitted to the receiver side and modified there into output data.
[0005] German patent DE 102019 201 728 A1 describes a method for securing data using at least two computing units and a decision unit connected to them. Each computing unit processes received data, generates an intermediate check value for the processed data, and transmits this value to the decision unit. The decision unit then uses the intermediate check values received from the computing units to calculate a final check value. The processed data is then marked with the final check value and output.
[0006] German patent DE 10 2021 211 709 A1 describes a data processing network for the redundant and validated execution of multiple successive data processing steps, each serving to generate output data from input data. The output data of a first data processing step is at least partially the input data of a subsequent data processing step. At least one first data processing module is provided for the execution of each data processing step. The first data processing modules are configured to transmit control parameters of the individual data processing steps to a comparator module of the data processing network. The comparator module is configured to provide a synchronized control parameter containing control information regarding at least one executed data processing step.The data processing network has a recording module in which a debug mode can be activated, with which debug data is recorded, containing information about each execution of a data processing step with the data processing network.
[0007] CN 115 / 085 867 A describes a procedure for end-to-end (E2E) verification of CAN bus messages. This involves receiving E2E-protected messages and verifying them using a pre-generated configuration file.
[0008] US 6,222,820 B1 describes a method for providing selective redundancy in a network between two end users. In this method, a primary connection is established via a first route, and a redundant connection is established via a second route between the end users. If a failure of the primary connection is detected, traffic is switched from the primary connection to the redundant connection.
[0009] CN 216 / 122938U describes a control system for vehicle lights with two microcontrollers and a comparator for comparing the outputs of the microcontrollers. The microcontrollers are connected to modules for voltage monitoring, data verification, operating program monitoring, LED diagnostics, communication protection, and logic validation.
[0010] CN 113 341 906 A describes a method for error handling in a vehicle's LIN bus, via which a main node is connected to at least one slave node. In this method, a first E2E message is sent to the first slave node, containing a CRC signal and a message counter signal. A second E2E message, correspondingly sent by the first slave node, is received, indicating whether a check of the CRC signal of the first E2E message failed and / or whether the message counter signal of the first E2E message is abnormal. Based on the second E2E message, it is then determined whether the first slave node has a communication error via the LIN bus. If so, an error code and so-called freeze frame information are stored, indicating communication error information detected by the first slave node.
[0011] However, current approaches often require significant effort, for example, for calculations and / or necessary hardware and / or data transmission via separate or redundant data connections, or similar measures. A reduction in effort and complexity would be desirable here, without compromising security.
[0012] The object of the present invention is to enable secure data transmission in a particularly cost-effective manner.
[0013] This problem is solved by the subject matter of the main claim and the dependent claims or independent claims. Further possible embodiments of the invention are disclosed in the subclaims, the description, and the figures. Features, advantages, and possible embodiments set forth in the description for one of the subject matter of the independent claims are to be regarded, at least analogously, as features, advantages, and possible embodiments of the respective subject matter of the other independent claims, as well as of any possible combination of the subject matter of the independent claims, optionally in conjunction with one or more of the dependent claims.
[0014] The method according to the invention serves to secure the transmission of user data from a transmitter to a receiver. The transmitter and receiver can be, for example, control units, computers, or other data processing devices. In particular, they can be control units, computing units, or the like for a motor vehicle. However, the invention can also be used for other applications. In one step of the method according to the invention, the user data to be transmitted is calculated within the transmitter from the respective input data, once in a main or primary path or by a main or primary module of the transmitter, and in parallel or redundantly a second time in a redundant path or secondary path or by a redundancy or secondary module. These modules can, for example, be separate computing units within the transmitter.In particular, the primary and secondary modules can use or comprise at least partially different, i.e., separate or dedicated, computing hardware. The input data can, for example, be data previously received by the transmitter, transmitted by an upstream device, or sensor data acquired or received by the transmitter. Similarly, the input data can be data resulting from a previous calculation or data processing by the transmitter, or similar information. The exact type and / or origin of the input data can therefore vary depending on the specific application.
[0015] In a further step of the inventive process, a test value is calculated in the redundant path or by the secondary module for the user data calculated by it, according to a predefined method. Since this test value is calculated within the transmitter device, it is also referred to here as the transmitter test value. For example, the transmitter test value can be a CRC sum, a hash value, or the like.
[0016] In a further step of the inventive process, the user data calculated by the primary module and the test value calculated by the secondary module are combined within the transmitter device to form a single overall data set. This can be performed, for example, by a merging or combining module of the transmitter device. Since the test value is calculated from the user data calculated by the secondary module, but the overall data set contains not this user data but instead the user data calculated by the primary module, it may still be unclear at this point whether the user data calculated by the primary module and the user data calculated by the secondary module correspond, i.e., whether the test value calculated by the secondary module matches the user data calculated by the primary module. This can therefore save the corresponding verification effort on the part of the transmitter device.
[0017] In a further step of the inventive process, the respective complete data set is then sent from the sending device to the receiving device via a data connection. In particular, the complete data set, i.e., all parts of the complete data set together, can be sent to the receiving device via a single data connection. This eliminates the need for a second or redundant data connection, thus saving the associated effort.
[0018] In a further step of the inventive process, the receiver device checks whether the test value contained in the received data set matches the user data contained in the received data set. If this is not the case, an error is detected. In this way, the receiver device can, for example, detect whether an error has occurred in one of the modules of the transmitter device, such as during the calculation of the user data or the calculation of the test value, or during the transmission of the data set from the transmitter device to the receiver device. If an error is detected, a predefined, automatic response can be initiated, which may depend on the specific application or requirements.If, however, the test value matches the user data, this can demonstrate that the entire dataset was transmitted correctly and that no error occurred during the previous combination of the user data with the test value. Furthermore, it can also demonstrate that the prior calculation of the user data in the primary module was performed correctly, and thus that the entire data processing function was executed correctly, since the result of the computational redundancy inherent in the primary module was implicitly transmitted and checked. These assumptions regarding error-free operation can be justified because, in practice, it is unlikely that multiple errors would occur simultaneously at different points, their effects canceling each other out or corresponding in such a way that no error is detected.
[0019] The methodology proposed here allows a single message transmitted from the sender to the receiver—that is, the entire data set—to be sufficient for checking for potential errors during calculation and / or transmission, thus enabling the detection of such errors without the need for separate transmission paths for the user data or error information. This results in improved communication integrity between the devices compared to unsecured transmission, while simultaneously reducing the complexity of the necessary security technology compared to conventional methods. For example, the present invention can reduce system complexity by eliminating a comparator, which in turn leads to less susceptibility to errors and a simpler system design, while, for example, compared to correspondingly more complex systems, a security or...A certain level of safety, such as a specific ASIL (Automotive Safety Integrity Level), can be maintained. By combining the user data and the test value in the overall data set, verification or validation can be simplified, thereby reducing or keeping the processing load on the devices, especially the receiving device, to a minimum, while simultaneously enabling comparatively simple implementation. Overall, the present invention can thus enable increased robustness in data transmission or distributed data use by facilitating the detection, i.e., the recognition, of various errors, particularly when combining user data and test values, as well as during transmission, without requiring additional safety mechanisms on the receiving device.
[0020] The present invention can, for example, be used in applications that are generally less safety-critical and / or enable a particularly simple achievement of a specific safety or security level. For example, according to the invention, individual components or steps, such as combining the user data calculated by the primary module with the test value calculated by the secondary module, or a corresponding combination module, can each be implemented in or with ASIL QM, and a higher ASIL can still be achieved overall, i.e., in a more comprehensive system. Within the framework of the method according to the invention, it is not necessary, for example, for the receiver device to recognize which message or data should have been sent by the transmitter device, or at what point a detected error occurred in detail. This allows the described savings and simplifications to be utilized practically and without difficulty.
[0021] In a possible further development of the present invention, the test value is calculated only by the secondary module. The primary module, on the other hand, does not calculate a test value. In other words, the test value is calculated only once in the transmitter. Redundancy in the test value calculation is therefore unnecessary. This saves considerable effort and complexity on the transmitter side. Because the test value and the user data ultimately used in the receiver are calculated by different modules within the transmitter, a certain degree of redundancy and protection against calculation errors of the user data or the test value is implicitly provided. Thus, while maintaining this protection on the transmitter side, manufacturing effort, data processing effort, implementation effort, and costs can be reduced.
[0022] In a further possible embodiment of the present invention, the primary module and the secondary module also output respective identification data and / or predefined keepalive signals or keepalive data. The identification data identifies the respective output data, i.e., the user data calculated by the primary module or the test value calculated by the secondary module, and / or a respective data source from which the respective data originates, i.e., the primary module or the secondary module. Such identification data can, for example, be DIDs (Decentralized Identifiers). The keepalive signals can, for example, include a counter value or a counter signal and / or a timestamp.Such a counter value or counter signal can be automatically incremented according to a predefined time schedule, so that at any point in the system it is clear at any time which keepalive signal should be received, was last received, or should be received next during normal operation. Similarly, the keepalive signals can be incremented with each intended or actual output or transmission of data or signals. The identification data and / or the keepalive signals can be output, for example, by the primary module together with the respective usage data, or by the secondary module together with the respective test value. Likewise, at least the keepalive signals can be incremented independently of the availability of new, i.e., not yet output, usage data.A new, i.e., not yet issued, test value is regularly output by the primary and secondary modules in a predefined manner. This enables monitoring of the modules' functionality and their data connection, for example, to the combination module mentioned elsewhere. This allows for the early and reliable detection of any errors. Furthermore, the identification data and / or keepalive signals support the combination of the respective user data with the corresponding test value, thus ensuring a particularly secure, reliable, and robust process. The identification data can, for example, uniquely identify the respective data source or communication channel, such as at the level of a motor vehicle in which the invention is applied.
[0023] In a further possible embodiment of the present invention, to check whether the test value corresponds to the user data, a test value is also calculated in or by the receiver device for the user data contained in the respective received total data set. This test value calculated on the receiver device side is also referred to here as the receiver test value. This receiver test value is then compared in or by the receiver device with the transmitter test value contained in the received total data set. In particular, the transmitter test value and the receiver test value can be calculated using the same function or methodology, i.e., according to the same calculation procedure. If the receiver test value and the transmitter test value are identical, it can be assumed that the calculation and transmission of the data was error-free. If, on the other hand, the receiver test value deviates from the transmitter test value, an error can be detected.Calculating the receiver checksum can be done relatively easily and with minimal effort. Furthermore, such checksums can enable robust detection of random errors or unintentional data changes, thus providing appropriate security.
[0024] In another possible embodiment of the present invention, the transmitter sends a keep-alive signal or keep-alive data to the receiver at predetermined intervals, regardless of whether new user data (i.e., data not yet transmitted to the receiver) is available. The receiver then detects an error if an expected keep-alive signal from the transmitter is not received. Thus, the receiver can, for example, detect a complete failure of the transmitter if no data or signals are received from it. Similarly, an error can be detected, for example, in the case of a temporary interruption of the data connection, such as when an expected keep-alive signal is skipped.The latter can mean, for example, that a keepalive signal received by the receiver, originating from the transmitter, is increased or modified by two units compared to the last received keepalive signal, even though an increase or modification of one unit is predetermined for each of two consecutive keepalive signals. The embodiment of the present invention proposed here allows for protection against a wider range of possible error scenarios.
[0025] In a further possible embodiment of the present invention, a predefined error response is executed or initiated when an error is detected in or by the receiver. An error can be detected at least when the test value does not match the usage data or when an expected signal from the transmitter is missing, i.e., not received by the receiver. Depending on the application, different error responses can be predefined. For example, the detected error can simply be logged as an error response. Similarly, an error response can be, for example, a request for retransmission of the data, i.e., sent from the receiver to the transmitter.Similarly, as an error response, a function affected by the error or dependent on the affected user data, for example in a motor vehicle in which the method according to the invention is applied, can be deactivated. Likewise, as an error response, a warning can be issued to a user or the issuance of such a warning can be initiated. Several different possible error responses can also be predefined, whereby the respective error response executed or initiated can then be automatically selected depending on the detected error or its type. By automatically executing or initiating a predefined error response, needs-based error handling can be implemented. Depending on the application, this can, for example, benefit robustness, reliability, or safety and / or enable the improvement or further development of a given system.
[0026] In a further possible embodiment of the present invention, the user data received as part of the overall data set is only processed further in or by the receiving device if no error is detected in or by the receiving device. For example, a predetermined calculation can then be performed using the user data, or a control operation can be carried out or initiated according to the user data, or the user data can be forwarded from the receiving device or a receiving and testing module of the receiving device, for example to a calculation module of the receiving device or the like. Conversely, if an error is detected, the further use of the received user data can be stopped or omitted.The proposed embodiment of the present invention prevents the propagation of errors, for example, to subsequent calculations or control processes. This avoids unforeseen consequences, which, depending on the application, can improve robustness, reliability, or safety.
[0027] The present invention also relates to a transmitter device configured for use as a transmitter in the method according to the invention. The transmitter device according to the invention comprises a primary module, a secondary module, a combination module, and an output interface. The primary module is configured to process input data into user data and to output the user data to the combination module. The secondary module is configured to process input data into user data, to calculate a test value for the user data, and to output the test value to the combination module. The combination module is configured to combine the user data output by the primary module and the test value output by the secondary module into a single overall data set and to transmit the single overall data set via the output interface to a receiver device.The transmitter device according to the invention can, in particular, be the transmitter device mentioned in connection with the method according to the invention or correspond to it. For this purpose, the transmitter device can comprise appropriate computing hardware, for example, microchips, microprocessors, microcontrollers, or the like, and computer-readable data storage devices coupled thereto. These data storage devices can then contain corresponding operating or computer programs that encode or implement the process steps, measures, or sequences described in connection with the method according to the invention, or corresponding control instructions, and which can be executed by means of the process equipment in order to carry out the corresponding method or to effect its execution. Likewise, the transmitter device can, for example, have an input interface for acquiring or receiving the respective input data.The input and output interfaces can be separate or combined or integrated in a common bidirectional interface. The transmitter can be specifically designed for a motor vehicle and thus configured accordingly. For example, the transmitter can be or include an engine control unit, a battery control unit, a cell supervision circuit (CSC), a sensor, or the like. Likewise, a variety of other configurations or applications are possible.
[0028] The present invention also relates to a motor vehicle comprising at least one transmitter device according to the invention and at least one receiver device connected thereto via at least one data connection. According to the invention, the motor vehicle is equipped for the execution of the method according to the invention, in particular automatically. The motor vehicle according to the invention may, in particular, be the motor vehicle mentioned in connection with the method according to the invention and / or in connection with the transmitter device according to the invention, or correspond to it.
[0029] In one possible embodiment of the present invention, the transmitter and receiver are connected to each other via a single data connection for transmitting data signals, such as the data associated with the complete data sets of the method according to the invention. Such a data connection can be, for example, a data line, a data cable, or a wireless data connection. Depending on the embodiment, it may also be possible to transmit data signals, i.e., data and / or signals, from the receiver to the transmitter, either via the same data connection or a different one.The embodiment of the present invention proposed here enables a particularly simple, cost-effective and robust construction of the motor vehicle by using only one data connection from the transmitter device to the receiver device, thus eliminating the need for a second or redundant data connection.
[0030] Further features of the invention may become apparent from the claims, the figures, and the description of the figures. The features and combinations of features mentioned above in the description, as well as the features and combinations of features shown below in the description of the figures and / or in the figures themselves, can be used not only in the combinations specified, but also in other combinations or on their own, without departing from the scope of the invention.
[0031] The drawing shows in: Fig. 1. A partial schematic representation of a motor vehicle equipped for secure data transmission between two control units; and Fig. 2. A schematic representation to further illustrate the secure data transmission.
[0032] In the figures, identical and functionally equivalent elements are provided with the same reference symbols.
[0033] Currently, vehicle communication systems often use two paths for safety-relevant functions to create redundancy. Such redundancy may be necessary to achieve a required ASIL (Automatic Safety Integrity Level). For example, if the result of a redundant calculation is to be sent to another control unit, end-to-end (E2E) protection of the transmission or a transmitted message can be implemented. In this approach, the message can be calculated in both a primary path and a redundant path, and E2E protection measures can be performed independently to ensure data integrity. The calculated and verified messages can then each be forwarded to a comparator that checks the consistency of both messages.However, typically only the main path is responsible for actually sending the verified message to the other control unit via a communication channel. In case of a calculation error, the comparator can inform the other control unit that an error has occurred via a second logical communication channel. This duplicated calculation and verification strategy can increase transmission security and reliability, which can be particularly important in safety-critical applications. However, this also entails considerable complexity, arising in particular from the use of a comparator and the need for a second communication channel.
[0034] However, at least for certain applications, some of this complexity can initially be reduced. To illustrate this, see... Fig. Figure 1 shows a partial schematic representation of a motor vehicle. The following components of this motor vehicle are shown schematically: a data source 2, a transmitter 3, a receiver 4, and a vehicle control unit 5. The data source 2 can be, for example, a sensor, a control unit, or the like, and sends data signals to the transmitter 3. From the transmitter 3's perspective, this data is input, which the transmitter 3 can receive and process. The resulting processing can then be sent from the transmitter 3 to the receiver 4. Based on this, the receiver 4 can then, for example, control the vehicle control unit 5 or, in turn, send its own processing results to the vehicle control unit 5.
[0035] The primary focus here is on the processing of input data in and from the transmitter 3, the data transmission from the transmitter 3 to the receiver 4, and further data processing in and from the receiver 4. In this sense, the focus is particularly on improved data transmission between the transmitter 3 and the receiver 4, which could, for example, be control units.
[0036] The transmitter 3 is schematically represented here by a transmitter input interface 6, through which the transmitter 3 can receive the input data from the data source 2, a primary module 7, a secondary module 8, a combination module 9, and a transmitter output interface 10. The primary module 7 and the secondary module 8 can process the respective input data in parallel and independently of each other and each output corresponding processing results to the combination module 9. The combination module 9 can combine the processing results output by the primary module 7 and the secondary module 8 and send a corresponding combined data set to the receiver 4 via the transmitter output interface 10.
[0037] The receiver device 4 is schematically represented here by a receiver input interface 11, a processor 12, a computer-readable data storage device 13 coupled to it, and a receiver output interface 14. The receiver device 4 can receive the data set transmitted by the transmitter device 3 via the receiver input interface 11. The receiver device 4 can then process this data set using the processor 12 and the data storage device 13 and, if necessary, output corresponding processing results or control signals, or the like, to the vehicle direction 5 via the receiver output interface 14.
[0038] Fig.Figure 2 shows a schematic representation to further illustrate the functionality and data processing. It depicts that the primary module 7 outputs a primary data set 15 to the combination module 9 as a processing result, containing primary metadata 16 and primary user data 17. The primary metadata 16 can, for example, be or include identification data and / or keepalive data. The primary user data 17 can be calculated by the primary module 7 from the input data.
[0039] In parallel, the secondary module 8 can also process the input data and output a secondary data record 18 to the combination module 9 as a processing result. This secondary data record 18 contains secondary metadata 19 and a check value 20. Analogous to the primary metadata 16, the secondary metadata 19 can be used to identify the source of the respective data record, in this case, the secondary module 8, and / or to indicate the ongoing activity of the respective module, in this case, the secondary module 8, or the data connection between the respective module and the combination module 9.
[0040] Secondary module 8 can be configured or designated to calculate the same user data as primary module 7, based on the respective input data. However, secondary module 8 additionally calculates the test value 20 for the user data and outputs it as part of secondary data set 18. In particular, unlike primary data set 15, secondary data set 18 does not contain any user data.
[0041] The combination module 9 combines the primary data set 15 and the secondary data set 18 into a combined data set 21. This combined data set 21 can contain or include sender metadata 22, the test value 20, and the primary payload 17. The sender metadata 22 can, for example, identify the combined data set 21 as originating from the sender device 3 and / or be or include keepalive data for the data link between the sender device 3 and the receiver device 4. When combining the primary data sets 15 and secondary data sets 18, the combination module 9 can take into account the primary metadata 16 and secondary metadata 19 contained therein to ensure correct assignment. This ensures that the test value 20 integrated into the respective combined data set 21 is calculated for payload data that was calculated from the same input data as the primary payload 17 ultimately integrated into the same combined data set 21.
[0042] The receiver 4 can, in turn, receive the complete data set 21 and, analogous to the test value 20, calculate a receiver test value for the primary user data 17 contained therein and compare this with the test value 20 contained in the respective complete data set 21 in order to detect any errors. Depending on the result of the comparison, the receiver 4 can then, for example, control the vehicle equipment 5 or execute or initiate a predefined error response.
[0043] The primary module 7 can represent a main path that outputs the payload without a checksum, while the secondary module 8 can represent a redundant path that outputs the checksum 20 but no payload. A merging process performed in or by the combination module 9 can combine both—the primary data set 15 and the secondary data set 18—into a secure message in the form of the complete data set 21. Based on this, errors can be detected in the receiving device 4 without an additional communication channel or logic. This reduces system complexity and ensures efficient error detection.
[0044] It can be assumed here that the calculation of the user data, as well as the calculation or provision of the input data, takes place in a secure environment. Combination module 9, on the other hand, can represent a non-safety-critical quality level, for which, for example, only ASIL QM might be required.
[0045] Overall, the described examples show how efficient and fault-tolerant sending of E2E-secured messages can be implemented from a redundantly calculated ASIL function. Reference symbol list 1 motor vehicle 2 Data source 3 transmitters 4 Receiver device 5 Vehicle equipment 6 Transmitter input interface 7 Primary Module 8 Secondary Module 9 Combination module 10 Transmitter output interface 11 Receiver input interface 12 processor 13 Data storage 14 Receiver output interface 15 Primary data set 16 Primary Metadata 17 Primary user data 18 Secondary data set 19 Secondary Metadata 20 test value 21 Total data set 22 Transmitter metadata
Claims
[1] Method for securing a transmission of user data (17) from a sending device (3) to a receiving device (4), wherein automatically - within the transmitter (3) the user data (17) to be transmitted is calculated from input data once by a primary module (7) of the transmitter (3) and in parallel a second time by a secondary module (8), - a test value (20) is calculated by the secondary module (8) for the user data calculated by the secondary module (8) according to a predefined method, - within the transmitter (3) the user data (17) calculated by the primary module (7) and the test value (20) calculated by the secondary module (8) are combined together in a total data set (21), - the complete data set (21) is sent from the sender device (3) to the receiver device (4) via a data connection, - in the receiver device (4) it is checked whether the check value (20) contained in the received total data set (21) matches the user data (17) contained in the received total data set (21) and if this is not the case, an error is detected. [2] Method according to claim 1, characterized by , that the test value (20) is only calculated by the secondary module (8) and the primary module (7) does not calculate a test value. [3] Method according to any one of the preceding claims, characterized by , that the primary module (7) and the secondary module (8) also output respective identification data (16, 19) which identify the respective output data (15, 18) and / or a respective data source (7, 8), and / or predefined keepalive signals (16, 19) and these are taken into account for combining the user data (17) output by the primary module (7) with the corresponding check value (20) output by the secondary module (8). [4] Method according to any one of the preceding claims, characterized by , that to check whether the test value (20) matches the user data (17), the receiver device (4) calculates a test value for the user data (17) contained in the received total data set (21) and compares it with the test value (20) contained in the received total data set (21). [5] Method according to any one of the preceding claims, characterized by , that the transmitter (3) sends a keepalive signal (22) to the receiver (4) at a predetermined regularity, irrespective of the availability of new user data (17), and that the receiver (4) detects an error if an expected keepalive signal (22) from the transmitter (3) is not received. [6] Method according to any one of the preceding claims, characterized by , that when an error is detected by the receiver (4), a predetermined error response is initiated. [7] Method according to any one of the preceding claims, characterized by , that only if no error is detected by the receiver (4) will the receiver (4) process the user data (17) received as part of the total data set (21) in the specified manner. [8] Transmitter device (3), in particular for a motor vehicle (1), which is configured for use as a transmitter device (3) in the method according to one of claims 1 to 7 and for this purpose comprises a primary module (7), a secondary module (8), a combination module (9) and an output interface (10), wherein - the primary module (7) is set up to process input data into respective user data (17) and to output the user data (17) to the combination module (9), - the secondary module (8) is set up to process the input data into respective user data, to calculate a test value (20) for this user data and to output the test value (20) to the combination module (9), - the combination module (9) is set up to combine the user data (17) output by the primary module (7) and the test value (20) output by the secondary module (8) into a respective total data set (21) and to send the respective total data set (21) via the output interface (10) to a receiver device (4). [9] Motor vehicle (1) comprising a transmitter (3) according to claim 8 and at least one receiver (4) connected thereto via a data connection, wherein the motor vehicle (1) is equipped to carry out the method according to any one of claims 1 to 7. [10] Motor vehicle (1) according to claim 9, characterized by, that the transmitter (3) and the receiver (4) are connected to each other via a single data connection for the transmission of data signals from the transmitter (3) to the receiver (4).
Citation Information
Patent Citations
Device and method for data transmission
DE102019106410A1
Method for securing data using at least two computing units and a decision unit that is in communication connection with the at least two computing units
DE102019201728A1
Data processing network for data processing
DE102021211709A1
data transmission path with device for checking the data integrity
DE10343172A1