Methods for flexibly adjusting the bit rate within a computer network

The intelligent mechanism in vehicle networks dynamically adjusts bit rates and introduces pseudo grandmaster clocks to address Ethernet-based challenges, enhancing reliability and security in vehicle networks.

DE102024202035B4Active Publication Date: 2026-02-05CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102024202035
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-03-05
Publication Date
2026-02-05
Estimated Expiration
2044-03-05

AI Technical Summary

Technical Problem

Existing Ethernet-based vehicle networks face challenges in flexible bit rate adaptation, heat dissipation, and single-point failure of the grandmaster clock, which can compromise operational safety and reliability, especially in autonomous driving applications.

Method used

Implementing an intelligent mechanism using the IEEE 802.1AS time synchronization protocol to dynamically adjust bit rates based on ambient temperature and network requirements, while introducing pseudo grandmaster clocks to enhance security and redundancy, without additional hardware or protocol modifications.

Benefits of technology

Enables flexible bit rate adjustment, enhances network reliability and security, reduces system costs, and improves fault detection, ensuring reliable data transmission and operational safety in vehicle networks.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A method for flexibly adjusting the bit rate within a computer network with at least one first node, wherein the node exchanges information via a data bus and / or a point-to-point connection, wherein the steps of - acquiring information about the first reception time of a first message, - receiving information about the first transmission time of the first message, - acquiring information about the second reception time of a second message, - receiving information about the second transmission time of the second message, - determining a first value depending on the received and acquired information, and - comparing the first value with a predetermined second value, - recognizing a state of the first node depending on the comparison result, are performed, characterized in thatthat the comparison result determines a clock generator for generating clock signals of at least the first node and the bit rate present via the data bus and / or via the point-to-point connection to and from the first node and to other nodes in the computer network, and that, if the bit rate is known, the bit rate in the computer network can be flexibly changed by modifying the clock generator for generating the clock signals.
Need to check novelty before this filing date? Find Prior Art

Description

FIELDThe present invention relates to a method for flexibly adapting the bit rate within a computer networkBACKGROUNDThe control units used in vehicles, in particular in motor vehicles, are connected via a computer network, so-called on-board power supply system, to one another and to sensors for detecting states of the vehicle or parts thereof. In this case, the control units used in a vehicle fulfil different functions for operating the vehicle and in this respect receive data which are sent by sensors via the on-board power supply system. Many applications require as deterministic as possible knowledge about the reliability of the sensor data. In order to ensure the most reliable possible function of the vehicle, the on-board power supply system must therefore meet particularly high requirements with respect to the convenience of the data transmitted on the on-board power supply system.Ethernet technologies are increasingly being used in vehicles and replace older or proprietary data connections and buses there. Ethernet connections support a plurality of switching protocols on layer 3 of the OSI layer model for the transmission of data packets between transmitters and receivers. In the higher protocol layers, the data stream is segmented into packets, the process communication between mutually communicating systems, the translation of data into a system-independent form and finally the provision of functions for applications.Work is currently being done on the next I / O architecture expression, the so-called "zone oriented architecture" and "server based architecture". The difference from a present-day architecture is that control units are positioned at specific geopositions in order to collect sensor data there. The major difference from conventional architectures is that the computing power and most functions are consolidated on the central server ECUs, i.e. application software is executed only on these control devices. All remaining ECUs, the so-called zone controllers, collect "only" data from the various sensors.Consolidation of the functions to very few control units (servers) means that much more computing power per ECU will be necessary. In order to be able to estimate and use this computing power, it must be known which computing power is made available by which system on chip and which bit rates are required for optimum data exchange.US 2022 / 0 123 849 A1 describes a method for measuring and compensating clock drift errors in time-aware networks and time-critical applications in which a time-aware system measures the clock drift and compensates the measured clock drift. There is a prediction of future clock drift values based on history and other physical measurements.DE 10 2013 224 697 A1 describes a method for establishing a common time base for network subscribers in a network of a motor vehicle, wherein a time master sends out a synchronization message via the network at specific time intervals. The network subscribers correct a respective time base by means of the received synchronization message and thus establish a common time base.DE 10 2011 087 472 A1 describes a method for synchronizing clocks in nodes of a vehicle network of a motor vehicle, which nodes are designed as control units, for example, in which the nodes communicate with one another via a communication protocol that is not synchronized per se, for example a bus system having an Ethernet protocol.Almost all Ethernet communication networks used in vehicles use a protocol for time synchronization which provides a global time base of the network synchronous in all network devices. The degree of spread of time-synchronized network devices will continue to increase in the future. One of the major challenges of these new server ECUs is the dissipation of heat. The high-performance (graphics) processors demand new, extensive cooling concepts, such as water cooling, as are currently scheduled and, in some vehicles, Tesla has already been introduced in series today.The management and diagnosis of the ECUs and their functions will take an even more important role than today in view of the ever more stringent safety requirements. Early detection of faults and critical situations plays an important role in this context. Electronics manufacturers will have to take more responsibility in the automobile delivery industry in the future. They develop and produce increasingly complex innovative assemblies which are passed on as a black box to the vehicle manufacturer in the supply chain. In the present case, the question will remain as to whether the necessary monitoring electronics only recognize genuine component defects or whether vehicle components which function correctly must be replaced, because there is a doubt as to their reliability against the background of functional safety. If, after an analysis has been made in detail, it is found that the exchanged parts function correctly, this nevertheless has effects on the supply chain. With regard to insurance deadlines and future service agreements, however, this question will not ensure the car driver whose vehicle is automatically repaired again and again almost overnight to the greatest satisfaction.In addition, the number of control units and their interconnection continuously increase. In addition to the actual control functions, diagnostic functions have become increasingly important. If the diagnosis originally adopted only one control function for compliance with legal exhaust gas standards, it is nowadays used in the entire value chain of the vehicle manufacturers: in development, in test and validation, in production and finally in customer service. The comfort functions of modern vehicles are also largely based on diagnostic functions.The IEEE 802.1AS standard provides such a protocol for time synchronization. Starting from a so-called "best clock" in the network, also referred to as grandmaster or grandmaster clock, a master-slave clock hierarchy is set up. The grandmaster provides the time base for the network to which all other network devices of the network synchronize themselves. The grandmaster is determined by means of the so-called best master clock algorithm (BMCA) and disclosed within the network. For this purpose, IEEE 802.1AS-capable network devices send Advertisement messages containing information about their internal clock to directly connected further network devices. The information about the internal clocks provides information on the accuracy of the respective clock, its reference or time reference, and other characteristics by which the best clock in the network can be determined. A receiver of such an Announce message compares the received information with the features of its own internal clock and possibly messages already received from another port with information about clocks of other network devices, and accepts a clock located in another network device if this has better clock parameters. After a short time, the best clock in the network is determined, which then becomes the grandmaster in the network. Starting from the grandmaster, messages are broadcast over the network for time synchronization. A network device which receives a message for time synchronization does not easily forward it, but corrects the time information by the previously determined runtime on the connection via which it receives messages for time synchronization from a directly connected network device and by the internal processing duration before it forwards the message for time synchronization with the corrected time information.In the IEEE 802.1AS watch hierarchy and the generalized precision time protocol (gTP) defined therein, only a single network device provides the best clock of the network at any given time. This network device thus controls and regulates the entire time of the vehicle. All other clocks in network devices of the network are exclusively based on this one clock. Some vehicle manufacturers are even synchronizing networks of other standards, for example. CAN, via this Ethernet time master, so that almost all network devices of the vehicle are informed of the system time by the network device providing the grandmaster. As a result, a single network device is defined in the network or the vehicle as a single point of failure, the failure or manipulation of which can have serious effects on the operational safety of the vehicle. For example, in vehicles with a high degree of driver assistance by corresponding systems or with systems for (partial) driving, a plurality of sensor data acquired within a narrow time window must be jointly processed in order to derive corresponding control signals for actuators of the vehicle. For documentation purposes as well, the most accurate possible time acquisition of sensor data can be of great importance, for example when storing in log files, by the analysis of which malfunctions or incorrect operations can be reconstructed. The latter is of great interest in particular for insurances and law enforcement authorities. Therefore, secure synchronized provision of the time information is indispensable.In addition, the number of control units and their interconnection continuously increase. In addition to the actual control functions, diagnostic functions have become increasingly important. If the diagnosis originally adopted only one control function for compliance with legal exhaust gas standards, it is nowadays used in the entire value chain of the vehicle manufacturers: in development, in test and validation, in production and finally in customer service. The comfort functions of modern vehicles are also largely based on diagnostic functions.The management and diagnosis of the ECUs and their functions will take an even more important role than today in view of the ever more stringent safety requirements. Early detection of faults and critical situations plays an important role in this context.Concepts are already being used to dynamically offload functions and applications to other control units / processors in order to optimize them. This is referred to as live migration, translocation, or migration.For Ethernet, there are only firmly defined bit rates, one per decade. Finer granularity exists for only >1Gbit / s. Thus, there are 10 M / s, 100 M / s, 1Gbit / s bit rates. Disadvantages of the fixed bit rates are that the topology and cables and thus the quality, windings, possibly shielding, must fit exactly to this bit rate. The adaptations to EMC and topology (in particular in the case of 10BASE-T1S in bus topology) are complicated or completely not permissible at all. Furthermore, it is necessary to provide problems for the use of additional capacitances for optimizing the EMC. Furthermore, stitch lengths are not permitted in the 10BASE-T 1S bus; a daisy chain architecture is absolutely necessary.The core of the application is that in particular the data protocol 10BASE-T1S does not have to be fixed to the bit rate of 10Bit / s. In contrast, the CAN protocol allows a plurality of different bit rates to be set depending on the bit timing and the quartz used.There are operating conditions, such as during end-of-band flashing, in which higher bit rates would be possible, since, for example, only parts of the temperature range occur, e.g. no -40° C.Some approaches are known in the art for detecting changes in the configuration or structure of a communication network using the time synchronization of the network. An unauthorized change in the configuration of the network can comprise, for example, the intermediate connection of a network device for preparing an attack, which intercepts messages for analysis and, if appropriate, forwards changed messages. This can be used to prevent or at least interfere with safe and proper operation.The new architectures now provide the first time for software to be implemented on different ECUs, since the hardware becomes more generalized and the software becomes more platform-independent. It is therefore not always fixed at the design time of the system on which control device (server) which software will run and which bit rates would be optimal for this purpose.One of the major challenges of the new server ECUs is dissipation of heat. The high-performance (graphics) processors require new, extensive cooling concepts, such as, for example. Water cooling.Implementing cost effective heat dissipation and monitoring of the new server ECUs presents a new challenge to the automotive industry. Precisely these new server ECUs form the core of the network or the only and central control units are in the future in the vehicle-a deactivation in the event of problems is easily hardly possible, since these are used for automated driving, for example. To fuse sensor data and perform highly complex computations, etc.In autonomous driving, the requirements for the reliability of all subsystems are additionally increased once again. In the safeguarding of all subsystems, the extended diagnostic functions in particular play an important role. The complexity which increases ever further requires the replacement of diagnostic data and these must also be delivered reliably and without errors. A challenge of the next few years will be the secure and reliable transmission of status information on the one hand and the redundant provision and transmission of this data on the other hand. For this purpose, new network management concepts will arise which always have an overall overview of the system and in some cases also become active from the cloud.Early detection of faults and critical situations plays an important role in this context. Electronics manufacturers will have to take more responsibility in the automobile delivery industry in the future. They develop and produce increasingly complex innovative assemblies which are passed on as a black box to the vehicle manufacturer in the supply chain. In the functional test, it will be an object whether the necessary monitoring electronics only recognize true component defects or correctly functioning vehicle components have to be replaced, because against the background of functional safety there is doubt as to their reliability. If, after an analysis has been made in detail, it is found that the exchanged parts function correctly, this nevertheless has effects on the supply chain. With regard to insurance deadlines and future service agreements, however, this question will not ensure the car driver whose vehicle is automatically repaired again and again almost overnight to the greatest satisfaction.In addition, the number of control units and their interconnection continuously increase. In addition to the actual control functions, diagnostic functions have become increasingly important. If the diagnosis originally adopted only one control function for compliance with legal exhaust gas standards, it is nowadays used in the entire value chain of the vehicle manufacturers: in development, in test and validation, in production and finally in customer service. The comfort functions of modern vehicles are also largely based on diagnostic functions.Possible overheating of ECUs presents an even greater problem in the future. The early diagnosis by means of a plurality of redundant technologies is necessary in order to meet the future requirements for security and safety. The controller can no longer execute software when it reaches its capacity limits, which are caused by a limited bit rate.US 2016 / 0 285 462 A1 discloses a method for manufacturing an oscillator including a resonator element, an oscillation circuit that outputs an oscillation signal by oscillating the resonator element, a temperature compensation circuit that compensates temperature characteristics of a frequency of the oscillation signal in a desired temperature range, includes a first temperature compensation step in which the frequency is measured at a plurality of temperatures and first temperature compensation data is calculated on the basis of a ratio between temperature and frequency, and a second temperature compensation stage in which, after the first temperature compensation stage, the frequency determined by a temperature compensation by the temperature compensation circuit on the basis of the first temperature compensation data at a plurality of temperatures and the second temperature compensation data is measured on the basis of a ratio between temperature and frequency.WO 2014 / 111 920 A1 discloses a method and a device for use with a host computer that messages communicate with a computer peripheral device via a computer bus, wherein the peripheral device can be in a plurality of states. The peripheral device may be an input or output device or a mass storage device such as a hard disk drive. The device communicates with the host computer and the computer peripheral device via a proprietary industry standard protocol or bus, which may be based on a point-to-point serial communication such as SATA. The peripheral condition is determined by monitoring the messages transmitted over the bus and the sensor associated with peripheral operation. The sensor may be a microphone or a camera and the system may include voice or image processing.The comparison may suggest a malfunction or operation suspected according to a predefined scheme and a signal is generated.The object of the application is to make possible a more rapid and reliable adaptation of the bit rate so that the server ECUs in the computer networks can be operated flexibly.The invention also advantageously solves the problem that each PHY (transceiver) has an external 25 MHz crystal as clock generator, the frequency being specified in the IEEE standard. By changing this clock, other bit rates can be set very easily.The proposed method advantageously proposes a solution which makes the bit rate in a computer network flexible to set, depending on the prevailing requirements for computer network operation.At present, this approach of proposed flexible adaptation of the bit rate is known. The application advantageously proposes that after the determination of the clocks, the bit rate can be changed in a computer network.DESCRIPTIONThis object is achieved by the method specified in claim 1 and the ether on-board power supply system specified in claim 12. Embodiments and further developments are specified in respective dependent claims.The invention message proposes a novel intelligent mechanism for modifying the bit rates of the controllers. The invention uses the Ethernet-based time synchronization protocol to enable adjustments to the bit rate of the nodes, commontees and / or ECUs in the computer network.Ethernet-based time synchronization (will be in use with all high-format ECUs) is realized by the IEEE802.1AS protocol. In this case, in each ECU, a crystal always passes the clock to a PLL, which is then matched by software to the best clock of the network. Quartzes are influenced much more strongly by the ambient temperature than the age - about 2 potencies more.The physical properties of a quartz and its quality are decisive for the accuracy of the time synchronization (e.g. PTP), the basis of which represents the oscillations of the quartz. The temperature has the highest influence on the quartz and its accuracy. The smallest deviations from its specification are a typical quartz at medium room temperature of +25°C. The number of oscillations decreases as the outside temperature decreases and oscillates more rapidly as the outside temperature increases, which heats the quartz.Bit rate matching at 10BASE-T1S is possible and is implementable when applied to chips currently in use. Specifically, a 25 MHz crystal is used for each 10BASE-T 1S node to achieve 10 Mbit / s on the bus. The reason is the DME (Differential Manchester Encoding) methods for clock recovery. At the beginning of each bit there is an edge transition. Depending on "1" or "0", there is a further or no flank change in the middle of the cycle.bits. The 4B5B coding is used to generate 5 bits from 4 bits, since additional control symbols are required for the bus access method. As a result, 10 Mbit user data corresponds to 12.5 Mbaud. 12.5 Mbaud corresponds to 25 MHz clock because of the DME.The specification of IEEE 802.1AS recommends a quartz with a quality no worse than ±100 ppm. AT-cut quartzes are characterized in that their oscillation via the temperature change corresponds to a cubic curve. As a result, the quartz can also operate stably over relatively large temperature ranges in comparison with other quartz types.The clock rate of its Ethernet crystal is determined by means of runtime measurements with the component to be examined and continuously observed (this does not require any further message exchange or protocols) and the ambient temperature can be determined in this ECU on the basis of the change in the clock rate, since this has a direct influence on the crystal.The essential advantages of the invention result from the fact that additional redundant mechanisms are implemented, which do not require additional protocols and which further increases the diagnostic capability of our control units. The time synchronization protocol has very low data consumption and is transmitted at a high frequency anyway. The method provides constant monitoring without additional bus load or new protocols.This method can be implemented in particular in the form of software which can be distributed on the network as an update or upgrade to existing software or firmware by subscribers and thus represents an independent product. The method can be OTA-loaded into already existing and delivered control units which, for example, also do not have a temperature sensor or in which it is defective or no longer operates reliably. Costs could even be saved as a result.By detecting modifications in the network, a further method is provided in order to ensure data security and functional security in the on-board power supply system. If, for example, a modified control device is used, this is obviously not actually aware of the driver or the workshop-but the network and the control devices can identify errors on the basis of the methods described in this invention. By using protocols and existing basic functions in the standard Ethernet TSN or AVB, no modifications are necessary in the protocol sequence. This means that neither the bus load is increased hereby nor are any modifications in hardware or software necessary at the transmitter.The method and the control device resulting therefrom are of particular interest for automotive use, since the issue of reliability and safety over Ethernet has a great significance in the automobile and will become increasingly prominent. In the next few years, the sensors (camera and radar) will also send uncompressed data over Ethernet. With such a data rate, further techniques are necessary to make the Ethernet system more fail-safe and performer. The invention contributes to this to enable these applications.An existing problem today and with any new system is the dependence on and support of the communication interfaces. The invention described herein can be designed much more platform independent and it can thereby achieve an extension of lifecycles of existing SW platforms and controllers.The computer network according to the invention is improved with regard to costs and reliability. The testability of the system is more clearly defined by the invention and hence test costs can be saved. In addition, the invention provides transparent security functionality. A further possible application of the method is in fields in which crystals are used with hardware-based time synchronization and in which the clock rate can be determined remotely.It is particularly advantageous if the initialization of the bit rate modification is carried out in a secure environment in which an attack can be ruled out with sufficiently high probability, for example at the end of a production process by which a product containing the secured network is produced. A one-time initialization can be sufficient above all when the network or its configuration no longer changes after initialization, for example in vehicles of all types.The method according to the invention further comprises the transmission of additional messages for time synchronization by selected network devices which do not provide the previously determined grandmaster clock, wherein the time information transmitted in the additional messages for time synchronization and the clock parameters relevant for a determination of the best clock by means of BMCA and the domain number coincide with or are comparable to those of the previously determined grandmaster clock. However, the additional messages for time synchronization contain a unique clock identification which corresponds to the identification of the respective selected network device. The clock parameters relevant for carrying out the BMCA include, in particular, the values for the variables priority1, priority2, clockTimes, clockAcc, offsetScaledLogVariance, and timeTime according to the IEEE 802.1AS standard. Each of the additional messages for time synchronization sent by the selected network devices therefore appears to originate from a grandmaster clock for each who listens to the network traffic, just like the messages for time synchronization of the grandmaster clock determined during the initialization, so that a multiplicity of grandmaster clocks exist in the network for the observer.The selected network devices transmit their additional messages for time synchronization preferably in cycles which correspond to those of the grandmaster clock determined during the initialization. Each of the selected network devices thus represents a kind of pseudo grandmaster clock which behaves as if it were the only and also the best clock of the network. The pseudo grandmaster clock cannot be distinguished from the grandmaster clock determined during initialization for an outsider despite the time synchronization trees differing with respect to the propagation of the messages for time synchronization within the network, since the additional messages for time synchronization are transmitted with the same domain number.The transmission of the additional messages for time synchronization by the selected network devices can begin as soon as the unique clock identification of the grandmaster clock determined during the initialization has been transmitted to all network devices. However, it is also possible to start the transmission of the additional messages for time synchronization only when a first time synchronization of all network devices of the network is complete.Each of the additional messages for time synchronization is forwarded by all network devices in the same way in accordance with the standard as the messages for time synchronization sent by the grandmaster clock determined during the initialization. That is, after correction of the time information by the delay time on the reception link and the internal processing time, a message for time synchronization is sent to other directly connected network devices.The network devices are connected to each other via physical interfaces. Messages for time synchronization are sent via logical ports defined for the interface, so that point-to-point connections for time synchronization exist even in the case of shared physical transmission media between two network devices. In the present specification, the term interface is used to refer to the term port unless the context dictates otherwise.Identification of the grandmaster clock determined during initialization is considerably more difficult or even impossible for an observer who only begins to listen to the network traffic after completion of the initialization by the method according to the invention.The selection of network devices which, in addition to the grandmaster clock, send their own messages for time synchronization and thereby output as grandmaster clock can comprise a check as to whether a network device is indispensable for the operation of the network or of a system containing the network and therefore should not serve as bait for a possible attack. Indispensable network devices are, for example, those which connect a plurality of network segments to one another, such as, for example, a switch, a bridge, or on which functions are implemented which cannot be taken over by other network devices, such as, for example, a domain computer for automated or autonomous driving or other safety-relevant functions. Such network devices are preferably not selected. During the selection, it can also be checked whether a network device is set up for executing generic functions or software, which can also be executed by another network device within the network and can be correspondingly moved to one of these other network devices if necessary, for example in the event of a detected attack on a network device. Such network devices can preferably be selected for the transmission of their own messages for time synchronization, just like network devices which are located at the edge of the network and / or provide functions which are not relevant to safety and whose isolation from the rest of the network would not lead to major functional disturbances in the case of a detected attack. The same applies to network devices to which only a few further network devices are connected, for example. Network devices with only one port and correspondingly only one neighbor, and which can thereby be isolated more easily. The selection of network devices for sending own messages for time synchronization can also preferably make network devices which are provided with particularly strong security mechanisms and can therefore better resist attacks. In a simple case, selecting network devices for sending own messages for time synchronization may include reading a flag that was set upon production or configuration of the network device for operation in the network. Other features for determining whether a network device can be configured to send additional messages for time synchronization may be determined by corresponding function queries.The method according to the invention also comprises, in network devices which do not provide the grandmaster clock determined during the initialization, the reception of messages for time synchronization at a first network interface and a check as to whether the clock identification transmitted in the message for time synchronization matches the stored clock identification of the grandmaster clock determined during the initialization. If the clock identifications match, a local clock is synchronized using the time information received in the message for time synchronization.A further development of the method according to the invention comprises monitoring the time information transmitted in additional messages for time synchronization for a deviation from the time information transmitted in messages for time synchronization with the clock identification of the grandmaster clock determined during the initialization. As long as a network device is synchronized with the grandmaster clock determined during the initialization, the time information on which the comparison is based can also be provided by the clock of the network device. If a deviation of the time information has been detected, additional messages for time synchronization with the associated clock identification can be blocked, i.e. not forwarded into the network for which a deviation has been detected. Should the deviation result from an attack on the network device, an attacker monitoring the network only at one location will not notice the blocking because messages for time synchronization are not acknowledged by a receiver. Alternatively, the deviating time information transmitted in the received additional message for time synchronization can be corrected and forwarded on the basis of the time information received from the grandmaster clock determined during the initialization. The basis for the time correction can also be the local clock synchronized with the grandmaster clock ascertained during the initialization. Alternatively or additionally, a corresponding message can be sent to a predefined network device of the network, which is configured to initiate and / or control suitable protective measures. Suitable protective measures can comprise, for example, isolating that network device or individual streams or messages of that network device from the rest of the network which sends the deviating time information, or restarting the relevant network device.One embodiment of the method according to the invention comprises the sporadic or cyclical transmission of messages for time synchronization by the grandmaster clock ascertained during the initialization, in which the time information differs from the actual time, and the monitoring of the additional messages for time synchronization transmitted by the other network devices for whether these correspondingly reflect the differing time information. If this is not the case-unavoidable tolerances during the synchronization can be ignored in this case-a malfunction or an attack may be present, and the network device which provides the grandmaster clock ascertained during the initialization can send a corresponding message to a previously defined network device of the network which is configured to initiate and / or control suitable protective measures, for example the network device which does not reflect the changes in the deviating time information, is isolated from the rest of the network. If the additional messages for time synchronization sent by the other network devices reflect the changed time information, it can be assumed that all pseudo grandmaster clocks behave in a rule-compliant manner.A computer program product according to the invention contains instructions which, when executed by a computer, cause the computer to execute one or more embodiments and further developments of the method described above.The invention message additionally also proposes a novel intelligent mechanism for monitoring the temperature change or the heat development of the control units. The method uses the Ethernet-based time synchronization protocol to detect changes in the ECU temperature.The Ethernet-based time synchronization is implemented in use in all high-format ECUs by the IEEE802.1AS protocol. In this case, in each ECU, a crystal always passes the clock to a PLL, which is then matched by software to the best clock of the network.The physical properties of a quartz and its quality are decisive for the accuracy of the time synchronization (e.g. PTP), the basis of which represents the oscillations of the quartz. The temperature has the highest influence on the quartz and its accuracy.The clock rate of its Ethernet crystal is determined by means of runtime measurements with the component to be examined and continuously observed (this does not require any further message exchange or protocols) and the ambient temperature can be determined in this ECU on the basis of the change in the clock rate, since this has a direct influence on the crystal.The controller that implemented the time master functionality must service certain interrupts and also keep resources free for them. However, the invention message allows almost any controller to be used, which in turn reduces the system costs or resources.The effect of the flexible adaptation of the bit rate provided by the method can additionally be recognized as being protected against unauthorized intervention of the time synchronization, corruption of the communication and against the exchange of devices. In addition, applications with an even higher level of security can also be achieved in this way, for example by using hardware encryption (or authentication). The method makes it possible to offer protection mechanisms more favorably, helpful to service requirements for ISO26262, and also reduces the system costs. The method could even be subsequently introduced by OTA.In the vehicle, on the other hand, it is generally not economical to send all subscribers connected to the network sufficient hardware equipment for a continuous, encrypted communication. The method described presupposes significantly lower hardware resources and can be implemented with existing implementations and thus significantly increases the safety level without this necessarily being linked to higher production costs for the computer network or devices connected thereto.This method can be implemented in particular in the form of software which can be distributed on the network as an update or upgrade to existing software or firmware by subscribers and thus represents an independent product.Advantageously, the quality of execution of software-based applications (e.g. automated driving) can be increased by the invention, in particular without additional financial expenditure. With the use of the newly introduced Ethernet protocol in automobiles, mechanisms are required that make use of simple techniques and given characteristics of technologies in order to be able to dispense with expensive implementations and further additional hardware. The network system according to the invention is improved in terms of cost and reliability. This allows software-based methods to retrieve the best from its ECU or network and offer more functionality to the customer.Advantageously, the security of a vehicle network can be increased significantly and very simply by the invention, in particular without additional financial expenditure. With the use of the newly introduced Ethernet protocol in automobiles, mechanisms are required that make use of simple techniques and given characteristics of technologies in order to be able to dispense with expensive implementations and further additional hardware. By more early detection of attacks and malfunction by means of the early analysis of the communication paths, gaps and errors can be detected before the delivery of the vehicle. The network system according to the invention is improved in terms of cost and reliability. The testability of the system is more clearly defined by the invention and hence test costs can be saved. In addition, the invention provides transparent security functionality.Today, applications are implemented, tailored and adapted to a vehicle type. With this presented method, the software can be designed more flexibly and multi-value services can be generated from the underlying system without having to have it previously programmed permanently into the software. We must actually originate from the worst case today, which costs resources (money) and loses quality. The invention allows software developers and architects to offer a software / application that can be more flexible and more precisely tailored to the requirements of the application. By incorporating the aforementioned methods in software, optimization can be carried out within the control unit. This means that the platform and vehicle type software can be designed more independently.The new technologies can no longer be held up in the automobile. Protocols such as IP, AVB and TSN have several thousand pages of specifications and test suites. The controllability of these new protocols in the automobile is not directly given.The new method can be integrated into an existing network without causing damage to existing devices. The standard is not violated because the existing protocol can be used.The method would also be applicable to other communication systems with clock synchronization components and embedded systems.The computer program product can be stored on a computer-readable medium or data carrier. The data carrier can be physically embodied, for example as a hard disk, CD, DVD, flash memory or the like, but the data carrier or the medium can also comprise a modulated electrical, electromagnetic or optical signal which can be received from a computer by means of a corresponding receiver and can be stored in the memory of the computer.A network device according to at least one embodiment of the invention comprises at least one physical communication interface in addition to a microprocessor and nonvolatile and volatile memory and a timer. The components of the network device are communicatively interconnected by one or more data lines or buses. The memory of the network device contains computer program instructions which, when executed by the microprocessor, configure the network device to implement one or more embodiments of the method described above.The present invention can advantageously protect the grandmaster, since its track which has hitherto been easily found is obscured or obscured by a multiplicity of incorrect tracks, and the position of the grandmaster within the network is therefore more difficult for attackers to determine. The attacker can then no longer grasp at all or he requires at least considerably more time. Attacks that do not accidentally affect the grandmaster immediately can be detected and appropriate defenses can be taken while the system continues to remain synchronized with the required accuracy and operates at a set bit rate.The method according to the invention can be implemented with existing network devices, wherein possibly only adaptations in the software or the state machines used for receiving and processing messages for time synchronization are required in order to use only the messages for time synchronization coming from the grandmaster clock determined during the initialization for the synchronization of the clocks, but nevertheless to forward the additional messages for time synchronization and not simply to delete them. This results in little, if any, additional costs for the reaction. Existing systems can also be set up by appropriately modified software to implement the method. A further advantage of the method according to the invention is that the respective underlying hardware platform is of no significance as long as they support synchronization according to the IEEE 802.1AS standard.DESCRIPTION OF EMBODIMENTSThe motor vehicle has an Ethernet on-board power supply system. According to the exemplary embodiment, the Ethernet on-board power supply system in turn has a plurality of control units, which can also be referred to as control devices or control units. The control units are connected to one another by connecting paths. Due to the existing topology of the Ethernet on-board power supply system 2 in the exemplary embodiment, there are a plurality of parallel communication paths between the control units. The connecting paths can be formed, for example, from different media types or materials.As the number of Ethernet variants increases, for example, the dynamic change of the connection speed will also be used. This means, for example, that the speed can be changed at runtime. For example, a 10Gbit / s connection path may be changed to 100 M / s to save power. Since this is a dynamic function, it may be that the on-board power supply system, after delivery or after initial assembly in the motor vehicle, is designed differently than, for example, after a software update or in a faulty situation.The Ethernet on-board power supply system has an at least first control unit or a first node, a second control unit or a second node and additionally a third control unit or a third node. The first control unit is connected to the second control unit through a first connection path. Further, the first control unit according to the embodiment is also connected to the second control unit through a second connection path.The first control unit, the second control unit and / or the third control unit can be designed, for example, as a control device or a network switch. The second control unit and the third control unit are connected to each other by a third connection path.According to an embodiment, the first control unit and the second control unit are directly connected to each other via the first connection path, while the first control unit and the second control unit are only indirectly connected to the second connection path, since the second connection path is divided into two parts by another control unit. According to another exemplary embodiment, the second connecting path can connect the first control unit and the second control unit, but also directly to one another. Generally speaking, the method is also suitable for detecting errors in the synchronization.It is possible to calculate or establish the duration of the asynchrony or when the time and when the last time was correctly synchronized. Based on an existing synchronization, the method proposes to determine the imprecision of the clocks in the network, e.g., the "my" neighbor ECU or the "neighbor" CPU, may be within the same ECU. On the basis of these determined data, it is possible to calculate, by means of a time stamp of this component, in conjunction with "my" own clock or that of the grandmaster and of the synchronization interval, how much time has elapsed since the last synchronization. It can thus be determined when the last successful synchronization has taken place. At a time, which is also called the ascertainment time, a time stamp of an ECU of a control device is recorded, from which it is desired to know whether it is still synchronous. On the basis of a series of parameters, it is then determined how many synchronization intervals or since which point in time this component was no longer successfully synchronized.Thus, the method determines when the last successful synchronization of a node has occurred and thus also how long the node has not been synchronized any longer. This is the basis for deciding whether or not the sensor data is trusted and thus usable.After the arrival of synchronization messages, the internal clock or the offset is adjusted. After that, the clock again continues with its own characteristic until the next synchronization.The method is distinguished in that the node, or a μC or switch, or the entire ECU or the control unit is interrogated at the time thereof or is read out by means of a time stamp. This value is stored. The method then determines the frequency drift of the timer and the frequency of the timer using the 802.1AS protocol (Delay Inquiry). Thus, cyclic messages, which are actually used for the runtime measurement and are in any case transmitted, are used to calculate the speed at which the clock generator of this ECU / μC or of the entire ECU or of a control unit is operating.A known procedure is used for the time of flight measurement. A port, the initiator, starts the measurement by sending a Delay_Re message to the port connected to it, the responder, and generating an output time stamp t1. This output time stamp denotes a hardware time stamp which is written as late as possible when leaving the Ethernet transceiver. The responder generates a time stamp t2when this packet arrives. In response, the responder sends a Delay_Response message. In this message, it transmits the reception time stamp t2 of the Delay_Re message. If this message leaves the responder, it in turn generates a time stamp t3, which is sent in a immediately following Delay_Response_Fol-Up message. Upon receipt of the Delay_Response message at the initiator, it generates a time stamp t4. The initiator can calculate the average runtime of the distances traveled from the four time stamps t1 to t4.PTP defines a master / slave clock hierarchy with a best clock within a network. From this clock, the grandmaster, the time base of the nodes located in this network is derived. The best master clock algorithm (BMCA) is used to determine this type of clock and to inform it of this information in the network. IEEE 802.1AS-enabled systems cyclically send Announce messages to their neighbor nodes with best cloud clock information. The recipient of such a message compares this information with the features of his clock and the messages possibly already received from another port. Based on these messages, a time synchronization spanning tree is established. Each port is assigned one of four port states in this context. The master port state is given by the port that has a shorter path to the grandmaster than its link partner. The slave state is then assigned if no other port has this state at this node. Disabled selects the port that cannot fully support the PTP protocol. The passive state is selected if none of the other three states are true.The exchange of the time information is finally performed by the Sync_Fol_Up mechanism. The master ports cyclically transmit sync and follow_up messages to the adjacent link partner. When the sync message leaves the master port, a time stamp is generated, which is transmitted immediately in a subsequent follow_up message. This time stamp corresponds to the current time of the grandmaster at the transmission time of the sync message. The messages originating from the grandmaster are not forwarded, but rather are re-created in each node, including the switches.The speed of the clock generator can be determined or calculated by the PTP NRR method (neighbor rate ratio). In this case, cyclical PDelay messages are used to calculate the speed (offset) of the clock generator relative to the reference clock. The read or retrieved time (Tverdant) is associated with the current system time (Trreference), thus the time that is trusted, either the grandmaster or the time for which the data is important. If the component to be examined is a sensor, then the sensor fusion time could be used as a reference. This means that the difference between the two times is determined for the first time.With the aid of the synchronization frequency, it is possible to first calculate how large Tble is supposed to be at a maximum: in the case of Ethernet, the interface between PHY (transceiver) and MAC is the decisive interface for receiving the time information. This interface (xMII) is clocked at a nominal frequency f of 25 MHz. Crystals for automotive Ethernet AVB / TSN-capable implementations must not exceed a maximum imprecision foof ±100 ppm. Thus, the worst possible quartz in conjunction with the interface causes a deviation in the frequency of 5 kHz from the nominal frequency f according to the formula:The change in the period between the maximum (25002500 Hz) and the minimum (24997500 Hz) frequency is 8 ps at a 40 ns period. This means that two crystals (and thus two ECUs) can have a maximum time difference of 8 ps at +25° C. with respect to one another in 40 ns. Exactly 3125000 periods a 40 ns are possible in the standard synchronization interval of 125 ms, which corresponds to a maximum deviation of 25 μs.The synchronization interval can be between 31.25 ms and 32 seconds according to the specification of IEEE802.1AS. In the case of the smallest interval, this means a worst case deviation of 6.25 μs and in the case of the largest interval of 6.4 ms.By means of the preceding formula, it is possible, by ascertaining the speed of the clock generator and knowing the synchronization interval Tbias, to calculate by the method when the last synchronization has taken place.In one exemplary embodiment of the Ethernet on-board power supply system, a first control unit, a second control unit and a third control unit. Furthermore, the Ethernet on-board power supply system also has the first connection path, the second connection path and the third connection path. According to the exemplary embodiment, a propagation time of a first signal on the first connection path is determined. The propagation time describes how long the first signal travels from the first control unit to the second control unit via the first connecting path or vice versa. Based on the propagation time of the first signal, a maximum speed of the first connection path is determined. The maximum speed of the first connecting path varies, for example, depending on the length of the cable, the speed of the transmission and / or the type of medium or the type of transmission medium. Based on the maximum speed, a type of a transmission medium of the first connection path is determined.According to this embodiment, the type of the transmission medium is determined to be optical, copper, or wireless. In the case of optical, the first connecting path is designed, for example, as a glass fiber connection. In the case of copper, the first connecting path is formed, for example, by cables with twisted pairs of wires, for example a cable with twisted pairs of wires without a screen (UTP). In the case of wireless, the first connection path is substantially designed as a radio link, and the first control unit and / or the second control unit have or are connected to a radio receiver and / or radio transmitter.The control unit determines a runtime for the data transmission via the on-board network to a fourth control unit; it is important that the determination of the runtime is carried out in some form on the basis of an actual physical condition of the transmission path from the first control unit to the fourth control unit, i.e. that there is a physical condition or property of the transmission path, the change of which leads to a change in the determined runtime.In this case, the one third control unit determines a runtime for the data transmission via the network to the fourth control unit. This can be done in an alternative manner. For example, the runtime can be carried out in the course of a time synchronization between the first subscriber and the second subscriber, for example according to the IEEE 802.1AS time synchronization standard and the PTP protocol contained therein. Thus, for example, the "Delay Request" and "Peer Delay" messages implemented within the scope of this protocol can be used as data packets. However, the method is not limited thereto. It is only important that the determination of the transmission time is carried out in some form on the basis of an actual physical condition of the transmission path from the first subscriber / the first control unit to the second subscriber / to the second control unit, i.e. that there is a physical condition or property of the transmission path, the change of which leads to a change of the determined transmission time.Furthermore, the first control unit determines the message frequency, which is derived in principle from the speed of the PLL and quartz, of the opposite fourth control unit. From these two values, which change constantly due to temperature, aging, etc., the third control unit derives a key for encrypting these time messages.The time synchronization messages are encrypted with the generated dynamic key, which can be derived from individual parameters to the connection partner in general terms.The type of transmission medium is communicated to a program in the Ethernet on-board power supply system. The program can be present, for example, in the first control unit, the second control unit or the third control unit or a further control unit of the Ethernet on-board power supply system. Depending on the type of transmission medium, a call routing is adjusted. For example, the program may send data over a different connection path than before the connection path selection by way of the connection path selection. However, the program can also interrupt the transmission of data by the connection path selection and resume it at a later point in time.According to the embodiment, a transmission security value is assigned to the first connection path based on the type of the transmission medium. The transmission security value describes a loss probability of data transmitted via the connection path. The transmission safety value thus permits a statement as to how reliably the data can be transmitted via the first connection path. This is supplied to the entropy source. If, for example, a safety limit value is undershot and the data can be transmitted only in an uncertain manner, it is to be expected that the data reach its destination in a delayed manner or else do not reach its destination at all if retransmission is not worthwhile on account of the required upduality of the data.According to a further embodiment, propagation times of a plurality of signals on the first connection path are determined and the fastest propagation time of the plurality of signals is selected. The maximum speed of the first connecting path is then determined on the basis of the fastest running time.A control unit starts the delay measurement and waits for messages to be received by the link partners. Based on the receipt of the messages using the example PTP, the line delay may be measured. If one link partner starts the delay measurement, then this is necessarily taken along by the other link partner and is likewise intended to start a measurement, so that these two measurements can also generate a related measured value, Analogously to the procedure described above, the type of transmission medium for the second connection path and / or the third connection path can also be determined.The respective values recorded are different, remain secret and stored in the control device, and are also not transmitted via the network. Finding out the key by merely probing is sufficiently unlikely. Taking the two values into account, an individual key is generated. On the one hand, the frequency of each crystal is different and, on the other hand, the line delay of each link is different. Here, two varying values are added and give a third value, which is even more difficult to guess, the value of the key. The line delay may typically be in the range of 50-500 nanoseconds and the frequency is a parameter and is given in + / - ppm. The forward and backward line delay is based on the same channel, and therefore the calculated values on both sides of the link are the same. The parameters therefore do not have to be exchanged. Thus, both partners have the same values for generating the key almost at the same time. One link partner encrypts using these two values resulting from the last measurement and the other link partner decrypts using its last values.Thus, it is also provided that a propagation time of a second signal is determined on the second connection path. A maximum speed of the second connecting path is then determined on the basis of the propagation time of the second signal. On the basis of the maximum speed of the second connecting path, in turn, a type of the transmission medium of the second connecting path is determined.It is advantageous to use the current key A1 as long as no new line measurement is being performed. Thus, the link partner always knows which key to use if no new line measurement was previously initiated. A new key is / can be generated either cyclically, e.g. predetermined frequency and thus bit rate, started as required by a trigger or always directly before sending important messages.Both the first control unit and the second control unit and also the third control unit can be operated in a normal operating mode or in an energy saving mode. In the energy saving mode, the respective control unit consumes less energy than in the normal operating mode. For example, in the energy saving mode, the speed of a port of the respective control unit can be reduced compared to the speed in the normal operating mode. The reduced speed of the port then also has an effect on the respective maximum speed of the respective connection path.According to a further exemplary embodiment, a service message can be sent from the first control unit to the third control unit. The service message then initiates the determination of a propagation time of a third signal. The third signal is transmitted between the second control unit and the third control unit. The propagation time of the third signal is determined by the third control unit according to the exemplary embodiment.The running time can be determined as follows. In a step, the propagation time of the first signal is determined. In a step, the type of the transmission medium is determined. In a step, the program is finally adapted. In a step, the propagation time of the first signal is determined. As a result, the type of the transmission medium can be determined in one step. The type of transmission medium may in turn comprise the following parameters: speed, medium, cable length, power transmission, bit error rate, bit rate. In a step, the adaptation of the program and the connection path selection then finally follow.According to this example, it is proposed to measure the transit time of the signals between connected control units or controllers. Methods of the IEEE 1588 or IEEE 802.1AS standard can be used, for example, to measure the runtimes. Methods can also be provided, for example, by TTEth (time-triggered ethernet) in order to determine the respective runtime.The program, which is executed in particular on at least one control unit, preferably first determines locally the time of day or the times of day if more than one control unit is directly connected. Thereafter, other control units are preferably queried via a service-oriented method, for example SOME / IP (scalable service-oriented middleware over IP), the runtime of which to the neighbor. This can be implemented either centrally or decentrally. The query can be carried out either once, at system start-up, definition or after software updates, or else can be carried out cyclically in order to detect dynamic changes. This data is then stored and allocated for the first time, in particular including the addresses of the control units. In one step, the respective runtime to the directly connected control units is determined. In one step, the respective runtimes of other connection paths are queried. In one step, the respective runtimes and their associated connection partners are stored.For example, if the current temperature is very high or poor cables are used, then prestored values may be too inaccurate. It is therefore proposed that the application or the program itself performs measurements on its own control unit, in particular with knowledge of its own parameters and other speeds, which can then be derived and calculated therefrom. In one step, one analysis is performed per local Ethernet port. In a step, it is queried whether channel parameters are known. If this is not the case, a step follows and the method is ended. If this is the case, a step follows in which the respective runtime is determined. In one step, the storage is performed and the determined runtime is set in relation to the channel parameters. In a step, a reference value list is created.A possible optimization by knowing the type of the transmission medium takes place in a step in which it is decided whether the type of the transmission medium is copper. If this is the case, a step follows in which it is confirmed that PoDL (Power over Data Lines), i.e. the supply of power via Ethernet, is possible. If it is decided in the step that the medium is not copper, a further step follows in which it is checked whether the type of the transmission medium is optical. If this is the case, a further step follows, in which it is determined that this results in a lower bit error rate and thus in a higher reliability of this connection path. In a further step, the possibility is given of deactivating RX (receiving unit) or TX (transmitting unit) of the control unit if this is not required.If it is decided that the medium or the type of transmission medium is not optical, it is assumed in a step that the respective connection path is designed as the relevant connection path as a direct MII connection (Media Independent Interface). In this case, the respective control unit is suitable, for example, for IEEE 802.1 CB (Frame Replication and Elimination for Redundancy).Further possibilities result from the knowledge about the transmission speed. Combined with the current data streams, data can be transmitted, for example, in a targeted manner via a high-band connection and thus other connection paths that are not required are deactivated, as a result of which energy can be saved.In addition, high-band connections have the possibility of using redundancy mechanisms (e.g. IEEE 802.1CB). Since the data are transmitted continuously redundantly in this case, a high bandwidth is necessary for this purpose. An adaptation of the application depending on the speed of the transmission path is also conceivable. A camera can, for example, adapt the resolution of the image data to be transmitted depending on the speed of the link or the connecting path.In addition to a microprocessor, the control unit 3 comprises a volatile and nonvolatile memory, two communication interfaces, and a synchronizable and modifiable timer or clock generator. The elements of the network device are communicatively interconnected via one or more data links or buses. The non-volatile memory contains program instructions which, when executed by the microprocessor, implement at least one embodiment of the method according to the invention and form the entropy source in the volatile and / or non-volatile memory, from which the dynamic keys for the connection paths are then formed.An assessment of the use of received data based on the last successful synchronization may be performed. This sequence makes it possible to determine whether the checked data which are located before storage are also suitable for the respective use. This is particularly advantageous if the storage takes place on a data recorder. For the data recorder, it is of decisive interest whether the data are also contentally correct. In the event of an accident, it is important whether or not, for example, the camera has detected the pedestrian. If wrong data is recorded or data with a wrong time, then the recording is invalid and cannot be recognized as such without the method.The querying component analyzes a data stream and its sender. Based on the method, it may be determined when the data was last trusted. The nominal limit values here determine either the functions, the system manufacturers or the application as such. This can be different per ECU and per application. On the basis of this limit value, the data can be classified as valid, invalid or also not trusted.A retroactive erasure of data takes place when the synchronization time is above the limit value. The method is also used, for example, when already stored data are present (or shortly before storage), such as in the case of the application data recorders. It is of decisive interest for the data recorder whether the data are also contentally correct-in the case of an accident it is important whether or not, for example, the camera has detected the pedestrian. If wrong data is recorded or data with a wrong time, then the recording is invalid. The querying component analyzes a data stream and its sender. Based on the method, it may be determined when the data was last trusted. The nominal limit values here determine either the functions, the system manufacturers or the application itself. This can be different per ECU and per application. On the basis of this limit value, the data can be classified as valid, invalid or also not trusted.The querying component can be a data recorder, a cloud memory, which wants to verify an order for examining a stored data set of a component, such as a sensor data stream. For this purpose, for example, the address, stream, time stamp can be checked. For this purpose, successful synchronization is last checked, and a determination is made of the time at which data were last valid. The memory is checked and incorrect-synchronous data sets are discarded.The crystal used in crystal oscillator circuits are usually crystal plates, rods or forks (such as a tuning fork) which can be brought by electric voltage to mechanical changes in shape, which in turn generate an electric voltage. The response is given by the mechanical vibration modes of the piezoelectric crystal.A quartz oscillator is excited to particularly strong resonant oscillations at an alternating voltage of a specific frequency, its resonant frequency (this property also includes piezoelectric transducers). It is almost independent of ambient influences such as temperature or amplitude with a suitable crystal section and is therefore used as a precise clock generator with a long-term stability of better than 0.0001%.Oscillating quartz plates have two electrically distinguishable electrical / mechanical modes:In series resonance, their apparent resistance to alternating current is particularly low and they behave like a series circuit of a coil and a capacitor.In parallel resonance, the apparent resistance is particularly large. Then they behave like a parallel connection of capacitor and coil with the peculiarity that no direct current can flow (quartz is a very good insulator).The parallel resonance is about 0.1% higher than the series resonance. A comparable oscillation behavior can also be found at the triple, five times, etc. fundamental frequency. A quartz with a resonant frequency of 9 MHz can thus also be caused to oscillate to 27 MHz or to 45 MHz. Harmonic quarters suitable especially for this purpose have a corresponding suspension in order not to impede these harmonics.The operating point of the quartz oscillator lies between the above-mentioned self-resonances. In this frequency range, the oscillating crystal behaves inductively like a coil. Along with its nominal capacitive load, the crystal oscillator oscillates at its nominal load resonant frequency. Slight deviations from the nominal frequency can be generated or compensated by a change / deviation from the nominal load capacitance.The frequency is easily temperature dependent, as already mentioned. For greater demands on the temperature response, there are temperature compensated crystal oscillators (TCXO). Thermistors are usually used which generate a control voltage which counteract the temperature-dependent frequency change of the quartz, as shown in FIG. 1.1b. The voltage thus generated is usually applied to a capacitance diode, so that the capacitance thus changed corrects the frequency of the crystal oscillator.If an even higher accuracy is required, a quartz furnace is used. The quartz is installed in a temperature-controlled housing in order to minimize ambient temperature-dependent influences. The quartz is then electrically heated to, for example, 70° C. This design is called an OCXO (Oven Controlled Crystal Oscillator). The "X" represents Xtal, the short form of crystal.AT crystals are used for Ethernet in the automotive sector.As already explained, the frequency is easily temperature-dependent. The invention takes advantage of this property of the crystals to derive therefrom the possible bit rate adaptation. Temperature changes have a direct effect on the quartz and thus on the uncontrolled PLL of the Ethernet transceiver. This in turn has effects on the generation of the clocks for sending the cyclical PTP messages. In the automotive sector, an AT-cut quartz is always used for Ethernet, since they have very good temperature stability. The temperature influence also always has a calculable effect.The system model of the time synchronization of Ethernet has influences on the quartz and thus on the uncontrolled PLL of the Ethernet transceiver. This in turn has effects on the generation of the clocks for sending the cyclical PTP messages. In vehicle technology, an AT-cut quartz is always used for Ethernet, since they have very good temperature stability. The temperature influence also always has calculable effects.The method starts at point t and starts with the start of the runtime measurement. In this case, a PDelay_Re message is sent to the ECU via the network week. This ECU responds with a PDelay_Response and a PDelay_Response_FolUP message. With the aid of these messages and their arrival time (hardware time stamp), the NRR is calculated-i.e. the frequency offset at its own clock, i.e. the frequency offset between the two clock generators can be measured.By means of the transit time measurement (measurement of the delay between nodes (cable+ PHY)), the neighbor rate ratio can additionally be determined. The NRR measures the frequency offset between two clocks (two PHYs or ECUs crystals). For example, it is thereby determined how great the difference in ppm is. This is possible because Ethernet uses hardware rather than software timestamps.NRR=1 would mean that both crystals / PLLs run exactly the same speed (hardly possible due to manufacturing tolerances... ). NRR=0.99998 would mean that the quartz would run at a slower speed of 20 ppm.The method continuously determines the clock rate of the quartz by measuring the transit time between the components, which also functions within an ECU via the PCB. These data are logged and compared to already recorded values. If the deviation changes (always taking into account its own local clock / clock), it can only be determined once whether a temperature rise or drop is the basis. (Aging also has an effect on the clock, but it is very slow acting and has no effect at all on measurements made sequentially). If a reference measurement is present, that is, if it can be determined or assigned how fast or slow the clock is to a given temperature, then the temperature can also be derived directly. On the basis of this temperature, it is possible to react, for example, with an error (feedback, error code... ) or else with adaptation of the synchronization.The component wishing to acquire knowledge of the bit rate may be a network manager of a central ECU, which may be a network manager, for example. Software moves or searches free resources. On the basis of the temperature obtained (temperature change), the unit can decide to offload software or also to move software to it.On the basis of the available resources of the server components, the method can be used to move software to the components that are not just before the collapse and thus could get in an unstable state.By means of the method described, functions and applications can be (dynamically) swapped out to other control units / processors, that is to say also in order to optimize them. This is referred to as live migration, translocation, or migration.The approach described here only provides ways to implement software on different ECUs as the hardware becomes more generalized and the software becomes more platform independent. It is therefore not always fixed at the design time of the system on which control device (server) which software will run.The component wishing to know the bit rate may be a network manager of a central ECU, which may be a network manager. Software moves or searches free resources. On the basis of the obtained bit rate or change of the bit rate, which can be determined via the network, the unit can offload distinct software or also move software thereto. Based on the available resources of the server components and adaptation of the bit rates, the method can be used to offload software to the components that are not just before the collapse, thereby achieving a higher overall stability of the overall network. Furthermore, the use of the method can be used in the decision for moving software / resources. The grandmaster's address is included in the synchronization messages.10BASE-T1S supports a transmission rate of 10 megabits per second (Mbit / s) over twisted pair cables with a maximum length of 25 meters at 8 nodes. It uses baseband signals and twisted pair cables that are terminated with RJ45 plug connectors and are used in non-automotive applications. Commonly, these non-automotive applications use unshielded Category 3, 4 or 5 twisted pair cables terminated with RJ45 connectors. Patch panels organize the cabling and patch cables connect the ports to the central hub. While most modern devices support higher speeds such as 100BASE-TX or gigabit Ethernet, 10BASE-T 1S devices may not be compatible with devices designed for 10 / 100 operation. When a 10BASE-T device is connected to a 10 / 100 switch, only that device's port is running at 10 Mbit / s, potentially affecting the overall speed of the network. Cable quality affects noise suppression and signal interference, which affects network performance effects: if a slower 10BASE-T device is introduced into a network running predominantly at higher speeds, such as 100BASE-T or faster, this may potentially slow the connected port down to 10 Mbit / s. This deceleration occurs because the device is operating at maximum speed, which affects the overall performance of the network. 10BASE-T is an Ethernet standard that supports transmission of 10 Mbit / s over twisted pair cables. While modern networks operate primarily at higher speeds such as gigabit Ethernet, compatibility problems may occur when legacy 10BASE-T devices are connected to faster network components, potentially impacting the overall speed of the network.Differential Manchester Coding (DM) is a line code used in digital frequency modulation in which data and clock signals are combined into a single two-stage, self-synchronizing data stream. In this coding scheme, each data bit is represented by the presence or absence of a signal level transition in the middle of the bit period, followed by a obligatory level transition at the beginning. In contrast to Manchester encoding, differential Manchester encoding does not depend on the polarity of the signal transitions, but on the presence or absence of transitions to indicate logical values. This method ensures robust clock recovery because it guarantees at least one transition per bit, which is helpful in noisy environments where detecting transitions is less prone to errors than comparing signal levels to a threshold. Moreover, differential Manchester encoding offers advantages such as insensitivity to signal inversions, reduced required transmit power due to zero DC bias, and minimized electromagnetic noise production. It is specified in standards such as IEEE 802.5 for token ring LANs and finds applications in various fields including magnetic and optical storage, AES3, S / PDIF, USB PD and more. If a 30 MHz quartz is present, 12 Mbit / s are possible on the bus. If a 30 MHz quartz is present, 8 Mbit / s are possible on the bus. If a 30 MHz quartz is present, 6 Mbit / s are possible on the bus. If a 30 MHz quartz is present, 4 Mbit / s are possible on the bus. Analogously, for any other bit rate on the quartz bus, the frequency must be 2.5 times. Generally speaking, quartz here stands for the clock generator, which can also be replaced by PLLs, resonators or other implementations depending on the requirement for precision.Using an example with a LIN (Local Interconnect Network) transceiver, which has been developed as an interface between a LIN protocol controller and the physical bus, it will be described how the bit rate can be changed in the simplest application. The transceiver is implemented in I3T technology so that both high voltage analog circuits and digital functions can coexist on the same chip. A LIN device is a member of the in-vehicle networking transceiver family (IVN). The LIN bus has been developed to transmit low rate data from controllers such as door locks, mirrors, car seats and sunroofs at as low a cost as possible. The bus is designed to eliminate as much wiring as possible, and is implemented with a single wire in each node. Each node has a slave MCU state machine that recognizes and translates the instructions specific to that function. To change the bit rate adjustment at the LIN transceiver, it is necessary to change the connected oscillator (crystal) for the clock of the PHY. In the simplest case, the use of another quartz is sufficient.Advantageously, the application generally saves energy if one down-cycles from 25 MHz. Each clock, and thus also the charge reversal process, costs energy. Slower clocking thus saves power. Furthermore, the emission or the interference emission is advantageously reduced or shifted in the frequency spectrum.It is advantageous to use, for example, a quartz crystal with a 300 MHz cycle rate for the cycle, since here it can be formed by a smallest common multiple (KGV). This can then be completely divided, for example. 10 clocks for a new clock would then yield 30MHz, 20 clocks, would yield 15MHz, 12 clocks would yield 25MHz.An alternative can be made via a PLL (Phase Locked Loop). Thus, from 25 MHz up to the 300 MHz mentioned above and then split down as described above. These 300 MHz or higher frequencies also do not necessarily contradict the statement with the current consumption, because this relates only to the oscillator. In a chip, these clock are tied to numerous gates / logics, and each consumes energy per switching operation, and the entire power consumption can be optimized by modifying the bit rate.

Claims

Method for flexibly adapting the bit rate within a computer network having at least one first node, wherein the node exchanges information via a data bus and / or via a point-to-point connection, wherein the steps - acquisition of information about a first reception time of a first message, - reception of information about a first transmission time of the first message, - acquisition of information about a second reception time of a second message, - reception of information about a second transmission time of the second message, - determination of a first value are carried out on the basis of the received and acquired information, and - comparison of the first value with a predefined second value, - detection of a state of the first node on the basis of the comparison result, characterized in that, a clock generator for generating clock signals of at least the first node and which bit rate is present via the data bus and / or via the point-to-point connection from and to the first node and to further nodes in the computer network is determined by the comparison result, and the bit rate in the computer network is changed flexibly when the bit rate is known via a modification of the clock generator for generating the clock signals.Method according to Claim 1, characterized in that the clock generator for generating the clock signals is modified in such a way that the clock generator for generating the clock signals generates 2.5 times the frequency of the bit rate to be achieved in the computer network.Method according to one of Claims 1 or 2, characterized in that a speed of the clock generator for generating the clock signals is determined by means of the PTP NRR method (neighbor rate ratio).The method of claims 1 to 3, wherein the computer network is a 10BASE-T1S or 100BASE-T1 or 1000BASE-T1 or multi-gigabit ether network.Method according to Claims 1 to 4, characterized in that a clock rate of the clocks for generating the clock signals of at least the first node is ascertained by means of the protocol gTP from IEEE 802.1AS.Method according to Claims 1 to 5, characterized in that the clock generator for generating the clock signals is realized by a crystal or resonators or phase locked loop (PLL).Method according to claims 1 to 6, wherein, in the presence of a 10BASE-T 1S computer network and a 25 MHz crystal as clock generator for generating the clock signals for at least the first node and a bit rate of 10 Mbit / s on the data bus, the clock generator for generating the clock signals for at least the first node is modified to 10 MHz in order to generate a bit rate of 4 Mbit / s to be achieved in the computer network.Method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 15 MHz in order to generate a bit rate to be achieved of 6 Mbit / s in the computer network.Method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 20 MHz in order to generate a bit rate to be achieved of 8 Mbit / s in the computer network.Method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 30 MHz in order to generate a bit rate to be achieved of 12 Mbit / s in the computer network.A control unit for a computer network, which is designed to: - send a signal to a second control unit of the computer network and to receive the signal from the second control unit; - determine a transit time of the signal on a connection path to the second control unit; - determine a maximum speed of the connection path on the basis of the transit time; and - determine a type of transmission medium of the connection path on the basis of the maximum speed, at least comprises - a microprocessor, - a volatile memory and nonvolatile memory, - at least two communication interfaces, - a modifiable clock generator for generating clock signals, the nonvolatile memory containing program instructions which, when they are executed by the microprocessor, characterized in that at least one embodiment of the method according to claims 1 to 10 can be implemented and executed.An Ethernet on-board power supply system for a motor vehicle, having a first control unit and a second control unit, wherein the control units are connected to one another via at least one connecting path, and the first control unit is designed according to claim 11.A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method according to one or more of claims 1-10.A more computer readable medium having stored thereon the computer program product of claim 13.Vehicle having an Ethernet on-board power supply system according to Claim 12, comprising a plurality of control units according to Claim 11.

Citation Information

Patent Citations

  • Method for synchronizing clocks in nodes of a vehicle network and for carrying out the procedure of established nodes

    DE102011087472A1

  • Method for establishing a common time base for network participants in a motor vehicle network

    DE102013224697A1

  • Technologies to compensate for errors in time synchronization due to clock drift

    US20220123849A1