Method for monitoring a communication connection between two network nodes that are directly connected to one another

EP4635150A1Pending Publication Date: 2025-10-22CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023828345
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-13
Filing Date
2023-12-01
Publication Date
2025-10-22

AI Technical Summary

Technical Problem

Existing methods for monitoring communication links between directly connected network nodes in time-synchronized Ethernet-based networks, such as those in motor vehicles, face challenges in detecting interventions that disrupt signal transit times, leading to unreliable time synchronization and potential safety risks due to the insertion of devices like TAPs or switches, which can cause delays and disrupt system operation.

Method used

A method to detect interventions by determining a limit value for signal transit time between two network nodes, using techniques like peer delay measurement and adjusting message delays to maintain system behavior without disruptions, allowing for the detection and compensation of signal transit time exceedances, thereby ensuring continuous operation and security.

Benefits of technology

This method enables reliable detection of interventions in signal transit times, maintaining system reliability and security by adjusting delays to prevent disruptions, thus ensuring uninterrupted operation and quick identification of unauthorized interference in time-synchronized networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

A method for detecting intervention in a direct connection between two network nodes of a system during operation comprises initiating messages of a first type in a cyclical manner or in a manner repeated at irregular intervals, to which messages a transmission time stamp in the transmitter and / or a reception time stamp in the receiver is added or assigned. After the time stamp has been set and before the message is transmitted via the physical layer and / or after the message has been received via the physical layer and before the reception time stamp is set, the messages are delayed by a previously determined limit value or previously determined limit values for the direct connection. It is then checked whether the signal propagation time has exceeded a predetermined value and this is signalled.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] Method for monitoring a communication connection between two directly connected network nodes

[0003] FIELD

[0004] The present invention relates to communication networks with time-synchronized network nodes. In particular, the invention relates to a method for monitoring an Ethernet-based communication network, for example, a communication network in a motor vehicle, and to a network node configured to carry out the method, for example, in the form of a control unit. The method can be used, among other things, to monitor for errors in the communication network and / or for changes in the network topology. For this purpose, monitoring of a direct communication connection between two network nodes, e.g., configured as electronic control units, is provided.

[0005] BACKGROUND

[0006] In many areas of technology, a large number of control units or computers communicate with each other via networks. In certain applications, it is necessary to synchronize these network nodes with each other, for example, in networked multimedia systems that are designed to play media content in a synchronized manner, or in systems in which a large number of interconnected sensors send sensor data to a processing unit, which evaluates the synchronized sensor data and generates control signals for the system.

[0007] An example of the latter application is partially or highly automated driving, in which sensor signals representing the vehicle environment and vehicle conditions are evaluated in real time or near real time in order to derive, among other things, control signals for the safe operation of the vehicle. The processing of sensor signals from a large number of sensors, even of different types, is also referred to as sensor fusion. Ethernet technologies are also increasingly being used in vehicles, replacing older or proprietary data connections and buses. Ethernet-based communication follows the so-called OSI layer model, in which each layer is assigned specific tasks that must be performed by the entities (devices and software) of the respective layer for communication to function.Each instance of a layer provides services according to the standardized network protocol, which a higher-level instance can use without having to worry about how and with what technical means the lower instance performs its tasks. Interfaces are defined between the different layers.

[0008] Fig. 1 schematically illustrates the known Ethernet-based communication, which is also applied in the present invention, between two network nodes 1, 2 of a wired communication network 3, designed, for example, as control units. This communication operates in a network protocol according to the OSI layer model with a total of seven layers I to VII. The tasks to be performed by the individual layers are implemented in computing units (not shown separately) of the network nodes 1, 2 and are schematically illustrated in Fig. 1.

[0009] According to the well-known OSI layer model, the layers are named as follows:

[0010] Layer I: Physical Layer, Layer II: Data Link Layer, Layer III: Network Layer, Layer IV: Transport Layer, Layer V: Session Layer, Layer VI: Presentation Layer, Layer VII: Application Layer.

[0011] Layers III to VII serve to prepare the physically transmitted data and assign it to specific applications that access the transmitted data via the application layer (Layer VII). These layers are organizational in nature and have nothing to do with the physical transmission of data or data packets. Since these layers are not concerned with the present invention, a description of the content of these layers, which is known to those skilled in the art, is omitted.

[0012] The actual data transmission takes place in Layers I and II. Layer I (PHY - Physical Layer) directly contains the tools for activating or deactivating the physical connection. These include, in particular, devices and network components such as amplifiers, connectors, sockets for the network cable, repeaters, hubs, transceivers, and the like. This Layer I thus serves to physically address the transmission channel using suitable electrical, optical, electromagnetic, or acoustic signals; in the case of wired Ethernet communication networks, these are usually electrical or electromagnetic signals. The network interfaces required for physical communication are assigned to each network node and form Layer I according to the OSI layer model.

[0013] Layer II of the OSI layer model, also known as the link layer, organizes and controls a largely error-free transmission and regulates access to the transmission medium. This layer also implements data flow control between sender and receiver. Logically, the link layer is often divided into a medium access control (MAC) and a logical link control (LLC). The media access control (MAC) regulates how multiple computers share the shared physical transmission medium. For this purpose, it uses, among other things, the so-called MAC addresses of the communication participants, which are assigned to each network node as a unique identifier in the communication network.The media access control (MAC) is managed by the logical link control (LLC), which distributes incoming data in each transmission direction and coordinates access to the higher-level network control layers. The tasks of the media access control (MAC) and the logical link control (LLC) form the so-called data link layer (Layer II), in which the various network participants are identified to organize network communication in a controlled manner. This logical management is schematically integrated in Fig. 1 between network nodes 1 and 2 in the line of the communication network 3 representing the physical connection.

[0014] The only control of network nodes 1, 2 as participants in the communication network thus occurs in the security view (Layer II), for example, through the unique MAC addresses for identifying the individual network participants, which is necessary for media access control. In the physical layer (Layer I), a network node 1, 2 has no knowledge of the other network nodes 2, 1 in the communication network 3, but only controls the physical communication at its interface to the communication network 3.

[0015] A large number of systems that are communicatively linked via Ethernet connections, including systems in vehicles or systems for the synchronized transmission of audio and video signals, can place particularly high demands on the reliability of transmission and the temporal coordination of data packets. In particular, safety-critical applications in vehicles, e.g. the transmission of sensor and control information for driver assistance systems or autonomous driving, place high demands on the temporal coordination of data packets. Even comparatively small changes in signal propagation times can lead to changed system behavior, e.g. because signals that are to be processed together or that must be present in a certain, closely coordinated time frame with other signals are no longer present in a suitable manner due to the change in signal propagation time.If the system behavior changes or is unpredictable, the reliability of the system can no longer be guaranteed.

[0016] The prevalence of time-synchronized network nodes will continue to increase in the future, partly because an ever-increasing number of control units transmit sensor data from different sensors, which are then linked and evaluated to provide safety and comfort functions. A particularly important aspect when fusioning sensor data is the temporal coherence of the sensor data. Depending on the application, it may be necessary to fuse sensor data that belong together to the nearest millisecond or microsecond, while in other applications a greater time interval between the recording times may be permissible. It is also conceivable that the recording times must belong together precisely in the range of nanoseconds. In addition to the data required for sensor fusion, however, the following data may also be required, for example:Data collected during the monitoring of the operation of the vehicle and used solely for maintenance purposes or to document its approved and proper operation are also subject to strict requirements for their timely recording and storage.

[0017] The time synchronization of network nodes within an Ethernet network can be achieved using appropriate protocols, ensuring a globally valid time base within the network. Time synchronization in Ethernet networks is defined, for example, in the IEEE 802.1 AS standard, which uses the Precision Time Protocol (PTP).

[0018] PTP defines a master-slave clock hierarchy with a best clock within a network, also known as the grandmaster clock. The time base of the remaining network nodes in the network is derived from this best clock, the grandmaster, which is determined using the Best Master Clock Algorithm (BMCA). Starting from the grandmaster, time synchronization messages are distributed across the network. PTP also defines a mechanism for measuring the signal propagation time on a connection and a method for exchanging time information.

[0019] To determine the Grandmaster Clock according to the BMCA, IEEE 802.1AS-capable network nodes cyclically send Announce messages with information about their internal clock to other directly connected network nodes. The information about the internal clocks provides information about the accuracy of the respective clock, its reference or time reference, and other properties that can be used to determine the best clock in the network. An example of such an Announce message is shown in Figure 2 a). A recipient of such an Announce message compares the received information with the characteristics of its own internal clock and, if applicable, messages already received from another port with information about clocks from other network nodes, and accepts a clock located in another network node if it has better clock parameters.After a short time, the best clock in the network is determined, which then becomes the grandmaster of the network, and a time synchronization spanning tree is established. Each port of a network node is assigned one of four port states. The "Master Port" state is assigned to the port that has a shorter path to the grandmaster than its link partner. The "Slave" state is assigned if no other port on this node has this state. Disabled is selected by the port that cannot fully support the PTP protocol. The "Passive" state is selected if none of the other three states apply.

[0020] In a variant of PTP, the generalized Precision Time Protocol (gPTP), two network nodes always communicate directly with each other for time synchronization, and neither of the two network nodes simply forwards a received time synchronization message to another network node in the network. Instead, the network node corrects the time information before forwarding it by the previously determined signal propagation time on the connection over which it receives time synchronization messages from a directly connected network node, as well as by the internal processing time, before creating and forwarding a new time synchronization message with the corrected time information. Network nodes that support gPTP are also referred to as "time-aware systems."

[0021] The signal propagation time on a connection between two network nodes can be determined using the Sync_Follow_Up mechanism, which is schematically shown in Figure 2 b). The master ports cyclically send Sync and Follow_Up messages to their neighboring link partners, i.e., their slave ports. When the Sync message leaves the master port, a timestamp is generated, which is immediately transmitted in a subsequent FollowJJp message. This timestamp corresponds to the current time of the Grandmaster at the time the Sync message was sent. From the difference between the reception times of the two messages, the receiver can determine the signal propagation time of the connection. Using this, and the time of the Grandmaster Clock transmitted in the Sync message, the receiver can then set its clock.

[0022] The so-called “peer delay mechanism” is used to determine the delay between two connected ports independently of time synchronization messages from the grandmaster clock. This is shown as an example in Figure 2 c). A port, the initiator, starts the measurement of the line delay by sending a Delay_Request message to the port of a network node directly connected to it, the responder. As late as possible before the message is actually sent via the Ethernet transceiver, a transmission timestamp with the time t1 is generated and inserted into the message so that this transmission timestamp t1 defines the actual transmission time to a good approximation. When the message arrives, the responder generates a reception timestamp t2. In response, the responder sends a Delay_Response message to the initiator. In this message, it transmits the reception timestamp t2 of the Delay_Request message.When this message leaves the responder, it generates a transmission timestamp t3, which is then sent to the initiator in an immediately following Delay_Response_Follow-Up message. Upon receipt of the Delay_Response message by the initiator, it generates a reception timestamp t4. The initiator can calculate the average delay on the communication link from the four timestamps t1 to t4. Since the delay on a connection link can vary depending on the direction, Delay_Request messages are sent independently by both communication partners.

[0023] These measurements can be performed cyclically, i.e., at predefined time intervals ranging from, for example, 100 ms up to several seconds or minutes. Even at a time interval of approximately one second, the network is not subject to significant load, so that even measurements at these relatively short time intervals are unproblematic for network operation. It may be useful to perform such signal propagation time measurements between all network nodes 1, 2 of the communication network 3 that are connected to one another, preferably as a direct signal propagation time between two network nodes 1, 2.

[0024] During the development or analysis of networked systems, it may be necessary to eavesdrop on the data traffic sent over the network connections, for example, to locate errors occurring in the system. To eavesdrop on communication between two directly connected network nodes without having to specifically adapt or modify the software of the network nodes, which could lead to altered system behavior in which the error does not occur or in which other errors occur, a so-called test access point (TAP) or a switch or bridge is typically inserted into the network connection between the two devices.

[0025] From the schematic representation of the physical connection of the communication network 3 shown in Figure 3 a), corresponding to the solid arrows, it can be seen that the physical connection can certainly be severed without the access control (MAC according to the link layer or Layer II) represented by the dashed arrows having to or being able to detect this. For this purpose, as shown in Figure 3 b), a tap 4, e.g., a TAP, is interposed between each two physical PHY interfaces. A network analyzer, for example, can be connected to this tap, which analyzes the data traffic between the two network nodes 1, 2 (not shown in the figure).

[0026] Such a TAP 4 is simply looped into the existing line connection, copies the data information or data packets bit by bit as the data stream passes through, without analyzing their content, and outputs the copied data information via another interface. The physical data stream is simply forwarded unchanged. Thus, the network analyzer 4 does not appear in the communication network 3. In particular, the link layer (layer II of the OSI layer model) of network nodes 1 and 2 is not aware of the existence of this network analyzer 4.

[0027] Compared to a direct line connection between network nodes 1 and 2, looping the data stream through TAP 4 results in an extended signal propagation time for the signals (data packets) transmitted between network nodes 1 and 2. This extension of the signal propagation time can amount to several hundred nanoseconds.

[0028] The use of switches or bridges in a connection between network nodes to monitor communication has an even greater impact on communication than a TAP. Even if a switch or bridge, like a TAP, does not have a direct address, it causes a significant delay, partly due to the potential storage of data before forwarding, and also participates in Layer 2 communication.

[0029] As already described above, the insertion of a TAP, switch, or bridge can lead to an increase in signal propagation time, which reduces the accuracy of time synchronization or even disrupts or prevents it. Particularly in systems where correct and reliable time synchronization is essential for the functioning of a large number of interconnected network nodes, disrupted or failed time synchronization can result in one or more network nodes switching from their original operating mode to another operating mode, e.g., an error operating mode, and the intended permissible interception of communications in the original operating mode of the network node or system cannot take place. This may no longer ensure secure operation, and troubleshooting is significantly more difficult.It is easy to see that the disruption to time synchronization increases with the number of TAPs, switches, or bridges inserted between two network nodes, unless the signal propagation time is re-determined and corrected accordingly when forwarding time synchronization messages. Inserting TAPs, switches, or bridges into a network connection can also be done for reasons other than troubleshooting, for example, to unauthorizedly eavesdrop on network communications and identify vulnerabilities that can be used to deliberately alter system behavior. This approach is particularly useful in systems that are deployed in large numbers in identical fashion. An attacker only needs to gain access to one of the systems and, after analyzing and finding a vulnerability, can then specifically attack any of the other systems.

[0030] This poses a certain risk, especially in safety-relevant applications such as those found in motor vehicles. For example, when information evaluated by driver assistance systems is transmitted, it is necessary to determine whether this information is being intercepted. Such interception could pave the way for a targeted attack on the vehicle's communication system, for example, by revealing the keys or network addresses used.

[0031] Since monitoring the participants in the communication network is generally only possible with knowledge of their addressing, i.e. their MAC addresses or other unique identification features in the network, the insertion of a TAP or switch or a bridge represents an attack possibility in an Ethernet-based communication system, which is not recognizable on Layer II or on higher layers of the OSI layer model.

[0032] In a static communications network, e.g., that of a motor vehicle, in which the network topology does not change unless the network is modified by a permissible or impermissible intervention, it is possible to detect an intervention by detecting changes in signal propagation time. One option for measuring signal propagation times between network nodes that can be used in this context is the method described with reference to Figure 2 c). The use of average propagation times determined in a system before any intervention on connections between two network nodes requires that these propagation times are stored in each network node for each direct connection to other network nodes. In addition, the propagation time measurement must be repeated cyclically at intervals that are not too short in order to be able to detect even short-term interventions.This can cyclically lead to an increased communication load on the network connection, which may cause particularly time-critical messages to reach their destination with a delay.

[0033] DESCRIPTION OF THE INVENTION

[0034] It is therefore desirable to provide a method for monitoring a communication connection between two directly connected network nodes of a system, by means of which an intervention in the direct connection can be detected even at the technical physical layer, where only the physical data traffic is processed, without having to perform a cyclical measurement of the signal propagation time and a comparison with a previously determined signal propagation time value. It is also desirable to be able to adapt parameters of the connection between the two network nodes that have been changed by an intervention in such a way that the operating behavior of the system does not differ from the operating behavior before the intervention.It is also desirable to specify a network node, in particular a control unit of a motor vehicle, which is connectable or connected to other network nodes and which is configured to carry out one or more embodiments of the monitoring method according to the invention or parts thereof.

[0035] A first part of this object is achieved according to the invention by a method having the features of claim 1. A further part of the object is achieved by the method of claim 8. Yet another part is achieved by the network node specified in claim 11. Further developments and refinements of the method are specified in the respective dependent claims. According to a first aspect of the invention, in order to detect an intrusion into the direct connection between two network nodes (network nodes), a limit value of a parameter of the direct connection between the two network nodes must first be determined. This limit value is exceeded in the event of an intrusion into the direct connection and can be used as a reliable indication of the presence of an intrusion. One such parameter is, for example, the signal propagation time on the direct connection, since the signal propagation time increases when a TAP or a switch is inserted ora bridge, as required for active intervention in the direct connection. This parameter cannot be queried from a network node, nor is it available for retrieval in a database or the like. Furthermore, the parameter can be different for each link and each link type. In the context of this description, the term "direct connection" refers to a direct physical connection between two network nodes, i.e., without any other network nodes in between.

[0036] A method according to the invention for determining a limit value for the signal propagation time of a direct connection between two network nodes initially comprises determining the signal propagation time on the direct connection at a time when there is no interference with the direct connection between two directly connected network nodes of a system. This can be done, for example, using the peer-delay-X / method known from the IEEE 802.1 AS standard, whereby the measurement can be carried out in one or both directions. However, the signal propagation time can also be determined by reading it from a database or configuration memory if the signal propagation time was previously determined and does not change over time. Other methods for determining the signal propagation time are conceivable and known to those skilled in the art.

[0037] In a next step, the transmission of a message of a first type is initiated via the direct connection, and a transmission timestamp is added or assigned to this first type of message at least in the sender. Additionally, a reception timestamp can be added or assigned to the first type of message in the receiver.

[0038] Using the timestamp(s) in the first message type, the signal propagation time can be verified at the physical level. The first message type can also trigger a response from the receiver, allowing the signal propagation time to be verified at the sender's end. The first message type can be a message from the event message class specified in the IEEE 8201 .AS standard, e.g., a peer-cfe / ay message.

[0039] Before the previously initiated message of the first type, which is provided with the transmission timestamp, is sent via the physical layer, it is delayed by a first transmission delay value. Additionally or alternatively, the message can be delayed by a first reception delay value after being received at the physical layer and before the reception timestamp is set. The first reception delay value can be dependent or independent of the first transmission delay value.

[0040] According to the IEEE 802.1 AS standard, at least for some messages from the event message class, if the signal propagation delay on the direct connection exceeds a predetermined value, a variable that previously signaled that the signal propagation delay on the direct connection was not exceeded is changed. The predetermined value is, for example, a value specified in the IEEE 802.1 AS standard via the variable meanLinkDelayThresh. The variable is, for example, the flag asCapableAcrossDomains or asCapable from the IEEE 802.1AS standard, which is used during the time synchronization of the system's network nodes and indicates the ability of a network port to perform time synchronization according to the standard.Changes to the value of asCapableAcrossDomains or asCapable, which can take the values ​​true or false as a Boolean variable, are communicated to a state machine in the PHY, which then sets the state of the respective port to reenabled Ext or disabledExt.

[0041] The port status is communicated, among other things, during time synchronization, so that the change is quickly communicated to all other network nodes due to the cyclical transmission of time synchronization messages. Accordingly, the method includes checking whether the signal propagation time has exceeded a predetermined value. This can be done, for example, by comparing the transmission time specified in the transmission timestamp with the synchronized system time of the receiver, by comparing the transmission time with the reception time sent back to the sender by the receiver in a response message, by evaluating the asCapableAcrossDomains or asCapable flags of the IEEE 802.1 AS standard, by evaluating the port states, or by other methods known to those skilled in the art.

[0042] If the check shows that the signal propagation time has not exceeded the predetermined value, the transmission of another message of a first type is initiated via the direct connection, whereby the delay after setting the timestamp and before the actual transmission on the physical layer is increased compared to the previously set value. Subsequently, a check is carried out again to determine whether the signal propagation time has exceeded the predetermined value. The initiation and delayed transmission is repeated, each time with a delay increased compared to the previous transmission process, until the signal propagation time has exceeded the predetermined value. The last delay value is then output and / or stored as the determined limit value for the direct connection at which the signal propagation time has not yet exceeded the predetermined value.If delay values ​​are set separately for both sending and receiving, the last delay values ​​are saved as the determined limit values. This can be saved locally or in an external database.

[0043] The determination of the limit value between the two directly connected network nodes can be done in both directions.

[0044] In one or more embodiments of the method, after the signal propagation time has exceeded the predetermined value for the first time, transmission is repeated with the previously set delay for a previously defined number of attempts or repetitions. If the signal propagation time has exceeded the predetermined value in all consecutive attempts or repetitions, the method proceeds to the next step. If the signal propagation time falls below the predetermined value again before the previously defined number of attempts or repetitions is reached, this repetition phase is restarted, with transmission and checking taking place with a delay that is longer than the previously set value. In this way, a delay value that leads to either an exceedance or a fall below the predetermined value of the signal propagation time due to the smallest deviations occurring during normal operation can be reliably detected.Such a value at the limit can be specifically used or omitted when the limit value for the signal propagation time is used later, depending on the application, especially if the delay can only be set in discrete steps that have a certain minimum size.

[0045] In one or more embodiments of the method, after the signal propagation time has exceeded the predetermined value at a set delay once or possibly several times, the value or values ​​for the delay can be reduced again and the test for exceeding the signal propagation time can be carried out again. The reduction and test are repeated if necessary until the signal propagation time is below the predetermined value. In one or more embodiments of this method, a repetition phase with the previously set delay can be used to check whether the signal propagation time is below the predetermined value in a previously defined number of consecutive attempts or repetitions and, if necessary, the repetition phase can be restarted with a further reduced delay.

[0046] To avoid disrupting ongoing system operation, in one or more embodiments of the method, after each message whose signal propagation time has exceeded the predetermined value, a message of the first type, to which a transmission timestamp is added or assigned in the transmitter and / or a reception timestamp in the receiver, can be sent without delay. This allows any existing mechanism to be reset, which only puts the system or one or more network nodes into an error operating mode or another mode deviating from the original operating mode after a predetermined number of attempts. In particular, the time synchronization methods according to the IEEE 802.1AS standard can compensate for the failure of up to two consecutive synchronization messages.Only if three consecutive synchronization messages are missing would the system's time synchronization be disrupted or re-initiated, network nodes would go into error mode, or show other effects that result in a change in the system's operation.

[0047] In one or more embodiments of the method, the delay for delayed transmission can be added, for example, by encrypting at least the messages of the first type on the physical layer, i.e. on the physical connection, after the timestamp has been set and before the encrypted data bits are actually transmitted over the communication medium. The MACsec mechanism known from IEEE 802.1AE, for example, can be used for this purpose. The MACsec mechanism supports, on the one hand, a method for ensuring the integrity of the transmitted data and, on the other hand, data encryption. In the former, the sender appends an 8-byte header and a 16-byte tail, which are checked by the receiver to ensure the integrity of the data. These 24 additional bytes alone increase the signal propagation time.Since encryption requires at least the storage of a certain number of data bits, this means that a delay occurs before the message is actually transmitted to the recipient. This delay depends, among other things, on the number of data bits encrypted in each block. In addition, depending on the encryption method and key selected, the number of bits or octets of the message to be transmitted can be considerably increased, so that the increased volume of data to be transmitted due to encryption also leads to an additional delay. Accordingly, in one or more embodiments of the method, different delays can be set by using different encryption parameters. For example, the use of GCM-AES-128 encryption can result in a shorter delay than the use of GCM-AES-256 encryption.If only a short delay is necessary, the method can be used to ensure integrity without data encryption. Alternatively, or in addition to encrypting messages of the first type, any other message can be encrypted and / or sent with additional bytes to ensure integrity immediately before sending the first type. Since in both cases the amount of data to be sent increases and the corresponding processing may require additional time, the sending of the subsequent message of the first type is delayed accordingly after the transmission timestamp is set in the sender's flow control buffer.Likewise, the received message of the first type is stored in the receiver buffer until the previously sent message is decrypted, so that the setting of the reception timestamp is also delayed by the use of the MACsec mechanism, and the signal propagation time visible to the network nodes is increased. Since a response to an encrypted message is also encrypted, applying the peer delay method described with reference to Figure 2 c) can result in a significant increase in the signal propagation time.

[0048] Since signal propagation times in a static communications network, such as those found in a motor vehicle, do not change significantly, apart from minor, insignificant deviations, for example, due to normal jitter or temperature-related propagation time differences, the determination of the signal propagation time limit does not need to be repeated at short intervals. To account for the aging of electronic components in the system of network nodes, repeating the determination of the limit at longer intervals is sufficient.

[0049] According to a second aspect of the invention, in a method for detecting an intrusion into a direct connection between two network nodes of a system during operation in a first operating mode, messages of the first type are initiated cyclically or at irregular intervals, to which the transmission time is added or assigned in the transmitter, e.g., a transmission timestamp, and / or for which the receiver logs the reception time, e.g., using a reception timestamp. After setting the transmission timestamp and before transmission via the physical layer and / or after receiving the message via the physical layer and before setting the reception timestamp, at least the messages of the first type are delayed by a limit value determined in the previously described method or by limit values ​​for the signal propagation time on the direct connection determined in the previously described method.A check is then carried out to determine whether the signal propagation time has exceeded a predetermined value. If the signal propagation time has exceeded the predetermined value, the exceedance is signaled. This makes it possible to detect any interference with the direct connection between the two network nodes and take appropriate action. The extension of the signal propagation time set by the delay is expediently selected such that, on the one hand, the predetermined signal propagation time value is reliably not exceeded, but even a small additional extension of the signal propagation time leads to an exceedance.

[0050] The role of the sending and receiving network node can also alternate repeatedly in this aspect of the invention, since messages of the first type can be sent cyclically and bidirectionally, i.e., in any direction of communication between the two network nodes. Monitoring is expediently performed cyclically, i.e., at predetermined or predeterminable time intervals, so that changes can be reliably detected.

[0051] As soon as an intervention in a direct connection between two network nodes is detected, the network node executing the procedure can communicate this to the affected system components at a higher communication level in the OSI layer model. This way, after further checking the legitimacy of the intervention, an adjustment can be initiated to enable continued system operation without exceeding the predetermined signal propagation time.

[0052] In order to be able to detect and ignore only one-time exceedances of the predetermined value of the signal propagation time at irregular intervals, it can be provided that only repeated exceedances of the predetermined value of the signal propagation time lead to a signaling. This can be used to intercept, for example, temporary overloads of network nodes which slightly delay signal acceptance or the computing operations carried out during it, but which do not represent an intervention in the structure of the network. According to one or more embodiments of the method according to the second aspect of the invention, in response to the signaling of the exceedance of the limit value, the system or at least one of the network nodes is put into an error operating mode in which, for example, safety-relevant functions are carried out in a particularly secure manner or are switched off.A network node operating in a fault mode can announce its operation in a fault mode to other network nodes in the system over the network.

[0053] Alternatively, the delay of at least the messages of the first type can be reduced to a reduced value at which the signal propagation time does not exceed a predetermined value. The method according to the first aspect of the invention can be used to determine this reduced value.

[0054] If the delay is reduced to a value at which the signal propagation time does not exceed the predetermined value, a system behavior can be restored that is identical to the system behavior before the signaling of the limit violation. This allows, for example, a system behavior that was changed by the permissible insertion of a TAP into a direct connection between two network nodes to be restored to the state it existed before the TAP was inserted. This ensures that, for example, no additional errors caused by the insertion of the TAP occur during troubleshooting, or that the system's operating behavior remains unchanged compared to before the TAPs were inserted.

[0055] According to a third aspect of the invention, a network node comprises one or more processors, volatile and non-volatile memory associated with the one or more processors, and a physical network interface communicatively connected to the one or more processors and configured to send and / or receive data via a communication medium shared by multiple network nodes. The elements of the network node are communicatively connected to one another by means of one or more data lines or buses. Computer program instructions are stored in the non-volatile memory, which, when executed by the at least one processor, configure the network node to execute one or more embodiments of the method according to the invention.

[0056] According to a fourth aspect of the invention, a system, in particular a vehicle system, comprises one or more network nodes, each networked via a direct connection. According to the invention, at least one of the network nodes is configured to execute at least one embodiment of the method according to the invention described above.

[0057] A computer program product according to a fifth aspect of the invention contains instructions which, when executed by a computer, cause the computer to carry out one or more embodiments and further developments of the method described above.

[0058] The computer program product can be stored on a computer-readable medium or data carrier. The medium or data carrier can be physically embodied, e.g., as a hard drive, CD, DVD, flash memory, or the like, but the medium or data carrier can also comprise a modulated electrical, electromagnetic, or optical signal that can be received by a computer via a corresponding receiver and stored in the computer's memory.

[0059] The methods described above and the network nodes executing the methods can advantageously be implemented without changes to existing hardware and can be integrated into existing networks accordingly, since the protocols already in use do not need to be changed and the function of the network during normal operation, i.e. without inadmissible interference with at least one direct connection between two network nodes, is not impaired by inadmissible exceedances of the signal propagation time. Since the integrity of the direct connections is monitored during operation, the operational reliability of systems, e.g. sensor networks and control units that control and execute actions based on sensor data, can be increased, e.g. in vehicles with a high degree of driver assistance or autonomously driving vehicles.Unauthorized interventions in one or more direct connections between two network nodes can be quickly detected and appropriate measures can be taken more quickly to restore safe operation or to transition to a safe operating mode.

[0060] Using the method for determining the signal propagation delay threshold according to the first aspect, a signal propagation delay map of the communications network can be created, in which the timing reserves of the respective connections between two network nodes are entered. This information cannot normally be easily retrieved from a network node, either because no query is implemented for this purpose or because the implementation is not disclosed. Nevertheless, the method according to the invention can be used, among other things, to identify connections into which network analyzers or diagnostic devices can be looped.In the case of such permissible intervention in one or more direct connections between two network nodes, a signal propagation time that has been increased by the intervention and then exceeds a predetermined value can be brought back to a range below the predetermined value by correspondingly reducing the delay at the transmitter and / or receiver. This makes it possible to return system behavior that has changed due to the intervention to a state comparable to that prior to the intervention. In contrast to previous methods, there is no need to use residual bus simulation or the like to test network nodes separately in the simulated system context. In a similar way, it can be determined in advance whether transmission protocols that cause additional time delays during transmission can be used in a system.

[0061] Even if network nodes are replaced or the communication lines between network nodes are replaced or repaired, the methods according to the invention can be carried out again without great effort in order to determine any changed parameters and to continue the operation of the system as before, if necessary with changed delays on individual connections.

[0062] The method described above and the network nodes executing the method can be used platform-independently and therefore flexibly due to the simple and lean implementation and the use of resources already available in standards.

[0063] The type of monitoring proposed by the invention also helps eliminate the need for additional complex and / or computationally intensive security protocols. This reduces the overall load on the communications network.

[0064] Although the invention has been described above with reference to Ethernet-based communication and a strong focus on the automotive environment, the principle is applicable to all systems in which directly connected network nodes use methods of the IEEE 802.1AS standard or methods comparable to those described therein for time synchronization, and in which network nodes can deliberately cause delays between the setting of a time stamp and the actual transmission on the physical layer by various measures.

[0065] SHORT DESCRIPTION OF THE DRAWING

[0066] The invention is explained below by way of example with reference to the drawing, from which further advantages, features, and possible applications of the invention will also emerge. All described and / or illustrated features, individually or in any combination, constitute the subject matter of the present invention, regardless of their summary in the claims or their references.

[0067] The drawing shows: Fig. 1 schematically the communication process between two network nodes of an Ethernet-based communication network according to the OSI layer model,

[0068] Fig. 2 Swim-lane diagrams of exemplary messages used for time synchronization and measurement of signal propagation times,

[0069] Fig. 3 schematically shows the physical and logical communication paths between two network nodes before and after the interposition of a TAP,

[0070] Fig. 4 is a schematic flow diagram of a method for determining a threshold value for the signal propagation time of two directly connected network nodes,

[0071] Fig. 5 is an exemplary schematic flow diagram of a method for determining a limit value for the signal propagation time of two directly connected network nodes during operation of a system in a first operating mode, without the operation of the system or the network nodes in the first operating mode being disturbed in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time or one of the network nodes of the system being switched to a second operating mode,

[0072] Fig. 6 shows an exemplary block diagram of a network node with a microprocessor pP and a typical physical Ethernet interface PHY,

[0073] Fig. 7 is a schematic flow diagram of a method according to the invention for monitoring the operation of a system with two or more network nodes that are directly connected to each other,

[0074] Fig. 8 is a schematic flow diagram of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly interconnected, and

[0075] Fig. 9 is an exemplary block diagram of a network node configured to carry out one or more aspects of the method according to the invention.

[0076] Identical or similar elements may be referenced with the same reference numerals in the figures. Figures 1 to 3 have already been described above and will therefore not be discussed again below.

[0077] DESCRIPTION OF EMBODIMENTS

[0078] Figure 4 shows a schematic flow diagram of a basic method 100 for determining a limit value for the signal propagation time of two directly connected network nodes. In step 102, the signal propagation time is first measured in a first operating mode. For this purpose, the method described with reference to Figure 2 c) can be used, for example. The first operating mode is, for example, normal operation of the two network nodes in their system context. The measurement can be carried out several times in succession in order to filter out minor fluctuations or deviations that can occur during normal operation by averaging or the like. In step 104, the transmission of a message of a first type from a first of the two network nodes to the second of the two network nodes is initiated. Before the message is actually sent over the communication medium, it is delayed by a delay value in step 106.In step 108, it is then checked whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, the "yes" branch of step 108 initiates the transmission of further messages of the first type from the first of the two network nodes to the second of the two network nodes, with these further messages of the first type being delayed by a delay value that is greater than the respective previous delay value of the previous message.If the check in step 108 reveals that the signal propagation time of the message is above a predetermined value due to the delay, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node (the "no" branch of step 108), a limit value for the signal propagation time is determined, or at least a limited range within which the limit value lies. The limit value lies in a range whose lower end is marked by the sum of the signal propagation time first determined in step 102 and the last set delay value, at which the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node.The upper end of the range is marked by the sum of the signal propagation time initially determined in step 102 and the delay value at which the signal propagation time of the message, due to the delay, first exceeds a predetermined value, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. The limit value or range determined according to the method described above, or a value selected from this range, can then be stored locally and / or output in step 114.

[0079] Figure 5 shows an exemplary schematic flow diagram of a method 500 for determining a limit value for the signal propagation time of two directly connected network nodes during ongoing operation of a system in a first operating mode, without the operation of the system or of the network nodes in the first operating mode being disrupted in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time, or without one of the network nodes of the system being switched to a second operating mode. The method according to the invention utilizes the knowledge that certain messages of the first type do not lead to a disruption of operation if a predetermined value for the signal propagation time is exceeded by no more than a predetermined number of consecutive messages.Individual messages with a signal propagation delay exceeding the threshold can increment an error counter, but this counter is reset by the next message with a signal propagation delay below the specified value. This prevents sporadic errors from affecting the system's operating behavior.

[0080] Steps 104, 106, and 108 correspond to those already described with reference to Figure 4. In step 104, the transmission of a message of a first type from a first of the two network nodes to the second of the two network nodes is initiated. Before the message is actually sent over the communication medium, it is delayed by a delay value in step 106. In step 108, a check is then made to determine whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node.

[0081] If this is the case (“yes” branch from step 108), a check is made in step 110 to determine whether a longer delay can be set for messages to be sent. If this is possible (“yes” branch from step 110), a longer delay is selected in step 112, and the process is repeated beginning with step 104. The setting of a modified delay is indicated by the dashed arrow from step 112 to step 106. If no longer delay can be set for messages to be sent (“no” branch from step 110), this greatest possible delay is assumed as the limit and stored and / or output in step 114.

[0082] If the check in step 108 reveals that the signal propagation time is above the predetermined value (the "no" branch of step 108), the signal propagation time of the direct connection is determined for this delay in step 116, and the delay is deactivated again in step 118. Subsequently, in step 120, another message of the first type is sent so that an error counter that may have been previously incremented due to the signal propagation time being exceeded is reset, or so that the system can compensate for or correct this exceeding of the signal propagation time in another way. Then, in step 122, a check is carried out to determine whether a reduced delay can be set that is lower than the last set delay but higher than a delay set before this one.If this is not the case, “no” branch of step 122, the deceleration value which led to the predetermined value being exceeded is assumed as the limit value and stored and / or output in step 114.

[0083] If the check in step 122 shows that a reduced delay can be set, but which is higher than the delay set before last, "yes" branch of step 122, this is selected in step 112, and the process is repeated starting with step 104.

[0084] Figure 6 shows an exemplary block diagram of a network node 600 with a microprocessor pP and a typical physical Ethernet interface PHY. The figure shows in particular at which point within the PHY a transmission timestamp is added or assigned to a message, and at which points the message can subsequently be delayed. The microprocessor pP communicates with the PHY via an interface whose implementation can be parallel or serial and which is generally different from the Ethernet transmission medium. Accordingly, a media-independent interface Mil (Media Independent Interface) is provided on the processor side of the PHY. The media-independent interface Mil receives messages from the MAC of the link layer, Layer II of the OSI layer model, for transmission over the transmission medium, and forwards received messages to the MAC.A message to be transmitted, received at the media-independent interface MIL and essentially present as raw data, is subjected to channel coding in a physical coding sublayer (PCS) before it is actually sent. Channel coding serves to protect digital data against transmission errors during transmission over noisy channels by adding redundancy. Channel coding adds redundancy to the data at the input of a transmission channel and decodes the data at its output. If the additional information merely indicates an error and requires retransmission of the data, this is referred to as backward error correction. If the redundancy information is sufficient to correct the error, this is referred to as forward error correction. Efficient channel coding increases the signal-to-noise ratio while maintaining the same bit error rate. Depending on the channel coding method, the code gain can be several dB.

[0085] An essential property of a channel code is its code rate R = k / n, where k is the number of symbols at the input of the encoder, the information symbols, and n is the number of symbols at the output, the code symbols. This means that k information symbols are mapped to n code symbols. A small rate, i.e. the larger n is for a given k, the higher the proportion of code symbols to the transmitted symbols, and thus a lower data transmission rate. Typically, a channel code with a lower code rate can correct more errors than a comparable channel code with a high code rate - a trade-off between data transmission rate and error correction capability is therefore possible.

[0086] Only the channel-coded data are sent into the transmission medium from a PMA interface adapted to the physical transmission medium.

[0087] Received data is processed accordingly in reverse order by the above-mentioned blocks.

[0088] If a transmission time stamp is added or assigned to a message before transmission or after reception, this can be done in a time stamp unit (TSU) located between the MIL and the PCS so that the time stamps are also captured by the channel coding.

[0089] The protocols defined in IEEE 802.1AE for confidential and secure data transmission, also known as MACsec, enable data to be encrypted or decrypted before being sent or received over the communication medium. Encryption occurs between the setting of the timestamp and before channel coding, among other things, to protect the timestamp and prevent any information from being extracted from the analysis of timestamps.

[0090] Based on the above-described arrangement of the functional blocks and the resulting predetermined order of processing data to be sent or received, the adjustable delay of the messages required for the method according to the invention after setting the respective time stamp can therefore only be implemented in one or more of the MACsec, PCS, or PMA blocks. Due to the predominantly analog structure of this block, setting a delay in the PMA block appears to be impossible or only possible to a very limited extent, which would be insufficient for the purposes of the invention.

[0091] In contrast, setting a delay in the PCS block appears to be quite possible, for example by selecting a suitable code rate during channel coding, by means of which the amount of data transmitted on the communication medium can be varied, so that a longer transmission time for a data packet of a fixed size, ie an additional delay, can be achieved simply by increasing the amount of data at a small code rate R compared to a large code rate R.

[0092] A particularly suitable block for setting a delay after setting the timestamp and before sending over the communication medium is the MACsec block. By selecting one of the different encryption methods agreed upon in IEEE 802.1AE, provided implemented in a PHY of a network node, a given amount of data is converted into a different, increasingly larger amount of encrypted data after encryption. The choice of key, e.g., its length, can also influence the amount of data added by encryption. The encryption process itself requires data to be stored, which results in a certain additional delay. The increased amount of data caused by encryption, which must be sent over the communication medium at the same speed as unencrypted data, results in a further delay.

[0093] To delay messages of the first type, either the message itself can be encrypted, and / or a message of any type sent immediately before the message of the first type can be encrypted. Since encrypting a message sent before the message of the first type increases its data volume, subsequently sent messages must be delayed accordingly in the PHY's flow control buffer. Thus, by appropriately selecting the message to be encrypted, its length if applicable, and the encryption method, a delay of at least the messages of the first type can be set for parts of the inventive method in a range from a few hundred nanoseconds to a few microseconds.

[0094] The appropriate method in each case, i.e. encryption of a message sent immediately before a message of the first type, choice of encryption method, choice of key length, choice of the length of the message to be encrypted, encryption (also) of the message of the first type as well as the key to be used in each case, its length and the encryption method to be used may depend on the transmission speed of the connection.

[0095] Figure 7 shows a schematic flow diagram of a method 700 according to the invention for monitoring the operation of a system with two or more network nodes that are each directly connected to one another. First, a limit value for the signal propagation time on a direct connection between two network nodes to be monitored is determined. For this purpose, one of the methods described with reference to Figure 4 or 5 can be used, for example. Alternatively, the limit value can be read from a memory. According to the invention, in step 702, for the transmission of at least messages of the first type, the transmission is delayed by a delay value at which the predetermined value for the signal propagation time is reliably just not exceeded. Subsequently, in step 104, the transmission of a message of the first type from a first of the two network nodes to the second of the two network nodes is initiated during operation of the system.Before the message is actually sent over the communication medium, it is delayed by a delay value in step 106. In step 108, a check is then made to determine whether the signal propagation time of the message, despite the delay, is below the predetermined value for the signal propagation time, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, "yes" branch of step 108, the method is repeated beginning with step 104 without changing the delay value set in step 702, whereby the repetition can occur cyclically or at irregular intervals. The control required for this in each case is indicated by method step 109 located between steps 108 and 104.The control can be conventional and use a timer or a (pseudo-)random generator, or an external trigger that reacts to a change in an environmental or system variable or the like.

[0096] If the check in step 108 reveals that the signal propagation time of the message is above the predetermined value due to the delay, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node (the "no" branch of step 108), an additional delay in the signal propagation time must have been introduced into the direct connection between the two network nodes, or another change or disruption has occurred. In any case, the exceeding of the predetermined value of the signal propagation time is signaled in step 704, whereupon at least the network node implementing the method can initiate further steps or measures.

[0097] The monitoring described above can therefore detect an intervention in a direct connection between two network nodes, which results in an extension of the signal propagation time.

[0098] If the change in signal propagation time was caused by a permissible intervention in the system, e.g. by temporarily inserting a measuring device via a TAP or a switch or a bridge, the system behavior as it existed before the intervention can be restored, e.g. using the procedure described with reference to Figure 8.

[0099] Figure 8 shows a schematic flow diagram of a method 800 of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly networked with one another. In the exemplary application, the aim is to determine on which direct connections between two network nodes the communication between these network nodes can be recorded and evaluated without the additional extension of the signal propagation time caused by the necessary insertion of a TAP, switch, or bridge leading to the operation of the system or the network nodes being disrupted in a way that cannot be corrected or compensated for, or one of the network nodes of the system being put into a second operating mode. According to the invention, the extension of the signal propagation time caused by the inserted TAP, switch, or bridge is determined in step 802. This can be done, for example,by suitable measurements, based on information in a data sheet or the like. Subsequently, in step 804, a method is determined by means of which a corresponding delay for messages to be sent can be set in the PHY of a network node of the system. Subsequently, it is verified whether, even with the added delay in the connection between two network nodes, operation of the system in the previously set operating mode is still possible, or whether none of the network nodes switches to an operating mode different from the previously used operating mode. If this is the case, i.e. operation is possible without change, a measuring device, TAP or switch or a bridge with a corresponding delay can be looped into this connection. The verification can be carried out, for example, using the method described with reference to Figure 5.This method can be used to identify those connections in a system where a signal propagation delay extended by an intervention can be compensated for without actually having to carry out the intervention.

[0100] If a monitoring method is implemented in the system's network nodes, as described with reference to Figure 7, the method described above can also be used. Typically, even a minimal further extension of the signal propagation time will result in the predetermined signal propagation time being exceeded for many connections between two network nodes. However, this can be compensated for by a corresponding reduction in the delay set for normal operation.

[0101] Figure 9 shows an exemplary block diagram of a network device 900 configured to execute one or more aspects of the method according to the invention. In addition to a microprocessor 902, the network device 900 includes volatile and non-volatile memory 904, 906, and one or more communication interfaces 908. The elements of the network device are communicatively connected to one another via one or more data connections or buses 910. The non-volatile memory 906 contains computer program instructions which, when executed by the microprocessor 902, configure the network device to execute at least one embodiment of the method according to the invention.

[0102] LIST OF REFERENCE SYMBOLS

[0103] 1 , 2 network nodes 900 network nodes

[0104] 3 Network / Connection 902 Microprocessor

[0105] 904 volatile memory

[0106] 100 Method 906 non-volatile memory

[0107] 102 Measuring signal propagation time 908 Communication interface

[0108] 104 Initiate sending 910 Data connections / buses

[0109] 106 Delay sending

[0110] 108 pre-determined value exceeded?

[0111] 109 Repetition Control

[0112] 110 longer delay adjustable?

[0113] 112 select larger / smaller directory

[0114] 114 Output limit value

[0115] 116 Determine signal propagation time

[0116] 118 Disable delay

[0117] 120 Send message immediately

[0118] 122 smaller delay adjustable?

[0119] 500 procedures

[0120] 600 network nodes

[0121] 700 procedures

[0122] 702 Delay sending

[0123] 704 Signal exceedance

[0124] 800 procedures

[0125] 802 Determine signal propagation time

[0126] 804 Determine delay procedures

Claims

CLAIMS 1 . Method (100) for determining a limit value for the signal propagation time on a connection between two directly connected network nodes of a system comprising a plurality of network nodes connected via a network, the method comprising: a) determining (102) the signal propagation time between the directly connected network nodes, the method being characterized by the steps of: b) initiating (104) a message of a first type via the direct connection, to which a transmission time stamp is added or assigned in the sender and / or a reception time stamp is added or assigned in the receiver, c) delaying (106) the message after setting the transmission time stamp and before sending the message via the physical layer and / or after receiving the message via the physical layer and before setting the reception time stamp by a first value orby first values ​​in each case, d) delayed sending of the message via the physical layer, e) checking (108) whether the signal propagation time has exceeded a predetermined value, f1) repeating steps c) to e) with a delay value in each case compared to the previously set delay value(s) compared to the previously set delay values. Delay values ​​increased delay value(s) until the signal propagation time has exceeded the predetermined value, and h) storing and / or outputting (114) the last delay value(s) as determined limit value(s) for the direct connection at which the signal propagation time has not yet exceeded the predetermined value.

2. Method according to claim 1, further comprising, after the signal propagation time has exceeded the predetermined value for the first time in step f1): f2) repeating steps c) to e) with the previously set delay value or the previously set delay values ​​until the signal propagation time exceeds the predetermined value a previously determined number of attempts or repetitions in sequence has been exceeded, whereby, if the signal propagation time has fallen below the predetermined value again before the specified number of attempts or repetitions has been reached, the method is repeated with step c) and a further increased delay time.

3. The method according to claim 1 or 2, further comprising, after the signal propagation time has exceeded the predetermined value in step f1) or has exceeded a predetermined number of consecutive attempts or repetitions in step f2): - g2) Repeating steps c) to e) with a delay value or delay values ​​that are reduced compared to the previously set delay value or delay values, until the signal propagation time no longer exceeds the predetermined value.

4. Method according to claim 3, further comprising, after the signal propagation time has fallen below the predetermined value for the first time in step g2): g3) repeating steps c) to e) with the previously set delay value or the previously set delay values ​​until the signal propagation time has fallen below the predetermined value for a previously defined number of attempts or repetitions in succession, wherein, if the signal propagation time has exceeded the predetermined value again before the defined number of attempts or repetitions is reached, the method is repeated with step c) and a further reduced delay time.

5. The method according to claim 3 or 4, further comprising: - g1) initiating (104) and sending () without delay a message of a first type via the direct connection, to which a transmission time stamp is added or assigned in the transmitter and / or a reception time stamp is added or assigned in the receiver, after each delayed message whose signal propagation time has exceeded the predetermined value.

6. The method according to any one of claims 1 to 5, wherein the delayed transmission (106) comprises: - Encrypting a message sent immediately before a message of the first type, and / or - Encrypting at least the first type of messages after setting the transmission timestamp, and / or wherein the delayed receiving comprises: - Decrypting the message received immediately before a message of the first type, and / or - Decrypt at least the first type of messages before setting the reception timestamp.

7. The method of claim 6, wherein setting different delays comprises: - Encryption of at least the first type of messages with different encryption parameters.

8. A method (700) for detecting an intrusion into a direct connection between two network nodes (1, 2) of a system during operation, comprising: - cyclical or irregularly repeated initiation (104) of messages of the first type, to which a transmission time stamp is added or assigned in the sender and / or a reception time stamp in the receiver, - Delaying (106) at least the first type of messages after setting the transmission time stamp and before sending the message via the physical layer and / or after receiving the message via the physical layer and before setting the reception time stamp by a limit value determined in the method according to one of claims 1 to 6 or by limit values ​​for the direct connection determined in the method according to claims 1 to 6, - checking (108) whether the signal propagation time has exceeded a predetermined value, wherein, if the signal propagation time has exceeded a predetermined value, the method further comprises: - Signaling (704) that the limit value has been exceeded.

9. The method according to claim 8, wherein in response to the signaling (704) the system or at least one of the network nodes is placed in an error mode or the delay (106) is reduced at least for the first type of messages to a value at which the signal propagation time does not exceed a predetermined value.

10. The method according to claim 9, wherein the delaying (106) to a value at which the signal propagation time does not exceed a predetermined value comprises re-determining the limit value by means of a method according to one of claims 1 to 6.

11. Network node (900) configured to communicate with another network node via a direct connection (3), having at least one processor (902), volatile (904) and non-volatile (906) memory, and a network interface (908), wherein computer program instructions are retrievably stored in the non-volatile memory (906), which, when executed by the at least one processor, configure the network node (900) to execute a method for determining a limit value for the signal propagation time and / or for monitoring the integrity of the communication according to one of the preceding claims 1 to 10.

12. System, in particular vehicle system, with two or more network nodes each connected to one another via direct connections, wherein at least one of the network nodes is a network node (900) according to claim 11.

13. A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method according to one or more of claims 1 to 10.

14. A computer-readable medium on which the computer program product according to claim 13 is stored.