End-to-end integrity control of a communication flow

The method for end-to-end integrity control in time-sensitive networks addresses the robustness gap of TSN by using virtual identifiers and hash functions, ensuring secure and flexible communication compatible with various equipment types.

FR3143925B1Active Publication Date: 2025-10-24THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022013599
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-16
Publication Date
2025-10-24
Estimated Expiration
2042-12-16

AI Technical Summary

Technical Problem

Current time-sensitive Ethernet networks (TSN) fail to meet the robustness requirements of the ARINC 664 P7 standard, particularly in terms of network equipment malfunctions, and are limited to proprietary and expensive equipment, lacking support for cyclic redundancy check (CRC) recalculations and specific fault specifications.

Method used

Implement a method for end-to-end integrity control in time-sensitive networks using virtual identifiers and hash functions to ensure message integrity, involving a preliminary phase of virtual allocation, message transmission with counter increments, and reception phase with aggregate comparison to verify message integrity.

Benefits of technology

The solution provides robustness against network equipment malfunctions, reduces the risk of message interception, and allows for cost-effective, flexible network communication with integrity control, compatible with both proprietary and COTS equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000019_0000
    Figure 00000019_0000
  • Figure 00000020_0000
    Figure 00000020_0000
Patent Text Reader

Abstract

End-to-end integrity control of a communication flow The invention relates to a method (50) of such integrity control, comprising: - an allocation (52) of a virtual identifier, to each flow, known only to each transmitter or receiver, located at one end of the flow; - a transmission (60) by a transmitter at one end of a flow, of a message comprising the useful data, the value (SN) of the counter of messages sent, and a transmission aggregate (HASH) determined from the virtual identifier (VID) known to the transmitter, the value (SN), the useful data; - the reception (64) by a receiver, at the other end of said flow, of said message and the determination (66) of a reception aggregate (HASH') from the virtual identifier (VID') known to the receiver, the value (SN) received; the useful data received; - end-to-end integrity control (68) by comparison of said transmission and reception aggregates. Figure for the abstract: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: End-to-end integrity control of a communication flow

[0001] The present invention relates to a method for end-to-end integrity control of a communication flow communicated within a time-sensitive network.

[0002] The invention also relates to a computer program associated with said method.

[0003] The invention also relates to a communication port of a time-sensitive network, said communication port being a transmitter or receiver, and capable of being located at one end of a communication flow communicated within said time-sensitive network.

[0004] The invention also relates to a time-sensitive network (TSN).

[0005] The invention lies in the field of network communication, and more particularly of communication within an avionics network used in aeronautics.

[0006] Currently in this avionics field, only the solution based on the use of the ARINC 664 P7 standard as carried out within the Ethernet network called AFDX™ (from the English Avionics Full DupleX switched ethemet) makes it possible to have a redundant network communication system, which guarantees both: maximum jitter, that the content is authentic and capable of resisting repetitive emissions caused for example by a breakdown or a cyberattack causing for example a denial of service.

[0007] The developments in the Ethemet standards of the TSN (Time Sensitive Network) group of the IEEE address most of the needs in determinism, bandwidth guarantee and redundancy of an aeronautical network.

[0008] However, currently such time-sensitive Ethemet networks TSN fail to cover certain properties of the ARINC 664 P7 standard implemented within an AFDX™ network, namely the properties relating to robustness to malfunctions of network equipment, which remain incompletely covered.

[0009] More specifically, the ARINC 664 P7 standard implemented within an AFDX™ network requires in particular that a switch, having a Design Assurance Level (DAL) of level A, guarantees the transmission of frames without alteration, therefore without the capacity to re-calculate the cyclic redundancy check (CRC).

[0010] The ability to meet such a requirement associated with the AFDX™ network is very difficult to demonstrate within standard IT products, also called COTS (commercial off-the-shelf) products, which can reconstruct an Ethernet frame and have the CRC cyclic redundancy check calculation function for supporting certain protocols such as “VLAN tagging” of 1TEEE802.1Q.

[0011] In addition, the ARINC 664 P7 standard implemented within an AFDX™ network provides the specification of robustness capabilities to very specific faults such as the repetition, on the part of a transmitter, of the same frame or the discontinuity of a transmission sequence. Such a specification is not addressed within the Ethernet standards of the TSN (Time Sensitive Network) group of the IEEE.

[0012] The ARINC 664 P7 standard implemented within an AFDX™ network has the disadvantage of being implemented only by proprietary IT equipment compliant with the AFDX™ network, which is more expensive than COTS products and not optimal in terms of bandwidth.

[0013] The object of the invention is to remedy the drawbacks of the state of the art by proposing an alternative solution to AFDX™ network communication while also addressing the same requirements in terms of robustness to malfunctions of network equipment.

[0014] To this end, the invention proposes a method for end-to-end integrity control of a communication flow communicated within a time-sensitive network TSN, said time-sensitive network TSN being an avionics communication network, the method comprising:

[0015] - a preliminary phase of virtual allocation of a virtual identifier to each communication flow suitable for being communicated within said time-sensitive network TSN, said virtual identifier being known only to each communication port, transmitter or receiver, suitable for being located at one end of the communication flow;

[0016] - a message transmission phase implemented by a communication port transmitter located at one end of a communication flow, said transmission phase comprising the following steps, for each message transmitted within said flow:

[0017] - incrementing the value of a counter of messages sent;

[0018] - determining an integrity control emission aggregate obtained from:

[0019] - the virtual identifier of said communication flow known by said port of transmitter communication,

[0020] - the value of the counter of messages sent;

[0021] - the useful data to be transmitted;

[0022] - the transmission of said message, within said flow, said transmitted message comprising at minus said useful data, said value of the counter of messages sent, and said transmission aggregate;

[0023] - a phase of receiving said message implemented by a communication port receiver located at the other end of said communication flow, said receiver communication port comprising a counter of messages received, said reception phase comprising the following steps, for each message received:

[0024] - receiving said message, within said stream, said received message comprising at minus said useful data, said value of the counter of messages sent, and said transmission aggregate,

[0025] - determining an integrity control reception aggregate obtained from of :

[0026] - the virtual identifier of said communication flow known by said port of receiver communication,

[0027] - the value of the message counter sent, received within the message received;

[0028] - the useful data received;

[0029] - end-to-end integrity control by comparison of said transmission aggregate said receiving aggregate, a difference between said sending aggregate and said receiving aggregate activating the rejection of said received message, whereas conversely, when said sending aggregate and said receiving aggregate are identical, said received message is accepted.

[0030] Thus, the present invention proposes the adoption of an end-to-end principle, to verify that any communication within a communication flow within said time-sensitive network TSN is intact, firstly implementing a prior allocation of a virtual identifier to each communication flow (i.e. communication flow) capable of transiting within said network, this virtual identifier being known to each communication port, transmitter or receiver, capable of being located at one end of the communication flow.

[0031] It should be noted that during the transmission as such, such a virtual identifier is not transmitted and therefore does not transit through the network, unlike the message transmitted comprising at least said useful data, said value of the counter of messages transmitted, and said transmission aggregate.

[0032] It is therefore impossible to maliciously intercept such a virtual identifier during the transmission of a message or to imagine a failure making it possible to guess this identifier, which drastically reduces the risk of reconstituting the transmission aggregate, the transmission aggregate requiring, for its determination (i.e. its obtaining by calculation), to know this virtual identifier combined with the value of the transmitted message counter and the useful data.

[0033] The method for end-to-end integrity control of a communication flow communicated within a time-sensitive network TSN proposed according to the present invention may also have one or more of the characteristics below, taken independently or in all technically conceivable combinations:

[0034] - said transmission aggregate and said reception aggregate are obtained using the same aggregate determination function, said aggregate determination function providing only irreversible aggregates;

[0035] - said aggregate determination function is a hash function;

[0036] - said hash function is a SHA-1 function;

[0037] - said hash function is a SHA-2 function;

[0038] - the reception phase further comprises a step of checking the correctness sequencing according to which if said value of the sent message counter is equal to the current value of the received message counter plus one or plus two then the received message is also accepted, and the current value of the received message counter is then updated by becoming equal to said value of the sent message counter.

[0039] The invention also relates to a computer program comprising software instructions which, when executed by a computer, implement a method for end-to-end integrity control of a communication flow communicated within a time-sensitive network TSN as defined above.

[0040] Hereinafter, reference to a computer program which, when executed, performs any of the foregoing software instructions, is not limited to an application program running on a single host computer.

[0041] In other words, the terms computer program and software are used hereinafter in a general sense to refer to any type of computer code (e.g., application software, firmware, microcode, or any other form of computer instruction) that can be used to program one or more processors to implement the method of end-to-end integrity control of a communication flow communicated within a time-sensitive network TSN.

[0042] The invention also relates to a communication port of a time-sensitive network TSN, said communication port being a transmitter or receiver, and suitable for being located at one end of a communication flow communicated within said time-sensitive network TSN, said communication port comprising a set of elements dedicated to implementing at least in part the method for end-to-end integrity control of a communication flow according to any one of the preceding claims, said set of elements comprising:

[0043] - a memory storage space dedicated to storing a virtual identifier of each communication flow suitable for being communicated within said time-sensitive network TSN;

[0044] and at least one of the following two devices corresponding to:

[0045] - a device for transmitting message(s) configured to transmit at least one message within a communication flow, said transmission device comprising, for each message transmitted within said communication flow:

[0046] - a counter of messages sent whose value is configured to be incremented at each message sent;

[0047] - a module for determining an obtained integrity control emission aggregate from:

[0048] - the virtual identifier of said communication flow known by said port of communication in transmitter mode,

[0049] - the value of the message counter sent;

[0050] - the useful data to be transmitted;

[0051] - a module for transmitting said message, configured to transmit within said flow, said transmitted message comprising at least said useful data, said value of the transmitted message counter, and said transmission aggregate;

[0052] - a message receiving device configured to receive at least one message within another communication stream, said receiving device comprising, for each message received within said other communication stream:

[0053] - a counter of messages received;

[0054] - a module for receiving said message, configured to receive said message at within said other stream, said received message comprising at least its useful data, a value of the message counter sent, and a transmission aggregate,

[0055] - a module for determining an integrity control reception aggregate obtained from:

[0056] - the virtual identifier of said other communication stream,

[0057] - the value of the message counter sent, received within the message received;

[0058] - the useful data received;

[0059] - an end-to-end integrity control module configured to control end-to-end integrity by comparing said transmitting aggregate to said receiving aggregate, a difference between said transmitting aggregate and said receiving aggregate activating the rejection of said received message, whereas conversely, when said transmitting aggregate and said receiving aggregate are identical, said received message is accepted.

[0060] The communication port proposed according to the present invention may also have the characteristics according to which said set of elements, dedicated to implementing at least in part the end-to-end integrity control method of a communication flow according to any one of the preceding claims, is activatable / deactivatable.

[0061] The invention also relates to a time-sensitive network TSN, said time-sensitive network TSN being an avionics communication network and said network comprising at least two communication ports as described above.

[0062] Other characteristics and advantages of the invention will emerge from the description given below, for information purposes only and in no way limiting, with reference to the appended figures, among which:

[0063] [Fig-1] [Fig.l] schematically represents a communication port according to a embodiment of the invention;

[0064] [Fig.2] [Fig.2] is a flowchart of an end-to-end integrity control method at the end of a communication flow communicated within a time-sensitive network TSN according to an embodiment of the invention.

[0065] As indicated previously, [Fig.l] schematically represents a communication port 10 of a time-sensitive network TSN according to an embodiment of the invention.

[0066] Such a communication port 10 is suitable for being in transmitter mode or in receiver mode, and is suitable for being located at one end (i.e. at one end) of a communication flow communicated within said time-sensitive network TSN.

[0067] The communication port 10 according to the present invention comprises a set 12 of elements dedicated to implementing at least in part the end-to-end integrity control method of a communication flow as detailed below in relation to [Fig.2].

[0068] According to the present invention, said set 12 of elements firstly comprises a memory storage space 14 dedicated to the storage of a virtual identifier, subsequently called VID for a transmitting communication port (i.e. in transmitting mode) and VID' for a receiving communication port (i.e. in receiving mode), of each communication flow capable of being communicated within said time-sensitive network TSN.

[0069] Furthermore, said set 12 of elements comprises, when said communication port 10 is a transmitting communication port (i.e. in transmission mode), a device 16 for transmitting message(s) configured to transmit at least one message within a communication flow.

[0070] Such a transmission device 16 comprises, according to the present invention, for each message transmitted within said communication flow a counter 18 of messages transmitted whose value is configured to be incremented with each message transmitted. Subsequently, this value of the message counter transmitted is called SN (from the English Sequence Number).

[0071] In addition, such a transmission device 16 further comprises, according to the present invention, a module 20 for determining a transmission aggregate, hereinafter called HASH, for integrity control.

[0072] Such a HASH emission aggregate is obtained by the determination module 20 from (i.e. using) at least three distinct types of information corresponding to:

[0073] - the virtual identifier VID of said communication flow known by said port of communication in transmitter mode,

[0074] - the SN value of the sent message counter;

[0075] - the useful data of the message to be transmitted.

[0076] In addition, such a transmission device 16 further comprises, according to the present invention, a transmission module 22 as such of said message. More precisely, such a transmission module is configured to transmit within said stream, said transmitted message comprising at least said useful data, said SN value of the transmitted message counter, and said HASH transmission aggregate.

[0077] According to one aspect illustrated by [Fig.l], the electronic transmission device 16 comprises an information processing unit 24 formed for example by a memory 26 and a processor 28 associated with the memory 26.

[0078] According to a particular example, the counter 18 of messages sent, and the module 20 for determining a transmission aggregate are each produced in the form of software, or a software brick, executable by the processor 28 of the electronic transmission device 16 according to the present invention. The memory 26 of the electronic transmission device 16 is then capable of storing software for counting messages sent and software for determining a transmission aggregate. The processor 28 is then capable of executing each of these software programs.

[0079] In a variant not shown, the counter 18 of messages sent, and the module 20 for determining a transmission aggregate are each produced in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array) or in the form of a dedicated integrated circuit, such as an ASIC (Application Specific Integrated Circuit).

[0080] When the electronic transmission device 16 is produced in the form of one or more software programs, that is to say in the form of a computer program, it is also capable of being recorded on a medium, not shown, readable by a computer. The computer-readable medium is for example a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. By way of example, the readable medium is an optical disk, a magneto-optical disk, a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, MVRAM), a magnetic card or an optical card. A computer program comprising software instructions is then stored on the readable medium.

[0081] In addition, said set 12 of elements comprises, when said communication port 10 is a receiving communication port (i.e. in reception mode), a device 30 for receiving message(s) configured to receive at least one message within another communication flow (i.e. distinct from a communication flow whose communication port is, for example in parallel, also a transmitter).

[0082] The electronic reception device 30 comprises, for each message received within said other communication flow, first of all a counter 32 of messages received.

[0083] In addition, the electronic receiving device 30 also comprises a module 34 for receiving said message. The receiving module 34 is configured to receive said message within said other stream, said received message comprising at least its useful data, an SN value of the message counter sent associated with said received message, and a HASH transmission aggregate also associated with said received message.

[0084] Furthermore, the electronic reception device 30 also comprises a module 36 for determining an integrity control HASH' reception aggregate.

[0085] Such a HASH' reception aggregate is obtained by the determination module 36 from (i.e. using) at least three distinct types of information corresponding to

[0086] - the virtual identifier VID' of said other communication flow known by said port of communication in receiver mode,

[0087] - the SN value of the message counter sent, received within the message received;

[0088] - the useful data received from the received message.

[0089] In addition, the electronic receiving device 30 also comprises an end-to-end integrity control module 38 configured to control the end-to-end integrity by comparing said HASH transmission aggregate to said HASH' reception aggregate, a difference between said HASH transmission aggregate and said HASH' reception aggregate activating the rejection of said received message, whereas conversely, when said HASH transmission aggregate and said HASH' reception aggregate, said received message is accepted.

[0090] As an optional addition, the electronic reception device 30 further comprises a good sequencing control module 40 configured to determine whether said value SN of the counter of messages sent is equal to the current value SN' of the counter of messages received plus one or plus two (i.e. such that SN = SN'+1 or such that SN = SN'+2), and then to accept said message received, the value SN' of the counter of messages received then being updated by becoming equal to said value SN of the counter of messages sent. If the good sequencing control module 40 on the contrary detects that SN SN'+l or SN SN'+2 to be tolerant to the loss of a message, the received message is rejected.

[0091] In other words, as soon as HASH HASH' the message is rejected for lack of integrity.

[0092] If HASH = HASH', but SN SN'+1 or SN SN'+2, then the message is also rejected for lack of sequence.

[0093] It should be noted that in the particular case of restarting (i.e. resetting) the electronic reception device 30, the value SN' is initialized by the value SN of the first message received after said restarting (i.e. resetting) and no check of correct sequencing is then implemented for this first message received after said restarting (i.e. resetting).

[0094] In other words, when no message has been received, SN' is not yet initialized, and the first message received with said SN value of the sent message counter is accepted by default.

[0095] According to one aspect illustrated by [Fig.l], the electronic reception device 30 comprises an information processing unit 42 formed for example of a memory 44 and a processor 46 associated with the memory 44.

[0096] According to a particular example, the counter 32 of received messages, the module 36 for determining a reception aggregate, the module 38 for end-to-end integrity control, and optionally the module 40 for checking good sequencing are each produced in the form of software, or a software brick, executable by the processor of the device according to the present invention. The memory 44 of the electronic reception device 30 is then capable of storing software for counting received messages, software for determining a reception aggregate, software for checking end-to-end integrity, and optionally software for checking good sequencing. The processor 46 is then capable of executing each of these software programs.

[0097] In a variant not shown, the counter 32 of messages received, the module 36 for determining a reception aggregate, the module 38 for end-to-end integrity control, and optionally the module 40 for controlling good sequencing are each produced in the form of a programmable logic component, such as an FPGA (Field Programmable Gate Array), or in the form of a dedicated integrated circuit, such as an ASIC (Application Specific Integrated Circuit).

[0098] When the electronic receiving device 30 is produced in the form of one or more software programs, i.e. in the form of a computer program, it is also capable of being recorded on a medium, not shown, that is readable by a computer. The computer-readable medium is, for example, a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. By way of example, the readable medium is an optical disk, a magneto-optical disk, a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, MVRAM), a magnetic card or an optical card. A computer program containing software instructions is then stored on the readable medium.

[0099] As an optional addition, said transmission aggregate and said reception aggregate are obtained using the same aggregate determination function, said aggregate determination function providing only irreversible aggregates.

[0100] According to an advantageous option of this optional complement, said aggregate determination function is a hash function.

[0101] According to a first optional variant, said hash function is a SHA-1 function, for example 80 bits long.

[0102] According to a second optional variant, said hash function is a SHA-2 function, for example 112 bits long, or a SHA-2 function of type SHA-256, SHA-512, SAH-224, SHA-384 etc.

[0103] It should be noted that to date such SHA hash functions are not integrated into the UDP / IP and Ethernet protocols used, and that such an implementation is therefore not obvious to those skilled in the art.

[0104] As an optional addition, said set of elements 12, dedicated to implementing at least in part the end-to-end integrity control method of a communication flow as described below in relation to [Fig.2], can be activated / deactivated for certain flows in order to enable communication with network elements incapable of implementing such an end-to-end integrity control method.

[0105] In [Fig. 1], such an option is illustrated by the element 48 capable of activating or not via a set of switches the elements of said set 12, which allows the communication port to participate in the implementation of the end-to-end integrity control method according to the present invention, or in the event of inactivation of said set 12 to operate conventionally (i.e. without integrity control according to the present invention, but with a conventional integrity control of the CRC type, unsuitable for taking into account the failure of a switch for example which would recalculate it).

[0106] It should be noted that the element 48 also makes it possible to activate the transmitter mode or the receiver mode of the communication port by making respectively, the electronic transmission device 16 active and the electronic reception device 30 inactive for the transmitter mode, and conversely the electronic transmission device 16 inactive and the electronic reception device 30 active for the receiver mode, when these two modes are not implemented in parallel for the communication of two distinct flows where the communication port of [Fig.l] is both the transmitter of a first communication stream and receiver of a second communication stream distinct from the first communication stream.

[0107] According to other variants not shown, the communication port 10 is only a transmitter (i.e. in transmission mode only) and in this case does not include the reception device 30 previously described, or the communication port 10 is only a receiver (i.e. in reception mode only) and in this case does not include the transmission device 16 previously described.

[0108] Furthermore, according to another variant not shown, each time the communication port is “single-mode” the memory storage space 14 is then integrated within the transmission device 16 if the communication port 10 is only a transmitter (i.e. in transmission mode only), or is integrated within the reception device 30 if the communication port 10 is only a receiver (i.e. in reception mode only).

[0109] As an alternative to [Fig. 1], when the communication port is “dual-mode”, i.e. to operate as a transmitting communication port and as a receiving communication port, the memory storage space 14 is not common to the transmitting 16 and receiving 30 devices as illustrated according to the embodiment of [Fig. 1], but integrated into each of these two transmitting 16 and receiving 30 devices respectively.

[0110] An example of operation of an end-to-end integrity check of a communication flow communicated within a time-sensitive network TSN according to an embodiment of the invention is now described below in relation to [Fig. 2], said time-sensitive network TSN being in particular an avionics network comprising at least two communication ports as described previously in relation to [Fig. 1].

[0111] More precisely, the method 50 for maintaining the integrity of the end-to-end positioning of a communicated communication flow implemented within said time-sensitive network TSN firstly comprises a first preliminary phase 52 of virtual allocation A_VID of a virtual identifier to each communication flow suitable for being communicated within said time-sensitive network TSN, said virtual identifier being known only to each communication port, transmitter or receiver, suitable for being located at one end of the communication flow and stored within the dedicated memory storage space 14 as illustrated in relation to [Fig.l].

[0112] For example, a communication flow Fi corresponds to a data flow, between a first transmitting communication port Pi (i.e. in transmission mode), at one end of the data flow FB and a second receiving communication port P2 at the other. end of the data stream Fi and is identified with the VID=VID'= 63, while a communication stream corresponding to a video stream F2 between these same two ports Pi and P2 is identified with a distinct identifier such as VID=VID'= 65.

[0113] According to another example, another communication flow F3 corresponds to a data flow between the first transmitting communication port Pi (i.e. in transmission mode), at one end of the data flow F3, and a receiving communication port P3 at the other end of the data flow F3 and is identified with the VID=VID'= 91, etc.

[0114] Then, for each message to be sent, the method 50 for maintaining the end-to-end integrity of a communication flow comprises a phase 54 of sending E a message implemented by a sending communication port (i.e. in sending mode) located at one end of the communication flow considered.

[0115] Phase 54 of transmission E notably comprises the steps described below, for each message transmitted within said flow considered.

[0116] A first step 56 of incrementing I_SN of the value SN of a counter 18 of messages sent is implemented by the sending communication port (i.e. in sending mode) located at one end of the communication flow considered.

[0117] Then, according to a step 58, the transmitting communication port (i.e. in transmission mode), located at one end of the communication flow considered, implements, via its determination module 20, the determination D_HASH of an integrity control transmission HASH aggregate obtained from a triplet of elements of a distinct nature, namely the virtual identifier VID of said communication flow known by said transmitting communication port (i.e. in transmission mode), the value SN of the message counter sent, and the useful data (from the English payload) to be transmitted as such within said message.

[0118] Then according to a step 60, the transmitting communication port (i.e. in transmission mode), located at one end of the communication flow considered, implements, via its transmission module 22, the transmission EM as such of said message, within said flow, said transmitted message comprising at least said useful data, said value SN of the transmitted message counter, and said transmission aggregate HASH.

[0119] A phase 62 of reception R of said message is implemented by a receiver communication port (i.e. in reception mode) located at the other end of said communication flow, said receiver communication port (i.e. in reception mode) comprising, as seen previously in relation to [Fig.l], a counter 32 of messages received.

[0120] Said reception phase 62 R comprises the steps described below, for each message received described in said flow considered.

[0121] First of all, within this phase 62, a first step 64 of reception RM of said message, within said flow is implemented, said received message comprising at least, as indicated previously, said useful data (i.e. payload), said value SN of the counter 18 of messages sent, and said HASH transmission aggregate.

[0122] Then, according to a step 66, the receiving communication port (i.e. in reception mode) located at the other end of said communication flow implements, via its determination module 36, the determination D_HASH' of a reception aggregate HASH' of integrity control obtained from a triplet of elements of a distinct nature, namely: the virtual identifier VID' of said communication flow known by said receiving communication port (i.e. in reception mode), the value SN, of the counter of messages sent, received within the message received, and the useful data received.

[0123] The reception phase 62 then comprises a step 68, implemented by the receiving communication port (i.e. in reception mode) located at the other end of said communication flow, via its control module 38, of end-to-end integrity control C_I by comparison of said transmission aggregate HASH with said reception aggregate HASH'.

[0124] Indeed, in the event of integrity, the virtual identifier of the VID flow known and stored on the sending communication port side (i.e. in sending mode) is identical to the VID' stored on the receiving communication port side (i.e. in receiving mode), this flow identifier advantageously never transiting as such within the network when sending a message, which drastically reduces the risk of accidental reconstitution of a correct control aggregate from data corrupted during transport.

[0125] Consequently, in the event of integrity, for the same message transmitted via said communication flow considered, the HASH transmission aggregate is identical to said HASH' reception aggregate, and the corresponding received message is accepted (i.e. retained).

[0126] On the other hand, during said comparison step 68, a difference between said transmission aggregate HASH and said reception aggregate HASH' activates the rejection of said received message. In other words, if the integrity check fails because HASH^ HASH' then the message is ignored due to an integrity defect.

[0127] According to a particular variant, said HASH transmission aggregate and said HASH' reception aggregate are obtained using the same aggregate determination function, said aggregate determination function providing only irreversible aggregates.

[0128] According to an advantageous option of this optional supplement, said aggregate determination function is a hash function. Such a hash function is dissimilar to the cyclic redundancy check (CRC) function (from the English Cyclic Redundancy Checky), notably used elsewhere conventionally to check the integrity of frames.

[0129] Among the hash functions, the algorithms of the SHA (Secure Hash Algorithm) family make it possible to meet the need to obtain irreversible aggregates, with SOC (System On Chip) systems now providing hardware acceleration of these hash functions, particularly cryptographic ones, which makes them easier to use.

[0130] According to a first optional variant, said hash function is a SHA-1 function, for example 80 bits long.

[0131] According to a second optional variant, said hash function is a SHA-2 function, for example 112 bits long, or a SHA-2 function of type SHA-256, SHA-512, SAH 224, SHA-384 etc., the size of the hash value having to result from a compromise with the cost on the size of the useful data (size of the payload).

[0132] As an optional addition, the reception phase 62 also comprises a step 70 for checking good sequencing according to which if said value SN of the counter of messages sent is equal to the value SN' of the counter of messages received plus one or plus two, (i.e. SN=SN'+1 or SN=SN'+2) then the message received is also accepted, and the value SN' of the counter of messages received is then updated by becoming equal to said value SN of the counter of messages sent. Such an option makes it possible to use the value received SN of the counter of messages sent to check good sequencing, in addition to the integrity check previously described, and thus to resynchronize quickly by losing only a single message, the message received corresponding to a continuous evolution of sequence so that it is accepted.

[0133] On the other hand, if SN^SN'+1 or SN SN'+2 then the received message is rejected due to sequencing error.

[0134] Those skilled in the art will understand that the invention is not limited to the embodiments described, nor to the particular examples of the description, the embodiments and variants mentioned above being suitable for being combined with each other to generate new embodiments of the invention.

[0135] The present invention thus proposes a network communication solution adapted to avionics requirements by taking advantage of the benefits of a time-sensitive network TSN, in terms of cost and bandwidth while being robust to malfunctions of network equipment.

[0136] Furthermore, the adoption of the end-to-end principle proposed according to the present invention, which distributes, optionally in an activatable / deactivatable manner, the integrity control only on the transmitting and receiving communication ports of the network located at each end of the communication flow, further allows the coexistence of traffic with integrity control and traffic without integrity control, increasing the level of flexibility of use of the network.

Claims

1. Claims Method (50) for end-to-end integrity control of a communication flow communicated within a time-sensitive network TSN, said time-sensitive network TSN being an avionics communication network, the method comprising: - a preliminary phase of virtual allocation (52) of a virtual identifier to each communication flow capable of being communicated within said time-sensitive network TSN, said virtual identifier being known only to each communication port, transmitter or receiver, capable of being located at one end of the communication flow; - a message transmission phase (54) implemented by a transmitting communication port located at one end of a communication flow, said transmission phase comprising the following steps, for each message transmitted within said flow: - incrementing (56) the value of a counter of messages sent; - the determination (58) of an integrity control emission aggregate (HASH) obtained from: - the virtual identifier (VID) of said communication flow known by said transmitting communication port, - the value (SN) of the counter of messages sent; - the useful data to be transmitted; - the transmission (60) of said message, within said flow, said transmitted message comprising at least said useful data, said value (SN) of the counter of messages transmitted, and said transmission aggregate (HASH); - a reception phase (62) of said message implemented by a receiver communication port located at the other end of said communication flow, said receiver communication port comprising a counter of messages received, said reception phase comprising the following steps, for each message received: - the reception (64) of said message, within said flow, said received message comprising at least said useful data, said value (SN) of the counter of messages sent, and said transmission aggregate (HASH), - the determination (66) of a reception aggregate (HASH') of integrity control obtained from: - the virtual identifier (VID') of said communication flow known by said receiving communication port, - the value (SN), of the message counter sent, received within the received message; - the useful data received; - the end-to-end integrity control (68) by comparison of said transmission aggregate (HASH) with said reception aggregate (HASH'), a difference between said transmission aggregate (HASH) and said reception aggregate (HASH') activating the rejection of said received message, whereas conversely, when said transmission aggregate (HASH) and said reception aggregate (HASH') are identical, said received message is accepted.

2. A method (50) for end-to-end integrity control of a communication flow according to claim 1, wherein said transmit aggregate and said receive aggregate are obtained using the same aggregate determination function, said aggregate determination function providing only irreversible aggregates.

3. A method (50) for end-to-end integrity control of a communication flow according to claim 2, wherein said aggregate determination function is a hash function.

4. Method (50) for end-to-end integrity control of a communication flow according to claim 3, wherein said hash function is a SHA-1 function.

5. Method (50) for end-to-end integrity control of a communication flow according to claim 3, wherein said hash function is a SHA-2 function.

6. Method (50) for end-to-end integrity control of a communication flow according to any one of the preceding claims, in which the reception phase further comprises a step (70) of correct sequencing control according to which if said value (SN) of the counter of messages sent is equal to the current value (SN') of the counter of messages received plus one or plus two then the message received is also accepted, and the current value (SN') of the counter of messages received is then updated by becoming equal to said value (SN) of the counter of messages sent.

7. A computer program comprising software instructions which, when executed by a computer, implement implements the method for end-to-end integrity control of a communication flow according to any one of the preceding claims.

8. Communication port (10) of a time-sensitive network TSN, said communication port being a transmitter or receiver, and suitable for being located at one end of a communication flow communicated within said time-sensitive network TSN, said communication port being characterized in that it comprises a set of elements dedicated to implementing at least in part the method for end-to-end integrity control of a communication flow according to any one of the preceding claims 1 to 6, said set of elements comprising: - a memory storage space (14) dedicated to storing a virtual identifier of each communication flow suitable for being communicated within said time-sensitive network TSN;and at least one of the following two devices corresponding to: - a message(s) transmission device (16) configured to transmit at least one message within a communication flow, said transmission device comprising, for each message transmitted within said communication flow: - a counter (18) of messages transmitted whose value is configured to be incremented with each message transmitted; - a module for determining (20) an integrity control transmission aggregate (HASH) obtained from: - the virtual identifier (VID) of said communication flow known by said communication port in transmitter mode, - the value (SN) of the message counter transmitted; - the useful data to be transmitted; - a module for transmitting (22) said message, configured to transmit within said flow, said message transmitted comprising at least said useful data, said value (SN) of the message counter transmitted, and said transmission aggregate (HASH);- a device (30) for receiving message(s) configured to receive at least one message within another communication flow, said receiving device comprising, for each message received within said other communication flow: - a counter (32) of messages received; - a module (34) for receiving said message, configured to receive said message within said other stream, said received message comprising at least its useful data, a value (SN) of the message counter sent, and a transmission aggregate (HASH), - a module for determining (36) a reception aggregate (HASH') of integrity control obtained from: - the virtual identifier (VID') of said other communication flow, - the value (SN), of the counter of messages sent, received within the message received; - the useful data received; - an end-to-end integrity control module (38) configured to control the end-to-end integrity by comparing said transmission aggregate (HASH) with said reception aggregate (HASH'), a difference between said transmission aggregate (HASH) and said reception aggregate (HASH') activating the rejection of said received message, whereas conversely, when said transmission aggregate (HASH) and said reception aggregate (HASH') are identical, said received message is accepted.

9. Communication port (10) according to claim 8 wherein said set of elements, dedicated to implementing at least in part the method of end-to-end integrity control of a communication flow according to any one of the preceding claims 1 to 6, is activatable / deactivatable.

10. Time sensitive network TSN characterized in that said time sensitive network TSN is an avionics communication network and in that said network comprises at least two communication ports according to claim 8 or 9.