Automotive network switch with fault detection

The network switch with embedded processors and ML accelerators detects anomalies in automotive networks by analyzing packet patterns, addressing fault detection challenges and enhancing system reliability.

JP2026003625APending Publication Date: 2026-01-13INFINEON TECHNOLOGIES AMERICAS CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025152573
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2019-06-25
Filing Date
2025-09-12
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing communication systems in automotive, industrial, and smart home networks face challenges in detecting anomalies in high-data-rate communication over short distances, particularly in identifying faults in electronic subsystems through packet analysis.

Method used

An automotive network switch equipped with processors and a machine learning accelerator analyzes packets to identify anomalies, such as statistically deviant patterns, and sends health scores to a central processing unit, distributing the analysis load across multiple switches.

Benefits of technology

The solution effectively identifies existing or impending faults in electronic subsystems by analyzing packet patterns, offloading central computers, and simplifying switch operations while integrating seamlessly with existing automotive architectures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026003625000001_ABST
    Figure 2026003625000001_ABST
Patent Text Reader

Abstract

To provide an automobile network switch and a method for identifying the abnormality of an electronic subsystem on a computer network arranged in a vehicle, and for notifying an external central processing unit of the abnormality.SOLUTION: The vehicle network switch 32 may include a plurality of ports 48, a switch core 52, and one or more processors 54, 56. The port receives packets from the electronic subsystem 28 over the computer network 20 deployed in the vehicle 24 and transmits packets to other electronic subsystems in the vehicle over the computer network. The switch core receives packets from one or more of the ports, forwards the packets to at least one of the ports, and transmits the packets over the computer network. The processor parses the captured packets to identify anomalies in one or more of the vehicle's electronic subsystems and notifies a central processing unit 60 external to the switch of the anomalies.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims the benefit of U.S. Provisional Patent Application No. 62 / 866,285, filed June 25, 2019, the disclosure of which is incorporated herein by reference.

[0002] The present disclosure relates generally to communication systems, and more particularly to a method and system for anomaly detection in a network switch. [Background technology]

[0003] Various applications, such as in-vehicle automotive communication systems, certain industrial communication systems, and smart home systems, require communication at high data rates over relatively short distances. Several types of protocols and communication media have been proposed for such applications. For example, Ethernet communication over twisted-pair copper media is specified in IEEE 802.3bw-2015 - IEEE Standard for Ethernet Amendment 1: Physical Layer Specifications and Management Parameters for 100 Mb / s Operation over a Single Balanced Twisted Pair Cable (100BASE-T1) of March 2015.

[0004] The foregoing is provided as a general overview of the related art in this field and should not be construed as an admission that any of the information it contains constitutes prior art to the present patent application.

[0005] Summary of the Invention One embodiment described herein provides an automotive network switch including a plurality of ports, a switch core, and one or more processors. The ports are configured to receive packets from electronic subsystems of the vehicle over a computer network deployed in the vehicle and to transmit packets to other electronic subsystems of the vehicle over the computer network. The switch core is configured to receive packets from one or more of the ports, forward the packets to at least one of the ports, and transmit the packets over a network link of the computer network. The one or more processors are configured to capture at least some of the packets processed by the switch, analyze the captured packets to identify anomalies in one or more of the electronic subsystems of the vehicle, and send a notification of the anomaly over the computer network to a central processing unit external to the switch.

[0006] In one embodiment, the one or more processors are configured to generate a health score that quantifies the severity of the anomaly and report the health score in the notification. In an exemplary embodiment, in analyzing the captured packets, the one or more processors are configured to identify existing anomalies or predict impending anomalies. In a disclosed embodiment, at least one of the electronic subsystems includes a sensor, the port is configured to receive at least a portion of the packets from the sensor, and the one or more processors are configured to identify abnormal functioning of the sensor.

[0007] In some embodiments, the one or more processors are configured to identify anomalies in response to detecting statistically deviant patterns of packet attributes, where in various embodiments the statistically deviant patterns include one or more of statistically deviant packet drops, statistically deviant packet rates, statistically deviant delays, and statistically deviant inter-packet intervals.

[0008] In some embodiments, the one or more processors are configured to execute a machine learning model configured to detect anomalies. In one embodiment, the one or more processors are configured to count events related to packets and detect anomalies based on the counted events. In disclosed embodiments, at least one of the one or more processors includes a machine learning (ML) accelerator located in the switch separate from a switch central processing unit (CPU) or a switch graphics processing unit (GPU).

[0009] In some embodiments, the one or more processors are configured to select one or more packet streams from among the plurality of packets processed by the switch according to predefined selection criteria and to identify anomalies by analyzing packets in the selected packet streams. In an exemplary embodiment, the one or more processors are configured to select the one or more packet streams by performing one or more of: (i) inspecting one or more header fields of one or more of the packets; and (ii) applying deep packet inspection (DPI) to one or more of the packets.

[0010] According to one embodiment described herein, there is additionally provided a method for anomaly detection in a vehicle. The method includes, at an automotive network switch in the vehicle, receiving packets from electronic subsystems of the vehicle over a computer network deployed in the vehicle and transmitting the packets over the computer network to other electronic subsystems of the vehicle. At least a portion of the packets processed by the switch are analyzed by the switch to identify anomalies in one or more of the electronic subsystems of the vehicle. A notification of the anomaly is sent from the switch over the computer network to a central processing unit external to the switch.

[0011] The present disclosure will be more fully understood from the following detailed description of embodiments of the disclosure, taken in conjunction with the drawings. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a block diagram that schematically illustrates an automotive communication system, according to one embodiment described herein.

[0013] [Figure 2] FIG. 2 is a diagram that schematically illustrates the collection of packet-related events per port in a network switch, according to one embodiment described herein.

[0014] [Figure 3] 2 is a flow chart that schematically illustrates a method for anomaly detection in a network switch of the communication system of FIG. 1 using machine learning (ML), according to one embodiment described herein. DETAILED DESCRIPTION OF THE INVENTION

[0015] The embodiments described herein provide improved methods and systems for condition monitoring for use in electronic systems having subsystems that exchange communication packets with each other. The disclosed techniques identify existing or impending faults in the electronic subsystems by detecting anomalies in the packets.

[0016] The embodiments disclosed herein are described in the context of automotive applications, such as systems for collecting data from sensors or communicating data within a vehicle. However, this choice is made solely for the sake of clarity. The disclosed techniques are equally applicable to other applications, such as in industrial networks and / or smart home networks.

[0017] In some disclosed embodiments, a vehicle has multiple electronic subsystems, such as sensors, various types of electronic control units (ECUs), advanced driver assistance systems (ADAS), in-vehicle infotainment (IVN) systems, a main central computer, etc. The electronic subsystems communicate over a computer network, such as, for example, an Ethernet network. The network has multiple network switches that communicate with each other and the various subsystems over network links, such as, for example, twisted-pair copper links.

[0018] In many practical scenarios, it is possible to identify existing or impending faults in electronic subsystems by detecting anomalies in network packets transmitted or received over a network link. For example, a faulty sensor may be identified by detecting an excessive rate of dropped packets or a statistically deviant packet rate.

[0019] In some embodiments described herein, the task of detecting anomalies in communication traffic is delegated to one or more of the network switches in the network. Typically, but not necessarily, anomaly detection is distributed among multiple network switches.

[0020] In an exemplary embodiment, the network switch includes, among other components, one or more processors configured to analyze at least a portion of packets processed by the switch and, based on the analyzed packets, identify anomalies in one or more of the vehicle's electronic subsystems. Upon identifying an anomaly, for example, through statistical analysis of network traffic, the processor(s) are configured to send a notification of the anomaly over the network to a central processing unit external to the switch. The notification may include, for example, a "health score" that quantifies the severity of the anomaly. The central processing unit is configured to receive the health scores from the various network switches and, in response to the health score, take appropriate action.

[0021] In one non-limiting embodiment, each network switch has an embedded CPU and a machine learning (ML) accelerator. The embedded CPU receives selected packet streams to be processed by the switch, performs specific preparations on the packet streams, and sends the packet streams to the ML accelerator. The ML accelerator analyzes the packet streams to execute suitable ML interference models that identify faults in the subsystems.

[0022] An ML interference model may be trained to detect, for example, statistically deviant patterns of packets, preferably based on, for example, one or more packets that are corrupted in some manner, one or more packets that deviate from predetermined policy rules, one or more packets that are dropped, one or more packets that are not dropped but are corrupted in a particular manner, etc. In some models, absolute quantities of packets are considered, while other models consider rates and / or percentages of packets that exhibit different characteristics. In some models, one or more characteristic signatures, which may be seen, for example, in a scatter plot defined by plotting two or more packet characteristics, are generated and then analyzed to determine the presence of anomalies.

[0023] Analyzing packet streams and identifying anomalies in network switches is highly effective for several reasons. First, network switches are located at the "network edge," near the sensors or other subsystems being monitored. Furthermore, the disclosed solution enables distribution of analysis tasks among multiple switches, thereby offloading a central computer and simplifying the operation of each individual switch. The disclosed distributed solution integrates naturally with current automotive system architectures, where a vehicle is divided into multiple zones served by different "zone ECUs" and different switches.

[0024] FIG. 1 is a block diagram that schematically illustrates an automotive communication system deployed in a vehicle 24, according to one embodiment described herein.

[0025] The vehicle 24 includes multiple electronic subsystems 28 of various types. Some of the subsystems 28 include sensors, such as video cameras, speed sensors, accelerometers, audio sensors, infrared sensors, radar sensors, LiDAR sensors, ultrasonic sensors, range finders or other proximity sensors, and / or any other suitable type of sensor. Other subsystems 28 include, for example, advanced driver assistance systems (ADAS) and / or in-vehicle infotainment (IVN) systems. Still other subsystems 28 include electronic control units (ECUs) that control vehicle elements such as the engine, body, steering, etc. Additionally or alternatively, the vehicle 24 may include any other suitable type of electronic subsystem 28.

[0026] In some embodiments, the vehicle 24 is divided into multiple zones, with the subsystems 28 in each zone controlled by a respective "zone ECU" 40. The various zone ECUs 40 communicate with a central computer 44 in the vehicle 24.

[0027] The electronic subsystems 28, ECU 40, and central computer 44 communicate with each other by sending and receiving communication packets over a computer network 20. In this example, the network 20 operates in accordance with one of the IEEE 802.3 Ethernet standards, such as IEEE 802.3bw-2015, cited above. The network 20 includes a plurality of automotive network switches 32, which in this example are Ethernet switches. Communication between the plurality of switches 32, between the switches 32 and the ECU 40, and between the ECU 40 and the subsystems 28 occurs over network links 36. Depending on the applicable Ethernet standard, the links 36 may include any suitable physical medium, such as, for example, twisted-pair copper links, optical links, and waveguides.

[0028] The inset at the bottom of Figure 1 shows the internal structure of an exemplary switch 32 in one embodiment. In some embodiments, all switches 32 in network 20 have a similar internal structure. In other embodiments, only a subset of switches 32, possibly only a single switch 32, has this structure.

[0029] In this example, the switch 32 includes multiple ports 48, a switch core 52, an embedded CPU 54, and a machine learning (ML) accelerator 56. The multiple ports 48 are connected to respective links 36, which connect the switch 32 to subsystems 28, to other switches 32, and / or to a higher-level computer 60 (e.g., a CPU or GPU), such as a zone ECU 40 or a central computer 44. Thus, the ports 48 are configured to send and receive packets over the network 20 to and from other system components. The switch core 52 is configured to forward packets across the multiple ports to send each received packet to its appropriate destination. The embedded CPU 54 is configured to configure and control the operation of the switch 32. The embedded CPU 54 may include, for example, an ARM processor or other suitable processor.

[0030] The system configuration of FIG. 1 and its elements and the internal structure of the network switch 32 as shown in FIG. 1 are exemplary configurations illustrated solely for clarity. In alternative embodiments, any other suitable configuration may be used. For example, the network 20 may have any suitable number of switches 32, possibly a single switch 32, and any other suitable interconnection topology. The number and types of subsystems 28 and ECUs 40 in the vehicle 24 may vary. For clarity, elements not essential to an understanding of the disclosed technology have been omitted from the figures.

[0031] 1 and its various components may be implemented using dedicated hardware or firmware, such as using hardwired or programmable logic in an application-specific integrated circuit (ASIC) or field-programmable gate array (FPGA). In some embodiments, for example, the entire automotive network switch 32 is implemented on a system-on-chip (SoC). Additionally or alternatively, some functionality, such as that of the embedded CPU 54 and / or ML accelerator 56, may be implemented in software and / or using a combination of hardware and software elements.

[0032] In some embodiments, the CPU 54 and / or the ML accelerator 56 comprise a programmable processor that is programmed in software to perform the functions described herein. For example, the software may be in electronic form and downloaded to any of the processors over a network, or alternatively or additionally, the software may be provided and / or stored on a non-transitory, tangible medium, such as magnetic, optical, or electronic memory.

[0033] In some embodiments, the embedded CPU 54 and the ML accelerator 56 are configured to analyze at least a portion of the packets processed by the switch 32. By analyzing the packets, the embedded CPU 54 and the ML accelerator 56 identify anomalies that may indicate existing or impending faults in subsystems of the vehicle 24.

[0034] Note that while the embodiments described herein refer to a specific "division of labor" between the embedded CPU 54 and the ML accelerator 56, this partitioning is by no means required. In alternative embodiments, packet analysis and anomaly detection may be partitioned between the embedded CPU 54 and the ML accelerator 56 in any other suitable manner. Further alternatively, packet analysis and anomaly detection may be performed by any other suitable configuration of one or more processors. For example, in some embodiments, packet analysis and anomaly detection are performed by the embedded CPU 54 alone, e.g., with the ML accelerator omitted, using a relatively simple interference model.

[0035] In the present context, the term "packet anomaly" refers to any pattern, attribute, content, and / or other characteristic(s) of a packet or packet stream that deviates from the baseline. Some exemplary anomalies include statistically deviant patterns in one or more attributes of packets originating from a particular subsystem 28. For example, Statistically deviant dropping of packets, for example, the percentage of dropped packets that deviates from the expected baseline drop rate by more than a certain threshold percentage or by more than a certain threshold percentage. Statistically deviant packet rates, such as packet rates that drop below a certain threshold rate or that deviate from the expected baseline rate by more than a certain threshold percentage. Statistically deviant packet delays, for example, delays that deviate from the expected baseline delay by more than a particular threshold delay or by more than a particular threshold percentage. Statistically deviant inter-packet intervals, for example, intervals that deviate from the expected baseline inter-packet interval by more than a particular threshold interval or by more than a particular threshold percentage.

[0036] In alternative embodiments, the embedded CPU 54 and ML accelerator 56 may identify any other suitable anomalies in packets processed by the switch 32, which may indicate an existing or impending failure.

[0037] In a typical embodiment, the embedded CPU 54 and ML accelerator 56 may monitor and establish expected baseline packet statistics (e.g., packet rate per source subsystem, packet drop rate per source subsystem or per port, etc.) This baseline is then used to identify deviations.

[0038] In various embodiments, the embedded CPU 54 and ML accelerator 56 detect various types of anomalies, which may indicate various existing or impending failures. For example, sensors can become contaminated, sensors can become unplugged, or connectors can become loose over time, a vehicle can pass through an area of ​​unexpected electromagnetic interference (e.g., an extreme thunderstorm), or engine problems can cause interference that affects packets. Some failures are "hard failures," such as the complete failure of a sensor. Other failures, such as a contaminated camera or a slightly loose connector, are "soft," meaning that they are not catastrophic failures but exhibit a certain degradation in performance that corresponds to a visible change in packets.

[0039] In some embodiments, a "soft" fault may evolve over time and become increasingly severe, and this progression is detected by analyzing packets by the embedded CPU 54 and / or the ML accelerator 56. For example, a trend of increasing latency, a trend of decreasing throughput, and / or a trend of increasing packet drops may indicate a developing fault.

[0040] In some embodiments, the embedded CPU 54 counts various packet-related events using suitable counters. Typically, but not necessarily, the counters accumulate events separately for each port 48. The embedded controller 54 and / or the ML accelerator 56 may use the counted events to detect anomalies.

[0041] 2 is a diagram that schematically illustrates the collection of packet-related events per port in a network switch 32, according to one embodiment described herein. In this example, the embedded controller 54 maintains suitable registers that count the occurrence of the following events for each port 48 of the switch 32: InDiscards - The total number of received frames that were good but could not be transmitted due to insufficient buffer memory. InFiltered - The total number of received frames that were good but were not forwarded due to policy rule filtering. InAccepted - The total number of received frames that were good but were not policy filtered and discarded due to an error. InBadAccepted The total number of received frames that had a CRC error but were not discarded or filtered.

[0042] The totals listed above are provided for illustrative purposes only. Additionally or alternatively, the embedded CPU 54 may accumulate any other suitable statistics useful for detecting anomalies.

[0043] In some cases, anomalies in a particular packet stream may indicate a fault in the subsystem that generates the packet stream. For example, an abnormally low packet rate from a camera may indicate a fault in the camera. In other cases, anomalies in a particular packet stream may indicate a fault in another component, such as a loose or faulty cable or connector elsewhere in the network. Thus, the term "fault in a subsystem of vehicle 24" in the present context broadly refers to any component that may cause anomalies in packets, such as, for example, subsystem 28, ECU, cables, and connectors.

[0044] In some embodiments, the ML accelerator 56 executes, in software and / or hardware, a trained ML interference model that identifies anomalies in one or more packet streams. In other embodiments, the ML interference model may run on the embedded CPU 54 without requiring an additional accelerator. In yet other embodiments, the embedded CPU 54 or other processor may analyze packets without an ML model and identify anomalies using any suitable criteria.

[0045] 3 is a flowchart that schematically illustrates a method for anomaly detection in a network switch 32 of a communication system 20 using machine learning (ML), according to one embodiment described herein. The method begins in a packet receive operation 70 with the switch core 52 receiving a packet via a port 48 from a sensor and / or other subsystem 28 of a vehicle 24.

[0046] In a selection and mirroring operation 74, the switch core 52 selects one or more relevant packet streams for analysis and mirrors packets of the selected packet streams to the embedded CPU 54. In some embodiments, the switch core 52 selects packet streams for mirroring using a suitable address-based policy or using other packet header fields. For example, the switch core 52 may select packets with predefined source addresses that correspond to respective sensors or other subsystems pre-designated to monitor. In other embodiments, the switch core 52 may perform deep packet inspection (DPI), for example, inspecting packet payloads or headers above the Ethernet layer to select packet streams for mirroring. Alternatively, the switch core 52 may use any other suitable technique or criteria for selecting which packets to forward to the embedded CPU 54.

[0047] In check operation 78, the embedded controller 54 checks whether the required ML analysis is within its own processing capabilities or whether the ML analysis requires the use of the ML accelerator 56. As noted above, in some cases the required ML analysis uses simple models that can be executed on the embedded controller 56. In such cases, in CPU analysis operation 82, the embedded CPU 54 applies the required ML models to the packet to identify existing or impending faults.

[0048] In some embodiments, upon identifying a fault, the model outputs a "health score," i.e., a numerical value that provides a quantitative measure of the severity of the fault. In an exemplary embodiment, a very low health score (e.g., zero) indicates a hard failure, a higher health score indicates a partial failure that degrades performance but is not catastrophic, and an even higher health score indicates an expected but imminent failure that has not yet occurred. Alternatively, any other suitable method of quantifying the severity of a fault may be used.

[0049] In a reporting operation 86, the embedded CPU 54 reports the health score to a higher-level CPU / GPU 60, such as a zone ECU 40, or to the central computer 44. In one embodiment, the embedded CPU 54 generates a dedicated Ethernet frame with the health score and transmits the frame via the switch core 52 to the higher-level CPU / GPU 60. Alternatively, the embedded CPU 54 may report the health score in any other suitable manner.

[0050] On the other hand, if the result of operation 78 indicates that the ML analysis is complex and requires the use of the ML accelerator 56, then in a forwarding operation 90, the embedded CPU 54 forwards the packet stream provided by the switch core 52 to the ML accelerator 56. In an accelerator analysis operation 94, the ML accelerator 56 applies an ML model (e.g., a deep learning model) to the packets to identify existing or impending faults. As described above, in some embodiments, upon identifying a fault, the model outputs a health score that provides a quantitative measure of the severity of the fault. The ML accelerator 56 transmits the health score to the embedded CPU 54. In a reporting operation 86, the embedded CPU 54 reports the health score to a higher-level CPU / GPU 60, e.g., a zone ECU 40, or to the central computer 44.

[0051] In various embodiments, the higher-level CPU / GPU 60 may take any suitable action in response to receiving the health score. For example, if the health score indicates a serious fault, the higher-level CPU / GPU 60 may issue a real-time alert or may record the health score in memory for offline analysis. In some embodiments, the higher-level CPU / GPU 60 may make a decision or initiate a responsive action based on a combination of health scores received from the same switch 32 or from multiple different switches 32.

[0052] While the embodiments described herein are primarily directed to automotive network communication systems, the methods and systems described herein may also be used in other applications, such as, for example, in industrial network communication systems that use Ethernet links to collect data from sensors and / or control various devices in an industrial environment, and in smart home systems that collect data from and control home sensors and appliances.

[0053] It should be noted that the above embodiments are cited as examples, and that the present invention is not limited to what has been specifically shown and described above. Rather, the scope of the present invention includes both combinations and subcombinations of the various features described above, as well as variations and modifications of various features not disclosed in the prior art that would occur to one skilled in the art upon reading the foregoing description. Documents incorporated by reference into this patent application shall be deemed an integral part of this application, except to the extent that any term is defined in these incorporated documents in a way that contradicts a definition expressly or impliedly made herein. Only the definitions in this specification shall be considered. [Other possible claims] [Item 1] 1. An automotive network switch, comprising: a plurality of ports configured to receive packets from electronic subsystems of a vehicle over a computer network deployed in the vehicle and to transmit the packets to other electronic subsystems of the vehicle over the computer network; a switch core configured to receive the packet from one or more of the ports, forward the packet to at least one of the ports, and transmit the packet over a network link of the computer network; one or more processors, obtaining at least a portion of the packets processed by the switch; analyzing the captured packets to identify anomalies in one or more of the electronic subsystems of the vehicle; and and one or more processors configured to send notification of the anomaly on the computer network to a central processing unit external to the switch. [Item 2] 2. The automotive network switch of claim 1, wherein the one or more processors are configured to generate a health score that quantifies the severity of the anomaly and report the health score in the notification. [Item 3] 3. The automotive network switch of claim 1, wherein in analyzing the captured packets, the one or more processors are configured to identify an existing anomaly or predict an impending anomaly. [Item 4] 3. The automotive network switch of claim 1, wherein at least one of the electronic subsystems includes a sensor, the port is configured to receive at least some of the packets from the sensor, and the one or more processors are configured to identify abnormal functioning of the sensor. [Item 5] 3. The automotive network switch of claim 1, wherein the one or more processors are configured to identify the anomaly in response to detecting a statistically deviant pattern of attributes of the packet. [Item 6] The above statistically deviant patterns are Statistically deviant dropping of packets, statistically deviant packet rates, Statistically deviant delays, and Statistically deviant inter-packet intervals Item 6. The automotive network switch of item 5, having one or more of: [Item 7] 3. The automotive network switch of claim 1, wherein the one or more processors are configured to execute a machine learning model configured to detect the anomaly. [Item 8] 3. The automotive network switch according to item 1 or 2, wherein the one or more processors are configured to count events relating to the packets and detect the anomaly based on the counted events. [Item 9] 3. The automotive network switch of claim 1, wherein at least one of the one or more processors has a machine learning (ML) accelerator located in the switch that is separate from a switch central processing unit (CPU) or a switch graphics processing unit (GPU). [Item 10] 3. The automotive network switch according to claim 1, wherein the one or more processors are configured to select one or more packet streams from among the plurality of packets processed by the switch according to predefined selection criteria, and to identify the anomaly by analyzing the packets in the selected packet streams. [Item 11] Item 11. The automotive network switch of item 10, wherein the one or more processors are configured to select the one or more packet streams by performing one or more of: (i) inspecting one or more header fields of one or more of the packets; and (ii) applying deep packet inspection (DPI) to one or more of the packets. [Item 12] 1. A method for anomaly detection in a vehicle, comprising: receiving, at an automotive network switch within the vehicle, packets from electronic subsystems of the vehicle over a computer network deployed in the vehicle and transmitting the packets to other electronic subsystems of the vehicle over the computer network; analyzing, by the switch, at least some of the packets processed by the switch to identify anomalies in one or more of the electronic subsystems of the vehicle; sending a notification of the anomaly from the switch to a central processing unit external to the switch over the computer network. [Item 13] 13. The method of claim 12, wherein analyzing the packet includes generating a health score that quantifies the severity of the anomaly, and sending the notification includes reporting the health score in the notification. [Item 14] 14. The method of claim 12, wherein analyzing the packets includes identifying an existing anomaly or predicting an impending anomaly. [Item 15] 14. The method of claim 12, wherein receiving the packet includes receiving at least a portion of the packet from a sensor, and analyzing the packet includes identifying abnormal functioning of the sensor. [Item 16] 14. The method of claim 12, wherein analyzing the packets includes identifying the anomaly in response to detecting a statistically deviant pattern of attributes of the packets. [Item 17] 14. The method of claim 12, wherein analyzing the packet comprises running a machine learning model configured to detect the anomaly. [Item 18] 14. The method according to claim 12, wherein the step of analyzing the packet includes a step of counting events related to the packet, and a step of detecting the anomaly based on the counted events. [Item 19] Item 14. The method of item 12 or 13, wherein the step of analyzing the packets is performed at least in part by a machine learning (ML) accelerator located in the switch and separate from a switch central processing unit (CPU) or a switch graphics processing unit (GPU). [Item 20] 14. The method according to claim 12, wherein the step of analyzing the packets includes a step of selecting one or more packet streams from among the plurality of packets processed by the switch according to predefined selection criteria by a plurality of processors, and a step of identifying the anomaly by analyzing the packets in the selected packet stream.

Claims

1. An automobile network switch, comprising: a plurality of ports configured to receive packets from electronic subsystems of a vehicle over a computer network deployed in the vehicle and to transmit the packets over the computer network to other electronic subsystems of the vehicle; a switch core configured to receive the packet from one or more of the ports, forward the packet to at least one of the ports, and transmit the packet over a network link of the computer network; one or more processors; Equipped with the one or more processors: Obtaining at least a portion of the packets processed by the switch; analyzing the captured packets to identify anomalies in one or more of the electronic subsystems of the vehicle; configured to transmit a notification of the anomaly to a central processing unit external to the switch on the computer network. Automotive network switch.

2. the one or more processors are configured to generate a health score that quantifies a severity of the anomaly and report the health score in the notification. The automotive network switch of claim 1 .

3. Upon analyzing the captured packets, the one or more processors are configured to identify existing anomalies or predict impending anomalies.

3. An automotive network switch according to claim 1 or 2.

4. at least one of the electronic subsystems includes a sensor, the port is configured to receive at least some of the packets from the sensor, and the one or more processors are configured to identify abnormal functioning of the sensor; 3. An automotive network switch according to claim 1 or 2.

5. the one or more processors are configured to identify the anomaly in response to detecting a statistically deviant pattern of attributes of the packet.

3. An automotive network switch according to claim 1 or 2.

6. The statistically deviant pattern may be Statistically deviant packet drops and Statistically deviant packet rates and Statistically deviant delays and statistically deviant inter-packet intervals; having one or more of:

6. The automotive network switch of claim 5.

7. the one or more processors are configured to execute a machine learning model configured to detect the anomaly.

3. An automotive network switch according to claim 1 or 2.

8. the one or more processors are configured to count events related to the packets and detect the anomaly based on the counted events.

3. An automotive network switch according to claim 1 or 2.

9. at least one of the one or more processors has a machine learning (ML) accelerator located in the switch that is separate from a switch central processing unit (CPU) or a switch graphics processing unit (GPU); 3. An automotive network switch according to claim 1 or 2.

10. the one or more processors are configured to select one or more packet streams from among the plurality of packets processed by the switch according to predefined selection criteria, and to identify the anomaly by analyzing the packets in the selected packet streams.

3. An automotive network switch according to claim 1 or 2.

11. the one or more processors: (i) inspecting one or more header fields of one or more of the packets; and (ii) applying deep packet inspection (DPI) to one or more of the packets; and selecting the one or more packet streams by performing one or more of: The automotive network switch of claim 10.

12. 1. A method for anomaly detection in a vehicle, the method comprising: receiving, at an automotive network switch within the vehicle, packets from electronic subsystems of the vehicle over a computer network deployed in the vehicle; and transmitting the packets to other electronic subsystems of the vehicle over the computer network; analyzing, by the switch, at least some of the packets processed by the switch to identify anomalies in one or more of the electronic subsystems of the vehicle; sending a notification of the anomaly from the switch to a central processing unit external to the switch over the computer network; A method comprising:

13. analyzing the packet includes generating a health score that quantifies the severity of the anomaly; sending the notification includes reporting the health score in the notification; The method of claim 12.

14. analyzing the packets includes identifying an existing anomaly or predicting an impending anomaly; 14. The method of claim 12 or 13.

15. receiving the packet includes receiving at least a portion of the packet from a sensor; analyzing the packets includes identifying abnormal functioning of the sensors; 14. The method of claim 12 or 13.

16. analyzing the packets includes identifying the anomaly in response to detecting a statistically deviant pattern of attributes of the packets.

14. The method of claim 12 or 13.

17. analyzing the packet includes running a machine learning model configured to detect the anomaly.

14. The method of claim 12 or 13.

18. The step of analyzing the packet includes the steps of counting events related to the packet and detecting the anomaly based on the counted events.

14. The method of claim 12 or 13.

19. the step of analyzing the packet is performed at least in part by a machine learning (ML) accelerator located in the switch, the machine learning (ML) accelerator being separate from a switch central processing unit (CPU) or a switch graphics processing unit (GPU).

14. The method of claim 12 or 13.

20. the step of analyzing the packets includes the steps of selecting one or more packet streams from among the plurality of packets processed by the switch according to predefined selection criteria; and identifying the anomaly by analyzing the packets in the selected packet streams.

14. The method of claim 12 or 13.