Error detection in computer networks
By comparing network configurations with target settings and applying traffic shaping/policing to manage data packet transfer, the system effectively detects errors in computer networks, enhancing safety by reducing the risk of failures in automated driving systems.
Patent Information
- Application Number
- JP2022559605
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-04-27
- Filing Date
- 2021-04-08
- Publication Date
- 2025-09-03
- Estimated Expiration
- 2041-04-08
AI Technical Summary
Existing systems fail to effectively detect errors or anomalies in computer networks, particularly in those of automated motor vehicles, which can lead to undesirable behavior due to corrupted configurations or unexpected errors.
A system that compares the current configuration of network components with a target configuration, using traffic shaping and policing to set upper limits on data packet transfer, and discards packets that deviate from these limits, thereby identifying errors in the network configuration.
This approach allows timely detection of errors in the network configuration, reducing the likelihood of safety-critical failures by identifying configuration discrepancies and ensuring consistent performance under varying conditions.
Smart Images

Figure 0007733671000001 
Figure 0007733671000002
Abstract
Description
[Technical Field]
[0001] The present invention relates to an apparatus and method for detecting errors and anomalies in a computer network. [Background technology]
[0002] Within the scope of this document, the term "automated driving" can be interpreted as driving with automated longitudinal or lateral maneuvering or autonomous driving with automated longitudinal or lateral maneuvering. The term "automated driving" encompasses automated driving with any degree of automation. Examples of degrees of automation are assisted driving, semi-automated driving, highly automated driving, and fully automated driving. These degrees of automation are defined by the German Federal Institute for Road and Traffic Research (BASt) (see non-patent document 1). In assisted driving, the driver continuously performs longitudinal or lateral maneuvering, while the system assumes other functions within certain limits. In semi-automated driving (TAF), the system assumes longitudinal and lateral maneuvering for certain periods of time and / or under certain circumstances, and the driver must continuously monitor the system, as in assisted driving. In highly automated driving (HAF), the system assumes longitudinal and lateral steering for a period of time, eliminating the need for the driver to constantly monitor the system, but the driver can still control the vehicle at certain times. In fully automated driving (VAF), the system can automatically accomplish driving under all circumstances for a specific application, eliminating the need for a driver for that application. The four levels of automation defined by BASt correspond to SAE Levels 1 to 4 in SAE Standard J3016 (SAE: Society of Automotive Engineers). For example, highly automated driving (HAF) according to BASt corresponds to Level 3 in SAE Standard J3016. Furthermore, SAE J3016 also defines SAE Level 5, which is not included in the BASt definition, as the highest level of automation. SAE Level 5 corresponds to driverless driving, where the system automatically handles all situations, similar to a human driver, throughout the entire journey, and generally eliminates the need for a driver. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] BASt publication "Forshung kompakt", November 2012 Summary of the Invention [Problem to be solved by the invention]
[0004] The object of the present invention is to detect errors or anomalies in computer networks, in particular in computer networks of automated motor vehicles. [Means for solving the problem]
[0005] This problem is solved by the features of the independent claims. Advantageous embodiments are set out in the dependent claims. It should be noted that additional features of claims dependent on an independent claim may, without the features of the independent claim or in combination with only a subset of the features of the independent claim, constitute an independent invention that can be the subject of an independent claim, a divisional application or an additional application and that is not dependent on the combination of all the features of the independent claim. This also applies to the technical teachings described herein that can constitute inventions that are not dependent on the features of the independent claims.
[0006] A first aspect of the present invention relates to an apparatus for detecting errors or anomalies in a computer network.
[0007] This computer network, in particular an Ethernet network, has at least one connection component, in particular a switch or hub. A switch (from the English word for "switch," "commuter," or "switch," also called a network switch or distributor) represents a connection component in a computer network that connects network segments together. It is responsible for allowing data packets within one segment (broadcast domain) to reach their destination.
[0008] The term "switch" generally refers to a multi-port bridge, an active network device that forwards frames based on information from the Data Link Layer (Layer 2) of the OSI model. Sometimes the more accurate names bridging hub or switching hub are also used. In IEEE Standard 802.3, this function is called a MAC bridge.
[0009] Devices comparable to switches at network layer 1 (layer 1) are called (repeater) hubs. Switches that process additional data at network layers (layer 3 or higher) are often called layer 3 switches or multilayer switches and can perform the functions of routers. In non-Ethernet networks, the connectivity task belongs to so-called gateways, which, like routers or switches, can connect heterogeneous networks to each other.
[0010] The linking component connects at least two network subscribers to each other, and one network subscriber may be a linking component of the other.
[0011] The interconnect component has a memory for the current configuration of the interconnect component and decides whether to forward or discard a data packet depending on the current configuration.
[0012] The apparatus has a target configuration for the interlocking components and is configured to compare a current configuration with the target configuration.
[0013] In this case, the comparison between the target configuration and the current configuration can be carried out once or several times, this comparison in particular being repeated regularly.
[0014] Here, the invention is based on the knowledge that due to errors, e.g. external disturbances, the current configuration in the memory of the connected components may be corrupted, which may lead to undesirable behavior when forwarding or discarding data packets.
[0015] Furthermore, it is based on the knowledge that even in the case of a correct or uncorrupted configuration, the interconnected parts may behave differently from the behavior prescribed by the configuration due to external influences, systematic errors or unexpected errors.
[0016] By comparing the current configuration with the target configuration, it is possible to determine, at least in a timely manner, whether the current configuration has changed relative to the target configuration due to an error. Of course, the target configuration may also change due to an error, but the probability that both the current configuration and the target configuration have the same error at the time of comparison is extremely low and can technically be further reduced by coding measures. In an advantageous embodiment, the device is a network subscriber connected to a connection component.
[0017] The device can access the diagnostic counters of the interconnection component as well as the current configuration, for example, to be able to see when, which, and how many data packets have been discarded and why. This mechanism can be used in an advantageous embodiment to ensure the integrity of certain configuration items. The device is configured to transmit a given number of data packets suitable for testing the configuration items of the interconnection component regarding network separation of the main control unit and the sub-control unit to the other network subscriber at a given time via the interconnection component, determine the number of data packets discarded by the interconnection unit, and compare the number of data packets transmitted to the other network subscriber with the number of data packets discarded by the interconnection unit.
[0018] Preferred packets are those that can test the correctness of individual components of the configuration, e.g., packets with unconfigured VLANs should be discarded. Furthermore, knowledge of the target system behavior, i.e., the complete network signature, can be advantageously utilized.
[0019] Here, the invention is based on the finding that the number of data discarded by a concatenated component operating without error is defined by a configured limit (e.g., a defined amount of data per time) or another configurable characteristic or filter rule, as well as by the processing capacity of the concatenated component itself.
[0020] In another advantageous embodiment, the configuration of the connection component defines at least one upper limit on the number of data packets transferred by the connection component within a given time, in particular by defining a data rate, for example in Mbits / second.
[0021] An example of this is traffic shaping. Traffic shaping represents a type of queue management in packet relay data networks that delays or drops data packets based on predetermined criteria in order to meet a predetermined demand profile. This function is performed by the cooperative operation of a network scheduler and a network shaper and is essentially a form of data rate limiting. Traffic shaping is unidirectional and typically memoryless, i.e., unlike data flow management, it operates without remote control information.
[0022] Instead, this is, for example, traffic policing. Traffic policing is a traffic flow method similar to traffic shaping, the difference being that it installs rules on incoming data packets that allow it to drop non-matching data packets. In this case, unlike traffic shaping, packets are not temporarily stored, but the policer keeps track of how often it drops packets.
[0023] In another advantageous embodiment of the invention, the configuration of the connection components defines characteristic upper limits for the transfer of data packets received by a network subscriber within a given time (for example, by traffic policing) and / or upper limits for the transfer of data packets sent to a network subscriber within a given time (for example, by traffic shaping). These limits can be selected in particular so that a perfect network and its characteristic traffic do not violate its signature, but anomalous traffic or incorrect configurations are detected and packets belonging to atypical traffic patterns are discarded. These packet losses can be used as an indicator of the integrity of the network.
[0024] Complementing this implementation, network traffic can also be engineered so that the chosen upper limit can be narrower and more sensitive, for example by "smoothing" short periods of high data rates over longer periods of time to prevent traffic spikes.
[0025] In another advantageous embodiment, the device is configured to compare the difference between the number of data packets sent to the other network subscriber and the number of data packets discarded by the connection unit with at least one upper limit on data packets forwarded by the connection component within a given time.
[0026] The invention is based on the finding that this comparison allows one to deduce that the configuration of a connected unit is incorrect. Furthermore, this connected unit is made up of a number of technical components that together form a process chain, and this configuration is only a part of this process chain. This comparison therefore allows one to deduce errors in the entire process chain within the connected unit that can be detected by this measure and that cause deviations from the target function.
[0027] In another advantageous embodiment, a comparison with possibly the highest available ASIL integrity is performed.
[0028] In another advantageous embodiment, the comparison is initiated by a component outside the process chain that has been developed to the required completeness (for example, according to ISO 26262 or IEC 61508), which also feeds back the results. In this case, the comparison is performed within a complete component outside the process chain. In this case, in order to prevent dangerous and adverse error cases, the patterns selected in this case for the inquiries, feedback, and possibly necessary transmitted test data must be selected in a complex manner so that errors in the E / E within the process chain can occur in a sufficiently predictable or systematic way.
[0029] In another advantageous embodiment, individual components in a process chain that are tested using a complete component outside the process chain can also be developed to the required completeness, and the error cases that are prevented thereby no longer have to be addressed by higher-level measures implemented by the component outside the process chain. This can result in, for example, a reduction in the requirements for the usage patterns of inquiries, feedback, and possibly necessary transmitted test data.
[0030] Another advantageous embodiment of the invention is a driving system for automated driving of a motor vehicle, which comprises a main control unit for automated driving and a secondary control unit for automated driving.
[0031] This division of the autonomous driving functions into a main control unit and a sub-control unit can be based on functional safety requirements that require, for example, a redundant system structure.
[0032] The main control unit and the sub-control unit each comprise a device and a coupling element according to one of the preceding claims, the coupling elements being connected to one another.
[0033] This results in a network topology in which, in particular, the device of the main control unit is connected to the connecting part of the main control unit, which is further connected to the connecting part of the sub-control unit, which is further connected to the device of the sub-control unit.
[0034] In another advantageous embodiment, the configuration of the connection components defines an upper limit for the transfer of data packets received by the network subscriber within a given time period and an upper limit for the transfer of data packets sent to the network subscriber within a given time period, the upper limit for the transfer of data packets sent to the other connection component within the given time period being lower or higher than the upper limit for the transfer of data packets received by one connection component within the given time period.
[0035] The invention is now based on the finding that a selected ratio of these two upper limits to one another makes it possible to identify errors in the process chain within the two linked components, in particular an incorrect configuration of the two linked components.
[0036] In another advantageous embodiment of the invention, the main control unit and the secondary control unit each comprise an apparatus as defined in claim 2, 3, 4 or 5, and the given point in time is prior to activating the automatic driving mode for the motor vehicle and / or during activation of the automatic driving mode for the motor vehicle.
[0037] Here, the present invention is based on the finding that error detection using the present invention is merely a timely measure, and that an error may occur immediately after the error detection.
[0038] Since the occurrence of errors can be considered a statistical process, the accumulated probability of error occurrence increases over time, so it is advantageous to select a given time point immediately before the activation of the automatic driving mode in order to reduce the probability of error occurrence before this safety-technically demanding event.
[0039] To ensure a sufficiently high level of error detection in this invention / measure, and therefore its usefulness in emergencies, we must ensure that failures, along with bubbling idiots, are unlikely to occur. The background to this is that an undetected failure (latent error) of this measure (shaping / policing) can immediately cause failures on both sides of the partial network in the event of a bubbling idiot error. To achieve this, we must address the following two important points: 1. If a system error occurs, it will inevitably occur due to changing environmental variables. Therefore, it must be ensured that the measures (shaping / policing) are performed in a manner that is as consistent as possible with the boundary conditions under which the bubbling idiot may cause a safety-related event. A suitable time for this in a highly automated vehicle is, for example, immediately before the driving task is handed over from the driver to the vehicle and while the vehicle is driving as autonomously as possible. An unsuitable time is, for example, when the vehicle is in stationary mode, i.e., when the boundary conditions do not match those during highly automated driving. 2. To adequately deal with unexpected errors, the frequency at which the test of this invention / measure (shaping / policing) is repeated must be selected so that the error rate assumed to cause the test to be invalid, multiplied by the probability of bubbling idiot occurrence within the monitoring interval, is small enough to satisfy the completeness requirement. If this is not sufficient, the monitoring interval must be shortened.
[0040] In another advantageous embodiment, the device of one of the control units is configured to send a low-priority data packet to the other device at at least one given time via the connection part of the control unit and the connection part of the other control unit, the priority of this data packet being selected such that for every unexpected communication between the two connection units, for example excluding a user communication, the data packet is discarded by one of the connection parts, and each of the other devices is configured to essentially expect to receive the data packet at a given time.
[0041] A second aspect of the present invention relates to a method for detecting errors in a computer network, the network having at least one interconnection component connecting at least two network subscribers to each other, the interconnection component having a memory for a current configuration of the interconnection component, the interconnection component forwarding or discarding data packets depending on the current configuration.
[0042] One step of the method is to compare the current configuration of the connected components with a target configuration.
[0043] The above-described embodiments of the device according to the invention according to the first aspect of the invention equally apply to the method according to the invention according to the second aspect of the invention. Advantageous embodiments of the method according to the invention not explicitly mentioned here and in the claims correspond to the advantageous embodiments of the device according to the invention mentioned above or claimed.
[0044] In the following, the invention will be explained on the basis of one embodiment with the aid of the attached drawings. [Brief explanation of the drawings]
[0045] [Figure 1] 1 is a schematic diagram of an embodiment of a traveling system according to the present invention; [Figure 2] Graph showing an example of data transmission speed trends DETAILED DESCRIPTION OF THE INVENTION
[0046] FIG. 1 illustrates a driving system for automatic driving of a motor vehicle, which comprises a main control unit for automatic driving hPAD and a secondary control unit for automatic driving mPAD.
[0047] The main control unit hPAD and the secondary control unit mPAD each comprise a device V1, V2 according to the invention and coupling parts S1, S2, which are connected to one another.
[0048] In this case, the connection components S1 and S2 and the main devices V1 and V2 constitute a computer network, and the connection components S1 and S2 and the main devices V1 and V2 are network subscribers.
[0049] The interconnection components S1, S2 each have a memory for the current configuration of the interconnection components S1, S2, and the interconnection components S1, S2 are each configured to forward or discard data packets depending on the current configuration.
[0050] The devices V1, V2 have a target configuration for each connected part S1, S2 of their control units hPAD, mPAD respectively, and the devices V1, V2 are each configured to compare a current configuration with the target configuration.
[0051] The devices V1, V2 are each configured to transmit at a given time a given number ds of data packets via the connection parts S1, S2 to the other network subscriber, for example to the other device V1, V2 respectively.
[0052] In this case, the given point in time is prior to activation of the automatic driving mode for the vehicle and / or during activation of the automatic driving mode for the vehicle.
[0053] The configuration of the connection components defines at least one upper limit O2 for the transfer of data packets received by the network subscriber within a given time and an upper limit O1 for the transfer of data packets sent to the network subscriber within a given time, and the upper limit O1 for the transfer of data packets sent to the other connection component S1, S2 within the given time is lower than the upper limit O2 for the transfer of data packets received by one connection component S1, S2 within the given time.
[0054] Furthermore, the devices V1, V2 are configured to determine the number I1, I2 of data packets discarded by the connection components S1, S2, respectively, and to compare the difference between the number ds of data packets sent to the other network subscriber and the number I1, I2 of data packets discarded by the connection components S1, S2 with at least one upper limit O1, O2 on data packets forwarded by the connection components S1, S2 within a given time.
[0055] Furthermore, the present device V1, V2 of one of the control units hPAD, mPAD is configured to send a low-priority data packet to the other present device V1, V2, respectively, via the connection part S1, S2 of its control unit hPAD, mPAD and the connection part S1, S2 of the other control unit hPAD, mPAD, at least at one given time, the priority of this data packet being selected by one of the connection parts S1, S2 so that the data packet is discarded for every unexpected communication between the two connection parts S1, S2, for example, excluding user communication, and the other present device V1, V2 is basically configured to expect to receive this data packet at a given time.
[0056] Figure 2 illustrates an example of the evolution of the data rate, where the data rate is plotted in Mbits over time t.
[0057] In this case, a data transmission level NL, which is normally transmitted as an effective load, is shown. This effective load NL is lower than two upper limits O1 and O2. The upper limit O1 for the transfer of data packets sent to each other connection component S1, S2 in a given time is lower than the upper limit O2 for the transfer of data packets received by one connection component S1, S2 in a given time.
[0058] In addition, three so-called bursts B1, B2, B3 are shown, which result at a given time from the transmission of data packets of a given number ds by the devices V1, V2 to the other network subscriber via the connecting parts S1, S2.
[0059] In this case, burst B1 represents the number ds of data packets actually transmitted from the devices V1 and V2. This number ds exceeds the two upper limits O1 and O2. If the connection components S1 and S2 are operating without errors, a certain number I1 of data packets is discarded by the first connection component S1 and S2. As a result, only burst B2 reaches the other connection component S1 and S2, respectively. The other connection component S1 and S2 discards a certain number I2 of data packets, and as a result, only burst B3 reaches the other device V1 and V2.
[0060] Since both the number of data packets ds and the two upper limits O1, O2 are known, the receiving devices V1, V2 can identify whether there is an error in the computer network, for example in the current configuration of the connected components S1, S2, by comparing the data packets actually received with the expected number of data packets obtained from the difference between the number of data packets ds sent to the devices and the upper limits O1, O2.
[0061] For example, if the number of actually received data packets exceeds an upper limit O2 on the transfer of data packets received by a network subscriber within a given time, it can be assumed that there is an error in the current configuration of the receiving connection components S1, S2.
[0062] For example, if the number of actually received data packets exceeds an upper limit O1 on the transfer of data packets sent to a network subscriber within a given time, it can be assumed that there is an error in the current configuration of the connecting components S1, S2 on the sending side. The present invention may also include the following aspects: 1. A device (V1, V2) for detecting errors in a computer network, the computer network has at least one connection component (S1, S2) connecting at least two network subscribers of the computer network to each other, the linking components (S1, S2) have a memory for the current configuration of the linking components (S1, S2); This connection component (S1, S2) forwards or discards the data packet depending on the current configuration, the device (V1, V2) has a target configuration with respect to the connecting parts (S1, S2), The device (V1, V2) is configured to compare a current configuration with a target configuration. 2. In the device (V1, V2) described in 1 above, The devices (V1, V2) are network subscribers connected to the connecting components (S1, S2), and the devices (V1, V2) are: Sending a given number (ds) of data packets at a given time to the other network subscriber via the connection components (S1, S2); Identifying the number (I1, I2) of data packets discarded by the connection component (S1, S2); A device configured to compare the number of data packets (ds) sent to the other network subscriber with the number of data packets (I1, I2) discarded by the connection components (S1, S2). 3. In the device (V1, V2) described in 1. or 2. above, An apparatus in which the configuration of a connection component (S1, S2) defines at least one upper limit (O1, O2) on the number of data packets transferred by the connection component (S1, S2) within a given time period. 4. In the device (V1, V2) described in 3 above, The configuration of the connecting parts (S1, S2) is at least one upper limit (O2) on the transfer of data packets received by a network subscriber within a given time period; and at least one upper limit (O1) on the transfer of data packets sent to a network subscriber within a given time period. 5. In the device (V1, V2) according to 3. or 4. above, This device (V1, V2) The device is configured to compare the difference between the number of data packets (ds) sent to the other network subscriber and the number (I1, I2) of data packets discarded by the connection unit (S1, S2) with at least one upper limit (O1, O2) on data packets forwarded by the connection unit (S1, S2) within a given time. 6. A driving system for automatic driving of automobiles, This driving system has a main control unit (hPAD) for automatic driving and a sub-control unit (mPAD) for automatic driving, and these main control unit (hPAD) and sub-control unit (mPAD) each have devices (V1, V2) and connecting parts (S1, S2) described in any one of 1. to 5. above, and these connecting parts (S1, S2) are connected to each other. 7. In the traveling system described in 6. above, The configuration of the connection components (S1, S2) defines an upper limit (O2) for the transfer of data packets received by the network subscriber within a given time and an upper limit (O1) for the transfer of data packets sent to the network subscriber within a given time, respectively; A running system in which the upper limit (O1) for the transfer of data packets sent to each other connected component (S1, S2) within a given time is lower than the upper limit (O2) for the transfer of data packets received by the connected components (S1, S2) within a given time. 8. In the traveling system described in 6. or 7. above, The main control unit (hPAD) and the sub-control unit (mPAD) each have the device (V1, V2) described in 2., 3., 4. or 5. above, and a given point in time is before the activation of an autonomous driving mode for a motor vehicle; and / or A driving system for a motor vehicle in automatic driving mode. 9. In the traveling system described in 6. above, the devices (V1, V2) of the control units (hPAD, mPAD) are configured to send low-priority data packets to the other devices (V1, V2) at least at one given time via the connection parts (S1, S2) of the control units (hPAD, mPAD) and the connection parts (S1, S2) of the other control units (hPAD, mPAD), respectively, for each unexpected communication between two connected components (S1, S2), a priority of this data packet is selected so that the data packet is discarded by one of the connected components (S1, S2); The running system is such that each other device (V1, V2) is essentially configured to expect to receive this data packet at a given time. 10. A method of detecting errors in a computer network, comprising: the computer network has at least one connection component (S1, S2) connecting at least two network subscribers of the computer network to each other, the linking components (S1, S2) have a memory for the current configuration of the linking components, This connection component (S1, S2) forwards or discards the data packet depending on the current configuration, The method comprises: The method comprises the step of comparing a current configuration for the connected components (S1, S2) with a target configuration.
Claims
1. A device (V1, V2) for detecting errors in a computer network, the computer network has at least one connection component (S1, S2) connecting at least two network subscribers of the computer network to each other, the linking components (S1, S2) have a memory for the current configuration of the linking components (S1, S2), This connection component (S1, S2) forwards or discards the data packet depending on the current configuration, the device (V1, V2) has a target configuration for the connecting parts (S1, S2), the devices (V1, V2) are configured to compare a current configuration with a target configuration, the configuration of the connection components (S1, S2) defines at least one upper limit (O1, O2) on the number of data packets transferred by the connection components (S1, S2) within a given time, The devices (V1, V2) are configured to compare the difference between the number of data packets (ds) sent to the other network subscriber and the number of data packets (I1, I2) discarded by the connection components (S1, S2) with at least one upper limit (O1, O2) on data packets forwarded by the connection components (S1, S2) within a given time.
2. 2. The device (V1, V2) according to claim 1, The devices (V1, V2) are network subscribers connected to the connecting components (S1, S2), and the devices (V1, V2) are: Sending a given number (ds) of data packets at a given time to the other network subscriber via the connection components (S1, S2); Identifying the number (I1, I2) of data packets discarded by the connected components (S1, S2); A device adapted to compare the number of data packets (ds) sent to the other network subscriber with the number of data packets (I1, I2) discarded by the connection components (S1, S2).
3. 3. The device (V1, V2) according to claim 1 or 2, The configuration of the connecting parts (S1, S2) is at least one upper limit (O2) on the transfer of data packets received by a network subscriber within a given time; and at least one upper limit (O1) on the transfer of data packets sent to a network subscriber within a given time period.
4. It is a driving system for autonomous driving of automobiles, The driving system comprises a main control unit (hPAD) for automatic driving and a sub-control unit (mPAD) for automatic driving, and these main control unit (hPAD) and sub-control unit (mPAD) each have a device (V1, V2) according to any one of claims 1 to 3 and a connecting element (S1, S2), and these connecting elements (S1, S2) are connected to each other.
5. The traveling system according to claim 4, The configuration of the connection components (S1, S2) defines an upper limit (O2) for the transfer of data packets received by a network subscriber within a given time and an upper limit (O1) for the transfer of data packets sent to the network subscriber within a given time, respectively; A running system in which the upper limit (O1) for the transfer of data packets sent to each other connected component (S1, S2) within a given time is lower than the upper limit (O2) for the transfer of data packets received by the connected components (S1, S2) within a given time.
6. 6. The traveling system according to claim 4 or 5, The main control unit (hPAD) and the sub-control unit (mPAD) each have a device (V1, V2) according to claim 2, 3, 4 or 5, and a given point in time is before the activation of an automatic driving mode for a motor vehicle; and / or A driving system for a motor vehicle in automatic driving mode.
7. The traveling system according to claim 4, the devices (V1, V2) of the control units (hPAD, mPAD) are configured to send low-priority data packets to the other devices (V1, V2) at least at one given time via the connection parts (S1, S2) of the control units (hPAD, mPAD) and the connection parts (S1, S2) of the other control units (hPAD, mPAD), respectively, for each unexpected communication between two connected components (S1, S2), a priority is assigned to this data packet so that it is discarded by one of the connected components (S1, S2), The running system is such that the respective other present device (V1, V2) is essentially configured to expect to receive this data packet at a given time.
8. 1. A method for detecting errors in a computer network, comprising: the computer network has at least one connection component (S1, S2) connecting at least two network subscribers of the computer network to each other, the linking components (S1, S2) have a memory for the current configuration of the linking components, This connection component (S1, S2) forwards or discards the data packet depending on the current configuration, The method comprises: comparing a current configuration of the connected components (S1, S2) with a target configuration; The method comprises a step of defining, by configuration of the connection components (S1, S2), at least one upper limit (O1, O2) on the number of data packets transferred by the connection components (S1, S2) within a given time, 10. A method according to claim 9, further comprising a step of comparing the difference between the number of data packets (ds) sent to the other network subscriber and the number of data packets (I1, I2) discarded by the connection components (S1, S2) with at least one upper limit (O1, O2) on data packets to be forwarded by the connection components (S1, S2) within a given time.
Citation Information
Patent Citations
Intrusion detecting control system
JP2003085139A
Packet relay device
JP2012134582A
Communication system, communication device and communication method
JP2014143499A
On-vehicle system, program and controller
JP2017152762A
Intrusion response apparatus and method for vehicle network
US20190332823A1