Subscriber station of a serial bus system and communication method in a serial bus system
The subscriber station with a tampering detection module addresses manipulation attacks in CAN FD and CAN XL bus systems by detecting and discarding frames with inverse pulses, ensuring secure and reliable communication with high data rates and robustness.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-13
- Publication Date
- 2026-03-23
AI Technical Summary
Existing bus systems, such as CAN FD and CAN XL, are vulnerable to manipulation attacks where a second valid CAN frame is embedded in the data field, leading to unauthorized operations and potential security risks due to undetected errors in the DLC field, which can cause the receiver to perceive two valid frames instead of one, disrupting normal operation and posing a security risk.
A subscriber station with a tampering detection module that checks for inverse pulses in predetermined fields of received frames and discards frames with such errors, ensuring secure communication by preventing unauthorized frame decoding.
The solution enhances security by preventing unauthorized frame manipulation, ensuring reliable and secure communication with high data rates and error robustness, even with varying frame lengths, thus improving the safety and flexibility of the bus system.
Smart Images

Figure 0007834236000001 
Figure 0007834236000002 
Figure 0007834236000003
Abstract
Description
Technical Field
[0001] The present invention relates to a subscriber station of a serial bus system and a communication method in a serial bus system that operates with high data rate, high flexibility, and high error robustness. In the operation of a superior technical device, it is necessary to prevent unauthorized improper operations.
Background Art
[0002] A bus system for communication between a sensor and a control device needs to enable transmission of a large amount of data, for example, in a vehicle, in order to ensure as many functions of technical devices and the vehicle as possible. In many cases, it is required to transmit data quickly from a transmitter to a receiver. Also, it is necessary to be able to transmit large data packets as required.
[0003] Currently, a bus system in which data is exchanged as messages between bus subscribers and encoded with CAN FD of the CAN protocol specification for transmission on the bus as frames of the ISO11898-1:2015 standard is already used in many series vehicles. Thus, messages are exchanged between bus subscribers of the bus system, such as sensors, control devices, encoders, etc., and transmitted as frames on the bus for this purpose. CAN FD is used by many manufacturers in the first step in vehicles with a data bit rate of 2 Mbit / s and a arbitration bit rate of 500 kbit / s.
[0004] Alternatively, CAN XL, a successor bus system to CAN FD, can also be used. CAN XL enables a higher data rate than CAN FD. Furthermore, longer messages are possible than with CAN FD. Thereby, CAN XL is particularly suitable for applications that support other functions in addition to pure data transfer by the CAN bus, such as functional safety (safety), data security (security), quality of service (QoS), etc. These are basic characteristics required, for example, for autonomous vehicles.
[0005] CAN XL, CAN FD, and Classical CAN are compatible, and CAN XL has at least the same error robustness as CAN FD and Classical CAN. In each of the above CAN versions, the data field of the message frame to be transmitted over the bus may contain any value.
[0006] A problem can occur if the manipulator embeds a second valid CAN frame (attack frame) into the data field of a valid frame (carrier frame).
[0007] The problem here is that messages of different lengths, i.e., different numbers of bytes in the data field, can be transmitted in both CAN FD and CAN XL. For this reason, the DLC field, which is placed before the data field of the message, specifies the number of bytes in the data field. Due to electromagnetic interference, the receiver may perceive one of the four bits in the DLC field of the CAN FD frame, particularly the most significant bit of the DLC field, as having a different value from the value corresponding to the code representing the actual length of the data field of the carrier frame. If this error is not detected by the transmitter, the transmitter will not interrupt the transmission of the carrier frame. Therefore, the receiver perceives and receives two valid CAN frames instead of one valid CAN frame: a valid but shortened carrier frame and an attack frame.
[0008] This could allow the receiver to be manipulated by the attack frame, potentially altering the normal operation of the device. This could lead to undesirable consequences and, in some cases, pose a security risk to higher-level technical equipment. [Overview of the Initiative] [Problems that the invention aims to solve]
[0009] Therefore, the object of the present invention is to provide a subscriber station for a serial bus system and a communication method in a serial bus system that solve the above problems. In particular, the present invention provides a subscriber station for a serial bus system and a communication method in a serial bus system that provides security against tampering in order to ensure the safe operation of the bus system and / or higher-level technical equipment, even with high error robustness of communication, high data rates, arbitrary values in the data field, and arbitrary amounts of data used per frame. [Means for solving the problem]
[0010] This problem is solved by a subscriber station of a serial bus system having the features of claim 1. The subscriber station comprises: a communication control device for controlling communication between the subscriber station and at least one other subscriber station of the bus system and for generating a transmit signal according to a frame; a receiving device configured to serially receive at least one signal from the bus; and a tampering detection module for checking whether at least one predetermined field of a frame created by the receiving device from at least one signal from the bus system and thus received has at least one pulse having a second bit value inverse to a predetermined first bit value in a received bit having a predetermined first bit value and a predetermined duration, wherein the tampering detection module is further configured to discard the received frame after the presence of at least one pulse having a second bit value inverse to a predetermined first bit value.
[0011] The aforementioned subscriber station (node), even if it is a receiving node and therefore not the sender of the frame received from the bus, can, by its configuration, inspect the frame received from the bus for tampering. Appropriate actions can be taken according to the inspection results, and in particular, frames can be discarded to prevent tampering by the subscriber station. In particular, a valid frame will not be mistakenly decoded as two valid frames.
[0012] As a result, a subscriber station infected with malware will no longer be able to send undetected frames that could disrupt the operation of the bus system or higher-level equipment and / or cause further damage. This improves the security of the bus system.
[0013] As a result, even with an increase in the amount of data used per frame, subscriber stations can reliably send and receive frames with high functional safety, great flexibility regarding current events in the operation of the bus system, and a low error rate.
[0014] The method performed by the subscriber stations can also be used if the bus system includes at least one CAN subscriber station and / or at least one CAN FD subscriber station and / or at least one CAN XL subscriber station that transmit messages according to the CAN protocol and / or CAN FD protocol and / or CAN XL protocol.
[0015] Further advantageous configurations of the subscriber station are described in the cited claims. The tampering detection module may be configured to perform an inspection of at least one predetermined field of the received frame, in addition to comparing the received frame with a frame format valid for the bus system.
[0016] In some cases, the tampering detection module may be configured to discard a received frame after the number of pulses having a second bit value that is the inverse of a predetermined first bit value exceeds a predetermined upper limit.
[0017] For example, a tampering detection module is configured to check whether, in a received recessive bit having a duration, at least one dominant pulse having a shorter duration than the received recessive bit occurs.
[0018] In one embodiment, the tampering detection module is configured to check whether at least one dominant pulse having a shorter duration than the received recessive bit occurs in a bit sequence of at least two received recessive bits, each having a duration.
[0019] The tampering detection module may have a first counter for counting the number of falling edges that occur from the start of a given field of a received frame to the end of a given field of the received frame.
[0020] Optionally, the tampering detection module has a second counter having an inverse bit value for counting the number of time quanta that occur from the start of a given field of a received frame to the end of a given field of a received frame.
[0021] In one embodiment, the tampering detection module has a second counter having an inverse bit value for counting a predetermined number of consecutive time quanta occurring from the start of a predetermined field of a received frame to the end of a predetermined field of a received frame.
[0022] The tamper detection module may optionally have a first evaluation block having a first counter and / or a second counter. The first evaluation block may be the bit timing logic of the communication control device.
[0023] The tampering detection module may optionally have a second evaluation block for evaluating whether a frame should be discarded, the second evaluation block being configured to exchange signals with the first evaluation block to evaluate a given field of the received frame.
[0024] The second evaluation block may be the bitstream processor of the communication control device. At least one predetermined field of the received frame may include at least one of the following fields or bits, namely, the acknowledgment spacer bit (ACK delimiter) in the acknowledgment field of the received frame following the acknowledgment bit (ACK slot), the end field of the received frame, and the error delimiter of the error frame.
[0025] According to one option, when incorporated into the communication on the bus, the illegal operation inspection module is configured to perform an inspection on the dominant pulse in order to detect a predetermined stationary state on the bus having a predetermined number of bits with the same value that cannot otherwise occur in the communication on the bus.
[0026] In some cases, the communication control device for serially generating a transmission signal for transmission to the bus is configured such that the bit time of the signal transmitted to the bus in the first communication phase and the bit time of the signal transmitted in the second communication phase are different for the frame.
[0027] In the first communication phase, it is possible to negotiate which of the subscriber stations of the bus system will obtain exclusive and collision-free access to the bus, at least temporarily, in the subsequent second communication phase.
[0028] The above-mentioned subscriber station may be part of a bus system including a bus and at least two subscriber stations connected via the bus so as to be able to communicate serially with each other here. Here, at least one of the at least two subscriber stations is the above-mentioned subscriber station.
[0029] The above problems are further solved by the communication method in a serial bus system described in claim 18. The method is performed at a subscriber station of a bus system having a communication control device, a receiving device, and a tampering inspection module, the method comprising the steps of: controlling communication between the subscriber station and at least one other subscriber station of the bus system, wherein the communication control device is configured to generate a transmit signal according to a frame; the receiving device serially receives at least one signal from the bus of the bus system; and the receiving device checks whether at least one predetermined field of a frame created from at least one signal received from the bus has at least one pulse having a second bit value inverse to a predetermined first bit value in a received bit having a predetermined first bit value and a predetermined duration, wherein the tampering inspection module is further configured to discard the received frame after the presence of at least one pulse having a second bit value inverse to a predetermined first bit value.
[0030] This method offers the same advantages as those described above for subscriber stations. Other possible embodiments of the present invention include combinations of features or embodiments not explicitly mentioned above or below with respect to the examples. Furthermore, those skilled in the art will add individual embodiments as improvements or supplements to each basic form of the present invention. [Brief explanation of the drawing]
[0031] The present invention will be described in more detail below with reference to the attached drawings and based on the examples. [Figure 1] This is a simplified block diagram of the bus system according to the first embodiment. [Figure 2] This figure shows the structure of a message that may be transmitted by a subscriber station of a bus system according to the first embodiment. [Figure 3] This is a simplified schematic block diagram of the subscriber station of the bus system according to the first embodiment. [Figure 4] This figure shows the time-dependent characteristics of bus signals CAN_H and CAN_L at a subscriber station according to the first embodiment. [Figure 5] This figure shows the time-dependent characteristics of the differential voltage VDIFF of bus signals CAN-XL_H and CAN-XL_L at a subscriber station according to the first embodiment. [Figure 6] This figure shows the bit division into time quanta of a frame created by a subscriber station according to the first embodiment, transmitted along with the bus signal in Figure 4 via the bus of the bus system. [Figure 7] This figure shows an example of a portion of the received signal RxD generated over time from the signal of a frame received from the bus by a subscriber station of the bus system according to the first embodiment. [Figure 8] This figure shows the time-dependent characteristics of the count value Z1 obtained by the first counter of the subscriber station according to the first embodiment, based on the received signal in Figure 7. [Figure 9] This figure shows the time-dependent characteristics of the count value Z2 obtained by the second counter of the subscriber station according to the first embodiment, based on the received signal in Figure 7.
[0032] In the diagrams, identical or functionally identical elements are given the same reference numeral unless otherwise specified. [Modes for carrying out the invention]
[0033] Figure 1 shows an example of bus system 1 configured based on a CAN bus system, a CAN FD bus system, a CAN XL bus system, and / or variations thereof as described below. Bus system 1 can be used in vehicles, particularly automobiles, aircraft, etc., or in hospitals, etc.
[0034] In Figure 1, the bus system 1 has a plurality of subscriber stations 10, 20, and 30, each connected to a bus 40 having a first bus wire 41 and a second bus wire 42, respectively. The bus wires 41 and 42 can also be called CAN_H and CAN_L, or CAN-XL_H and CAN-XL_L, and are used for electrical signal transmission with respect to transmit-state signals after the introduction of a dominant level or after the generation of a recessive level or other level. Messages 45 and 46 in the form of signals can be transmitted serially between the individual subscriber stations 10, 20, and 30 via the bus 40. If an error occurs during communication on the bus 40, as indicated by the jagged black block arrows in Figure 1, an error frame 47 (error flag) may optionally be transmitted. The subscriber stations 10, 20, and 30 are, for example, automotive control equipment, sensors, display devices, etc.
[0035] As shown in Figure 1, subscriber station 10 has a communication control device 11, a transceiver 12, and a tampering detection module 15. Subscriber station 20 has a communication control device 21, a transceiver 22, and optionally a tampering detection module 25. Subscriber station 30 has a communication control device 31, a transceiver 32, and a tampering detection module 35. The transceivers 12, 22, and 32 of subscriber stations 10, 20, and 30 are each directly connected to a bus 40, although not shown in Figure 1. Each of the transceivers 12, 22, and 32 may optionally be configured as a separate transmitter and a separate receiver.
[0036] The communication control devices 11, 21, and 31 are used to control the communication of each subscriber station 10, 20, and 30 via the bus 40 with at least one other subscriber station among the subscriber stations 10, 20, and 30 connected to the bus 40.
[0037] The communication control devices 11 and 31 create and read a first message 45, which is, for example, a modified CAN message 45. Here, the modified CAN message 45 is constructed based on the CAN FD format, which is described in more detail in relation to Figure 2, and the respective tampering modules 15 and 35 are used. The communication control devices 11 and 31 may also be configured to create and read other modified CAN messages 46, which are based on CAN XL. Here, the modified CAN message 46 is based on the CAN XL format, which is a further development of CAN FD and is compatible with CAN FD. CAN FD messages 45 can contain 0 to 64 data bytes and are transmitted at a significantly faster data rate than classical CAN messages. CAN XL messages 46 can contain 0 to approximately 2k bytes or any other arbitrary value and are transmitted at a significantly faster data rate than CAN FD messages 45.
[0038] Thus, the communication control devices 11 and 31 are configured to provide or receive CAN FD messages 45 or CAN XL messages 46 to the transceivers 12 and 32 as needed. That is, the communication control devices 11 and 31 create and read the first message 45 or the second message 46, and the first message 45 and the second message 46 differ in their data transmission standards, namely CAN FD or CAN XL in this case.
[0039] The communication control device 21 may be configured like a conventional CAN controller compliant with ISO 11898-1:2015, that is, like a CAN FD-tolerant classical CAN controller or CAN FD controller. The communication control device 21 creates and reads a first message 45, for example, a CAN FD message 45. In particular, the communication control device 21 is configured like a conventional CAN FD controller.
[0040] The transceiver 22 may be configured as a conventional CAN transceiver or CAN FD transceiver compliant with ISO 11898-1:2015. The transceivers 12 and 32 may be configured to receive or provide messages 45 in CAN FD format or messages 46 in CAN XL format from the associated communication control devices 11 and 31, as necessary.
[0041] The two subscriber stations 10 and 30 enable the generation and subsequent transmission of messages 46 in CAN XL format, as well as the reception of such messages 45. Figure 2 shows a CAN FD frame 450 for message 45, which is encoded by the communication control device 11 over time t and provided to the transceiver 12 for transmission to the bus 40. Here, the communication control device 11 creates a frame 450 that is compatible with both classical CAN and a successor version of CAN FD, such as CAN XL, as also shown in Figure 2 in this embodiment. The same applies to the communication control device 31 and transceiver 32 of the subscriber station 30.
[0042] As shown in Figure 2, a CAN FD frame 450 for CAN communication on bus 40 is divided into two distinct communication phases 451 and 452, namely the arbitration phase 451 and the data phase 452. Frame 450 has an arbitration field 453, a control field 454, a data field 455, a checksum field 456 for the checksum CRC, an acknowledgment field 457, and an end field 458. The bit duration of the bits in the arbitration phase 451 is longer than the bit duration of the bits in the data phase 452. The physical layer is the same for frame 450 in both the arbitration phase 451 and the data phase 452, as in the case of classical CAN. The physical layer corresponds to the bit transmission layer or layer 1 of the known OSI model (Open Systems Interconnection Model).
[0043] The start of frame 450 is indicated by the Start of Frame (SOF) bit. Next, at least one of the subscriber stations, for example, 10, 30, transmits an identifier (ID) in the arbitration field 453. Based on this, in the arbitration phase 451, using bits 28 to 18 of the identifier (ID) in the arbitration field 453, subscriber stations 10, 20, and 30 negotiate bit by bit which of them desires to transmit messages 45 and 46 with the highest priority at the moment, and therefore, in the subsequent data phase 452, will obtain exclusive access to bus 40 of bus system 1 for the next transmission time. The last bit of the arbitration field 453 is transmitted as RRS.
[0044] A key point between phases 451 is that the known CSMA / CR scheme is used, which allows simultaneous access to bus 40 from subscriber stations 10, 20, and 30 without the high-priority messages 45 and 46 being corrupted. This makes it relatively easy to add additional bus subscriber stations 10, 20, and 30 to bus system 1, which is a significant advantage.
[0045] The CSMA / CR scheme requires a so-called recessive state on bus 40, which can be overwritten by a dominant state on bus 40 by other subscriber stations 10, 20, and 30. In the recessive state, a high-resistance situation prevails at a single subscriber station 10, 20, or 30, which, combined with bus wire parasitism, results in a relatively long time constant. This limits the maximum bit rate of the current CAN-FD physical layer (FD transceiver compliant with ISO11898-2:2016) to approximately 2 megabits / second in actual vehicle use. CAN XL can further increase this maximum bit rate by specifically additionally switching the physical layer of data phase 452.
[0046] In the data phase 452, for the frame in Figure 2, in addition to a portion of the control field 454, usage data for the CAN FD frame 450, or a message 45 from the data field 455, and almost the entirety of the checksum field 456 are transmitted. The control field 454 has control bits for IDE, FDF, res, BRS, and ESI, and four bits from bit 3 to bit 0 of the DLC field. The checksum field 456 has an SBC field, a field for the checksum CRC, and a CRC delimiter bit.
[0047] If the subscriber station 10, acting as the transmitter, wins the arbitration and has exclusive access to the bus 40 of the bus system 1 for transmission, the transmitter of message 45 begins transmitting the bits of data phase 452 to the bus 40.
[0048] Generally, bus systems using CAN XL can achieve the following different characteristics compared to CAN or CAN FD. a) Adopting, and where appropriate, the proven characteristics related to the robustness and ease of use of CAN and CAN FD, particularly the identified frame structure and arbitration using the CSMA / CR method, b) Increase the net data transmission speed, especially to approximately 10 megabits per second. c) Increase the data size used per frame, specifically to about 2k bytes or any other arbitrary value.
[0049] As shown in Figure 2, in the arbitration phase 451, which is the first communication phase, the subscriber station 10 uses a known format from CAN / CAN-FD compliant with ISO 11898-1:2015, in particular up to the FDF bits (including). For CAN XL messages 46, the subscriber station 10 uses the CAN XL format from the FDF bits in the first communication phase and the data phase 452, which is the second communication phase.
[0050] In this embodiment, CAN XL and CAN FD are compatible. For CAN XL, the res bit, also known as the XLF bit in CAN XL and known from CAN FD in Figure 2, is used to switch from the CAN FD format to the CAN XL format. Therefore, the frame formats of CAN FD and CAN XL are the same up to the res bit or XLF bit. The receiver detects the format in which frame 450 is transmitted based on the res bit or XLF bit. CAN XL subscriber stations, i.e., subscriber stations 10 and 30 in this case, also support CAN FD.
[0051] As an alternative to frame 450 shown in Figure 2, which uses an 11-bit identifier (bits ID 28 to 18) according to the CAN FD base frame format, an optional extended frame format for CAN FD or CAN XL using a 29-bit identifier is available. This is the same as the known CAN FD extended frame format according to ISO 11898-1:2015 up to the FDF bit.
[0052] In frame 450 shown in Figure 2, bits with fixed values, i.e., 0 or 1, are indicated by thick black lines. In Figure 2, bits indicated by thick lines on the lower side are transmitted as dominant or "0" in frame 450. In Figure 2, bits indicated by thick lines on the upper side are transmitted as recessive or "1" in frame 450. In CAN XL data phase 452, when using a special CAN SIC XL transceiver, symmetrical "1" and "0" levels may be used instead of recessive and dominant levels.
[0053] Generally, two different stuffing rules apply when generating a CAN XL frame. The dynamic bit stuffing rule for CAN FD applies up to the res bit in control field 454, requiring the insertion of a reverse stuffing bit after five consecutive equal bits. Such stuffing bits are also called dynamic stuffing bits. After the res bit in control field 454, the fixed stuffing rule applies to the CAN XL frame, requiring the insertion of a fixed number of fixed stuffing bits. Alternatively, two or more bits may be inserted as fixed stuffing bits instead of a single stuffing bit.
[0054] In frame 450 of Figure 2, the res bit, which corresponds to the "XLF bit" in the CAN XL format, follows immediately after the FDF bit, as described above. When the res bit is 1, i.e., transmitted as recessive, frame 450 is detected as a CAN XL frame. For CAN FD frames, the communication control device 11 sets the res bit to 0, i.e., dominant.
[0055] Following the res bit, the BRS bit is set in frame 450, where the bit duration of the arbitration phase 451 is switched to the bit duration of the data phase 452.
[0056] The BRS bit is followed by a DLC field, into which a Data Length Code (DLC) is inserted, specifying the number of bytes in the data field 455 of frame 450. The Data Length Code (DLC) can take any value from 0 up to the maximum length of the data field 455 or the data field length itself. Since the maximum data field length for CAN FD is 64 bytes, the Data Length Code (DLC) is 4 bits, i.e., bits 3 through 0. DLC=0 means the data field length is 0 bytes, and DLC=15 means the data field length is 64 bytes. This is to ensure that the receiver of frame 450 correctly receives the data used and reliably detects the end of frame 450 in fields 456, 457, and 458. Furthermore, in order to maximize the data rate of bus system 1, bus 40 should be re-enabled as soon as possible to send other frames 450 or messages 45, 46. In other words, frame 450 should not block bus 40 unnecessarily.
[0057] In frame 450 of Figure 2, the DLC field is followed by the data field 455. The data field 455 consists of 0 to 64 data bytes. The length of the data field 455 is encoded in the DLC field as described above.
[0058] Following the data field 455, frame 450 is followed by the SBC field of bits SBC3-SBC0 and the checksum CRC. Since the checksum CRC is CRC21 or CRC17, the checksum CRC consists of bits 20-0 or bits 16-0. The length of the checksum CRC, i.e., the length of the CRC polynomial, must be selected according to the desired Hamming distance. The checksum CRC protects the entire frame. By the CRC delimiter bit in the checksum field 456, or starting from the CRC delimiter bit, the duration of the bits in frame 450 is switched from the duration of the data phase 452 to the duration of the arbitration phase 451, in other words, from a short duration to a long duration, as shown in Figure 2.
[0059] Following the CRC delimiter bit, and therefore the checksum field 456, frame 450 is followed by an acknowledgment field 457, which has an ACK slot bit to confirm the correct reception of frame 450. Receiving subscriber stations 10, 30 transmit the ACK slot bit as dominant if they have correctly received frame 450. Transmitting subscriber stations transmit the ACK slot bit as recessive. Thus, bits originally transmitted to bus 40 in frame 450 can be overwritten by receiving subscriber stations 10, 30. The ACK delimiter bit is transmitted as a recessive bit used to separate it from other fields.
[0060] The acknowledgment field (ACK field) 457 is followed by the end of frame field 458 (EOF = End of Frame) of frame 450. Bits 1 through 7 of the end of frame field 458 (EOF) are used to indicate the end of frame 450. The end of frame field (EOF), along with the ACK delimiter bit, results in the transmission of 8 recessive bits at the end of frame 450. This is a bit sequence that cannot occur within frame 450. This ensures that subscriber stations 10, 20, and 30 can reliably detect the end of frame 450.
[0061] The End Field (EOF) is followed by the Intermission Field (INT) within frame 450, which is not shown in Figure 2 but is shown only in Figure 8. The Intermission Field (INT) is a minimum of 3 bits in CAN. This Intermission Field (INT) is configured in CAN XL in the same way as CAN FD, in accordance with ISO 11898-1:2015.
[0062] Figure 3 shows the basic structure of a subscriber station 10, which includes a communication control device 11, a transceiver 12, and a tamper detection module 15, which is part of the communication control device 11 within the subscriber station 10. The subscriber station 30 is configured similarly to that shown in Figure 3, but the tamper detection module 35 shown in Figure 1 is located separately from the communication control device 31 and the transceiver 32. Therefore, the subscriber station 30 will not be described separately.
[0063] According to Figure 3, the subscriber station 10 has, in addition to the communication control device 11 and the transceiver 12, a microcontroller 13 to which the communication control device 11 is assigned, and a system ASIC 16 (ASIC = application-specific integrated circuit), where the system ASIC 16 may alternatively be a system base chip (SBC) that combines multiple functions required for the electronic modules of the subscriber station 10. In addition to the transceiver 12, a power supply device 17 that supplies power to the transceiver 12 is incorporated into the system ASIC 16. The power supply device 17 typically supplies a voltage of 5V CAN_Supply. However, the power supply device 17 may supply a voltage of a different value as needed. Additionally or alternatively, the power supply device 17 may be configured as a power source.
[0064] The transmission signal TxD is exchanged between the communication control device 11 and the transceiver 12 via their respective terminals TXD, and the reception signal RxD is exchanged via terminal RXD, as described above and later.
[0065] The tampering detection module 15 in Figure 3 has a first evaluation block 151 and a second evaluation block 152. The first evaluation block 151 has a first counter 1511 and a second counter 1512. The second evaluation block 152 has a configuration register 1525.
[0066] The first evaluation block 151 generates sampling points SP (Figure 6) for the signals CAN_H and CAN_L received from the bus 40 and outputs the associated signal S1 to the second evaluation block 152. Furthermore, the first evaluation block 151 calculates the bit value BW of the received signal RxD and outputs it to the second evaluation block 152. The first evaluation block 151 may be the bit timing logic (BTL) or a part thereof of the communication control device 11. The bit timing logic (BTL) is a state machine that is evaluated once for each time quantum and synchronized with the bitstream at terminal RXD of the device 11. Figure 6 shows a bit consisting of eight time quanta TQ1 to TQ8 as an example. The bit timing logic (BTL) also generates sampling points SP. Parameters 152A and 152B are stored in register 1525 and used by the first evaluation block 151 for evaluation as described later.
[0067] The second evaluation block 152 outputs signal S2 to the first evaluation block 151. The second evaluation block 152 may be the bitstream processor (BSP) or a part of the communication control device 11. The bitstream processor (BSP) is a state machine that is evaluated once per CAN bit time, i.e., during either the bit duration t_bt1 in the arbitration phase 451 or the bit duration t_bt2 in the data phase 452. The bitstream processor (BSP) encodes and / or decodes the CAN bitstream at terminals TXD and RXD according to the rules of the CAN protocol.
[0068] The second evaluation block 152, in particular the bitstream processor (BSP), notifies the first evaluation block 151, in particular the bit timing logic (BTL), by signal S2 that the first evaluation block 151 should further evaluate the received signal RxD. Signal S2 is also called the "additional evaluation field" signal. As soon as signal S2 ("additional evaluation field") becomes inactive, the first evaluation block 151 resets counters 1511 and 1512, in particular their counter values, to 0.
[0069] The functions of the fraud detection module 15 are described in detail below. Furthermore, the transceiver 12 includes a transmitting module 121 and a receiving module 122. While the transceiver 12 will be described below, the receiving module 122 may alternatively be located in a separate device outside the transmitting module 121. The transmitting module 121 and the receiving module 122 can be configured similarly to a conventional transceiver 22. The transmitting module 121 may, in particular, have at least one operational amplifier and / or transistor. The receiving module 122 may, in particular, have at least one operational amplifier and / or transistor.
[0070] The transceiver 12 is connected to the bus 40, specifically to a first bus wire 41 for CAN_H or CAN-XL_H and a second bus wire 42 for CAN_L or CAN-XL_L. Power is supplied to the power supply device 17 for supplying power, in particular the voltage CAN_Supply, to the first and second bus wires 41 and 42, via at least one terminal 43. Connection to ground or CAN_GND is made via terminal 44. The first and second bus wires 41 and 42 are terminated with termination resistors 49.
[0071] In the transceiver 12, the first and second bus wires 41 and 42 are connected not only to the transmitting module 121, also called the transmitter, but also to the receiving module 122, also called the receiver, although the connections are not shown in Figure 3 for simplification.
[0072] While the bus system 1 is operating, the transmitting module 121 converts the transmission signal TxD from the communication control device 11 into signals CAN_H and CAN_L corresponding to bus wires 41 and 42, and transmits these signals to the bus 40 at the terminals for CAN_H and CAN_L. The difference signal VDIFF=CAN_H-CAN_L shown in Figure 5 is formed on the bus 40.
[0073] The receiving module 122 in Figure 3 forms the received signal RxD from the signals CAN_H and CAN_L received from the bus 40 shown in Figure 4, or from the difference signal VDIFF shown in Figure 5. As shown in Figure 3, the receiving module 122 transfers the received signal RxD to the terminal RXD of the communication control device 11 via the terminal RXD of the transceiver 12.
[0074] Except in idle or standby states, the transceiver 12 having the receiving module 122 will always intercept data or transmissions of messages 45, 46 on the bus 40 during normal operation, regardless of whether the transceiver 12 is the sender of message 45 or message 46.
[0075] In the example in Figure 4, the signals CAN_H and CAN_L have dominant and recessive bus levels 401 and 402, respectively, as is known from CAN, at least in the arbitration phase 451. Each bit of the signal VDIFF with bit time t_bt1 can be detected in the arbitration phase 451 by a receiving module 122 having, for example, a receive threshold T_a of 0.7V, as shown in Figure 5. In the data phase 452, as already described with reference to Figure 2, the bits of signals CAN_H and CAN_L are transmitted faster than in the arbitration phase 451, i.e., with a shorter bit time t_bt2 (Figure 7). Thus, the signals CAN_H and CAN_L in Figure 4 in the data phase 452 differ from the conventional signals CAN_H and CAN_L in the arbitration phase 451 in that they have a faster bit rate. If the CAN XL signals CAN_H and CAN_L in data phase 452 are further generated at different physical layers, the receive threshold in the receive module 122 is also switched, for example, to a receive threshold T_d of approximately 0.0V in data phase 452.
[0076] The sequence of signals CAN_H and CAN_L states 401 and 402 in Figure 4, and the resulting sequence of voltage VDIFF in Figure 5, are used solely to illustrate the function of subscriber station 10. The sequence of data states for bus states 401 and 402 can be selected as needed.
[0077] In other words, in the first operating mode shown in Figure 4, the transmitter module 121 in Figure 3 generates a first data state as a bus state 402 with different bus levels for the two bus wires 41 and 42 of the bus line, and a second data state as a bus state 401 with the same bus level for the two bus wires 41 and 42 of the bus line of bus 40. Furthermore, in the second operating mode, which includes a data phase 452, the transmitter module 121 in Figure 3 transmits bits to the bus 40 at a higher bit rate for the elapsed time of signals CAN_H and CAN_L. As described above, the signal for the CAN XL message 46 in the data phase 452 may be generated at a different physical layer than CAN FD. This allows the bit rate in the data phase 452 to be even higher than in the case of CAN FD.
[0078] The tampering detection module 15 in Figure 3, particularly its evaluation block 151, is used to evaluate whether a dominant pulse is present in the currently received frame 450. Tampering detection helps detect and prevent certain attacks. In this attack, a malware-infected subscriber station, for example, subscriber station 30, sends a message 45 containing specially selected content in the data field 452. If only one receiving node, for example, subscriber station 10, detects a bit error in the DLC field of frame 450, particularly bit 3 of the DLC field, the receiving node may be deceived into believing that frame 450 has a shorter frame length than it actually does. The tampering detection module 15 in Figure 3 is particularly necessary when receiving frame 450 in order to detect a tampered frame 450.
[0079] For evaluation purposes, the fraud detection module 15 proceeds as described below with reference to Figures 6 to 9. Figure 6 shows the division of a bit of a received signal RxD generated by subscriber stations 10, 20, and 30 into time-quanta TQ1 to TQ8, as applied by the associated communication control devices 11, 21, and 31. Time-quanta TQ1, ..., TQ8 correspond to the time units in which the communication control devices 11, 21, and 31 sample the received signal RxD. In Figure 6, for clarity, reference signs are not assigned to all of the time-quanta TQ2 to TQ7, which are located over a time t between time-quanta TQ1 and TQ8. A bit is sampled to evaluate to a bit value of 1 or 0 at a sampling point SP that is typically located at about 75% of the bit duration t_bt1. In Figure 6, a bit value of "1" is sampled. The position of the sampling point SP in a bit can be configured as one of the parameters 152A and 152B of register 1525 and stored in register 1525.
[0080] As an example, the bit in Figure 6 is a bit with a bit duration t_bt1 used in the arbitration phase 451. The number of time quanta TQ1, ..., TQ8 is determined by the first evaluation block 151. In particular, the number of time quanta TQ1, ..., TQ8 for a single bit is limited by the specifications of the CAN standard and is freely selectable. That is, the first evaluation block 151 performs a division into time quanta such as TQ1, ..., TQ8. The number of time quanta TQ1, ..., TQ8 contained in the bit is configured as one of the parameters 152A, 152B and can be stored in register 1525.
[0081] Although not explicitly shown, the same thing described with reference to Figure 6 regarding the bits of the arbitration phase 451 also applies to the bits of the data phase 452, which have a bit duration t_bt2. The bit durations t_bt1 and t_bt2 are configured as one of the parameters 152A and 152B and can be stored in register 1525.
[0082] Figure 7 shows a portion of the received signal RxD generated by the communication control device 11 from the signals CAN_H, CAN_L, or VDIFF received from the bus 40 for frame 450. Figure 7 shows the received signal RxD or RxD signal of the data field 455 of frame 450, which has special content that can be used for security-related attacks. In this data field, the early termination of frame 450 is falsified. Figure 7 shows the termination falsified using bits from the second communication phase 452, more precisely, the termination after the CRC delimiter bit at the end of the data field 455.
[0083] Figure 7 shows the evaluation result of the currently received frame 450 (carrier frame). First, frame 450 is evaluated as a first frame 450_1 having a front part 450_1_1 and a end part 450_1_2, but the data field 455 of the currently received frame 450 (carrier frame) is actually still being transmitted via bus 40. The reason for the expected early termination of frame 450 is a bit error in the DLC field bits, which will be described in detail later. In other words, the communication control device 11 first receives the ACK bit (ACK slot) and the end field 458 (EOF) of the actual data field 455 of the currently received frame 450 (carrier frame) from the data field 455, and evaluates these as the end part 450_1_2 of the currently received frame 450 (carrier frame).
[0084] The reason for the expected early termination is that the receiving communication control device 11 detected a bit error in the DLC field, specifically bit 3 of the DLC field. For example, the DLC field of the currently received frame 450 (carrier frame) had a value of 0xF before the tampering due to the bit error, which, due to the bit error, indicates a data field 455 of length 7 bytes (DLC field = 0x7). However, the currently received frame 450 (carrier frame) actually has a data field 455 of length 64 bytes. In other words, the communication control device 11 mistakenly expected a data field 455 of only 7 bytes. Furthermore, the currently received frame 450 (carrier frame) shown in Figure 7 includes a bit sequence from the 8th byte onward of the data field 455 corresponding to a valid checksum CRC, followed by an emulated ACK field 457 with ACK slot and ACK delimiter bits, an emulated end field 458 with EOF bits 1-7 (see Figure 2), an emulated inter-frame distance (INT1, intermission), and an emulated bit sequence for the arbitration phase 451 of the subsequent frame 450.
[0085] Due to the dynamic CAN bit stuffing mechanism, the currently received frame 450 (carrier frame) of the CAN FD data field 455 cannot represent a sufficiently long recessive level or bit value to accurately emulate, for example, the 8 recessive bits of the ACK delimiter and EOF fields 458. Since the bit value depends only on the value of the signal RxD at the sample point, the communication control device 11 can filter out short dominant pulses DP in the signals CAN_H, CAN_L, or VDIFF received from the bus 40.
[0086] Generally, the receiving module 122 may have at least one pulse having a second bit value that is the opposite of the predetermined first bit value, for a received bit having a predetermined first bit value and predetermined durations t_bt1, t_bt2.
[0087] The occurrence of a dominant pulse DP in a recessive bit, or the occurrence of a recessive pulse in a dominant bit, can be detected using module 15, in particular counters 1511 and 1512, for frame 450 in Figure 7, whose count values Z1 and Z2 are shown in Figures 8 and 9. Here, both the first counter 1511, which can also be called a "falling edge" meter, and the second counter 1512, which can also be called a "dominant time quantum" meter, can detect dominant pulses DP and, consequently, count them.
[0088] For example, the device 11, in particular the tampering detection module 15, uses a first counter 1511 to count the number of falling edges of the RxD signal, i.e., the number of conversions from bit value 1 (recessive) to bit value 0 (dominant) of the RxD signal, and / or the number of time quantum TQs of the RxD signal that appear as bit value 0 (dominant).
[0089] When the first evaluation block 151, in particular the bit timing logic (BTL), detects a number of falling edges or dominant pulses DP that is configured as an upper limit N for the number of falling edges or dominant pulses DP, block 151 reports a dominant received bit (bit value 0) at the next sampling point SP (Figure 6) to the second evaluation block 152, regardless of what the first evaluation block 151 actually sampled at the sampling point SP (Figure 6). In this case, the second evaluation block 152 sees a format error in the currently received frame 450. The upper limit N for the number of falling edges or dominant pulses DP is configured in one of parameters 152A or 152B and can be stored in register 1525.
[0090] In other words, if the number of edges in the RxD signal and / or the number of time quantum TQs seen as bit value 0 (dominant) exceeds a previously selected limit, the device 11, in particular the tampering detection module 15, treats this as a format error. Due to the format error, the currently received frame 450 is evaluated or classified as invalid by the subscriber station 10 (receiver). As a result, the subscriber station 10 (receiver) rejects frame 450.
[0091] As shown in Figure 8, the end field 458 (EOF) can be classified as invalid (format error) based on the counter reading of counter 1511, for example, N=2, or the counter value Z1. This means that in the examples in Figures 7-9, reception is interrupted, and the subscriber station 10 (receiving node) does not receive the subsequent second frame (attack CAN frame). Instead, the subscriber station 10 (receiving node) initiates an error frame 47 (error frame). Thus, the attack is prevented by the currently received frame 450 (carrier frame into which the second frame is integrated).
[0092] The device 11, in particular the tampering detection module 15, evaluates at least one predetermined field or bit, in particular the ACK delimiter bit and / or field 458 (EOF) and / or the error delimiter field (which is part of the error frame 47), using the evaluation block 1511 and at least one of the counters 1511 and 1512, for the received CAN frame 450. The predetermined field or bit is configured as one of the parameters 152A and 152B and can be stored in the register 1525.
[0093] For example, the device 11, in particular the tampering detection module 15, may proceed as follows: If the first evaluation block 151 detects a synchronous edge corresponding to the falling edge of the RxD signal in one of the fields to be evaluated in the CAN frame 450, block 151 reports this to the second evaluation block 152 as the dominant sampling bit at the next sampling point SP (sampling point, Figure 6) via signals S1, BW.
[0094] The second evaluation block 152 uses signals S1 and BW to perform a comparison with the CAN format of the frame shown in Figure 2, thereby detecting any format errors in the currently received frame 450.
[0095] In this way, a bit error in one of the bits of the DLC field of frame 450 can be reliably detected in the case of an embedded frame attack. This makes it very easy to circumvent the tactic of having one valid frame 450 (carrier frame) contain another valid frame 450, while the receiving subscriber station detects not just one frame 450 (carrier frame), but two valid frames 450.
[0096] According to the second embodiment, the apparatus 11, in particular the tampering detection module 15, proceeds as follows: For example, at least one counter 1511, 1512 of the first evaluation block 151 counts a column or sequence of N consecutive time quantities TQ instead of individual time quantities TQ. Thus, the resolution can be set by N, that is, it can be set from which width of the dominant pulse DP the counters 1511, 1512 count. Here, N may be any natural number. In particular, N may be a number between 1 and 500 in specific examples.
[0097] In particular, the count value Z1 of counter 1511 is changed, specifically incremented or decremented, only when N=3 is selected and, for example, three time quantum TQs with dominant bit values occur consecutively.
[0098] In the second embodiment, robustness against short dominant pulses DP can be obtained. Furthermore, the above attack can be avoided by a valid frame 450 (carrier frame) with an embedded valid CAN frame. This is because the transmitter of the valid frame 450 (carrier frame) is configured to emulate the embedded attack CAN frame only with a bit time t_bt2 resolution for the bits of the data phase 452. It is also possible by chance that a frame 450 (carrier frame) is transmitted in which the data field 455 coincidentally contains a bit sequence that looks like an embedded attack CAN frame (attack CAN frame). In this way, the inspection by the tampering inspection modules 15, 25, and 35 protects against intentional (attack) and unintentional transmission of carrier frames.
[0099] In addition, modules 15, 25, and 35 are configured in the same manner as described above for the first embodiment. According to the third embodiment, the tampering detection module 15 has only one counter, namely either the first counter 1511 or the second counter 1512. In this case, value N=1 is selected as the upper limit of counter value Z1 or Z2, and at this counter value Z1 or Z2, the tampering detection module 15 determines that the currently received frame 450 has a format error and is therefore to be discarded. In this case, the first evaluation block 151 reports a dominant bit after one synchronization edge.
[0100] Choosing N=1 is very advantageous because it only requires implementing one counter to count the number of synchronous edges (falling edges) or the number of consecutive dominant time quanta TQ1-TQ8. Furthermore, a counter that only counts from 0 to 1 is very easy to implement and cost-effective.
[0101] In addition, modules 15 and 35 are configured in the same manner as described above for the first embodiment. According to the fourth embodiment, the device 11, in particular the tampering detection module 15, is configured to additionally use the evaluation of the currently received frame 450 described above when reintegrating the subscriber station 10 into ongoing communications on the bus 40. Such reintegration is required when the subscriber station 10 is restarted or woken up again after a period of inactivity. In the case of CAN XL communications in a special mode where the error signal is turned off by the subscriber station configuration, reintegration is performed whenever a reception error is detected.
[0102] In this case, the device 11, in particular the tampering detection module 15, uses blocks 151 and 152 to evaluate whether 11 recessive bits are detected consecutively on the CAN bus 40. If such a bit sequence is detected, the device 11, in particular the tampering detection module 15, evaluates this as a stationary state ("idle state") on the bus. Thus, the bus 40 is free, and the device 11 can begin sending messages 45 and 46 to the bus 40.
[0103] In this way, the ongoing operation of bus system 1 and higher-level technical equipment is not interrupted. This means that the function of avoiding at least some unauthorized operations of bus system 1 can also be used to contribute to improving the data rate within the bus system. This makes it very easy and efficient to prevent unexpected interference and / or performance degradation of bus system 1.
[0104] In addition, modules 15 and 35 are configured in the same manner as described above for the first or second embodiment. According to the fifth embodiment, at least one of the subscriber stations 10, 30 is configured to generate a frame 450 as a result of detected tampering and transmit it over the bus 40, and notifies the other subscriber stations 10, 20, 30 that a frame 450 already transmitted over the bus 40 or a previously transmitted frame 450 has been detected as having been tampered with.
[0105] All embodiments of the subscriber stations 10, 20, 30, bus system 1, and the methods implemented therein, as described above, can be used individually or in all possible combinations. In particular, all features of the embodiments described above and / or their modifications can be combined arbitrarily. Additionally or alternatively, the following modifications are particularly conceivable:
[0106] Although the present invention has been described above using the example of a CAN bus system, the present invention can be used in each communication network and / or communication method that uses two different communication phases, each with different bus states generated for different communication phases. In particular, the present invention can be used in the development of Ethernet and / or 10BASE-T1S Ethernet, fieldbus systems, and other serial communication networks.
[0107] In particular, the bus system 1 according to the embodiment may be a communication network capable of serially transmitting data at two different bit rates. It is advantageous, but not essential, for the bus system 1 to guarantee exclusive and collision-free access to a common channel for subscriber stations 10, 20, and 30 for at least a certain period of time.
[0108] The number and arrangement of subscriber stations 10, 20, and 30 in the bus system 1 of this embodiment are arbitrary. In particular, subscriber station 20 in bus system 1 is optional. It is also possible for one or more subscriber stations 10 or 30 to exist in bus system 1. It is also possible for all subscriber stations in bus system 1 to be configured in the same way, that is, for only subscriber station 10 or only subscriber station 30 to exist.
Claims
1. The subscriber stations (10;20;30) of the serial bus system (1), A communication control device (11;21;31) controls communication between the subscriber station (10;20;30) and at least one other subscriber station (10;20;30) of the serial bus system (1), and generates a transmit signal (TxD) according to a frame (450), A receiving device (12; 22; 32) configured to serially receive at least one signal (CAN_H, CAN_L; VDIFF) from the bus (40) of the serial bus system (1), Tampering detection modules (15;25;35) for checking whether at least one predetermined field (457, 458) of a received frame (450;450_1_1, 450_1_2) created by the receiving device (12;22;32) from the serial bus system (1) has at least one pulse (DP) having a second bit value opposite to the predetermined first bit value in a received bit having a predetermined first bit value and a predetermined duration (t_bt1;t_bt2), based on an evaluation of the received bit at the sampling point (SP), It has, The tampering detection modules (15; 25; 35) are configured to check whether at least one dominant pulse (DP) having a shorter duration than the received recessive bit occurs in the bit sequences of at least two received recessive bits having durations (t_bt1; t_bt2), respectively. The tamper detection module (15; 25; 35) is further configured to discard the received frame (450; 450_1_1, 450_1_2) after the presence of at least one pulse (DP) having a second bit value opposite to a predetermined first bit value. Subscriber station.
2. The subscriber station (10;20;30) according to claim 1, wherein the tampering detection module (15;25;35) is configured to perform an inspection of at least one predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2), in addition to comparing the received frame (450;450_1_1, 450_1_2) with a frame format valid for the serial bus system (1).
3. The subscriber station (10;20;30) according to claim 1, wherein the tamper detection module (15;25;35) is configured to discard the received frame (450;450_1_1, 450_1_2) after the number of at least one pulse (DP) having a second bit value inverse to a predetermined first bit value exceeds a predetermined upper limit (N).
4. The subscriber station (10;20;30) according to claim 1, wherein the tampering detection module (15;25;35) is configured to check whether at least one dominant pulse (DP) having a shorter duration than the received recessive bit occurs in a received recessive bit having a duration (t_bt1;t_bt2).
5. The subscriber station (10;20;30) according to claim 1, wherein the tampering detection module (15;25;35) has a first counter (1511) for counting the number of falling edges that occur from the start of the predetermined fields (457, 458) of the received frame (450;450_1_1, 450_1_2) to the end of the predetermined fields (457, 458) of the received frame (450;450_1_1, 450_1_2).
6. The subscriber station (10;20;30) according to claim 5, wherein the tampering detection module (15;25;35) has a first evaluation block (151) having the first counter (1511).
7. The subscriber station (10; 20; 30) according to claim 6, wherein the first evaluation block (151) is the bit timing logic of the communication control device (11).
8. The tampering detection module (15; 25; 35) has a second evaluation block (152) for evaluating whether the frame (450; 450_1_1) should be discarded, The second evaluation block (152) is configured to exchange signals (S1, S2, BW) with the first evaluation block (151) in order to evaluate the predetermined fields (457, 458) of the received frame (450; 450_1_1, 450_1_2). The subscriber station (10; 20; 30) according to claim 6.
9. The subscriber station (10; 20; 30) according to claim 8, wherein the second evaluation block (152) is the bitstream processor of the communication control device (11).
10. The subscriber station (10;20;30) according to claim 1, wherein the tamper detection module (15;25;35) has a second counter (1512) for counting the number of time quanta (TQ) occurring from the start of the predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2) to the end of the predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2).
11. The subscriber station (10;20;30) according to claim 1, wherein the tamper detection module (15;25;35) has a second counter (1512) for counting a predetermined number of consecutive time quanta (TQ) occurring from the start of the predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2) to the end of the predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2).
12. The subscriber station (10; 20; 30) according to claim 10 or 11, wherein the tamper detection module (15; 25; 35) has a first evaluation block (151) having the second counter (1512).
13. The subscriber station (10;20;30) according to claim 12, wherein the first evaluation block (151) is the bit timing logic of the communication control device (11).
14. The tampering detection module (15;25;35) has a second evaluation block (152) for evaluating whether the frame (450;450_1_1) should be discarded. The subscriber station (10;20;30) according to claim 12, wherein the second evaluation block (152) is configured to exchange signals (S1, S2, BW) with the first evaluation block (151) to evaluate the predetermined fields (457, 458) of the received frame (450;450_1_1, 450_1_2).
15. The subscriber station (10;20;30) according to claim 14, wherein the second evaluation block (152) is the bitstream processor of the communication control device (11).
16. The subscriber station (10;20;30) according to claim 1, wherein the at least one predetermined field (457, 458) of the received frame (450;450_1_1, 450_1_2) includes at least one of the following fields or bits: the acknowledgment spacer bit (ACK delimiter) in the acknowledgment field (457) of the received frame (450;450_1_1, 450_1_2) following the acknowledgment bit (ACK slot), the end field (458) of the received frame (450;450_1_1, 450_1_2), and the error delimiter of the error frame (47).
17. The subscriber station (10;20;30) according to claim 1, wherein the tampering detection module (15;25;35) is configured to perform the inspection on dominant pulses (DP) in order to detect a predetermined quiescent state on the bus (40) having a predetermined number of bits having the same value that would otherwise not occur in the communication on the bus (40).
18. The subscriber station (10;20;30) according to claim 1, wherein the communication control device (11;21;31) for serially generating the transmission signal (TxD) to be transmitted to the bus (40) is configured such that the bit time (t_bt1) of the signal transmitted to the bus (40) in the first communication phase (451) and the bit time (t_bt2) of the signal transmitted in the second communication phase (452) are different with respect to the frame (450).
19. The subscriber stations (10;20;30) of the serial bus system (1) according to claim 1, wherein in a first communication phase (451), negotiations are held regarding which of the subscriber stations (10;20;30) of the serial bus system (1) will obtain exclusive and collision-free access to the bus (40), at least temporarily, in a subsequent second communication phase (452).
20. Bus (40) and, At least two subscriber stations (10;20;30) are connected via the bus (40) to enable serial communication with each other, and at least one of them is a subscriber station (10;20;30) as described in claim 1, A bus system (1) having the following features.
21. A communication method in a serial bus system (1), which is performed at a subscriber station (10;20;30) of the serial bus system (1) having a communication control device (11;21;31), a receiving device (12;22;32), and a tamper detection module (15;25;35), The communication method in the serial bus system (1) is: A step of controlling communication between the subscriber station (10;20;30) and at least one other subscriber station (10;20;30) of the serial bus system (1) using the communication control device (11;21;31), wherein the communication control device (11;21;31) is configured to generate a transmit signal (TxD) according to a frame (450), The receiving device (12; 22; 32) serially receives at least one signal (CAN_H, CAN_L; VDIFF) from the bus (40) of the serial bus system (1), The steps include: checking whether at least one predetermined field (457, 458) of a received frame (450; 450_1_1, 450_1_2) created by the receiving device (12; 22; 32) from the bus (40) has at least one pulse (DP) having a second bit value opposite to the predetermined first bit value, based on an evaluation of the received bit at the sampling point (SP), in a received bit having a predetermined first bit value and a predetermined duration (t_bt1; t_bt2); It has, The tampering detection modules (15; 25; 35) are configured to check whether at least one dominant pulse (DP) having a shorter duration than the received recessive bit occurs in the bit sequences of at least two received recessive bits having durations (t_bt1; t_bt2), respectively. The tamper detection module (15; 25; 35) is further configured to discard the received frame (450; 450_1_1, 450_1_2) after the presence of at least one pulse (DP) having a second bit value opposite to a predetermined first bit value. method.
Citation Information
Patent Citations
Method for controlling data frames with redundant identifier on e.g. controller area network bus, involves initiating termination of transmission of data frames, if identifier of frames is matched with identifier of second bus device
DE102012224234A1