Network with data integrity monitoring capabilities
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- THE BOEING CO
- Filing Date
- 2022-02-07
- Publication Date
- 2026-08-04
AI Technical Summary
【0023】 説明してきた形態、作用及び効果を様々な例毎に個別に実現することができるし、さらに別の例に組み入れてもよく、このような例のさらなる詳細を以下の説明と図面とを参照して理解することができる。
Smart Images

Figure 0007900158000001 
Figure 0007900158000002 
Figure 0007900158000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to data communication and networks, and more particularly to a network having a data integrity monitoring function.
Background Art
[0002] In the specifications of networks that communicate data such as data networks installed in airplanes and other systems, although erroneous data is not detected, it is defined that there is a possibility that it is acceptable for the continued operation of the airplane or system. Possible types of damage to the data network include spoof messages, lack of sequence integrity, excessive or increased latency, and data corruption. There is some possibility of damage caused by line replaceable units (LRUs) or the physical layer, such as electromagnetic radiation, vibration, and contamination of optical fibers. The data integrity monitoring function in a network, particularly a data network installed in an airplane, is important for taking countermeasures and avoiding or minimizing the grounding of the airplane.
Summary of the Invention
Means for Solving the Problems
[0003] According to an example, a method for monitoring the data integrity of a network includes the step of reading error data from an interface associated with a specific link of the network in response to the presence of error data in a message received at the specific link. The method also includes the step of creating a report message including the error data and the step of transmitting the report message to a network monitoring algorithm operable on a processor circuit. The network monitoring algorithm is configured to determine the data integrity of a specific link based on the error data.
[0004] In either of the above examples, a method for monitoring network data integrity includes the step of receiving a message by a network switch or network node using a network link. The method also includes the step of determining whether the message contains error data and, if the message contains error data, creating a report message. The method further includes the step of sending the report message to a network data integrity management unit to determine whether the link is faulty.
[0005] In either of the above examples, or in another example, a network with data integrity monitoring capabilities comprises multiple network switches. These network switches are configurable to selectively interconnect two or more network nodes from a group of network nodes. Each network switch includes a network switch processor circuit and a switch function that operates within the network switch processor circuit. The switch function is configured to selectively connect the network switch to another network switch or to a network node from the group of network nodes. Each network switch also includes a network switch error data reporting function, configurable within the network switch processor circuit, which reads error data from the switch interface associated with a particular link in the network, creates a network switch report message containing the error data, and sends the network switch report message to a network monitoring algorithm. The network monitoring algorithm is configured to determine the data integrity of a particular link.
[0006] In either of the above examples, the method and the network further include the step of determining the data integrity of a particular link by determining whether the error data exceeds an error data threshold for that link. The data integrity of a particular link becomes unacceptable as the error data exceeds the error data threshold. The method and the network further include the step of performing a default action in response to a failure in a particular link.
[0007] In either of the above examples, the default response includes at least one of the steps of blocking a specific link or transmitting data using another link in the network until the specific link is repaired.
[0008] In either of the above examples, the step of reading error data includes reading error data from the network interface of the network node by an error data reporting function that can be operated in the processor circuit of the network node, and the step of sending a report message includes sending a report message by the error data reporting function of the network node.
[0009] In either of the above examples, the step of reading error data includes reading error data from the switch interface of the network switch by an error data reporting function that can be operated in the processor circuit of the network switch, and the step of sending a report message includes sending a report message by the error data reporting function of the network switch.
[0010] In either of the above examples, the method and the network further include the step of receiving a specific reporting message by a network monitoring node for each of the links among a plurality of links in the network for which error data exists. The network monitoring node includes a network monitoring algorithm. The method and the network further include the step of reading the error data from the specific reporting message for each link and the step of determining the data integrity of each link by determining whether the error data exceeds an error data threshold for each link. The data integrity of a link becomes unacceptable as the error data exceeds the error data threshold. The method and the network further include the step of performing a default action in response to a link failure.
[0011] In either of the above examples, the method and network further include the step of receiving a message using a specific link, the message being received by either a network switch or a network node. The method and network further include the step of determining whether the message contains error data using an embedded error detection method. The method and network further include, based on the embedded error detection method, incrementing the count of an error data counter associated with the specific link by 1 in the memory of the network switch or network node, in accordance with the presence of error data. A report message is created after a predetermined period has elapsed, and the report message contains the count of the error data counter.
[0012] In either of the above examples, the method and the network further include the step of sending a report message to the network data integrity management unit via the error data reporting function of the network switch or network node that received the message. The network data integrity management unit is configured to use the count of the error data counter to determine the likelihood that an undetected corruption message is sent by a particular link.
[0013] In either of the above examples, the method and the network further include the step of using an embedded error detection method to determine whether a message contains error data.
[0014] In either of the above examples, the method and the network further include the step of incrementing the count of an error data counter associated with a link in response to a message containing error data.
[0015] In the case of one example and the example above, the method and the network further include the steps of enabling one or more further messages to be received via the link in accordance with the fact that a predetermined period has not elapsed, and incrementing the count of an error data counter for each of the further messages containing error data.
[0016] In either of the examples above, the reporting message includes an error data counter count.
[0017] In the case of either Example 1 or the above example, the method and the network further include the steps of adding the count of an error data counter to the count of a corrupted data counter, comparing the count of the corrupted data counter with an error data threshold for the link, and determining that the link is faulty in accordance with the fact that the count of the corrupted data counter exceeds the error data threshold for the link.
[0018] In either of the above examples, the method and the network further include the steps of determining the likelihood of an undetected corruption message being transmitted by a link using a corrupted data counter count, and transmitting a message indicating that the likelihood of undetected corruption on a link has exceeded a design value, in accordance with the corrupted data counter count exceeding an error data threshold for the link.
[0019] In one example and in either of the above examples, at least some of the network nodes include a network node processor circuit and a vehicle function that is operable on the network node processor circuit and performs specific functions related to the vehicle. At least some of the network nodes further include a network node error data reporting function that is operable on the network node processor circuit and reads error data from a network interface related to another specific link in the network, creates a network node report message containing the error data, sends the network node report message to a network monitoring algorithm, and the network monitoring algorithm is configured to determine the data integrity of another specific link.
[0020] In either of the above examples, the method and the network further include network monitoring nodes for multiple network nodes. The network monitoring node includes a processor circuit, a network monitoring algorithm operable on the processor circuit, memory associated with the processor circuit, and a configuration table stored in the memory. The configuration table includes identification information for each of the multiple links in the network and an error data threshold associated with each link. The configuration table is configured to be used by the network monitoring algorithm to determine whether error data read from an interface associated with a particular link in the network exceeds the error data threshold for that particular link.
[0021] In either of the above examples, the network monitoring node is configured to perform a set of functions that include, for each of the multiple links in the network where error data exists, the function to receive a specific reporting message, the function to read the error data from the specific reporting message for each link, the function to determine the data integrity of each link by determining whether the error data exceeds an error data threshold for each link, the function that the data integrity of a link becomes unacceptable as the error data exceeds the error data threshold, and the function to perform a default action in response to a link failure.
[0022] In either of the above examples, the network further includes a network data integrity management unit. The network data integrity management unit includes a processor circuit and memory associated with the processor circuit. The memory includes computer-readable program instructions that, when executed by the processor circuit, cause the processor circuit to execute a set of functions that includes the function of receiving a reported error message with a count of an error data counter associated with a particular link. The count of the error data counter increases as each message is received using a particular link containing error data. The set of functions also includes the function of adding the count of the error data counter to the count of a corrupted data counter. The set of functions further includes the function of comparing the count of the corrupted data counter with an error data threshold for a particular link, and the function of determining that a particular link is faulty as the count of the corrupted data counter exceeds the error data threshold for that link.
[0023] The forms, functions, and effects described can be implemented individually in various examples, or they can be incorporated into other examples. Further details of such examples can be understood by referring to the following descriptions and drawings. [Brief explanation of the drawing]
[0024] [Figure 1A]A block schematic diagram of an example of a network with a data integrity monitoring function according to an example of the present disclosure. [Figure 1B] A block schematic diagram of a typical network of FIG. 1A including an example of a network switch and a network node configured for a data integrity monitoring function according to an example of the present disclosure. [Figure 2] A block schematic diagram of a network including a system for a data integrity monitoring function according to another example of the present disclosure. [Figure 3] A flowchart of an example of a method for creating a setting table used for a data integrity monitoring function according to an example of the present disclosure. [Figure 4] An example of a message including data and an embedded error detection code used for a data integrity monitoring function according to an example of the present disclosure. [Figure 5] An example of a setting table including identification information for each link of a plurality of links in a network and an error data threshold related to each link according to an example of the present disclosure. [Figure 6A] A flowchart of an example of a method for monitoring the data integrity of a network according to an example of the present disclosure. [Figure 6B] A flowchart of an example of a method for monitoring the data integrity of a network according to an example of the present disclosure. [Figure 7A] A flowchart of an example of a method for monitoring the data integrity of a network according to another example of the present disclosure. [Figure 7B] A flowchart of an example of a method for monitoring the data integrity of a network according to another example of the present disclosure.
Mode for Carrying Out the Invention
[0025] In the following detailed description of the embodiments, reference is made to the accompanying drawings that illustrate specific embodiments of the present disclosure. Other embodiments having different structures and performing different operations do not depart from the scope of the present disclosure. Like reference numerals may refer to the same components in different drawings.
[0026] This disclosure may be a system, method, and / or a computer program product. The computer program product may include a computer-readable storage medium (also referred to as a medium) containing computer-readable program instructions that cause a processor to execute an aspect of this disclosure.
[0027] A computer-readable storage medium can be a tangible device capable of holding and storing instructions used by an instruction execution device. A computer-readable storage medium may be, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples of computer-readable storage media include portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM, i.e., flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multi-purpose discs (DVDs), memory sticks, floppy disks, perforated cards, and mechanically encoded devices such as grooved raised structures with instructions stored in the groove structure itself, or any suitable combination thereof. The computer-readable storage medium used in this application is not to be interpreted as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (for example, an optical pulse passing through an optical fiber cable), or a transient signal itself such as an electrical signal transmitted by a wire.
[0028] The computer-readable program instructions described in this application can be downloaded from a computer-readable storage medium to each computing / processing unit, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing unit receives computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each computing / processing unit.
[0029] The computer-readable program instructions for performing the operations of this disclosure may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-specific instructions, microcode, firmware instructions, state setting data, or they may be written in any combination of one or more programming languages, and may be either source code or object code including object-oriented programming languages such as Smalltalk or C++, or they may be traditional procedural programming languages such as C or similar programming languages. The entire computer-readable program instructions may be executed on the user's computer, or only a portion of the instructions may be executed on the user's computer, or the instructions may be executed as a standalone software package, or parts of the instructions may be executed on the user's computer and a remote computer, or the entire instructions may be executed on a remote computer or server. In the latter part of the description, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or a connection to an external computer may be made (for example, using the Internet with an Internet Service Provider). In some embodiments, to carry out aspects of the present disclosure, computer-readable program instructions may be executed by using, for example, electronic circuits including programmable logic circuits, field-programmable gate arrays (FPGAs), and programmable logic arrays (PLAs), and by utilizing state information of computer-readable program instructions and customizing them for the electronic circuits.
[0030] This description will explain aspects of the disclosure with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the disclosure. It will be understood that each block in the flowcharts and / or block diagrams and combinations of blocks in the flowcharts and / or block diagrams can be implemented by computer-readable program instructions.
[0031] A computer-readable program instruction may be given to the processor of a general-purpose computer, a dedicated computer, or other programmable data processing device to generate a machine, such that the instruction executed by the processor of the computer or other programmable data processing device generates means for performing functions / operations shown in one or more blocks of a flowchart and / or block diagram. The computer-readable program instruction may also be stored in a computer-readable storage medium, which can instruct a computer, a programmable data processing device, and / or other device to function in a particular way, such that the computer-readable storage medium containing the instruction comprises a product containing the instruction for performing the modes of functions / operations shown in one or more blocks of a flowchart and / or block diagram.
[0032] Computer-readable program instructions can also be loaded into a computer, other programmable data processing device, or other device so that a series of action steps are executed by the computer, other programmable device, or other device, thereby realizing a process performed by the computer.
[0033] Figure 1A is a block schematic of an example of a network 100 with data integrity monitoring capabilities according to an example of the present disclosure. In one example, network 100 is a data network installed on a vehicle 104, such as an airplane or other vehicle or system. Network 100 includes a plurality of network switches 106, shown as 106a to 106n in Figure 1A. The plurality of network switches 106a to 106n can be configured to selectively interconnect two or more network nodes 108, shown as 108a to 108n in Figure 1A, by links 110. As described in more detail with reference to Figure 1B, at least some of the network switches 106 and network nodes 108 are configured for or include a form of data integrity monitoring capabilities. In addition, in some examples, a network data integrity management unit 112 is configured to monitor data integrity. Examples of methods for monitoring network data integrity that can be performed by the network data integrity management unit 112 are described in more detail with reference to Figures 7A and 7B.
[0034] In the example shown in Figure 1A, the network data integrity management unit 112 is implemented within the integrated processing module 114. In some examples, the integrated processing module 114 is also the network node 108a. The network data integrity management unit 112, as described in more detail herein, is configured to monitor the data integrity of the network 100 and to perform one or more default actions in response to detecting error data on a link 110 associated with a particular network switch 106 or network node 108. Examples of default actions include, but are not limited to, blocking the particular link 110, sending a message or data via an alternative link 110, and / or generating and sending a message indicating that the particular link 110 is faulty. The message is sent to the responsible contact so that the link 110 can be repaired or replaced. Possible causes of error data on link 110 include spoofed messages, incomplete sequence, excessive or increased latency, and data corruption. In addition, corrupted or erroneous data may be caused by electromagnetic radiation, vibration, or contamination of optical fibers, among other factors, in the Line Replacement Units (LRUs) or physical layer of the network 100.
[0035] In the example shown in Figure 1, the network data integrity management unit 112 includes an undetectable corruption prediction algorithm 116. The undetectable corruption prediction algorithm 116 is configured to predict the amount of undetectable corrupted data that may have been transmitted using a particular link 110, or the number of undetected messages containing error data 128, based on the number of detected corrupted messages or the number of detected messages containing error data. Corrupted data and error data have the same meaning and may be used interchangeably in this application. In one example, the undetectable corruption prediction algorithm 116 is configured to predict the amount of undetectable corrupted data or the number of undetected messages containing error data 128 by using network traffic volume, i.e., rate information, message size, and link speed combined with a mathematical error model that compares the number of error patterns detected by the frame check sequence's CRC (or other protection method) with the number of times they were not detected. In some examples, the network traffic volume, i.e., rate information, message size, and link speed for each link 110 are also included in the configuration table 168 (Figure 2).
[0036] In the example illustrated in Figure 1A, the integrated processing module 114, or network data integrity management unit 112, includes a processor circuit 118 and associated memory 119. The memory 119 contains computer-readable program instructions 120 that cause the processor circuit 118 to execute a set of functions 121 when executed by the processor circuit 118. An example of the set of functions 121 is an undetectable corruption prediction algorithm 116.
[0037] The network data integrity management unit 112 also includes a corrupted data counter 122. As described in more detail in this document with reference to Figures 7A and 7B, the count of the corrupted data counter 122 is compared with a default data threshold for a particular link 110. If the count is below the default threshold, no action is taken. If the count exceeds the default threshold, the count of the corrupted data counter 122 is used by the undetectable corruption prediction algorithm 116 to determine the likelihood that an undetected corruption message may be transmitted by the particular link 110. The network data integrity management unit 112 performs a default action in accordance with the count exceeding the default threshold. The default threshold is adjustable for each link 110 to coordinate the data integrity monitoring function of the network 100. For example, some network nodes 108 that perform more critical or essential vehicle functions require a higher level of data integrity compared to other network nodes 108 that perform less critical or essential vehicle functions. Network nodes 108 and associated links 110 that perform more critical or essential vehicle functions have a lower tolerance for corrupted data or messages, and their default thresholds are smaller compared to other network nodes 108 and associated links 110 that perform less critical or essential vehicle functions. These network nodes 108 and associated links 110 have a higher tolerance for corrupted data or messages, meaning they can tolerate a higher rate of corrupted data or messages, and their default thresholds are correspondingly higher.
[0038] Referring to Figure 1B, Figure 1B is a block schematic of a typical network 100 of Figure 1A, including an example of a network switch 106 and a network node 108 configured for a data integrity monitoring function, relating to an example of the present disclosure. As described above, the network 100 includes a plurality of network switches 106a to 106n. The plurality of network switches 106a to 106n can be configured to selectively interconnect two or more network nodes 108a to 108n from a plurality of network nodes 108a to 108n. Each network switch 106 includes a network switch processor circuit 124 and a switch function 125 that can be operated by the processor circuit 124 and selectively connects the network switch 106 to another network switch 106 or to a network node 108 from the plurality of network nodes 108a to 108n.
[0039] Each network switch 106 also includes a network switch error data reporting function 126 that can be operated by a network switch processor circuit 124. The error data reporting function 126 is configured to read error data 128 from a switch interface 130 associated with a specific link 110 of the network 100. In some examples, the function of reading error data from the switch interface 130 includes a function that uses an embedded error detection method to determine whether a message received by the switch interface 130 contains error data 128. Examples of embedded error detection methods include, but are not limited to, cyclic redundancy checks (CRC) embedded in the message and frame check sequences (FCS) embedded in the message. See also Figure 4, which is an example of a message 400 including data 402 and an embedded error detection code 404 used in a data integrity monitoring function according to an example of the present disclosure. In the example message 400 in Figure 4, the embedded error detection code 404 is a frame check sequence.
[0040] The error data reporting function 126 is also configured to create a network switch report message containing error data and send the network switch report message to the network monitoring algorithm 132. The network monitoring algorithm 132 is configured to determine the data integrity of a specific link 110. In the example illustrated in Figure 1B, the network monitoring algorithm 132 is implemented and executed by a network node 108, for example, a network monitoring node 134, i.e., node 108n. In some examples, the network monitoring node 134 is used instead of the integrated processing module 114 and the network data integrity management unit 112.
[0041] In some examples, each network switch 106 includes a processor circuit 124 and a memory 136 associated with the processor circuit 124. The memory 136 includes computer-readable program instructions 138 that cause the processor circuit 124 to execute a set of functions 140 when executed by the processor circuit 124. Examples of the set of functions are described in more detail with reference to Figures 6A to 6B. In the example of Figure 1B, the set of functions 140 includes a switch function 125 that can be operated by the processor circuit 124. The switch function 125 is configured to selectively connect network switch 106a to another network switch 106 or to selectively connect network switch 106 to one of several network nodes 108a to 108n 108.
[0042] The function set 140 also includes a network switch error data reporting function 126 that can operate in the network switch processor circuit 124. In some examples, the function set 140 or the error data reporting function 126 includes the function of reading error data 128 from a switch interface 130 associated with a specific link 110 of the network 100. The function set 140 or the error data reporting function 126 also includes the function of creating a network switch report message containing the error data 128. The function set 140 or the error data reporting function 126 further includes the function of sending the network switch report message to a network monitoring algorithm 132. The network monitoring algorithm 132 is configured to determine the data integrity of a specific link 110 based on the error data.
[0043] In some examples, each network switch 106 also includes an error data counter 141. As illustrated with reference to Figure 7A, when a message received by the network switch 106 includes error data 128, i.e., when the error data 128 is read from the switch interface 130, the count of the error data counter 141 associated with a particular link 110 is incremented by 1. In the example of Figure 1B, the error data counter 141 is stored in the memory 136 of the network switch 106.
[0044] At least some of the network nodes 108a to 108n, for example, network node 108c in Figure 1B, include a processor circuit 142 and vehicle functions 144 and functions that can be operated by the network node processor circuit 142. The vehicle functions 144 are configured to perform specific functions related to the vehicle 104. In some examples, the processor circuit 142 is of the same type or similar to the processor circuit 124 of the network switch 106. In other examples, the processor circuit 142 is different from the processor circuit 124 of the network switch 106.
[0045] Network node 108 also includes a network node error data reporting function 146 that can be operated by the network node processor circuit 142. The network node error data reporting function 146 is configured to read error data 128 from a network interface 150 associated with a specific link 110 of network 100. The error data reporting function 146 of network node 108 is also configured to create a network node report message containing the error data 128. The error data reporting function 146 of network node 108 is further configured to send the network node report message to the network monitoring algorithm 132. As described above, the network monitoring algorithm 132 is configured to determine the data integrity of a specific link 110.
[0046] In some examples, each network node 108 includes a processor circuit 142 and a memory 152 associated with the processor circuit 142. The memory 152 includes computer-readable program instructions 154 that cause the processor circuit 142 to execute a set of functions 156 when executed by the processor circuit 142. Examples of the set of functions 156 are described in more detail with reference to Figures 6A and 6B. In the example of Figure 1B, the set of functions 156 includes one or more vehicle functions 144 and an error data reporting function 146.
[0047] In some examples, at least some network nodes 108 also include an error data counter 141. As illustrated with reference to Figure 8A, when a message received by a network node 108 includes error data 128, i.e., when the error data 128 is read from the network interface 150, the count of the error data counter 141 associated with a particular link 110 is incremented by 1. In the example of Figure 1B, the error data counter 141 is stored in the memory 152 of the network node 108.
[0048] In some examples, multiple network nodes 108a to 108n include a network monitoring node 134. The network monitoring node 134 includes a processor circuit 158 and a network monitoring algorithm 132 that can run on the processor circuit 158. The processor circuit 158 may be the same as or similar to processor circuits 124 and 142, or it may be a different type of processor circuit.
[0049] The network monitoring node 134 also includes memory 160 associated with the processor circuit 158. In the example in Figure 1B, memory 160 stores the network monitoring algorithm 132. In some examples, memory 160 also stores one or more vehicle functions 162 executed by the processor circuit 158. Memory 160 includes computer-readable program instructions 164 that cause the processor circuit 158 to execute a set of functions 166 when executed by the processor circuit 158. Examples of the set of functions 166 are described in more detail with reference to Figures 6A and 6B. In the example in Figure 1B, the set of functions 156 appropriately includes one or more vehicle functions 162 and the network monitoring algorithm 132.
[0050] In some examples, the network monitoring node 134 also includes a configuration table 168 stored in memory 160. See also Figure 5, which is an example of a configuration table 168 that includes identification information 502 for each of the multiple links 110 of the network 100 and an error data threshold 504 associated with each link 110. In the example in Figure 5, the configuration table 168 includes a first column 506 of link identification information 502 and a second column 508 listing the associated error data threshold 504. The configuration table 168 is configured to be used by the network monitoring algorithm 132 and / or the undetectable failure prediction algorithm 116 to determine whether error data 128 read from an interface 130 or 150 associated with a particular link 110 of the network 100 exceeds the error data threshold 504 for that particular link 110.
[0051] Figure 2 is a block schematic of a network 200 including a system 202 for data integrity monitoring functions, relating to another example of the present disclosure. In one example, network 200 is a data network installed on a vehicle 104, such as an airplane or other vehicle or system. Network 200 is similar to network 100 in Figures 1A and 1B, except that at least some or all of the network switches 106 in network 200 are remote switches 206 manufactured by Aeronautical Radio Corporation (ARINC), indicated as 206a to 206n in Figure 2. Multiple ARINC remote switches (ARS) 206a to 206n can be configured by links 110 to selectively interconnect two or more network nodes 108, indicated as 108a to 108n in Figure 2. At least some of the ARS 206 and network nodes 108 are configured for data integrity monitoring functions or include forms of data integrity monitoring functions similar to those described above.
[0052] Each ARS206 includes a processor circuit 212 and a memory 214 associated with the processor circuit 212. In some examples, the processor circuit 212 and memory 214 are the same as the processor circuit 124 and memory 136 in Figure 1B. The memory 214 includes computer-readable program instructions 216 that cause the processor circuit 212 to execute a set of functions 218 when executed by the processor circuit 212. An example of the set of functions 218 includes a switch function 125 and a fault reporting function 220. The fault reporting function 220 includes the function of reading error data 128 from a switch interface 230 associated with a particular link 110 and sending a message to the network data integrity management unit 112 indicating that the particular link 110 is faulty. In some examples, the fault reporting function 220 is similar to those described in Figures 6A-6B or Figures 7A-7B.
[0053] In some examples, at least some ARS206 also include an error data counter 141. As illustrated with reference to Figure 7A, when a message received by the ARS206 includes error data 128, i.e., when the error data 128 is read from the switch interface 230, the count of the error data counter 141 associated with a particular link 110 is incremented by 1. In the example in Figure 2, the error data counter 141 is stored in the memory 214 of the ARS206.
[0054] In some examples, each ARS206 also includes an ARINC 664 end system 222 connected to a processor circuit 212. The ARINC 664 end system 222 is configured to perform a specific function. The ARINC 664 end system 222 includes a network interface device that enables network nodes 108 or network switches 206 to send and receive data on the ARINC 664 network 200. The ARINC 664 end system 222 handles ARINC 664 protocol elements, and is essentially an extended Ethernet interface. The ARINC 664 end system 222 communicates with the ARINC 664 switch 206, which polices, filters, and routes traffic between it and other ARINC end systems.
[0055] In the example where Vehicle 104 is an airplane, each network node 108 is configured to perform one or more airplane functions 208. Each of the network nodes 108 is also configured to perform an error data reporting function 146, as described above with reference to Figures 1A and 1B.
[0056] In some examples, the network 200 is connected to the integrated processing module 114, as illustrated in Figure 2. The integrated processing module 114 implements the network data integrity management unit 112. In one example, the integrated processing module 114 and the network data integrity management unit 112 are the same as those described above with reference to Figure 1A. In other examples, the integrated processing module 114 is replaced by a network monitoring node such as the network monitoring node 134, i.e., node 108n, in Figure 1B.
[0057] Figure 3 is a flowchart of an example of a method 300 for creating configuration tables, such as configuration table 168, used for a data integrity monitoring function, according to an example of the present disclosure. As described above, an example of configuration table 168 is shown in Figure 5. In one example, method 300 is implemented and executed in any system including a processor circuit and associated memory similar to those described herein. The memory includes computer-readable program instructions that cause the processor circuit to execute a set of functions described with reference to blocks 302-310 when executed by the processor circuit.
[0058] In block 302, method 300 includes the step of performing a method for configuring networks such as network 100 and network 200 when designing a vehicle 104 such as an airplane or other type of vehicle.
[0059] In block 304, method 300 includes the step of determining the data integrity level of each link 110 of network 100 or 200. The step of determining the data integrity level includes the step of determining the amount of error data 128 that is acceptable for a particular link 110. As described above, some network nodes 108 that perform more critical or essential vehicle functions require a higher level of data integrity compared to other network nodes 108 that perform less critical or essential vehicle functions. Network nodes 108 and associated links 110 that perform more critical or essential vehicle functions have a lower tolerance for error or corrupted data and a higher data integrity level compared to other network nodes 108 and associated links 110 that perform less critical or essential vehicle functions. These network nodes 108 and associated links 110 have a high tolerance for corrupted or error data, that is, they can tolerate a high rate of error data occurrence.
[0060] In block 306, method 300 includes the step of setting an error data threshold 504 for each link based on the data integrity level and the characteristics of a particular link.
[0061] In block 308, method 300 includes the step of creating a configuration table 168 to be used for a network monitoring algorithm, such as the network monitoring algorithm 132 in Figure 1B. The configuration table 168 includes identification information 502 for each link 110 and associated error data thresholds 504.
[0062] In block 310, method 300 includes the step of loading a configuration table 168 onto a network node 108, for example, the network monitoring node 134 in Figure 1B.
[0063] Figures 6A and 6B are flowcharts of an example of a method 600 for monitoring the data integrity of a network 100 or 200, relating to an example of the present disclosure. In some examples, the first part 602 of method 600 (Figure 6A) is implemented and executed by the network switch 106 and network node 108 in Figures 1A-1B and 2. The second part 616 of method 600 (Figure 6B) is implemented and executed by the network data integrity management unit 112 and / or network monitoring node 134 (Figure 1B) of the integrated processing module 114 (Figures 1A and 2). For example, the error data reporting function 126 of network switch 106 and the error data reporting function 146 of network node 108 include the first part 602 of method 600. The undetectable corruption prediction algorithm 116 and / or network monitoring algorithm 132 include the second part 616 of method 600.
[0064] In block 604, method 600 includes the step of starting an error data reporting function 126 on each network switch 106 and an error data reporting function 146 on each network node 108. In some examples, the error data reporting functions 126 or 146 are intermittent functions, for example, they run at predetermined intervals or for predetermined periods.
[0065] In block 606, method 600 includes the step of reading error data 128 from an interface (switch interface 130 or network interface 150) associated with a particular link 110 of network 100, in which case the error data 128 is present in a message received on a particular link 110, for example, message 400 in Figure 4. The step of reading error data 128 includes the step of reading error data 128 from the switch interface 130 of network switch 106 by an error data reporting function 126 that can be operated in the processor circuit 124 of network switch 106. The step of reading error data 128 also includes the step of reading error data 128 from the network interface 150 of network node 108 by an error data reporting function 146 that can be operated in the processor circuit 142 of network node 108.
[0066] In block 606, method 600 also includes the step of determining whether the message contains error data 128 using an embedded error detection method such as the cyclic redundancy check (CRC) or frame check sequence (FCS) described above.
[0067] In block 608, method 600 includes the step of creating a report message 610 which contains at least error data.
[0068] In block 612, method 600 includes the step of sending a report message 610 to a network monitoring algorithm 132 operable in processor circuit 158. The network monitoring algorithm 132 is configured to determine the data integrity of a particular link 110 based on error data 128. The step of sending the report message 610 includes the step of sending the report message 610 by the error data reporting function 126 of network switch 106, or the step of sending the report message 610 by the error data reporting function 146 of network node 108.
[0069] In some examples, the report message 610 is sent to the network monitoring node 134, which includes the network monitoring algorithm 132. In other examples, the report message 610 is sent to the network data integrity management unit 112, which includes the undetectable corruption prediction algorithm 116. As described above, the undetectable corruption prediction algorithm 116 is configured to predict the amount of undetectable corrupted data that may have been transmitted using a particular link 110, and the number of undetected messages containing error data 128, based on the number of corrupted messages actually detected by reading error data 128 from the switch interface 130 or the network interface 150, and the number of actually detected messages containing error data 128.
[0070] In block 614, the function for reporting error data during that intermittent period ends. Method 600 may return to block 604 to start the error data reporting function when the next default period begins. In some examples, data integrity monitoring of network 100 or 200 can be performed as needed. In other examples, data integrity monitoring of network 100 or 200 is performed at default intervals.
[0071] In block 618, method 600 includes the step of receiving a report message 610 by a network monitoring node 134 for each of multiple links 110 of network 100 or 200 where error data 128 exists on link 110. The network monitoring node 134 includes a network monitoring algorithm 132. As described above, the report message 610 can be received from the error data reporting function 126 of network switch 106 or from the error data reporting function 146 of network node 108. In some examples, method 600 includes the step of receiving the report message 610 by a network data integrity management unit 112 (Figures 1 and 2).
[0072] In block 620, method 600 includes the step of storing a report message 610 for each link 110 in which error data 128 exists.
[0073] In block 622, method 600 includes the step of performing a network monitoring algorithm 132.
[0074] In block 624, method 600 includes the step of performing a data integrity analysis on each link 110 of network 100 or 200 that caused the report message 610 to be received. In the example in Figure 6B, the step of performing a data integrity analysis includes blocks 626-634. In block 626, method 600 includes the step of reading error data 128 from the report message 610 for the specific link 110 that caused the report message 610 to be received.
[0075] In block 628, method 600 includes the step of determining the data integrity of a particular link 110 by determining whether the error data 128 exceeds an error data threshold for that particular link 110, for example, an error data threshold 504 in the configuration table 168 of Figure 5. The data integrity of the particular link 110 becomes invalid if the error data 128 exceeds the error data threshold 504 for that particular link 110.
[0076] If, in block 630, error data 128 exceeds the error data threshold 504, method 600 proceeds to block 632. In block 632, method 600 determines that a particular link 110 is failing and includes the step of performing a default action in accordance with the failure of the particular link 110. As described above, examples of default actions include, but are not limited to, blocking the particular link 110, transmitting messages or data using another link 110 in the network until the particular link 110 is repaired or replaced, and / or generating and sending a message indicating that the particular link 110 is failing. The message is sent to a contact person responsible for repairing or replacing the failed link.
[0077] In block 634, method 600 includes the step of determining whether a particular link 110 is the last link, i.e., whether there are other links that caused the report message 610 to be received. If the particular link 110 is not the last link, method 600 returns to block 626 and proceeds as described above. If the particular link 110 is the last link, method 600 proceeds to block 636. In block 636, the intermittent period function of monitoring the data integrity of network 100 or 200 ends. Monitoring the data integrity of network 100 or 200 can be performed as needed or at intermittent intervals.
[0078] Referring to Figures 7A and 7B, Figures 7A and 7B are flowcharts of an example of a method 700 for monitoring the data integrity of a network 100 or 200, relating to another example of the present disclosure. In some examples, the first part 702 of method 700 (Figure 7A) is implemented and executed by the network switch 106 and network node 108 in Figures 1A-1B and 2. The second part 722 of method 700 (Figure 7B) is implemented and executed by the network data integrity management unit 112 and / or network monitoring node 134 of the integrated processing module 114 (network node 108a) in Figure 1B. For example, the error data reporting function 126 of network switch 106 and the error data reporting function 146 of network node 108 include the first part 702 of method 700. The undetectable corruption prediction algorithm 116 and the network monitoring algorithm 132 include the second part 722 of method 700.
[0079] In block 704, method 700 includes the step of receiving a message using link 110 of network 100 or 200. The message is received by either network switch 106 or network node 108.
[0080] In block 706, method 700 includes the step of determining whether a message contains error data 128. For example, method 700 includes the step of using an embedded error detection method to determine whether a message contains error data 128. An error detection code is embedded in the message used to determine whether a message contains error data 128. Examples of embedded error detection codes include cyclic redundancy checks, frame check sequences, or other embedded error detection codes.
[0081] If the message in block 708 does not contain error data 128, method 700 returns to block 704 and repeats as described above. If the message contains error data 128, method 700 proceeds to block 710.
[0082] In block 710, method 700 includes the step of incrementing the count of an error data counter 141 (Figures 1B and 2) associated with link 110 in response to the message containing error data 128. The error data counter 141 is located in the memory 136 of the network switch or the memory 152 of the network node 108. For example, based on an embedded error detection method, the count of the error data counter 141 associated with a particular link 110 is incremented by 1 in the memory of the network switch 106 or the network node 108 in response to the presence of error data 128 in the message.
[0083] In block 712, it is determined whether a predetermined period has elapsed. If the predetermined time has not elapsed, method 700 returns to block 704, allowing one or more further messages to be received via link 110, received by network switch 106 or network node 108, and incrementing the error data counter 141 for each of these further messages, which contain error data 128.
[0084] If the default period has elapsed in block 712, method 700 proceeds to block 714. In block 714, method 700 includes the step of creating a report message 716 in response to one or more messages being received by network switch 106 or network node 108 and containing error data 128, i.e., the count of the error data counter 141 exceeding zero. The report message 716 contains the count of the error data counter 141. The report message 716 is created after the default period has elapsed. The report message 716 contains the count of the error data counter 141 of network switch 106 or network node 108.
[0085] In block 718, method 700 includes the step of sending a report message 716 to the network data integrity management unit 112 to determine whether or not link 110 is faulty. In another example, the report message 716 is sent to the network monitoring node 134. In some examples, method 700 includes the step of sending the report message 716 by the error data reporting function 126 of the network switch 106, or by the error data reporting function 146 of the network node 108, depending on which of the two received one or more messages containing error data 128. The network data integrity management unit 112 is configured to use the count of the error data counter 141 associated with a particular link 110 to determine the likelihood that an undetected corruption message is sent by that particular link 110.
[0086] In block 720, method 700 includes the step of resetting the error data counter 141 associated with link 110 to zero in response to sending a report message 716 to the network data integrity management unit 112 or the network monitoring node 134. In response to sending the report message 716 and / or resetting the error data counter 141, method 700 returns to block 704 to receive further messages using link 110 by the associated network switch 106 or the associated network node 108.
[0087] In block 724, method 700 includes the step of receiving a report message 716 from network switch 106 or network node 108 by network data integrity management unit 112 or network monitoring node 134. As described above, the report message 716 includes the count of the error data counter 141 of network switch 106 or network node 108.
[0088] In block 726, method 700 includes the step of adding the count of error data counter 141 to the count of corrupted data counter 122, or the step of using a count in the network monitoring algorithm 132 of network monitoring node 134 to determine the data integrity of a particular link 110.
[0089] In block 728, method 700 includes the step of comparing the count of the corrupted data counter 122 with the error data threshold 504 for link 110. In block 730, if the count of the corrupted data counter 122 does not exceed the error data threshold 504 for link 110, method 700 proceeds to block 732. Upon entering block 732, no action is taken. If the count of the corrupted data counter 122 exceeds the error data threshold 504 for the link, method 700 proceeds to block 734.
[0090] In block 734, method 700 includes the step of determining the likelihood of an undetected corruption message being sent by link 110 using the count of the corrupted data counter 122. As described above, the undetected corruption prediction algorithm 116 is configured to determine the likelihood of an undetected corruption message being sent by link 110 using the count of the corrupted data counter 122.
[0091] In block 736, method 700 includes the step of determining that link 110 is faulty in response that the count of the corrupted data counter 122 exceeds the error data threshold 504 for link 110. Method 700 also includes the step of sending a message that the likelihood of undetected corruption on link 110 has exceeded the design value in response to the count of the corrupted data counter 122 exceeding the error data threshold 504 for link 110. For example, the message is sent to a contact person responsible for performing a default action.
[0092] In block 738, method 700 includes the step of performing a default action for the failed link 110. As above, examples of default actions include blocking the failed link 110, sending a message over another link, or other default actions.
[0093] In some cases, computer-readable program instructions are implemented in computer program products similar to or identical to those described in this application. The computer-readable program instructions are downloaded by a processor circuit and stored in memory associated with the processor circuit.
[0094] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions that contains one or more executable instructions for performing one or more logical functions shown. In some other implementations, the functions described in a block may be executed in a different order than shown in the figure. For example, two blocks shown consecutively may actually be executed almost simultaneously, or they may be executed in reverse order depending on the functions in which the blocks are involved. It should also be noted that each block in the block diagram and / or flowchart diagram, and combinations of blocks in the block diagram and / or flowchart diagram, can be implemented by a dedicated hardware-based system that performs the functions and operations shown or implements combinations of dedicated hardware and computer instructions.
[0095] The terms used herein are for the purpose of describing specific embodiments and are not intended to limit the embodiments of the present disclosure. Where used herein, the singular forms “a,” “an,” and “the” are intended to include the plural form unless otherwise specified in the context. Where used herein, the terms “include,” “includes,” “comprises,” and / or “comprising” indicate the existence of described forms, integers, steps, operations, elements, and / or components, while not excluding the existence or addition of one or more other forms, integers, steps, operations, elements, components, and / or groups thereof.
[0096] The corresponding structures, materials, actions, and equivalents of all means-plus-function or step-plus-function elements of the claims described below are intended to include any structures, materials, or actions for performing a function in combination with other claimed elements that are more specifically claimed. While the description of this embodiment has been provided for illustrative and explanatory purposes, it is not intended to be exhaustive or to be limited to embodiments that take the form disclosed. Many modifications and variations will be apparent to those skilled in the art, without departing from the scope and spirit of the embodiment.
[0097] While this application illustrates and describes specific embodiments, any configuration intended to achieve the same objective may be used instead of the specific embodiments shown, and those skilled in the art will understand that embodiments may have other uses in other environments. This application is intended to cover all adaptations and modifications. The following claims are not intended to limit the scope of embodiments of the disclosure to the specific embodiments described herein. [Explanation of Symbols]
[0098] 100 Networks 104 Vehicles 106 Network Switches 108 network nodes 110 links 112 Network Data Integrity Management Department 114 Integrated Processing Module 116 Undetectable Damage Prediction Algorithm 118 Processor Circuits 119 memory 120 Computer-Readable Program Instructions 121 Function set 122 corrupted data counter 124 Processor Circuits 125 Switch function 126 Error Data Reporting Function 128 Error Data 130 Switch Interfaces 132 Network Monitoring Algorithms 134 Network Monitoring Nodes 136 memory 138 Computer-Readable Program Instructions 140 feature set 141 Error Data Counter 142 Processor Circuits 144 Vehicle Functions 146 Error Data Reporting Function 150 Network Interfaces 152 memory 154 Computer-Readable Program Instructions 156 feature set 158 Processor Circuits 160 memory 162 Vehicle Functions 164 Computer-Readable Program Instructions 166 feature set 168 Configuration Table 200 Networks 202 System 206 ARINC Remote Switch 208 Airplane Functions 212 Processor Circuit 214 memory 216 Computer-Readable Program Instructions 218 Function set 220 Incident Reporting Function 222 End System 230 Switch Interfaces 300 ways 400 messages 402 Data 404 Error Detection Code 502 Identification Information 504 Error Data Threshold 506 Column 1 508 Error Data Threshold 508 Second column 600 How to Monitor Network Data Integrity 602 Part 1 610 Report Message 616 Part 2 700 How to monitor network data integrity 702 Part 1 716 Report Message 722 Part 2
Claims
1. A method (600, 700) for monitoring the data integrity of a network (100, 200), The steps include: reading the error data (128) from an interface (130, 150, 230) associated with the specific link (110) of the network (100, 200) in response to the presence of the error data (128) in a message (400) received on a specific link (110); Step (710) of increasing the count of the error data counter (141) associated with the specific link (110) in response to the presence of the error data (128), The steps (608, 714) include creating a report message (610, 716) containing the aforementioned error data (128), Steps (612, 718) include sending the report messages (610, 716) to a network monitoring algorithm (132) operable in a processor circuit (158), wherein the network monitoring algorithm (132) determines the data integrity of the particular link (110) based on the error data (128), and the determination of data integrity is configured to determine, using the count of the error data counter (141), the likelihood that an undetected corruption message will be transmitted by the particular link (110), and A method comprising (600, 700).
2. Step (628) of determining the data integrity of the specific link (110) by determining (628) whether the error data (128) exceeds an error data threshold for the specific link (110), wherein the data integrity of the specific link (110) becomes unacceptable as the error data (128) exceeds the error data (128) threshold, Step (632) of performing a predetermined action in response to a failure in the aforementioned specific link (110) and The method according to claim 1 (600, 700), further comprising the above.
3. The aforementioned default correspondence is, The step of blocking the specific link (110), Alternatively, the step of transmitting data using another link (110) of the network (100, 200) until the specific link (110) is repaired. The method according to claim 2 (600, 700), comprising at least one of the above.
4. The method according to any one of claims 1 to 3 (600, 700), wherein the step of reading the error data (128) comprises the step (606) of reading the error data (128) from the network interface (150) of the network node (108) by an error data reporting function (146) that can be operated on the processor circuit (142) of the network node (108), and the step (612) of sending the reporting messages (610, 716) comprises the step of sending the reporting messages (610, 716) (400) by the error data reporting function (146) of the network node (108).
5. The method according to any one of claims 1 to 4 (600, 700), wherein the step (606) of reading the error data (128) comprises the step (606) of reading the error data (128) from the switch interface (130) of the network switch (106) by an error data reporting function (126) that can be operated by the processor circuit (124) of the network switch (106), and the step (612) of sending the report message (610) comprises the step (612) of sending the report message (610) by the error data reporting function (126) of the network switch (106).
6. Step (618) of receiving a specific report message (610) by a network monitoring node (134) for each of the multiple links (110) of the network (100, 200) where error data (128) exists on the link (110), wherein the network monitoring node (134) includes the network monitoring algorithm (132), The steps include reading the error data (128) from the specific report message (610) for each link (110) (626), Step (628) of determining the data integrity of each link (110) by determining (628) whether the error data (128) exceeds the error data threshold for each link (110), wherein the data integrity of the link (110) becomes unacceptable as the error data (128) exceeds the error data threshold, Step (632) of performing a predetermined action in response to a failure in the aforementioned link (110) and The method according to any one of claims 1 to 5, further comprising (600, 700).
7. Step (704) of receiving the message (400) using the specific link (110), wherein the message (400) is received by either a network switch (106) or a network node (108), The method further includes a step (706) of determining whether the message (400) contains the error data (128) using an embedded error detection method, The method according to any one of claims 1 to 6 (600, 700), wherein the step (710) of increasing the count of an error data counter (141) associated with the particular link (110) by 1 in response to the presence of the error data (128) is, based on the embedded error detection method, the count of the error data counter (141) associated with the particular link (110) is increased by 1 in the memory (136, 152) of the network switch (106) or the network node (108) in response to the presence of the error data (128), and the report message (716) is created after a predetermined period has elapsed, and the report message (716) comprises the count of the error data counter (141).
8. The method according to claim 7 (600, 700), wherein the reporting message (716) is transmitted to a network data integrity management unit (112) by an error data reporting function (126, 146) of the network switch (106) or the network node (108) that received the message (400), and the network data integrity management unit (112) is configured to use the count of the error data counter (141) to determine the possibility that an undetected corruption message is transmitted by the particular link (110).
9. A method (700) for monitoring the data integrity of a network (100, 200), The steps include: receiving a message (400) by a network switch (106) or network node (108) using a link (110) of the aforementioned network (100, 200) (704); The steps include determining whether the message (400) includes error data (128) (706), The steps include increasing the count of an error data counter (141) associated with the link (110) in accordance with the message (400) comprising error data (128), The steps include: creating a report message (716) in accordance with the fact that the message (400) includes error data (128); Step (718) of sending the report message (716) to the network data integrity management unit (112) to determine whether or not there is a failure in the link (110), wherein the network data integrity management unit (112) determines the data integrity of the link (110) based on the error data (128), and the determination of data integrity determines, using the count of the error data counter (141), the possibility that an undetected corruption message is transmitted by the link (110), and A method comprising (700).
10. The method according to claim 9 (700), further comprising the step (706) of using an embedded error detection method to determine whether the message (400) includes error data (128).
11. Step (712) to allow one or more additional messages (400) to be received using the link (110) if the predetermined period has not elapsed, Step (710) increment the count of the error data counter (141) for each of the further messages (400) having error data (128) The method according to claim 10 (700), further comprising the above.
12. The method according to claim 11 (700), wherein the reporting message (716) comprises the count of the error data counter (141).
13. The steps include adding the count of the error data counter (141) to the count of the corrupted data counter (122) (726), The steps include: comparing the count of the corrupted data counter (122) with the error data threshold (508) for the link (110) (728); Step (736) of determining that there is a failure in the link (110) when the count of the corrupted data counter (122) exceeds the error data threshold (508) for the link (110) The method according to claim 12 (700), further comprising the above.
14. The steps include: using the count of the corrupted data counter (122), determining the possibility that an undetected corrupted message will be transmitted by the link (110); Step (736) of sending a message that the possibility of undetected damage in the link (110) has exceeded the design value, in response to the count of the damage data counter (122) exceeding the error data threshold (508) for the link (110); The method according to claim 13 (700), further comprising the above.
15. A network (100, 200) equipped with data integrity monitoring capabilities, A plurality of network switches (106) that can be configured to selectively interconnect two or more network nodes (108) out of a plurality of network nodes (108), wherein each network switch (106) Network switch processor circuit (124), The network switch processor circuit (124) is capable of operating and includes a switch function (125) that selectively connects to another network switch (106) or to one of the network nodes (108) among the plurality of network nodes (108), The network switch processor circuit (124) is operable, Error data (128) is read (606) from a switch interface (130) associated with a specific link (110) of the aforementioned network (100, 200), In accordance with the error data (128), the count of the error data counter (141) associated with the specific link (110) is increased. A network switch report message (610) containing the aforementioned error data (128) is created (608), The network switch report message (610) is sent to the network monitoring algorithm (132) (612), which is configured to determine the data integrity of the specific link (110), and the determination of data integrity uses the count of the error data counter (141) to determine the likelihood that an undetected corruption message will be sent by the specific link (110). The network switch error data reporting function (126) is configured as follows: Multiple network switches (106) are provided. A network equipped with (100, 200).
16. At least some of the aforementioned plurality of network nodes (108) Network node processor circuit (142), The network node processor circuit (142) is capable of operating and includes a vehicle function (144) that performs specific functions related to the vehicle (104), The network node processor circuit (142) is operable, Error data (128) is read (606) from a network interface (150) associated with another specific link (110) of the aforementioned network (100, 200), A network node report message (610) containing the aforementioned error data (128) is created (608), The network monitoring algorithm (132) is configured to send the network node report message (610) to the network monitoring algorithm (132) (612) and to determine the data integrity of another specific link (110) (628). The network node error data reporting function (146) is configured as follows: The network (100, 200) according to claim 15, comprising the above.
17. The plurality of network nodes (108) further comprises network monitoring nodes (134), and the network monitoring nodes (134) are Processor circuit (158), The network monitoring algorithm (132) that can be operated on the processor circuit, The memory (160) associated with the processor circuit, A configuration table (168) stored in the memory, the configuration table (168) comprises identification information (502) for each link (110) of a plurality of links (110) of the network (100, 200), and an error data threshold (508) associated with each link (110), and the configuration table (168) is configured to be used by the network monitoring algorithm (132) to determine whether the error data (128) read from an interface (130, 150) associated with a particular link (110) of the network exceeds the error data threshold (508) for that particular link (110), and The network (100, 200) according to claim 15 or 16, comprising:
18. The aforementioned network monitoring node (134) A function (618) for receiving a specific report message (610) for each of the multiple links (110) of the aforementioned network (100, 200) where error data (128) exists in the link (110), A function (626) for reading the error data (128) from the specific reporting message (610) for each link (110), A function (628) that determines the data integrity of each link (110) by determining (628) whether the error data (128) exceeds the error data threshold (508) for each link (110), wherein the data integrity of the link (110) becomes unacceptable as the error data (128) exceeds the error data threshold (508), A function (632) that performs a predetermined action in response to a failure in the aforementioned link (110) and The network (100, 200) according to claim 17, configured to execute a set of functions comprising the above.
19. Processor circuit (118), A memory (119) related to the processor circuit, wherein the memory is executed by the processor circuit. Function (724) for receiving a reported error message (716) having a count of an error data counter (141) associated with a specific link (110), wherein the count of the error data counter increases as each message (400) is received using the specific link (110) containing error data (128), The function (726) of adding the count of the error data counter (141) to the count of the corrupted data counter (122), A function (728) for comparing the count of the corrupted data counter (122) with an error data threshold (508) for the specific link (110), A function (736) that determines that there is a failure in the specific link (110) when the count of the corrupted data counter (122) exceeds the error data threshold (508) for the specific link (110) and A memory (119) and a computer-readable program instruction (120) that causes the processor circuit to execute a set of functions (121) comprising the above. The network (100, 200) according to any one of claims 15 to 18, further comprising a network data integrity management unit (112) equipped with