Methods and apparatus for wireless communication

JP7904720B2Active Publication Date: 2026-08-13ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-02
Publication Date
2026-08-13

AI Technical Summary

Benefits of technology

【0004】 したがって、受信機の側における安全性インテグリティレベルに従った処理は、下位層においても有効化される。有利には、安全通信は、シグナリング及び物理的送信フォーマット/フレームを介して識別される。システムは、高い信頼性とともに有効化され、したがって、機能安全ニーズを伴うアプリケーションを実現するために適している。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007904720000003
    Figure 0007904720000003
  • Figure 0007904720000004
    Figure 0007904720000004
  • Figure 0007904720000005
    Figure 0007904720000005
Patent Text Reader

Abstract

To provide a method for a device (100) that operates in a wireless communication network.SOLUTION: A method includes: a step (122) of determining at least one functional safety indicator (FSF) indicating whether at least relevant data (d#1, e#3), in particular V2X data including at least one of vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technical data including building operations data, is relevant according to at least one safety integrity level (SIL); and a step (132-136) of transmitting the data (d#1) together with the determined at least one functional safety indicator (FSF).SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method and apparatus for wireless communication.

Summary of the Invention

Problems to be Solved by the Invention

[0002] This description provides an advancement in wireless communication, and in particular, provides an advancement in wireless communication between a vehicle and other V2X communication entities.

Means for Solving the Problems

[0003] Disclosure of the Invention According to a first aspect of the description, a method for an apparatus operating in a wireless communication network includes at least determining at least one functional safety indicator indicating whether at least one of related data, particularly V2X data including at least one of vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technology data including building operation data, is associated according to at least one safety integrity level, and transmitting the data together with at least one determined functional safety indicator.

[0004] Thus, processing according to the safety integrity level on the receiver side is also enabled in the lower layer. Advantageously, secure communication is identified via signaling and physical transmission formats / frames. The system is enabled with high reliability and is thus suitable for realizing applications with functional safety needs.

[0005] According to a favorable example, the method includes the step of determining a functional safety level indicator that represents at least one of several safety integrity levels, the determination of at least one functional safety indicator being based on the functional safety level indicator.

[0006] As a result, the Functional Safety Level Indicator (FSI) is mapped to the appropriate Functional Safety Indicator (FSF), e.g., priority or physical layer mapping value or media access control-control element (MAC-CE) priority mapping value, which is identified in the physical layer / layer-1 for each functional safety-related transmission. The L1 or MAC then maps this identification in its transmission signal so that the receiver recognizes FuSa handling, even before sending it to the safety communication layer SCL. The transmission signal is considered to be the FuSa lower layer signaling carrier.

[0007] According to a favorable example, the method includes the step of mapping a QoS flow belonging to data to a data radio bearer based on at least one functional safety level indicator, and the transmission of data is performed via the mapped data radio bearer.

[0008] According to a favorable example, the method includes the step of determining at least one communication request based on at least one functional safety level indicator, and the mapping of the QoS flow to data radio bearers includes the step of selecting a data radio bearer from a set of available data radio bearers based on a comparison of the determined at least one communication request with at least one communication parameter associated with each of the available data radio bearers.

[0009] Advantageously, the mapping results in the selection of a data radio bearer that satisfies the communication requirements with the relevant communication parameters. According to a favorable example, the method includes the step of mapping the safety integrity level associated with the data to a functional safety level indicator.

[0010] This mapping between SIL and FSI provides that vendor-specific functional safety levels are mapped to general functional safety levels. In other words, the transmitter translates events, hazards, risks, etc., into appropriate functional safety procedures to initiate data transmission, and into functional safety level indicators such as setting indices.

[0011] According to favorable examples, data is carried along with relevant headers, particularly an SDAP header, that include functional safety level indicators, either as part of a QFI that identifies the QoS flow associated with the data, or in addition to a QFI.

[0012] Advantageously, the Safety Level Indicator (FSI) is also available on the receiver side. In a favorable example, the transmission of multiple functional safety indicators is performed via at least one physical control channel, in particular, via at least one of the physical uplink control channel PUCCH, the physical downlink control channel PDCCH, and the physical sidelink control channel PSCCH, or the transmission of multiple functional safety indicators is performed via their respective media access control-control elements (MAC-CE).

[0013] Advantageously, the physical control channel or MAC-CE allows for early assessment of the relevance of received data for SIL. According to the second aspect of the description, the device for operating in a wireless communication network includes at least determination means for determining at least one functional safety indicator indicating whether relevant data, in particular V2X data including at least one of vehicle operating parameters and road events, or industrial data including machine operating parameters, or building technical data including building operation data, is relevant according to at least one safety integrity level, and transmission means for transmitting the data together with the at least one determined functional safety indicator.

[0014] According to a third aspect of the description, a method for a device operating in a wireless communication network includes receiving data, in particular V2X data including at least one of vehicle operating parameters and road events, or industrial data including machine operating parameters, or building technical data including building operation data, together with at least one functional safety indicator indicating whether the relevant data is related according to at least one safety integrity level.

[0015] Advantageously, processing according to the safety integrity level on the receiver side is also enabled at lower layers. According to a favorable example, the method includes the step of deciding to process the data according to at least one safety integrity level indicated by a functional safety level indicator received along with the data.

[0016] According to favorable examples, data is carried either as part of a QFI that identifies the QoS flow associated with the data, or in addition to the QFI, along with associated headers, particularly an SDAP header, that include functional safety level indicators.

[0017] In a favorable example, reception of multiple functional safety indicators is performed via at least one physical control channel, in particular, via at least one of the physical uplink control channel PUCCH, the physical downlink control channel PDCCH, and the physical sidelink control channel PSCCH, or reception of multiple functional safety indicators is performed via their respective media access control-control elements (MAC-CE).

[0018] Advantageously, the physical control channel or MAC-CE allows for early assessment of the relevance of received data for functional safety. According to the fourth aspect described, a device for operating in a wireless communication network includes at least receiving means for receiving, together with at least one functional safety indicator indicating whether related data is related according to at least one safety integrity level, V2X data including at least one of data, in particular, vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technology data including building operation data.

Brief Description of the Drawings

[0019] [Figure 1] It is a schematic sequence diagram. [Figure 2] It is a diagram showing wireless communication between two vehicles. [Figure 3] It is a diagram showing a schematic protocol stack. [Figure 4] It is a schematic block diagram of a transmitting device. [Figure 5] It is a diagram of a schematic layer. [Figure 6] It is a schematic time - resource diagram. [Figure 7] It is a schematic flowchart. [Figure 8] It is a schematic flowchart. [Figure 9] It is a time - frequency diagram. [Figure 10] It is a diagram showing a heart - beat SPS transmission structure.

Modes for Carrying Out the Invention

[0020] Figure 1 shows a schematic sequence diagram of two entities V1 and V2, for example, automobiles, communicating with each other. Entities V1 and V2 include devices 100 and 200, which include the Safety Communication Layer (abbreviated as SCL) SCL_100 and SCL_200 and the lower layers LOW_100 and LOW_200. The lower layers L_100 and L_200 are responsible for lower layer processing, which includes at least one of layers 1 and 2 according to the OSI / ISO model. The application layers APP_100 and APP_200 are responsible for handling data according to the Safety Integrity Level (SIL), in particular the Automotive Safety Integrity Level (ASIL), and of course, the Quality Control Level. In the following example, data d#1 and e#3 are sent from device 100 to device 200.

[0021] The following terms apply throughout this document. Safety Integrity Level (SIL): A level of functional safety integrity derived from one type of detected risk, hazard, or failure, particularly in the application layer or functional safety layer.

[0022] Functional Safety Level Indicator, FSI: The FSI is derived from SIL to provide a generalized form of the functional safety level related to the transmission of functional safety-related data. Functional Safety Indicator (FSF): The FSF is carried, for example, in a physical control channel or MAC-CE; for example, the FSF is derived from the FSI. The functional safety indicator FSF has a smaller range of available values ​​than the higher-level functional safety level indicator FSI.

[0023] Safety-related: For example, safety-related V2X data is potentially safety-related for the receiver. For example, V2X data notifying the initiation of emergency braking is related to the driving safety of the receiving vehicle. Therefore, "safety-related" can be understood as "related for the driving safety of the receiving device or vehicle."

[0024] Data: The examples in this description refer to V2X data. However, the description is also applicable to other application data besides V2X data. When we say "data," this term encompasses "application data."

[0025] Heartbeat signal: This is a repeated transmission of the FSF along with the functional safety container. The mapping means 102 maps data d#1 to at least one safety integrity level (SIL) based on detected events, hazards, or risks associated with data d#1.

[0026] The mapping means 112 maps data d#1 to a functional safety level indicator FSI based on at least one safety integrity level SIL associated with data d#1. Data d#1 is carried with associated headers, particularly SDAP, Service Data Adaptive Protocol headers, which include the functional safety level indicator FSI as part of a QFI or as an addendum to a QFI that identifies the QoS flow F associated with data d#1. The FSI is encapsulated in an L2 protocol data unit PDU frame, which is then encapsulated in an L1 frame.

[0027] According to another example of the mapping means 112, the FSI may be derived from setting up three negotiation layers. For example, the FSI has a 1-bit value, which is 1 if the ASIL level is C or D, and zero if the ASIL level is A or B. For example, if the FSI is not present, the communication does not require functional safety.

[0028] In yet another example, the FSI is a 2-bit value, where 00 is for A, 01 for B, 10 for C, and 11 for D. For example, if the FSI is not present, the communication does not require functional safety. Another bit can be added to the FSI, so that all zeros are sent to the lower layer / interface sublayer, which indicates a non-functionally safe transmission, in which case the FSI field is always set and included at the SDAP layer.

[0029] In another example, three different levels may be identified by the FSI as follows: - A multi-(A)SIL value, which may be identified as A-D or 1-4, a single (A)SIL level; - Quality Management (QM) levels, which are non-(A)SIL levels, related to several identified V2X / industrial services. This level itself can distinguish multiple sub-levels if necessary; - How prioritization is done depends on lower levels: non-safe, non-(A)SIL, non-QM levels.

[0030] The mapping means 114 maps data d#1 to a functional safety indicator FSF based on at least one functional safety integrity level indicator FSI associated with data d#1. The mapping means 114 determines at least one communication request cr based on at least one functional safety level indicator FSI, at least one FSF, or SIL.

[0031] For example, the above mapping / transformation results in a pre-configured functional safety indicator (FSI). For instance, the FSI can be retrieved via a lookup table selectively combined with parameters related to events, FuSa levels, hazards, risks, etc. These parameters include event periodicity, maximum irregularity, maximum survival time, NACK rate, and continuous NACK rate.

[0032] The mapping means 116 maps the QoS flow F belonging to data d#1 to the data radio bearer DRB#1 based on at least one functional safety level indicator FSI, and the transmission of data d#1 via the transmission means 132-136 is performed via the mapped data radio bearer DRB#1. The mapping of the QoS flow F to the data radio bearer DRB#1 includes selecting the data radio bearer DRB#1 from a set of available data radio bearers based on a comparison of a determined at least one communication request cr with at least one communication parameter associated with each of the available data radio bearers. The FSI is used to map the FuSa data flow associated with the FSI to the appropriate transmitting data radio bearer, and the bearer satisfies the required communication parameter associated with the FSI.

[0033] The determination or processing means 122, 124 are provided to determine at least one communication request cr, in particular the periodicity of transmission of the functional safety indicator FSF, the minimum time period between subsequent transmissions of the functional safety indicator FSF, or the maximum time period between subsequent transmissions of the functional safety indicator FSF, based on at least one safety integrity level SIL, or at least one functional safety level indicator FSI, or at least one functional safety indicator FSF. The transmission means 132-136 initiate the transmission of a plurality of functional safety containers FSCs and a plurality of associated functional safety indicator FSFs in accordance with the determined at least one communication request cr. For example, the at least one communication request cr is signaled or pre-configured via an received RRC, radio resource configuration, message.

[0034] According to one example, the determination or processing means 122 determines at least one functional safety indicator FSF indicating whether the relevant data d#1, e#3, in particular the V2X data, is relevant according to at least one safety integrity level SIL. Thus, the data d#1, e#3 can be relevant or unrelated to safety integrity. The transmission means 132-136 then transmit the data d#1, e#3 along with the at least one determined functional safety indicator FSF.

[0035] The transmission of data and at least one functional safety indicator FSF "together" includes a) both data and FSF being transmitted over the same resource block, b) both data and FSF being transmitted over adjacent radio resources, and c) both data and FSF being transmitted over radio resources separated by frequency and time.

[0036] According to one example, the determination or processing means 122 determines at least one functional safety indicator FSF indicating whether at least relevant data d#1, e#3, in particular V2X data including at least one of vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technical data including building operation data, are relevant according to at least one safety integrity level SIL. Other examples for data include industrial data including machine operation parameters and building technical data including building operation data. Thus, data d#1, e#3 may or may not be relevant to safety integrity. The transmission means 132-136 transmit data d#1 along with at least one determined functional safety indicator FSF.

[0037] According to one example, at least one functional safety indicator (FSF) includes at least two values, for example, in the form of bits. According to the first value, FSF indicates that SIL relevance exists according to at least one Safety Integrity Level (SIL). According to the second value, FSF indicates that safety relevance does not exist according to at least one Safety Integrity Level (SIL). Therefore, the second value may indicate that a "quality control" level, which indicates a risk associated with a hazardous event, does not require safety measurement according to the Safety Integrity Level (SIL).

[0038] In one example, the determination or processing means 112 determines a functional safety level indicator FSI for V2X data d#1 that represents at least one of a plurality of safety integrity levels SIL. The determination of at least one functional safety indicator FSF according to the determination or processing means 122 is based on the functional safety level indicator FSI.

[0039] At least one communication request cr is signaled and / or pre-configured to devices 100, 200 via received RRC, radio resource configuration, and messages. Another indicator x#1, x#3, for example, is sent along with data d#1, e#3 which indicates the SIL relationship of data d#1, e#3 itself.

[0040] According to one example, the transmission and reception of multiple functional safety indicators (FSFs) are performed via at least one physical control channel, in particular, via at least one of the physical uplink control channel PUCCH, the physical downlink control channel PDCCH, and the physical sidelink control channel PSCCH.

[0041] In another example, the transmission and reception of multiple functional safety indicators (FSFs) are performed via their respective media access control-control elements (MAC-CEs). After receiving multiple functional safety containers FSCs at different times along with at least one associated functional safety indicator FSF via receiving means 232-234, the determination or processing means 244 determines, based on multiple reception times associated with at least one functional safety indicator FSF, whether the received transmission is part of a functional safety iterative heartbeat (including the FSF) and whether the received data quality d#1, e#2 should be processed via processing means 252 according to at least one safety integrity level SIL. Processing means 525 then operates to comply with safety requirements derived from the corresponding SIL.

[0042] For example, a marker m is determined, which indicates whether the V2X data d#1 and e#3 carried in each functional safety container FSC are eligible to be processed in the processing means 252 of the application layer APP_200 according to at least one safety integrity level SIL. If V2X data d#1 is SIL-related and V2X data e#3 is not, then both are eligible for SIL processing in the first example. However, further indicators not shown determine whether the V2X data d#1 and e#3 are SIL-related. Based on this further marker, the marker m is determined.

[0043] Further indicators x#1, x#3, for example bits, are transmitted along with data d#1, e#3 indicating the SIL relevance of the data, and data e#3 marked by the further indicator x#3 as not SIL relevant is excluded from the decision of the decision means 244.

[0044] The determination means 242 determines the communication request cr based on at least one of the functional safety indicators FSF. Advantageously, the mapping between the functional safety indicators and the communication request enables the monitoring parameter without further communication or configuration overhead.

[0045] The decision via the decision means 244 is made based on whether at least one monitored communication parameter related to the reception time matches a communication request cr related to at least one monitored communication parameter.

[0046] An example of a communication request cr includes at least one of the following: the periodicity of transmission of functional safety indicators (FSFs), the minimum time interval between subsequent transmissions of functional safety indicators (FSFs), and the maximum time interval between subsequent transmissions of functional safety indicators (FSFs).

[0047] Furthermore, the detection of a functional safety indicator triggers a higher L2 sublayer of the device to identify the encapsulated FSI, which is then sent to a higher layer of the receiver to evaluate possible events, functional safety levels, risks, hazards, etc.

[0048] On the receiver side, the mapping means 246 maps the lower-layer functional safety indicator FSF to the higher-layer functional safety indicator FSI associated with data d#1. The conversion between FSI and FSF by mapping means 122 and 246 is performed to reduce the granularity and range of possible FSIs that can be signaled on the L1 (physical) control channel and / or the L2 (e.g., MAC) control channel (e.g., MAC control element). A lower-level trigger for activating FuSa monitoring is sufficient. Based on the limited FSF level / value range, a specific malfunction procedure is performed. Furthermore, the FSF is used to identify heartbeat transmissions that receive L1 and L2 measurement report generation.

[0049] In one example, the function for determining the conversion between FSI and FSF, and vice versa, can be characterized by the following pseudocode ("Pseudocode 1"). ***Pseudocode 1-START*** <Function 1> #In the main function, if a specific FSF is found and extracted from the L1 and / or L2 controls, the measurement is performed. #channel is detected If FSF=true measurements=excute_measurements(Input_signal,FSF)#ie,according to FSF detected level end fault=L1_L2_Procedure_Monitor(parameters,...) <Function 2> #Possible L1_L2_Procedure_Monitor pseudocode return fault=L1_L2_Procedure_Monitor(parameters,...) if parameters.Periodicity~=measurements.Periodicity if measurements.irregularity>parameters.irregularityThreshold fault=“non-periodic-not-accepted-irregularity” else fault=“periodic-not-accepted-irregularity” end if else fault = “no_fault” end if if measurements.NACK_Counts>parameters.NACK_Counts fault=“too_many_errors_not_stable_channel” else fault = “no_fault” end if if measurements.survivalTime>parameters.survivalTimeMax fault=“channel_packet_loss_blockage” else fault = “no_fault” end if ***Pseudocode 1-END***

[0050] In one example, after receiving data d#1 via receiving means 232-236, along with at least one functional safety indicator FSF indicating whether the associated data d#1, e#3 is associated according to at least one safety integrity level SIL, the decision or processing means decision 244 determines whether to process data d#1 via processing means 252 according to at least one safety integrity level SIL indicated by the functional safety level indicator FSI received with data d#1. Furthermore, the QoS flow is identified by QFI carried along with the functional safety level indicator FSI.

[0051] Data d#1 is carried along with the associated headers, in particular an SDAP header containing the Functional Safety Level Indicator (FSI), either as part of the QFI identifying the QoS flow F associated with data d#1, or added to the QFI.

[0052] The SDAP header (in 5G protocol encapsulation) includes, for example, SFI in addition to QFI (QoS flow indication). A transmission initiated by the transmitting means 136 is not properly received by the receiving means 236 of the device 200. In other words, a communication error occurs. This communication error is determined via the determination means 248. The determination means 248 determines a reaction indicator ri, which indicates the execution of the failsafe function 254, if at least one monitored communication parameter does not match the communication request cr.

[0053] If at least one monitored communication parameter does not match the determined communication request cr, the transmitting means 262 transmits a communication failure message CFM indicating a communication failure.

[0054] In one example, a receiver detects that the lifespan associated with the transmission of multiple safety containers has been exceeded and sends this information as part of a failure message. In another example, if the receivers of multiple functional safety containers are unable to decode the functional safety data or detect and decode the functional safety indicator FSF, the receivers send a negative response (NACK) as part of the fault message.

[0055] In one example, channel status information is updated when determining reaction indicators, and channel status information represents communication failure messages. Measurements performed at the receiver, which depend on the decoded FSI value and associated parameters, are sent back to the transmitter entity in the form of a communication failure message. The transmitter is enabled to evaluate the following: 1. Channel monitoring values, e.g., an extended channel status information SCI report showing FuSa malfunction evaluations from a table; 2. Faults, e.g., using an extended NACK report to evaluate the NACK rate, continuous NACK rate, continuous NACK count / threshold, etc.; 3. QoS reports containing values, e.g., detected high QoS, intermediate QoS, low QoS, etc.; 4. Lifetime, e.g., lifetime exceeding a certain threshold, continuously increasing lifetime, etc.

[0056] For example, decoding a functional safety indicator would show communication requests related to pre-configured FuSa transmission parameters / functional safety monitoring, such as transmission periodicity, maximum granularity, lifespan, expected HARQ rate, expected continuous NACK, etc.

[0057] The receiving means 162 receives at least one communication failure message CFM indicating a failure related to the transmission of at least one of a plurality of functional safety containers FSCs and / or the transmission of at least one of a plurality of functional safety indicators FSFs.

[0058] The modification or processing means 172 is provided to modify at least one communication request cr for the transmission of a functional safety container FSC and / or a functional safety indicator FSF based on at least one communication failure message CFM. By modifying the communication parameters, the transmission start is modified, so that the functional safety communication state on the receiver side can be maintained or re-established.

[0059] When the providing or processing means 174 receives at least one communication failure message CFM, it provides a reaction indicator ri to, for example, a higher-layer function, which indicates the execution of a failsafe function 182 in, for example, the application layer APP_100.

[0060] Alternatively, or in addition to that, upon receiving the reaction indicator ri, defense functions 192 and 292 are activated. Defense functions 192 and 292 respond depending on information received from lower-layer functions LOW_100 and LOW_200, which are carried along with the reaction indicator ri, for example.

[0061] A functional safety system, including devices 100 and 200, is provided so that detection is performed when the received packet / data corresponds to the latest transmission by the transmitter. One option is to identify errors via regular (periodic / quasi-periodic) transmissions, e.g., semi-persistent scheduling SPS.

[0062] The SPS should be adapted to include (A) FSI and / or FSF derived from or mapped to the SIL level or quality control transmission. If the system does not identify (A) SIL or QM, the system must either identify it or leave it at a lower level.

[0063] The FuSa lower-layer signaling carriers are provided by lower-layer LOW_100 and LOW_200. The repeated transmission of functional safety containers FSC#1-3 together with the FSF provides a functional safety heartbeat. This heartbeat is transmitted over the SPS by defining irregular or semi-regular heartbeat transmissions that fit the nature of the SPS / configured grant. Irregularity ranges can be pre-configured / pre-set in the UE, i.e., irregularity may also be set based on (or mapped) ASIL / SIL values ​​in the FSI. An interface connecting the safety communication layer SCL and the lower layers is assumed to handle safety communications in the lower layers and utilize lower-layer defense mechanisms and measurements. Furthermore, the defense mechanisms are assumed to be divided between the SCL and the lower layers, and interaction messages, decisions, and measurements are assumed to pass through the aforementioned interface.

[0064] A (functional safety) partition is provided between the lower layers LOW_100 and LOW_200 and the safety communication layers SCL_100 and SCL_200, which transmit mandatory safety-related information to the lower layers LOW_100 and LOW_200. As described above, the lower layers LOW_100 and LOW_200 include verification and mapping of safety-related information transmitted from SCL to the DRB and / or physical resources. Furthermore, the lower layers LOW_100 and LOW_200 include transmitting safety-related metrics / measurement reports to SCL and safety information and requests to the lower layers (round trip) through the interface.

[0065] The defense matrix / mechanism is divided into two parts, one of which is handled within the gray communication channel via insertion and monitoring of FSF transmissions. Further defense mechanisms are performed (again) in SCL_100 and SCL_200. In this case, further defense in the SCL is supported by information transmitted and triggered via lower layers. In other words, SCL_100 and SCL_200 perform exception handling based on information transmitted from Layer 1 and / or Layer 2 L1 / L2. The SCL and lower layers are connected via an interface (passing up lower layer measurements and metrics; passing down FuSa requests). The defense mechanism is divided between two defense matrices: the proactive communication defense matrix and the reactive SCL defense matrix.

[0066] Figure 2 illustrates communication from the first vehicle V1 to the second vehicle V2, which is driving behind vehicle V1. Vehicle V1 transmits a V2V emergency braking warning message (EBW). This message is subject to functional safety integrity handling. Functional safety is also referred to as "FuSa" in this document. On the other hand, when referring to the QM ("Quality Management") level, it refers to non-FuSa data or conformance.

[0067] (A) Because there may be different understandings and interpretations of how to map SIL levels to different procedures / events for different OEMs, the higher-level functional safety indicator FSI is determined. Based on the FSI, the vehicle V1 can select a data radio bearer DRB for transmission. In this form, the functional safety indicator provides that events such as emergency braking of the vehicle V1 are standardized.

[0068] From the higher-level FSI values ​​(which have a higher granularity compared to ASIL), different OEM, OEM-1, and OEM-2 vehicles V1 and V2 can interpret or match the (A)SIL, (Automotive) Safety Integrity Level, to have the same or equivalent functional safety procedures required by TX. In this case, the functional safety indicator FSF is transmitted along with the V2X emergency braking warning message EBW, referred to herein as the “heartbeat.” The transmission of the FSF provides a “gray communication channel” from which events, parameters, risks, hazards, and errors can be described and transmitted. Such a standardized FSI can be as follows:

[0069] [Table 1]

[0070] In one example, the function for determining the functional safety indicator FSI can be characterized by the following pseudocode ("Pseudocode 2"). ***Pseudocode 2-START*** #(A)SIL<->FSI interpretation enumerate fault If(OEM-A transmitted event FSI-1 and OEM-B received FSI-1) OEM-B RX entity evaluates FSI-1 packet flow and heartbeat FSI-1 (L1_L2_Procedure_Monitor) If(monitored FSL-1 is not showing a fault) OEM-B RX entity will interpret the event to its internal design QM level or (A)SIL level(may be according to lowest to OEM interpretation) Else if(monitored FSI-1 is showing a fault)#returning from Function(L1_L2_Procedure_Monitor) OEM-B RX entity will interpret it based on what may be recommended in the table(fine) Or OEM-B RX entity will interpret it based on what is implemented by OEM engineers(fine if still follow the FuSa certificates) End if End if ***Pseudocode 2-END*** If the lower-layer gray channel is not performed or does not deliver sufficient information / measurements, an example of pseudocode 1 may be considered in the functional safety layer.

[0071] On the other hand, when gray channels are implemented, they assist or supplement the functional safety layer, along with the measurement and evaluation of failures to specific events (FSIs). The functional safety layer interprets the FSI values ​​and analyzes the relevant fault / malfunction handling in the gray channels.

[0072] Figure 3 shows a schematic protocol stack for wireless communication. The 5G protocol stack or communication carrier layer includes a block "Safety Adaptive Layer (Layer 2)" which reads the SIL and corresponding safety application and converts it to a standardized FSI. Later, it maps the FSI to existing bearers (note that bearers are constantly changing, for example, based on channel availability). The Safety Adaptive Layer identifies heartbeat parameters through the mapping of the FSI to P, Tmin, and Tmax. The 5G protocol stack or communication carrier layer includes a block "Heartbeat Signal (Layer 1)": this is the function that implements the heartbeat, appends the FSF field to it, and manages resources for transmitting the heartbeat strictly per P or in best effort between Tmin / Tmax.

[0073] The system includes a safety application layer that handles and runs safety-related information, a safety adaptation layer adapted to send safety markers as fits to lower layers or to receive safety metrics from lower layers, and an adapted black channel in the form of a gray channel that identifies safety-related markers and carries safety-related information, such as sequences.

[0074] As described above, the security communication layers SCL_100 and SCL_200 send security-related information / markers / identifiers, e.g., (A)SIL or mapped values ​​therefrom, to the lower layers. The proposal further requires that SCL use the security-related markers / indicators / defenses sent by the lower layers to handle exceptional cases (e.g., fail-safes) and / or elevate them to security mechanisms.

[0075] SCL_100 and SCL_200 provide their defense mechanisms along with lower-layer defense mechanisms, namely lower-layer error reports, such as automatic repeat requests (ARQ), time of survival, and packet error ratio (PER).

[0076] In addition, the solution proposes having an interface (FuSa interface) connecting SCL_100 and SCL_200 to the lower layer. On the other hand, the interface carries safety-related markers / FSI mappings associated with the data / packets sent to the lower layer. On the other hand, the interface sends safety-related reports / error metrics to the SCL.

[0077] The lower-level FuSa procedure includes at least one of the following: - Map the safety-related marker / (A)SIL to the functional safety identifier (FSI), which may be carried in the FSI field of the SDAP header; - Map an FSI (which may be accompanied by a QoS flow) to a radio bearer (RB) that identifies it as a security-related communications RB; - Triggers functionally secure encryption / masqueraded protection and identification, as well as reorder / insertion identification at the PDCP layer; - Trigger functional safety error detection and error reporting in RLC / L1 based on Hybrid Auto Repeat Requests (HARQ) and / or L2 Auto Repeat Requests (ARQ). When lifetime is identified in RLC, MAC, and L1, RLC may send reports for lifetime end handling / values, etc. - The MAC identifies the FSF field, for example, in the SDAP header, which is mapped from the FSI value. This value (FSF bit) is sent to L1, which is marked in each heartbeat signaling. The adapted resource allocation may be prioritized in the MAC based on the FSF mapped (for the TX packet) or decoded (from each received packet).

[0078] In addition, L1 can transmit a heartbeat signal along with FSF identification. Furthermore, L1 may identify the following for functional safety mechanisms: transmit power, sudden channel fading, transmit error / channel error, maximum lifespan end / maximum packet delay, irregularity metrics (e.g., rate and duration of irregular SPS, etc.), dropped RX packets / interference (e.g., in band interference).

[0079] The defense mechanisms at lower layers are triggered and executed based on malfunction metrics or error function values. Furthermore, the defense mechanisms in the SCL are assisted by error / malfunction information sent / triggered by lower layers (e.g., gray channels) via the safe gray channel interface and further L2 / L1 adaptations, as described above. In other words, the SCL can perform exception handling based on the information sent, i.e., measurement reports. These reports are relayed by the safe gray channel interface (FuSa interface). These reports may include, as shown above, Tmax / lifetime, PER, HARQ count, etc.

[0080] The first table shows possible examples of security-related defense mechanisms to be addressed in the lower, adapted layers, i.e., the gray channel. The table is addressed in the lower layers, allowing for measurements to generate reports for the upper layers / security communication layers.

[0081] [Table 2]

[0082] SCL is assisted by malfunction handling signals sent from lower layers. For example: - Deletion / delay may be detected from the appended SCL sequence number and / or from the Tmax / lifetime value received from the lower layer; - Corruption or inconsistency may be detected from SCL safety codes (e.g., CRC) or from received HARQ / and RLC reports; - When a physical / MAC source / destination ID mismatch report is sent to the detection / SCL, the SCL source and destination ID mismatch detection may receive an early warning.

[0083] Figure 4 shows a schematic block diagram of the transmitter 100, particularly the FSI filtering and DRB mapping. For each PDU session, the UE in the core network in the User Plane Function (UPF) and / or the Non-Access Layer (NAS) filter in the NAS filter map application packets / data (e.g., IP packets, e.g., sent to the communication layer via the secure communication layer) to different FSI values ​​and QoS flow indicators (QFI). The FSI and QFI are stamped / identified in the PDU session packet, i.e., mapped to the SDAP header (as in Figure XYZ).

[0084] When packets / data are sent across the SDAP layer, the packets are mapped to different data radio bearers (DRBs). In the first example, a bearer may be established to allocate FuSa-related packets (identified in the SDAP header along with the FSI and (if a QFI is present) the QFI). In the second example, another DRB may be established to allocate FuSa packets along with QM packets, i.e., if resources are available. In the third example, a DRB may be established to allocate non-FuSa (QM only) packets.

[0085] In V2X transmission, the FSF is derived from the FSI field inserted into the QFI (or 5QI) and the SDAP (of the PDU session). Example 1: Eight values ​​(3-bit FSF) map QFI and FSI, and thus: Level 0: FSI-1 and 2 and QoS-High, Level 1: FSI-3 & 4 and QoS-High, Levels 3-7, Remaining QoS flows (QM) and non-FuSa Example 2: The following two fields: FSF mapping old QFI / 5QI, An FSF mapped to an ASIL or SIL level (e.g., a 2-bit field) or a truncated value of an ASIL / SIL level, e.g., a 1-bit value representing A / B (1 / 2) or C / D (3 or 4).

[0086] In sending side links, (As in Example 1) FSF mapping to QoS and FSI fields, or Priority field (i.e., mapping QoS) and functional safety field (FSF) bits (i.e., mapping FSI) (as in Example 2) However, it can be considered that the data is transmitted over a physical control channel. In this case, the data can be mapped to either a first-stage sidelink control channel (SCI) (with the minimum number of bits) or a second-stage SCI. Upon decoding the first or second-stage SCI, the receiving UE interprets the transmission as a functional safety-related transmission.

[0087] For Uu SPS or Uplink configuration grants or Uu dynamic grants (uplink or downlink), the gNB may additionally configure priority fields and FSF bits for one or more parallel configuration resources. This can be done in RRC configurations for Type 1 configuration grants and / or in downlink control channels for SPS and Type 2 configuration grants.

[0088] Figure 6 shows a schematic time-resource diagram. To classify functionally safe communication transmissions in the lower layers, carriers for communication signaling are implemented in the form of heartbeat signals. Periodic transmissions such as SPS and / or setting grants (CG) can be used to send heartbeat signals. Additionally, identification for communication channels, for example in SPS / CG settings or lower-layer signaling control channels, such as FSF, can be stamped on the transmission signal.

[0089] However, as illustrated in Figure 9, due to the continuous reselection procedure sidelink SPS and / or the iterative resetting of Uu SPS / CG by gNB, SPS / CG may represent a kind of irregular heartbeat (i.e., not a very regular periodic transmission heartbeat). This means that messages are not received in a regular form. However, messages rather have a variance with mean period T0 and a standard deviation (i.e., ±ΔT) near the mean. Figure 10 shows what an irregular heartbeat looks like. For example, P0-ΔT1 should not be smaller than the least possible early message configured for (A) the SIL level and / or the derived priority level (i.e., from QFI and FSI).

[0090] However, as illustrated in Figure 10, the message rather has a variance with mean period P0 and a standard deviation near the mean (i.e., ±ΔT). For example, T0-ΔT1 should not be smaller than the minimum possible early message set for (A) the SIL level and / or the derived priority level (i.e., from QFI and FSI).

[0091] In the case of faulty communication, all of the errors listed above must be detected at the receiver (in its lower layers). Regular (or rather, semi-regular) signal structures, such as heartbeats, can be used to detect the loss at the receiver. In one example, the transmission of heartbeats is implemented at the lower layers using, for example, SPS and / or configuration grants. In this case, the SPS / configuration grants become the carriers for functional safety-related heartbeat transmissions.

[0092] Furthermore, an indication that a transmission is a functionally safe transmission can be identified in the physical layer control channel. Reception of the next physical layer transmission must be detected periodically over period P, before a maximum time Tmax and after Tmin; otherwise, the receiving device will signal the application or safety layer about packet loss or delayed packets. P, Tmax, and Tmin can be set (or pre-configured) for the UE. Mapping functionality between the FSI and P, Tmax, and / or Tmin can also be set. In addition, Tmax can be set to lifetime, and the end of such lifetime is transferred to the functional safety layer.

[0093] In one example, if the UE is configured / pre-configured to send L2-identified FuSa transmissions (via FSI) to reduce irregularity, the UE will limit the likelihood of retaining resources (P_keep) for the re-selection procedure to a high value, for example, near the end range, e.g., [60%, 80%]. In addition, for high FSL values ​​(equal to high SIL / ASIL), it will only be up to a pre-configured maximum value, e.g., 80%.

[0094] In another example, irregularity measurements, such as (measured) Tmax-actual and (measured) Tmin-actual, are monitored to consider how often and how severely they occur. For example, a timer and / or counter are set to measure how often / for how long and how often irregularities occur. If a value exceeds a (pre-set) threshold, the lower layer of the UE must notify the SCL of the exceeded value.

[0095] In one example, HARQ feedback or support information from other UEs in the system to the FuSa SPS is a means of transmission failure. Furthermore, delayed feedback can also be monitored and considered a malfunction. For example, if a UE experiences too much NACK feedback (from unicast or groupcast communications), it may notify the SCL if the number of feedbacks exceeds a certain threshold.

[0096] In one example, toggle bits may be used within or in conjunction with a functional safety container to mimic a sequence number. These bits may be inserted as an in-data control channel (e.g., in-uplink, DL, or second-stage sidelink control channel) or a physical control channel. The receiver monitors this field to ensure the toggle sequence is correct. A false toggle sequence indicates a deleted / dropped transmission or a sequence error.

[0097] In one example, if a UE has mixed data related to (A)SIL, QM, and FSI for noncritical purposes, the UE selects only subsequent transmission periods, for example, when safety-related information is transmitted or when a heartbeat must be carried in non-safety-related information and must be marked with an FSF. Non-safety-related messages may be transmitted in the same SPS, but if a heartbeat is not carried with the aforementioned data, they may not be marked with an FSF bit.

[0098] In one example, UE / device 100 in Figure 1 is configured to send a heartbeat signal in an already configured SPS / grant if the UE receives a safety-related (FSI-marked) packet in its L2 buffer. In addition, if the UE receives a safety-related (FSI-marked) packet and the UE does not have a configured resource, the UE may initiate a new SPS transmission (e.g., using sidelink resource selection) or request a configured grant. In the latter case, the UE may initiate an SPS transmission whether the UE has multiple MAC buffer PDU packets or whether the MAC has only one PDU packet but secure communication with a heartbeat is required. That is, in the case of one FSI-marked or heartbeat-carrying PDU packet, the UE sends a first transmit and trust upper layer, and sends more safety-related packets as FSI-marked (and mapped to FSF bits); the UE may send a heartbeat with only control information, either no data or a repetition of the last transmitted data.

[0099] Figure 7 shows a schematic flowchart illustrating the TX procedure when a functional safety communication request is set / identified. The TX identifies the safety communication, maps it to the bearer, generates a heartbeat according to the required (A)SIL, and sends the heartbeat. The transmitter may send a safety communication carrying the heartbeat, or a heartbeat carried in non-safety communication data, or a signal consisting only of a heartbeat.

[0100] Figure 8 shows a schematic flowchart illustrating the RX procedure when functional safety communication signaling is identified at a lower layer of the receiver. The RX identifies the safety communication from a heartbeat or identified safety marker, e.g., DRB. The RX monitors the heartbeat and / or performs lower layer measurements according to the identified safety level (e.g., FSF, FSI, (A)SIL). Finally, the RX sends a safety report / decision to a higher layer (e.g., SCL). [Explanation of Symbols]

[0101] 100 devices 102 Mapping means 112 Mapping means 114 Mapping means 116 Mapping means 122 Determination or Processing Means 124 Determination or Processing Means 132 Transmission means 134 Transmission method 136 Transmission means 162 Receiving means 172 Means of modification or processing 174 Means of providing or processing 182 Failsafe function 192 Defense Function 200 equipment 232 Receiving means 234 Receiving means 236 Receiving means 242 Decision-making means 244 Decision-making methods 246 Mapping means 248 Decision-making methods 252 Processing means 254 Failsafe function 262 Transmission means 292 Defense Function

Claims

1. A method for a device (100) operating in a wireless communication network, Step (122) of determining at least one functional safety indicator (FSF) that indicates whether the relevant data (d#1, e#3), in particular V2X data including at least one of vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technical data including building operation data, are relevant according to at least one safety integrity level (SIL), A method comprising the steps (132-136) of transmitting the data (d#1) together with the at least one functional safety indicator (FSF) determined in step (122), The aforementioned method, The process includes the step (112) of determining a functional safety level indicator (FSI) that represents at least one of several safety integrity levels (SILs), The step (122) of determining the at least one functional safety indicator (FSF) is based on the functional safety level indicator (FSI), The step (116) includes mapping the QoS flow (F) belonging to the data (d#1) to a data radio bearer (DRB#1) based on the Functional Safety Level Indicator (FSI), A method wherein the step (132-136) of transmitting the data (d#1) is performed via the mapped data radio bearer (DRB#1).

2. The method includes the step (114) of determining at least one communication request (cr) based on the functional safety level indicator (FSI), The method according to claim 1, wherein the step (116) of mapping the QoS flow (F) to the data radio bearer (DRB#1) includes the step of selecting the data radio bearer (DRB#1) from the set of available data radio bearers based on a comparison of the determined at least one communication request (cr) with at least one communication parameter associated with each of the available data radio bearers.

3. The method according to claim 1, comprising the step (112) of mapping the safety integrity level (SIL) associated with the data (d#1) to the functional safety level indicator (FSI).

4. The method according to claim 1, wherein the data (d#1) is carried together with a related header, particularly an SDAP header, which includes the functional safety level indicator (FSI) as part of a QFI that identifies the QoS flow (F) associated with the data (d#1) or in addition to the QFI.

5. The step of transmitting the at least one functional safety indicator (FSF) is performed via at least one physical control channel, in particular via at least one of the physical uplink control channel PUCCH, the physical downlink control channel PDCCH, and the physical sidelink control channel PSCCH, or The method according to claim 1, wherein the step of transmitting the at least one functional safety indicator (FSF) is performed via each medium access control-control element (MAC-CE).

6. A device (100) for operating in a wireless communication network, At a minimum, determination means (122) for determining at least one functional safety indicator (FSF) indicating whether relevant data (d#1, e#3), in particular V2X data including at least one of vehicle operation parameters and road events, or industrial data including machine operation parameters, or building technical data including building operation data, are relevant according to at least one safety integrity level (SIL), The apparatus (100) includes transmission means (132-136) for transmitting the data (d#1) together with the at least one functional safety indicator (FSF) determined in the determination means (122), The aforementioned device is The system includes determination means (112) for determining a functional safety level indicator (FSI) that indicates at least one of a plurality of safety integrity levels (SIL), The determination means (122) for determining the at least one functional safety indicator (FSF) is based on the functional safety level indicator (FSI), The system includes a mapping means (116) that maps the QoS flow (F) belonging to the data (d#1) to a data radio bearer (DRB#1) based on the Functional Safety Level Indicator (FSI), An apparatus in which the transmission means (132-136) that transmits the data (d#1) is transmitted via the mapped data radio bearer (DRB#1).

7. A method according to any one of claims 1 to 5, or use of the apparatus (100) according to claim 6.

Citation Information

Patent Citations

  • Wireless communication method, terminal device, and network device

    EP3637807A1

  • Method and apparatus for mapping TC and PPPP in a wireless communication system

    JP2020533831A