Method for flexibly adapting the bit rate within a computer network

WO2025186001A8PCT designated stage Publication Date: 2025-10-02CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/054556
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-05
Filing Date
2025-02-20
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing Ethernet communication networks in vehicles face challenges with fixed bit rates, which complicate topology adjustments and EMC adaptations, and there is a risk of single-point failures in time synchronization due to reliance on a single grandmaster clock, posing security and reliability issues.

Method used

Implementing a method that uses the IEEE 802.1AS protocol for Ethernet-based time synchronization to dynamically adjust bit rates by monitoring quartz crystal oscillations affected by temperature, allowing flexible bit rate adjustments without additional protocols or hardware, and introducing pseudo-grandmaster clocks to obscure the grandmaster's trace, enhancing security and reliability.

Benefits of technology

Enables flexible bit rate adjustments and improved security by reducing single-point failures, enhancing reliability and cost-effectiveness, while maintaining network integrity and reducing testing costs.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to a method for flexibly adapting the bit rate within a computer network comprising at least one first node, wherein the node exchanges information over a data bus and / or over a point-to-point connection, wherein the following steps are performed: acquiring information about a first reception time of a first message, receiving information about a first transmission time of the first message, acquiring information about a second reception time of a second message, receiving information about a second transmission time of the second message, ascertaining a first value depending on the received and acquired information, and comparing the first value with a predefined second value, and identifying the state of the first node depending on the comparison result, wherein the comparison result is used to determine the clock used to generate the clock signals of at least the first node and what bit rate is present over a data bus and / or over a point-to-point connection from and to the first node and to further nodes in the computer network and, if the bit rate is known, the bit rate in the computer network is changed flexibly by modifying the clock used to generate the clock signals.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Method for flexible adjustment of the bit rate within a computer network

[0003] FIELD

[0004] The present invention relates to a method for flexible adaptation of the bit rate within a computer network

[0005] BACKGROUND

[0006] The control units used in vehicles, particularly motor vehicles, are connected to each other and to sensors via a computer network, known as the on-board network, to record the conditions of the vehicle or its components. The control units used in a vehicle perform various functions for operating the vehicle and receive data sent by sensors via the on-board network. Many applications require the most deterministic knowledge possible regarding the reliability of the sensor data. To ensure the most reliable function of the vehicle, the on-board network must therefore meet particularly high requirements regarding the punctuality of the data transmitted via the on-board network.

[0007] Ethernet technologies are increasingly being used in vehicles, replacing older or proprietary data connections and buses. Ethernet connections support a variety of switching protocols for transmitting data packets between senders and receivers at Layer 3 of the OSI layer model. The higher protocol layers handle the segmentation of the data stream into packets, process communication between communicating systems, translation of data into a system-independent format, and, finally, the provision of functions for applications. Work is currently underway on the next E / E architecture form, the so-called "zone-oriented architecture" and "server-based architecture." The difference from today's architecture is that control units are positioned at specific geolocations to collect sensor data.The significant difference from conventional architectures is that the computing power and most functions are consolidated on the central server ECUs, meaning that application software runs only on these ECUs. All remaining ECUs, the so-called zone controllers, "merely" collect data from the various sensors.

[0008] Consolidating functions onto a very few control units (servers) means that significantly more computing power will be required per ECU. To estimate and utilize this computing power, it is necessary to know which computing power is provided by which system on chip and which bit rates are required for optimal data exchange.

[0009] Almost all Ethernet communication networks used in vehicles use a time synchronization protocol that provides a global network time base that is synchronous across all network devices. The prevalence of time-synchronized network devices will continue to grow in the future. One of the biggest challenges facing these new server ECUs is heat dissipation. These powerful (graphics) processors require new, comprehensive cooling concepts, such as water cooling, as currently planned and already introduced in series production in some Tesla vehicles.

[0010] The management and diagnostics of ECUs and their functions will play an even more significant role than today in light of the ever-increasing safety requirements. The early detection of faults and critical situations plays a crucial role in this. Manufacturers of electronic components will have to assume greater responsibility in the automotive supply industry in the future. They will develop and manufacture increasingly complex, innovative assemblies that are passed on to the vehicle manufacturer as black boxes in the supply chain. The question that will remain intriguing is whether the necessary monitoring electronics will only detect genuine component faults, or whether even perfectly functioning vehicle components will have to be replaced because of doubts about their reliability from a functional safety perspective.Even if, after a thorough analysis, it turns out that the replaced parts are functioning perfectly, this still has an impact on the supply chain. However, with regard to warranty periods and future service contracts, this issue won't concern drivers, whose vehicles are automatically repaired again and again, almost overnight, to their utmost satisfaction.

[0011] In addition, the number of control units and their interconnection are continuously increasing. In addition to the actual control functions, diagnostic functions have become increasingly important. While diagnostics originally only served a monitoring function for compliance with legal emissions standards, today they are used throughout the entire value chain of vehicle manufacturers: in development, testing and validation, production, and ultimately in customer service. The comfort features of modern vehicles are also largely based on diagnostic functions.

[0012] The IEEE 802.1 AS standard provides such a protocol for time synchronization. Starting with a so-called "best clock" in the network, also known as the grandmaster or grandmaster clock, a master-slave clock hierarchy is established. The grandmaster provides the time base for the network, to which all other network devices in the network synchronize. The grandmaster is determined using the so-called Best Master Clock Algorithm (BMCA) and announced within the network. For this purpose, IEEE 802.1 AS-capable network devices send Announce messages with information about their internal clock to other directly connected network devices. The information about the internal clocks provides information about the accuracy of the respective clock, its reference or time reference, and other properties that can be used to determine the best clock in the network.A recipient of such an Announce message compares the received information with the characteristics of its own internal clock and, if any messages already received from another port, with information about clocks on other network devices. It accepts a clock located on another network device if it has better clock parameters. After a short time, the best clock in the network is determined, which then becomes the network's grandmaster. Time synchronization messages are distributed across the network from the grandmaster.A network device that receives a time synchronization message does not simply forward it, but corrects the time information by the previously determined delay on the connection over which it receives time synchronization messages from a directly connected network device, as well as by the internal processing time, before forwarding the time synchronization message with the corrected time information.

[0013] In the clock hierarchy according to IEEE 802.1 AS and the “generalized precision time protocol” (gPTP) defined therein, only one network device ever provides the best clock in the network. This network device therefore controls and regulates the entire time of the vehicle. All other clocks in network devices in the network are based exclusively on this one clock. Some vehicle manufacturers even synchronize networks of other standards, e.g. CAN, via this Ethernet time master, so that almost all network devices in the vehicle are informed of the system time by the network device providing the grandmaster. This defines a single network device in the network or vehicle as a single point of failure, the failure or tampering of which can have serious consequences for the operational reliability of the vehicle. For example,In vehicles with a high degree of driver assistance through corresponding systems or with systems for (partially) autonomous driving, a large amount of sensor data recorded within a narrow time window is processed together in order to derive corresponding control signals for the vehicle's actuators. The most accurate time recording of sensor data can also be of great importance for documentation purposes, e.g. when storing it in log files, the analysis of which can be used to reconstruct malfunctions or incorrect operation. The latter is of particular interest to insurance companies and law enforcement authorities. Therefore, the secure, synchronized provision of time information is essential. In addition, the number of control units and their interconnection is continuously increasing. In addition to the actual control functions, diagnostic functions have become increasingly important.While diagnostics originally served only as a monitoring function for compliance with legal emissions standards, today they are used throughout the entire value chain of vehicle manufacturers: in development, testing and validation, production, and ultimately customer service. The comfort features of modern vehicles are also largely based on diagnostic functions.

[0014] The management and diagnostics of ECUs and their functions will play an even more important role than today in light of the ever-increasing safety requirements. Early detection of errors and critical situations plays a crucial role.

[0015] Concepts are already being developed to dynamically outsource functions and applications to other ECUs / processors for optimization. This is referred to as live migration, reallocation, or migration.

[0016] For Ethernet, there are only fixed bit rates, one per decade. A finer granularity exists only for bit rates >1 Gbit / s. Thus, there are 10 Mbit / s, 100 Mbit / s, and 1 Gbit / s bit rates. Disadvantages of fixed bit rates are that the topology and cable—and thus the quality, windings, and possibly shielding—must precisely match this bit rate. Adaptations to EMC and topology (especially with 10BASE-T1 S in bus topology) are complicated or even impossible. Furthermore, it is necessary to provide for the use of additional capacity to optimize EMC problems. Furthermore, stub lengths are not permitted in the 10BASE-T1 S bus; a daisy-chain architecture is mandatory.

[0017] The core of the application is that the 10BASE-T1 S data protocol, in particular, does not have to be fixed to a bit rate of 10 Mbps. In contrast, the CAN protocol allows a wide range of different bit rates to be set depending on the bit timing and the quartz crystal used. There are operating conditions, such as flashing at the end of the band, in which higher bit rates would be possible, for example, because only parts of the temperature range exist, e.g., no -40°C.

[0018] Some approaches to detecting changes in the configuration or structure of a communications network using the network's time synchronization are known from the state of the art. An unauthorized change to the network's configuration can, for example, involve inserting a network device in preparation for an attack, intercepting messages for analysis and, if necessary, retransmitting modified messages. This can be used to prevent or at least disrupt secure and proper operation.

[0019] The new architectures now offer the possibility of implementing software on different ECUs, as the hardware becomes more generalized and the software more platform-independent. Therefore, at system design time, it is not always clear which software will run on which ECU (server) and which bit rates would be optimal for this.

[0020] One of the biggest challenges facing new server ECUs is heat dissipation. These powerful (graphics) processors require new, comprehensive cooling concepts, such as water cooling.

[0021] Implementing cost-effective heat dissipation and monitoring for the new server ECUs presents a new challenge for the automotive industry. These new server ECUs form the core of the network, meaning they will be the only central control units in the vehicle in the future. Shutting them down in the event of problems is hardly possible, as they are used for automated driving, for example, to merge sensor data and perform highly complex calculations, etc.

[0022] With autonomous driving, the demands on the reliability of all subsystems increase even further. Advanced diagnostic functions play a particularly important role in safeguarding all subsystems. The ever-increasing complexity requires the constant exchange of diagnostic data, and this data must be delivered securely and error-free. A challenge in the coming years will be the secure and reliable transmission of status information, as well as the redundant provision and transmission of this data. To this end, new network management concepts will emerge that always maintain a complete overview of the system and, in some cases, will also be activated from the cloud.

[0023] The early detection of errors and critical situations plays a key role in this. Manufacturers of electronic components will have to assume greater responsibility in the automotive supply industry in the future. They will develop and manufacture increasingly complex, innovative assemblies that are passed on to the vehicle manufacturer as black boxes in the supply chain. One task of functional testing will be to determine whether the necessary monitoring electronics only detect genuine component defects, or whether perfectly functioning vehicle components need to be replaced because of doubts about their reliability from a functional safety perspective. Even if, after thorough analysis, it turns out that the replaced parts are functioning perfectly, this will still have an impact on the supply chain.However, with regard to warranty periods and future service contracts, this question will not concern the driver, whose vehicle is automatically repaired again and again, almost overnight, to his utmost satisfaction.

[0024] In addition, the number of control units and their interconnection are continuously increasing. In addition to the actual control functions, diagnostic functions have become increasingly important. While diagnostics originally only served a monitoring function for compliance with statutory emissions standards, they are now used throughout the entire value chain of vehicle manufacturers: in development, testing and validation, production, and ultimately in customer service. The comfort functions of modern vehicles are also largely based on diagnostic functions. Potential overheating of ECUs will pose an even greater problem in the future. Early diagnosis using multiple redundant technologies is necessary to meet future security and safety requirements. The ECU can no longer execute software if it reaches its capacity limits, which are caused by a limited bit rate.

[0025] US 2016 285462 discloses a method for manufacturing an oscillator including a resonator element, an oscillation circuit that outputs an oscillation signal by oscillating the resonator element, a temperature compensation circuit that compensates for temperature characteristics of a frequency of the oscillation signal in a desired temperature range, comprising a first temperature compensation step in which the frequency is measured at a plurality of temperatures and first temperature compensation data is calculated based on a relationship between temperature and frequency; and performing a second temperature compensation step in which, after the first temperature compensation step, the frequency determined by a

[0026] Temperature compensation is determined by the temperature compensation circuit based on the first temperature compensation data at a plurality of temperatures, and the second temperature compensation data is measured based on a relationship between temperature and frequency.

[0027] WO 2014111920 A1 discloses a method and apparatus for use with a host computer that communicates messages with a computer peripheral device over a computer bus, where the peripheral device can be in multiple states. The peripheral device can be an input or output device or a mass storage device such as a hard disk drive. The device communicates with the host computer and the computer peripheral device over a proprietary protocol or an industry-standard bus, which can be based on point-to-point serial communication such as SATA. The peripheral state is determined by monitoring the messages transmitted over the bus and the sensor associated with the peripheral operation. The sensor can be a microphone or a camera, and the system can include voice or image processing.The comparison may suggest a malfunction or a suspected operation according to a predefined pattern, and a signal is generated.

[0028] The purpose of the application is to enable faster and more reliable bit rate adjustment so that the server ECUs can be operated flexibly in the computer networks.

[0029] The invention also advantageously solves the problem that each PHY (transceiver) has an external 25 MHz quartz clock, the frequency of which is specified in the IEEE standard. By changing this clock, different bit rates can be easily set.

[0030] Advantageously, the proposed method provides a solution that allows the bit rate in a computer network to be flexibly adjusted depending on the prevailing requirements for the computer network operation.

[0031] Currently, this approach, which proposes flexible bit rate adjustment, is known. The application advantageously proposes that, after the clocks have been determined, the bit rate can be changed in a computer network.

[0032] DESCRIPTION

[0033] This object is achieved by the method specified in claim 1 and the Ether on-board network specified in claim 12. Embodiments and further developments are specified in the respective dependent claims.

[0034] The invention proposes a novel, intelligent mechanism for modifying the bit rates of control units. The invention uses the Ethernet-based time synchronization protocol to enable modifications of the bit rates of nodes, components, and / or ECUs in the computer network. The Ethernet-based time synchronization (which will be used in all high-performance ECUs) is implemented using the IEEE802.1AS protocol. In each ECU, a quartz crystal always sends the clock to a PLL, which is then synchronized to the best clock in the network via software. Quartz crystals are influenced by ambient temperature much more than by age—approximately two orders of magnitude more.

[0035] The physical properties of a quartz crystal and its quality are crucial for the accuracy of time synchronization (e.g., PTP), which is based on the quartz crystal's oscillations. Temperature has the greatest influence on the quartz crystal and its accuracy. A typical quartz crystal exhibits the smallest deviations from its specifications at an average room temperature of +25°C. The number of oscillations decreases as the outside temperature decreases, and the quartz crystal oscillates more rapidly as the outside temperature increases, which heats up the quartz crystal.

[0036] Adapting the bit rate for 10BASE-T1 S is possible and can be implemented using chips currently in use. Specifically, a 25 MHz crystal is used for each 10BASE-T1 S node to achieve 10 Mbit / s on the bus. This is due to the DME (Differential Manchester Encoding) method for clock recovery. At the beginning of each bit, there is an edge transition. Depending on whether the bit is "1" or "0," there is another edge transition or no edge transition in the middle of the bit.

[0037] Bits. 4B5B coding is used to convert 4 bits into 5 bits, as additional control symbols are required for the bus access procedure. This means that 10 Mbit of payload data corresponds to 12.5 Mbaud. Due to the DME, 12.5 Mbaud corresponds to a 25 MHz clock rate.

[0038] The IEEE 802.1AS specification recommends a quartz crystal with a quality of no worse than ±100 ppm. AT-cut quartz crystals are characterized by their oscillation following a cubic curve with temperature variation. This allows the quartz crystal to operate stably over wider temperature ranges compared to other quartz crystal types. Time-of-flight measurements with the component under test determine the clock rate of its Ethernet quartz crystal and continuously monitor it (this requires no additional message exchange or protocols). Based on the change in the clock rate, the ambient temperature in this ECU can be determined, as this has a direct influence on the quartz crystal.

[0039] The key advantages of the invention arise from the implementation of additional redundant mechanisms that do not require additional protocols and further increase the diagnostic capabilities of our control units. The time synchronization protocol has very low data consumption and is transmitted at a high frequency anyway. The method provides constant monitoring without additional bus load or new protocols.

[0040] This process can be implemented, in particular, in the form of software that can be distributed as an update or upgrade to existing software or firmware by network participants, thus representing a standalone product. The process can be flashed via OTA into existing and delivered control units that, for example, also lack a temperature sensor, or whose temperature sensor is defective or no longer works reliably. This could even result in cost savings.

[0041] By detecting modifications in the network, another method is created to ensure data security and functional safety in the vehicle electrical system. If, for example, a modified control unit is used, neither the driver nor the workshop is actually aware of this – however, the network and the control units can identify errors based on the methods described in this invention. By using protocols and existing basic functions in the Ethernet TSN or AVB standards, no modifications to the protocol flow are necessary. This means that the bus load is neither increased nor are any hardware or software modifications required at the transmitter.

[0042] The method and the resulting control unit are particularly interesting for automotive applications, as reliability and safety over Ethernet are of great importance in automobiles and will become increasingly important. In the coming years, sensors (cameras and radar) will also send uncompressed data over Ethernet. With such data rates, additional technologies are necessary to make the Ethernet system more fail-safe and perform better. The invention contributes to enabling these applications.

[0043] A problem that exists today, and with every new system, is the dependency on communication interfaces and their support. The invention described here allows for much more platform-independent development, thus extending the life cycles of existing software platforms and controllers.

[0044] The computer network according to the invention is improved in terms of cost and reliability. The invention more clearly defines the testability of the system, thus saving testing costs. Furthermore, the invention offers transparent security functionality. Another possible application of the method lies in areas where quartz crystals are used with hardware-based time synchronization and where the clock rate can be determined remotely.

[0045] It is particularly advantageous if the initialization of the bit rate modification is performed in a secure environment where an attack can be ruled out with a sufficiently high degree of probability, for example, at the end of a manufacturing process through which a product containing the secured network is manufactured. A one-time initialization may be sufficient, especially if the network or its configuration does not change after initialization, for example, in all types of vehicles.

[0046] The method according to the invention further comprises the sending of additional time synchronization messages by selected network devices that do not provide the previously determined grandmaster clock, wherein the time information sent in the additional time synchronization messages as well as the clock parameters relevant for determining the best clock using BMCA and the domain number match or are comparable to those of the previously determined grandmaster clock. However, the additional time synchronization messages contain a unique clock identification that corresponds to the identification of the respective selected network device. The clock parameters relevant for carrying out the BMCA include, in particular, the values ​​for the variables priority 1 , priority 2 , clockClass, clockAccuracy, offsetScaledLogVariance, and timeSource according to the IEEE 802.1 AS standard.Each of the additional time synchronization messages sent by the selected network devices therefore appears to anyone listening to the network traffic to originate from a grandmaster clock, just as the time synchronization messages of the grandmaster clock determined during initialization, so that for the observer, a multitude of grandmaster clocks exist in the network.

[0047] The selected network devices preferably send their additional time synchronization messages in cycles that correspond to those of the grandmaster clock determined during initialization. Each of the selected network devices thus represents a type of pseudo-grandmaster clock that behaves as if it were the only and best clock in the network. Despite the different time synchronization trees within the network regarding the propagation of time synchronization messages, the pseudo-grandmaster clocks are indistinguishable from the grandmaster clock determined during initialization because the additional time synchronization messages are sent with the same domain number.

[0048] The selected network devices can begin sending additional time synchronization messages as soon as the unique clock identification of the grandmaster clock determined during initialization has been sent to all network devices. However, it is also possible to not start sending additional time synchronization messages until an initial time synchronization of all network devices in the network has been completed. Each additional time synchronization message is forwarded by all network devices in the same standard-compliant manner as the time synchronization messages sent by the grandmaster clock determined during initialization. This means that after the time information has been corrected by the propagation time on the receive link and the internal processing time, a time synchronization message is sent to other directly connected network devices.

[0049] The network devices are connected to each other via physical interfaces. Time synchronization messages are sent via logical ports defined for the interface, so that point-to-point connections for time synchronization exist between two network devices, even when they share physical transmission media. In this description, the term "interface" is used interchangeably with the term "port" unless the context indicates otherwise.

[0050] The method according to the invention makes it considerably more difficult or even impossible for an observer who begins to listen to the network traffic only after initialization has been completed to identify the grandmaster clock determined during initialization.

[0051] The selection of network devices that send their own time synchronization messages in addition to the grandmaster clock, thereby posing as a grandmaster clock, may include a review of whether a network device is essential for the operation of the network or a system containing the network and should therefore not serve as bait for a potential attack. Essential network devices include, for example, those that connect multiple network segments, such as a switch or a bridge, or those that implement functions that cannot be performed by other network devices, such as a domain computer for automated or autonomous driving or other security-relevant functions. Such network devices are preferably not selected.During the selection process, it can also be checked whether a network device is set up to execute generic functions or software that can also be executed by another network device within the network and can therefore be relocated to one of these other network devices if necessary, e.g. in the event of a detected attack on a network device. Such network devices can be given priority for sending their own messages for time synchronization, as can network devices that are located at the edge of the network and / or provide non-security-relevant functions and whose isolation from the rest of the network would not lead to major functional disruptions in the event of a detected attack. The same applies to network devices to which only a few other network devices are connected, e.g. network devices with only one port and therefore only one neighbor, and which can therefore be more easily isolated.The selection of network devices for sending their own time synchronization messages can also preferentially target network devices equipped with particularly strong security mechanisms and therefore better able to withstand attacks. In a simple case, the selection of network devices for sending their own time synchronization messages can involve reading a flag that was set during production or configuration of the network device for operation on the network. Other characteristics for determining whether a network device can be configured to send additional time synchronization messages can be determined through appropriate function queries.

[0052] The method according to the invention also includes, in network devices that do not provide the grandmaster clock determined during initialization, receiving time synchronization messages at a first network interface and checking whether the clock identification transmitted in the time synchronization message matches the stored clock identification of the grandmaster clock determined during initialization. If the clock identifications match, a local clock is synchronized using the time information received in the time synchronization message.

[0053] A further development of the method according to the invention comprises the

[0054] Monitoring the time information transmitted in additional time synchronization messages for a discrepancy with the time information transmitted in time synchronization messages with the clock identification of the grandmaster clock determined during initialization. As long as a network device is synchronized with the grandmaster clock determined during initialization, the time information underlying the comparison can also be provided by the network device's clock. If a discrepancy in the time information is detected, additional time synchronization messages with the associated clock identification can be blocked, i.e., not forwarded to the network for which a discrepancy has been detected.If the deviation is the result of an attack on the network device, an attacker who is only monitoring the network from one point will not notice the blockage because time synchronization messages are not confirmed by a recipient. Alternatively, the deviating time information transmitted in the received additional time synchronization message can be corrected and forwarded based on time information received from the grandmaster clock determined during initialization. The basis for the time correction can also be the local clock synchronized with the grandmaster clock determined during initialization. Alternatively or additionally, a corresponding message can be sent to a previously specified network device in the network that is set up to initiate and / or control suitable protective measures. Suitable protective measures can, for example, be:This may include isolating the network device or individual streams or messages of the network device that is sending the different time information from the rest of the network, or restarting the network device in question.

[0055] One embodiment of the method according to the invention comprises the sporadically or cyclically sending time synchronization messages by the grandmaster clock determined during initialization, in which the time information deviates from the actual time, and monitoring the additional time synchronization messages sent by the other network devices to determine whether they appropriately reflect the deviating time information. If this is not the case - unavoidable tolerances during synchronization can be ignored - a malfunction or an attack may be occurring, and the network device that provides the grandmaster clock determined during initialization can send a corresponding message to a previously specified network device in the network, which is configured to initiate and / or control suitable protective measures, e.g.The network device that does not reflect the changes in the deviating time information is isolated from the rest of the network. If the additional time synchronization messages sent by the other network devices reflect the changed time information, it can be assumed that all pseudo-grandmaster clocks are behaving according to the rules.

[0056] A computer program product according to the invention contains instructions which, when executed by a computer, cause the computer to carry out one or more embodiments and further developments of the method described above.

[0057] The invention disclosure also proposes a novel intelligent mechanism for monitoring temperature changes or heat generation in the control units. The method uses the Ethernet-based time synchronization protocol to detect changes in the ECU temperature.

[0058] Ethernet-based time synchronization is implemented in all high-performance ECUs using the IEEE802.1AS protocol. In each ECU, a quartz crystal always sends the clock to a PLL, which is then synchronized to the best clock in the network via software.

[0059] The physical properties of a quartz crystal and its quality are crucial for the accuracy of time synchronization (e.g., PTP), which is based on the quartz crystal's oscillations. Temperature has the greatest influence on the quartz crystal and its accuracy.

[0060] By conducting runtime measurements with the component under test, the clock rate of its Ethernet crystal is determined and continuously monitored (this does not require any further message exchange or protocols). Based on the change in the clock rate, the ambient temperature in this ECU can be determined, as this has a direct influence on the crystal.

[0061] The controller that implements the time master functionality must handle certain interrupts and reserve resources for them. However, thanks to the invention disclosure, virtually any controller can be used, which in turn reduces system costs and resources.

[0062] The flexible bit rate adjustment provided by the method can also be recognized as protection against unauthorized attacks on time synchronization, communication corruption, and device replacement. Furthermore, applications with an even higher level of security can be achieved this way, for example, through the use of hardware encryption (or authentication). The method allows for more cost-effective protection mechanisms, which is helpful for meeting ISO 26262 requirements and also reduces system costs. The method could even be implemented retroactively via OTA.

[0063] In vehicles, however, it is generally not cost-effective to provide all network participants with sufficient hardware for seamlessly encrypted communication. The described method requires significantly fewer hardware resources and can be implemented with existing implementations, thus significantly increasing the level of security without necessarily resulting in higher manufacturing costs for the computer network or the devices connected to it.

[0064] This method can be implemented, in particular, in the form of software that can be distributed as an update or upgrade to existing software or firmware by network participants and thus represents a standalone product. The invention can advantageously improve the performance of software-based applications (e.g., automated driving), particularly without additional financial outlay. With the use of the newly introduced Ethernet protocol in automobiles, mechanisms are necessary that utilize simple techniques and existing technological properties in order to avoid expensive implementations and additional hardware. The network system according to the invention is improved in terms of cost and reliability. This allows one to get the most out of one's ECU or network using software-based methods and offer the customer more functionality.

[0065] Advantageously, the invention can significantly and very simply increase the security of a vehicle network, particularly without additional financial outlay. With the use of the newly introduced Ethernet protocol in automobiles, mechanisms are necessary that utilize simple techniques and existing technological properties, eliminating the need for expensive implementations and additional hardware. Earlier detection of attacks and malfunctions through early analysis of communication paths allows gaps and errors to be identified before the vehicle is delivered. The network system according to the invention is improved in terms of cost and reliability. The testability of the system is more clearly defined by the invention, thus saving testing costs. Furthermore, the invention offers transparent security functionality.

[0066] Today, applications are implemented, tailored, and adapted to a specific vehicle type. This method allows the software to be designed more flexibly, generating value-added services from the underlying system without having to program them into the software beforehand. Today, we actually have to assume the worst-case scenario, which costs resources (money) and results in a loss of quality. The invention allows software developers and architects to be offered software / applications that can be tailored more flexibly and precisely to the requirements of the application. By incorporating the aforementioned methods into software, optimization can occur within the control unit. This means that the software can be designed more independently of the platform and vehicle type.

[0067] The new technologies in automobiles are unstoppable. Protocols such as IP, AVB, and TSN have several thousand pages of specifications and test suites. The manageability of these new protocols in automobiles is not immediately certain.

[0068] The new method can be integrated into an existing network without damaging existing devices. The standard is not violated because the existing protocol can be used.

[0069] The method could also be used for other communication systems with clock synchronization components and embedded systems.

[0070] The computer program product may be stored on a computer-readable medium or data carrier. The data carrier may be physically embodied, e.g., as a hard disk, CD, DVD, flash memory, or the like, but the data carrier or medium may also comprise a modulated electrical, electromagnetic, or optical signal that can be received by a computer using a corresponding receiver and stored in the computer's memory.

[0071] A network device according to at least one embodiment of the invention comprises, in addition to a microprocessor, non-volatile and volatile memory, and a timer, at least one physical communication interface. The components of the network device are communicatively connected to one another via one or more data lines or buses. The memory of the network device contains computer program instructions which, when executed by the microprocessor, configure the network device to implement one or more embodiments of the method described above. The present invention can advantageously protect the grandmaster because its previously easily detectable trace is obscured or hidden by a multitude of false traces, thus making the grandmaster's position within the network more difficult for attackers to determine. The attacker can then no longer attack at all, or at least requires considerably more time.Attacks that do not happen to immediately affect the grandmaster can be detected, and appropriate mitigation measures can be taken, while the system remains synchronized with the required accuracy and operates at a set bitrate.

[0072] The method according to the invention can be implemented with existing network devices, whereby if necessary only adjustments to the software or the state machines used for receiving and processing time synchronization messages are required in order to use only the time synchronization messages coming from the grandmaster clock determined during initialization for synchronizing the clocks, while still forwarding the additional time synchronization messages and not simply deleting them. This means that only minimal additional costs, if any, are incurred for implementation. Existing systems can also be configured to implement the method by appropriately modifying the software. A further advantage of the method according to the invention is that the respective underlying hardware platform is irrelevant as long as it supports synchronization according to the IEEE 802.1 AS standard.

[0073] DESCRIPTION OF EMBODIMENTS

[0074] The motor vehicle has an Ethernet on-board network. According to the exemplary embodiment, the Ethernet on-board network, in turn, has a plurality of control units, which can also be referred to as control devices or control units. The control units are interconnected via connection paths. Due to the existing topology of the Ethernet on-board network 2 in the exemplary embodiment, there are several parallel communication paths between the control units. The connection paths can, for example, be formed from different media types or materials.

[0075] As the number of Ethernet variants increases, dynamic connection speed changes will also be used. This means, for example, that the speed can be changed at runtime. For example, a 10 Gbit / s connection path can be changed to 100 Mbps to save energy. Because this is a dynamic function, the on-board network may be configured differently after delivery or initial installation in the vehicle than it would be after a software update or in a malfunction.

[0076] The Ethernet on-board network comprises at least a first control unit or a first node, a second control unit or a second node, and additionally a third control unit or a third node. The first control unit is connected to the second control unit via a first connection path. Furthermore, according to the exemplary embodiment, the first control unit is also connected to the second control unit via a second connection path.

[0077] The first control unit, the second control unit, and / or the third control unit can be configured, for example, as a control device or network switch. The second control unit and the third control unit are connected to each other by a third connection path.

[0078] According to one embodiment, the first control unit and the second control unit are directly connected to one another via the first connection path, while the first control unit and the second control unit are only indirectly connected to the second connection path, since the second connection path is split into two parts by a further control unit. According to another embodiment, the second connection path can connect the first control unit and the second control unit directly to one another. Generally speaking, the method is also suitable for detecting synchronization errors. It is possible to calculate or determine the duration of the asynchrony or when the time and when the last time synchronization was correctly carried out. On the basis of an existing synchronization, the method proposes to correct the inaccuracy of the clocks in the network, e.g.of "my" neighboring ECU or the "neighboring" CPU, which may be located within the same ECU. On the basis of this determined data, a timestamp of this component, in conjunction with "my" own clock or that of the grandmaster and the synchronization interval, can be used to calculate how much time has passed since the last synchronization. This can be used to determine when the last successful synchronization took place. At a point in time, also called the determination time, a timestamp of an ECU of a control unit is recorded, the one you want to know whether it is still synchronized. Based on a series of parameters, it is then determined how many synchronization intervals or since which point in time this component has not been successfully synchronized.

[0079] The method thus determines when a node's last successful synchronization occurred and thus how long it has been out of synchronization. This is the basis for deciding whether the sensor data is trustworthy and therefore usable.

[0080] After synchronization messages arrive, the internal clock or offset is adjusted. Afterward, the clock continues to run with its own characteristics until the next synchronization.

[0081] The method is characterized by the fact that the node, respectively a PC or switch or the entire ECU or the control unit, is queried for its time or read out using a timestamp. This value is saved. The method then uses the 802.1AS protocol (Pdelay query) to determine the frequency drift of the timer and the frequency of the timer. This is used to calculate the speed at which the clock generator of this ECU / PC or entire ECU or control unit operates using cyclic messages, which actually serve to measure the runtime and are transmitted anyway. A well-known process is used for the runtime measurement. A port, the initiator, starts the measurement by sending a Delay_Request message to the port connected to it, the responder, and generates an output timestamp t1. This output timestamp refers to a hardware timestamp that is written as late as possible after leaving the Ethernet transceiver.When this packet arrives, the responder generates a timestamp t2. In response, the responder sends a Delay_Response message. In this message, it transmits the received timestamp t2 of the Delay_Request message. When this message leaves the responder, the responder generates a timestamp t3, which is sent in an immediately subsequent Delay_Response_Follow-Up message. When the initiator receives the Delay_Response message, the initiator generates a timestamp t4. The initiator can calculate the average runtime of the distances traveled from the four timestamps t1 to t4.

[0082] PTP defines a master-ZSIave clock hierarchy with a best clock within a network. The time base of the nodes in the network is derived from this clock, the grandmaster. The Best Master Clock Algorithm (BMCA) is used to determine this clock type and to announce this information within the network. IEEE 802.1 AS-capable systems cyclically send Announce messages to their neighboring nodes with information about the best clock in the cloud. The recipient of such a message compares this information with the characteristics of its clock and any messages already received from another port. A time synchronization spanning tree is created based on these messages. Each port is assigned one of four port states in this process. The Master Port state is assigned to the port that has a shorter path to the grandmaster than its link partner.The Slave state is assigned when no other port on this node has this state. Disabled selects the port that cannot fully support the PTP protocol. The Passive state is selected when none of the other three states apply. The exchange of time information is finally carried out by the Sync_Follow_Up mechanism. The master ports cyclically send Sync and Follow_Up messages to the neighboring link partner. When the Sync message leaves the master port, a timestamp is generated, which is immediately transmitted in a subsequent FollowJJp message. This timestamp corresponds to the current time of the Grandmaster at the time the Sync message is sent. The messages outgoing from the Grandmaster are not forwarded, but rather are created anew in each node, including the switches.

[0083] The PTP NRR (Neighbor Rate Ratio) method can be used to determine or calculate the clock speed. Cyclic PDelay messages are used to calculate the clock speed (offset) relative to the reference clock. The read or queried time (Tsuspect) is assigned to the current system time (TReference), thus the trusted time, either the grandmaster or the time for which the data is important. If the component under investigation is a sensor, the sensor fusion time can be used as a reference. This means that the difference between the two times is first determined.

[0084] TDeviation = TReference-Tsuspect

[0085] Using the synchronization frequency, the maximum T deviation can be calculated: In Ethernet, the interface between the PHY (transceiver) and the MAC is the key interface for receiving the timing information. This interface (xMII) is clocked at a nominal frequency f of 25 MHz. Crystals for implementations suitable for Automotive Ethernet AVB / TSN must not exceed a maximum inaccuracy fo of ±100 ppm. Thus, the worst possible crystal in conjunction with the interface causes a frequency deviation of 5 kHz from the nominal frequency f according to the formula: df = (f *fo) / 10 A6 The change in the period between the maximum (2500-2500 Hz) and the minimum frequency (2499-7500 Hz) is 8 ps with a period of 40 ns. This means that two quartz crystals (and thus two ECUs) can have a maximum time difference of 8 ps at +25 °C in 40 ns. Exactly 3125,000 periods of 40 ns are possible in the standard synchronization interval of 125 ms, which corresponds to a maximum deviation of 25 ps.

[0086] According to the IEEE802.1AS specification, the synchronization interval can be between 31.25 ms and 32 seconds. At the shortest interval, this results in a worst-case deviation of 6.25 ps, and at the longest interval, a worst-case deviation of 6.4 ms.

[0087] Using the previous formula, by determining the speed of the clock and knowing the synchronization interval TDeviation, the method can be used to calculate when the last synchronization took place.

[0088] In one embodiment of the Ethernet on-board network, there is a first control unit, a second control unit, and a third control unit. The Ethernet on-board network also has the first connection path, the second connection path, and the third connection path. According to the embodiment, a propagation time of a first signal on the first connection path is determined. The propagation time describes how long the first signal travels along the first connection path from the first control unit to the second control unit, or vice versa. A maximum speed of the first connection path is determined based on the propagation time of the first signal. The maximum speed of the first connection path varies, for example, depending on the length of the cable, the transmission speed, and / or the media type or type of transmission medium. A type of transmission medium of the first connection path is determined based on the maximum speed.

[0089] According to this embodiment, the type of transmission medium is defined as optical, copper, or wireless. In the case of optical transmission, the first connection path is embodied, for example, as a fiber optic connection. In the case of copper transmission, the first connection path is embodied, for example, by a cable with twisted wire pairs, such as an unshielded twisted wire pair cable (UTP). In the case of wireless transmission, the first connection path is essentially embodied as a radio link, and the first control unit and / or the second control unit have a radio receiver and / or radio transmitter or are connected thereto.

[0090] The control unit determines a runtime for the data transmission via the on-board network to a fourth control unit. It is important that the runtime is determined in some way on the basis of an actual physical condition of the transmission path from the first control unit to the fourth control unit, i.e. that there is a physical condition or property of the transmission path, the change of which leads to a change in the determined runtime.

[0091] Here, a third control unit determines a propagation time for the data transmission over the network to the fourth control unit. This can be done in an alternative way. For example, the propagation time can be determined during a time synchronization between the first participant and the second participant, for example according to the time synchronization standard IEEE 802.1 AS and the PTP protocol contained therein. For example, the "Delay Request" and "Peer Delay" messages implemented within this protocol can be used as data packets. However, the method is not limited to this. It is only important that the propagation time is determined in some way based on an actual physical condition of the transmission path from the first participant / first control unit to the second participant / second control unit, i.e.that there is a physical condition or property of the transmission path, the change of which leads to a change in the determined transit time.

[0092] Furthermore, the first control unit determines the message frequency, which is essentially derived from the speed of the PLL and the quartz crystal, for the fourth control unit opposite. From these two values, which constantly change due to temperature, aging, etc., the third control unit derives a key for encrypting these time messages.

[0093] The time synchronization messages are encrypted with the generated dynamic key, which can generally be derived from individual parameters of the connection partner.

[0094] The type of transmission medium is communicated to a program in the Ethernet on-board network. The program can, for example, be located in the first control unit, the second control unit, the third control unit, or another control unit in the Ethernet on-board network. Depending on the type of transmission medium, the connection path selection is adjusted. For example, the program can use the connection path selection to send data via a different connection path than the one used before the connection path selection. However, the program can also, for example, interrupt the transmission of data by selecting the connection path and resume it at a later time.

[0095] According to the exemplary embodiment, a transmission reliability value is assigned to the first connection path based on the type of transmission medium. The transmission reliability value describes the probability of loss of data transmitted over the connection path. The transmission reliability value thus allows a statement to be made about how reliably the data can be transmitted over the first connection path. This is fed into the entropy source. If, for example, a security threshold is exceeded and the data can only be transmitted insecurely, it can be expected that the data will reach its destination with a delay or, if retransmission is not worthwhile due to the required timeliness of the data, it will not reach its destination at all.

[0096] According to a further embodiment, propagation times of a plurality of signals on the first connection path are determined, and the fastest propagation time of the plurality of signals is selected. The maximum speed of the first connection path is then determined based on the fastest propagation time.

[0097] A control unit starts the delay measurement and waits for the link partner messages to be received. Based on the message reception, using the PTP example, the line delay can be measured. When one link partner starts the delay measurement, the other link partner is automatically notified and should also start a measurement so that these two measurements can generate a related measured value.

[0098] Analogous to the procedure described above, the type of transmission medium for the second connection path and / or the third connection path can also be determined.

[0099] The recorded values ​​are different, remain secret and stored in the control unit, and are not transmitted over the network—nor do they need to be. It is sufficiently unlikely that the key will be discovered simply by trial and error. Taking these two values ​​into account, an individual key is generated. Firstly, the frequency of each crystal is different, and secondly, the line delay of each link is different. Here, two fluctuating values ​​are added together to produce a third value that is even more difficult to guess—the value of the key. The line delay can typically be in the range of 50-500 nanoseconds, and the frequency is a parameter and is specified in + / - ppm. The line delay both ways is based on the same channel, which is why the calculated values ​​are the same on both sides of the link. Therefore, the parameters do not need to be exchanged.Thus, both partners have virtually the same values ​​for key generation at virtually the same time. One link partner encrypts using these two values ​​derived from the last measurement, and the other link partner decrypts using its last values.

[0100] It is also intended that the propagation time of a second signal on the second connection path is determined. A maximum speed of the second connection path is then determined based on the propagation time of the second signal. Based on the maximum speed of the second connection path, the type of transmission medium for the second connection path is determined.

[0101] It is advantageous to use the current key A1 as long as no new line measurement is performed. This way, the link partner always knows which key to use if no new line measurement has been initiated previously. A new key should / can be generated either cyclically, e.g., at a specified frequency and thus bit rate, as needed by a trigger, or always immediately before sending important messages.

[0102] Both the first control unit, the second control unit, and the third control unit can be operated in a normal operating mode or in a power-saving mode. In power-saving mode, the respective control unit consumes less energy than in normal operating mode. For example, in power-saving mode, the speed of a port of the respective control unit can be reduced compared to the speed in normal operating mode. The reduced port speed then also affects the respective maximum speed of the respective connection path.

[0103] According to a further embodiment, a service message can be sent from the first control unit to the third control unit. The service message then triggers the determination of a propagation time of a third signal. The third signal is sent between the second control unit and the third control unit. According to the embodiment, the propagation time of the third signal is determined by the third control unit.

[0104] The propagation time can be determined as follows: In one step, the propagation time of the first signal is determined. In another step, the type of transmission medium is determined. Finally, in one step, the program is adapted. In one step, the propagation time of the first signal is determined.

[0105] This allows the type of transmission medium to be determined in a single step. The type of transmission medium can, in turn, include the following parameters: speed, medium, cable length, power transmission, bit error rate, and bit rate. Finally, the program is adapted and the connection path is selected in a single step.

[0106] According to this example, it is proposed to measure the propagation time of signals between connected control units or controllers. Methods from the IEEE 1588 or IEEE 802.1 AS standards, for example, can be used to measure propagation times. TTEthernet (time-triggered Ethernet), for example, can also provide methods for determining the respective propagation time.

[0107] The program, which is executed in particular on at least one control unit, preferably first determines the time of day and the runtime or the runtimes locally if more than one control unit is directly connected. Then, preferably other control units are queried for their runtime relative to their neighbors using a service-oriented method, for example SOME / IP (Scalable Service-Oriented Middleware over IP). This can be implemented either centrally or decentrally. The query can be performed once, at system startup, definition or after a software update, or it can be executed cyclically to detect dynamic changes. This data, including the addresses of the control units, is then saved and assigned the first time. In one step, the respective runtime for the directly connected control units is determined. In a third step, the respective runtimes for other connection paths are queried.In one step, the respective runtimes and their associated connection partners are saved.

[0108] If, for example, the current temperature is very high or poor-quality cables are used, pre-stored values ​​may be too inaccurate. It is therefore recommended that the application or program performs its own measurements on its own control unit, particularly with knowledge of its own parameters and other speeds, which can then be derived and calculated. In one step, an analysis is carried out for each local Ethernet port. In one step, it is checked whether channel parameters are known. If this is not the case, a step follows and the process is terminated. If this is the case, a step follows in which the respective propagation time is determined. In one step, the data is saved, and the determined propagation time is related to the channel parameters. In one step, a reference value list is created.

[0109] One possible optimization based on knowledge of the type of transmission medium occurs in a step in which a decision is made as to whether the type of transmission medium is copper. If this is the case, a step follows in which it is confirmed that PoDL (Power over Data Lines), i.e. power supply via Ethernet, is possible. If it is decided in this step that the medium is not copper, a further step follows in which it is checked whether the type of transmission medium is optical. If this is the case, a further step follows in which it is determined that this results in a lower bit error rate and therefore a higher reliability of this connection path. A further step provides the option of deactivating the RX (receiving unit) or TX (transmitting unit) of the control unit if not required.

[0110] If it is determined that the medium or type of transmission medium is not optical, a first step is to assume that the respective connection path is configured as a direct MII (Media Independent Interface) connection. In this case, the respective control unit is suitable for IEEE 802.1 CB (Frame Replication and Elimination for Redundancy), for example.

[0111] Further possibilities arise from knowledge of the transmission speed. Combined with current data streams, for example, data can be transmitted selectively over a high-bandwidth connection, thus deactivating other, unused connection paths, thus saving energy.

[0112] In addition, high-bandwidth connections offer the possibility

[0113] Redundancy mechanisms (e.g., IEEE 802.1 CB) should be used. Since the data is transmitted continuously and redundantly, this requires a high bandwidth. It is also conceivable to adapt the application to the speed of the transmission path. For example, a camera can adjust the resolution of the image data to be transmitted depending on the speed of the link or connection path.

[0114] The control unit 3 comprises a microprocessor, a volatile and non-volatile memory, two communication interfaces, and a synchronizable and modifiable timer or clock. The elements of the network device are communicatively connected to one another via one or more data connections or buses. The non-volatile memory contains program instructions which, when executed by the microprocessor, implement at least one embodiment of the method according to the invention. The entropy source is formed in the volatile and / or non-volatile memory, from which the dynamic keys for the connection paths are then formed.

[0115] An evaluation of the use of received data can be performed based on the last successful synchronization. This process can be used to determine whether the checked data prior to storage is suitable for the respective application. This is particularly advantageous when storage is carried out on a data recorder. It is of particular interest to the data recorder whether the data content is correct. In the event of an accident, for example, it is important whether the camera detected the pedestrian or not. If incorrect data is recorded or data with an incorrect time, the recording is invalid and cannot be recognized as such without the procedure.

[0116] The querying component analyzes a data stream and its sender. Based on this procedure, it can be determined when the data was last trusted. The nominal thresholds are determined either by the functions, the system manufacturer, or the use case itself. This can vary per ECU and per use case. Based on this threshold, the data can be classified as valid, invalid, or untrusted.

[0117] Data is deleted retroactively if the synchronization time exceeds the threshold. This procedure is also used, for example, when data has already been saved (or is about to be saved), as in the data recorder application. The data recorder is particularly interested in whether the data content is correct – in the event of an accident, for example, it is important whether the camera detected the pedestrian or not. If incorrect data is recorded or data with an incorrect time, the recording is invalid. The querying component analyzes a data stream and its sender. Based on this procedure, it can be determined when the data was last trusted. The nominal thresholds are determined either by the functions, the system manufacturer, or the application itself. This can vary per ECU and per use case.Based on this threshold, the data can be classified as valid, invalid, or untrustworthy.

[0118] The querying component can be a data recorder or a cloud storage device that wants to examine a task to examine a stored data set from a component, such as a sensor data stream. For this purpose, the address, stream, and timestamp can be checked. A successful synchronization is checked for the last time, and the time at which the data was last valid is determined. The storage is checked, and any data records that are not correctly synchronized are discarded.

[0119] The quartz crystals used in quartz oscillator circuits are usually crystal plates, rods, or forks (like a tuning fork) that can be subjected to mechanical deformation by applying electrical voltage, which in turn generates an electrical voltage. The response is determined by the mechanical vibration modes of the piezoelectric crystal. A quartz crystal is excited to particularly strong resonant vibrations when exposed to an alternating voltage of a specific frequency, its resonant frequency (this property is also shared by piezoelectric sound generators). With a suitable crystal cut, this vibration is almost independent of environmental influences such as temperature or amplitude and is therefore used as a precise clock generator with a long-term stability of better than 0.0001%.

[0120] Oscillating quartz plates have two electrically distinguishable electrical / mechanical modes:

[0121] At series resonance, their apparent resistance to alternating current is particularly low and they behave like a series circuit consisting of a coil and a capacitor.

[0122] At parallel resonance, the apparent resistance is particularly high. They then behave like a parallel circuit of a capacitor and an inductor, with the exception that no direct current can flow (quartz is a very good insulator).

[0123] The parallel resonance is approximately 0.1% higher than the series resonance. A comparable oscillation behavior can also be found at three, five, etc., the fundamental frequency. A quartz crystal with a resonant frequency of 9 MHz can also be made to oscillate at 27 MHz or 45 MHz. Harmonic quartz crystals specifically designed for this purpose are mounted accordingly to prevent interference with these harmonics.

[0124] The operating point of the quartz crystal in the crystal oscillator lies between the natural resonances mentioned above. In this frequency range, the quartz crystal behaves inductively like a coil. Together with its nominal capacitive load, the quartz crystal oscillates at its nominal load resonance frequency. Slight deviations from the nominal frequency can be generated or compensated by changing / deviating from the nominal load capacitance. The frequency is slightly temperature-dependent, as already mentioned. For more demanding temperature response, temperature-compensated oscillators (TCXOs) are available. These typically use thermistors to generate a control voltage that counteracts the temperature-dependent frequency change of the quartz crystal, as shown in Figure 1.1 b.The voltage thus generated is usually applied to a capacitance diode so that the resulting change in capacitance corrects the frequency of the quartz oscillator.

[0125] If even greater precision is required, a quartz furnace is used. The quartz is housed in a temperature-controlled enclosure to minimize ambient temperature-dependent influences. The quartz is electrically heated to, for example, 70 °C. This design is called an OCXO (oven-controlled crystal oscillator). The "X" stands for Xfa / , short for crystal.

[0126] AT quartz crystals are used for Ethernet in the automotive sector.

[0127] As already explained, the frequency is slightly temperature-dependent. The invention utilizes this property of the quartz crystals to derive the possible bit rate adaptation. Temperature changes have a direct impact on the quartz crystal and thus on the uncontrolled PLL of the Ethernet transceiver. This, in turn, affects the generation of the clocks for sending the cyclic PTP messages. In the automotive sector, AT-cut quartz crystals are always used for Ethernet because of their excellent temperature stability. Furthermore, the influence of temperature always has a predictable effect.

[0128] The system model for Ethernet time synchronization affects the quartz crystal and thus the uncontrolled PLL of the Ethernet transceiver. This, in turn, affects the generation of the clocks used to send the cyclic PTP messages. In automotive technology, AT-cut quartz crystals are always used for Ethernet because of their excellent temperature stability. Furthermore, the influence of temperature always has a predictable effect.

[0129] The process starts at time point t and begins with the start of the runtime measurement. A PDelay_Request message is sent to the ECU over the network. The ECU responds with a PDelay_Response and a PDelay_Response_FollowUP message. Using these messages and their arrival time (hardware timestamp), the NRR is calculated—the frequency offset to the internal clock, meaning that the frequency offset between the two clock generators can be measured.

[0130] By measuring the delay between nodes (cable + PHY), the Neighbor Rate Ratio can also be determined. The NRR measures the frequency offset between two clocks (the crystals of two PHYs or ECUs). For example, it can be used to determine the difference in ppm. This is possible because Ethernet uses hardware instead of software timestamps.

[0131] NRR = 1 would mean both crystals / PLLs run at exactly the same speed (hardly possible due to manufacturing tolerances, etc.). NRR = 0.99998 would mean that the crystal runs 20 ppm slower.

[0132] The process continuously determines the clock rate of the quartz crystal by measuring the propagation time between the components. This also works within an ECU via the PCB. This data is logged and compared with previously recorded values. If the deviation changes (always taking the local clock / clock generator into account), it can be determined whether a rise or fall in temperature is the cause. (Aging also affects the clock generator, but this happens very slowly and has no influence at all on measurements taken one after the other.) If a reference measurement is available, i.e. if it can be determined or assigned how fast or slow the clock is for a given temperature, then the temperature can also be derived directly. Based on this temperature, a response can be made, for example, with an error (feedback, error code, etc.) or by adjusting the synchronization.The component that wants to obtain information about the bit rate could be a network manager of a central ECU, which, for example, needs to offload software or search for free resources. Based on the temperature (temperature change) received, the unit can decide whether to offload software or move software to it.

[0133] Based on the available resources of the server components, the method can be used to shift software to the components that are not on the verge of collapse and thus could enter an unstable state.

[0134] Using the described process, functions and applications can be (dynamically) outsourced to other control units / processors, including for optimization. This is referred to as live migration, reallocation, or migration.

[0135] The approach described here now offers the first opportunity to implement software on different ECUs, as the hardware becomes more generalized and the software more platform-independent. Therefore, at system design time, it is not always clear which software will run on which ECU (server).

[0136] The component that wants to know the bitrate could be a network manager of a central ECU, which, for example, wants to relocate software or search for free resources. Based on the received bitrate or a change in the bitrate, which can be determined via the network, the unit can decide to relocate software or move software there. Based on the available resources of the server components and adjusting the bitrates, the method can be used to relocate software to components that are not close to collapse, thereby achieving greater overall stability of the entire network. Furthermore, the method can be used to decide on relocating software / resources. The address of the grandmaster is contained in the synchronization messages.

[0137] 10BASE-T1 S supports a transmission speed of 10 megabits per second (Mbps) over twisted-pair cables with a maximum length of 25 meters at 8 nodes. It uses baseband signals and twisted-pair cables terminated with RJ45 connectors. These non-automotive applications typically use unshielded Category 3, 4, or 5 twisted-pair cables terminated with RJ45 connectors. Patch panels organize the cabling, and patch cables connect the ports to the central hub. While most modern devices support higher speeds such as 100BASE-TX or Gigabit Ethernet, 10BASE-T1 S devices may not be compatible with devices designed for 10 / 100 operation.When a 10BASE-T device is connected to a 10 / 100 switch, only that device's port will run at 10 Mbps, potentially affecting the overall network speed. Cable quality affects noise rejection and signal interference, which impacts network performance. Impact on network performance: If a slower 10BASE-T device is introduced into a network that predominantly runs at higher speeds such as 100BASE-T or faster, it may slow the connected port to 10 Mbps. This slowdown occurs because the device is operating at its maximum speed, which impacts the overall network performance. 10BASE-T is an Ethernet standard that supports 10 Mbps transmission over twisted-pair cabling.While modern networks primarily operate at higher speeds such as Gigabit Ethernet, compatibility issues can arise when connecting older 10BASE-T devices to faster network components, potentially affecting the overall speed of the network.

[0138] Differential Manchester coding (DM) is a line code used in digital frequency modulation (DFM) that combines data and clock signals into a single two-level, self-synchronizing data stream. In this coding scheme, each data bit is represented by the presence or absence of a signal level transition in the middle of the bit period, followed by a mandatory level transition at the beginning. Unlike Manchester coding, differential Manchester coding does not depend on the polarity of signal transitions, but rather on the presence or absence of transitions to indicate logical values. This method ensures robust clock recovery because it guarantees at least one transition per bit, which is useful in noisy environments where detecting transitions is less error-prone than comparing signal levels to a threshold.In addition, differential Manchester coding offers advantages such as immunity to signal inversions, reduced required transmit power due to zero DC bias, and minimized electromagnetic noise production. It is specified in standards such as IEEE 802.5 for Token Ring LANs and finds applications in various areas, including magnetic and optical storage, AES3, S / PDIF, USB PD, and more. With a 30 MHz crystal, 12 Mbps on the bus is possible. With a 30 MHz crystal, 8 Mbps on the bus is possible. With a 30 MHz crystal, 6 Mbps on the bus is possible. With a 30 MHz crystal, 4 Mbps on the bus is possible. Similarly, for any other bit rate on the bus, the crystal must have 2.5 times the frequency. Generally speaking, quartz represents the clock generator, which can also be replaced by PLL, resonators or other implementations depending on the precision requirements.

[0139] Using an example of a LIN (Local Interconnect Network) transceiver, which was developed as an interface between a LIN protocol controller and the physical bus, we will describe how the bit rate can be changed in the simplest use case. The transceiver is implemented using I3T technology, allowing both high-voltage analog circuits and digital functions to coexist on the same chip. A LIN device is a member of the In-Vehicle Networking (IVN) transceiver family. The LIN bus was developed to transmit low-rate data from control units such as door locks, mirrors, car seats, and sunroofs at the lowest possible cost. The bus is designed to eliminate as much wiring as possible and is implemented with a single wire in each node. Each node has a slave MCU state machine that recognizes and translates the instructions specific to that function.To change the bit rate adjustment on the LIN transceiver, the connected oscillator (crystal) for the PHY clock needs to be changed. In the simplest case, simply using a different crystal is sufficient.

[0140] Registering can be beneficial in general energy savings by clocking down from 25 MHz. Every clock cycle, including the charging process, consumes energy. Slower clocking saves power. Furthermore, radiation and interference emissions are reduced or shifted within the frequency spectrum.

[0141] It's advantageous to use a quartz clock with a 300 MHz clock rate, for example, because this can be calculated using a lowest common multiple (LCM). This can then be divided down to the nearest possible number, for example, 10 cycles for a new clock would result in 30 MHz, 20 cycles would result in 15 MHz, and 12 cycles would result in 25 MHz.

[0142] An alternative can be achieved using a PLL (phase-locked loop). This means dividing the clock frequency from 25 MHz to the aforementioned 300 MHz and then down, as described above. These 300 MHz or higher frequencies don't necessarily contradict the power consumption statement, because they only affect the oscillator. In a chip, countless gates / logic are connected to this clock, and each consumes energy per switching operation. The overall power consumption can be optimized by modifying the bit rate.

Claims

Patent claims 1. A method for flexible adaptation of the bit rate within a computer network with at least one first node, wherein the node exchanges information via a data bus and / or via a point-to-point connection, wherein the steps - Recording information about a first time of receipt of a first message, - Receipt of information about a first sending time of the first message, - capturing information about a second time of receipt of a second message, - Receiving information about a second sending time of the second message, - Determination of an initial value depending on the information received and recorded, and - Comparison of the first value with a given second value, - Detecting the state of the first node depending on the comparison result, characterized in that the comparison result is used to determine the clock generator for generating the clock signals of at least the first node and which bit rate is present via a data bus and / or via a point-to-point connection from and to the first node and to further nodes in the computer network, and if the bit rate is known, the bit rate in the computer network is flexibly changed by modifying the clock generator for generating the clock signals.

2. Method according to claim 1, characterized in that the modification of the clock generator for generating the clock signals is carried out in such a way that the clock generator for generating the clock signals generates 2.5 times the frequency of the bit rate to be achieved in the computer network.

3. Method according to one of claims 1 or 2, characterized in that the speed of the clock generator for generating the clock signals is determined by means of the PTP NRR method (Neighbor Rate Ratio).

4. The method according to claim 1 to 3, wherein the computer network is a 10BASE-T1 S or 100BASE-T1 or 1000BASE-T1 or Multi-Gigabit Ether network.

5. Method according to claim 1 to 4, characterized in that the determination of a clock rate of the clock generator for generating the clock signals of at least the first node is carried out by means of the gPTP protocol from IEEE 802.1AS.

6. Method according to claim 1 to 5, characterized in that the clock generator for generating the clock signals is implemented by a quartz or resonators or phase locked loop (PLL).

7. The method according to claim 1 to 6, wherein, in the presence of a 10BASE-T1 S computer network and a 25 MHz quartz as a clock generator for generating the clock signals for at least the first node and a bit rate of 10 Mbit / s on the data bus, the clock generator for generating the clock signals for at least the first node is modified to 10 MHz in order to generate a bit rate of 4 Mbit / s to be achieved in the computer network.

8. The method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 15 MHz in order to generate a bit rate of 6 Mbit / s to be achieved in the computer network.

9. The method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 20 MHz in order to generate a bit rate of 8 Mbit / s in the computer network.

10. The method according to claim 7, wherein the clock generator for generating the clock signals for at least the first node is modified to 30 MHz in order to generate a bit rate of 12 Mbit / s in the computer network. 11 . Control unit for a computer network, which is designed to: - to send a signal to a second control unit of the computer network and to receive the signal from the second control unit; - to determine a propagation time of the signal on a connection path to the second control unit; - to determine a maximum speed of the connection path based on the transit time; and - to determine a type of transmission medium of the connection path based on the maximum speed, comprising at least -a microprocessor, -a volatile memory and a non-volatile memory, -at least two communication interfaces, -a modifiable clock generator for generating the clock signals, which contains non-volatile memory program instructions which, when executed by the microprocessor, are characterized in that at least one embodiment of the method according to claims 1 to 10 can be implemented and executed.

12. Ethernet on-board network for a motor vehicle, comprising a first control unit and a second control unit, wherein the control units are connected to one another via at least one connection path, and the first control unit is designed according to claim 11.

13. A computer program product comprising instructions which, when the program is executed by a computer, cause the computer to carry out the method according to one or more of claims 1 to 10.

14. A computer-readable medium on which the computer program product according to claim 13 is stored.

15. A vehicle having an on-board Ethernet network comprising a plurality of control units according to claim 13.