Method for detecting a runtime error occurring during a data processing
A method using dual data processing units with hash value encoding/decoding detects runtime errors efficiently, addressing the need for fault-tolerant error detection in safety-critical applications without specialized hardware, enabling cost-effective and flexible deployment.
Patent Information
- Application Number
- PCT/EP2025/060545
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-29
- Filing Date
- 2025-04-16
- Publication Date
- 2025-11-06
AI Technical Summary
Existing methods for detecting runtime errors during data processing are inadequate, particularly in safety-critical applications, as they often require specialized hardware and do not ensure fault tolerance and error rates that meet safety requirements.
A method involving two physically separate data processing units that monitor application software, calculate hash values, and encode/decode these values using self-calculated and reference keys to detect runtime errors without requiring specialized hardware, ensuring fault tolerance and error detection.
This approach efficiently detects runtime errors, allowing for flexible deployment in safety-critical applications like motor vehicles and robots, reducing costs and maintaining backward compatibility with existing systems while avoiding performance overhead and latency.
Smart Images

Figure EP2025060545_06112025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] The invention relates to a method and a system for detecting a runtime error that occurred during data processing, a computer program and a machine-readable storage medium.
[0004] State of the art
[0005] Disclosure document DE 10 2007 040 721 A1 discloses a data processing arrangement.
[0006] The patent application DE 10 2010 037 457 A1 discloses a method for data processing to provide a value for determining whether an error has occurred during the execution of a program.
[0007] The patent application DE 10 2014 117 971 A1 discloses a method for data processing to determine whether an error has occurred during the execution of a program.
[0008] Patent specification US 9,304,872 B2 discloses a method for providing a value to determine whether an error has occurred during the execution of a program.
[0009] Disclosure of the invention: The object underlying the invention is to provide a concept for detecting a runtime error that has occurred during data processing.
[0010] This problem is solved by means of the respective subject matter of the independent claims. Advantageous embodiments of the invention are the subject matter of dependent claims.
[0011] Following a first aspect, a method for detecting a runtime error occurring during data processing is provided, comprising the following steps: processing identical input data by two physically separate data processing units, each using its own application software, to generate user data for a receiver; executing at least one monitoring function by each of the two data processing units to at least partially monitor the respective application software in order to determine at least one monitoring result; calculating a hash value of the user data generated by each of the two data processing units; and calculating at least one reference monitoring result determined by the other data processing unit, assuming that...that the respective at least partial monitoring has not revealed any errors, so that the respective reference monitoring results each correspond to at least one monitoring result determined by the respective data processing device in the error-free case,
[0012] Encoding by one of the two data processing units of the self-calculated hash value based on the self-determined at least one monitoring result and the self-calculated at least one reference monitoring result,
[0013] Output of the encoded hash value by one of the two data processing units, receipt of the output encoded hash value by the other of the two data processing units,
[0014] Decoding the received encoded hash value by the other of the two data processing units based on the self-determined at least one monitoring result and the self-calculated at least one reference monitoring result,
[0015] Output of a message comprising the self-generated payload, the decoded hash value, and the self-calculated hash value by the other of the two data processing units,
[0016] Receipt of the sent message by the recipient,
[0017] The recipient checks the message to detect a runtime error that occurred during data processing.
[0018] According to a second aspect, a system for detecting a runtime error that occurred during data processing is provided, comprising: two physically separate implemented data processing facilities, a receiver, wherein the system is configured to perform all steps of the procedure according to the second aspect.
[0019] According to a third aspect, a computer program is provided, comprising instructions which, when the computer program is executed by the system according to the second aspect, cause it to perform a procedure according to the first aspect.
[0020] According to a fourth aspect, a machine-readable storage medium is provided on which the computer program is stored according to the third aspect.
[0021] The invention is based on the understanding that the application software used to generate the user data is monitored, and that a monitoring result is determined based on this monitoring. This monitoring result is used to encode the hash value calculated from the user data. Furthermore, the data processing units each determine reference monitoring results, assuming that their respective monitoring has not resulted in any errors, so that the corresponding reference monitoring results each correspond to at least one monitoring result determined by the respective data processing unit under error-free conditions. One of the two data processing units uses its own calculated monitoring result to encode the hash value.This encoded hash value is sent to, or output to, the other of the two data processing units. The other data processing unit receives the encoded hash value and decodes it based on at least one self-determined monitoring result and at least one self-calculated reference monitoring result. The decoded hash value, along with the self-generated user data and the self-calculated hash value, is sent by the other data processing unit to the receiver, which then checks the two hash values against the user data to detect any runtime errors that may have occurred during data processing.
[0022] If the calculations of the user data on all data processing units (DPUs) yielded the same result, and the monitoring functions on all DPUs executed flawlessly, both hash values should correspond to the user data. Furthermore, the decoding of the hash values by the other DPU should result in a valid message from the decoded and reconstructed user data segments. However, if a monitoring function on one DPU detects an error, it invalidates parts of the user data, rendering the reconstructed user data segments invalid as well. Similarly, if a program flow in the application software malfunctions, the monitoring result of the corresponding DPU will deviate from the expected reference monitoring result, and the processing unit will be unable to correctly decode the corresponding user data segment.
[0023] This results, for example, in the technical advantage that a runtime error occurring during data processing can be efficiently detected. Therefore, the concept described here can be advantageously implemented or used in safety-critical applications. Safety-critical applications are typically run on specialized, purpose-built hardware. The application's safety requirements usually impose hardware requirements regarding fault tolerance and error rates, which are often not guaranteed by non-safety-critical, especially widely used, hardware such as processors or RAM.
[0024] The concept described here advantageously makes it possible to test the sufficiently correct execution of the application software and the safety-relevant monitoring functions that monitor the application software during operation, without the need for special intrinsically safe hardware.
[0025] Thus, for example, the concept described here enables a significantly more flexible / virtualized deployment of application software, for example as a software container on existing computing clusters / servers, with regard to security.
[0026] The concept described here, for example, advantageously enables cost savings for each instance of an infrastructure setup used to control a receiver, such as a motor vehicle or robot, since it can replace one or more specialized security hardware platforms, such as a security PLC. PLC stands for "Programmable Logic Controller".
[0027] The concept described here is advantageously backward compatible with existing systems, such as AVP systems, since no changes to the interface between infrastructure and receiver, e.g., vehicle / robot, are necessary. AVP stands for "Automated Valet Parking".
[0028] The concept described here has the particular advantage that changes to existing systems can be implemented by means of changes and extensions to the infrastructure application software, so that these changes do not place any special / additional requirements on the computer hardware platforms used.
[0029] The concept described here has the particular advantage that no significant additional performance overhead is generated.
[0030] The concept described here has the particular technical advantage of not introducing any significant additional latency. The steps described within this concept can be implemented efficiently. For example, encoding and decoding can be implemented using XOR.
[0031] Thus, the particular technical advantage is that a concept for efficiently detecting a runtime error that occurred during data processing is provided.
[0032] In one embodiment of the method, this comprises the following steps: processing the same input data by at least one further data processing unit, implemented physically separate from the two data processing units, using further application software to generate further user data for the receiver; executing at least one further monitoring function by the at least one further data processing unit to at least partially monitor the further application software in order to determine at least one further monitoring result; and calculating a further hash value over the user data it generated itself by the at least one further data processing unit.The respective calculation by at least one further data processing unit of at least one reference monitoring result determined by the other data processing units, assuming that the respective at least partial monitoring has not revealed an error, so that the respective reference monitoring results each correspond to at least one monitoring result determined by the respective data processing unit in the error-free case; the respective encoding by at least one further data processing unit of the self-calculated further hash value based on the self-determined at least one further monitoring result and the self-calculated reference monitoring results; the respective output of the encoded further hash value by at least one further data processing unit.The respective calculation by the two data processing units of a respective further reference monitoring result determined by at least one further data processing unit, assuming that the respective at least partial monitoring has not revealed an error, so that the respective further reference monitoring results each correspond to at least one further monitoring result determined by at least one further data processing unit in the error-free case, wherein the self-calculated hash value is additionally encoded by one of the two data processing units based on the self-calculated at least one further reference monitoring result.
[0033] Receiving the further encoded hash value output by at least one other data processing unit by the other of the two data processing units,
[0034] Decoding the received encoded further hash value by the other of the two data processing units based on the self-determined at least one monitoring result, the self-calculated at least one reference monitoring result, and the self-calculated at least one further reference monitoring result, wherein the message output by the other of the two data processing units additionally includes the decoded further hash value.
[0035] This results, for example, in the technical advantage of further increasing security, since an error would now have to simultaneously affect the calculations of, for example, three data processing units. The additional redundancy reduces the probability of such an error occurring. Another technical advantage, particularly when monitoring functions are very resource-intensive, is that they can potentially be distributed across multiple data processing units. This allows only specific aspects of the application software (ASW) to be monitored at any given time, and the sum of all (partial) monitoring applied across the multiple data processing units provides sufficient overall security. This can be particularly useful with homogeneous data processing units (i.e., the same operating system and the same hardware), as it allows for a degree of diversity through differently applied monitoring mechanisms.
[0036] According to this embodiment, at least one further data processing unit is provided in addition to the two data processing units, i.e., at least a third data processing unit. In other words, the concept described here can provide for more than two data processing units. Each of the data processing units calculates corresponding reference monitoring results. All but the other of the two data processing units encode their own calculated hash value with the reference monitoring results they themselves determine, in addition to their own monitoring result. The encoded hash values are then output by the respective data processing units to the other of the two data processing units, which decodes the encoded hash values accordingly.This means that a data processing unit is provided for decoding the hash values encoded by the other data processing units and sending or outputting them to the recipient.
[0037] In one embodiment of the method, it is provided that the verification of the message by the recipient includes a verification of the hash values contained in the message based on the payload contained in the message.
[0038] This results, for example, in the technical advantage that the message can be efficiently checked. In particular, this results in the technical advantage that the integrity of the message can be efficiently checked.
[0039] In one embodiment of the method, this comprises the following steps: each calculating a key by the two data processing units based on their respective self-calculated at least one monitoring result, each calculating a respective reference key by the two data processing units based on their respective self-calculated at least one reference monitoring result, wherein the data to be encoded is encoded by one of the two data processing units using the self-calculated key and the self-calculated reference key, and wherein the data to be decoded is decoded by the other of the two data processing units using the self-calculated reference key and the self-calculated key.
[0040] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently.
[0041] For example, in the error-free case, a key and a reference key form a key pair which can be used to encode and decode any data.
[0042] For example, in a flawless case, the key and the reference key are identical.
[0043] Keys and reference keys, for example, are calculated using different mathematical methods.
[0044] In one embodiment of the method, this comprises the following steps: each additional data processing unit calculates a further key based on its own further monitoring results; each additional data processing unit calculates further reference keys based on its own further monitoring results, wherein the data to be coded is encoded with the self-calculated further key and with the respective self-calculated reference keys; the two data processing units calculate, for each additional data processing unit, a respective further reference key based on the respective self-calculated reference monitoring result.wherein the data to be encoded is additionally encoded by one of the two data processing units using the respective self-determined further reference keys, and wherein the data to be decoded is decoded by the other of the two data processing units using the respective further reference keys.
[0045] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently.
[0046] For example, in the error-free case, an additional key and an additional reference key form another key pair which can be used to encode and decode any data.
[0047] For example, in the error-free case, the other key and the other reference key are identical.
[0048] Further keys and further reference keys are calculated, for example, using different mathematical methods.
[0049] In one embodiment of the method, it is provided that the respective encoding and decoding are carried out based on a value explicitly or implicitly synchronized between the data processing devices, e.g. a respective counter and / or based on a respective timestamp.
[0050] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently and, in particular, without additional synchronization effort. In one embodiment of the method, the calculation of the (additional) keys and the (additional) reference keys is performed using a value explicitly or implicitly synchronized between the data processing units, e.g., a respective counter and / or a respective timestamp.
[0051] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently and, in particular, without additional synchronization effort.
[0052] In one embodiment of the method, it is provided that the respective encoding and decoding are carried out based on a respective counter and / or based on a respective timestamp.
[0053] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently and, in particular, without additional synchronization effort.
[0054] In one embodiment of the method, it is provided that the calculation of the (additional) keys and the (additional) reference keys is carried out using the respective counter and / or the respective timestamp.
[0055] This results, for example, in the technical advantage that encoding and decoding can be carried out efficiently and, in particular, without additional synchronization effort.
[0056] In general, the use of a timestamp and / or a counter offers the technical advantage of efficiently avoiding errors based on faulty repetitions of an (outdated) message, for example, so-called "stuck-at" errors.
[0057] In one embodiment of the method, the receiver is a motor vehicle or a robot. This provides, for example, the technical advantage that the processing of user data for a motor vehicle or a robot can be efficiently protected against runtime errors.
[0058] In one embodiment of the method, it is provided that the (further) user data each comprise one or more elements of the following user data:
[0059] Minimum / maximum / target speeds; minimum / maximum / target accelerations / decelerations; minimum / maximum / target-released track sections; maximum validity period of one or more current control commands and / or a current driving release; minimum / maximum / target-released steering or joint angles.
[0060] This results, for example, in the technical advantage that user data for a motor vehicle or for a robot can be efficiently protected against runtime errors.
[0061] This results, for example, in the technical advantage that different types of user data can be provided.
[0062] Monitoring application software includes, for example, monitoring the program flow of the application software.
[0063] The phrase “at least one” means “one or more”.
[0064] The phrase "at least two" means "two or more".
[0065] Statements made in connection with more than one of the data processing facilities apply analogously to the other data processing facilities and vice versa. This means, in particular, that statements made in connection with more than one additional data processing facility apply analogously to other additional data processing facilities and / or to one or both of the aforementioned data processing facilities and vice versa.
[0066] The phrase "at least partially" means "partially or completely".
[0067] In one embodiment of the method, it is provided that this is carried out by the system.
[0068] The system is, for example, programmed to execute the computer program.
[0069] The method is, for example, a computer-implemented method.
[0070] In the error-free case, at least one monitoring function determines a monitoring result that is known or that can be calculated independently of the monitoring.
[0071] Procedure characteristics result analogously from corresponding system characteristics and vice versa.
[0072] If the check does not detect any runtime errors, the payload is used by the recipient, for example. Otherwise, the payload is not used by the recipient, but is discarded, for example.
[0073] If the check confirms that the integrity of the user data has been preserved, the user data will be used by the recipient, for example. Otherwise, the user data will not be used by the recipient, but will be discarded, for example.
[0074] The embodiments and examples described here can be combined in any way, even if this is not explicitly described.
[0075] The invention is explained in more detail below with reference to preferred embodiments. Figure 1 shows a block diagram and
[0076] Fig. 2 a machine-readable storage medium.
[0077] Fig. 1 shows a block diagram 100 which illustrates the concept described here by way of example.
[0078] Reference numeral 101 refers to a first data processing unit. Reference numeral 103 refers to a second data processing unit. The two data processing units, 101 and 103, are implemented in physically separate locations.
[0079] Reference numeral 105 points to a receiver, which is, for example, a motor vehicle or a robot.
[0080] Reference numeral 107 refers to input data that is processed by the two data processing units 101 and 103, which is described in more detail below.
[0081] The input data 107 is processed by the first data processing unit 101 using first application software 109 to generate payload data 111 for the receiver 105. The first data processing unit 101 then calculates or determines a hash value 113 (hereinafter also referred to as hash value A) from the generated payload data 111. For example, the first data processing unit 101 applies a hash function to the generated payload data 111 to determine the hash value 113.
[0082] The first data processing unit 101 performs several monitoring functions to at least partially monitor the first application software 109. A first monitoring function 115, a second monitoring function 117, and a third monitoring function 119 are shown symbolically as examples. Based on the respective monitoring by the three monitoring functions 115, 117, and 119, a monitoring result is determined, for example, based on which a first key 121 (hereinafter also referred to as key A) is calculated.
[0083] The input data 107 is processed by the second data processing unit 103 using a second application software 123 to generate payload data 125 for the receiver 105. The second data processing unit 103 then calculates or determines a hash value 127 (hereinafter also referred to as hash value B) from the generated payload data 125. For example, the second data processing unit 103 applies a hash function to the generated payload data 125 to determine the hash value 127.
[0084] The second data processing unit 103 performs several monitoring functions to at least partially monitor the second application software 123. A fourth monitoring function 129, a fifth monitoring function 131, and a sixth monitoring function 133 are shown symbolically as examples.
[0085] Based on the respective monitoring by the three monitoring functions 129, 131, 133, for example, a respective monitoring result is determined, based on which a second key 135 (hereinafter also referred to as key B) is calculated.
[0086] The first data processing unit 101 calculates corresponding reference monitoring results for the second data processing unit 103, assuming that the monitoring of the second data processing unit 103 has not revealed any errors, so that the respective reference monitoring results correspond to the monitoring results determined by the second data processing unit 103 in the error-free case.
[0087] Based on the reference monitoring results calculated by the first data processing unit 101, the first data processing unit 101 calculates a first reference key 137 (hereinafter also referred to as key B'), which in the error-free case corresponds to the second key 135 (key B) or is a counterpart key to the second key 135 (key B).
[0088] The second data processing unit 103 calculates corresponding reference monitoring results for the first data processing unit 101, assuming that the monitoring of the first data processing unit 101 did not reveal any errors, so that the respective reference monitoring results correspond to the monitoring results determined by the first data processing unit 101 in the error-free case.
[0089] Based on the reference monitoring results calculated by the second data processing unit 103, the second data processing unit 103 calculates a second reference key 139 (hereinafter also referred to as key A'), which in the error-free case corresponds to the first key 121 (key A) or is a counterpart key to the first key 121 (key A).
[0090] The first data processing unit 101 encodes the self-calculated hash value 113 based on the first key 121 and the first reference key 137. The correspondingly encoded hash value 113 is identified by the reference sign 141.
[0091] The encoded hash value 141 is output by the first data processing unit 101 to the second data processing unit 103. The second data processing unit 103 receives the output encoded hash value 141 and decodes it based on the second key 135 and the second reference key 139. The second data processing unit 103 sends a message 143, which includes the self-generated payload 125, the decoded hash value, and the self-calculated hash value 127.
[0092] The output message 143 is received by receiver 105. Receiver 105 checks message 143 according to a function block 145 to detect any runtime errors that may have occurred during data processing. Receiver 105's check of message 143 includes, for example, checking the hash values contained in message 143 based on the payload contained in message 143.
[0093] If the check according to function block 143 reveals no integrity errors or runtime errors, the user data is used according to function block 147. If an error is detected or integrity could not be maintained, function block 149 stipulates that one or more error actions are performed.
[0094] Figure 1 thus shows a system 151 for detecting a runtime error that occurred during data processing, wherein the system 151 comprises the first data processing unit 101, the second data processing unit 103, and the receiver 105. The system 151 is configured to execute all steps of the procedure for detecting a runtime error that occurred during data processing.
[0095] Fig. 2 shows a machine-readable storage medium 201 on which a computer program 203 is stored. The computer program 203 comprises instructions which, when executed by the system 151, cause the computer program 203 to execute a procedure according to the first aspect.
[0096] The concept described here will be further explained using examples below.
[0097] The following abbreviations are defined or established:
[0098] Computer A is a first data processing unit, for example the first data processing unit 101 of Fig. 1. Computer B is a second data processing unit, for example the second data processing unit 103 of Fig. 1.
[0099] Both computers run application software and monitoring functions, which may be the same application software or monitoring functions. The execution of the application software involves processing the same input data to determine or generate user data.
[0100] Computer A calculates a hash value, for example a CRC, of the payload data and encodes it with key A, the result of its program flow check, and with key B', the expected result of the program flow from computer B. CRC stands for "Cyclic Redundancy Check".
[0101] This encoded hash value A is then forwarded to computer B. Computer B calculates its own hash value B on its user data, for example, using a different method, such as a CRC with a different polynomial. To decode the encoded hash value A, computer B calculates the expected result of the program flow of A, key A', and uses the result of its own program flow control, key B, for decoding.
[0102] Computer B now appends both hash values A and B to the self-generated payload to create a corresponding message. This secured payload can then be validated by the recipient, for example, recipient 105 in Fig. 1, by simply checking hash values A and B against the payload, e.g., by calculating the different CRCs. Neither computer A nor computer B possesses enough information on its own to calculate both hash values and unintentionally construct a valid message. Furthermore, each computer verifies the program flow of the other computer through encoding / decoding.
[0103] The concept described here specifically involves monitoring the correct execution of safety-critical software (e.g., a monitoring function) using several combined hash functions. The results of all such secured monitoring functions are then incorporated into a computer-specific key S. This key is used, for example, to encode certain security-relevant user data.
[0104] If the calculations of the user data on all computers (or other data processing facilities) yielded the same result and the monitoring functions on all computers were executed without errors, the decoded hash values can be validated against the user data. However, if a monitoring function on one computer detects an error, for example, due to a faulty program flow, the computer-specific key will deviate from the expected key. In other words, a different key is calculated for encoding the hash value than the reference key—that is, the key expected in the error-free case—so the corresponding decoded hash value cannot be validated against the user data.
[0105] To avoid errors based on faulty repetitions of an (outdated) message, e.g., so-called stuck-at errors, a constantly changing value, such as a counter or timestamp, is used, for example, when generating the computer-specific keys and hash values or hashes of the monitoring functions.
[0106] Summary
[0107] The invention relates to a method and a system for detecting a runtime error that has occurred during data processing.
[0108] It is designed that two or more data processing units (DPUs) each process identical input data to generate payload data for a receiver. The processing of the input data is monitored by one or more monitoring functions. Based on the monitoring results, DPU-specific keys are calculated. These keys are used by all but one of the DPUs to encode the payload data using their own self-calculated hash values. The DPU that does not encode its own hash value receives the encoded hash values and decodes them using its own reference keys. These reference keys are calculated under the assumption that the monitoring of the other DPUs has not detected any errors in the processing of the input data.The decoded hash values, the self-calculated hash value, and the self-calculated payload are sent by this data processing facility to a receiver, which checks the hash values against the payload to detect any runtime errors that may have occurred during data processing.
[0109] The invention further relates to a computer program and a machine-readable storage medium.
Claims
Claims 1. A method for detecting a runtime error that occurred during data processing, comprising the following steps: processing identical input data (107) by two physically separate data processing units (101, 103) using application software (109, 123) to generate payload data (111, 125) for a receiver (105); executing at least one monitoring function (115, 117, 119, 129, 131, 133) by each of the two data processing units (101, 103) to at least partially monitor the application software (109, 123) in order to determine at least one monitoring result; calculating a hash value (113, 127) over the payload data (111, 125) generated by each of the two data processing units (101, 103); Calculation by the two data processing units (101,103) of at least one reference monitoring result determined by the respective other data processing unit (101 , 103) under the assumption that the respective at least partial monitoring has not revealed any error, so that the respective reference monitoring results each correspond to at least one monitoring result determined by the respective data processing unit (101 , 103) in the error-free case, Encoding by one of the two data processing units (101, 103) of the self-calculated hash value (113) based on the self-determined at least one monitoring result and the self-calculated at least one reference monitoring result, Output of the encoded hash value (141) by one of the two data processing units (101 , 103), Receiving the output encoded hash value (141) by the other of the two data processing units (101 , 103), Decoding the received encoded hash value by the other of the two data processing units (101, 103) based on the self-determined at least one monitoring result and at least one self-calculated reference monitoring result, Output of a message (143) comprising the self-generated payload (125), the decoded hash value and the self-calculated hash value (127) by the other of the two data processing facilities (101 , 103), receipt of the output message (143) by the receiver (105), inspection of the message (143) by the receiver (105) in order to detect a runtime error that occurred during data processing.
2. The method according to claim 1, comprising: processing the same input data (107) by at least one further data processing device physically separate from the two data processing devices (101, 103) using a further application software to generate further user data for the receiver (105); executing at least one further monitoring function by the at least one further data processing device to at least partially monitor the further application software in order to determine at least one further monitoring result; calculating a further hash value over the self-generated user data by the at least one further data processing device; and calculating a result by the at least one further data processing device of the other data processing devices (101, 103).103) determined at least one reference monitoring result under the assumption that the respective at least partial monitoring did not reveal any errors, so that the respective reference monitoring results each correspond to at least one monitoring result determined by the respective data processing unit (101, 103) in the error-free case, respective encoding by the at least one further data processing unit of the self-calculated further hash value based on the self-determined at least one further monitoring result and the self-calculated reference monitoring results, respective output of the encoded further hash value by the at least one further data processing unit, The respective calculation by the two data processing units (101, 103) of at least one further reference monitoring result determined by at least one further data processing unit, assuming that the respective at least partial monitoring has not revealed an error, so that the respective further reference monitoring results each correspond to at least one further monitoring result determined by at least one further data processing unit in the error-free case, wherein the self-calculated hash value is additionally encoded by one of the two data processing units (101, 103) based on the self-calculated at least one further reference monitoring result, and the other of the two data processing units receives the encoded further hash value output by the at least one further data processing unit. Decoding the received encoded further hash value by the other of the two data processing units (101, 103) based on the self-determined at least one monitoring result, the self-calculated at least one reference monitoring result, and the self-calculated at least one further reference monitoring result, wherein the message output by the other of the two data processing units (101, 103) additionally includes the decoded further hash value.
3. Method according to claim 1 or 2, wherein the checking of the message (143) by the receiver (105) comprises checking the hash values included in the message (143) based on the payload data (125) included in the message (143).
4. A method according to any of the preceding claims, comprising: the two data processing units (101, 103) each calculating a key (121, 135) based on at least one monitoring result calculated by each unit, and the two data processing units (101, 103) each calculating a reference key (137, 121) based on at least one reference monitoring result calculated by each unit. wherein the data to be encoded is encoded by one of the two data processing units (101 , 103) using the self-calculated key and the self-calculated reference key, and wherein the data to be decoded is decoded by the other of the two data processing units (101 , 103) using the self-calculated reference key and the self-calculated key.
5. The method of claim 4, insofar as it relates back to claim 2, comprising: the respective calculation of a further key by the at least one further data processing unit based on the further monitoring results determined by the unit itself, the respective calculation of further reference keys by the at least one further data processing unit based on the further monitoring results determined by the unit itself, wherein the data to be coded is encoded with the further key determined by the unit itself and with the reference keys determined by the unit itself. The two data processing units (101, 103) calculate for each at least one further data processing unit of a respective further reference key based on the respective self-calculated at least one further reference monitoring result, wherein the data to be coded is additionally coded with the respective self-determined further reference keys by one of the two data processing units (101, 103), wherein the data to be decoded is decoded using the respective further reference keys by the other of the two data processing units (101, 103).
6. Method according to one of the preceding claims, wherein the respective encoding and decoding are performed based on a respective counter and / or based on a respective timestamp.
7. Method according to claim 5 and claim 6, wherein the calculation of the (further) keys and the (further) reference keys is carried out using the respective counter and / or the respective timestamp.
8. Method according to any of the preceding claims, wherein the receiver (105) is a motor vehicle or a robot.
9. Method according to one of the preceding claims, wherein the (further) user data each comprise one or more elements of the following user data: minimum / maximum / (target) speeds; minimum / maximum / (target) accelerations / decelerations; minimum / maximum / (target) cleared track sections; maximum validity period of one or more current control commands and / or a current driving release; minimum / maximum / (target) steering or joint angles.
10. System (151) for detecting a runtime error that occurred during data processing, comprising: two physically separate data processing devices (101 , 103), a receiver (105), wherein the system (151) is configured to perform all steps of the method according to any of the preceding claims.
11. Computer program (203) comprising instructions which, when the computer program (203) is executed by the system (151) according to claim 10, cause the system to execute a method according to any one of claims 1 to 9.
12. Machine-readable storage medium (201) on which the computer program (203) according to claim 11 is stored.
Citation Information
Patent Citations
Data processing arrangement comprises coding device, which is adjusted to assign codeword to data item to be stored in memory element based on signal information
DE102007040721A1
Methods for data processing to provide a value for determining whether an error has occurred during the execution of a program, methods for data processing to determine whether an error has occurred during the execution of a program, methods for generating program code, data processing arrangements for providing a value for determining whether an error has occurred during the execution of a program, data processing arrangements for determining whether an error has occurred during the execution of a program, and data processing arrangements for generating program code
DE102010037457A1
Method for data processing for determining whether an error has occurred when executing a program, and data processing arrangements for generating program code
DE102014117971A1
Method for providing a value for determining whether an error has occurred in the execution of a program
US9304872B2
Procedures for verifying the processing of user data
DE102022208087A1